2. Protect/Detect
1. Vulnerablility Characterization and Assessmentβ
μ μ‘°μ¬λ μλ³λ μ·¨μ½μ μ νΉμ±ν(characterize)νκ³ νκ°(assess)ν΄μΌ ν¨.
ENThe FDA recommends that manufacturers characterize and assess identified vulnerabilities because it will provide information that will aid manufacturers to triage remediation activities.KRFDAλ μ μ‘°μ¬κ° μλ³λ μ·¨μ½μ μ νΉμ±ν(characterize)νκ³ νκ°(assess)ν κ²μ κΆμ₯ν©λλ€. μ΄λ μ μ‘°μ¬κ° μνκ°μ νλμ μ°μ μμλ₯Ό μ νλ λ° λμμ΄ λλ μ 보λ₯Ό μ 곡νκΈ° λλ¬Έμ λλ€.
ENWhen characterizing the exploitability of a vulnerability, the manufacturer should consider factors such as remote exploitability, attack complexity, threat privileges, actions required by the user, exploit code maturity, and report confidence.KRμ·¨μ½μ μ μ μ© κ°λ₯μ±(exploitability)μ νΉμ±νν λ, μ μ‘°μ¬λ μ격 μ μ© κ°λ₯μ±(remote exploitability), 곡격 볡μ‘μ±(attack complexity), μν κΆν(threat privileges), μ¬μ©μμκ² μꡬλλ νλ(actions required by the user), μ μ© μ½λ μ±μλ(exploit code maturity), λ³΄κ³ μ λ’°λ(report confidence)μ κ°μ μμλ€μ κ³ λ €ν΄μΌ ν©λλ€.
ENScoring systems such as the βCommon Vulnerability Scoring Systemβ (CVSS) provide a consistent framework for assessing exploitability by quantifying the impact of the factors that influence exploitability.KRβκ³΅ν΅ μ·¨μ½μ μ μ μμ€ν (Common Vulnerability Scoring System, CVSS)βκ³Ό κ°μ μ μ 체κ³(scoring systems)λ μ΄λ¬ν μμλ€μ΄ μ μ© κ°λ₯μ±μ λ―ΈμΉλ μν₯μ μμΉννμ¬ μΌκ΄λ νκ° νλ μμν¬λ₯Ό μ 곡ν©λλ€.
2. Risk Analysis and Threat Modelingβ
μ μ‘°μ¬λ μν λͺ¨λΈλ§μ ν¬ν¨ν μ¬μ΄λ²λ³΄μ μν λΆμμ μννκ³ , TPLC λμ ν΄λΉ λΆμμ μ λ°μ΄νΈν΄μΌ ν¨.
ENThe FDA recommends that manufacturers conduct cybersecurity risk analyses that include threat modeling for each of their devices and to update those analyses over time.KRFDAλ μ μ‘°μ¬κ° κ° κΈ°κΈ°μ λν΄ μν λͺ¨λΈλ§(threat modeling)μ ν¬ν¨ν μ¬μ΄λ²λ³΄μ μν λΆμ(cybersecurity risk analyses)μ μννκ³ , μκ°μ΄ μ§λ¨μ λ°λΌ ν΄λΉ λΆμμ μ λ°μ΄νΈν κ²μ κΆμ₯ν©λλ€.
ENRisk analyses and threat modeling should aim to triage vulnerabilities for timely remediation.KRμν λΆμκ³Ό μν λͺ¨λΈλ§μ μ·¨μ½μ μ μ μν μνμ κ°μ νκΈ° μν΄ μ°μ μμλ₯Ό μ νλ λ° λͺ©μ μ λμ΄μΌ ν©λλ€.
