1. Labeling Recommendations
FDA는 장치 라벨링을 규제함.
ENFDA regulates device labeling in several ways.KRFDA는 장치 라벨링을 여러 방식으로 규제합니다.
ENFor example, section 502(f) of the FD&C Act requires that labeling include adequate directions for use.KR예를 들어, FD&C 법 제502(f)항은 라벨링에 적절한 사용 지침이 포함되어야 함을 요구합니다.
ENUnder section 502(a)(1) of the FD&C Act, a medical device is deemed misbranded if its labeling is false or misleading in any particular.KRFD&C 법 제502(a)(1)항에 따르면, 라벨링이 어떤 부분에서든 허위이거나 오해의 소지가 있는 경우 해당 의료기기는 허위 표시된 것으로 간주됩니다.
시판 전 제출문서는 라벨링을 포함함.
위험전가는 사용성 테스트를 고려해야 함.
ENWhen drafting labeling for inclusion in a premarket submission, a manufacturer should consider all applicable labeling requirements and how informing users through labeling may be an effective way to manage cybersecurity risks and/or to ensure the safe and effective use of the device.KR시판 전 제출 문서에 포함될 라벨링을 작성할 때, 제조사는 모든 관련 라벨링 요구사항을 고려하고, 라벨링을 통해 사용자에게 정보를 제공하는 것이 사이버보안 위험을 관리하거나 장치를 안전하고 효과적으로 사용하는 데 효과적인 방법이 될 수 있는지를 검토해야 합니다.
ENAny risks transferred to the user should be detailed and considered for inclusion as tasks during usability testing (e.g., human factors testing) to ensure that the type of user has the capability to take appropriate actions to manage those risks.KR사용자에게 전가되는 위험은 상세히 기술되어야 하며, 해당 위험을 사용자가 적절히 관리할 수 있도록 하기 위해 사용성 테스트(예: 인간 공학 테스트)에서 과제로 포함하는 것이 고려되어야 합니다.
라벨링에 포함되는 정보.
라벨링에 포함되는 정보
- Device instructions and product specifications related to recommended cybersecurity controls appropriate for the intended use environment (e.g., anti-malware software, use of a firewall, password requirements).
- 의도된 사용 환경에 적합한 권장 사이버보안 통제와 관련된 장치 사용 지침 및 제품 사양 (예: 악성코드 방지 소프트웨어, 방화벽 사용, 비밀번호 요구사항)
- Sufficiently detailed diagrams for users that allow recommended cybersecurity controls to be implemented.
- 사용자가 권장된 사이버보안 통제를 구현할 수 있도록 충분히 상세한 도표
- A list of network ports and other interfaces that are expected to receive and/or send data. This list should include a description of port functionality and indicate whether the ports are incoming, outgoing, or both, along with approved destination end-points.
- 데이터를 송수신할 것으로 예상되는 네트워크 포트 및 기타 인터페이스 목록. 이 목록에는 포트 기능 설명과 함께 포트가 수신용인지, 송신용인지, 또는 양방향인지, 그리고 승인된 목적지 엔드포인트가 포함되어야 함
- Specific guidance to users regarding supporting infrastructure requirements so that the device can operate as intended (e.g., minimum networking requirements, supported encryption interfaces). Where appropriate, such guidance should include technical instructions to permit secure network deployment and servicing, and instructions for users on how to respond upon detection of a cybersecurity vulnerability or incident.
- 장치가 의도대로 작동할 수 있도록 지원 인프라 요구사항에 대한 사용자 지침 (예: 최소 네트워크 요구사항, 지원되는 암호화 인터페이스). 적절한 경우, 보안 네트워크 배포 및 서비스 제공을 위한 기술 지침과 사이버보안 취약점 또는 사고 감지 시 사용자 대응 지침 포함
- An SBOM to effectively manage their assets, to understand the potential impact of identified vulnerabilities to the medical device system, and to deploy countermeasures to maintain the device’s safety and effectiveness. Manufacturers should provide or make available SBOM information to users on a continuous basis. If an online portal is used, manufacturers should ensure that users have up-to-date links that contain accurate information. The SBOM should be in a machine-readable format.
- SBOM. 이를 통해 자산을 효과적으로 관리하고, 식별된 취약점이 의료기기 시스템에 미치는 잠재적 영향을 이해하며, 장치의 안전성과 유효성을 유지하기 위한 대응책을 배포할 수 있음. 제조사는 사용자에게 지속적으로 SBOM 정보를 제공하거나 접근 가능하게 해야 하며, 온라인 포털을 사용하는 경우 최신 링크와 정확한 정보를 제공해야 함. SBOM은 기계 판독 가능한 형식이어야 함
- A description of systematic procedures for users to download version-identifiable manufacturer-authorized software and firmware, including a description of how users will know when software is available.
