2. Documentation Supporting SBOM
SBOM 구성 요소.
ENManufacturers should provide machine-readable SBOMs consistent with the minimum elements (also referred to as “baseline attributes”) identified in the October 2021 National Telecommunications and Information Administration (NTIA)KR제조사는 2021년 10월 미국 국가통신정보청(NTIA)의 다자간 협의 과정에서 발표된 「소프트웨어 구성요소 투명성의 틀: 공통 SBOM 수립」 문서에 명시된 최소 요소(“기준 속성”이라고도 함)에 부합하는 기계 판독 가능한 SBOM을 제공해야 합니다.
SBOM 구성요소
- Requests by NTIA
- Author Name;
- Timestamp;
- Supplier Name;
- Component Name;
- Version String;
- Component Hash;
- Unique Identifier;
- Relationship;
- Additional requests by FDA
- The software level of support provided through monitoring and maintenance from the software component manufacturer (e.g., the software is actively maintained, no longer maintained, abandoned); and
- The software component’s end-of-support date.
시판 전 제출문서는 알려진 취약점이 있는 구성요소(SBOM)을 포함함.
ENAs part of the premarket submission, manufacturers should also identify all known vulnerabilities associated with the device and the software components, including those identified in CISA’s Known Exploited Vulnerabilities Catalog.KR장치 및 소프트웨어 구성요소와 관련된 취약점(예: CISA의 알려진 악용 취약점 목록에 포함된 항목 포함)에 대해, 각 알려진 취약점에 대해 제조사는 해당 취약점이 어떻게 발견되었는지를 설명하여 평가 방법이 충분히 견고했는지를 입증해야 합니다.
ENFor each known vulnerability, manufacturers should describe how the vulnerabilities were discovered to demonstrate whether the assessment methods were sufficiently robust. For components with known vulnerabilities, device manufacturers should provide in premarket submissions:KR알려진 취약점이 있는 구성요소에 대해서는 장치 제조사가 시판 전 제출 문서에 다음 사항을 포함해야 합니다:
알려진 취약점에 대한 위험 평가
- A safety and security risk assessment of each known vulnerability (including device and system impacts); and
- 각 알려진 취약점에 대한 안전 및 보안 위험 평가(장치 및 시스템에 미치는 영향 포함)
- Details of applicable safety and security risk controls to address the vulnerability. If risk controls include compensating controls, those should be described in an appropriate level of detail.
- 해당 취약점을 해결하기 위한 적용 가능한 안전 및 보안 위험 통제에 대한 세부사항. 위험 통제에 보완적 통제 수단이 포함되는 경우, 그에 대한 설명도 적절한 수준의 세부사항으로 제공되어야 합니다.