FDA网络安全对标签的要求

2023年9月27日,FDA发布医疗器械网络安全指南,重点介绍软件网络安全质量体系考虑因素和上市前提交的内容。该指南取代2014年10月2日发布的医疗器械网络安全管理上市前提交文件的内容。目前该指南已经执行,如果准备的递交资料不符合要求会引申发补,从而影响递交的进度甚至最后的结果,需要引起重视。
该指南对网络安全的多个方面提出了要求。设备标签也是FDA关于网络安全重点关注的内容,那么下面就来介绍一下设备标签如何满足该指南的要求。
FDA以多种方式监管器械标签,例如FD&C法案第502(f)节的要求。
对于存在网络安全风险的设备,告知用户相关安全信息是控制标签风险相关的有效措施,有助于减轻网络安全风险和确保设备的持续安全性和有效性。因此,在设计标签时,制造商应考虑所有适用的标签要求,以确保用户采取适当的措施来管理这些风险。
网络安全风险的说明应该为用户所理解,广大厂商应采用有效的方法来确保标签信息能被用户所理解。
以下是指南为制造商提供的标签中的信息示例:
1.制造商需要结合申报产品针对网络风险进行的控制措施(需考虑预期使用环境),识别与控制措施相关联的器械说明以及规格的相关信息,补充到设备标签中,例如:说明是否使用反恶意软件、使用防火墙、密码等。
指南原文:Device instructions and product specifications related to recommended cybersecurity controls appropriate for the intended use environment (e.g., anti-malware software, use of a firewall, password requirements).
2.制造商需要在设备标签中提供足够的相关信息(建议尽量用图表方式),以便用户实施需要他们做的网络安全控制措施。
指南原文:Sufficiently detailed diagrams for users that allow recommended cybersecurity controls to be implemented.
3.制造商需要在设备标签中提供网络端口和其他接口的相关信息,具体要求如下:
√预期接收和/或发送数据的网络端口和其他接口的列表,
√并在该列表包括各端口功能的描述,并指明端口是输入端口、输出端口还是两者都有,以及批准的目标终点。
指南原文:A list of network ports and other interfaces that are expected to receive and/or send data. This list should include a description of port functionality and indicate whether the ports are incoming, outgoing, or both, along with approved destination end-points.
4.制造商需要在设备标签中提供支持与网络安全功能相关的infrastructure需求的具体指导的内容,以便产品可以按照预期运行,例如:如最低网络要求,支持的加密接口等。
备注:如申报产品适用的情况下,建议提供的以上指导的内容应该包括:
√确保安全网络部署和服务的技术说明;
√指导用户在检测到网络安全漏洞或事故时如何响应的说明。
指南原文:Specific guidance to users regarding supporting infrastructure requirements so that the device can operate as intended (e.g., minimum networking requirements, supported encryption interfaces). Where appropriate, such guidance should include technical instructions to permit secure network deployment and servicing, and instructions for users on how to respond upon detection of a cybersecurity vulnerability or incident.
5.制造商需要在设备标签中提供SBOM(软件物料清单)。
√需要保持持续动态的方式让用户通过设备标签可以获得SBOM;
√如果使用在线官方网站提供,应确保设备标签中的链接是可及时获取准确信息的最新链接;
√SBOM应该是机器可读的格式。
指南原文:An SBOM as specified in Section V.A.4. or in accordance with an industry accepted format to effectively manage their assets, to understand the potential impact of identified vulnerabilities to the medical device system, and to deploy countermeasures to maintain the device’s safety and effectiveness. Manufacturers should provide or make available SBOM information to users on a continuous basis. If an online portal is used, manufacturers should ensure that users have up-to-date links that contain accurate information. The SBOM should be in a machine-readable format.
6.制造商需要设备标签提供系统程序的描述,以确保用户可以下载可识别版本的授权软件和固件,同时需要提供用户如何知道软件何时可用的说明的描述说明。
指南原文:A description of systematic procedures for users to download version-identifiable manufacturer-authorized software and firmware, including a description of how users will know when software is available.
