Skip to main content

3. Evaluation of Risk of Patient Harm

악용 가능성과 환자 위해 심각도의 조합으로 환자 위해 위험을 평가함. (Controlled or Uncontrolled)
ENA key purpose of conducting the cyber-vulnerability risk assessment is to evaluate whether the risk of patient harm is controlled (acceptable) or uncontrolled (unacceptable).
KR사이버보안 취약점 위험 평가를 수행하는 주요 목적은 환자 위해(patient harm)의 위험이 통제됨(허용 가능, acceptable)인지, 통제되지 않음(허용 불가능, unacceptable)인지를 평가하는 것입니다.
ENOne method of assessing the acceptability of risk involves using a matrix with combinations of “exploitability” and “severity of patient harm” to determine whether the risk of patient harm is controlled or uncontrolled.
KR위험의 허용 가능성을 평가하는 한 가지 방법은 “악용 가능성(exploitability)”과 “환자 위해의 심각도(severity of patient harm)”의 조합을 활용한 매트릭스(matrix)를 사용하여 환자 위해 위험이 통제되었는지 여부를 결정하는 것입니다.
ENA manufacturer can then conduct assessments of the exploitability and severity of patient harm and then use such a matrix to assess the risk of patient harm for the identified cybersecurity vulnerabilities.
KR제조사는 악용 가능성과 환자 위해의 심각도를 평가한 후, 이러한 매트릭스를 활용하여 식별된 사이버보안 취약점에 대한 환자 위해 위험을 평가할 수 있습니다.
통제되지 않은 위험은 추가적인 위험개선을 해야 함.
ENFor risks that remain uncontrolled, additional remediation should be implemented.
KR통제되지 않은 상태로 남아 있는 위험에 대해서는 추가적인 위험개선을 시행해야 합니다.
환자 위해 위험 평가 예시.
ENThe following figure is an example matrix that shows a possible approach to evaluate the relationship between exploitability and patient harm.
KR다음 그림은 악용 가능성(exploitability)과 환자 위해(patient harm) 간의 관계를 평가하는 하나의 접근 방법을 보여주는 예시 매트릭스(matrix)입니다.
ENIt can be used to assess the risk of patient harm from a cybersecurity vulnerability as controlled or uncontrolled.
KR이 매트릭스는 사이버보안 취약점으로 인한 환자 위해 위험을 통제됨(controlled) 또는 통제되지 않음(uncontrolled)으로 평가하는 데 활용될 수 있습니다.
ENWhile in some cases the evaluation will yield a definite determination that the situation is controlled or uncontrolled, it is possible that in other situations this determination may not be as distinct. Nevertheless, in all cases, FDA recommends that manufacturers make a binary determination that a vulnerability is either controlled or uncontrolled using an established process that is tailored to the product, its safety and essential performance, and the situation.
KR일부 경우에는 평가 결과가 상황이 통제되었는지 또는 통제되지 않았는지를 명확히 보여줄 수 있지만, 다른 경우에는 이러한 판단이 그만큼 뚜렷하지 않을 수도 있습니다. 그럼에도 불구하고, 모든 경우에 FDA는 제조사가 제품, 그 안전성과 필수 성능, 그리고 상황에 맞게 구축된 프로세스를 사용하여 취약점이 통제되었는지 또는 통제되지 않았는지를 이진(binary) 방식으로 결정할 것을 권장합니다.
ENRisk mitigations, including compensating controls, should be implemented when necessary to bring the residual risk to an acceptable level.
KR또한, 보완통제를 포함한 위험 완화 조치(risk mitigations)는 필요한 때에 잔여 위험(residual risk)을 허용 가능한 수준으로 낮추기 위해 구현되어야 합니다.

ENEvaluation of Risk of Patient Harm
Evaluation of Risk of Patient Harm