Skip to main content

4. Risk Mitigation of Safety and Essential Performance

제조사는 환자 위해 위험이 보안 통제에 의해 통제되고 있는지 평가해야 함.
ENOnce the preceding information has been assessed and characterized, manufacturers should determine if the risk of patient harm presented by the vulnerability are adequately controlled by existing device features and/or manufacturer defined compensating controls (i.e., residual risk levels are acceptable).
KR앞서 언급된 정보가 평가되고 특성화된 후, 제조사는 취약점으로 인해 발생할 수 있는 환자 위해(patient harm) 위험이 기존 기기 기능(device features) 및/또는 제조사가 정의한 보완통제에 의해 충분히 통제되고 있는지(즉, 잔여 위험 수준이 허용 가능한지) 여부를 결정해야 합니다.
ENActions taken should reflect the magnitude of the problem and align with the risks encountered.
KR취해지는 조치는 문제의 심각성(magnitude of the problem)을 반영하고 직면한 위험(risks encountered)에 부합해야 합니다.
ENManufacturers should also include an evaluation of residual risk, benefit/risk, and risk introduced by the remediation.
KR또한 제조사는 잔여 위험(residual risk), 이익/위험(benefit/risk), 그리고 위험개선으로 인해 새롭게 발생하는 위험을 평가에 포함해야 합니다.
ENManufacturers should design their devices to ensure that risks inherent in remediation are properly mitigated including ensuring that the remediation is adequate and validated, that the device designs incorporate mechanisms for secure and timely updates.
KR제조사는 위험개선 과정에서 내재된 위험이 적절히 완화되도록 기기를 설계해야 하며, 위험개선이 충분하고 검증되었는지 확인하고, 기기 설계에 안전하고 신속한 업데이트를 위한 메커니즘을 포함해야 합니다.
통제된 위험에 해당하는 취약점에 대해 이루어진 변경은 일반적으로 리콜(recall)이 아닌 의료기기 기능향상으로 간주함.
ENChanges made for vulnerabilities of controlled risk are generally considered device enhancements, not recalls.
KR통제된 위험(controlled risk)에 해당하는 취약점에 대해 이루어진 변경은 일반적으로 리콜(recall)이 아닌 의료기기 기능향상으로 간주됩니다.
ENCybersecurity routine updates and patches are generally considered a type of device enhancement.
KR사이버보안 정기 업데이트(routine updates)와 패치(patches)는 일반적으로 의료기기 기능향상의 한 유형으로 간주됩니다.