SGS CYBERSECUIRTY SERVICESSGSྪஏҾඇޜခ௮ܾྼஓକ߸ܠ႑တࡽೕࡽዚࠅ
SGS்ڦᇼৠOur visionඤ൧႑LjओटظႎENTHUSIASM, INTEGRITY, POSITIVE, INNOVATIONࠓණኤऐࢅĂॠᄓ֪ڦණࠅाࡔSGSSGS IS THE WORLD’S LEADING TESTING, INSPECTION, AND CERTIFICATION COMPANYሞ்ڦ֪ĂॠᄓࢅණኤޜခଶᇘփظႎOUR EXPERTISE IN TESTING, INSPECTION, AND CERTIFICATION SERVICES IS CONSTANTLY INNOVATINGඇ൰ྺׯణՔڦ்ࠓခऐޜڦ૰ׂิࢅ૰ਏ৪ኛGLOBALLY COMPETITIVE AND PRODUCTIVE SERVICE ORGANIZATION๔ዕྺඇ൰ഓᄽခޜጆᄽࠃ༵ULTIMATELY PROVIDING PROFESSIONAL SERVICES TO GLOBAL ENTERPRISES
ํᄓՓքඇ൰LABORATORIES ARE SPREAD ALL OVER THE WORLDԛĂฉ࡛Ă࠽ዝĂศᒰĂઑĂԛࡔڪాॆࡔڪೢेĂႎࡔĂெࡔ݆૧ĂںનĂဇӬცĂӎࢁSGSྪஏҾඇํᄓCybersecuirty laboratory
SGSඇ൰ጨዊGlobal accreditationsࠓණኤऐࢅĂॠᄓ֪ڦණࠅाࡔSGS IS THE WORLD’S LEADING TESTING, INSPECTION, AND CERTIFICATION COMPANY
ெࡔFDAྪஏᇑ႑တҾඇᄲ൱FDA cybersecurity202212ሆ29නLjĖ2023ጹࢇծ݆ėധຈׯ݆ྺୱăጹڼࢇ3305ཉ — “ඓԍᅅଐยԢڦྪஏҾඇ” — Ⴊ۩କĖӺ๋Ăᄱࣅࢅጏ݆ӄė(FD&C݆ӄ)Ljཁेକڼ524Bཉ“ඓԍยԢڦྪஏҾඇ”(ڼ3305ཉ)ăጹࢇำLjFD&C݆ӄڦႪኟӄॽᇀ݆ӄӰքࢫ90ཀ(न20233ሆ29න)ิၳăOn December 29, 2022, the Consolidated Appropriations Act, 2023 (\"Omnibus\") was signed into law. Section 3305 of the Omnibus -- \"Ensuring Cybersecurity of Medical Devices\" -- amended the Federal Food, Drug, and Cosmetic Act (FD&C Act) by adding section 524B, Ensuring Cybersecurity of Devices (section 3305). The Omnibus states that the amendments to the FD&C Act shall take effect 90 days after the enactment of this Act, on March 29, 2023.༵ᅃݻऺࣄLjᅜሞࢇڦ้क़ాጡ൧॔੦Ă๎՚ࢅਦฉࢫྪஏҾඇ۴ࢅ۴LjԈઔၹۙᅃዂڦ۴ಽࢅ၎ײ࠲ႾăSubmit to the Secretary a plan to monitor, identify, and address, as appropriate,in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures.ยऺĂਸ݀ࢅྼࢺୁײࢅײႾLjᅜࢇԍኤยԢࢅ၎࠲ဣཥڦྪஏҾඇLjժྺยԢࢅ၎࠲ဣཥ༵ࠃฉࢫ߸ႎࢅցۡăDesign, develop, and maintain processes and procedures to provide a reasonableassurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems.༵ࠃॲଙൣڇLjԈઔฆᄽĂਸᇸࢅ၄ڦׯॲፇॲăProvide to the Secretary a software bill of materials, including commercial, open-source, and off-the-shelf software components.ஏҾඇăྪڦဣཥ࠲၎ࢅԍኤยԢࢇLjᅜࡀ݆ڦᄲ൱ഄࡤքԈీ࣏݀FDAThe FDA may also issue regulations with other requirements to demonstrate reasonable assurance that the device and related systems are cybersecure.
