Skip to main content

1. General Principles

FDA는 사이버보안을 이해관계자들이 공동으로 책임져야 하는 영역으로 인식하고 있음.
ENFDA recognizes that medical device cybersecurity is a shared responsibility among stakeholders including health care facilities, patients, providers, and manufacturers of medical devices.
KRFDA는 의료기기 사이버보안이 의료기관, 환자, 의료 제공자, 의료기기 제조사 등 이해관계자들이 공동으로 책임져야 하는 영역임을 인식하고 있습니다.
ENFailure to maintain cybersecurity can result in compromised device functionality, loss of data (medical or personal) availability or integrity, or exposure of other connected devices or networks to security threats.
KR사이버보안을 유지하지 못하면 의료기기의 기능 저하, 데이터(의료 또는 개인)의 가용성이나 무결성 손실, 또는 다른 연결된 장치나 네트워크가 보안 위협에 노출될 수 있습니다.
ENThis in turn may have the potential to result in patient illness, injury or death.
KR이는 결국 환자의 질병, 부상, 또는 사망으로 이어질 잠재성을 가질 수 있습니다.
FDA는 사이버보안에 NIST 프레임워크의 5가지 핵심 기능(식별, 보호, 탐지, 대응, 복구)을 적용할 것을 권장함.
사이버보안 취약점 및 관리 요소
  • Identification of assets, threats, and vulnerabilities;
  • 자산, 위협, 취약점의 식별
  • Assessment of the impact of threats and vulnerabilities on device functionality and end users/patients;
  • 위협과 취약점이 의료기기 기능 및 최종 사용자/환자에게 미치는 영향 평가
  • Assessment of the likelihood of a threat and of a vulnerability being exploited;
  • 위협과 취약점이 악용될 가능성 평가
  • Determination of risk levels and suitable mitigation strategies;
  • 위험 수준 결정 및 적절한 완화 전략 수립
  • Assessment of residual risk and risk acceptance criteria.
  • 잔여 위험(residual risk) 및 위험 수용 기준 평가