Skip to main content

8. Firmware and Software Updates

장치는 TPLC 동안 안전성과 유효성을 유지하기 위해 안전하고 신속하게 업데이트할 수 있어야 함.
ENDevices should be capable of being updated in a secure and timely manner to maintain safety and effectiveness throughout the product’s lifecycle. Despite best efforts, undiscovered, exploitable vulnerabilities may exist in devices after they are marketed. This is especially true over the device’s service life, as threats evolve over time and exploit methods change, and become more sophisticated.
KR장치는 제품의 전체 수명 주기 동안 안전성과 유효성을 유지하기 위해 안전하고 신속하게 업데이트할 수 있어야 합니다. 최선의 노력을 기울이더라도, 제품이 출시된 이후에도 발견되지 않은 취약점이 존재할 수 있으며, 이는 악용될 수 있습니다. 특히 장치의 서비스 수명이 길어질수록 위협은 진화하고, 공격 방식은 변화하며 더욱 정교해지기 때문에 이러한 위험은 더욱 커집니다.
장치 업데이트를 위한 권고사항
ENFDA recommends that manufacturers should not only build in the ability for devices to be updated, but that manufacturers also plan for the rapid testing, evaluation, and patching of devices deployed in the field.
KRFDA는 제조사가 장치에 업데이트 기능을 내장하는 것뿐만 아니라, 현장에 배포된 장치에 대해 신속한 테스트, 평가 및 패치 계획도 수립할 것을 권장합니다.
이벤트 감지 및 로깅을 위한 권고사항
  • Design devices to anticipate the need for software and firmware patches and updates to address future cybersecurity vulnerabilities. This will likely necessitate the need for additional storage space and processing resources.
  • 장치가 향후 사이버보안 취약점을 해결하기 위한 소프트웨어 및 펌웨어 패치와 업데이트의 필요성을 예측할 수 있도록 설계해야 합니다. 이를 위해 추가적인 저장 공간과 처리 자원이 필요할 수 있습니다.
  • Consider update process reliability and how update process works in event of communication interruption or failure. This should include both considerations for hardware impacts (timing specifics of interruptions) and which phase of the update process the interruption or failure occurs.
  • 업데이트 프로세스의 신뢰성과 통신 중단 또는 실패 시 업데이트가 어떻게 작동하는지를 고려해야 합니다. 여기에는 하드웨어에 미치는 영향(중단 시점의 타이밍)과 업데이트 프로세스의 어느 단계에서 중단 또는 실패가 발생했는지를 포함해야 합니다.
  • Consider cybersecurity patches and updates that are independent of regular feature update cycles.
  • 기능 업데이트 주기와는 별도로 독립적인 사이버보안 패치 및 업데이트를 고려해야 합니다.
  • Implement processes, technologies, security architectures, and exercises to facilitate the rapid verification, validation, and distribution of patches and updates.
  • 패치 및 업데이트의 신속한 검증, 확인 및 배포를 가능하게 하는 프로세스, 기술, 보안 아키텍처 및 훈련 절차를 구현해야 합니다.
  • Preserve and maintain full build environments and virtual machines, regression test suites, engineering development kits, emulators, debuggers, and other related tools that were used to develop and test the original product to ensure updates and patches may be applied safely and in a timely manner.
  • 업데이트 및 패치를 안전하고 신속하게 적용할 수 있도록, 제품 개발 및 테스트에 사용된 전체 빌드 환경, 가상 머신, 회귀 테스트 도구, 개발 키트, 에뮬레이터, 디버거 및 기타 관련 도구를 보존하고 유지해야 합니다.
  • Maintain necessary third-party licenses throughout the supported lifespan of the device. Develop contingency plans for the possibility that a third-party company goes out of business or stops supporting a licensed product. Modular designs should be considered such that third-party solutions could be readily replaced.
  • 장치의 지원 수명 동안 필요한 서드파티 라이선스를 유지해야 하며, 라이선스 제공 업체가 사업을 중단하거나 제품 지원을 중단할 경우를 대비한 비상 계획을 수립해야 합니다. 모듈형 설계를 고려하여 서드파티 솔루션을 쉽게 교체할 수 있도록 해야 합니다.
  • Implement a secure process and mechanism for providing validated software updates and patches for users.
  • 사용자에게 검증된 소프트웨어 업데이트 및 패치를 제공하기 위한 안전한 프로세스와 메커니즘을 구현해야 합니다.