« 米国 NIST SP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始 (2026.01.22) | Main | IPA 「情報セキュリティ10大脅威 2026」を公開 (2026.01.29) »

2026.01.30

米国 NIST IR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイル

こんにちは、丸山満彦です。

NISTがIR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイルを公表し、意見募集をしていますね。。。

CSF 2.0をベースに、策定したものですね。。。このアプローチはガイドラインがとっちらからなくてよいですよね...で、


交通セクターの優先事項とベストプラクティスに沿っており、サイバーセキュリティ活動と成果の優先順位付けの指針として、あるいは新たなプログラム構築の出発点として活用できる。交通機関向けプロファイルは、交通機関が依存している、あるいは既に導入している既存のサイバーセキュリティプログラム、ガイドライン、ポリシーを補完するものであり、それらに取って代わるものではない。


ということのようです...

 

NIST - ITL

・2026.01.22 NIST IR 8576 (Initial Public Draft) Transit Cybersecurity Framework Community Profile

NIST IR 8576 (Initial Public Draft) Transit Cybersecurity Framework Community Profile NIST IR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイル
Announcement 発表
Transit operators face increasing cybersecurity risks that can impact the delivery of safe and reliable services. They must manage IT and OT system risks while meeting strict safety and operating demands. The Transit Cybersecurity Framework (CSF) Community Profile is a voluntary, risk-based guide designed to help U.S. transit agencies enhance cybersecurity while maintaining safe and efficient transit services. Built on CSF 2.0, it translates transit mission needs into a cybersecurity outcomes baseline that transit agencies can adopt and tailor to their unique operational environments.  公共交通事業者は、安全で信頼性の高いサービスの提供に影響を及ぼす可能性のあるサイバーセキュリティリスクの増大に直面している。厳格な安全基準と運用要件を満たしつつ、ITシステムとOTシステムのリスクを管理しなければならない。公共交通サイバーセキュリティ枠組み(CSF)コミュニティプロファイルは、米国の公共交通機関が安全かつ効率的な交通サービスを維持しつつサイバーセキュリティを強化するための、自主的なリスクベースの指針である。CSF 2.0を基盤とし、公共交通の使命上の必要性をサイバーセキュリティ成果の基準に翻訳したもので、公共交通機関が独自の運用環境に合わせて採用・調整できる。
As a non-regulatory and neutral entity, NIST developed the Transit Profile in collaboration with the transit community to provide cybersecurity considerations and guidelines tailored to the sector’s unique challenges. By working closely with transit operators, federal agencies, and other stakeholders, NIST ensures the Profile reflects industry needs while supporting voluntary adoption of cybersecurity best practices. 非規制かつ中立的な事業体であるNISTは、交通業界の特有の課題に合わせたサイバーセキュリティ上の考慮事項とガイドラインを提供するため、交通コミュニティと協力して本プロファイルを開発した。NISTは交通事業者、連邦機関、その他の関係者と緊密に連携することで、業界のニーズを反映しつつ、サイバーセキュリティのベストプラクティスの自主的な採用を支援している。
Abstract 概要
This document is a Cybersecurity Framework (CSF) Community Profile developed to support United States-based transit agencies. This “Transit Profile” is aligned with transit sector priorities and best practices and can be used as a guide for prioritizing cybersecurity activities and outcomes or as a starting point for building a new program. The Transit Profile was developed to complement, not replace, any existing cybersecurity programs, guidelines, or policies that transit agencies may rely on or have in place. 本文書は、米国を拠点とする交通機関を支援するために開発されたサイバーセキュリティ枠組み(CSF)コミュニティプロファイルである。この「交通機関向けプロファイル」は、交通セクターの優先事項とベストプラクティスに沿っており、サイバーセキュリティ活動と成果の優先順位付けの指針として、あるいは新たなプログラム構築の出発点として活用できる。交通機関向けプロファイルは、交通機関が依存している、あるいは既に導入している既存のサイバーセキュリティプログラム、ガイドライン、ポリシーを補完するものであり、それらに取って代わるものではない。

 

 

・[PDF] NIST.IR.8576.ipd

20260129-64633

 

 

