Supporting Cybersecurity Risk Management for Medical Devices via the SECUMAN Ontology and Shapes

📅 2026-08-01
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses critical challenges in the management of cybersecurity risk documentation for medical devices, which is typically authored in semi-structured natural language and suffers from poor consistency, low review efficiency, limited reusability, and a lack of unified modeling of safety and cybersecurity risks. To overcome these limitations, the authors propose SECUMAN, an ontology integrated with SHACL constraints, extending the safety-oriented RISKMAN methodology to the cybersecurity domain for the first time. The framework introduces key concepts such as threat scenarios, protection objectives, and attacker profiles, aligning with both the VDE Spec 90025 standard and the RISKMAN ontology. This approach enables semantic structuring of risk documentation, automated completeness validation, and cross-domain interoperability, thereby significantly enhancing document consistency, review efficiency, and the integrated governance of safety and cybersecurity risks.
📝 Abstract
We propose the SECUMAN ontology and shapes for representing and analysing cybersecurity risk-management documentation for medical devices. Cybersecurity risks are increasingly relevant for connected medical devices and may have direct consequences for patient safety. Current risk-management files are often maintained as semi-structured natural language text, which makes consistency checking, certification review, and reuse difficult. SECUMAN provides a formal OWL-based vocabulary for modelling security-risk context, assessment, control measures, and residual-risk evaluation, and uses SHACL constraints to check structural completeness and conformity with the intended documentation model. The ontology is aligned with VDE Spec 90025 and the related RISKMAN ontology and shapes, while extending their safety-oriented approach to concepts relevant to cybersecurity risk documentation such as threat scenarios, protection goals, attacker profiles, exposure levels, assets, and secure design arguments. SECUMAN is intended to support automated first-pass validation, traceability, and integration of cybersecurity and safety risk-management documentation.
Problem

Research questions and friction points this paper is trying to address.

cybersecurity risk management
medical devices
risk documentation
semi-structured text
consistency checking
Innovation

Methods, ideas, or system contributions that make the work stand out.

SECUMAN ontology
SHACL constraints
cybersecurity risk management
medical devices
semantic modeling