4. Submission Documentation
시판 전 제출문서는 사이버보안 통제 설계 문서를 포함함.
사이버보안 통제는 의료기기가 사용될 수 있는 확장된 시스템을 고려해야 함.
ENManufacturers should take into account the larger system in which the device may be used.KR제조사는 장치가 사용될 수 있는 더 큰 (확장된) 시스템을 고려해야 합니다.
ENIf a thermometer (medical device) is used in a safety-critical control loop, or is connected to networks or other devices, then the cybersecurity risks for the device are considered to be greater and more substantial design controls should result.KR온도계(의료기기)가 안전에 중요한 제어 루프에서 사용되거나 네트워크 또는 다른 장치에 연결되는 경우, 해당 장치의 사이버보안 위험은 더 크다고 간주되며 보다 강력한 설계 통제가 필요합니다.
ENSubmitters should consider including in premarket submissions to FDA documentation generated from those design controls used during the development of a device with cybersecurity risks.KR제출자는 사이버보안 위험이 있는 장치를 개발하는 과정에서 사용된 설계 통제로부터 생성된 문서를 FDA에 시판 전 제출 시 포함하는 것을 고려햐여 한다.
사이버보안 통제는 장치의 의도된 사용 환경과 실제 사용 환경을 함께 고려해야 함.
ENCybersecurity controls established during premarket development should also take into consideration the intended and actual use environment.KR시판 전 개발 단계에서 수립된 사이버보안 통제는 장치의 의도된 사용 환경과 실제 사용 환경을 함께 고려해야 합니다.
ENCybersecurity risks evolve over time and as a result, the effectiveness of cybersecurity controls may degrade as new risks, threats, and attack methods emerge.KR사이버보안 위험은 시간이 지남에 따라 진화하며, 그 결과 새로운 위험, 위협, 공격 방식이 등장함에 따라 기존 사이버보안 통제의 효과가 저하될 수 있습니다.
부적절한 레이블링은 법 위반 가능성이 존재함.
ENIn addition, inadequate cybersecurity information in the device labeling may cause a device to be misbranded under section 502(f) of the FD&C Act if its labeling does not bear adequate directions for use or under section 502(j) of the FD&C Act because it is dangerous to health when used in the manner recommended or suggested in the labeling, among other possible violations.KR또한, 장치 라벨에 사이버보안 정보가 충분하지 않을 경우, 해당 라벨이 적절한 사용 지침을 포함하지 않으면 FD&C 법 제502(f)조에 따라 허위표시(misbranding)로 간주될 수 있으며, 라벨에 명시된 권장 또는 제안된 방식으로 사용할 경우 건강에 해로울 수 있다면 FD&C 법 제502(j)조에 따라 오표시로 간주될 수 있습니다. 이 외에도 다양한 위반 가능성이 존재합니다.
ENFor cyber devices, failure to comply with any requirement under section 524B(b)(2) of the FD&C Act (relating to ensuring device cybersecurity) is considered a prohibited act under section 301(q) of the FD&C Act.KR사이버 장치의 경우, FD&C 법 제524B(b)(2)조(장치 사이버보안 보장과 관련된 요건)를 준수하지 않으면 FD&C 법 제301(q)조에 따라 금지 행위(prohibited act)로 간주됩니다.
시판 전 제출 문서는 (의료기기 등급이 아닌) 사이버 위험에 근거한 사이버보안 정보를 포함해야 함.
ENThis guidance recommends cybersecurity information be included in submissions based on cybersecurity risks, not on any other criteria or level of risk/concern established in a separate FDA guidance (e.g., the risk-based approach in the Premarket Software Guidance to help determine a device’s Documentation Level).KR이 지침은 사이버보안 정보가 제출 문서에 포함될 때, 사이버보안 위험을 기준으로 해야 하며, 별도의 FDA 지침에서 설정된 다른 기준이나 위험 수준(예: 장치의 문서화 수준을 결정하기 위한 시판 전 소프트웨어 지침의 위험 기반 접근 방식)을 기준으로 해서는 안 된다고 권장합니다.