Skip to main content

2. Security Architecture

보안 아키텍처의 정의와 기능.
ENA security architecture, like a system architecture, defines the system and all end-to-end connections into and/or out of the system.
KR보안 아키텍처는 시스템 아키텍처와 유사하게 시스템과 시스템 내부 및 외부의 모든 종단 간 연결을 정의합니다.
ENA security architecture definition process includes both high-level definitions of the devices and/or systems that interact, and detailed information on the implementations for how those interactions occur and are secured.
KR보안 아키텍처 정의 프로세스는 상호작용하는 장치 및/또는 시스템에 대한 고수준 정의와, 이러한 상호작용이 어떻게 이루어지고 어떻게 보안이 유지되는지에 대한 구현 세부 정보를 모두 포함합니다.
ENIt contains information that demonstrates that the risks considered during the risk management process are adequately controlled, which, in turn, supports the demonstration of the safety and effectiveness of the medical device system.
KR이 프로세스는 위험 관리 과정에서 고려된 위험이 적절히 통제되고 있음을 입증하는 정보를 포함하며, 이는 의료기기 시스템의 안전성과 유효성을 입증하는 데 기여합니다.
21 CFR 820.30 설계 프로세스
ENUnder 21 CFR 820.30(b), a manufacturer must establish and maintain plans that describe or reference the design and development activities and define responsibility for implementation.
KR21 CFR 820.30(b)에 따라, 제조사는 설계 및 개발 활동을 설명하거나 참조하고, 구현에 대한 책임을 정의하는 계획을 수립하고 유지해야 합니다.
ENSuch plans must be reviewed, updated, and approved as design and development evolves (21 CFR 820.30(b)).
KR이러한 계획은 설계 및 개발이 진행됨에 따라 검토, 업데이트 및 승인되어야 합니다(21 CFR 820.30(b)).
ENUnder 21 CFR 820.30(c), a manufacturer must establish and maintain procedures to ensure that the design requirements relating to a device are appropriate and address the intended use of the device, including the needs of the user and patient.
KR21 CFR 820.30(c)에 따라, 제조사는 장치와 관련된 설계 요구사항이 적절하며, 장치의 의도된 사용 목적을 포함하여 사용자 및 환자의 요구를 충족하도록 보장하기 위한 절차를 수립하고 유지해야 합니다.
ENUnder 21 CFR 820.30(d), a manufacturer must establish and maintain procedures for defining and documenting design output in terms that allow an adequate evaluation of conformance to design input requirements.
KR21 CFR 820.30(d)에 따라, 제조사는 설계 입력 요구사항에 대한 적절한 적합성 평가가 가능하도록 설계 산출물을 정의하고 문서화하기 위한 절차를 수립하고 유지해야 합니다.
EN21 CFR 820.30(d) also states that design output procedures shall contain or make reference to acceptance criteria and shall ensure that those design outputs that are essential for the proper functioning of the device are identified.
KR또한 21 CFR 820.30(d)는 설계 산출물 절차에 수용 기준이 포함되거나 이를 참조해야 하며, 장치의 적절한 기능 수행에 필수적인 설계 산출물이 식별되도록 해야 한다고 명시하고 있습니다.
21 CFR 820.30 Design Controls
보안 아키텍처는 전반적인 사이버보안을 고려사항을 다루어야 함.
ENFDA recommends that these plans and procedures include design processes, design requirements, and acceptance criteria for the security architecture of the device such that they holistically address the cybersecurity considerations for the device and the system in which the device operates.
KRFDA는 이러한 계획과 절차에 장치의 보안 아키텍처에 대한 설계 프로세스, 설계 요구사항, 수용 기준을 포함하여, 장치 및 해당 장치가 작동하는 시스템에 대한 사이버보안 고려사항을 전체적으로 다룰 수 있도록 할 것을 권장합니다.
