2. Uncontrolled Risk to Safety and Essential Performance
통제되지 않은 위험: 불충분한 위험 완화와 보완 동제로 인해 발생할 수 있는 환자 위해의 위험이 허용 불가능한 수준임.
ENUncontrolled risk is present when there is unacceptable residual risk of patient harm due to insufficient risk mitigations and compensating controls.KR통제되지 않은 위험(Uncontrolled risk)은 불충분한 위험 완화(risk mitigations)와 보완통제로 인해 환자 위해(patient harm)의 잔여 위험(residual risk)이 허용 불가능(unacceptable)한 수준일 때 존재합니다.
ENIf the risk of patient harm is assessed as uncontrolled, additional risk control measures should be applied.KR환자 위해 위험이 통제되지 않은(uncontrolled) 것으로 평가될 경우, 추가적인 위험 통제 조치(risk control measures)가 적용되어야 합니다.
ENManufacturers should remediate uncontrolled risks as quickly as possible.KR제조사는 통제되지 않은 위험(Uncontrolled risks)을 가능한 한 신속하게 개선(remediate)해야 합니다.
통제되지 않은 위험과 관련된 취약점을 해결하기 위해 수행할 수 있는 보완 통제 조치
통제되지 않은 위험의 보완 통제 조치
- Manufacturers should remediate the vulnerabilities to reduce the risk of patient harm to an acceptable level;
- 제조사는 취약점을 개선(remediate)하여 환자 위해(patient harm) 위험을 허용 가능한 수준(acceptable level)으로 낮추어야 합니다.
- While fixing the vulnerability may not be feasible or immediately practicable, manufacturers should identify and implement risk mitigations and compensating controls to adequately mitigate the risk;
- 취약점을 수정하는 것이 실행 가능하지 않거나 즉시 실현하기 어려운 경우에도, 제조사는 위험을 충분히 완화하기 위해 위험 완화 조치(risk mitigations)와 보완통제를 식별하고 구현해야 합니다.
- Customers and the user community should be provided with relevant information on recommended controls and residual cybersecurity risks so that they can take appropriate steps to mitigate the risk and make informed decisions regarding device use;
- 고객과 사용자 커뮤니티에는 권장되는 통제 조치 및 잔여 사이버보안 위험(residual cybersecurity risks)에 관한 관련 정보를 제공받아야 합니다. 그래서 그들이 위험을 완화하기 위한 적절한 조치를 취하고 기기 사용에 대해 정보에 입각한 결정을 내릴 수 있도록 해야 합니다.
- Manufacturers must report these vulnerabilities to the FDA according to 21 CFR part 806, unless reported under 21 CFR parts 803 or 1004 36. However, the FDA does not intend to enforce reporting requirements under 21 CFR part 806 for specific vulnerabilities with uncontrolled risk when the following circumstances are met:
- 제조사는 이러한 취약점을 21 CFR part 806에 따라 FDA에 보고해야 하며, 다만 21 CFR parts 803 또는 1004에 따라 보고된 경우는 예외입니다. 그러나 FDA는 특정 취약점이 통제되지 않은 위험(uncontrolled risk)을 가지는 경우, 다음과 같은 상황이 충족될 때에는 21 CFR part 806의 보고 요건을 집행(enforce)할 의도는 아닙니다:
- There are no known serious adverse events or deaths associated with the vulnerability;
- 해당 취약점과 관련하여 알려진 중대한 이상 사례(serious adverse events)나 사망 사례는 없습니다.
- As soon as possible but no later than 30 days after learning of the vulnerability, the manufacturer communicates with its customers and user community regarding the vulnerability, identifies interim compensating controls, and develops a remediation plan to bring the residual risk to an acceptable level. Controls should not introduce more risk to the device’s safety and essential performance than the original vulnerability. The manufacturer must document37 the timeline rationale for its remediation plan.38 The customer communication should, at minimum:
- 취약점을 인지한 후 가능한 한 신속하게, 그러나 늦어도 30일 이내에 제조사는 해당 취약점에 대해 고객 및 사용자 커뮤니티와 소통하고, 임시 보완통제(interim compensating controls)를 식별하며, 잔여 위험(residual risk)을 허용 가능한 수준으로 낮추기 위한 위험개선 계획을 수립해야 합니다. 통제 조치는 원래의 취약점보다 기기의 안전성(safety)과 필수 성능(essential performance)에 더 큰 위험을 초래해서는 안 됩니다. 제조사는 위험개선 계획의 일정(timeline)과 그 근거(rationale)를 반드시 문서화해야 합니다. 고객과의 소통에는 최소한 다음 사항이 포함되어야 합니다:
- Describe the vulnerability including an impact assessment based on the manufacturer’s current understanding,
- 취약점을 설명하고, 제조사의 현재 이해(current understanding)에 기반한 영향 평가(impact assessment)를 포함할 것
- State that manufacturer’s efforts are underway to address the risk of patient harm as expeditiously as possible,
- 제조사가 환자 위해(patient harm) 위험을 가능한 한 신속하게 해결하기 위한 노력을 진행 중임을 명시할 것
- Describe compensating controls, if any, and
- 가능하다면 보완통제를 설명할 것
- State that the manufacturer is working to fix the vulnerability, or provide a defense-in-depth strategy to reduce the probability of exploit and/or severity of harm, and will communicate regarding the availability of a fix in the future.
