« 英国 NCSC Web PKIにおける証明書のプロビジョニングと管理 (2025.12.10) | Main | 米国 CISA他 親ロシア派ハクティビストによる米国及び世界の重要インフラへの機会主義的攻撃 (2025.12) »

2025.12.20

カナダ CCCS カナダの水システムに対するサイバー脅威:アセスメントと緩和 (2025.12.04)

こんにちは、丸山満彦です。

カナダのサイバーセキュリティセンター( Canadian Centre for Cyber Security: CCCS)が、水道システムのサイバー脅威のアセスメントと対策(脅威の緩和策)を公表していますね...

カナダは重要インフラを10分野指定していますが、水道システム(上下水道)もその1つになっています。

ちなみに、10分野は、

Energy and utilities エネルギーと公益事業
Finance 金融
Food 食品
Health 医療
Government 政府
Safety 安全
Water
Transportation 運輸
Information and communication technology 情報通信技術
Manufacturing 製造業

 

カナダ政府としては、次のように評価しているようです...

  • 物理的プロセスを監視・制御する運用技術(OT)ネットワークは、水道システムを妨害しようとする攻撃者の主要標的となる可能性が極めて高い

  • 金銭目的のサイバー犯罪者が水道システムに影響を与える最も可能性の高いサイバー脅威である。サイバー犯罪者は、ランサムウェア関連の恐喝、盗まれた情報の悪用、ビジネスメール詐欺(BEC)を通じて、水道セクターの組織やシステムをほぼ確実に悪用し続ける。ランサムウェアは、OTシステムへの潜在的な影響から、カナダの安定した水供給に対するほぼ確実に重要なサイバー脅威である

  • 我々は、水システムが国家支援アクターにとって、破壊的または妨害的なサイバー脅威活動を通じた権力投射の戦略的標的であることはほぼ確実である。国家支援アクターがカナダの水システムへの事前配置アクセスを確立している可能性が極めて高い。ただし、これらのアクターが水システムを妨害するのは国家間の危機や紛争時のみである可能性が高い

  • 非国家主体によるサイバー攻撃は、カナダの重要インフラ(CI)に対する脅威として拡大している。非国家主体は、特に主要な地政学的イベントに関連して、カナダ国内のインターネットに晒された水道システムOTを機会主義的に侵害・妨害し続ける可能性が極めて高い

ほぼ確実 (almost certainly):90%-100%

可能性が極めて高い (very likely):75% - 89%

可能性が高い(likely): 60%-74%

 

 

 


日本も上下水道は経済安全保障の観点から基幹インフラに指定されていて、国土交通省が所管していますね...

で、特定社会基盤事業者として指定されている事業者は2025.07.31現在で、23事業者ですね。。。すべて自治体と自治体の集まりである水道企業団です...

ちょっと心配???

国土交通省 - 経済安全保障(基幹インフラ役務の安定的な提供の確保に関する制度)水道分野における経済安全保障

簡易水道事業以外の水道事業(給水人口:100万人超)

  1. 札幌市(札幌市水道事業)
  2. 仙台市(仙台市水道事業)
  3. さいたま市(さいたま市水道事業)
  4. 千葉県(千葉県水道事業)
  5. 東京都(東京都水道事業)
  6. 神奈川県(神奈川県水道事業)
  7. 横浜市(横浜市水道事業)
  8. 川崎市(川崎市水道事業)
  9. 名古屋市(名古屋市水道事業)
  10. 京都市(京都市水道事業)
  11. 大阪市(大阪市水道事業)
  12. 神戸市(神戸市水道事業)
  13. 広島市(広島市水道事業)
  14. 北九州市(北九州市水道事業)
  15. 福岡市(福岡市水道事業)

水道用水供給事業(1日最大給水量:50万㎥超)

  1. 宮城県(仙南・仙塩広域水道用水供給事業)
  2. 埼玉県(埼玉県水道用水供給事業)
  3. 愛知県(愛知県水道用水供給事業)
  4. 沖縄県(沖縄県営水道用水供給事業)
  5. 北千葉広域水道企業団(北千葉広域水道用水供給事業)
  6. 神奈川県内広域水道企業団(神奈川県内広域水道用水供給事業)
  7. 大阪広域水道企業団(大阪広域水道企業団水道用水供給事業)
  8. 阪神水道企業団(阪神水道企業団用水供給事業)

内閣府 - 基幹インフラ役務の安定的な提供の確保に関する制度


 

では、カナダの話に戻ります...(^^)

 

The cyber threat to Canada’s water systems: Assessment and mitigation カナダの水システムに対するサイバー脅威:アセスメントと緩和
Table of contents 目次
About this document 本文書について
Message from the Head of the Cyber Centre サイバーセンター長からのメッセージ
Key judgements 主要な判断
Canada’s water sector カナダの水分野
The threat from cybercriminals サイバー犯罪者からの脅威
The state-sponsored cyber threat to water systems 国家が支援する水システムへのサイバー脅威
Non-state cyber actors: A growing threat 非国家主体によるサイバー脅威:増大する脅威
Outlook: What this means for the Canadian Water Sector 展望:カナダの水分野にとっての意味
Mitigation 緩和
Additional resources 追加リソース
References 参考文献

 

一部...