ENThe security architecture should include a consideration of system-level risks, including but not limited to risks related to the supply chain (e.g., to ensure the device remains free of malware, or vulnerabilities inherited from upstream dependencies such as third-party software, among others), design, production, and deployment (i.e., into a connected/networked environment).
KR보안 아키텍처에는 시스템 수준의 위험에 대한 고려가 포함되어야 하며, 여기에는 공급망과 관련된 위험(예: 장치가 악성코드에 감염되지 않도록 하거나, 제3자 소프트웨어 등 상위 종속성으로부터 유입된 취약점을 방지하기 위한 조치), 설계, 생산, 배포(즉, 연결된/네트워크 환경으로의 배포)와 관련된 위험이 포함됩니다.
시판 전 제출문서는 보안 아키텍처 문서를 포함함.
ENFDA recommends that premarket submissions include documentation on the security architecture.
KRFDA는 시판 전 제출 문서에 보안 아키텍처에 대한 문서를 포함할 것을 권장합니다.
ENThe objective in providing security architecture information in premarket submissions is to provide to FDA the security context and trust-boundaries of the medical device system in terms of the interfaces, interconnections, and interactions that the medical device system has with external entities.
KR시판 전 제출 문서에 보안 아키텍처 정보를 제공하는 목적은 의료기기 시스템이 외부 엔터티와 가지는 인터페이스, 상호 연결, 상호작용 측면에서 FDA가 해당 시스템의 보안 맥락과 신뢰 경계를 이해할 수 있도록 하는 데 있습니다.
설계 프로세스는 사이버보안 통제를 위한 설계 입력을 포함해야 함.
ENFDA considers the way in which a device addresses cybersecurity risks and the way in which the device responds when exposed to cybersecurity threats as functions of the device design.
KRFDA는 장치가 사이버보안 위험을 어떻게 다루는지, 그리고 사이버보안 위협에 노출되었을 때 어떻게 대응하는지를 장치 설계의 기능으로 간주합니다.
ENEffective cybersecurity relies upon security being “built in” to a device, and not “bolted on” after the device is designed.
KR효과적인 사이버보안은 장치 설계 이후에 “덧붙여지는(bolted on)” 것이 아니라, 장치에 “내재되어 있는(built in)” 보안에 기반합니다.
ENFDA recommends that device manufacturers’ design processes include design inputs for cybersecurity controls.
KRFDA는 제조사의 설계 프로세스에 사이버보안 통제를 위한 설계 입력이 포함될 것을 권장합니다.
보안 아키텍처가 포함해야 할 통제 수단의 범주.
보안 아키텍처가 포함해야 할 통제 수단의 범주
  • Authentication;
  • Authorization;
  • Cryptography;
  • Code, Data, and Execution Integrity;
  • Confidentiality;
  • Event Detection and Logging;
  • Resiliency and Recovery; and
  • Updatability and Patchability.
시판 전 제출문서는 보안 아키텍처 문서를 포함함.
ENFDA recommends the requirements and acceptance criteria for each of the above categories be provided in premarket submissions to demonstrate safety and effectiveness.
KRFDA는 위에 언급된 각 범주에 대한 요구사항과 수용 기준이 시판 전 제출 문서에 포함되어 장치의 안전성과 유효성을 입증할 수 있도록 할 것을 권장합니다.
ENManufacturers should submit documentation in their premarket submissions demonstrating that
KR제조사는 시판 전 제출 문서에 다음 사항을 입증하는 문서를 제출해야 합니다:
ENthe security controls for the categories above, and further detailed in the recommendations in Appendix 1, have (1) been implemented,
KR위의 범주에 대한 보안 통제는, 부록 1의 권고사항에서 더 자세히 설명된 바와 같이, (1) 이미 구현되어 있으며,
ENand (2) been tested in order to validate that they were effectively implemented.
KR(2) 해당 통제가 효과적으로 구현되었음을 검증하기 위해 테스트가 수행되었음을 보여야 합니다.