1. Identify
1. Maintaining Safety and Essential Performanceβ
μ μ‘°μ¬λ κΈ°κΈ°μ μμ μ±κ³Ό νμ μ±λ₯, μμ μ λ°μν νμ μν΄μ μ¬κ°λ, κ·Έλ¦¬κ³ μν μμ© κΈ°μ€μ μ μν΄μΌ ν¨.
ENManufacturers should define, as part of their comprehensive cybersecurity risk management plan, the safety and essential performance of their device, the resulting severity of patient harm if compromised, and the risk acceptance criteria.KRμ μ‘°μ¬λ ν¬κ΄μ μΈ μ¬μ΄λ²λ³΄μ μν κ΄λ¦¬ κ³ν(comprehensive cybersecurity risk management plan)μ μΌνμΌλ‘, κΈ°κΈ°μ μμ μ±κ³Ό νμ μ±λ₯, μμ μ λ°μν νμ μν΄μ μ¬κ°λ(severity), κ·Έλ¦¬κ³ μν μμ© κΈ°μ€(risk acceptance criteria)μ μ μν΄μΌ ν©λλ€.
ENThese steps allow manufacturers to triage vulnerabilities for remediation.KRμ΄λ¬ν λ¨κ³λ μ μ‘°μ¬κ° μ·¨μ½μ μ μνμ κ°μ νκΈ° μν μ°μ μμλ₯Ό μ νλ κ²μ κ°λ₯νκ² ν©λλ€.
μν λͺ¨λΈλ§μ κΈ°κΈ° μ·¨μ½μ μ μ μ© κ°λ₯μ±κ³Ό νμ μν΄ κ°λ₯μ±μ μ΄ν΄νκ³ νκ°νλ λ° μμ΄ μ€μν¨.
ENThreat modeling is important to understanding and assessing the exploitability of a device vulnerability and its potential for patient harm.KRμν λͺ¨λΈλ§(threat modeling)μ κΈ°κΈ° μ·¨μ½μ μ μ μ© κ°λ₯μ±(exploitability)κ³Ό νμ μν΄ κ°λ₯μ±μ μ΄ν΄νκ³ νκ°νλ λ° μ€μν©λλ€.
ENThreat modeling can also be used in determining whether a proposed or implemented remediation can provide assurance that the risk of patient harm due to a cybersecurity vulnerability is reasonably controlled.KRλν μν λͺ¨λΈλ§μ μ μλκ±°λ μνλ μνκ°μ μ΄ μ¬μ΄λ²λ³΄μ μ·¨μ½μ μΌλ‘ μΈν νμ μν΄ μνμ΄ ν©λ¦¬μ μΌλ‘ ν΅μ λκ³ μμμ 보μ₯ν μ μλμ§ νλ¨νλ λ°μλ μ¬μ©λ μ μμ΅λλ€.
ENImportantly, acceptable mitigations will vary depending upon the severity of patient harm that may result from exploitation of a vulnerability affecting the device.KRμ€μν μ μ, νμ© κ°λ₯ν μν μ‘°μΉ(acceptable mitigations)λ μ·¨μ½μ μ΄ μ μ©λ κ²½μ° λ°μν νμ μν΄μ μ¬κ°λμ λ°λΌ λ¬λΌμ§λ€λ κ²μ λλ€.
2. Idenitification of Cybersecurity Signalsβ
λΆλ§, λ°ν, μλΉμ€ κΈ°λ‘, κΈ°ν νμ§ λ°μ΄ν°μ μΆμ²λ₯Ό λΆμνμ¬ λΆμ ν© μ νμ΄λ κΈ°ν νμ§ λ¬Έμ μ κΈ°μ‘΄ λ° μ μ¬μ μμΈμ μλ³ν΄μΌ ν¨(21 CFR 820.100).
ENManufacturers are required to analyze complaints, returned product, service records, and other sources of quality data to identify existing and potential causes of nonconforming product or other quality problems (21 CFR 820.100).KRμ μ‘°μ¬λ λΆλ§(complaints), λ°νλ μ ν(returned product), μλΉμ€ κΈ°λ‘(service records), κΈ°ν νμ§ λ°μ΄ν°μ μΆμ²λ₯Ό λΆμνμ¬ λΆμ ν©(nonconforming) μ νμ΄λ κΈ°ν νμ§ λ¬Έμ μ κΈ°μ‘΄ λ° μ μ¬μ μμΈμ μλ³ν΄μΌ ν©λλ€(21 CFR 820.100).