Message from the Head of the Cyber Centre サイバーセンター長からのメッセージ
I spend a lot of time looking at threats most people never see. They are quiet, often hidden, yet capable of real-world consequences. Among the most critical are the cyber threats facing Canada’s water and wastewater systems. These systems are the backbone of modern life, yet they’re often out of sight and out of mind. When they function, no one notices. When they fail, everyone does. 私は多くの時間を、一般の人々が決して目にすることのない脅威の分析に費やしている。それらは静かで、しばしば隠れているが、現実世界に影響を及ぼす能力を持つ。最も重大な脅威の一つが、カナダの水道・下水システムに対するサイバー脅威だ。これらのシステムは現代生活の基盤でありながら、往々にして目に見えず、意識されることもない。正常に機能している時は誰も気づかない。しかし故障した時は誰もが気づく。
This assessment is meant to bring clarity to a topic that can feel abstract or overly technical. Cyber threats to water infrastructure are growing, evolving quickly, and can affect every community in Canada. You don’t need to be an engineer or a cyber security expert to understand why this matters. Clean water is essential, and the systems that deliver it are now largely digital – meaning they are vulnerable to the same kinds of cyber threats that target businesses and governments around the world. このアセスメントは、抽象的あるいは技術的すぎると思われるテーマを明確にすることを目的としている。水道インフラへのサイバー脅威は拡大し、急速に進化しており、カナダのあらゆる地域社会に影響を及ぼしうる。これがなぜ重要なのかを理解するのに、技術者やサイバーセキュリティの専門家である必要はない。清潔な水は不可欠であり、それを供給するシステムは今や大部分がデジタル化されている。つまり、世界中の企業や政府を標的とするのと同じ種類のサイバー脅威に脆弱性があるのである。
We’ve seen an unmistakable shift in recent years. Cybercriminals are more sophisticated, state-sponsored actors are more willing to target essential services, and disruptive tools are easier to access. Water systems now face a threat landscape they were never designed to withstand. 近年、明らかな変化が起きている。サイバー犯罪者はより洗練され、国家支援アクターは重要サービスを標的にする傾向を強め、破壊的なツールは入手しやすくなった。水道システムは、耐えるよう設計されていない脅威環境に直面しているのだ。
Whether you’re a critical infrastructure executive, an elected official, or a policymaker, I want to emphasize that cyber security for water systems is not just a technical issue, it is a public safety issue, an economic stability issue, and ultimately a public trust issue. Leadership matters. The choices you make about investment, governance, and preparedness will determine our collective resilience in the years ahead. 重要インフラの責任者であれ、選出された公職者であれ、政策立案者であれ、強調したいのは、水道システムのサイバーセキュリティは単なる技術的問題ではなく、公共の安全問題であり、経済的安定の問題であり、究極的には公共の信頼の問題だということだ。リーダーシップが重要である。投資、ガバナンス、準備態勢に関する選択が、今後数年間の我々の集団的レジリエンスを決定づける。
But this is not a message of alarm; it is a message of readiness. Across Canada, utilities, municipalities, and provincial and territorial partners have shown a strong commitment to improving their cyber resilience. What’s needed now is a clear-eyed analysis of the cyber threats facing our water systems in Canada. That’s what this assessment provides. しかしこれは警戒を促すメッセージではない。準備を促すメッセージだ。カナダ全土で、公益事業体、自治体、州・準州のパートナーはサイバーレジリエンス強化への強い決意を示している。今必要なのは、カナダの給水システムが直面するサイバー脅威に対する冷静な分析だ。このアセスメントがそれを提供する。
My hope is that it empowers decision-makers to act confidently, ask the right questions, and support the people who keep these systems running. Cyber threats aren’t going away, but with awareness and a steady commitment to resilience, we can stay ahead of them. 本アセスメントが意思決定者の確信ある行動、適切な質問、そしてシステムを維持する人々への支援を後押しすることを願う。サイバー脅威は消えないが、認識とレジリエンスへの揺るぎない取り組みによって、我々は脅威を先回りできる。
Sincerely, 敬具
Rajiv Gupta, Head of the Canadian Centre for Cyber Security ラジブ・グプタカナダサイバーセキュリティセンター長
Key judgements 主要な判断
・We assess that operational technology (OT) networks that monitor and control physical processes are very likely the primary target for actors seeking to disrupt water systems. ・物理的プロセスを監視・制御する運用技術(OT)ネットワークは、水道システムを妨害しようとする攻撃者の主要標的となる可能性が極めて高いと評価する。
・We assess that financially motivated cybercriminals are the most likely cyber threat to affect water systems. We assess that cybercriminals will almost certainly continue to exploit water sector organizations and systems through extortion tied to ransomware, exploiting stolen information, and business email compromise (BEC). We assess that ransomware is almost certainly the most significant cyber threat to the reliable supply of water in Canada due to the potential impacts against OT systems. ・金銭目的のサイバー犯罪者が水道システムに影響を与える最も可能性の高いサイバー脅威であると評価する。サイバー犯罪者は、ランサムウェア関連の恐喝、盗まれた情報の悪用、ビジネスメール詐欺(BEC)を通じて、水道セクターの組織やシステムをほぼ確実に悪用し続けると評価する。ランサムウェアは、OTシステムへの潜在的な影響から、カナダの安定した水供給に対するほぼ確実に重要なサイバー脅威であると評価する。
・We assess that water systems are almost certainly a strategic target for state-sponsored actors to project power through disruptive or destructive cyber threat activity. We assess that state-sponsored actors have almost certainly developed pre-positioned access to Canadian water systems. However, we judge that these actors would likely only disrupt those water systems in times of crisis or conflict between states. ・我々は、水システムが国家支援アクターにとって、破壊的または妨害的なサイバー脅威活動を通じた権力投射の戦略的標的であることはほぼ確実である。国家支援アクターがカナダの水システムへの事前配置アクセスを確立していることはほぼ確実であると評価する。ただし、これらのアクターが水システムを妨害するのは国家間の危機や紛争時のみである可能性が高いと判断する。
・Non-state cyber actors are a growing threat to Canada’s critical infrastructure (CI). We assess that non-state actors will very likely continue to opportunistically compromise and disrupt Internet-exposed water system OT within Canada, especially in connection to major geopolitical events. 非国家主体によるサイバー攻撃は、カナダの重要インフラ(CI)に対する脅威として拡大している。非国家主体は、特に主要な地政学的イベントに関連して、カナダ国内のインターネットに晒された水道システムのOTを機会主義的に侵害・妨害し続ける可能性が極めて高いと評価する。
Canada’s water sector カナダの水分野
