4. Third-Party Software Components
제3자 소프트웨어의 사용.
ENMedical devices commonly include third-party software components, including off-the-shelf and open source software.KR의료기기에는 일반적으로 기성 소프트웨어 및 오픈 소스 소프트웨어를 포함한 제3자 소프트웨어 구성요소가 포함됩니다.
제조사는 제3자 소프트웨어의 사이버보안 위험에 대해 평가해야 함.
ENAll software, including those developed by the device manufacturer (“proprietary software”) or obtained from third parties, should be assessed for cybersecurity risk.KR장치 제조사가 개발한 소프트웨어(“자사 독점 소프트웨어”)는 물론 제3자로부터 제공받은 모든 소프트웨어는 사이버보안 위험에 대해 평가되어야 합니다.
ENDevice manufacturers should document all software components of a device and address or otherwise mitigate risks associated with these software components.KR장치 제조사는 장치에 포함된 모든 소프트웨어 구성요소를 문서화하고, 이들 구성요소와 관련된 위험을 해결하거나 적절히 완화해야 합니다.
제조사는 공급업체 관리 프로세스를 수립해야 함.
ENIn addition, under 21 CFR 820.50, a manufacturer must put in place processes and controls to ensure that its suppliers conform to the manufacturer’s requirements.KR또한, 21 CFR 820.50에 따라 제조사는 공급사가 제조사의 요구사항을 준수하도록 보장하기 위한 프로세스와 통제 수단을 마련해야 합니다.
ENSuch information is documented in the Design History File, required by 21 CFR 820.30(j), and Device Master Record, required by 21 CFR 820.181.KR이러한 정보는 21 CFR 820.30(j)에서 요구되는 설계 이력 파일(Design History File)과 21 CFR 820.181에서 요구되는 장치 마스터 기록(Device Master Record)에 문서화됩니다.
제조사는 (공급사) 소프트웨어 소스 코드의 관리 권한을 설정하고 유지해야 함.
ENSoftware is updated over time to provide additional features, address security concerns, and otherwise be maintained.KR소프트웨어는 시간이 지남에 따라 새로운 기능을 추가하고, 보안 문제를 해결하며, 유지 관리를 위해 업데이트됩니다.
ENThese changes may introduce new considerations or risks that must be accounted for as part of risk management.KR이러한 변경 사항은 위험 관리의 일환으로 고려되어야 할 새로운 요소나 위험을 초래할 수 있습니다.
ENAs a result, device manufacturers should establish and maintain custodial control of device source code (the original “copy” of the software) throughout the lifecycle of a device as part of configuration management.KR따라서 장치 제조사는 구성 관리의 일환으로 장치의 전체 수명주기 동안 소스 코드(소프트웨어의 원본 “사본”)에 대한 관리 권한을 설정하고 유지해야 합니다.
ENThis may be accomplished through different methods, such as source code escrow or source code backups, among others.KR이는 소스 코드 에스크로(source code escrow)나 소스 코드 백업 등 다양한 방법을 통해 수행될 수 있습니다.
공급사 소프트웨어 소스 코드의 통제권이 없는 경우의 고려사항.
ENManufacturers may not have control of source code due to licensing restrictions, terms of supplier agreements, or other challenges.KR제조사는 라이선스 제한, 공급업체 계약 조건 또는 기타 문제로 인해 소스 코드에 대한 통제권을 갖지 못할 수 있습니다.
ENWhile source code is not required to be provided in premarket submissions, manufacturers should include plans for how third-party software components could be updated or replaced if support ends or other software issues arise in premarket submissions.KR시판 전 제출 문서에 소스 코드를 반드시 포함할 필요는 없지만, 제조사는 제3자 소프트웨어 구성요소에 대한 지원이 종료되거나 기타 소프트웨어 문제가 발생할 경우 이를 어떻게 업데이트하거나 교체할 것인지에 대한 계획을 포함해야 합니다.
ENThe device manufacturer should also provide users with whatever information they may need in the device labeling to allow them to manage risks associated with the software components, including known vulnerabilities, configuration specifications, and other relevant security and risk management considerations.KR또한, 장치 제조사는 사용자에게 소프트웨어 구성요소와 관련된 위험을 관리할 수 있도록 필요한 정보를 장치 라벨링에 제공해야 하며, 여기에는 알려진 취약점, 구성 사양, 기타 관련된 보안 및 위험 관리 고려사항이 포함됩니다.