Skip to main content

4. Recommended Content to Include in PMA Periodic Reports

정기 보고 요건이 있는 PMA 기기의 경우. 사이버보안 취약점과 기기 변경 및 보완통제에 관한 정보는 FDA에 정기(연간) 보고되어야 합
ENFor PMA devices with periodic reporting requirements under 21 CFR 814.84, information concerning cybersecurity vulnerabilities, and device changes and compensating controls implemented in response to this information should be reported to FDA in a periodic (annual) report.
KR21 CFR 814.84에 따라 정기 보고 요건(periodic reporting requirements)이 있는 PMA 기기의 경우, 사이버보안 취약점과 이에 대응하여 시행된 기기 변경(device changes) 및 보완통제에 관한 정보는 FDA에 정기(연간) 보고서(periodic/annual report)로 보고되어야 합니다.
21 CFR 814.84 Reports
정기 보고에 제공할 정보
정기 보고에 제공할 정보
  • A brief description of the vulnerability prompting the change including how the firm became aware of the vulnerability;
  • 변경을 유발한 취약점에 대한 간략한 설명, 해당 취약점을 회사가 어떻게 인지하게 되었는지 포함
  • A summary of the conclusions of the firm’s risk assessment including whether the risk of patient harm was controlled or uncontrolled;
  • 회사의 위험 평가(risk assessment) 결론 요약, 환자 위해(patient harm) 위험이 통제되었는지 또는 통제되지 않았는지 여부 포함
  • A description of the change(s) made, including a comparison to the previously approved version of the device;
  • 실시된 변경 사항(change)에 대한 설명, 이전에 승인된 기기 버전과의 비교 포함
  • The rationale for making the change;
  • 변경을 수행한 근거(rationale)
  • Reference to other submissions/devices that were modified in response to this same vulnerability;
  • 동일한 취약점에 대응하여 수정된 다른 제출물/기기에 대한 참조(reference)
  • Identification of event(s) related to the rationale/reason for the change (e.g., MDR number(s), recall number);
  • 변경의 근거/사유와 관련된 사건(event) 식별 (예: MDR 번호, 리콜 번호)
  • Unique Device Identification (UDI) should be included, if available;
  • 가능하다면 고유 기기 식별(UDI, Unique Device Identification) 포함
  • A link to an ICS-CERT advisory or other government or ISAO alert (https://ics-cert.us-cert.gov/advisories), if applicable;
  • 적용 가능한 경우 ICS-CERT 권고문(advisory) 또는 기타 정부/ISAO 알림에 대한 링크 (https://ics-cert.us-cert.gov/advisories)
  • All distributed customer notifications;
  • 배포된 모든 고객 통보(customer notifications)
  • The date and name of the ISAO to which the vulnerability was reported, if any; and
  • 취약점이 보고된 ISAO의 날짜 및 이름(있는 경우)
  • Reference to other relevant submission (PMA Supplement, 30-Day Notice, 806 report, etc.), if any, or the scientific and/or regulatory basis for concluding that the change did not require a submission/report.
  • 관련 제출물(PMA 보완, 30일 통보, 806 보고 등)에 대한 참조(있는 경우), 또는 변경이 제출/보고를 필요로 하지 않는다고 결론 지은 과학적·규제적 근거