ENThe following figure is an example matrix that shows a possible approach to evaluate the relationship between exploitability and patient harm.
KR다음 그림은 악용 가능성(exploitability)과 환자 위해(patient harm) 간의 관계를 평가하는 하나의 접근 방법을 보여주는 예시 매트릭스(matrix)입니다.
ENIt can be used to assess the risk of patient harm from a cybersecurity vulnerability as controlled or uncontrolled.
KR이 매트릭스는 사이버보안 취약점으로 인한 환자 위해 위험을 통제됨(controlled) 또는 통제되지 않음(uncontrolled)으로 평가하는 데 활용될 수 있습니다.
ENWhile in some cases the evaluation will yield a definite determination that the situation is controlled or uncontrolled, it is possible that in other situations this determination may not be as distinct. Nevertheless, in all cases, FDA recommends that manufacturers make a binary determination that a vulnerability is either controlled or uncontrolled using an established process that is tailored to the product, its safety and essential performance, and the situation.
KR일부 경우에는 평가 결과가 상황이 통제되었는지 또는 통제되지 않았는지를 명확히 보여줄 수 있지만, 다른 경우에는 이러한 판단이 그만큼 뚜렷하지 않을 수도 있습니다. 그럼에도 불구하고, 모든 경우에 FDA는 제조사가 제품, 그 안전성과 필수 성능, 그리고 상황에 맞게 구축된 프로세스를 사용하여 취약점이 통제되었는지 또는 통제되지 않았는지를 이진(binary) 방식으로 결정할 것을 권장합니다.
ENRisk mitigations, including compensating controls, should be implemented when necessary to bring the residual risk to an acceptable level.
KR또한, 보완통제를 포함한 위험 완화 조치(risk mitigations)는 필요한 때에 잔여 위험(residual risk)을 허용 가능한 수준으로 낮추기 위해 구현되어야 합니다.
ENEvaluation of Risk of Patient Harm