Executive Summary  エグゼクティブサマリー
The Transit Cybersecurity Framework (CSF) Community Profile (“Transit Profile”) is a voluntary, risk-based guide designed to help U.S. transit agencies enhance cybersecurity while maintaining safe and efficient transit services. Built on the National Institute of Standards and Technology (NIST) CSF 2.0, it translates transit mission needs into a baseline of cybersecurity outcomes that transit agencies can adopt and tailor to their unique operational environments.  公共交通サイバーセキュリティ枠組み(CSF)コミュニティプロファイル(「公共交通プロファイル」)は、米国の公共交通機関が安全かつ効率的な交通サービスを維持しつつサイバーセキュリティを強化するための、自主的なリスクベースの指針である。国立標準技術研究所(NIST)CSF 2.0を基盤とし、公共交通のミッション要件をサイバーセキュリティ成果の基盤に翻訳したもので、各交通機関が独自の運用環境に合わせて採用・調整できる。
Transit agencies operate complex networks of business and operational systems, such as rail signaling, bus charging, scheduling, ticketing, and public information systems. The transition to digital, network-based communication has expanded the cyber attack surface, requiring agencies to manage cybersecurity risks alongside safety and operational demands. To address these challenges, the Transit Profile focuses on three strategic priorities: securing and managing critical assets to ensure safe and reliable operations, fostering collaboration with stakeholders and suppliers to enhance resilience and supply chain security, and continuously improving organizational processes and workforce cybersecurity awareness and capabilities.  公共交通機関は、鉄道信号、バス充電、運行計画、発券、公共情報システムなど、複雑な業務・運用システムのネットワークを運用している。デジタル化やネットワークベースの通信への移行によりサイバー攻撃対象領域が拡大し、安全性と運用上の要求に加え、サイバーセキュリティリスクの管理が機関に求められるようになった。これらの課題に対処するため、トランジット・プロファイルは三つの戦略的優先事項に焦点を当てる。安全で信頼性の高い運営を確保するための重要資産の保護と管理、レジリエンスとサプライチェーンの安全性を高めるための関係者・供給業者との連携促進、組織プロセスと従業員のサイバーセキュリティ意識・能力の継続的改善である。
The Transit Profile can help transit agencies focus resources on cybersecurity activities aligned with these strategic priorities by mapping them to relevant CSF Subcategories. This enables transit leaders to prioritize cybersecurity capabilities, perform gap analyses, and make informed decisions. The Profile integrates industry-specific cybersecurity considerations and guidelines for agencies of all sizes, including small- and medium-sized transit agencies (SMTAs) with limited resources, and supports scalable actions based on size and maturity. The Profile can enhance existing cybersecurity programs, helping agencies adopt best practices, establish a shared taxonomy for discussing cybersecurity risk with leadership, plan strategically, and communicate cybersecurity needs to stakeholders, suppliers, and funding entities.   トランジット・プロファイルは、これらの戦略的優先事項に関連するCSFサブカテゴリーにマッピングすることで、交通機関がリソースをこれらの活動に集中させることを支援する。これにより、交通機関のリーダーはサイバーセキュリティ能力の優先順位付け、ギャップ分析の実施、情報に基づいた意思決定が可能となる。本プロファイルは、業界固有のサイバーセキュリティ上の考慮事項とガイドラインを統合し、限られた資源を持つ中小規模交通機関(SMTA)を含むあらゆる規模の機関に対応する。また、規模と成熟度に基づいた拡張可能な行動を支援する。本プロファイルは既存のサイバーセキュリティプログラムを強化し、機関がベストプラクティスを採用し、経営陣とサイバーセキュリティリスクを議論するための共通分類法を確立し、戦略的に計画を立て、ステークホルダー、サプライヤー、資金提供事業体にサイバーセキュリティの必要性を伝達することを支援する。
The Profile is intended to complement, not replace, existing programs, standards, and regulatory obligations. As a non-regulatory and neutral entity, NIST developed the Transit Profile in collaboration with the transit community to provide cybersecurity considerations and guidelines tailored to the sector’s unique challenges. By working closely with transit operators, federal agencies, and other stakeholders, NIST ensures the Profile reflects industry needs while supporting voluntary adoption of cybersecurity best practices.  本プロファイルは、既存のプログラム、標準、規制上の義務を補完するものであり、それらに取って代わるものではない。非規制かつ中立的な事業体として、NISTは交通機関コミュニティと協力して交通機関向けプロファイルを開発し、この分野特有の課題に合わせたサイバーセキュリティ上の考慮事項とガイドラインを提供した。NISTは交通事業者、連邦機関、その他の利害関係者と緊密に連携することで、プロファイルが業界のニーズを反映しつつ、サイバーセキュリティのベストプラクティスの自主的な採用を支援することを保証している。
1. Introduction   1. 序論
