Skip to main content

2. Medical Device Cybersecurity Risk Management

제조사는 위험 관리 프르세스를 정의하고 문서화해야 함.
프로세스는 위험 분석, 위험 평가, 위험 통제, 생산 및 생산 후 정보의 통합을 포함해야 함.
ENAs part of their risk management process consistent with 21 CFR part 820, a manufacturer should establish, document, and maintain throughout the medical device lifecycle an ongoing process for
KR21 CFR part 820에 부합하는 위험 관리 프로세스의 일환으로, 제조사는 의료기기 생애주기 전반에 걸쳐
ENidentifying hazards associated with the cybersecurity of a medical device, estimating and evaluating the associated risks, controlling these risks, and monitoring the effectiveness of the controls.
KR사이버보안과 관련된 위해요인을 식별하고, 관련 위험을 추정·평가하며, 이러한 위험을 통제하고, 통제의 효과성을 모니터링하는 지속적인 프로세스를 수립·문서화·유지해야 합니다.
ENThis process should include risk analysis, risk evaluation, risk control, and incorporation of production and post-production information.
KR이 프로세스에는 위험 분석(risk analysis), 위험 평가(risk evaluation), 위험 통제(risk control), 생산 및 생산 후 정보의 통합을 포함해야 합니다.
ENElements identified in the Appendix of this guidance should be included as part of the manufacturer’s cybersecurity risk management program to support an effective risk management process.
KR또한, 본 지침의 부록(Appendix)에 명시된 요소(식별, 보호, 탐지, 대응, 복구)들은 효과적인 위험 관리 프로세스를 지원하기 위해 제조사의 사이버보안 위험 관리 프로그램에 포함되어야 합니다.
ENManufacturers should have a defined process to systematically conduct a risk evaluation and determine whether a cybersecurity vulnerability affecting a medical device presents an acceptable or unacceptable risk.
KR제조사는 체계적으로 위험 평가를 수행하고, 의료기기에 영향을 미치는 사이버보안 취약점이 허용 가능한 위험인지 또는 허용 불가능한 위험인지를 결정하기 위한 명확한 프로세스를 가져야 합니다.
ENFDA recommends that manufacturers define and document their process for objectively assessing the cybersecurity risk for their device(s).
KRFDA는 제조사가 자사 기기에 대한 사이버보안 위험을 객관적으로 평가하기 위한 프로세스를 정의하고 문서화할 것을 권장합니다.