2. Design, Develop, and Maintain Processes
제조사는 FD&C 법 제524B(b)(2) 요구사항을 준수하기 위해 사이버 장치를 설계, 개발 및 유지 관리할 때, 적절한 사이버보안 통제를 구현해야 함. (부록 4의 문서화 권장사항 참고)
ENManufacturers of cyber devices must “design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure . . .” (section 524B(b)(2) of the FD&C Act).KR사이버 장치 제조사는 “장치 및 관련 시스템이 사이버보안이 확보되었음을 합리적으로 보장할 수 있도록 설계, 개발 및 유지 관리 절차를 수립하고 유지해야 합니다”(FD&C 법 제524B(b)(2)항).
ENFDA considers related systems to include, among other things, manufacturer-controlled elements, such as other devices, software that performs “other functions” as described in FDA’s Guidance “Multiple Function Device Products: Policy and Considerations,” software/firmware update servers, and connections to healthcare facility networks.KRFDA는 관련 시스템을 제조사가 관리하는 요소들—예: 다른 장치, FDA의 지침 「다기능 장치 제품: 정책 및 고려사항」에서 설명된 “기타 기능”을 수행하는 소프트웨어, 소프트웨어/펌웨어 업데이트 서버, 의료기관 네트워크와의 연결 등—을 포함하는 것으로 간주합니다.
ENIn the design, development and maintenance of a cyber device, manufacturers should consider the cybersecurity risks of related systems to the cyber device and implement appropriate security controls to mitigate those risks.KR사이버 장치를 설계, 개발 및 유지 관리할 때, 제조사는 관련 시스템이 해당 사이버 장치에 미치는 사이버보안 위험을 고려하고, 이러한 위험을 완화하기 위한 적절한 보안 통제를 구현해야 합니다.
ENThe documentation recommendations identified in this guidance and summarized in Appendix 4 should be considered and used to demonstrate reasonable assurance that the device and related systems are cybersecure as required by section 524B(b)(2) of the FD&C Act.KR본 지침에서 제시되고 부록 4에 요약된 문서화 권장사항은 장치 및 관련 시스템이 FD&C 법 제524B(b)(2)항에서 요구하는 사이버보안 요건을 충족함을 입증하기 위해 고려되고 활용되어야 합니다.