Good public and environmental health depend on access to clean water. Footnote1  Drinking water, stormwater and wastewater treatment systems (collectively: water systems) have many important economic, environmental, and safety uses. A loss of water does not just affect residents but also can have effects on other critical infrastructure. For example, in 2024, water main breaks in Calgary and Montreal resulted in cascading impacts on other systems, including hospitals, fire prevention and universities. Footnote2  For these reasons and others, our water systems are considered part of Canada’s critical infrastructure (Figure 1). Footnote3  Any disruption in the water system is not only a threat to public health and safety, but also a threat to public confidence, the environment and the economy. Footnote4  As a result, the cyber security of our water systems is vital to Canada’s national security. 良好な公衆衛生と環境衛生は、清潔な水へのアクセスに依存している。脚注1 飲料水、雨水、廃水処理システム(総称:水道システム)は、経済的、環境的、安全面において多くの重要な用途を持つ。水の喪失は住民に影響を与えるだけでなく、他の重要インフラにも影響を及ぼし得る。例えば2024年、カルガリーとモントリオールで発生した水道本管破裂は、病院、防火システム、大学など他のシステムに連鎖的な影響をもたらした。Footnote2 このような理由から、我が国の水道システムはカナダの重要インフラの一部と位置付けられている(図1)。Footnote3 水道システムの混乱は、公衆衛生と安全への脅威であるだけでなく、国民の信頼、環境、経済への脅威でもある。脚注4 したがって、水道システムのサイバーセキュリティはカナダの国家安全保障にとって極めて重要である。
Figure 1: Critical infrastructure 図1:重要インフラ
Critical infrastructure refers to the processes, systems, facilities, technologies, networks, assets and services essential to the health, safety, security or economic well-being of Canadians and the effective functioning of government. 重要インフラとは、カナダ国民の健康・安全・保安・経済的福祉、および政府の有効な機能に不可欠なプロセス、システム、施設、技術、ネットワーク、資産、サービスを指す。
Ncta2023fig5
The threat surface of Canada’s water systems カナダの水道システムの脅威対象範囲
A water system generally includes the services and infrastructure to safely and reliably obtain, store, filter and distribute potable water, divert runoff and floodwater as well as remove, collect and treat wastewater. Canada has thousands of water systems that vary greatly in size. A small number of large water utilities serve major urban areas while international organizations manage shared systems. Meanwhile, many small systems are owned and operated by municipalities, other levels of government, Indigenous communities, private sector companies and individual citizens. Footnote5 水道システムは一般的に、安全かつ確実に飲料水を採取・貯蔵・濾過・配水し、雨水や洪水を迂回させ、汚水を除去・収集・処理するためのサービスとインフラを含む。カナダには数千もの水道システムが存在し、その規模は大きく異なる。少数の大規模水道事業体が主要都市圏をカバーする一方、国際機関が共有システムを管理している。また、多くの小規模システムは自治体、その他の政府、先住民コミュニティ、民間企業、個人市民が所有・運営している。脚注5
Water systems operate in a variety of ways. Many are completely manual or even passive systems that require little to no active management, including most small water supplies and stormwater systems. Large urban water systems, in contrast, are usually geographically dispersed, industrial systems operated from a digital control environment. These include many remotely managed OT devices integrated into dams, pumping stations, and treatment facilities. These systems also extend into a web of connected suppliers of digital products and services. 水道システムの運用方法は様々である。多くは完全に手動、あるいは受動的なシステムであり、積極的な管理をほとんど、あるいは全く必要としない。これには小規模な給水システムや雨水システムの大半が含まれる。これに対し、大規模な都市水道システムは通常、地理的に分散した産業用システムであり、デジタル制御環境から運営される。これにはダム、ポンプ場、処理施設に統合された遠隔管理のOTデバイスが多数含まれる。これらのシステムはまた、デジタル製品・サービスを提供する相互接続されたサプライヤーのネットワークへと拡大している。
Many of these water systems are managed out of municipal or community offices and are exposed to all the cyber threats encountered by public-facing organizations. The more internet-connected assets an organization has, the larger the threat surface. A larger threat surface implies an increase in the cyber threat the organization faces. Footnote6  In addition to increasing internet connectivity, most water systems are operated by small public sector organizations and frequently face challenges that can negatively influence cyber security, including low financial resources, aging physical and digital infrastructure and a shortage of cyber security expertise. Footnote7 こうした水道システムの多くは自治体やコミュニティの事務所から管理されており、一般向け組織が直面するあらゆるサイバー脅威に晒されている。組織がインターネットに接続する資産が増えるほど、脅威対象領域は拡大する。脅威対象領域の拡大は、組織が直面するサイバー脅威の増加を意味する。脚注6 インターネット接続性の増加に加え、大半の水システムは小規模な公共部門組織によって運営されており、財政資源の不足、老朽化した物理的・デジタルインフラ、サイバーセキュリティ専門知識の不足など、サイバーセキュリティに悪影響を及ぼし得る課題に頻繁に直面している。脚注7
The role of operational technology in our water systems 水道システムにおける運用技術(OT)の役割
Operators use industrial OT including supervisory control and data acquisition (SCADA) and industrial Internet of things (IIoT) devices to manage large water systems and address issues like population growth, outdated infrastructure and declining revenue. Footnote8  These systems are used to control water system equipment like dam gates, valves and pumps and to monitor sensors such as chemical detectors and flowrate monitors. The OT in water systems is continually evolving and is increasingly managed through digital devices with embedded computing and communications abilities. Footnote9  This process, called digital transformation or digitalization, has allowed OT asset operators like those in the water sector to connect their OT devices to operating centres, corporate networks and, increasingly, directly to the internet. A 2021 survey counted over 60,000 OT-related network interfaces in Canada. Footnote10  In 2023, a similar survey conducted on internet-connected devices associated mainly with water systems in the U.S. and UK found a relatively low level of basic cyber hygiene. Almost half of the devices could be manipulated without any authentication required. Footnote11 事業者は、大規模な水道システムの管理や、人口増加・老朽化したインフラ・収益減少といった課題への対応に、監視制御とデータ収集(SCADA)や産業用モノのインターネット(IIoT)デバイスを含む産業用OTを活用している。脚注8 これらのシステムは、ダムのゲートやバルブ、ポンプといった水道設備の制御や、化学物質検知器や流量モニターなどのセンサーの監視に使用される。水道システムのOTは絶えず進化しており、組み込みコンピューティングとコミュニケーション機能を備えたデジタルデバイスによる管理が拡大している。脚注9 この「デジタルトランスフォーメーション」または「デジタル化」と呼ばれるプロセスにより、水道分野などのOT資産運用者は、OTデバイスを運用センターや企業ネットワークに接続し、さらにインターネットに直接接続するケースが増えている。2021年の調査では、カナダ国内に6万を超えるOT関連ネットワークインターフェースが確認された。脚注10 2023年には、主に米国と英国の水道システムに関連するインターネット接続デバイスを対象とした同様の調査で、基本的なサイバー衛生状態が比較的低い水準にあることが判明した。デバイスのほぼ半数は、認証を一切必要とせずに操作可能であった。脚注11