• ౹ዞᅅଐഗႁ݆ࡀ)MDR & IVDR)ᄲ൱ྪஏҾඇᄲ൱ǖ• ܔᇀԈࡤॲڦยԢईፕྺยԢԨวڦॲLjॲᆌӀቷ၄ᆶरຍೝႜਸ݀ࢅሰLjժ୯ڟਸ݀ิంዜĂᇱሶLjԈઔ႑တҾඇĂᄓڦ࠶၃ޅኤࢅඓණă• MDCGྪஏҾඇኸڞ࿔ॲ(201912ሆ)• ྪஏҾඇޅ၃/ᄲ൱Ⴔᄲሞޅڦ܀ڇ၃࠶ײࡗዐႜتLjࢇޙISO 14971ݛڦ)݆ଷ९AAMI TIR 57/SW 96)ă• ࢇޙᆯࡔॆऐࠓ݀քڦྪஏҾඇኸళ(ස BSIईANSM)ă• The European Medical Device Regulation (MDR&IVDR) requires cybersecurity requirements:• For devices containing software or software as the device itself, the software should be developed and manufactured according to the current level of technology, taking into account the principles of development lifecycle and risk management, including information security, verification, and confirmation.• MDCG Network Security Guidance Document (December 2019)• Cybersecurity risks/requirements need to be addressed in a separate risk, management process, in accordance with the methods of ISO 14971 (see also AAMI TIR 57/SW 96).• Compliant with cybersecurity guidelines issued by national institutions such as BSI or ANSM.౹MDRྪஏᇑ႑တҾඇᄲ൱MDR cybersecurityዐࡔNMPAྪஏᇑ႑တҾඇᄲ൱NMPA cybersecurityᅅଐഗႁྪஏҾඇጀ֩MEDICAL DEVICE CYBERSECURITY REGISTRATIONĖᅅଐഗႁጀ֩࠶Ӹ݆ėڼෙๆ຺ཉࡀۨLjݛࢺஏҾඇԍྪڦᅅଐഗႁ༵ړฤ൩ටᆌӄLjຫྪஏҾඇԍٯࢺแࢅरຍٯแLjᅈᅅଐഗႁݴૌ࠶ణतᆶ࠲रຍڪݔࡀڦᄲ൱LjඓྪஏҾඇԍٯࢺแࢅरຍٯแྜړᆌ࣏Ljฤ൩ට้ᄲ൱ăཞࢅྷݔᆩڦăݔࡀፕ֡ࢅ܈࠶ஏҾඇྪڦ࠲၎Article 34 of the Measures for the Administration of Medical Device Registration stipulates that the applicant shall submit a cybersecurity protection plan for the medical device, explain the cybersecurity protection measures and technical measures, and clarify the scope and requirements of the cybersecurity protection measures and technical measures in accordance with the requirements of the medical device classification management catalog and relevant technical specifications. At the same time, the applicant should also improve the relevant cybersecurity management system and operational standards.ᅅଐഗႁྪஏҾඇጀ֩रຍอֱኸڞᇱሶGUIDING PRINCIPLES FOR TECHNICAL REVIEW OF MEDICAL DEVICE CYBERSECURITY REGISTRATION• ඓକᅅଐഗႁׂݴڦૌՔጚǖݥຕጴࣅׂĂথຕጴࣅׂĂᆶথຕጴࣅׂࢅഴ๕ຕጴࣅׂă• ྜକरຍอֱాඹǖׂยऺĂຕدĂݡ࿚੦Ăे໙݆ĂҾඇ۴࠶ڪă• ेഽକኸڞᇱሶڦํ७Ⴀă• The classification criteria for medical device products have been clarified: non digital products, unconnected digital products, connected digital products, and embedded digital products.• Improved the technical review content, including product design, data transmission, access control, encryption algorithms, and security vulnerability management.• Enhanced the practicality of guiding principles.
֪ࢵఇFUZZINGཚࡗၠణՔဣཥईᆌᆩײႾۇٴଉໜऐĂփݔࡀईऑႚڦຕLj֪ഄሞᅴ൧ူڦႜྺࢅ࿘ۨႠă݀၄࿄ኪڦ۴Lj૩සԪએĂా٪ႅई࿄تڦᅴăTest the behavior and robustness of the target system or application under abnormal conditions by inputting a large amount of random, irregular, or malformed data. Discovering unknown vulnerabilities, such as crashes, memory leaks, or unprocessed exceptions.ࢃஓอپᇸSOURCE CODE REVIEWܔᆌᆩײႾڦᇸپஓႜဣཥႠॠֱLjᅜ݀၄യሞڦҾඇ࿚༶ă๎՚இडඍ။Ăپஓጀۅईഄ۴ăConduct systematic checks on the source code of the application to identify potential security issues. Identify logical defects, code injection points, or other vulnerabilities.าཪ֪PENETRATION TESTINGڦࣅۯईጲۯࡗLjཚྺႜڦऍኁ߿ెఇݛ๕ൔణՔဣཥᅜೠࠚഄҾඇႠă๎՚ဣཥዐڦෑۅLjժᄓኤ۴ڦํा૧ᆩీႠăSimulate the behavior of attackers and invade the target system manually or automatically to evaluate its security. Identify vulnerabilities in the system and verify their actual potential for exploitation.ࠚ၃ೠޅၾॺఇतྰTHREAT MODELING AND RISK ASSESSMENTဣཥႠں๎՚ဣཥዐയሞڦྰၾࢅ۴LjժݴဆኄၵྰၾڦీႠࢅᆖၚăIdentify potential threats and vulnerabilitiesin the system, and analyze the likelihood and impact of these threats.۴௮VULNERABILITY SCANNING๑ᆩጲ߾ࣅۯਏ௮ణՔဣཥईྪஏᅜॠ֪ᅙኪ۴ăUse automated tools to scan target systems or networks for known vulnerabilities.SGSᅅଐഗႁྪஏҾඇޜခSGS medical cybersecurity services
12/24/SGS cybersecuirty services_V1 © SGS Société Générale de Surveillance SA. (2024)www.sgs.comwww.sgsonline.com.cnဣ் CONTACT USฉ࡛ ShanghaiTel: +86 (0)21 6191 5670Emial: ee.shanghai@sgs.comศᒰ ShenzhenTel: +86 (0)755 2654 4661Emial: ee.shenzhen@sgs.comၑߗ HongkongTel: +852 2204 8343Emial: ee.hk@sgs.com࠽ዝ GuangzhouTel: +86 (0)20 8215 5411Emial: ee.guangzhou@sgs.comዘ൪ ChongqingTel: +86 (0)23 8553 8555Emial: ee.chongqing@sgs.com




