3. Remediating and Reporting Cybersecurity Vulnerabilities
제조사는 이미 구현된 보완 통제(compensating controls)와 위험 완화 조치(risk mitigations)를 위험 평가에 포함시켜야 함.
ENWhen determining how to manage a cybersecurity vulnerability, manufacturers should incorporate already implemented compensating controls and risk mitigations into their risk assessment.KR사이버보안 취약점을 관리하는 방법을 결정할 때, 제조사는 이미 구현된 보완통제와 위험 완화 조치(risk mitigations)를 위험 평가에 포함시켜야 합니다.
제조사는 시판 중인 의료기기에 대해 효율적이고, 시의적절하며, 지속적인 사이버보안 위험 관리를 수행해야 함.
시판 후 사이버보안 위험 관리
- Cybersecurity routine updates and patches. the FDA will, typically, not need to conduct premarket review to clear or approve the medical device software changes.
- 사이버보안의 정기 업데이트 와 패치 (routine updates and patches). FDA는 일반적으로 의료기기 소프트웨어 변경을 승인하거나 허가하기 위한 시판 전 심사(premarket review)를 수행할 필요가 없습니다
- Adopt a coordinated vulnerability disclosure policy and practice that includes acknowledging receipt of the initial vulnerability report to the vulnerability submitter
- 취약점 제출자(vulnerability submitter)에게 초기 취약점 보고서를 접수했음을 확인하는 절차를 포함한, 조율된 취약점 공개 정책(coordinated vulnerability disclosure policy)과 실행 관행을 채택할 것
- Proactively practice good cyber hygiene, reassess risk assessments regularly, and seek opportunities to reduce cybersecurity risks even when residual risk is acceptable;
- 선제적으로 사이버 위생(cyber hygiene)을 실천하고, 위험 평가(risk assessment)를 정기적으로 재검토하며, 잔여 위험(residual risk)이 허용 가능한 수준이라 하더라도 사이버보안 위험을 줄일 기회를 모색할 것
- Remediate cybersecurity vulnerabilities to reduce the risk of patient harm to an acceptable level;
- 사이버보안 취약점을 개선(remediate)하여 환자 위해(patient harm)의 위험을 허용 가능한 수준으로 낮출 것
- Conduct appropriate software validation under 21 CFR 820.30(g) to assure that any implemented remediation effectively mitigates the target vulnerability without unintentionally creating exposure to other risks;
- 21 CFR 820.30(g)에 따라 적절한 소프트웨어 벨리데이션을 수행하여, 구현된 위험개선이 목표 취약점을 효과적으로 완화하면서 다른 위험에 대한 노출을 의도치 않게 발생시키지 않도록 보장할 것
- Properly document the methods and controls used in the design, manufacture, packaging, labeling, storage, installation and servicing of all finished devices as required by 21 CFR part 820;
- 21 CFR part 820에서 요구하는 바에 따라, 모든 완제품 의료기기의 설계, 제조, 포장, 라벨링, 저장, 설치 및 서비스 과정에서 사용된 방법과 통제를 적절히 문서화할 것
- Identify and implement compensating controls to adequately mitigate the cybersecurity vulnerability risk, especially when new device design controls 33 may not be feasible or immediately practicable. In addition, manufacturers should consider the level of knowledge and expertise needed to properly implement the recommended control;
- 새로운 기기 설계 통제가 실행 불가능하거나 즉시 적용하기 어려운 경우에도, 사이버보안 취약점 위험을 충분히 완화하기 위해 보완통제를 식별하고 구현할 것. 또한, 권장되는 통제를 적절히 구현하기 위해 필요한 지식과 전문성을 고려할 것
- Provide users with relevant information on recommended device and compensating controls and residual cybersecurity risks so that they can take appropriate steps to mitigate the risk and make informed decisions regarding device use; and
- 사용자가 위험을 완화하고 기기 사용에 대해 정보에 입각한 결정을 내릴 수 있도록, 권장되는 기기 통제 및 보완통제, 그리고 잔여 사이버보안 위험에 관한 관련 정보를 제공할 것
- Recognize that some changes made to strengthen device security might also significantly affect other device functionality (e.g., use of a different operating system) and assess the scope of change to determine if additional premarket or postmarket regulatory actions are appropriate.
- 기기 보안을 강화하기 위해 이루어진 일부 변경 사항은 다른 기기 기능(예: 다른 운영체제 사용)에 상당한 영향을 미칠 수 있음을 인식하고, 변경 범위를 평가하여 추가적인 시판 전(premarket) 또는 시판 후(postmarket) 규제 조치가 적절한지 여부를 결정할 것