Unfortunately, the management efficiency and savings gained from connecting digitally transformed OT also exposes the water system to cyber threats. Footnote10  For example, in early 2000, an employee was fired from a company providing services to Maroochy Water Services in Queensland, Australia. The individual retained remote access to the network of OT devices in the pumping stations of the wastewater treatment system. Footnote12  He used this access to issue malicious commands to the devices that ultimately caused nearly a million litres of raw sewage to be discharged into local parks and rivers, causing severe environmental harm, according to officials. Footnote13  This was the first example of a remote access in a public water system being used to disrupt or sabotage OT systems, and illustrates the potential for cyber threats to jeopardize public and environmental safety and the local economy. Footnote10  We assess that operational technology (OT) networks that monitor and control physical processes are very likely the primary target for actors seeking to disrupt water systems. 残念ながら、デジタル変革されたOTを接続することで得られる管理効率とコスト削減は、同時に水道システムをサイバー脅威に晒すことになる。脚注10 例えば2000年初頭、オーストラリア・クイーンズランド州のマロッチー水道サービスに業務委託していた企業から従業員が解雇された。この人物は下水処理システムのポンプ場にあるOT機器ネットワークへのリモートアクセス権を保持していた。脚注12 当局によれば、この人物はアクセス権を悪用し、装置に悪意のある指令を発行。結果として約100万リットルの未処理汚水が地域の公園や河川に流出、深刻な環境被害を引き起こした。脚注13 これは公共水道システムにおけるリモートアクセスがOTシステムの妨害・破壊に利用された初の事例であり、サイバー脅威が公共・環境安全及び地域経済を脅かす可能性を示している。脚注10 物理的プロセスを監視・制御する運用技術(OT)ネットワークは、水道システムを妨害しようとする者にとって主要な標的となる可能性が極めて高いと我々は評価している。
On the rise: Cyber threats to supply chains 増加傾向にある:サプライチェーンへのサイバー脅威
Water system utilities often depend on a diverse supply chain of digital products and services to operate, maintain and modernize their OT assets. The supply chain for these products and services includes manufacturers, vendors, integrators, contractors and service providers. Water system OT’s dependency on the supply chain is a critical vulnerability  that gives cyber actors inside information on and opportunities for access to otherwise protected OT systems. 水道事業者は、OT資産の運用・保守・近代化のために多様なデジタル製品・サービスのサプライチェーンに依存している。これらの製品・サービスのサプライチェーンには、製造事業者、ベンダー、インテグレーター、請負業者、プロバイダが含まれる。水道システムOTのサプライチェーン依存は重大な脆弱性であり、サイバー攻撃者に本来防御されたOTシステムへの内部情報とアクセス機会を提供する。
Cyber threat actors target organizations’ digital supply chains to collect business and contextual information for use in social engineering  attacks or to collect organizational network and system information to support future cyber attacks. Activity against the digital supply chain can also be an indirect route to gain access to the target organization’s networks in situations where there is continuous information transfer, for example software updates, or remote network access connections between the organization and its suppliers. In late 2019, a sophisticated cyber threat actor compromised the software-as-a-service provider, SolarWinds. The actors, attributed to Russia’s intelligence services, used their access to SolarWinds’ development environment to embed malicious code into a software update. The compromised update provided the actors access to thousands of client networks worldwide, including over 100 in Canada. Footnote14 サイバー脅威アクターは、組織のデジタルサプライチェーンを標的とし、ソーシャルエンジニアリング攻撃に利用する業務情報や文脈情報を収集したり、将来のサイバー攻撃を支援する組織ネットワーク・システム情報を収集したりする。デジタルサプライチェーンに対する活動は、ソフトウェア更新や組織とサプライヤー間のリモートネットワーク接続など、継続的な情報転送が行われる状況下では、標的組織のネットワークへのアクセスを得る間接的な経路ともなり得る。2019年末、高度なサイバー脅威アクターがSaaSプロバイダであるSolarWindsを侵害した。ロシア情報機関に帰属するとされるこれらのアクターは、SolarWindsの開発環境へのアクセス権を利用して、ソフトウェア更新プログラムに悪意のあるコードを埋め込んだ。侵害された更新プログラムにより、アクターは世界中の数千のクライアントネットワーク(カナダ国内でも100以上を含む)へのアクセス権を獲得した。脚注14
Publicly available cyber tools are increasing the volume and effectiveness of cyber threat activity 公開されているサイバーツールが、サイバー脅威活動の量と効果を高めている
We assess it almost certain that cyber threat actors are increasingly using publicly available cyber tools to gain and maintain access to CI networks, making it easier for threat actors of all levels of sophistication to target water sector OT. The wide availability  of these tools, including legitimate penetration testing tools like Cobalt Strike, has lowered the barrier to entry to cyber threat activity and increased the capacity for cyber threat actors to gain, maintain, and expand access to target systems. Footnote15 我々は、サイバー脅威アクターがCIネットワークへのアクセス獲得・維持に公開ツールをますます活用していることをほぼ確実と見なす。これにより、あらゆるレベルの脅威アクターが水道セクターのOTを標的にしやすくなっている。コバルトストライクのような正当なペネトレーションテストツールを含むこれらのツールの広範な入手可能性は、サイバー脅威活動への参入障壁を低下させ、標的システムへのアクセス獲得・維持・拡大能力を高めている。脚注15
