Skip to main content

3. Maintaining Safety and Essential Performance

제조사는 포괄적인 사이버보안 위험 관리의 일환으로 의료기기의 안전성과 필수 성능을 정의하고 환자 위해의 심각도 및 위험 수용 기준을 설정해야 함.
ENManufacturers should define, as part of the comprehensive cybersecurity risk management, the safety and essential performance of their device, the resulting severity of patient harm if compromised, and the risk acceptance criteria. These steps allow manufacturers to triage vulnerabilities for remediation.
KR제조사는 포괄적인 사이버보안 위험 관리의 일환으로, 자사 의료기기의 안전성(safety)과 필수 성능(essential performance)을 정의하고, 그것이 손상될 경우 발생할 수 있는 환자 위해(patient harm)의 심각도(severity) 및 위험 수용 기준(risk acceptance criteria)을 설정해야 합니다. 이러한 단계들은 제조사가 취약점을 분류(triage)하여 위험개선할 수 있도록 합니다.
위협 모델링은 취약점의 악용 가능성과 환자 위해의 가능성을 이해하고 평가하는데 있어 중요함.
ENThreat modeling is important in understanding and assessing the exploitability of a device vulnerability and potential for patient harm.
KR위협 모델링(threat modeling)은 의료기기 취약점의 악용 가능성(exploitability)과 환자 위해(patient harm) 가능성을 이해하고 평가하는 데 중요합니다.
ENThreat modeling can also be used in determining whether a proposed or implemented remediation can provide assurance that the risk of patient harm due to a cybersecurity vulnerability is reasonably controlled.
KR위협 모델링은 또한 제안되거나 구현된 위험개선이 사이버보안 취약점으로 인한 환자 위해 위험을 합리적으로 통제할 수 있다는 보증(assurance)을 제공할 수 있는지를 결정하는 데 활용될 수 있습니다.
ENImportantly, acceptable mitigations will vary depending upon the severity of patient harm that may result from exploitation of a vulnerability affecting the device.
KR중요하게도, 허용 가능한 완화책(acceptable mitigations)은 취약점이 악용될 경우 발생할 수 있는 환자 위해의 심각도(severity)에 따라 달라집니다.