Skip to main content

1. Controlled Risk of Patient Harm

통제된 위험: 취약점으로 인해 발생할 수 있는 환자 위해의 위험이 허용가능한 수준임.
ENControlled risk is present when there is sufficiently low (acceptable) residual risk of patient harm due to the vulnerability.
KR통제된 위험(controlled risk)은 취약점으로 인해 발생할 수 있는 환자 위해(patient harm)의 잔여 위험(residual risk)이 충분히 낮을(허용 가능한 수준, acceptable) 때 존재합니다.
통제된 위험과 관련된 취약점을 해결하기 위해 수행할 수 있는 보완 통제 조치
통제된 위험의 보완 통제 조치
  • Changes to a device that are made solely to strengthen cybersecurity are typically considered device enhancements, which may include cybersecurity routine updates and patches, and are generally not required to be reported, under 21 CFR part 806.
  • 사이버보안을 강화하기 위해서만 이루어진 기기 변경은 일반적으로 의료기기 기능향상으로 간주되며, 여기에는 사이버보안 정기 업데이트(routine updates)와 패치(patches)가 포함될 수 있으며, 일반적으로 21 CFR part 806에 따라 보고할 필요가 없습니다.
  • Even when risks are controlled, manufacturers may wish to deploy an additional control(s) as part of a “defense-in-depth” strategy. Typically, these changes would be considered a cybersecurity routine update or patch, a type of device enhancement;
  • 위험이 통제되었더라도, 제조사는 “심층 방어(defense-in-depth)” 전략의 일환으로 추가적인 통제(control)를 배포(deploy)하기를 원할 수 있습니다. 이러한 변경은 일반적으로 사이버보안 정기 업데이트 또는 패치로 간주되며, 의료기기 기능향상의 한 유형입니다.
  • Device changes made solely to address a vulnerability that, if exploited, could lead to compromise of PHI, would typically be considered a cybersecurity routine update or patch;
  • 취약점을 해결하기 위해서만 이루어진 기기 변경이, 만약 악용될 경우 PHI(개인 건강 정보, Protected Health Information)가 손상될 수 있다면, 이는 일반적으로 사이버보안 정기 업데이트 또는 패치로 간주됩니다.
  • For premarket approval (PMA) devices with periodic reporting requirements under 21 CFR 814.84, newly acquired information concerning cybersecurity vulnerabilities and device changes made as part of cybersecurity routine updates and patches should be reported to FDA in a periodic (annual) report. See Section VIII for recommended content to include in the periodic report.
  • 사전 시장 승인(Premarket Approval, PMA) 기기 중 21 CFR 814.84에 따른 정기 보고 요건(periodic reporting requirements)이 있는 경우, 새롭게 획득된 사이버보안 취약점 관련 정보와 사이버보안 정기 업데이트 및 패치의 일환으로 이루어진 기기 변경은 FDA에 정기(연간) 보고서(periodic report)로 보고해야 합니다. 정기 보고서에 포함해야 할 권장 내용은 섹션 VIII을 참조하십시오.
21 CFR 814.84 Reports