The proliferation of publicly available cyber tools has advantages for sophisticated cyber threat actors as well. Advanced cyber threat actors often use a combination of publicly available tools and living-off-the-land (LOTL) techniques when possible and bespoke malware  when necessary. For example, People’s Republic of China (PRC) threat actors Volt Typhoon, Flax Typhoon and APT40 commonly use a mixed toolset and likely maintain an extensive catalog of open source and custom malware. Footnote16  LOTL techniques exclusively rely on legitimate tools and processes already present in the victim’s environment, for example Windows PowerShell or Windows Management Instrumentation, to carry out malicious activity. Footnote17  These techniques allow threat actors to blend their malicious activity in with normal network activity. By using generic publicly available tools and LOTL techniques, sophisticated actors limit the distinct signature they leave on a target’s network, making detecting cyber threat activity and attributing the source of that activity even more challenging. Footnote18 公開されているサイバーツールの拡散は、高度なサイバー脅威アクターにとっても利点がある。高度なサイバー脅威アクターは、可能な場合には公開ツールとLOTL(現地調達)手法を組み合わせ、必要に応じて特注マルウェアを使用することが多い。例えば、中華人民共和国(PRC)の脅威アクターであるVolt Typhoon、Flax Typhoon、APT40は混合ツールセットを頻繁に使用し、オープンソースとカスタムマルウェアの広範なカタログを維持している可能性が高い。脚注16 LOTL手法は、Windows PowerShellやWindows Management Instrumentationなど、被害者環境に既に存在する正当なツールやプロセスのみに依存して悪意のある活動を実行する。脚注17 この手法により、脅威アクターは自身の悪意ある活動を通常のネットワーク活動に溶け込ませることができる。汎用的な公開ツールとLOTL手法を用いることで、高度な攻撃者は標的ネットワークに残す特徴的な痕跡を最小限に抑え、サイバー脅威活動の検知と発生源の特定をさらに困難にする。脚注18
The threat from cybercriminals サイバー犯罪者による脅威
We assess that financially motivated cybercriminals are the most likely cyber threat to affect water systems. We assess that cybercriminals will almost certainly continue to exploit water sector organizations and systems through extortion tied to ransomware, exploiting stolen information and business email compromise (BEC). BEC is a type of fraud that uses compromised email accounts to trick people into transferring money or sensitive information to attacker-controlled accounts, while ransomware  is malware that encrypts data or locks devices to extort a target organization for ransom payment. Footnote19  Although BEC is likely more common and more costly than ransomware to victims, ransomware can disrupt operations such as the delivery of safe drinking water through loss of visibility or control over important industrial processes. Footnote20  We assess that ransomware is almost certainly the most significant cyber threat to the reliable supply of water in Canada due to the potential impacts against OT systems. Cybercriminals are aware that the disruption of critical products and services increases the pressure on an organization to pay ransom. Footnote21  For example, ransomware attacks disrupted water treatment systems in California, Maine and Nevada in 2021, and in Kansas in 2024, forcing system operators to manually operate their OT systems to maintain service. Footnote22 我々は、金銭的動機を持つサイバー犯罪者が水道システムに影響を与える最も可能性の高いサイバー脅威であると評価する。我々は、サイバー犯罪者がランサムウェア関連の恐喝、盗まれた情報の悪用、ビジネスメール詐欺(BEC)を通じて、水道セクターの組織やシステムをほぼ確実に悪用し続けると評価している。BECは、侵害されたメールアカウントを利用して、攻撃者が管理する口座へ金銭や機密情報を送金させる詐欺の一種である。一方、ランサムウェアはデータを暗号化したりデバイスをロックしたりして、標的組織から身代金支払いを強要するマルウェアである。脚注19 BECは被害者にとってより一般的でより高コストである可能性が高いが、ランサムウェアは重要な産業プロセスの可視性や制御の喪失を通じて、安全な飲料水の供給などの業務を妨害し得る。脚注20 我々は、OTシステムへの潜在的影響から、ランサムウェアがカナダの安定した水供給に対するほぼ確実に最も重要なサイバー脅威であると評価する。サイバー犯罪者は、重要製品・サービスの混乱が組織の身代金支払圧力を高めることを認識している。脚注21 例えば2021年にはカリフォルニア州、メイン州、ネバダ州で、2024年にはカンザス州でランサムウェア攻撃が水処理システムを混乱させ、システム運用者はサービスを維持するためOTシステムを手動操作せざるを得なかった。脚注22
Ransomware incidents are becoming more complex and costly to remediate ランサムウェア被害の復旧は複雑化・高コスト化している
We assess that ransomware attacks against CI organizations, including those in the water sector, are almost certainly becoming more frequent as well as more costly and complex to remediate. The number of observed ransomware incidents has increased across sectors from 2021 to 2024. The size of ransom demands, cost of recovery, and the sophistication and complexity of tactics being used by cybercriminals have also increased. Footnote23  These trends are driven by the proliferation of ransomware-as-a-service (RaaS) variants, the cybercrime-as-a-service (CaaS) ecosystem, and the increased use of multiple extortion methods. Footnote24 我々は、水道部門を含む重要インフラ組織に対するランサムウェア攻撃が、ほぼ確実に頻度を増すとともに、復旧コストと複雑性も高まっていると評価する。2021年から2024年にかけて、各部門で観測されたランサムウェア被害件数は増加している。身代金要求額、復旧コスト、サイバー犯罪者が用いる戦術の高度化・複雑化も進行している。脚注23 こうした傾向は、ランサムウェア・アズ・ア・サービス(RaaS)の変種の拡散、サイバー犯罪・アズ・ア・サービス(CaaS)の生態系、複数の恐喝手法の併用増加によって促進されている。脚注24
Cybercriminals have widely adopted the practice of stealing and threatening to leak their victims’ sensitive data as either a supplement to traditional encryption -based extortion or as the primary lever for extortion. In early 2023, the cybercriminal group CL0P exploited a vulnerability in MOVEit Transfer, a file transfer tool made by Progress Software. CL0P’s attacks were far-reaching, allowing them to steal information from government, public and business groups all over the world, including the water utility files of Queens Municipality in Nova Scotia. Footnote25  In early 2024, 2 different cybercriminal groups conducted ransomware attacks against water sector organizations in North America and the United Kingdom. The groups disrupted IT systems and leaked stolen data including business data and personal information. Footnote26 サイバー犯罪者は、従来の暗号化に基づく恐喝を補完する手段として、あるいは恐喝の主要な手段として、被害者の機密データを盗み流出を脅迫する手法を広く採用している。2023年初頭、サイバー犯罪グループCL0Pは、Progress Software製のファイル転送ツール「MOVEit Transfer」の脆弱性を悪用した。CL0Pの攻撃は広範囲に及び、ノバスコシア州クイーンズ自治体の水道事業ファイルを含む、世界中の政府・公共・企業団体から情報を窃取した。脚注25 2024年初頭には、2つの異なるサイバー犯罪グループが北米と英国の水道事業組織に対しランサムウェア攻撃を実施。両グループはITシステムを妨害し、業務データや個人情報を含む窃取データを流出させた。脚注26
