5. Confidentiality
제조사는 환자에게 위해를 초래할 수 있는 데이터의 유출을 방지하기 위한 데이터 기밀성을 지원해야 함.
ENManufacturers should ensure support for the confidentiality81 of any/all data whose disclosure could lead to patient harm (e.g., through the unauthorized use of otherwise valid credentials, lack of encryption).KR제조사는 환자에게 위해를 초래할 수 있는 데이터(예: 유효한 자격 증명의 무단 사용, 암호화 부족)의 유출을 방지하기 위해 해당 데이터의 기밀성(confidentiality)을 지원해야 합니다.
ENLoss of confidentiality of credentials could be used by a threat-actor to effect multi-patient harm. Lack of encryption to protect sensitive information and or data at rest and in transit can expose this information to misuse that can lead to patient harm.KR자격 증명의 기밀성이 손실되면 위협 행위자가 이를 악용하여 여러 환자에게 피해를 줄 수 있습니다. 민감한 정보나 저장 및 전송 중인 데이터에 대한 암호화가 부족하면, 해당 정보가 악용되어 환자에게 위해를 초래할 수 있습니다.
ENFor example, confidentiality is required in the handling and storage of cryptographic keys used for authentication because disclosure could lead to unauthorized use/abuse of device functionality.KR예를 들어, 인증에 사용되는 암호화 키의 처리 및 저장에는 기밀성이 요구되며, 키가 유출될 경우 장치 기능의 무단 사용 또는 오용으로 이어질 수 있습니다.
제조사는 위협 모델링 및 기타 위험 관리 활동을 통해 실제로 기밀성이 확보되고 있는지를 평가하고 검토해야 함.
ENThe proper implementation of authorization and authentication schemes as described in this Appendix 1 and 2 will generally ensure confidentiality.KRAppendix 1 및 2에서 설명된 권한 부여 및 인증 체계의 적절한 구현은 일반적으로 기밀성을 보장합니다.
ENHowever, manufacturers should evaluate and assess whether this is the case during their threat modeling and other risk management activities and make any appropriate changes to their medical device systems to ensure appropriate confidentiality controls are in place.KR그러나 제조사는 위협 모델링 및 기타 위험 관리 활동을 통해 실제로 기밀성이 확보되고 있는지를 평가하고 검토해야 하며, 적절한 기밀성 통제가 마련되도록 의료기기 시스템에 필요한 변경을 수행해야 합니다.