2. Cybersecurity Risk Assessment
제조사는 사이버보안 위험을 평가해야 함.
ENAs a part of security risk management, security risks and controls should be assessed for residual risks as part of a cybersecurity risk assessment.KR보안 위험 관리의 일환으로, 보안 위험과 통제 수단은 사이버보안 위험 평가의 일부로서 잔여 위험에 대해 평가되어야 합니다.
ENSecurity risk assessment processes focus on exploitability, or the ability to exploit vulnerabilities present within a device and/or system. FDA recommends that manufacturers assess identified risks according to the level of risk posed from the device and the system in which it operates.KR보안 위험 평가는 장치 및/또는 시스템 내 존재하는 취약점을 악용할 수 있는 가능성, 즉 exploitability에 초점을 맞춥니다. FDA는 제조사가 식별된 위험을 장치 및 해당 장치가 작동하는 시스템에서 발생할 수 있는 위험 수준에 따라 평가할 것을 권장합니다.
알려진 취약점과 테스트 도중 식별된 취약점은 TPLC를 고려해서 평가해야 함.
ENAcceptance criteria for cybersecurity risks should carefully consider the TPLC of the medical device system, as it might be more difficult to mitigate cybersecurity issues once the device is marketed.KR사이버보안 위험에 대한 수용 기준은 의료기기 시스템의 전체 제품 수명주기(TPLC)를 신중하게 고려해야 합니다. 이는 장치가 시장에 출시된 이후에는 사이버보안 문제를 완화하기가 더 어려울 수 있기 때문입니다.
ENKnown vulnerabilities should be assessed as reasonably foreseeable risks.KR알려진 취약점은 합리적으로 예측 가능한 위험으로 평가되어야 합니다.
ENThe cybersecurity risk assessment for vulnerabilities identified during cybersecurity testing should also consider the TPLC of the device as the exploitability of the vulnerability is likely to increase over the device lifecycle. If a penetration tester, for example, was able to exploit a vulnerability, the ability of a threat actor to exploit that vulnerability is likely to increase over the device lifecycle.KR사이버보안 테스트 중에 식별된 취약점에 대한 위험 평가는 해당 장치의 TPLC를 고려해야 하며, 이는 장치 수명주기 동안 해당 취약점의 악용 가능성이 증가할 수 있기 때문입니다. 예를 들어, 침투 테스트자가 특정 취약점을 악용할 수 있었다면, 위협 행위자가 해당 취약점을 악용할 가능성도 장치 수명주기 동안 점점 높아질 수 있습니다.
ENFurthermore, vulnerabilities identified in CISA’s Known Exploited Vulnerabilities Catalog should be designed out of the device, as they are already being exploited and expose the medical device system and users to the risk.KR또한, CISA의 ‘Known Exploited Vulnerabilities Catalog(이미 악용된 취약점 목록)’에 등재된 취약점은 이미 실제로 악용되고 있으므로, 의료기기 시스템과 사용자에게 위험을 초래할 수 있으며, 장치 설계 단계에서 반드시 제거되어야 합니다.
시판 전 제출문서는 사이버보안 위험 평가를 포함함.
ENFDA recommends that the cybersecurity risk assessment provided in premarket submissions capture the risks and controls identified from the threat model.KR위험의 완화 전후 점수화 방법, 관련 수용 기준, 그리고 보안 위험을 안전 위험 평가 프로세스로 전환하는 방법 또한 시판 전 제출 문서에 함께 제공되어야 합니다.
ENThe methods used for scoring the risk pre- and post-mitigation and the associated acceptance criteria as well as the method for transferring security risks into the safety risk assessment process should also be provided as part of the premarket submission.KRFDA는 시판 전 제출 문서에 포함되는 사이버보안 위험 평가는 위협 모델에서 식별된 위험과 통제 수단을 반영할 것을 권장합니다.