欧州委員会 EUのサイバー危機調整を強化するための新たなサイバーセキュリティ青写真 (2024.02.24)
こんにちは、丸山満彦です。
欧州委員会が、EUのサイバー危機調整を強化するためのサイバーセキュリティ青写真を発表し、意見募集をしていますね。。。
提案の分野は...
I: EUサイバー危機管理枠組みの枠組み、範囲、原則
II: 連邦レベルのサイバー危機に備える
(a) 状況認識と情報
(b) 一般的な演習
(c) DNS解決機能
(d) リソース
III: サイバー危機に発展しかねないインシデントの検知
IV: 連邦レベルでのサイバー危機への対応
V: サイバー回復
VI: 安全なコミュニケーション
VII: サイバー危機と軍事アクターとの調整
VIII: 戦略的協力
● European Commission
プレス...
・2025.02.24 Commission launches new cybersecurity blueprint to enhance EU cyber crisis coordination
| Commission launches new cybersecurity blueprint to enhance EU cyber crisis coordination | 欧州委員会、EUのサイバー危機調整を強化するための新たなサイバーセキュリティ青写真を発表 |
| The Commission has presented a proposal to ensure an effective and efficient response to large-scale cyber incidents. | 欧州委員会は、大規模サイバーセキュリティインシデントへの効果的かつ効率的な対応を確保するための提案を発表した。 |
| The proposed blueprint updates the comprehensive EU framework for Cybersecurity Crisis Management and maps the relevant EU actors, outlining their roles throughout the entire crisis lifecycle. This includes preparedness and shared situational awareness to anticipate cyber incidents, and the necessary detection capabilities to identify them, including the response and recovery tools needed to mitigate, deter and contain those incidents. | 提案された青写真は、サイバーセキュリティ危機管理のための包括的なEUの枠組みを更新し、EUの関係者をマッピングし、危機のライフサイクル全体を通してのそれぞれの役割を概説している。これには、サイバーインシデントを予期するための準備と状況認識の共有、インシデントを緩和、抑止、封じ込めるために必要な対応・復旧ツールを含む、インシデントを特定するために必要な検知能力が含まれる。 |
| Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said: | ヘンナ・ヴィルクネン副総裁(技術主権・安全保障・民主主義担当)は、次のように述べた: |
| "In an increasingly interdependent Union economy, disruptions from cybersecurity incidents can have far-reaching impacts across various sectors. The proposed cybersecurity blueprint reflects our commitment to ensuring a coordinated approach, leveraging existing structures to protect the internal market and uphold vital societal functions. This Recommendation is a crucial step forward in reinforcing our collective cyber resilience." | 「相互依存が高まる連合経済において、サイバーセキュリティインシデントによる混乱は、さまざまな部門に広範囲な影響を及ぼす可能性がある。提案されているサイバーセキュリティの青写真は、域内市場を保護し、重要な社会機能を維持するための既存の構造を活用し、協調的なアプローチを確保するという我々のコミットメントを反映している。この勧告は、我々の集団的なサイバーレジリエンスを強化する上で極めて重要な前進である。 |
| The proposed plan builds on the existing frameworks, such as the Integrated Political Crisis Response and the EU Cyber Diplomacy Toolbox, while aligning with recently adopted initiatives, such as the Critical Infrastructure Blueprint and the network code on cybersecurity for the EU electricity sector. It proposes measures to strengthen collaboration between civilian and military entities, including NATO, while reflecting the objectives of the forthcoming EU preparedness strategy. Furthermore, this proposal promotes secure communication and strategic efforts to counter disinformation. | 提案されている計画は、統合された政治的危機対応計画やEUサイバー外交ツールボックスといった既存の枠組みを基礎としつつ、重要インフラの青写真やEUの電力部門のサイバーセキュリティに関するネットワークコードといった最近採択されたイニシアティブとも整合している。また、NATOを含む文民と軍事の事業体間の協力を強化する方策を提案するとともに、EUの次期準備戦略の目標を反映させている。さらに、この提案は、安全なコミュニケーションと偽情報に対抗するための戦略的取り組みを促進するものである。 |
| This also complements the Joint Communication of the Commission and the HRVP to strengthen the security and resilience of submarine cables, which Executive Vice-President Virkkunen presented in Helsinki on 21 February. | この提案は、2月21日にヴィルクネン副委員長がヘルシンキで発表した、海底ケーブルの安全性とレジリエンスを強化するための欧州委員会とHRVPの共同コミュニケーションも補完するものである。 |
| Read further information: | 詳細はこちら: |
| The Cyber Blueprint - draft Council Recommendation | サイバー青写真 - 欧州理事会勧告案 |
| The EU Cybersecurity policies | EUサイバーセキュリティ政策 |
| Related topics | 関連トピック |
| Cybersecurity | サイバーセキュリティ |
| Related content | 関連コンテンツ |
| Cyber Blueprint - Draft Council Recommendation | サイバー青写真-理事会勧告ドラフト |
・2025.02.24 Cyber Blueprint - Draft Council Recommendation
| Cyber Blueprint - Draft Council Recommendation | サイバー青写真-理事会勧告ドラフト |
