こんにちは、丸山満彦です。
U.S. GAOが2020.02.25に重要インフラストラクチャの保護として「(サイバーセキュリティ)フレームワークの採用とその結果としての改善点を特定するために必要な追加措置」についての報告書を公表しています。監査して時点から報告書を公表するまでに時間があるので、その間に色々と改善もされていますが、米国のGAOの働きについては、改善を促す意味でも非常に良い働きをしていますよね。。。
● GAO (Government Accountability Office)
・2020.02.25 GAO-20-299 CRITICAL INFRASTRUCTURE PROTECTION:Additional Actions Needed to Identify Framework Adoption and Resulting Improvements
・Report
[PDF] Highlights Page
[PDF] Full Report
=====
All 12 organizations in our review were voluntarily using the framework, and told us they’ve seen benefits. For example, one organization said that the framework allowed it to better identify and address cybersecurity risks.
However, the agencies with lead roles in protecting critical infrastructure are not collecting or reporting on improvements from using the framework as we recommended.
DeepLによる機械翻訳
私たちのレビューに参加した12の組織は、すべて自発的にこのフレームワークを使用しており、その効果を実感していると述べています。例えば、ある組織では、フレームワークのおかげでサイバーセキュリティのリスクをよりよく特定し、対処できるようになったと述べています。
しかし、重要インフラストラクチャの保護に主導的な役割を果たす機関は、私たちが推奨したようにフレームワークの使用による改善点を収集したり、報告したりしていません。
=====
・Recommendations for Executive Action (Summary)
(01) The Director of NIST should establish time frames for completing NIST's initiatives, to include the information security measThe Administrator of the General Services Administration, in coordination with the Secretary of Homeland Security, should take steps to consult with respective sector partner(s), such as the Coordinating Council and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
urement program and the cybersecurity framework starter profile, to enable the identification of sector-wide improvements from using the framework in the protection of critical infrastructure from cyber threats.
(02) The Secretary of Agriculture, in coordination with the Secretary of Health and Human Services, should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(03) The Secretary of Defense should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(04) The Secretary of Energy should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(05) The Administrator of the Environmental Protection Agency should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(06) The Administrator of the General Services Administration, in coordination with the Secretary of Homeland Security, should take steps to consult with respective sector partner(s), such as the Coordinating Council and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(07) The Secretary of Health and Human Services, in coordination with the Secretary of Agriculture, should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(08) The Secretary of Homeland Security should take steps to consult with respective sector partner(s), such as the SCC and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sectors using existing initiatives.
(09) The Secretary of Transportation, in coordination with the Secretary of Homeland Security, should take steps to consult with respective sector partner(s) such as the SCC and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
(10) The Secretary of the Treasury should take steps to consult with respective sector partner(s), such as the SCC, DHS, and NIST, as appropriate, to collect and report sector-wide improvements from use of the framework across its critical infrastructure sector using existing initiatives.
Recent Comments