5. Criteria for Defining Active Participation by a Manufacturer in an ISAO
FDA가 제조사의 ISAO 적극 참여를 판단할 때의 고려사항
ENFDA intends to consider the following in determining whether a manufacturer is an active participant in an ISAO:KRFDA는 제조사가 ISAO에 적극적으로 참여하고 있는지 여부를 판단할 때 다음 사항들을 고려할 예정입니다:
FDA가 제조사의 ISAO 적극 참여를 판단할 때의 고려사항
- The manufacturer is a member of an ISAO that shares vulnerabilities and threats that impact medical devices;
- 제조사는 의료기기에 영향을 미치는 취약점과 위협을 공유하는 ISAO의 회원이다.
- The ISAO has documented policies pertaining to participant agreements, business processes, operating procedures, and privacy protections;
- ISAO는 참가자 협약(participant agreements), 비즈니스 프로세스(business processes), 운영 절차(operating procedures), 개인정보 보호(privacy protections)에 관한 문서화된 정책을 보유하고 있다.
- The manufacturer shares vulnerability information with the ISAO, including any customer communications pertaining to cybersecurity vulnerabilities; and
- 제조사는 사이버보안 취약점과 관련된 고객 커뮤니케이션을 포함하여 취약점 정보를 ISAO와 공유한다.
- The manufacturer has documented processes for assessing and responding to vulnerability and threat intelligence information received from the ISAO. This information should be traceable to medical device risk assessments, countermeasure solutions, and mitigations.
- 제조사는 ISAO로부터 받은 취약점과 위협 정보(vulnerability and threat intelligence)를 평가하고 대응하기 위한 문서화된 절차를 보유하고 있으며, 이 정보는 의료기기 위험 평가(risk assessments), 대응책(countermeasure solutions), 및 위험 완화(mitigations)와 추적 가능해야 한다.