<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>device security Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/device-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/device-security/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Fri, 21 Nov 2025 14:24:24 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>device security Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/device-security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>FED Roundup &#8211; November 2018</title>
		<link>https://www.corsec.com/fed-nov18/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 28 Nov 2018 18:11:58 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[device security]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=16674</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-nov18/">FED Roundup &#8211; November 2018</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: left;"><span style="color: #000000;"><strong><a style="color: #000000;" href="http://sitdev.disa.mil/newsandevents">DISA’s November News</a></strong></span></h5>
<ul>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2018/DISA-invites-industry-collaborate"><span style="color: #0000ff;">DISA holds Forecast to Industry</span></a></li>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2018/Marine-Corps-243rd-birthday"><span style="color: #0000ff;">DISA celebrates Marines Corp Birthday</span></a></li>
</ul>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST’s November News</a></strong></h5>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2018/NCCoE-Releases-Draft-NISTIR-8219-for-Comment"><span style="color: #0000ff;"><span style="color: #0000ff;">Draft NISTIR 8219, &#8220;Securing Manufacturing Industrial Control Systems: Behavioral Anomaly Detection</span></span></a></li>
<li><a href="https://csrc.nist.gov/News/2018/nccoe-releases-draft-sp-1800-19b-for-comment"><span style="color: #0000ff;">SP 1800-19, Trusted Cloud: Security Practice Guide for VMWare Hybrid Cloud Infrastructure as a Service</span></a></li>
<li><a href="https://csrc.nist.gov/News/2018/security-telehealth-remote-patient-monitoring-drft"><span style="color: #0000ff;">Draft project description, Securing Telehealth Remote Patient Monitoring Ecosystem: Cybersecurity for the Healthcare Sector</span></a></li>
<li><a href="https://csrc.nist.gov/News/2018/NIST-Releases-2nd-Draft-SP-800-57-Part-2-Rev-1"><span style="color: #0000ff;">2nd Draft of SP 800-57 Part 2 Revision 1, Recommendation for Key Management: Best Practices for Key Management Organizations</span></a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s November News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><a href="https://sitdev.niap-ccevs.org/Ref/Progress_Report_2018_Q3.pdf"><span style="color: #0000ff;">Third Quarter Progress Report</span></a></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li class="wpb_wrapper" style="text-align: left;">None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-nov18/">FED Roundup &#8211; November 2018</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Just When You Thought It Was Safe To Shut Down Your Computer</title>
		<link>https://www.corsec.com/just-when-you-thought-it-was-safe-to-shut-down-your-computer/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 25 Sep 2018 17:27:58 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[device security]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=16213</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/just-when-you-thought-it-was-safe-to-shut-down-your-computer/">Just When You Thought It Was Safe To Shut Down Your Computer</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Although Cold Boot Attacks are considered to be somewhat of an antiquated method, largely due to the need for an attacker to have physical access to the machine, they still represent a threat to unprotected systems.</p>
<p>By definition, a Cold Boot Attack is a type of side channel attack in which an attacker with physical access to a computer is able to retrieve encryption keys from a running operating system after using a cold reboot to restart the machine. Known since 2008, these attacks target data memory remanences, sometimes containing sensitive and personal information, on a CPU&#8217;s RAM which can linger anywhere from a few seconds to a few minutes after power has been removed. By utilizing a removable disk, attackers are able to upload sensitive data and viola, you have a security breach.</p>
<p>Many modern systems have security countermeasures to prevent these types of attacks; by memory scrambling or encrypting RAM the ability to steal encryption keys is essentially eliminated, but a new threat could threaten most modern computers according to experts.</p>
<p>Researchers from F-Secure, a Finnish company, have found new methods to disable current cold boot attack firmware security measures. This attack still requires the physical access that previous cold boot attacks utilized, but the threat is still present. The company is positioned to release additional information on their findings at upcoming events and conferences.</p>
<p>In the meantime, companies looking to protect their data can look to modernize security functionality of their systems by following guidelines and requirements laid out within <a href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a>. The FIPS <a href="https://www.corsec.com/fips-140-2/#theplayers">requirements for level 3</a> require, in addition to all security measures from level 1 and 2, identity-based authentication, physical security mechanisms for tamper detection and tamper response, and zeroization of keys to destroy this type of data. Implementing these changes helps to prevent cold boot attacks from ever occurring.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://www.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 style="text-align: left;"><strong>About Corsec Security, Inc.</strong></h5>
