1. CYBERSECURITY IS PART OF DEVICE SAFETY AND THE QUALITY SYSTEM REGULATION
제조사는 품질시스템을 수립하고 준수해야 함. (21 CFR 820).
ENDevice manufacturers must establish and follow quality systems to help ensure that their products consistently meet applicable requirements and specifications.KR장치 제조사는 자사 제품이 관련 요건과 사양을 지속적으로 충족하도록 보장하기 위해 품질 시스템을 수립하고 이를 준수해야 합니다.
ENThe quality systems requirements are found in the QS regulation in 21 CFR Part 820.KR품질 시스템 요건은 21 CFR Part 820의 품질 시스템(QS) 규정에 명시되어 있습니다.
ENDepending on the device, QS requirements may be relevant at the premarket stage, postmarket stage,15 or both.KR장치에 따라, QS 요건은 시판 전 단계, 시판 후 단계 또는 양쪽 모두에 적용될 수 있습니다.
제조사는 설계 통제를 위한 절차를 수립하고 유지해야 함. (21 CFR 820.30(a))
제조사는 사이버보안 위험 관리 및 밸리데이션 프로세스를 수립해야 함. (21 CFR 820.30(g))
ENFor example, 21 CFR 820.30(a) requires that for all classes of devices automated with software, a manufacturer must establish and maintain procedures to control the design of the device in order to ensure that specified design requirements are met (“design controls”).KR예를 들어, 21 CFR 820.30(a)는 소프트웨어가 자동화된 모든 등급의 장치에 대해 제조사가 장치 설계를 통제하기 위한 절차를 수립하고 유지해야 한다고 규정하고 있습니다. 이는 설계 요건이 충족되도록 보장하기 위한 것입니다.
ENAs part of design controls, a manufacturer must “establish and maintain procedures for validating the device design,” which “shall include software validation and risk analysis, where appropriate” (21 CFR 820.30(g)). As part of the software validation and risk analysis required by 21 CFR 820.30(g), software device manufacturers may need to establish cybersecurity risk management and validation processes, where appropriate.KR설계 통제의 일환으로, 제조사는 장치 설계를 검증하기 위한 절차를 수립하고 유지해야 하며, 여기에는 적절한 경우 소프트웨어 밸리데이션 및 위험 분석이 포함되어야 합니다(21 CFR 820.30(g)). 이에 따라, 소프트웨어 장치 제조사는 적절한 경우 사이버보안 위험 관리 및 밸리데이션 프로세스를 수립해야 할 수 있습니다.