6. TPLC Security Risk Management
제조사는 TPLC 동안 지속적으로 사이버보안을 식별하고 이를 위한 자원을 확보해야 함.
ENCybersecurity risks may continue to be identified throughout the device’s TPLC. Manufacturers should ensure they have appropriate resources to identify, assess, and mitigate cybersecurity vulnerabilities as they are identified throughout the supported device lifecycle.KR사이버보안 위험은 장치의 전체 제품 수명주기(TPLC) 동안 지속적으로 식별될 수 있습니다. 제조사는 지원되는 장치 수명주기 전반에 걸쳐 사이버보안 취약점을 식별, 평가 및 완화할 수 있는 적절한 자원을 확보해야 합니다.
제조사는 TPLC 동안 새로운 위협, 취약점, 자산 또는 부정적인 영향이 발견될 경우 보안 위험 관리 문서를 업데이트해야 함.
ENAs part of using an SPDF, manufacturers should update their security risk management documentation as new information becomes available, such as when new threats, vulnerabilities, assets, or adverse impacts are discovered during development and after the device is released.KRSPDF를 사용하는 일환으로, 제조사는 개발 중 또는 장치 출시 이후에 새로운 위협, 취약점, 자산 또는 부정적인 영향이 발견될 경우 보안 위험 관리 문서를 업데이트해야 합니다.
ENWhen maintained throughout the device lifecycle, this documentation (e.g., threat modeling, cybersecurity risk assessment) can be used to quickly identify vulnerability impacts once a device is released and, when appropriate, to support timely corrective and preventive action activities described in 21 CFR 820.100.KR이러한 문서를 장치 수명주기 전반에 걸쳐 유지하면, 장치가 출시된 이후 취약점의 영향을 신속하게 식별할 수 있으며, 필요 시 21 CFR 820.100에 명시된 시기적절한 시정 및 예방 조치 활동을 지원하는 데 활용될 수 있습니다.
제조사는 업데이트, 패치와 관련된 지표의 측정값 및 평균값을 기록하고 PMA 제출 및 연례 보고서에 포함해야 함.
ENFDA recommends that a manufacturer track and record the measures and metrics below, and provide them in premarket submissions and PMA annual reports (21 CFR 814.84), when available.KR제조사의 프로세스 효과성을 입증하기 위해, FDA는 제조사가 아래의 지표와 측정값을 추적 및 기록하고, 가능할 경우 이를 시판 전 제출 문서 및 PMA 연례 보고서(21 CFR 814.84)에 포함할 것을 권장합니다.
ENAverages of the above measures should be provided if multiple vulnerabilities are identified and addressed.KR여러 개의 취약점이 식별되고 해결된 경우, 위에서 언급한 측정값들의 평균치를 제공해야 합니다.
업데이트, 패치와 관련된 지표
- Percentage of identified vulnerabilities that are updated or patched (defect density);
- 식별된 취약점 중 업데이트되거나 패치된 비율(결함 밀도)
- Duration from vulnerability identification to when it is updated or patched; and
- 취약점이 식별된 시점부터 업데이트 또는 패치가 적용된 시점까지의 소요 시간
- Duration from when an update or patch is available to complete implementation in devices deployed in the field, to the extent known.
- 업데이트 또는 패치가 제공된 시점부터 현장에 배포된 장치에 완전히 적용되기까지의 소요 시간(알려진 범위 내에서)