This work was divided into 3 phases, to allow
Cerebra to manage the project, and to define the
scope of future phases:
In Phase 1, Aversan conducted an audit on the Cerebra
Prodigy 2 Sleep System DHF against IEC 62304:
20151 and the FDA’s guidance for Cybersecurity in
Medical Devices2,3 documenting findings,
observations and recommendations for remediation.
Based upon the Phase 1 findings, Aversan was
awarded Phase 2 of this project, to provide
assistance in remediating the findings from the
audit. Cerebra chose to engage in several solutions
to expedite their remediations. Leveraging Aversan’s
resource talents, staff augmentation was utilized by
Cerbra to address documentation gaps and internal
improvements.
In addition, Cerebra engaged Aversan on an
additional phase to expand their test evidence,
specifically targeting Cybersecurity requirements
such as threat modelling and penetration testing of
the Cerebra Sleep System.
The project schedule was aggressive with durations
of 4 and 8 weeks for Phase 1 and Phase 2,
respectively. Aversan staffed the team with the
required technical resources to support the project
schedule needs. The team worked independently on
both phases of the project and solicited input
from the Cerebra team when necessary. The
Aversan team completed the project deliverables
on-time as per the original plan although the
customer extended the schedule to complete their
Phase 2 activities. The customer accepted the audit
and penetration test reports and the drafts of the
supporting documents with minimal comments.