| The objective of this draft Council Recommendation on the EU Blueprint for cybersecurity crisis management (Cyber Blueprint) is to present, in a clear, simple and accessible manner, the EU framework for cyber crisis management. | サイバーセキュリティ危機管理のためのEU青写真(サイバー・青写真)に関するこの理事会勧告案の目的は、サイバー危機管理のためのEUの枠組みを明確かつシンプルで利用しやすい形で提示することである。 |
| The Cyber Blueprint should enable relevant Union-actors (meaning Union-level individual entities and networks of entities) to understand how to interact and make the best use of available mechanisms across the full crisis management lifecycle. It aims to explain what a cyber crisis is and what triggers a cyber crisis mechanism at Union level. It explains the use of available mechanisms like the Cybersecurity Emergency Mechanism, including the EU Cybersecurity Reserve, in preparing how to manage, respond to and recover from a crisis arising from a large-scale cybersecurity incident. It furthermore aims to foster a more structured cooperation between civilian and military actors, including cooperation with North Atlantic Treaty Organisation (NATO), given that a large-scale cyber incident affecting Union civilian infrastructure on which the military rely may also activate NATO response mechanisms. | サイバー青写真は、関連するEUの事業体(EUレベルの個々の事業体および事業体のネットワークを意味する)が、危機管理のライフサイクル全体にわたって、どのように相互作用し、利用可能なメカニズムを最大限に活用するかを理解できるようにすべきである。その目的は、サイバー危機とは何か、何が連邦レベルでのサイバー危機メカニズムの引き金となるのかを説明することである。大規模サイバーセキュリティインシデントから生じる危機をどのように管理し、対応し、回復するかを準備する上で、EUサイバーセキュリティリザーブを含むサイバーセキュリティ緊急メカニズムのような利用可能なメカニズムの利用について説明する。さらに、北大西洋条約機構(NATO)との協力を含め、文民と軍事の間のより構造的な協力関係を促進することも目的としている。これは、軍が依存しているEUの文民インフラに影響を及ぼす大規模なサイバーインシデントが、NATOの対応メカニズムも作動させる可能性があることを考慮したものである。 |
| The Cyber Blueprint is a non-binding instrument which identifies specific actions for relevant actors in a cyber crisis and which can enhance the overall effectiveness of the cyber crisis management framework. It updates the blueprint set out in Commission Recommendation (EU) 2017/1584 on coordinated response to large-scale cybersecurity incidents and crises, and it is informed by the outcomes and lessons learned from Union-level exercises since that recommendation was adopted. | サイバー青写真は、サイバー危機における関連主体の具体的行動を特定し、サイバー危機管理枠組みの全体的有効性を高めることができる拘束力のない文書である。これは、大規模サイバーセキュリティインデントと危機への協調的対応に関する欧州委員会勧告(EU)2017/1584で定められた青写真を更新するものであり、同勧告が採択されて以来、欧州連合レベルの演習で得られた成果と教訓に基づくものである。 |
・[PDF] Cyber Blueprint - Proposal Council Recommendation
・[PDF] Cyber Blueprint - Proposal Council Recommendation - Annexes
附属書 I - サイバーセキュリティ危機に対応するためのEUの青写真
| (1) CSIRIs and/or Cross-border Cyber Hubs detect a large- scale cybersecurity incident. | (1) CSIRI および/または国境を越えたサイバーハブが大規模サイバーセキュリティインシデントを検知する。 |
| (2) CSIRTS Network escalates in accordance with internal procedures. | (2)CSIRTSネットワークは、内部手順に従ってエスカレーションを行う。 |
| (3) EU-CyCLONe coordinates operational response in the case of a large-scale incident. | (3) EU-CyCLONeは、大規模なインシデントが発生した場合の作戦対応を調整する。 |
| (4) Council Presidency, in consultation with Member States, the Commission and the High Representative, determines whether to activate or deactivate the EU (IPCR) crisis arrangements. | (4) 理事会議長は、加盟国、欧州委員会および上級代表者と協議の上、EU(IPCR)危機管理体制を作動させるか停止させるかを決定する。 |
| (5) Where the IPCR is activated, ISAA reports developed by the Commission services and EEAS inform discussions. EU-CyCLONe and JCAR should provide input to ISAA. Council is also informed by SIAC analyses. | (5) IPCRが発動された場合、欧州委員会のサービスとEEASが作成したISAA報告書が協議に反映される。EU-CyCLONeおよびJCARは、ISAAにインプットを提供すべきである。理事会はまた、SIACの分析からも情報を得る。 |
| (6) CERT- EU is responsible for the operational response to crises affecting Union entities; relevant information may be provided to EU-CyCLONe by the IICB via the Commission as point of contact. | (6) CERT- EUは、EUの事業体に影響を及ぼす危機への実務的対応を担当する。関連情報は、欧州委員会を窓口として、IICBからEU-CyCLONeに提供される。 |
| (7) Council, EU-CyCLONe and CSIRTs Network have overview of responses at political, operational and technical levels, respectively. | (7) EU理事会、EU-CyCLONeおよびCSIRTsネットワークは、それぞれ政治レベル、運用レベルおよび技術レベルでの対応を統括する。 |



Comments