2. Cybersecurity Management Plans
제조사는 식별된 식약점을 관련 당사자에게 전달하기 위한 계획을 수립해야 함. (21 CFR 820.100 및 21 CFR Part 806)
ENFDA recommends that manufacturers establish a plan for how they will identify and communicate to the relevant parties the vulnerabilities that are identified after releasing the device in accordance with the 21 CFR 820.100 and 21 CFR Part 806, as appropriate.KRFDA는 제조사가 장치 출시 이후 식별된 (외부에서 발견된 범용) 취약점을 관련 당사자에게 어떻게 (우리 기기애 실제 적용가능한 취약점인지를) 식별하고 전달할 것인지에 대한 계획을 21 CFR 820.100 및 21 CFR Part 806에 따라 수립할 것을 권장합니다.
시판 전 제출문서는 사이버보안 관리 계획을 포함함.
ENFDA recommends that manufacturers submit their cybersecurity management plans as part of their premarket submissions. . For cyber devices, “a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures” is required (see section 524B(b)(1) of the FD&C Act).KRFDA는 제조사가 시판 전 제출 문서에 사이버보안 관리 계획을 포함시킬 것을 권장합니다. 사이버 장치의 경우, “출시 후 사이버보안 취약점 및 악용 가능성을 합리적인 시간 내에 모니터링, 식별 및 적절히 대응하기 위한 계획(통합된 취약점 공개 및 관련 절차 포함)”이 요구됩니다(FD&C 법 제524B(b)(1)항)
사이버보안 관리 계획의 구성 요소.
사이버보안 관리 계획의 구성 요소
- Personnel responsible;
- 담당 인력;
- Sources, methods, and frequency for monitoring and identifying vulnerabilities (e.g., researchers, NIST national vulnerability database (NIST NVD), third-party software manufacturers);
- 취약점 모니터링 및 식별을 위한 출처, 방법, 빈도 (예: 연구자, NIST 국가 취약점 데이터베이스(NIST NVD), 제3자 소프트웨어 제조업체);
- Identify and address vulnerabilities identified in CISA’s Known Exploited Vulnerabilities Catalog;
- CISA의 Known Exploited Vulnerabilities Catalog에 식별된 취약점 식별 및 대응;
- Periodic security testing;
- 주기적 보안 테스트;
- Timeline to develop and release patches;
- 패치 개발 및 배포 일정;
- Update processes;
- 업데이트 프로세스;
- Patching capability (i.e., rate at which update can be delivered to devices);
- 패치 적용 능력 (즉, 업데이트가 기기에 전달될 수 있는 속도);
- Description of their coordinated vulnerability disclosure process; and
- 조율된 취약점 공개(Coordinated Vulnerability Disclosure) 프로세스 설명;
- Description of how the manufacturer intends to communicate forthcoming remediations, patches, and updates to customers.
- 제조업체가 향후 보완 조치, 패치 및 업데이트를 고객에게 전달하려는 방식 설명.