2. Changes Unlikely to Impact Cybersecurity
사이버보안에 영향을 미치지 않는 것으로 보이는 변경사항: 제료 변경, 멸균 방법 변경, 아키텍처/연결성 변경
ENIn general, changes unlikely to impact cybersecurity could include changes in materials, sterilization method changes, or a change to an algorithm without change to architecture/software structure/connectivity.KR일반적으로 사이버보안에 영향을 미치지 않을 것으로 보이는 변경 사항에는 재료 변경, 멸균 방법 변경, 또는 아키텍처/소프트웨어 구조/연결성에 영향을 주지 않는 알고리즘 변경 등이 포함될 수 있습니다.
사이버보안에 영향을 미치지 않는 것으로 보이는 변경사항에 대해, 제조사는 제공해야 할 정보
ENFor these types of changes, FDA recommends that manufacturers of cyber devices provide the following information to meet their premarket submission requirements in section 524B of the FD&C Act:KR이러한 유형의 변경에 대해, FDA는 사이버 장치 제조사가 FD&C 법 제524B조의 시판 전 제출 요구사항을 충족하기 위해 다음 정보를 제공할 것을 권장합니다.
사이버보안에 영향을 미치지 않는 것으로 보이는 변경사항에 대해, 제조사는 제공해야 할 정보
- 524B(b)(1)
- If not previously provided, manufacturers must provide a plan as described in section 524B(b)(1) of the FD&C Act; we recommend that it contain the information as described in Section 4.3.1, above.
- 이전에 제공되지 않은 경우, 제조사는 FD&C 법 제524B(b)(1)항에 명시된 계획을 제공해야 하며, 해당 계획에는 위의 섹션 4.3.1에서 설명된 정보를 포함할 것을 권장합니다.
- If a plan described in Section 4.3.1, above, was previously provided, the manufacturer should provide a reference to the prior submission and a summary of any changes to the plan.
- 위의 섹션 4.3.1에서 설명된 계획이 이전에 제공된 경우, 제조사는 이전 제출에 대한 참조와 계획의 변경 사항 요약을 제공해야 합니다.
- 524B(b)(2)
- Instead of the full documentation described as required or recommended in Section 4.3.2, above, manufacturers may provide the following information:
- 위의 섹션 4.3.2에서 요구되거나 권장된 전체 문서 대신, 제조사는 다음 정보를 제공할 수 있습니다:
- Description of whether there are currently any “critical vulnerabilities that could cause uncontrolled risks.”
- 현재 “통제되지 않는 위험을 초래할 수 있는 치명적인 취약점”이 존재하는지에 대한 설명
- Description of whether any vulnerabilities with uncontrolled risk were remediated in the device since the last authorization. If so, manufacturers should describe how remediation was performed following the recommendations in FDA’s Postmarket Cybersecurity Guidance.
- 이전 승인 이후 장치에서 통제되지 않는 위험을 가진 취약점이 해결되었는지에 대한 설명. 해결된 경우, 제조사는 FDA의 출시 후 사이버보안 지침에 따라 어떻게 위험개선이 이루어졌는지를 설명해야 합니다.
- 524B(b)(3)
- Section 524B(b)(3) of the FD&C Act requires manufacturers of cyber devices to provide an SBOM, including commercial, open-source, and off-the-shelf software components. To assist with complying with this requirement, we recommend that a manufacturer of a cyber device provide an SBOM that contains the information recommended in Section 2.1.4.2 above.
- FD&C 법 제524B(b)(3)항은 사이버 장치 제조사가 상용, 오픈소스 및 기성 소프트웨어 구성 요소를 포함한 SBOM을 제공할 것을 요구합니다. 이 요구사항을 준수하는 데 도움이 되도록, 사이버 장치 제조사는 위의 섹션 2.1.4.2에서 권장된 정보를 포함하는 SBOM을 제공할 것을 권장합니다.