Blue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 29

    What the FDA Wants in Security Architecture Views for Devices

    With MedTech leader - What are the four security architecture views that the FDA prioritizes, and how do they impact your device's design? This episode explores the FDA-defined security architecture views essential for medical device cybersecurity.

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Trevor Slattery, COO at Blue Goat Cyber

    Reviewed by Trevor Slattery

    COO · Blue Goat Cyber

    Last reviewed: May 1, 2026

    Listen now

    What are the four security architecture views that the FDA prioritizes, and how do they impact your device's design?

    This episode explores the FDA-defined security architecture views essential for medical device cybersecurity. Christian and Trevor break down the four views - global system, updatability/patchability, multi-patient harm, and secure use cases - with real-world examples and practical advice.

    Key points:

    (5:25) The Global System View

    • Companion apps and cloud infrastructure must be part of the device scope.

    • Many device manufacturers overlook update infrastructure in this view.

    • Distinguishing in-scope versus out-of-scope components is a common challenge.

    (12:52) Updatability and Patchability

    • Secure update procedures must cover the entire lifecycle.

    • FDA wants manufacturers to consider both infrastructure and delivery integrity.

    • A weak development environment can compromise update trustworthiness.

    (18:21) Multi-Patient Harm Scenarios

    • Risk is based on the scope and scale of potential compromise.

    • Even small devices can cause large-scale issues depending on their connectivity.

    (23:09) Secure Use Case Views and Closing Advice

    • Every device function should have a corresponding security consideration.

    • Functional requirements can guide secure use case documentation.

    More episodes

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.