ENThreat modeling is a procedure for optimizing Network/Application/Internet Security by identifying objectives and vulnerabilities, and then defining countermeasures to prevent, or mitigate the effects of, threats to the system.KRμν λͺ¨λΈλ§μ λ€νΈμν¬/μ ν리μΌμ΄μ /μΈν°λ· 보μμ μ΅μ ννκΈ° μν μ μ°¨λ‘, λͺ©ν(objectives)μ μ·¨μ½μ (vulnerabilities)μ μλ³ν λ€ μμ€ν μ λν μν(threats)μ μλ°©νκ±°λ κ·Έ μν₯μ μννκΈ° μν λμμ± (countermeasures)μ μ μνλ κ³Όμ μ λλ€.
ENThreat modeling provides traditional risk management and failure mode analysis paradigms, and a framework to assess threats from active adversaries/malicious use.KRμν λͺ¨λΈλ§μ μ ν΅μ μΈ μν κ΄λ¦¬(risk management)μ κ³ μ₯ λͺ¨λ λΆμ(failure mode analysis) ν¨λ¬λ€μμ μ 곡νλ©°, μ κ·Ήμ μΈ κ³΅κ²©μ(active adversaries)/μ μμ μ¬μ©(malicious use)μΌλ‘λΆν°μ μνμ νκ°νκΈ° μν νλ μμν¬λ₯Ό μ 곡ν©λλ€.
ENFor each vulnerability, a summary report should be produced that concisely summarizes the risk analysis and threat modeling information.KRκ° μ·¨μ½μ μ λν΄μλ μν λΆμκ³Ό μν λͺ¨λΈλ§ μ 보λ₯Ό κ°κ²°νκ² μμ½ν λ³΄κ³ μ(summary report)λ₯Ό μμ±ν΄μΌ ν©λλ€.
ENDue to the cyclical nature of the analyses, the information should be traceable to related documentation.KRμ΄λ¬ν λΆμμ μνμ (cyclical) νΉμ±μ κ°μ§λ―λ‘, κ΄λ ¨ λ¬Έμ(documentation)μ μΆμ κ°λ₯ν΄μΌ ν©λλ€.
3. Analysis of Threat Sourcesβ
μ μ‘°μ¬λ κ°λ₯ν μν μμ²(threat sources)μ λΆμν΄μΌ ν¨.
ENThe FDA recommends manufacturers to analyze possible threat sources.KRFDAλ μ μ‘°μ¬κ° κ°λ₯ν μν μμ²(threat sources)μ λΆμν κ²μ κΆμ₯ν©λλ€.
ENA threat source is defined as the intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability.KRμν μμ²μ μ·¨μ½μ μ μλμ μΌλ‘ μ μ©νκΈ° μν μλ(intent)μ λ°©λ²(method), λλ μ·¨μ½μ μ μ°λ°μ μΌλ‘(trigger accidentally) μ λ°ν μ μλ μν©κ³Ό λ°©λ²μΌλ‘ μ μλ©λλ€.
ENAnalysis of threat sources, as part of risk analysis and threat modeling provides a framework for risk introduced by an active adversary.KRμν μμ² λΆμμ μν λΆμ(risk analysis)κ³Ό μν λͺ¨λΈλ§(threat modeling)μ μΌλΆλ‘μ, μ κ·Ήμ μΈ κ³΅κ²©μ(active adversary)μ μν΄ λ°μνλ μνμ νκ°ν μ μλ νλ μμν¬λ₯Ό μ 곡ν©λλ€.
ENTherefore, characterization of threat sources will be advantageous to manufacturers in accessing risks not covered by traditional failure mode analysis methods.KRλ°λΌμ μν μμ²μ νΉμ±ν(characterization)νλ κ²μ μ ν΅μ μΈ κ³ μ₯ λͺ¨λ λΆμ(failure mode analysis) λ°©λ²μΌλ‘λ λ€λ£¨μ΄μ§μ§ μλ μνμ νκ°νλ λ° μ μ‘°μ¬μ μ 리νκ² μμ©ν κ²μ λλ€.
4. Incorporation of Threat Detection Capabilitiesβ
μ μ‘°μ¬λ 곡격 λ°μ μ κΈ°κΈ°κ° μνμ νμ§νκ³ , λ²μνμ μΌλ‘ νλΉν μ¦κ±° ν보λ₯Ό ν μ μλ μ€κ³ κΈ°λ₯μ ν¬ν¨νλ κ²μ κ³ λ €ν΄μΌ ν¨.