Cybercrime marketplaces provide specialized services and increase impacts against victims サイバー犯罪マーケットプレイスは専門サービスを提供し、被害者への影響を拡大させる
Cybercrime is continuously evolving to maximize profits and increase the payouts extracted from targets. Footnote27  The CaaS ecosystem allows for specialization and division of labour among cybercriminal groups. This allows cybercriminals to access a range of services including network access brokering, access to RaaS variants and money laundering. Access brokers opportunistically collect network accesses into victim organizations and sell them to other cybercriminals. Those cybercriminals then conduct reconnaissance  and use social engineering to determine which targets to deploy ransomware against. These decisions are often based on which organizations are most likely and/or able to pay a ransom. Footnote19Footnote27  We assess that the CaaS ecosystem is almost certainly increasing the number of actors participating in cybercrime by enabling less technically sophisticated actors to carry out cyber threat activity. サイバー犯罪は利益を最大化し、標的から抽出される支払額を増やすため、絶えず進化している。脚注27 CaaSエコシステムは、サイバー犯罪グループ間の専門化と分業を可能にする。これにより、サイバー犯罪者はネットワークアクセス仲介、RaaS亜種のアクセス、資金洗浄など多様なサービスを利用できる。アクセス仲介業者は、被害組織へのネットワークアクセスを機会主義的に収集し、他のサイバー犯罪者に販売する。その後、これらの犯罪者は偵察活動を行い、ソーシャルエンジニアリングを用いてランサムウェアを展開する標的を決定する。この判断は、身代金を支払う可能性が最も高く、かつ/または支払能力のある組織を基準に行われることが多い。脚注19脚注27 CaaSエコシステムは、技術的に未熟な犯罪者でもサイバー脅威活動を実施できるようにすることで、サイバー犯罪に参加する者の数をほぼ確実に増加させていると我々は評価する。
The state-sponsored cyber threat to water systems 国家が支援する水道システムへのサイバー脅威
We assess that water systems are almost certainly a strategic target for state-sponsored actors to project power through disruptive or destructive cyber threat activity. State-sponsored actors pre-position for this activity by identifying and gaining access to Internet-connected OT systems or IT networks from which they can laterally move to OT systems. Once in the target network, they collect information on assets within the network to identify opportunities for disruptive or destructive action. For example, this could mean causing water tanks to overflow or changing the chemical balance of water treatment processes. We assess that state-sponsored cyber threat actors have almost certainly developed pre-positioned access to Canadian water systems. However, we judge that these actors would likely only disrupt those water systems in times of crisis or conflict between states. 我々は、水道システムが国家支援アクターにとって、破壊的または破壊的なサイバー脅威活動を通じて権力を投射するための戦略的標的であることはほぼ確実であると評価する。国家支援アクターは、インターネットに接続されたOTシステムやITネットワークを識別し、アクセス権を獲得することで、この活動に備える。その後、横方向にOTシステムへ移動する。標的ネットワークに侵入すると、ネットワーク内の資産に関する情報を収集し、破壊的または破壊的な行動の機会を特定する。例えば、貯水タンクの溢水を引き起こしたり、水処理プロセスの化学的バランスを変更したりすることが考えられる。我々は、国家が支援するサイバー脅威アクターがカナダの給水システムへの事前配置アクセスをほぼ確実に確立していると評価する。ただし、これらのアクターが給水システムを妨害するのは、国家間の危機や紛争時のみであると判断する。
State-sponsored cyber threat actors have targeted water sector organizations and systems globally for both espionage and disruption or destruction. In an early example of state-sponsored cyber activity in water system OT, in 2013, Iranian actors gained access to the SCADA system of a small dam in New York State. This access allowed them to obtain information regarding the dam’s status and the ability to operate the sluice gates of the dam, which could affect water levels and flow rates in the watershed. The system was under maintenance at the time of the compromise , so the actors did not obtain actual access to the dam’s physical controls. Footnote28 国家が支援するサイバー脅威アクターは、諜報活動と妨害・破壊の両方の目的で、世界中の水セクター組織やシステムを標的にしてきた。国家支援型サイバー活動が水道システムのOT(オペレーションテクノロジー)を標的とした初期事例として、2013年にイランのアクターがニューヨーク州の小規模ダムのSCADAシステムへのアクセス権を獲得した。このアクセスにより、ダムの状態に関する情報の取得と、水門の操作能力を得ることができた。これにより流域の水位や流量に影響を与える可能性があった。侵害発生時はシステムが保守中だったため、攻撃者はダムの物理制御装置への実際のアクセス権は得られなかった。脚注28
In 2023, an Iranian Revolutionary Guard  Corps cyber unit acting under the non-state actor persona “CyberAv3ngers” compromised the Municipal Water Authority of Aliquippa, Pennsylvania. The CyberAv3ngers exploited a publicly exposed Unitronics Vision Series OT device with default passwords and defaced the system’s interface  with an anti-Israel message. This activity was part of a broader campaign targeting commonly used Israeli-made OT devices, likely to undermine Western support for Israel. Tampering with the controller's user interface implies a level of access that would allow full access to the device settings, as well as potential access to other devices on the network. It is not known if cyber activity beyond defacement was planned or carried out. Footnote29 2023年には、非国家主体「CyberAv3ngers」を名乗るイラン革命防衛隊サイバー部隊が、ペンシルベニア州アリキッパ市水道局を侵害した。CyberAv3ngersはデフォルトパスワードのまま公開されていたUnitronics VisionシリーズOT機器を悪用し、システムインターフェースを反イスラエルメッセージで改竄した。この活動はイスラエル製OT機器を標的とした広範なキャンペーンの一環であり、西側諸国のイスラエル支援を弱体化させる意図があったと推測される。制御装置のユーザーインターフェース改ざんは、機器設定への完全なアクセス権限、およびネットワーク上の他機器への潜在的アクセス権限を意味する。改ざん以外のサイバー活動が計画・実行されたかは不明である。脚注29
In 2023 and 2024, the Cyber Centre and its partners published the following joint advisories to warn critical infrastructure organizations of a PRC state-sponsored cyber group known as Volt Typhoon: 2023年と2024年、サイバーセンターとそのパートナー機関は、Volt Typhoonとして知られる中国国家支援サイバーグループについて重要インフラ組織に警告するため、以下の共同勧告を発表した:
Joint guidance for executives and leaders of critical infrastructure organizations on protecting infrastructure and essential functions against PRC cyber activity ・重要インフラ組織の経営幹部・リーダー向け:中国サイバー活動からインフラと重要機能を防御するための共同ガイダンス
