Skip to main content

1. Security Risk Management

보안 위험 관리는 제조사의 품질 시스템에 통합되고, TPLC 전반에 걸쳐 다루어져야 함.
ENTo fully account for cybersecurity risks in medical device systems, the safety and security risks of each device should be assessed within the context of the larger system in which the device operates.
KR의료기기 시스템에서 사이버보안 위험을 완전히 고려하기 위해서는, 각 장치의 안전 및 보안 위험을 해당 장치가 작동하는 더 큰 시스템의 맥락에서 평가해야 합니다.
ENSecurity risk management should be an integrated part of a manufacturer’s entire quality system, addressed throughout the TPLC.
KR보안 위험 관리는 제조사의 전체 품질 시스템에 통합되어야 하며, 제품 전체 수명주기(TPLC) 전반에 걸쳐 다루어져야 합니다.
ENThe quality system processes entail the technical, personnel, and management practices, among others, that manufacturers use to manage potential risks to their devices and ensure that their devices are, and once on the market, remain, safe and effective, which includes security.
KR품질 시스템 프로세스에는 기술적, 인적, 관리적 관행 등이 포함되며, 이는 제조사가 자사 장치에 대한 잠재적 위험을 관리하고, 장치가 시장에 출시되기 전은 물론 출시된 이후에도 안전하고 효과적으로 유지되도록 보장하는 데 사용됩니다. 여기에는 보안도 포함됩니다.
보안 위험 관리는 안전 위험 관리(ISO 14971)와는 구별되는 활동임.
ENWhile safety risk management focuses on physical injury, damage to property or the environment, or delay and/or denial of care due to device or system unavailability, security risk management may include risks that can result in indirect or direct patient harm.
KR안전 위험 관리는 신체적 부상, 재산 또는 환경에 대한 손상, 장치나 시스템의 사용 불가로 인한 진료 지연 또는 거부 등에 초점을 맞추는 반면, 보안 위험 관리는 환자에게 간접적 또는 직접적인 위해를 초래할 수 있는 위험을 포함할 수 있습니다.
ENAdditionally, risks that are outside of FDA’s assessment of safety and effectiveness, such as those related to business or reputational risks, may also exist.
KR이와 더불어, FDA의 안전성과 유효성 평가 범위를 벗어나는 위험—예를 들어 비즈니스 또는 평판과 관련된 위험—도 존재할 수 있습니다.
제조사는 보안 위험 관리 프로세스를 수립해야 함.
ENThe scope and objective of a security risk management process, in conjunction with other SPDF processes (e.g., security testing), is to expose how threats, through vulnerabilities, can manifest patient harm and other potential risks.
KR보안 위험 관리 프로세스의 범위와 목적은 다른 SPDF(보안 제품 개발 프레임워크) 프로세스(예: 보안 테스트)와 함께 위협이 어떻게 취약점을 통해 환자에게 위해를 초래하거나 기타 잠재적 위험을 발생시킬 수 있는지를 드러내는 데 있습니다.
ENThese processes should also ensure that risk control measures for one type of risk assessment do not inadvertently introduce new risks in the other. For example, AAMI TIR57 and ANSI/AAMI SW96 detail how the security and safety risk management processes should interface to ensure all risks are adequately assessed.
KR이러한 프로세스는 또한 한 유형의 위험 평가를 위한 통제 조치가 다른 유형의 위험을 의도치 않게 새로 유발하지 않도록 보장해야 합니다. 예를 들어, AAMI TIR57 및 ANSI/AAMI SW96은 보안 위험 관리와 안전 위험 관리 프로세스가 어떻게 연계되어야 모든 위험이 적절히 평가될 수 있는지를 상세히 설명하고 있습니다.
ENFDA recommends that security risk management processes, as detailed in the QS regulation,28 be established or incorporated into those that already exist, and should address the manufacturer’s design, manufacturing, and distribution processes, as well as updates across the TPLC
KRFDA는 QS(품질 시스템) 규정에 명시된 바와 같이 보안 위험 관리 프로세스를 새로 수립하거나 기존 프로세스에 통합할 것을 권장하며, 이는 제조사의 설계, 제조, 유통 프로세스뿐만 아니라 제품 수명주기(TPLC) 전반에 걸친 업데이트까지 포함해야 합니다.
ENThe processes in the QS regulation which may be relevant in this context include, but are not limited to design controls (21 CFR 820.30), validation of production processes (21 CFR 820.70), and corrective and preventive actions (21 CFR 820.100).
