Focus on Cybersecurity: Gap Analysis for Audit Preparation at TNI medical

TNI medical AG develops solutions in the field of respiratory therapy with the goal of supporting the treatment of patients in their daily lives. In addition to product functionality, issues such as information security and regulatory requirements are also becoming increasingly important, particularly with regard to audits by Notified Bodies.

For the “Masimo softFlow” system, the task at hand was precisely this: The existing cybersecurity requirements needed to be fully and transparently documented in the technical documentation, particularly in the risk management file. To identify potential gaps early on, TNI medical commissioned the BAYOOMED team to conduct a gap analysis.

Analysis of interfaces and data flows

As part of the project, the current state of cybersecurity was systematically assessed. The main focus was on the question of where risks can arise – especially where data enters or leaves the system, for example via USB or SD interfaces.

We also looked at how cybersecurity risks are taken into account in existing risk management and what measures are already defined to protect data and ensure system stability.

SBOM creation and analysis

A central component of the activities was the consideration of the external software components used in the product. The focus here was on creating a Software Bill of Materials (SBOM) specially tailored to the firmware framework used. This involved determining which components and libraries are actually used in the firmware stack.

In addition, the establishment of an SBOM analysis process was considered: i.e. how known vulnerabilities can be specifically searched for and evaluated on the basis of the SBOM created, for example by comparing them with relevant databases such as CVE and NVD.

View of processes and documentation

Another part of the analysis concerned the handling of software throughout its entire life cycle. This included the question of how updates and patches are implemented and whether changes to the software can be tracked properly.

The handling of known vulnerabilities was also examined. For this purpose, processes were analyzed with which information from databases such as BfArM, MAUDE or NVD CVE is evaluated. The decisive factor here was whether this information is specifically applied to the software components used in the product – including external libraries (SOUP).

In addition, we examined how TNI medical communicates in the event of security-related updates or incidents—that is, how customers are informed and what options are available for questions or support.

Cooperation in the course of the project

As has been the case in other projects, it became clear that coordination between teams plays an important role—especially when it comes to issues involving both technical and regulatory aspects.

Sebastian Wittor, Senior Project Manager, Medical Engineering at BAYOOMED

TNI medical also viewed the collaboration in the same light.

Ewald Anger, CEO of TNI medical:

Results as a basis for further preparation

The results were summarized in a gap and risk assessment report. This report serves as a basis for TNI medical to address the identified issues in a targeted manner and to further complete the documentation in preparation for the upcoming audit.

Further services in the area of cybersecurity

Do you need support in the area of cybersecurity and are currently looking for a suitable partner for the implementation? Simply contact us and we’ll get to know each other and find out whether we’re the right choice for you.