Skip to main content

6. Event Detection and Logging

이벤트 감지 및 로그 기록 기능은 의료기기를 손상시키려는 시도를 식별하고 추적하는 기능으로, 장치에 포함되어야 함.
ENEvent detection and logging are critical capabilities that should be present in a device and the larger system in which it operates in order to ensure that suspected and successful attempts to compromise a medical device may be identified and tracked. These event detection capabilities and logs should include storage capabilities, if possible, so that forensic discovery may later be performed.
KR이벤트 감지 및 로그 기록 기능은 의료기기를 손상시키려는 시도—의심되거나 실제로 성공한 경우 모두—를 식별하고 추적할 수 있도록 장치 및 해당 장치가 작동하는 시스템 전체에 반드시 포함되어야 하는 핵심 기능입니다. 이러한 이벤트 감지 기능과 로그는 향후 포렌식 분석이 가능하도록 저장 기능도 포함하는 것이 바람직합니다.
이벤트 감지 및 로깅을 위한 권고사항
이벤트 감지 및 로깅을 위한 권고사항
  • Implement design features that allow for security compromises and suspected compromise attempts to be detected, recognized, logged, timed, and acted upon during normal use. Acting upon security events should consider the benefit/risk assessment in accordance with Section 6.5 of AAMI TIR57 or Section 7.4 of ANSI/AAMI SW96 in determining whether it is appropriate to affect standard device functionality during a security event.
  • 보안 침해 및 침해 시도 감지, 인식, 기록, 시간 추적, 대응이 가능한 설계 기능을 구현해야 합니다. 보안 이벤트에 대한 대응은 AAMI TIR57의 섹션 6.5 또는 ANSI/AAMI SW96의 섹션 7.4에 따른 이익/위험 평가를 고려하여, 보안 이벤트 중에 표준 장치 기능에 영향을 주는 것이 적절한지 판단해야 합니다.
  • Ensure the design enables forensic evidence capture.82 The design should include mechanisms to securely create and store log files off the device to track security events. Documentation should include how and where log files are located, stored, recycled, archived, and how they could be consumed by automated analysis software (e.g., IDS). Examples of security events include, but are not limited to, configuration changes, network anomalies, login attempts, and anomalous traffic (e.g., sending requests to unknown entities).
  • 포렌식 증거 수집이 가능하도록 설계해야 합니다. 보안 이벤트를 추적하기 위해 장치 외부에 로그 파일을 안전하게 생성하고 저장할 수 있는 메커니즘을 포함해야 합니다. 문서에는 로그 파일의 위치, 저장 방식, 재활용 및 보관 방법, 자동 분석 소프트웨어(예: IDS)를 통해 로그가 어떻게 활용될 수 있는지에 대한 내용이 포함되어야 합니다. 보안 이벤트의 예로는 구성 변경, 네트워크 이상, 로그인 시도, 이상 트래픽(예: 알 수 없는 엔티티에 대한 요청 전송)이 있습니다.
  • Design devices such that the potential impact of vulnerabilities is limited by specifying a secure configuration. Secure configurations may include endpoint protections, such as anti-malware, firewall/firewall rules, allow-listing, defining security event parameters, logging parameters, physical security detection, and/or HIDS/HIPS.
  • 취약점의 잠재적 영향을 제한할 수 있도록 보안 구성을 명시하여 장치를 설계해야 합니다. 보안 구성에는 엔드포인트 보호(예: 악성코드 방지, 방화벽/방화벽 규칙, 허용 목록 설정, 보안 이벤트 및 로그 매개변수 정의, 물리적 보안 감지, HIDS/HIPS 등)가 포함될 수 있습니다.
  • Design devices such that they may integrate and/or leverage antivirus/anti-malware protection capabilities. These capabilities may vary depending on the type of device and the software and hardware components it contains:
  • 장치가 백신/악성코드 방지 기능을 통합하거나 활용할 수 있도록 설계해야 합니다. 이러한 기능은 장치 유형 및 포함된 소프트웨어/하드웨어 구성 요소에 따라 달라질 수 있습니다:
    • For devices that leverage Windows Operating System:
    • Windows 운영체제를 사용하는 장치:
      • Antivirus/anti-malware is recommended on the device. Manufacturers are recommended to qualify multiple options to support user preferences for different options, especially if the device is used in healthcare facility environments.
      • 장치에 백신/악성코드 방지 기능을 사용하는 것이 권장됩니다. 특히 의료기관 환경에서 사용되는 경우, 사용자 선호도를 지원할 수 있도록 여러 옵션을 검증하는 것이 좋습니다.
    • For devices that leverage other Commercial Operating Systems (e.g., Ubuntu, Unix, Linux, Apple, Android):
    • 기타 상용 운영체제(Ubuntu, Unix, Linux, Apple, Android 등)를 사용하는 장치:
      • Antivirus/anti-malware may be recommended based on the environment and associated risks of the device. Different operating systems will likely follow a case-by-case determination based on network exposure and risk. 장치의 환경 및 관련 위험에 따라 백신/악성코드 방지 기능이 권장될 수 있습니다. 운영체제별로 네트워크 노출 및 위험 수준에 따라 개별적으로 판단해야 합니다.
    • For devices that leverage Embedded Operating Systems (e.g., Real-Time Operating Systems, Windows embedded):
    • 임베디드 운영체제(실시간 운영체제, Windows Embedded 등)를 사용하는 장치:
      • Antivirus/malware detection/protection software is generally not needed unless a particular risk or threat is identified that would not be addressed by other expected security controls.
      • 특정 위험이나 위협이 식별되지 않는 한, 일반적으로 백신/악성코드 탐지/보호 소프트웨어는 필요하지 않습니다.
  • Design devices to enable software configuration management and permit tracking and control of software changes to be electronically obtainable (i.e., machine readable) by authorized users.
  • 장치가 소프트웨어 구성 관리를 가능하게 하고, 소프트웨어 변경 사항의 추적 및 제어가 전자적으로(즉, 기계 판독 가능하게) 승인된 사용자에게 제공될 수 있도록 설계해야 합니다.
  • Design devices to facilitate the performance of variant analyses such that the same vulnerabilities can be identified across device models and product lines.
  • 장치가 변형 분석 수행을 지원하도록 설계되어, 동일한 취약점을 장치 모델 및 제품 라인 전반에서 식별할 수 있어야 합니다.
  • Design devices to notify users when malfunctions or anomalous device behavior, including those potentially related to a cybersecurity breach, are detected.
  • 사이버보안 침해와 관련된 이상 동작을 포함하여, 오작동이나 이상 장치 동작이 감지되었을 때 사용자에게 알릴 수 있도록 장치를 설계해야 합니다.
  • Consider designing devices such that they are able to produce an SBOM in a machine readable format.
  • 장치가 기계 판독 가능한 형식의 SBOM을 생성할 수 있도록 설계하는 것도 고려해야 합니다.