Skip to main content

1. Implementation of Security Controls

시판 전 제출문서에 포함해야 할 아키텍처 뷰.
ENFDA recommends that premarket submissions include the architecture views described in this section.
KRFDA는 시판 전 제출 문서에 본 섹션에서 설명된 아키텍처 뷰를 포함할 것을 권장합니다.
ENIf corrective and preventive actions are identified, these views can be used to help identify impacted functionality and solutions that address the risks.
KR시정 및 예방 조치가 식별된 경우, 이러한 뷰는 영향을 받는 기능을 식별하고 위험을 해결하는 솔루션을 도출하는 데 활용될 수 있습니다.
EN21 CFR 820.100 requires that manufacturers establish and maintain procedures for implementing corrective and preventive action, which must include, among other things, requirements for analyzing quality data to identify existing and potential causes of quality problems.
KR21 CFR 820.100은 제조사가 시정 및 예방 조치를 구현하기 위한 절차를 수립하고 유지할 것을 요구하며, 이에는 품질 문제의 기존 및 잠재적 원인을 식별하기 위한 품질 데이터 분석 요구사항 등이 포함되어야 합니다.
아키택처 뷰
  • Global System View;
  • Multi-Patient Harm View;
  • Updateability/Patchability View; and
  • Security Use Case View(s).
21 CFR 820.100 Corrective and Preventive Action (시정 및 예방조치)
아키텍처 뷰의 사용 목적.
아키텍처 뷰의 사용 목적 뷰
  • Identify security-relevant medical device system elements and their interfaces;
  • 보안과 관련된 의료기기 시스템 요소 및 해당 인터페이스를 식별할 것
  • Define security context, domains, boundaries, critical user roles, and external interfaces of the medical device system;
  • 의료기기 시스템의 보안 맥락, 도메인, 경계, 주요 사용자 역할 및 외부 인터페이스를 정의할 것
  • Align the architecture with
  • 아키텍처를 다음과 정렬할 것:
    • (a) the medical device system security objectives and requirements,
    • (a) 의료기기 시스템의 보안 목표 및 요구사항
    • (b) security design characteristics in order to address the identified threats; and
    • (b) 식별된 위협을 해결하기 위한 보안 설계 특성
  • Establish traceability of architecture elements to user and medical device system security requirements. Such traceability should exist throughout the cybersecurity risk management documentation.
  • 아키텍처 요소를 사용자 및 의료기기 시스템의 보안 요구사항에 추적 가능하도록 설정할 것. 이러한 추적성은 사이버보안 위험 관리 문서 전반에 걸쳐 존재해야 합니다.
ENIf a particular view sufficiently captures the risks of another view identified above, we do not expect manufacturers to duplicate documentation.
KR특정 뷰가 앞서 언급된 다른 뷰의 위험 요소를 충분히 포착하는 경우, FDA는 제조사가 문서를 중복하여 제출할 것을 기대하지 않습니다.
ENSimilarly, if threat modeling documentation sufficiently captures the view, we do not expect manufacturers to duplicate documentation.
KR마찬가지로, 위협 모델링 문서가 해당 뷰를 충분히 포착하는 경우에도 문서 중복 제출은 필요하지 않습니다.
ENAdditionally, if one of the views listed above is not appropriate, manufacturers should instead provide an explanation for why the view is not included in the premarket submission.
KR또한, 위에 나열된 뷰 중 하나가 적절하지 않은 경우, 제조사는 해당 뷰가 시판 전 제출 문서에 포함되지 않은 이유를 설명해야 합니다.