Skip to main content

1. Premarket Considerations

사이버보안 취약점 및 관리 요소.
ENManufacturers should establish design inputs for their device related to cybersecurity, and establish a cybersecurity vulnerability and management approach as part of the software validation and risk analysis that is required by 21 CFR 820.30(g). The approach should appropriately address the following elements:
KR제조사는 사이버보안과 관련된 설계 입력(design inputs)을 기기에 설정해야 하며, 21 CFR 820.30(g)에 의해 요구되는 소프트웨어 밸리데이션 및 위험 분석(risk analysis)의 일환으로 사이버보안 취약점 및 관리 접근법을 수립해야 합니다. 이 접근법은 다음 요소들을 적절히 다루어야 합니다:
사이버보안 취약점 및 관리 요소
  • Identification of assets, threats, and vulnerabilities;
  • 자산, 위협, 취약점의 식별
  • Assessment of the impact of threats and vulnerabilities on device functionality and end users/patients;
  • 위협과 취약점이 의료기기 기능 및 최종 사용자/환자에게 미치는 영향 평가
  • Assessment of the likelihood of a threat and of a vulnerability being exploited;
  • 위협과 취약점이 악용될 가능성 평가
  • Determination of risk levels and suitable mitigation strategies;
  • 위험 수준 결정 및 적절한 완화 전략 수립
  • Assessment of residual risk and risk acceptance criteria.
  • 잔여 위험(residual risk) 및 위험 수용 기준 평가
21 CFR 820.30 Design controls