英国 NCSC 中小企業向けマネージド・サービスプロバイダー選定ガイド (2025.11.24)
こんにちは、丸山満彦です。
英国のNCSCが、中小企業向けのマネージドサービス・プロバイダー選定ガイドが公表されていますね...
250名以上の企業の場合は、2018年策定(2023年最終改定)されたクラウドセキュリティガイダンスの利用が推奨されていますね...
● NCSC
・2025.11.24 Choosing a managed service provider (MSP)
| Choosing a managed service provider (MSP) | マネージドサービス・プロバイダー(MSP)の選定 |
| An SME’s guide to selecting and working with managed service providers. | 中小企業向け:MSPの選定と活用ガイド |
| in this guidance | 本ガイダンスの内容 |
| Introduction: SMEs are at risk | 序論:中小企業はリスクに晒されている |
| Choosing an appropriate MSP | 適切なMSPの選定 |
| Security issues to discuss with your MSP | MSPと協議すべきセキュリティ課題 |
| Details to check in your MSP contract | MSP契約で確認すべき事項 |
| MSP due diligence checklis | MSPデューデリジェンスチェックリスト |
| Many small to medium-sized enterprises (SMEs) use managed service providers (MSPs) to deliver IT products and services, manage important data, and to provide cyber security. This guidance describes how to select and work effectively with MSPs, and includes a checklist you can use when sourcing MSPs. | 多くの中小企業(SME)は、IT製品・サービスの提供、重要データの管理、サイバーセキュリティ対策のためにマネージドサービス・プロバイダー(MSP)を利用している。本ガイダンスでは、MSPの選定方法と効果的な連携手法を説明し、MSP調達時に使用できるチェックリストを掲載する。 |
| Note: | 注記: |
| If you’re part of an IT team responsible for working with MSPs within larger organisations (over 250 people), you should refer to the NCSC’s more detailed Cloud Security Guidance. | 大規模組織(従業員250名以上)においてMSPとの連携を担当するITチームの一員である場合は、NCSCのより詳細なクラウドセキュリティガイダンスを参照すべきである。 |
| MSP due diligence checklist | MSPデューデリジェンスチェックリスト |
| Choosing an MSP | MSPの選定 |
| Does the MSP hold recognised security certifications (e.g., Cyber Essentials Plus, ISO 27001)? If not, what security standards do they use? | MSPは公認のセキュリティ認証(例:Cyber Essentials Plus、ISO 27001)を保持しているか?保持していない場合、どのセキュリティ標準を採用しているか? |
| Can they provide references, testimonials or case studies from other SMEs? | 他の中小企業からの推薦状、証言、事例研究を提供できるか? |
| Do they have a proven track record of security and service quality? | セキュリティとサービス品質において実績があるか? |
| Do they demonstrate transparency about their services and processes? | サービスとプロセスについて透明性を示しているか? |
| Are their service levels (response times, uptime) clearly defined in SLAs? | サービスレベル(応答時間、稼働時間)はSLAで明確に定義されているか? |
| Do they fit your needs and budget? | 自社のニーズと予算に合致しているか? |
| Services to request | 要求すべきサービス |
| Timely patch management for all systems and software | 全システム・ソフトウェアに対するタイムリーなパッチ管理 |
| Automated, off-site data backups and regular testing of restore processes | 自動化されたオフサイトデータバックアップと復元プロセスの定期テスト |
| Security monitoring and logging, with alerts for suspicious activity | セキュリティ監視・ログ記録、不審な活動に対するアラート |
| Use of 2SV across all access points | 全アクセスポイントでの2段階認証(2SV)の使用 |
| Clear incident response and management procedures | 明確なインシデント対応・管理手順 |
| Application of timely security updates and firmware patches | タイムリーなセキュリティ更新とファームウェアパッチの適用 |
| Contract and agreement considerations | 契約と合意事項の検討点 |
| Is there a detailed Service Level Agreement (SLA)? | 詳細なサービスレベル契約(SLA)は存在するか? |
| Are roles, responsibilities, and liabilities clearly defined? | 役割、責任、賠償責任は明確に定義されているか? |
| Does the contract specify how and when security incidents are notified? | 契約書はセキュリティインシデントの通知方法と時期を規定しているか? |
| Are there provisions for regular reviews and reporting? | 定期的な見直しと報告に関する条項は存在するか? |
| Is the principle of least privilege applied to MSP access? | MSPアクセスには最小権限の原則が適用されているか? |
| Are there clauses for managing obsolete accounts and infrastructure? | 廃止されたアカウントとインフラを管理する条項は存在するか? |
| Is there a clear process for contract review, renewal, or termination? | 契約の見直し、更新、解約に関する明確なプロセスは存在するか? |
| Risk and responsibility | リスクと責任 |
| Have you assessed your MSP’s supply chain risks? | MSPのサプライチェーンリスクを評価したか? |
| MSP’s supply chain risks | MSPのサプライチェーンリスク |
| Are accountability and liability for cyber security incidents explicitly documented? | サイバーセキュリティインシデントに対する説明責任と責任が明示的に文書化されているか? |
| Do MSPs have a tested incident response and recovery plan? | MSPはテスト済みのインシデント対応および復旧計画を有しているか? |
| Are backup and disaster recovery procedures outlined and agreed upon? | バックアップおよび災害復旧手順が明記され合意されているか? |
| Is there a process for regular security training and awareness | 定期的なセキュリティ研修および意識向上のためのプロセスは存在するか? |
参考にクラウドセキュリティガイダンス...
・2023.06.07 Cloud security guidance
グーグルとマイクロソフトのチェックリストも参考になりますね...
・Google Workspace: Security checklist for small businesses (1-100 users)
・Microsoft 365: Top 10 ways to secure your data with Microsoft 365
« 欧州 政策研究センター (CEPS) 量子安全な世界へのEU移行強化 (2025.12.03) | Main | カナダ 英国 NCSC 組織のための公開コンテンツの来歴証明(provenance)(2025.12.04) »

Comments