3. Protect/Respond/Recover
1. Compensating Controling Assessment (Detect/Respond)โ
์ ์กฐ์ฌ๋ ๊ธฐ๊ธฐ ์ค๊ณ ํต์ ๋ฅผ ๊ตฌํํ๊ณ ์ฌ์ฉ์์๊ฒ ๋ณด์ํต์ ๋ฅผ ์ ๊ณตํด์ผ ํจ.
ENThe FDA recommends that manufacturers implement device-based features, i.e. device design controls, as a primary mechanism to mitigate the risk of patient harm.KRFDA๋ ์ ์กฐ์ฌ๊ฐ ํ์ ์ํด(patient harm) ์ํ์ ์ํํ๊ธฐ ์ํ ์ฃผ์ ๋ฉ์ปค๋์ฆ์ผ๋ก ๊ธฐ๊ธฐ ๊ธฐ๋ฐ ๊ธฐ๋ฅ(device-based features), ์ฆ ๊ธฐ๊ธฐ ์ค๊ณ ํต์ (device design controls)๋ฅผ ๊ตฌํํ ๊ฒ์ ๊ถ์ฅํฉ๋๋ค.
ENManufacturers should assess and provide users with compensating controls such that the risk of patient harm is further mitigated. In total, these efforts represent a defense-in-depth strategy for medical device cybersecurity.KR์ ์กฐ์ฌ๋ ํ์ ์ํด ์ํ์ ์ถ๊ฐ์ ์ผ๋ก ์ํํ ์ ์๋๋ก ์ฌ์ฉ์์๊ฒ ๋ณด์ํต์ ๋ฅผ ํ๊ฐํ๊ณ ์ ๊ณตํด์ผ ํฉ๋๋ค. ์ด๋ฌํ ๋ชจ๋ ๋ ธ๋ ฅ์ ์๋ฃ๊ธฐ๊ธฐ ์ฌ์ด๋ฒ๋ณด์์ ๋ํ ์ฌ์ธต ๋ฐฉ์ด(defense-in-depth) ์ ๋ต์ ์๋ฏธํฉ๋๋ค.
ENSection 3 describes recommendations for remediating and reporting identified cybersecurity vulnerabilities, including the development, implementation and user notification concerning fixes.KR์น์ 3์์๋ ์๋ณ๋ ์ฌ์ด๋ฒ๋ณด์ ์ทจ์ฝ์ ์ ๋ํ ์ํ๊ฐ์ ๋ฐ ๋ณด๊ณ (reporting) ๊ถ๊ณ ์ฌํญ์ ์ค๋ช ํ๋ฉฐ, ์ฌ๊ธฐ์๋ ์์ (fix)์ ๊ฐ๋ฐ, ๊ตฌํ, ์ฌ์ฉ์ ํต๋ณด๊ฐ ํฌํจ๋ฉ๋๋ค.
ENManufacturers should also adopt a coordinated vulnerability disclosure policy and practice that includes acknowledging receipt of the vulnerability to the vulnerability submitter within a specified time frame.KR๋ํ ์ ์กฐ์ฌ๋ ์ทจ์ฝ์ ์ ์ถ์(vulnerability submitter)์๊ฒ ํน์ ๊ธฐ๊ฐ ๋ด์ ์ทจ์ฝ์ ์ ์(acknowledging receipt)๋ฅผ ํ์ธํ๋ ๊ฒ์ ํฌํจํ ์กฐ์ ๋ ์ทจ์ฝ์ ๊ณต๊ฐ(coordinated vulnerability disclosure) ์ ์ฑ ๊ณผ ๊ดํ์ ์ฑํํด์ผ ํฉ๋๋ค.
ENThe FDA has recognized ISO/IEC 29147:2014: Information Technology โ Security Techniques โ Vulnerability Disclosure that may be a useful resource for manufacturers.KRFDA๋ ์ ์กฐ์ฌ์ ์ ์ฉํ ์ ์๋ ์์์ผ๋ก ISO/IEC 29147:2014 ใ์ ๋ณด๊ธฐ์ โ ๋ณด์ ๊ธฐ๋ฒ โ ์ทจ์ฝ์ ๊ณต๊ฐ(Vulnerability Disclosure)ใ๋ฅผ ์ธ์ (recognized)ํ์ต๋๋ค.