1. Diagrams
FDA는 제조사가 사이버보안 통제를 설명하는 데 도움이 되는 다이어그램을 제공할 것을 권장함.
ENFDA recommends that manufacturers provide diagrams to help describe the medical device system architecture, interfaces, communication protocols, threats, and cybersecurity controls used throughout the system.KRFDA는 제조사가 의료기기 시스템의 아키텍처, 인터페이스, 통신 프로토콜, 위협 요소 및 시스템 전반에 걸쳐 사용되는 사이버보안 통제를 설명하는 데 도움이 되는 다이어그램을 제공할 것을 권장합니다.
ENDifferent diagramming methods can be used to describe the architecture, including data flow diagrams, state diagrams, swim-lane diagrams, and call-flow diagrams, among others.KR아키텍처를 설명하기 위해 다양한 다이어그램 방식이 사용될 수 있으며, 여기에는 데이터 흐름도(data flow diagram), 상태도(state diagram), 스윔레인 다이어그램(swim-lane diagram), 콜 플로우 다이어그램(call-flow diagram) 등이 포함됩니다.
아키텍처 뷰를 기술(description)할 때의 권장사항.
ENArchitecture views should include diagram(s) with explanatory text that describes the sequence of process or protocol steps in explicit detail for an associated use case.KR아키텍처 뷰(architecture views)에는 관련 사용 사례에 대해 프로세스 또는 프로토콜 단계의 순서를 명확하게 설명하는 다이어그램과 해설 텍스트가 포함되어야 합니다.
ENArchitecture views should provide specific protocol details of the communication pathways between parts of the medical device system, to include authentication or authorization procedures and session management techniques.KR아키텍처 뷰는 의료기기 시스템의 구성 요소 간 통신 경로에 대한 구체적인 프로토콜 세부사항을 제공해야 하며, 여기에는 인증 또는 권한 부여 절차, 세션 관리 기법 등이 포함됩니다.
ENThese views should be sufficiently detailed such that engineers and reviewers should be able to logically and easily follow data, code, and commands from any asset (e.g., a manufacturer server) to any other associated asset (e.g., a medical device), while possibly crossing intermediate assets (e.g., application).KR이러한 뷰는 엔지니어와 검토자가 제조사 서버와 같은 자산에서 의료기기와 같은 다른 관련 자산까지, 중간 자산(예: 애플리케이션)을 거칠 수 있는 데이터, 코드, 명령의 흐름을 논리적으로 쉽게 따라갈 수 있을 정도로 충분히 상세하게 작성되어야 합니다.