1. Plans and Procedures (Section 524B(b)(1))
제조사는 FD&C 법 제524B(b)(1) 요구사항을 준수하기 위해 사이버보안 관리 계획서를 제공해야 함.
ENSection 524B(b)(1) of the FD&C Act requires manufacturers of cyber devices to submit to FDA “a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures” in their premarket submissions.KRFD&C 법 제524B(b)(1)항에 따르면, 사이버 장치 제조사는 시판 전 제출 문서에 “출시 후 사이버보안 취약점 및 악용 가능성을 합리적인 시간 내에 모니터링, 식별 및 적절히 대응하기 위한 계획(통합된 취약점 공개 및 관련 절차 포함)”을 FDA에 제출해야 합니다.
ENWe recommend that the plan contain the information recommended for the Cybersecurity Management Plan described in Section 3.2.KR이 계획에는 섹션 3.2에서 설명된 사이버보안 관리 계획(Cybersecurity Management Plan)에 대해 권장된 정보가 포함되어야 합니다.
사이버보안 관리 계획서는 업데이트와 패치를 개발하고 배포하기 위한 일정을 포함해야 함.
ENPlans required by section 524B(b)(1) of the FD&C Act should also describe the timeline, with associated justifications, to develop and release required updates and patches:KRFD&C 법(section 524B(b)(1))에서 요구하는 계획에는 필요한 업데이트와 패치를 개발하고 배포하기 위한 일정(timeline)과 그에 따른 정당화 사유(justifications)도 포함되어야 합니다:
통합된 취약점 공개 (CVD) 및 절차
- Section 524B(b)(2)(A) of the FD&C Act requires manufacturers of cyber devices to make available updates and patches to the device and related systems for known unacceptable vulnerabilities, with these updates and patches made available on a reasonably justified regular cycle.
- FD&C 법 제524B(b)(2)(A)항은 사이버 장치 제조사가 알려진 수용 불가능한 취약점에 대해 장치 및 관련 시스템에 대한 업데이트 및 패치를 합리적으로 정당화된 주기로 제공할 것을 요구합니다.
- A “known unacceptable vulnerability” in 524B(b)(2)(A) contrasts with a “critical vulnerability that could cause uncontrolled risks” in 524B(b)(2)(B).
- 제524B(b)(2)(A)항에서 말하는 “알려진 수용 불가능한 취약점”은 제524B(b)(2)(B)항의 “통제되지 않는 위험을 초래할 수 있는 치명적인 취약점”과 구별됩니다.
- A known unacceptable vulnerability could include
- 알려진 수용 불가능한 취약점에는
- a vulnerability that could not cause uncontrolled risks;
- 통제되지 않는 위험을 초래하지 않는 취약점,
- a vulnerability that is not currently known to cause uncontrolled risks; or
- 현재로서는 통제되지 않는 위험을 초래하는 것으로 알려지지 않은 취약점, 또는
- a vulnerability that could present controlled risk, as described in FDA’s Postmarket Cybersecurity Guidance.
- FDA의 출시 후 사이버보안 지침에서 설명된 바와 같이 통제된 위험을 나타낼 수 있는 취약점이 포함될 수 있습니다.
- Updates and/or patches to address these vulnerabilities may be intended to maintain the supportability of software. Generally, software should be regularly updated to maintain the supportability of the software.
- 이러한 취약점을 해결하기 위한 업데이트 및 패치는 소프트웨어의 지원 가능성을 유지하기 위한 목적일 수 있습니다. 일반적으로 소프트웨어는 지원 가능성을 유지하기 위해 정기적으로 업데이트되어야 합니다.
- Section 524B(b)(2)(B) of the FD&C Act requires manufacturers of cyber devices to make available updates and patches to the device and related systems to address as soon as possible out of cycle,65 critical vulnerabilities that could cause uncontrolled risks.
- FD&C 법 제524B(b)(2)(B)항은 사이버 장치 제조사가 통제되지 않는 위험을 초래할 수 있는 치명적인 취약점을 가능한 한 신속하게, 정기적인 주기 외에(out of cycle) 업데이트 및 패치를 통해 해결할 수 있도록 장치 및 관련 시스템에 대해 제공할 것을 요구합니다.
- In general, this includes vulnerabilities that could cause uncontrolled risks, as described in FDA’s Postmarket Cybersecurity Guidance. For examples of vulnerabilities associated with uncontrolled risks.
- 일반적으로 이는 FDA의 출시 후 사이버보안 지침에서 설명된 바와 같이 통제되지 않는 위험을 초래할 수 있는 취약점을 포함합니다.
제조사는 사이버보안 관리 계획서를 TPLC 전반에 걸쳐 업데이트하고 수행해야 함.
ENManufacturers of cyber devices anticipate and make appropriate updates to these plans, as well as to the processes and procedures discussed in Section VII.C.2 below, as new information becomes available, such as when new risks, threats, vulnerabilities, assets, or adverse impacts are discovered throughout the total product lifecycle.KR사이버 장치 제조사는 전체 제품 수명주기 동안 새로운 위험, 위협, 취약점, 자산 또는 부정적인 영향이 발견될 경우를 대비하여, 이러한 계획뿐만 아니라 아래 섹션 VII.C.2에서 논의된 프로세스 및 절차에 대해 적절한 업데이트를 사전에 고려하고 수행할 것을 권장합니다.
ENTo support such efforts, manufacturers should also create or update appropriate documentation (e.g., threat modeling, cybersecurity risk assessment) and maintain it throughout the device lifecycle.KR이러한 노력을 지원하기 위해 제조사는 위협 모델링, 사이버보안 위험 평가 등 적절한 문서를 작성하거나 업데이트하고, 장치 수명주기 전반에 걸쳐 이를 유지해야 합니다.
사이버보안 관리 계획서는 필드 장치에 대한 위험 관리의 차이를 반영해야 함.
ENCybersecurity management plan also should, as appropriate, account for any differences in the risk management for fielded devices (e.g., differences between marketed devices and devices no longer marketed but still in use).KR사이버보안 관리 계획서는 또한, 필요에 따라 현장에 배치된 장치에 대한 위험 관리의 차이를 반영해야 합니다(예: 현재 판매 중인 장치와 더 이상 판매되지 않지만 여전히 사용 중인 장치 간의 차이).
ENFor example, if an update is not applied automatically for all fielded devices, then there will likely be different risk profiles for the differing software configurations of the device.KR예를 들어, 모든 현장 배치 장치에 대해 업데이트가 자동으로 적용되지 않는 경우, 장치의 소프트웨어 구성에 따라 서로 다른 위험 프로파일이 존재할 수 있습니다.
ENVulnerabilities should be assessed for any differing impacts for all fielded versions to ensure patient risks are being accurately assessed.KR모든 현장 배치 버전에 대해 취약점의 영향을 평가하여 환자 위험이 정확하게 평가되도록 해야 합니다.