<p style="text-align: left;">For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><a href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a></strong>, <a href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a> (CC) and the <a href="https://www.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 style="text-align: left;"><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p style="text-align: left;">Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
<div class="wpb_text_column wpb_content_element "></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/just-when-you-thought-it-was-safe-to-shut-down-your-computer/">Just When You Thought It Was Safe To Shut Down Your Computer</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Securing Medical Devices, Where to Start?</title>
		<link>https://www.corsec.com/securing-medical/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 13 Sep 2017 21:45:45 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[device security]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[medical devices]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=9878</guid>

					<description><![CDATA[<p>During a recent discussion held at the Bipartisan Policy Center titled, Cybersecurity and Medical Devices: Risk Assessment and Response, an esteemed panel of experts lead a discussion about increasing medical device standards and educating the ... </p>
<p class="read-more-container"><a title="Securing Medical Devices, Where to Start?" class="read-more button" href="https://www.corsec.com/securing-medical/#more-9878" aria-label="More on Securing Medical Devices, Where to Start?">Read more</a></p>
<p>The post <a href="https://www.corsec.com/securing-medical/">Securing Medical Devices, Where to Start?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>During a recent discussion held at the Bipartisan Policy Center titled, <a href="https://bipartisanpolicy.org/events/cybersecurity-and-medical-devices-risk-assessment-and-response/"><em>Cybersecurity and Medical Devices: Risk Assessment and Response</em></a>, an esteemed panel of experts lead a discussion about increasing medical device standards and educating the public on the industry&#8217;s risk vs. benefits in regards to technological innovations. Michael Chertoff, Executive Chairman and Co-Founder of The Chertoff Group and Former Secretary of the U.S. Department of Homeland Security (DHS), noted that the timing of innovations within the medical device industry allows for increased opportunities for risk and vulnerability management more efficiently and effectively during the medical device development and design stages rather than tailoring vulnerability solutions to existing devices.</p>
<p>Chertoff describes the risk mitigation process he finds to be most successful after witnessing its implementation across multiple industries. In this process, there are five steps:</p>
<ol>
<li>Educate the board and senior management on potential threats and risks<br />
-Threat = what the adversary is actually doing<br />
-Risk = the threat multiplied by the consequence</li>
<li>Take ownership of threat &amp; risk mitigation by understanding that the Cyber Threat is to be handled like any other threat being discussed within your organization</li>
<li>Implement a threat mitigation strategy within your company after careful analysis and expert guidance</li>
<li>Allocate human capital investments and financial resources in order to successfully uphold the strategy</li>
<li>Hold all individuals within the company accountable for behaviors exhibiting potential threats and risks</li>
</ol>
<p>Medical devices are not a &#8220;one size fits all&#8221; type of solution, and neither is the issue of securing the devices themselves. With so many options available: non-surgical, implanted, portable, etc; these devices not only aid the user but also store and transmit sensitive user data. Protecting this data should be prioritized, but with the numerous options available throughout the market; it is difficult to know where to start.</p>
<p>The innovation within the technology that is embedded into these evolving medical devices allows for less intrusive treatment as time goes on. Not only are the devices becoming smaller, but they also allow for increased connectivity- whether it is between patient&#8217;s phones and networks, or providing physicians with real-time access to patient information; thus leading to more proactive methods of treatment, intervention, medications, and observations.</p>
<p>What is important to note is that although direct access to medical records and patient data provides patient transparency on, their are significant risks associated with transmitting sensitive data. Medical device manufacturers must think about not only protecting present cyber vulnerabilities, but the need to also anticipate future risks by implementing company wide strategies in preparation for any necessary risk mitigation. We have reached a point where cybersecurity could impact the wellbeing of a person with a medical device implanted.</p>
<p>Like all devices that process sensitive data, medical devices/solutions could benefit from obtaining security certifications like:<strong><span style="color: #008000;"> <a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a></span></strong>,<strong> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/">Common Criteria</a></span></strong>, and the <strong><span style="color: #000080;"><a style="color: #000080;" href="https://www.corsec.com/uc-apl/">DoDIN APL</a>.</span></strong></p>
<p><strong><a href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe">Subscribe</a></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>
<p>The post <a href="https://www.corsec.com/securing-medical/">Securing Medical Devices, Where to Start?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
