Appendix 4. General Premarket Submission Documentation Elements and Scaling with Risk
본 지침에서 식별된 각 문서 유형은 사이버보안 위험이 존재하는 모든 장치의 시판 전 제출문서로 권장됨
ENDevice cybersecurity design and documentation are expected to scale with the cybersecurity risk of that device.KR장치의 사이버보안 설계 및 문서화는 해당 장치의 사이버보안 위험 수준에 따라 확장(scale)되어야 합니다.ENWhile documentation breadth is expected to scale, each type of documentation identified throughout the guidance is recommended for all premarket submissions for devices with potential cybersecurity risks.KR문서의 범위는 위험 수준에 따라 확장되는 것이 기대되지만, 본 지침에서 식별된 각 문서 유형은 사이버보안 위험이 존재하는 모든 장치의 시판 전 제출(premarket submission)에 대해 권장됩니다.
시판 전 제출문서의 문서 유형
| Type of Premarket Submission Documentation | IDE Submission |
|---|---|
| Cybersecurity Risk Management Report | Could be helpful to submit, but not specifically recommended |
- Threat Model (may include Architecture Views) | Could be helpful to submit, but not specifically recommended |
- Cybersecurity Risk Assessment | Could be helpful to submit, but not specifically recommended |
- SBOM | Recommended |
- Vulnerability Assessment and Software Support | Could be helpful to submit, but not specifically recommended |
- Unresolved Anomalies Assessment | Could be helpful to submit, but not specifically recommended |
- Traceability | Could be helpful to submit, but not specifically recommended |
| Measures and Metrics | Could be helpful to submit, but not specifically recommended |
| Architecture Views | Recommended |
- Requirements | Recommended |
- Architecture Views | Recommended |
| Labeling | Recommended |
| Cybersecurity Management Plan | Could be helpful to submit, but not specifically recommended |