KRQS 규정에서 이와 관련하여 적용될 수 있는 프로세스에는 다음이 포함되며, 이에 국한되지 않습니다. 설계 통제 (21 CFR 820.30), 생산 공정 밸리데이션 (21 CFR 820.70), 시정 및 예방 조치 (21 CFR 820.100)
ENFor completeness in performing risk analyses under 21 CFR 820.30(g), FDA recommends that device manufacturers conduct both a safety risk assessment and a separate, accompanying security risk assessment to ensure a more comprehensive identification and management of patient safety risks.
KRFDA는 21 CFR 820.30(g)에 따른 위험 분석을 완전하게 수행하기 위해, 장치 제조사가 안전 위험 평가와 별도로 보안 위험 평가도 함께 수행할 것을 권장하며, 이를 통해 환자 안전 위험을 보다 포괄적으로 식별하고 관리할 수 있습니다.
21 CFR 820.30 Design controls21 CFR 820.70 Production and Process Controls21 CFR 820.100 Corrective and Preventive Action (시정 및 예방조치)
제조사는 보완통제를 할 수 있으며, 적절한 경우 위험전가를 할 수도 있음.
ENA device should be designed to eliminate or mitigate known vulnerabilities. For marketed devices, if comprehensive design mitigations are not possible, compensating controls should be considered.
KR장치는 알려진 취약점을 제거하거나 완화할 수 있도록 설계되어야 합니다. 이미 시판 중인 장치의 경우, 포괄적인 설계 기반 완화 조치가 불가능하다면 보완 통제(compensating controls)를 고려해야 합니다.
ENFor all devices, when any known vulnerabilities are only partially mitigated or unmitigated by the device design, they should be assessed as reasonably foreseeable risks in the risk assessment and be assessed for additional control measures or risk transfer to the user/operator, or, if necessary, the patient.
KR모든 장치에 대해, 알려진 취약점이 장치 설계에 의해 부분적으로만 완화되었거나 전혀 완화되지 않은 경우, 해당 취약점은 위험 평가에서 합리적으로 예측 가능한 위험으로 간주되어야 하며, 추가적인 통제 조치 또는 사용자/운영자, 필요 시 환자에게의 위험 전가(risk transfer) 가능성에 대해 평가되어야 합니다.
ENRisk transfer, if appropriate, should only occur when all relevant risk information is known, assessed, and appropriately communicated to users and includes risks inherited from the supply chain as well as how risk transfer will be handled when the device or manufacturer-controlled assets of the medical device system reach end of support and end of life and whether or how the user is able to take on that role (e.g., if the user may be a patient).
KR위험 전가는 적절한 경우에만 이루어져야 하며, 모든 관련 위험 정보가 충분히 파악되고 평가되며 사용자에게 적절히 전달된 상황에서만 허용되어야 합니다. 여기에는 공급망으로부터 유입된 위험뿐만 아니라, 장치 또는 제조사가 통제하는 의료기기 시스템 자산이 지원 종료(end of support) 또는 수명 종료(end of life)에 도달했을 때 위험 전가가 어떻게 처리될 것인지, 그리고 사용자가 해당 역할(예: 사용자가 환자인 경우)을 수행할 수 있는지 여부도 포함됩니다.
제조사는 AAMI TIR57 및 ANSI/AAMI SW96에 따라 보안 위험 관리 계획서와 보안 위험 관리 보고서 문서를 작성해야 함.
ENTo document the security risk management activities for a medical device system, FDA recommends that manufacturers generate a security risk management plan and report such as that described in AAMI TIR57 and ANSI/AAMI SW96.
KR의료기기 시스템에 대한 보안 위험 관리 활동을 문서화하기 위해, FDA는 제조사가 AAMI TIR57 및 ANSI/AAMI SW96에서 설명된 것과 같은 보안 위험 관리 계획 및 보고서를 작성할 것을 권장합니다.
보안 위험 관리 보고서의 구성 요소
보안 위험 관리 보고서의 구성 요소
  • The system threat modeling;
  • Cybersecurity risk assessment;
  • Software Bill of Materials (SBOM);
  • Component support information;
  • Vulnerability assessments;
  • Unresolved anomaly assessment(s);
  • Summarize the risk evaluation methods and processes;
  • Detail the residual risk conclusion from the security risk assessment;
  • Detail the risk mitigation activities undertaken as part of a manufacturer’s risk management processes; and
  • Provide traceability between the threat model, cybersecurity risk assessment, SBOM, and testing documentation as discussed later in this guidance as well as other relevant cybersecurity risk management documentation.