2. Using an SPDF to Manage Cybersecurity Risks
제조사는 SPDF를 통해 사이버보안 위험을 통제해야 함.
ENThe increasingly interconnected nature of medical devices has demonstrated the importance of addressing cybersecurity risks associated with device connectivity in device design because of the effects on safety and effectiveness.KR의료기기의 상호 연결성이 점점 증가함에 따라, 장치 설계 시 연결성과 관련된 사이버보안 위험을 해결하는 것이 장치의 안전성과 유효성에 영향을 미친다는 점에서 매우 중요하다는 사실이 입증되었습니다.
ENCybersecurity risks to the medical device or to the larger medical device system can be reasonably controlled through using an SPDF.KRSPDF(보안 제품 개발 프레임워크)를 활용하면 의료기기 자체 또는 더 큰 의료기기 시스템에 대한 사이버보안 위험을 합리적으로 통제할 수 있습니다.
SPDF의 사용목적은 안전하고 효과적인 장치를 제조하고 유지하는 것임.
ENThe primary goal of using an SPDF is to manufacture and maintain safe and effective devices.KRSPDF(보안 제품 개발 프레임워크)를 사용하는 주요 목적은 안전하고 효과적인 장치를 제조하고 유지하는 것입니다.
ENFrom a security standpoint, these are also trustworthy and resilient devices. These devices can then be managed (e.g., installed, configured, updated, review of device logs) through the device design and associated labeling by the device manufacturers and/or users (e.g., patients, healthcare facilities).KR보안 관점에서 볼 때, 이러한 장치는 신뢰할 수 있고 복원력 있는(resilient) 장치이기도 합니다. 이러한 장치는 제조사 및/또는 사용자(예: 환자, 의료기관)가 장치 설계 및 관련 라벨링을 통해 설치, 구성, 업데이트, 로그 검토 등의 방식으로 관리할 수 있습니다.
ENFor healthcare facilities, these devices can also be managed within their own cybersecurity risk management frameworks, such as the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity, generally referred to as the NIST Cybersecurity Framework or NIST CSF.KR의료기관의 경우, 이러한 장치는 자체적인 사이버보안 위험 관리 프레임워크 내에서도 관리될 수 있으며, 예를 들어 미국 국립표준기술연구소(NIST)의 「핵심 인프라 사이버보안 향상을 위한 프레임워크」(일반적으로 NIST 사이버보안 프레임워크 또는 NIST CSF로 불림)와 같은 체계를 활용할 수 있습니다.
제조사가 사용가능한 SPDF 예시.
ENFDA recommends that manufacturers use device design processes such as those described in the QS regulation to support secure product development and maintenance.KRFDA는 제조사가 안전한 제품 개발 및 유지 관리를 지원하기 위해 QS(품질 시스템) 규정에 설명된 것과 같은 장치 설계 프로세스(SPFD)를 사용할 것을 권장합니다.
ENManufacturers may use other existing frameworks that satisfy the QS regulation and align with FDA’s recommendations for using an SPDF. Possible frameworks to consider include, but are not limited to,KR제조사는 QS 규정을 충족하고 SPDF(보안 제품 개발 프레임워크) 사용에 대한 FDA의 권고사항과 일치하는 기존의 다른 프레임워크를 사용하는 것도 가능합니다.
제조사가 사용가능한 기존의 다른 프레임워크 예시
- Medical Device and Health IT Joint Security Plan (JSP2);
- IEC 81001-5-1; and
- Frameworks from other sectors may also comply with the QS regulations, like the framework provided in ANSI/ISA 62443-4-1 Security for industrial automation and control systems Part 4 1: Product security development life-cycle requirements.