「Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions」(最新版Final Guidance,於2026年2月3日發布

2026 年指引的核心精神

  FDA 要求醫療器材必須做到:
     • Secure by Design(安全設計)
     • Secure by Default(預設安全)
     • Secure Throughout the Product Lifecycle(全生命週期維護)
       意指產品從設計、開發、驗證、生產、上市到停產,都必須持續管理網路安全。

FDA 要求建立 SPDF(Secure Product Development Framework)

  SPDF 是 FDA 最重要的要求,應至少包含:
     1. 網路安全政策
     2. 安全需求分析
     3. Threat Modeling(威脅模型)
     4. 安全架構設計
     5. Secure Coding
     6. 軟體組態管理
     7. 弱點管理
     8. Security Verification
     9. Penetration Testing
     10. 上市後漏洞監測
     FDA 希望網路安全活動整合至 ISO 13485/QMSR 品質系統,而非獨立存在。

威脅模型Threat Modeling

  FDA 特別要求建立威脅模型,例如:
     • STRIDE
     • Attack Tree
     • MITRE ATT&CK
     • MITRE CAPEC
  需分析:
     • 攻擊者
     • 攻擊路徑
     • 被攻擊資產
     • 安全控制措施
     • 殘餘風險

安全驗證(Security Verification)

  FDA 建議提供:
     • Vulnerability Assessment
     • Penetration Test
     • Fuzz Testing
     • Static Code Analysis
     • Dynamic Analysis
     • Software Composition Analysis (SCA)
     • Secure Configuration Review
     • Authentication Testing
     • Encryption Verification