ENManufacturers are encouraged to actively identify cybersecurity signals that might affect their product, and engage with the sources that report them.KRμ μ‘°μ¬λ μμ¬ μ νμ μν₯μ λ―ΈμΉ μ μλ μ¬μ΄λ²λ³΄μ μ νΈ(cybersecurity signals)λ₯Ό μ κ·Ήμ μΌλ‘ μλ³νκ³ μ΄λ₯Ό λ³΄κ³ νλ μΆμ²μ νλ ₯ν κ²μ κΆμ₯ν©λλ€.
ENIt is important to recognize that signals can originate from sources familiar to the medical device workspace such as internal investigations, post market surveillance and or/complaints.KRμ νΈλ λ΄λΆ μ‘°μ¬(internal investigations), μν ν κ°μ(post market surveillance), λΆλ§ λ± μλ£κΈ°κΈ° λΆμΌμμ μ΅μν μΆμ²μμ λ°μν μ μμμ μΈμνλ κ²μ΄ μ€μν©λλ€.
ENIt is also important to recognize that cybersecurity signals may originate from cybersecurity-centric sources such as Cyber Emergency Response Teams (CERTS), ISAOs, security researchers, or from other critical infrastructure sectors such as the Defense or Financial Sectors.KRλν μ¬μ΄λ²λ³΄μ μ νΈλ μ¬μ΄λ² λΉμ λμν(CERTS), ISAO, 보μ μ°κ΅¬μ(security researchers), κ΅λ°©(Defense)μ΄λ κΈμ΅(Financial)κ³Ό κ°μ λ€λ₯Έ μ€μ μΈνλΌ λΆλ¬Έμμ λ°μν μ μμμ μΈμνλ κ²λ μ€μν©λλ€.
ENIrrespective of the originating source, a clear, consistent and reproducible process for intake and handling of vulnerability information should be established and implemented by the manufacturer.KRμΆμ²μ κ΄κ³μμ΄, μ μ‘°μ¬λ μ·¨μ½μ μ 보(vulnerability information)μ μ μ(intake) λ° μ²λ¦¬(handing)λ₯Ό μν λͺ ννκ³ μΌκ΄λλ©° μ¬ν κ°λ₯ν νλ‘μΈμ€λ₯Ό μ립νκ³ μ€νν΄μΌ ν©λλ€.
ENFDA has recognized ISO/IEC 29147:2014, Information Technology - Security Techniques - Vulnerability Disclosure and ISO/IEC 30111:2013: Information Technology β Security Techniques β Vulnerability Handling Processes that may be useful resources for manufacturers.KRFDAλ μ μ‘°μ¬μ μ μ©ν μ μλ μμμΌλ‘ ISO/IEC 29147:2014 γμ 보기μ β 보μ κΈ°λ² β μ·¨μ½μ 곡κ°(Vulnerability Disclosure)γμ ISO/IEC 30111:2013 γμ 보기μ β 보μ κΈ°λ² β μ·¨μ½μ μ²λ¦¬ νλ‘μΈμ€(Vulnerability Handling Processes)γλ₯Ό μΈμ (recognized)νμ΅λλ€.
ENManufacturers should develop strategies to enhance their ability to detect signals (e.g., participating in an ISAO for medical devices).KRμ μ‘°μ¬λ μ νΈ νμ§ λ₯λ ₯μ ν₯μμν€κΈ° μν μ λ΅μ κ°λ°ν΄μΌ ν©λλ€ (μ: μλ£κΈ°κΈ°μ© ISAO μ°Έμ¬).
ENManufacturers can also enhance their postmarket detection of cybersecurity risks by incorporating detection mechanisms into their device design and device features to increase the detectability of attacks and permit forensically sound evidence capture.KRλν κΈ°κΈ° μ€κ³ λ° κΈ°κΈ° κΈ°λ₯μ νμ§ λ©μ»€λμ¦μ ν΅ν©νκ³ λ²μνμ μΌλ‘ νλΉν(forensically sound) μ¦κ±° ν보λ₯Ό κ°λ₯νκ² ν¨μΌλ‘μ¨ μν ν(postmarket) μ¬μ΄λ²λ³΄μ μν νμ§λ₯Ό κ°νν μ μμ΅λλ€.