- 제조사가 취약점을 수정하기 위해 노력하고 있음을 명시하거나, 악용 가능성(exploit probability) 및/또는 위해(harm)의 심각도를 줄이기 위한 심층 방어(defense-in-depth) 전략을 제공하며, 향후 수정(fix)의 가용성에 대해 소통할 것
- As soon as possible but no later than 60 days after learning of the vulnerability, the manufacturer fixes the vulnerability, validates the change, and distributes the deployable fix to its customers and user community such that the residual risk is brought down to an acceptable level. In some circumstances, a compensating control could produce a long-term solution provided the risk of patient harm is brought to an acceptable level. Controls should not introduce more risk to the device’s safety and essential performance than the original vulnerability. Additionally, the manufacturer should follow-up with end-users as needed beyond the initial 60 day period;39
- 취약점을 인지한 후 가능한 한 신속하게, 그러나 늦어도 60일 이내에 제조사는 해당 취약점을 수정(fix)하고, 변경 사항을 검증(validate)하며, 배포 가능한 수정본(deployable fix)을 고객 및 사용자 커뮤니티에 제공하여 잔여 위험(residual risk)을 허용 가능한 수준(acceptable level)으로 낮추어야 합니다. 일부 상황에서는, 보완통제(compensating control)가 환자 위해(patient harm) 위험을 허용 가능한 수준으로 낮출 수 있다면 장기적인 해결책(long-term solution)이 될 수 있습니다. 통제 조치는 원래의 취약점보다 기기의 안전성(safety)과 필수 성능(essential performance)에 더 큰 위험을 초래해서는 안 됩니다. 또한,
- The manufacturer actively participates as a member of an ISAO that shares vulnerabilities and threats that impact medical devices, such as NH-ISAC (see section IX) and provides the ISAO with any customer communications upon notification of its customers; 제조사는 의료기기에 영향을 미치는 취약점과 위협을 공유하는 NH-ISAC(섹션 IX 참조)와 같은 ISAO(Information Sharing and Analysis Organization)의 회원으로서 적극적으로 참여합니다. 또한 고객에게 통보할 때 발생하는 모든 고객 커뮤니케이션을 ISAO에 제공해야 합니다.
- Remediation of devices with annual reporting requirements (e.g., class III devices) should be included in the annual report;
- 연간 보고 요건(annual reporting requirements)이 있는 기기(예: 클래스 III 기기)의 위험개선은 연간 보고서에 포함되어야 합니다.
- The manufacturer should evaluate the device changes to assess the need to submit a premarket submission (e.g., PMA supplement 40, 510(k), etc.) to the FDA;
- 제조사는 기기 변경 사항을 평가하여, FDA에 사전 시장 제출(premarket submission) — 예: PMA 보완(PMA supplement 40), 510(k) 등 —을 제출할 필요가 있는지 판단해야 합니다.
- For PMA devices with periodic reporting requirements under 21 CFR 814.84, information concerning cybersecurity vulnerabilities, and the device changes and compensating controls implemented in response to this information should be reported to FDA in a periodic (annual) report. See Section VIII for recommended content to include in the periodic report.
- 21 CFR 814.84에 따라 정기 보고 요건(periodic reporting requirements)이 있는 PMA 기기의 경우, 사이버보안 취약점과 이에 대응하여 시행된 기기 변경(device changes) 및 보완통제에 관한 정보는 FDA에 정기(연간) 보고서(periodic/annual report)로 보고되어야 합니다. 정기 보고서에 포함해야 할 권장 내용은 섹션 VIII을 참조하십시오.
위험개선이 이루어지지 않은 경우, FD&C 법(Federal Food, Drug, and Cosmetic Act) 위반으로 간주될 수 있음.
ENIn the absence of remediation, a device with uncontrolled risk of patient harm may be considered to have a reasonable probability that use of, or exposure to, the product will cause serious adverse health consequences or death.KR위험개선이 이루어지지 않은 경우, 환자 위해(patient harm)에 대한 통제되지 않은 위험(uncontrolled risk)을 가진 기기는 해당 제품의 사용 또는 노출이 심각한 건강상의 부정적 결과(serious adverse health consequences)나 사망을 초래할 합리적인 가능성(reasonable probability)이 있다고 간주될 수 있습니다.
ENThe product may be considered in violation of the FD&C Act and subject to enforcement or other action.KR이러한 제품은 FD&C 법(Federal Food, Drug, and Cosmetic Act)을 위반한 것으로 간주될 수 있으며, 집행(enforcement) 또는 기타 조치의 대상이 될 수 있습니다.