Skip to main content

3. Protect/Respond/Recover

1. Compensating Controling Assessment (Detect/Respond)โ€‹

์ œ์กฐ์‚ฌ๋Š” ๊ธฐ๊ธฐ ์„ค๊ณ„ ํ†ต์ œ๋ฅผ ๊ตฌํ˜„ํ•˜๊ณ  ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ณด์™„ํ†ต์ œ๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•จ.
ENThe FDA recommends that manufacturers implement device-based features, i.e. device design controls, as a primary mechanism to mitigate the risk of patient harm.
KRFDA๋Š” ์ œ์กฐ์‚ฌ๊ฐ€ ํ™˜์ž ์œ„ํ•ด(patient harm) ์œ„ํ—˜์„ ์™„ํ™”ํ•˜๊ธฐ ์œ„ํ•œ ์ฃผ์š” ๋ฉ”์ปค๋‹ˆ์ฆ˜์œผ๋กœ ๊ธฐ๊ธฐ ๊ธฐ๋ฐ˜ ๊ธฐ๋Šฅ(device-based features), ์ฆ‰ ๊ธฐ๊ธฐ ์„ค๊ณ„ ํ†ต์ œ(device design controls)๋ฅผ ๊ตฌํ˜„ํ•  ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.
ENManufacturers should assess and provide users with compensating controls such that the risk of patient harm is further mitigated. In total, these efforts represent a defense-in-depth strategy for medical device cybersecurity.
KR์ œ์กฐ์‚ฌ๋Š” ํ™˜์ž ์œ„ํ•ด ์œ„ํ—˜์„ ์ถ”๊ฐ€์ ์œผ๋กœ ์™„ํ™”ํ•  ์ˆ˜ ์žˆ๋„๋ก ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ณด์™„ํ†ต์ œ๋ฅผ ํ‰๊ฐ€ํ•˜๊ณ  ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋ชจ๋“  ๋…ธ๋ ฅ์€ ์˜๋ฃŒ๊ธฐ๊ธฐ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ์— ๋Œ€ํ•œ ์‹ฌ์ธต ๋ฐฉ์–ด(defense-in-depth) ์ „๋žต์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.
ENSection 3 describes recommendations for remediating and reporting identified cybersecurity vulnerabilities, including the development, implementation and user notification concerning fixes.
KR์„น์…˜ 3์—์„œ๋Š” ์‹๋ณ„๋œ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ์œ„ํ—˜๊ฐœ์„  ๋ฐ ๋ณด๊ณ (reporting) ๊ถŒ๊ณ ์‚ฌํ•ญ์„ ์„ค๋ช…ํ•˜๋ฉฐ, ์—ฌ๊ธฐ์—๋Š” ์ˆ˜์ •(fix)์˜ ๊ฐœ๋ฐœ, ๊ตฌํ˜„, ์‚ฌ์šฉ์ž ํ†ต๋ณด๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.
ENManufacturers should also adopt a coordinated vulnerability disclosure policy and practice that includes acknowledging receipt of the vulnerability to the vulnerability submitter within a specified time frame.
KR๋˜ํ•œ ์ œ์กฐ์‚ฌ๋Š” ์ทจ์•ฝ์  ์ œ์ถœ์ž(vulnerability submitter)์—๊ฒŒ ํŠน์ • ๊ธฐ๊ฐ„ ๋‚ด์— ์ทจ์•ฝ์  ์ ‘์ˆ˜(acknowledging receipt)๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ์„ ํฌํ•จํ•œ ์กฐ์ •๋œ ์ทจ์•ฝ์  ๊ณต๊ฐœ(coordinated vulnerability disclosure) ์ •์ฑ…๊ณผ ๊ด€ํ–‰์„ ์ฑ„ํƒํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
ENThe FDA has recognized ISO/IEC 29147:2014: Information Technology โ€“ Security Techniques โ€“ Vulnerability Disclosure that may be a useful resource for manufacturers.
KRFDA๋Š” ์ œ์กฐ์‚ฌ์— ์œ ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ž์›์œผ๋กœ ISO/IEC 29147:2014 ใ€Œ์ •๋ณด๊ธฐ์ˆ  โ€“ ๋ณด์•ˆ ๊ธฐ๋ฒ• โ€“ ์ทจ์•ฝ์  ๊ณต๊ฐœ(Vulnerability Disclosure)ใ€๋ฅผ ์ธ์ •(recognized)ํ–ˆ์Šต๋‹ˆ๋‹ค.