2. Postmarket Considerations
제조사는 포괄적인 사이버보안 위험 관리 프로그램과 문서화를 구현해야 함. (21 CFR 820)
ENIt is essential that manufacturers implement comprehensive cybersecurity risk management programs and documentation consistent with the Quality System Regulation (21 CFR part 820), including but not limited toKR제조사는 품질 시스템 규정(Quality System Regulation, 21 CFR part 820)에 부합하는 포괄적인 사이버보안 위험 관리 프로그램과 문서화를 반드시 구현해야 합니다. 여기에는 다음이 포함되며, 이에 국한되지 않습니다:
ENcomplaint handling (불만 처리, 21 CFR 820.198),ENquality audit (품질 감사, 21 CFR 820.22),ENcorrective and preventive action (시정 및 예방 조치, 21 CFR 820.100),ENsoftware validation and risk analysis (소프트웨어 밸리데이션 및 위험 분석, 21 CFR 820.30(g)) andENservicing (서비스, 21 CFR 820.200).
사이버보안 위험 관리 프로그램의 핵심 구성 요소
ENCybersecurity risk management programs should emphasize addressing vulnerabilities which may permit the unauthorized access, modification, misuse or denial of use, or the unauthorized use of information that is stored, accessed, or transferred from a medical device to an external recipient, and may result in patient harm. Manufacturers should respond in a timely fashion to address identified vulnerabilities.KR사이버보안 위험 관리 프로그램은 의료기기에서 외부 수신자에게 저장·접근·전송되는 정보가 무단 접근, 수정, 오용, 사용 거부(denial of use), 또는 무단 사용될 수 있는 취약점(vulnerabilities)을 해결하는 데 중점을 두어야 하며, 이는 환자 위해(patient harm)로 이어질 수 있습니다. 제조사는 식별된 취약점을 해결하기 위해 적시에 대응해야 합니다.
위험 관리 프로그램의 핵심 구성 요소
- Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk;
- 사이버보안 정보 출처를 모니터링하여 사이버보안 취약점과 위험을 식별 및 탐지
- Maintaining robust software lifecycle processes that include mechanisms for:
- 견고한 소프트웨어 생애주기 프로세스를 유지, 여기에는 다음과 같은 메커니즘이 포함됨:
- monitoring third party software components for new vulnerabilities throughout the device’s total product lifecycle;
- 장치의 전체 제품 생애주기 동안 서드파티 소프트웨어 구성 요소의 새로운 취약점 모니터링
- design verification and validation for software updates and patches that are used to remediate vulnerabilities, including those related to Off-the-shelf software;
- 취약점을 개선(remediate)하기 위해 사용되는 소프트웨어 업데이트 및 패치에 대한 설계 검증과 밸리데이션, 기성(off-the-shelf) 소프트웨어 관련 항목 포함
- Understanding, assessing and detecting presence and impact of a vulnerability;
- 취약점의 존재와 영향에 대한 이해, 평가 및 탐지
- Establishing and communicating processes for vulnerability intake and handling
- 취약점 접수(intake) 및 처리 프로세스 수립 및 전달
- Note: The FDA has recognized ISO/IEC 30111:2013: Information Technology – Security Techniques – Vulnerability Handling Processes;
- 참고: FDA는 ISO/IEC 30111:2013 (정보기술 – 보안 기법 – 취약점 처리 프로세스)를 인정함
- Using threat modeling to clearly define how to maintain safety and essential performance of a device by developing mitigations that protect, respond and recover from the cybersecurity risk;
- 위협 모델링(threat modeling)을 활용하여 사이버보안 위험으로부터 보호·대응·복구할 수 있는 완화책을 개발하고, 이를 통해 장치의 안전성과 필수 성능을 유지하는 방법을 명확히 정의
- Adopting a coordinated vulnerability disclosure policy and practice. The FDA has recognized ISO/IEC 29147:2014: Information Technology – Security Techniques – Vulnerability Disclosure which may be a useful resource for manufacturers; and
- 통합된 취약점 공개(coordinated vulnerability disclosure) 정책 및 관행 채택. 참고: FDA는 ISO/IEC 29147:2014 (정보기술 – 보안 기법 – 취약점 공개)를 인정하며, 이는 제조사에 유용한 자료가 될 수 있음
- Deploying mitigations that address cybersecurity risk early and prior to exploitation.
- 사이버보안 위험을 악용(exploitation) 이전 단계에서 조기에 해결할 수 있는 완화책 배포
시판 후 사이버보안 정보는 다양한 출처에서 발생할 수 있음.
FDA는 제조사가 취약점과 위협을 공유하는 ISAO에 참여할 것을 권장함.
