Skip to main content

1. Threat Modeling

위협 모델링 정의.
ENThreat modeling includes a process for identifying security objectives, risks, and vulnerabilities across the medical device system, and then defining countermeasures to prevent, mitigate, monitor, or respond to the effects of threats to the medical device system throughout its lifecycle.
KR위협 모델링(threat modeling)은 의료기기 시스템 전반에 걸쳐 보안 목표, 위험, 취약점을 식별한 후, 장치 수명주기 전반에 걸쳐 위협의 영향을 예방, 완화, 모니터링 또는 대응하기 위한 대응 조치를 정의하는 과정을 포함합니다.
위협 모델의 구성 요소.
ENFDA recommends that threat modeling be performed to inform and support the risk analysis activities. The threat model should:
KRFDA는 위협 모델링(threat modeling)을 수행하여 위험 분석 활동을 지원하고 정보를 제공할 것을 권장합니다. 위협 모델은 다음을 포함해야 합니다:
보안 위험 관리 보고서의 구성 요소
  • Identify medical device system risks and mitigations as well as inform the pre- and post-mitigation risks considered as part of the cybersecurity risk assessment;
  • 의료기기 시스템의 위험과 완화 조치를 식별하고, 사이버보안 위험 평가의 일환으로 고려되는 완화 전후의 위험에 대한 정보를 제공할 것
  • State any assumptions about the medical device system or environment of use (e.g., hospital networks are inherently hostile, therefore manufacturers are recommended to assume that an adversary controls the network with the ability to alter, drop, and replay packets); and
  • 의료기기 시스템 또는 사용 환경에 대한 가정 사항을 명시할 것 (예: 병원 네트워크는 본질적으로 적대적일 수 있으므로, 제조사는 공격자가 네트워크를 제어하며 패킷을 변경, 삭제, 재전송할 수 있다고 가정하는 것이 권장됨)
  • Capture cybersecurity risks introduced through the supply chain, manufacturing, deployment, interoperation with other devices, maintenance/update activities, and decommission activities that might otherwise be overlooked in a traditional safety risk assessment process.
  • 공급망, 제조, 배포, 다른 장치와의 상호 운용, 유지보수/업데이트 활동, 폐기 활동 등을 통해 발생할 수 있는 사이버보안 위험을 포착할 것 — 이는 기존의 안전 위험 평가 프로세스에서는 간과될 수 있음
시판 전 제출문서는 위협 모델을 포함함.
ENFDA recommends that premarket submissions include threat modeling documentation.
KRFDA는 시판 전 제출 문서에 위협 모델링 문서를 포함할 것을 권장한다.
시판 전 제출 문서는 위협 모델링 활동에 대한 정보를 포함함.
ENFDA recommends that threat modeling documentation include sufficient information on threat modeling activities performed by the manufacturer.
KRFDA는 제조사가 수행한 위협 모델링 활동에 대한 충분한 정보를 문서에 포함시킬 것을 권장합니다.