7.制造商需要在设备标签中提供描述产品的设计是如何确保在器械监测到到异常情况(即安全事件)时做出响应,例如:设计方面包括通知用户、记录相关信息等。
指南原文:A description of how the design enables the device to respond when anomalous conditions are detected (i.e., security events). This should include notification to the user and logging of relevant information. Security event types could be configuration changes, network anomalies, login attempts, or anomalous traffic (e.g., send requests to unknown entities).
8.制造商需要在设备标签中提供针对保护关键功能(如备份模式、禁用端口/通信等)的相关的器械特性的描述。
指南原文:A high-level description of the device features that protect critical functionality (e.g., backup mode, disabling ports/communications).
9.制造商需要在设备标签中提供备份和恢复功能的描述、以及恢复经过身份验证的配置的过程的描述。
指南原文:A description of backup and restore features and procedures to restore authenticated configurations.
10.制造商需要在设备标签中添加由经过身份验证的授权用户保留和恢复设备配置的方法说明。
指南原文:A description of methods for retention and recovery of device configuration by an authenticated authorized user.
11.制造商需要在设备标签提供如下描述:
√对出厂设备安全配置的描述
√用户可配置更改的说明
√对可能增加医疗设备系统安全风险的用户可配置更改的识别
√安全配置可包括终端保护,如反恶意软件、防火墙/防火墙规则、允许列表、拒绝列表、安全事件参数、日志记录参数、物理安全检测和凭证重置等。
指南原文:A description of the secure configuration of shipped devices, instructions for user configurable changes, and identification of user-configurable changes that could increase security risk for the medical device system. Secure configurations may include end point protections such as anti-malware, firewall/firewall rules, allow lists, deny lists, security event parameters, logging parameters, and physical security detection, and resetting of credentials, among others.
12.制造商需要在设备标签中说明如何获取取证证据,包括但不限于为安全事件保存的任何日志文件。并提供日志文件描述,应包括日志文件的位置、存储、回收、归档方式和格式,以及自动分析软件(如入侵检测系统 (IDS) 或安全信息与事件管理 (SIEM))如何使用日志文件。
指南原文:Where appropriate for the intended use environment, a description of how forensic evidence is captured, including but not limited to any log files kept for a security event. Log file descriptions should include how, where, and in what format the log file is located, stored, recycled, archived, and how it could be consumed by automated analysis software (e.g., Intrusion Detection System (IDS) or Security Information and Event Management (SIEM)).
13.制造商需要在设备标签中提供有关设备网络安全(包括组件)支持终止和使用寿命终止的已知或预期信息。在支持结束时,如制造商无法再合理地提供安全补丁或软件更新,如果设备在支持结束后仍在使用,生产商应预先制定和沟通风险转移流程,强调最终用户的网络安全风险可能会随着时间的推移而增加。
指南原文:Information, if known or anticipated, concerning device cybersecurity (including components) end of support and end of life. At the end of support, a manufacturer may no longer be able to reasonably provide security patches or software updates. If the device remains in service following the end of support, the manufacturer should have a preestablished and pre-communicated process for transferring the risks highlighting that the cybersecurity risks for end-users can be expected to increase over time.
14.制造商需要在设备标签中补充相关的信息,以说明通过清理敏感、机密和专有数据和软件来确保器械安全退市。
指南原文:Information on securely decommissioning devices by sanitizing the product of sensitive, confidential, and proprietary data and software.
另外,医疗设备和健康IT联合安全计划(Medical Device and Health IT joint Security Plan,简称JSP),医疗设备安全制造商披露声明(Manufacturer Disclosure Statement for Medical Device Security,简称:MDS2)可以解决上述的部分建议。
同时,制造商们可以参考IEC TR 80001-2-2、IEC TR 80001-2-8和IEC TR 80001-2-9等标准进一步了解关于网络安全风险的设备标签信息。