CSE and its Canadian Centre for Cyber Security release advisory on People's Republic of China state-sponsored cyber threat ・CSE及びカナダサイバーセキュリティセンターによる中華人民共和国国家支援サイバー脅威に関する勧告
Joint advisory on PRC state-sponsored actors compromising and maintaining persistent access to U.S. critical infrastructure and joint guidance on identifying and mitigating living off the land ・米国重要インフラへの持続的アクセス侵害・維持を行う中華人民共和国国家支援アクターに関する共同勧告及び「現地調達型攻撃」の識別・緩和に関する共同ガイダンス
Volt Typhoon activity has been observed since mid-2021 targeting the water sector and communication, transportation and energy organizations. Footnote30  Volt Typhoon strategically selects targets, pre-positioning itself in organizations that, if disrupted, would restrict military mobilization efforts and cause societal chaos. While the Cyber Center assesses that the direct threat to Canada’s CI by Volt Typhoon is less than that to the U.S., it is not insignificant, especially for Canadian organizations that rely on cross-border trade, infrastructure or operations. In addition, the likelihood of a cyber attack  impacting Canada’s CI is higher than it otherwise might be because of the connections between US and Canadian infrastructure. ボルト・タイフーンの活動は2021年半ば以降、水道部門及びコミュニケーション・運輸・エネルギー組織を標的として確認されている。脚注30 Volt Typhoonは戦略的に標的を選定し、妨害された場合に軍事動員努力を制限し社会混乱を引き起こす組織に事前配置する。サイバーセンターはVolt Typhoonによるカナダの重要インフラへの直接脅威は米国向けより低いと評価するが、特に国境を越えた貿易・インフラ・事業に依存するカナダ組織にとっては無視できない。さらに、米国とカナダのインフラが相互接続されているため、カナダの重要インフラがサイバー攻撃を受ける可能性は、そうでない場合よりも高い。
Non-state cyber actors: A growing threat 非国家主体によるサイバー攻撃:増大する脅威
The Cyber Centre warned in our National Cyber Threat Assessment 2025-2026 that non-state cyber actors are a growing threat to Canada’s critical infrastructure. The wide proliferation of easy-to-use disruptive cyber capabilities has contributed to the emergence of a large eco-system of hacktivists and other non-state actors who opportunistically target Canada and its allies for a variety of reasons. Often, this activity is intended to intimidate or coerce its targets or to influence Canadian public opinion or policy decisions related to geopolitical events outside Canada. サイバーセンターは「2025-2026年国家サイバー脅威評価」において、非国家主体によるサイバー攻撃がカナダの重要インフラに対する脅威として増大していると警告した。容易に入手可能な破壊的サイバー能力の広範な拡散が、ハクティビストやその他の非国家主体からなる大規模なエコシステムの出現を助長している。彼らは様々な動機からカナダやその同盟国を機会主義的に標的とする。こうした活動は、標的を威嚇・強制したり、カナダ国外の地政学的事件に関連する国内世論や政策決定に影響を与えたりする意図がしばしばある。
Non-state threat activity frequently targets public-facing websites through techniques including distributed denial-of-service (DDoS ) and defacement attacks. However, some non-state actors have adopted the practice of targeting and attempting to disrupt vulnerable Internet-connected OT systems. Although non-state actors have targeted OT across CI sectors, a notable proportion of this activity has implicated water system OT. 非国家主体の脅威活動は、分散型サービス妨害(DDoS)攻撃や改ざん攻撃などの手法で、一般向けウェブサイトを頻繁に標的とする。しかし一部の非国家主体は、脆弱なインターネット接続型OTシステムを標的とし、その妨害を試みる手法を採用している。非国家主体は重要インフラ分野全体でOTを標的にしているが、この活動のかなりの割合が水道システムのOTに関与している。
In May 2024, the Cyber Centre and partners issued a joint advisory warning of pro-Russia non-state actors targeting Internet-exposed industrial systems. These actors opportunistically identify targets using publicly available scanning tools to search for internet-exposed systems with vulnerable configurations, such as using default or weak passwords or not using multi-factor authentication. Footnote31  After gaining access to these systems, they attempt to disrupt the system by defacing system interfaces, making configuration changes, and manipulating system controls. This activity can result in OT systems operating in unintended ways, operational disruptions, and, potentially, physical damage to the systems. For example, in early 2024, a non-state actor compromised the OT systems controlling water storage tanks in the towns of Abernathy and Muleshoe, Texas and caused a tank overflow resulting in the loss of roughly 100,000 litres of water. Footnote32 2024年5月、サイバーセンターとパートナー機関は共同で、インターネットに公開された産業システムを標的とする親ロシア系非国家主体の脅威に関する警告を発出した。これらの主体は、公開されているスキャンツールを駆使して、デフォルトまたは脆弱なパスワードの使用、多要素認証の不使用など、脆弱性を持つインターネットに晒されたシステムを機会主義的に識別する。これらのシステムへのアクセス権を獲得した後、システムインターフェースの改ざん、設定変更、システム制御の操作によってシステムの妨害を試みる。この活動は、OTシステムの意図しない動作、運用上の混乱、そして潜在的にはシステムへの物理的損傷を引き起こす可能性がある。例えば2024年初頭、非国家主体がテキサス州アバーナシー及びミュールシューの貯水タンク制御OTシステムを侵害し、タンクの溢水を引き起こして約10万リットルの水を損失させた事例がある。脚注32
The Cyber Centre is aware of several instances of non-state actors similarly attempting to disrupt internet-exposed OT systems in Canada, including within water systems. We assess that non-state actors will very likely continue to opportunistically compromise and disrupt internet-exposed water system OT within Canada, especially in connection to major geopolitical events. サイバーセンターは、カナダ国内のインターネットに晒されたOTシステム(水道システムを含む)に対し、非国家主体が同様の妨害を試みた複数の事例を把握している。非国家主体が、特に主要な地政学的イベントに関連して、カナダ国内のインターネットに接続された水道システムのOTを機会主義的に侵害・妨害し続ける可能性が極めて高いと評価する。
Outlook: What this means for the Canadian water sector 展望:カナダの水道部門にとっての意義
In the Cyber Centre’s National Cyber Threat Assessment 2025-2026, we assess that the cyber threat to Canada’s critical infrastructure is almost certainly increasing. We judge that the primary threats to CI come from cybercrime, state-sponsored adversaries and, increasingly, from non-state actors. Changes in the geopolitical environment have elevated the profile and importance of critical infrastructure as a target for cyber activity. This has combined with the increasing interconnectivity of IT and OT in the water sector to increase the cyber threat to the water supply. サイバーセンターの「2025-2026年国家サイバー脅威評価」では、カナダの重要インフラに対するサイバー脅威がほぼ確実に増加していると評価している。重要インフラに対する主な脅威は、サイバー犯罪、国家支援アクター、そして増加傾向にある非国家主体から生じると判断する。地政学的環境の変化により、重要インフラはサイバー活動の標的として注目度と重要性を高めている。これに加え、水道分野におけるITとOTの相互接続性の高まりが、水道供給へのサイバー脅威を増大させている。
