米国 NISTIR 8428 運用技術(OT)向けデジタルフォレンジックおよびインシデント対応(DFIR)フレームワーク (2022.06.22)
こんにちは、丸山満彦です。
NISTがIR8428 運用技術(OT)向けデジタルフォレンジックおよびインシデント対応(DFIR)フレームワークを公表していますね...
OT向けのインシデンタオ対応フレームワークということで参考になることも多いかもとも思います...
アクティブ・ディフェンスとインシデントレスポンスの関係も...
⚫︎ NIST - ITL
・2022.06.22 Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT)
| Abstract | 概要 |
| This document provides a new Incident Handling framework dedicated to Operational Technology. This framework expands the traditional technical steps by giving an Incident Response procedure based on the event escalation and provides techniques for OT Digital Forensics. It includes an overview with general terms explanation and a list of unique properties of OT DFIR, the preparation that should be done to establish an OT Incident Response Team, and finally, the suggested OT Incident Handling framework in detail. | 本書は、オペレーショナル・テクノロジー(OT)に特化した新たなインシデントハンドリングフレームワークを提示するものである。本フレームワークは、事象のエスカレーションに基づくインシデント対応手順を提示することで従来の技術的ステップを拡張し、OTデジタルフォレンジックの手法を提供する。本書には、一般的な用語の解説やOT DFIRの特有の性質のリストを含む概要、OTインシデント対応チームを設立するために必要な準備、そして最後に、提案するOTインシデントハンドリングフレームワークの詳細が含まれている。 |
・[PDF] IR.8428
目次...
| 1 Introduction | 1 序論 |
| 1.1. Preface | 1.1. 序文 |
| 1.1.1. Main Incident Response challenge in OT | 1.1.1. OTにおけるインシデント対応の主な課題 |
| 1.1.2. Main Digital Forensic challenge in OT | 1.1.2. OTにおけるデジタルフォレンジクスの主な課題 |
| 1.2. Purpose and Scope | 1.2. 目的と範囲 |
| 1.3. Audience | 1.3. 対象読者 |
| 1.4. Document Structure | 1.4. ドキュメントの構成 |
| 2 Overview of OT DFIR | 2 OT DFIRの概要 |
| 2.1. DFIR in general | 2.1. DFIRの概要 |
| 2.1.1. Active Defense | 2.1.1. 積極的な防衛 |
| 2.1.2. Incident Response | 2.1.2. インシデント対応 |
| 2.1.3. Digital Forensics | 2.1.3. デジタルフォレンジック |
| 2.2. OT DFIR Unique Properties | 2.2. OT DFIRの特有の性質 |
| 2.2.1. Properties that affect OT Incident Response | 2.2.1. OTインシデント対応に影響を与える特性 |
| 2.2.2. Properties that affect OT Digital Forensic | 2.2.2. OTデジタルフォレンジックに影響を与える特性 |
| 3 OT DFIR Preparation | 3 OT DFIRの準備 |
| 3.1. Incident Response Team | 3.1. インシデント対応チーム |
| 3.1.1. Roles and Responsibilities | 3.1.1. 役割と責任 |
| 3.1.2. Tool Kit | 3.1.2. ツールキット |
| 3.1.3. Situation Room | 3.1.3. 状況室 |
| 3.1.4. Training and practice | 3.1.4. 訓練と演習 |
| 3.2. Digital Forensic Lab | 3.2. デジタルフォレンジックラボ |
| 3.2.1. Hardware | 3.2.1. ハードウェア |
| 3.2.2. Software | 3.2.2. ソフトウェア |
| 3.3. Preparations in the field OT systems | 3.3. OTシステムにおける現場の準備 |
| 4 OT DFIR Framework | 4 OT DFIRフレームワーク |
| 4.1. The Framework | 4.1. フレームワーク |
| 4.2. The Detailed Process | 4.2. 詳細なプロセス |
| 4.2.1. Routine | 4.2.1. ルーチン |
| 4.2.2. Initial Identification and Reporting | 4.2.2. 初期の特定と報告 |
| 4.2.3. Technical Event Handling | 4.2.3. 技術的インシデント対応 |
| 4.2.4. Cyber Incident Analysis and Response | 4.2.4. サイバーインシデントの分析と対応 |
| 4.2.5. End of Cyber Incident | 4.2.5. サイバーインシデントの終了 |
| 4.2.6. Post-Incident | 4.2.6. インシデント後 |
| References | 参考文献 |
| Appendix A: Acronyms and Abbreviations | 附属書A:略語および頭字語 |
| Appendix B: OT DFIR Framework – A suggested small-scale organization implementation | 附属書B:OT DFIRフレームワーク – 小規模組織向け 実装の提案 |
プロセス全体
« 米国 GAO 来年度 (FY23) の予算要求額は8億1,030万ドル(約1兆700億円)サイバーセキュリティも強化項目 | Main | NIST SP 1800-34 (ドラフト) コンピューティングデバイスの完全性の検証 »




Comments