ENMedical devices may not be capable of detecting threat activity and may be reliant on network monitoring.KRμλ£κΈ°κΈ°λ μν νλ(threat activity)μ νμ§ν μ μλ λ₯λ ₯μ΄ μμ μλ μμΌλ©°, λ€νΈμν¬ λͺ¨λν°λ§μ μμ‘΄ν μ μμ΅λλ€.
ENManufacturers should consider the incorporation of design features that establish or enhance the ability of the device to detect and produce forensically sound postmarket evidence capture in the event of an attack. This information may assist the manufacturer in assessing and remediating identified risks.KRμ μ‘°μ¬λ 곡격 λ°μ μ κΈ°κΈ°κ° μνμ νμ§νκ³ , λ²μνμ μΌλ‘ νλΉν(forensically sound) μν ν(postmarket) μ¦κ±° ν보λ₯Ό μνν μ μλ λ₯λ ₯μ ꡬμΆνκ±°λ κ°ννλ μ€κ³ κΈ°λ₯(design features)μ ν¬ν¨νλ κ²μ κ³ λ €ν΄μΌ ν©λλ€.
5. Impact Assessment on All Devicesβ
μ μ‘°μ¬λ μ¬μ΄λ²λ³΄μ μ νΈμ μν₯μ μνμ (μ ν ν¬νΈν΄λ¦¬μ€) κ·Έλ¦¬κ³ μμ§μ (μ ν ꡬμ±μμ)μΌλ‘ νκ°ν μ μλ νλ‘μΈμ€λ₯Ό μ립ν΄μΌ ν¨.
ENThe FDA recommends that manufacturers have a process to assess the impact of a cybersecurity signal horizontally (i.e., across all medical devices within the manufacturerβs product portfolio and sometimes referred to as variant analyses) and vertically (i.e., determine if there is an impact on specific components within the device).KRFDAλ μ μ‘°μ¬κ° μ¬μ΄λ²λ³΄μ μ νΈ(cybersecurity signal)μ μν₯μ μνμ μΌλ‘(μ¦, μ μ‘°μ¬μ μ ν ν¬νΈν΄λ¦¬μ€ λ΄ λͺ¨λ μλ£κΈ°κΈ°μ κ±Έμ³, νν λ³μ΄ λΆμ[variant analyses]μ΄λΌ λΆλ¦Ό) κ·Έλ¦¬κ³ μμ§μ μΌλ‘(μ¦, κΈ°κΈ° λ΄ νΉμ κ΅¬μ± μμμ μν₯μ΄ μλμ§ μ¬λΆλ₯Ό κ²°μ ) νκ°ν μ μλ νλ‘μΈμ€λ₯Ό κ°μΆ κ²μ κΆμ₯ν©λλ€.
ENA signal may identify a vulnerability in one device, and that same vulnerability may impact other devices including those in development, or those not yet cleared, approved or marketed.KRνλμ μ νΈκ° νΉμ κΈ°κΈ°μ μ·¨μ½μ μ μλ³ν μ μμΌλ©°, λμΌν μ·¨μ½μ μ΄ κ°λ° μ€μΈ κΈ°κΈ°λ μμ§ μΉμΈΒ·νκ°Β·νλ§€λμ§ μμ λ€λ₯Έ κΈ°κΈ°μλ μν₯μ λ―ΈμΉ μ μμ΅λλ€.
ENTherefore, it will be advantageous to manufacturers to conduct analyses for cybersecurity signals such that expended detection resources have the widest impact.KRλ°λΌμ μ μ‘°μ¬κ° μ¬μ΄λ²λ³΄μ μ νΈμ λν λΆμμ μννμ¬ νμ§ μμ(detection resources)μ΄ κ°μ₯ λμ λ²μμ μν₯μ λ―ΈμΉλλ‘ νλ κ²μ΄ μ 리ν κ²μ λλ€.