If Canada’s water infrastructure was to become a priority for state-sponsored actors, for example in the case of imminent or active armed conflict, we assess that any water system organizations with OT devices exposed to the Internet are almost certainly a target for disruptive cyber threat activity. Water systems may also be affected by cyber activity against other sectors due to the interconnected nature of infrastructure and supply chain complexity. For example, systems including water treatment plants, pumping stations, and distribution networks without backup power capacity may be vulnerable to disruptions in the energy sector, which may lead to interruptions in the treatment, storage and distribution of safe water to clients. 例えば差し迫った武力紛争や進行中の武力紛争において、カナダの水インフラが国家支援アクターの優先標的となった場合、インターネットに接続されたOT機器を有する水道システム組織は、ほぼ確実に破壊的サイバー脅威活動の標的となると評価する。インフラの相互接続性とサプライチェーンの複雑性により、水道システムは他セクターに対するサイバー活動の影響も受ける可能性がある。例えば、浄水場、ポンプ場、配水網を含むシステムで予備電源容量がない場合、エネルギー分野の混乱に対して脆弱であり、顧客への安全な水の処理・貯蔵・供給が中断される可能性がある。
Defending Canada’s water sector against cyber threats and related influence operations requires addressing both the technical and social elements of cyber threat activity. These include threats that originate in the digital supply chain, and the technology and skills shortage in the sector. There are almost certainly water system operators in Canada with exposed devices. The Cyber Centre encourages all critical infrastructure asset owners, including those in the water sector, to take appropriate mitigation measures to protect their systems against cyber threats. カナダの水道分野をサイバー脅威や関連する影響工作から守るには、サイバー脅威活動の技術的要素と社会的要素の両方に対処する必要がある。これにはデジタル供給網に起因する脅威や、同分野の技術・技能不足が含まれる。カナダには、ほぼ確実にデバイスが露出している水道システム運営者が存在する。サイバーセンターは、水道部門を含む全ての重要インフラ資産所有者に対し、サイバー脅威からシステムを保護するための適切な緩和措置を講じるよう促す。
Mitigation 緩和策
The Cyber Centre is dedicated to advancing cyber security and increasing the confidence of Canadians in the systems they rely on daily. This includes offering support to CI and other systems of importance to Canada. We approach security through collaboration, combining expertise from government, industry and academia. Working together, we can increase Canada’s resilience against cyber threats. Cyber security investments will allow OT asset operators to benefit from new technologies, while avoiding undue risks to the safe and reliable provision of critical services to Canadians. サイバーセンターは、サイバーセキュリティの向上と、カナダ国民が日常的に依存するシステムへの信頼強化に尽力している。これには、重要インフラ(CI)やカナダにとって重要なその他のシステムへの支援提供も含まれる。我々は、政府、産業界、学界の専門知識を結集した協働を通じてセキュリティに取り組む。協力することで、カナダはサイバー脅威に対するレジリエンスを高められる。サイバーセキュリティへの投資により、OT資産の運営者は新技術の恩恵を受けつつ、カナダ国民への重要サービスの安全かつ確実な提供に対する不必要なリスクを回避できる。
The following mitigation measures can help water systems operators prevent cyber threat actors from exploiting vulnerable systems, attacking devices and networks and stealing sensitive data. Each of the mitigations below are linked to the Cyber Centre’s Cyber Security Readiness Goals (CRGs). The CRGs are a set of baseline cyber security practices an organization can take to bolster their cyber security posture. Further details of each goal can be found in the Cross-Sector Cyber Security Readiness Goals Toolkit. The mitigations below are highlighted to help prevent and reduce cyber attacks against the water sector. 以下の緩和は、水道システム運営者が脆弱性の悪用、デバイスやネットワークへの攻撃、機密データの窃取といったサイバー脅威アクターを防ぐのに役立つ。下記の各緩和は、サイバーセンターのサイバーセキュリティ準備目標(CRG)に関連付けられている。CRGとは、組織がサイバーセキュリティ態勢を強化するために実施できる基本対策のセットである。各目標の詳細は「セクター横断型サイバーセキュリティ準備目標ツールキット」に記載されている。以下の緩和は、水道分野に対するサイバー攻撃の防止・軽減を目的として強調されている。
Protect all management interfaces 全ての管理インターフェースを防御する
Phishing-resistant MFA (CRG 2.7) フィッシング耐性のある多要素認証(MFA)(CRG 2.7)
Secure administrator workstation (CRG 2.21) 管理者のワークステーションを防御する(CRG 2.21)
Secure the supply chain サプライチェーンの保護
Vendor/supplier cyber security requirements (CRG 0.2) ベンダー/サプライヤーに対するサイバーセキュリティ要件(CRG 0.2)
Prevent credential theft 認証情報の窃取防止
Changing default passwords (CRG 2.0) デフォルトパスワードの変更(CRG 2.0)
Email security (CRG 2.11) 電子メールのセキュリティ(CRG 2.11)
Basic and OT cyber security training (CRG 2.8) 基本およびOT(オペレーショナルテクノロジー)向けサイバーセキュリティ研修(CRG 2.8)
Disable macros by default (CRG 2.12) マクロのデフォルト無効化(CRG 2.12)
Protect internet-accessible vulnerable assets and services インターネット経由でアクセス可能な脆弱な資産とサービスを防御する
No exploitable services on the internet (CRG 2.20) インターネット上に悪用可能なサービスを置かない(CRG 2.20)
Limit OT connections to public Internet (CRG 2.18) OT接続をパブリックインターネットに制限する(CRG 2.18)
Network segmentation (CRG 2.5) ネットワークセグメンテーション(CRG 2.5)
Mitigating known vulnerabilities (CRG 1.1) 既知の脆弱性を緩和する(CRG 1.1)
Improve cyber security incident response capability サイバーセキュリティインシデント対応能力を向上させる
Incident response plans (CRG 1.3) インシデント対応計画(CRG 1.3)
Asset inventory and network topology (CRG 1.0) 資産インベントリとネットワークトポロジー(CRG 1.0)
System backups and redundancy (CRG 2.14) システムバックアップと冗長性(CRG 2.14)

 

 

 

 

|

« 英国 NCSC Web PKIにおける証明書のプロビジョニングと管理 (2025.12.10) | Main | 米国 CISA他 親ロシア派ハクティビストによる米国及び世界の重要インフラへの機会主義的攻撃 (2025.12) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 英国 NCSC Web PKIにおける証明書のプロビジョニングと管理 (2025.12.10) | Main | 米国 CISA他 親ロシア派ハクティビストによる米国及び世界の重要インフラへの機会主義的攻撃 (2025.12) »