ENPostmarket cybersecurity information may originate from an array of sources including independent security researchers, in-house testing, suppliers of software or hardware technology, health care facilities, and information sharing and analysis organizations.KR시판 후(postmarket) 사이버보안 정보는 독립적인 보안 연구소, 내부 테스트, 소프트웨어 또는 하드웨어 기술 공급업체, 의료기관, 정보 공유 및 분석 조직(ISAO) 등 다양한 출처에서 발생할 수 있습니다.
ENIt is strongly recommended that manufacturers participate in an ISAO that shares vulnerabilities and threats that impact medical devices.KR제조사는 의료기기에 영향을 미치는 취약점과 위협을 공유하는 ISAO에 참여할 것을 강력히 권장합니다.
ENSharing and dissemination of cybersecurity information and intelligence pertaining to vulnerabilities and threats across multiple sectors is integral to a successful postmarket cybersecurity surveillance program.KR여러 산업 부문에 걸쳐 취약점과 위협에 관한 사이버보안 정보와 분석정보를 공유·전파하는 것은 성공적인 시판 후 사이버보안 감시 프로그램의 핵심 요소입니다.
위험 관리 프로그램의 핵심 구성 요소
- 용어 정의
- ISAO (Information Sharing and Analysis Organization, 정보 공유 및 분석 조직)
- 정부 및 민간 부문 간에 사이버보안 위협 지표, 취약점, 완화 조치(Mitigation) 등 '사이버보안 신호(Cybersecurity Signal)'를 실시간으로 수집하고 공유하기 위해 설립된 커뮤니티 또는 협의체입니다.
- 대표적인 의료/보건 분야 ISAO: H-ISAC (Health Information Sharing and Analysis Center), MedISAO 등.
- ISAO (Information Sharing and Analysis Organization, 정보 공유 및 분석 조직)
- FDA 요구사항: ISAO 참여를 통한 선제적 위협 수집 체계 확립
- 이슈: H-ISAC 등 글로벌 프리미엄 ISAO의 높은 연회비 및 유지 관리 인력 부족
- 대응: [무료/공공 인프라 융합 활용] 유료 멤버십 대신 CISA(미국 사이버보안·인프라 보안국)의 공식 KEV(알려진 악용 취약점) 알림 메일링 구독 및 무료 수준의 MedISAO Basic 멤버십 가입을 통해 '동등한 신호 수집 채널'을 구축함을 명문화.
- FDA 요구사항: 취약점 공개 (CVD - Coordinated Vulnerability Disclosure)
- 이슈: 자사 제품 취약점 발견 시, 자체적으로 언론/고객 대응 시 발생할 평판 리스크 및 법적 부담
- 대응: 사이버보안 관리 계획서에 "당사 기기의 취약점 발견 시 자체 발표 전, ISAO(또는 CISA/CERT)에 우선 보고하여 업계 공동의 완화 조치를 조율(Coordinated)한다"고 명시함.
FDA는 시판 후 사이버보안 관리 프로그램에 NIST 프레임워크의 5가지 핵심 기능(식별, 보호, 탐지, 대응, 복구)을 포함할 것을 권장함.
ENIt is recommended as part of a manufacturer’s cybersecurity risk management program that the manufacturer incorporate elements consistent with the NIST Framework for Improving Critical Infrastructure Cybersecurity (i.e., Identify, Protect, Detect, Respond, and Recover)KR제조사의 사이버보안 위험 관리 프로그램의 일환으로, 제조사가 NIST 「중요 인프라 사이버보안 개선 프레임워크(NIST Framework for Improving Critical Infrastructure Cybersecurity)」와 일관된 요소들을 포함할 것을 권장합니다. (즉, 식별(Identify), 보호(Protect), 탐지(Detect), 대응(Respond), 복구(Recover) 단계)
시판 후 사이버보안 관리 프로그램이 포함해야 할 접근 방법
- Methods to identify, characterize, and assess a cybersecurity vulnerability.
- 사이버보안 취약점을 식별, 특성화(characterize), 평가하는 방법
- Methods to analyze, detect, and assess threat sources. For example:
- 위협 원인을 분석, 탐지, 평가하는 방법
- A cybersecurity vulnerability might impact all of the medical devices in a manufacturer’s portfolio based on how their products are developed; or
- 사이버보안 취약점은 제조사의 제품 개발 방식에 따라 포트폴리오 내 모든 의료기기에 영향을 미칠 수 있음
- A cybersecurity vulnerability could exist vertically (i.e., within the components of a device) which can be introduced at any point in the supply chain for a medical device manufacturing process.
- 사이버보안 취약점은 수직적으로(즉, 장치의 구성 요소 내에서) 존재할 수 있으며, 이는 의료기기 제조 과정의 공급망(supply chain) 어느 지점에서든 도입될 수 있습니다.