Skip to main content

2. Designing for Security

FDA는 보안목표를 구현하기 위한 사이버보안을 평가함.
보안목표 - Authenticity, Authorization, Availability, Confidentiality, Updatability and Patchability
ENWhen reviewing premarket submissions, FDA intends to assess device cybersecurity based on a number of factors, including, but not limited to, the device’s ability to provide and implement the security objectives below throughout the device architecture.
KRFDA는 시판 전 제출 문서를 검토할 때, 장치의 전체 아키텍처를 통해 아래의 보안 목표를 제공하고 구현할 수 있는 능력을 포함하여 다양한 요소를 기반으로 장치의 사이버보안을 평가할 예정입니다.
보안 목표
  • Authenticity, which includes integrity;
  • Authorization;
  • Availability;
  • Confidentiality; and
  • Secure and timely updatability and patchability.
시판 전 제출문서는 보안 목표를 만족시키기 위한 설계 정보를 포함해야 함.
ENPremarket submissions should include information that describes how the above security objectives are addressed by and integrated into the device design.
KR시판 전 제출 문서에는 위의 보안 목표가 장치 설계에 어떻게 통합되고 충족되는지를 설명하는 정보가 포함되어야 합니다.
ENThe extent to which security requirements, architecture, supply chain, and implementation are needed to meet these objectives will depend on but may not be limited to:
KR이러한 보안 목표를 충족하기 위해 필요한 보안 요건, 아키텍처, 공급망, 구현 수준은 다음과 같은 요소에 따라 달라질 수 있습니다:
보안 구현 수준에 영향을 미치는 요소
  • The device’s intended use, indications for use, and reasonably foreseeable misuse;
  • 장치의 사용 목적 및 사용 지침, 예측 가능한 오용 가능성
  • The presence and functionality of its electronic data interfaces;
  • 전자 데이터 인터페이스의 존재 및 기능
  • Its intended and actual environment of use;18
  • 의도된 사용 환경 및 실제 사용 환경
  • The risks presented by cybersecurity vulnerabilities;
  • 사이버보안 취약점이 제기하는 위험
  • The exploitability of the vulnerabilities; and
  • 취약점의 악용 가능성
  • The risk of patient harm due to vulnerability exploitation.
  • 취약점 악용으로 인한 환자 피해 위험
알려진 취약점이나 약한 사이버보안 통제의 악용은 설계 시 고려해야 함.
ENSPDF processes aim to reduce the number and severity of vulnerabilities and thereby reduce the exploitability of a medical device system and the associated risk of patient harm.
KRSPDF 프로세스는 취약점의 수와 심각도를 줄이고, 의료기기 시스템의 악용 가능성과 환자 피해 위험을 줄이는 데 목적이 있습니다.
ENBecause exploitation of known vulnerabilities or weak cybersecurity controls should be considered reasonably foreseeable failure modes for medical device systems, these factors should be addressed in the device design.
KR알려진 취약점이나 약한 사이버보안 통제의 악용은 의료기기 시스템의 예측 가능한 고장 모드로 간주되어야 하며, 이러한 요소는 장치 설계에서 반드시 고려되어야 합니다.