- 사용자가 제조사가 승인한 소프트웨어 및 펌웨어를 버전 식별 가능하게 다운로드할 수 있는 체계적인 절차에 대한 설명, 그리고 소프트웨어가 이용 가능함을 사용자가 인식할 수 있는 방법에 대한 설명
- A description of how the design enables the device to respond when anomalous conditions are detected (i.e., security events). This should include notification to the user and logging of relevant information. Security event types could be configuration changes, network anomalies, login attempts, or anomalous traffic (e.g., send requests to unknown entities).
- 설계가 이상 상태(즉, 보안 이벤트) 감지 시 장치가 어떻게 대응하는지를 설명. 여기에는 사용자 알림 및 관련 정보 로그 기록이 포함되어야 함. 보안 이벤트 유형에는 구성 변경, 네트워크 이상, 로그인 시도, 이상 트래픽(예: 알 수 없는 엔티티로의 전송 요청) 등이 포함될 수 있음
- A high-level description of the device features that protect critical functionality (e.g., backup mode, disabling ports/communications).
- 핵심 기능을 보호하는 장치 기능에 대한 상위 수준 설명 (예: 백업 모드, 포트/통신 비활성화)
- A description of backup and restore features and procedures to restore authenticated configurations.
- 인증된 구성 복원을 위한 백업 및 복원 기능 및 절차에 대한 설명
- A description of methods for retention and recovery of device configuration by an authenticated authorized user.
- 인증된 권한 있는 사용자가 장치 구성을 유지 및 복구할 수 있는 방법에 대한 설명
- A description of the secure configuration of shipped devices, instructions for user configurable changes, and identification of user-configurable changes that could increase security risk for the medical device system. Secure configurations may include end point protections such as anti-malware, firewall/firewall rules, allow lists, deny lists, security event parameters, logging parameters, and physical security detection, and resetting of credentials, among others.
- 출하된 장치의 보안 구성, 사용자 구성 변경에 대한 지침, 그리고 의료기기 시스템의 보안 위험을 증가시킬 수 있는 사용자 구성 변경 항목 식별. 보안 구성에는 악성코드 방지, 방화벽/방화벽 규칙, 허용 목록, 차단 목록, 보안 이벤트 매개변수, 로그 매개변수, 물리적 보안 감지, 자격 증명 재설정 등이 포함될 수 있음
- Where appropriate for the intended use environment, a description of how forensic evidence is captured, including but not limited to any log files kept for a security event. Log file descriptions should include how, where, and in what format the log file is located, stored, recycled, archived, and how it could be consumed by automated analysis software (e.g., Intrusion Detection System (IDS) or Security Information and Event Management (SIEM)).
- 의도된 사용 환경에 적절한 경우, 포렌식 증거 수집 방법에 대한 설명. 여기에는 보안 이벤트에 대해 유지되는 로그 파일이 포함될 수 있음. 로그 파일 설명에는 로그 파일이 어디에, 어떤 형식으로 위치하고 저장되며, 재활용되고, 보관되며, 자동 분석 소프트웨어(예: 침입 탐지 시스템(IDS) 또는 보안 정보 및 이벤트 관리(SIEM))에 의해 어떻게 활용될 수 있는지가 포함되어야 함
- Information, if known or anticipated, concerning device cybersecurity (including components) end of support and end of life. At the end of support, a manufacturer may no longer be able to reasonably provide security patches or software updates. If the device remains in service following the end of support, the manufacturer should have a preestablished and pre-communicated process for transferring the risks highlighting that the cybersecurity risks for end-users can be expected to increase over time.
- 장치 사이버보안(구성 요소 포함)의 지원 종료 및 수명 종료에 대한 정보(예상되는 경우 포함). 지원 종료 시 제조사는 더 이상 보안 패치나 소프트웨어 업데이트를 합리적으로 제공할 수 없을 수 있음. 장치가 지원 종료 이후에도 서비스에 남아 있는 경우, 제조사는 사용자에게 사이버보안 위험이 시간이 지남에 따라 증가할 수 있음을 강조하는 사전 수립 및 사전 전달된 위험 전이 절차를 마련해야 함
- Information on securely decommissioning devices by sanitizing the product of sensitive, confidential, and proprietary data and software.
- 민감한, 기밀성 있는, 독점적인 데이터 및 소프트웨어를 제품에서 제거하여 장치를 안전하게 폐기하는 방법에 대한 정보
참고 문서: 제조사 공개 성명서(MDS2) 및 JSP2에 명시된 고객 보안 문서.
ENA revision-controlled, Manufacturer Disclosure Statement for Medical Device Security (MDS2) and Customer Security Documentation as outlined in the Medical Device and Health IT Joint Security Plan version 2 (JSP2) may address a number of the above recommendations.KR시판 전 제출 문서에 포함될 라벨링을 작성할 때, 제조사는 모든 관련 라벨링 요구사항을 고려하고, 라벨링을 통해 사용자에게 정보를 제공하는 것이 사이버보안 위험을 관리하거나 장치를 안전하고 효과적으로 사용하는 데 효과적인 방법이 될 수 있는지를 검토해야 합니다.