Skip to main content

5. Security Assessment of Unresolved Anomalies

시판 전 제출문서는 Anomaly(이상) 목록을 포함함.
ENFDA’s Premarket Software Guidance recommends that device manufacturers provide a list of software anomalies that exist in a product at the time of submission.
KRFDA의 시판 전 소프트웨어 지침은 제조사가 제출 시점에 제품에 존재하는 소프트웨어 이상(anomaly) 목록을 제공할 것을 권장합니다.
제조사는 Anamaly를 평가할 때는 보안과 알려진 CWE (공통 취약점 분류)애 대해서도 고려해야 함.
ENSome anomalies discovered during development or testing may require an assessment of potential security impacts.
KR개발 또는 테스트 중에 발견된 일부 이상은 보안에 미칠 수 있는 잠재적 영향에 대한 평가를 포함할 수 있습니다.
ENThe assessment should also include consideration of any present Common Weakness Enumeration (CWE) categories.
KR또한, 평가에는 현재 존재하는 CWE(Common Weakness Enumeration, 공통 취약점 분류) 범주에 대한 고려도 포함되어야 합니다.
ENFor example, a clinical user may inadvertently reveal the presence of a previously unknown software anomaly during normal use, where the impact of the anomaly might occur sporadically and be assessed to be acceptable from a software risk perspective. Conversely, a threat might seek out these types of anomalies, and identify means to exploit them in order to manifest the anomaly’s impact continuously, which could significantly impact the acceptability of the risk when compared to an anomaly assessment that didn’t include security considerations.
KR예를 들어, 임상 사용자가 정상적인 사용 중에 이전에 알려지지 않았던 소프트웨어 이상을 우연히 드러낼 수 있으며, 이 이상은 간헐적으로 발생하고 소프트웨어 위험 관점에서 수용 가능한 것으로 평가될 수 있습니다. 반면, 위협 행위자는 이러한 유형의 이상을 의도적으로 찾아내어 이를 지속적으로 악용할 수 있는 방법을 식별할 수 있으며, 이는 보안 고려가 포함되지 않은 이상 평가와 비교할 때 위험 수용 가능성에 중대한 영향을 미칠 수 있습니다.
시판 전 제출문서는 Anomalies를 해결하기 위한 기준과 근거를 포함함.
ENThe criteria and rationales for addressing the resulting anomalies with security impacts should be provided as part of documentation in the premarket submission.
KR보안 영향을 수반하는 이상(anomalies)을 해결하기 위한 기준과 근거는 시판 전 제출 문서의 일부로 제공되어야 합니다.