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 introduced the concept of a Community Profile. A Community Profile is a baseline of CSF cybersecurity outcomes that is created and published to address shared interests and goals among a number of organizations. It is typically developed for a particular sector, subsector, technology, threat type, or other use case, and can be used by an organization as the basis for its own Organizational Target Profile [CSF2.0].   国立標準技術研究所(NIST)のサイバーセキュリティ枠組み(CSF)2.0は、コミュニティプロファイルの概念を導入した。コミュニティプロファイルとは、複数の組織間で共有される関心事や目標に対応するために作成・公開される、CSFサイバーセキュリティ成果の基盤である。通常、特定のセクター、サブセクター、技術、脅威の種類、その他のユースケース向けに開発され、組織が自らの組織別目標プロファイル[CSF2.0]の基盤として利用できる。
NIST developed the Transit Profile to provide a voluntary, risk-based approach for managing cybersecurity activities, reducing cybersecurity risks, and improving the cybersecurity posture of the transit community.    NISTは、公共交通コミュニティにおけるサイバーセキュリティ活動の管理、サイバーセキュリティリスクの低減、サイバーセキュリティ態勢の改善に向けた自発的かつリスクベースのアプローチを提供するため、公共交通プロファイルを開発した。
1.1. Purpose and Scope  1.1. 目的と範囲
This document represents a CSF Community Profile that describes shared interests, goals, and outcomes for mitigating cybersecurity risk within the transit community. Transit agencies, as defined in this Profile, include owners and operators of public transportation services, including bus and transit rail systems (e.g., light rail, subway, commuter rail), as well as affiliated entities such as county governments overseeing and/or funding transit operations.   本文書は、公共交通コミュニティにおけるサイバーセキュリティリスク緩和のための共通の関心事項、目標、成果を記述するCSFコミュニティプロファイルである。本プロファイルで定義する公共交通機関には、バスや公共鉄道システム(例:ライトレール、地下鉄、通勤鉄道)を含む公共交通サービスの所有者・運営者、ならびに公共交通運営を監督・資金提供する郡政府などの関連事業体が含まれる。
The Transit Profile suggests prioritization of cybersecurity outcomes to meet specific strategic business/mission focus areas for the transit community and identifies relevant and actionable security practices that can be implemented in support of those areas. It is intended to complement, not replace, any existing cybersecurity programs, guidelines, or policies that transit agencies may already have in place.    本トランジット・プロファイルは、公共交通コミュニティの特定の戦略的事業/ミッション重点領域に対応するため、サイバーセキュリティ成果の優先順位付けを提案し、それらの領域を支援するために実施可能な関連性のあるセキュリティ実践を識別する。これは、公共交通機関が既に導入している既存のサイバーセキュリティプログラム、ガイドライン、またはポリシーを補完するものであり、それらに取って代わるものではない。   
The Transit Community Profile:    公共交通コミュニティ・プロファイル:
•  Describes a shared taxonomy to support communication about cybersecurity risk management for transit owners/operators    • 交通機関の所有者・運営者向けサイバーセキュリティリスクマネジメントに関する共通の分類体系を提示する
•  Offers a framework to aggregate transit cybersecurity considerations and guidelines from multiple industry resources     • 複数の業界リソースから交通機関のサイバーセキュリティに関する考慮事項とガイドラインを集約する枠組みを提供する
•  Develops common target outcomes that transit owners and operators can use to support strategic planning efforts and cybersecurity assessments    • 交通機関の所有者・運営者が戦略的計画策定やサイバーセキュリティアセスメントに活用できる共通目標成果を開発する
•  Assists in identifying and communicating cybersecurity needs to the broader transit community of suppliers, operating partners, and funding entities  • 供給業者、運営パートナー、資金提供事業体など広範な交通コミュニティに対し、サイバーセキュリティニーズの特定と伝達を支援する 
•  Provides scalable and achievable cybersecurity considerations and guidelines for transit owners/operators of all sizes   • あらゆる規模の交通機関所有者・運営者向けに、拡張性と実現可能性を備えたサイバーセキュリティ上の考慮事項とガイドラインを提供する。  
1.2. Audience  1.2. 対象読者
This document focuses on cybersecurity considerations specific to transit agencies and assumes readers have a foundational understanding of operational technology (OT) and general information technology (IT) security concepts. The intended audience includes:  本文書は交通機関特有のサイバーセキュリティ上の考慮事項に焦点を当て、読者が運用技術(OT)および一般的な情報技術(IT)セキュリティ概念の基礎的理解を有することを前提とする。対象読者は以下の通りである:
•  Control engineers, integrators, system suppliers, and architects involved in designing or implementing secure transit systems.  • 安全な交通システムの設計または実装に携わる制御エンジニア、インテグレーター、システム供給業者、アーキテクト。
•  System and network administrators, cybersecurity professionals, physical security personnel, and OT operators responsible for managing, patching, or securing transit systems.  • 交通システムの管理、パッチ適用、セキュリティ確保を担当するシステム・ネットワーク管理者、サイバーセキュリティ専門家、物理的セキュリティ担当者、OTオペレーター。
•  Executives and management teams overseeing transit operations.  • 交通運営を監督する経営幹部および管理チーム。
•  Senior security officials evaluating cyber risks and implementing cybersecurity programs to support transit operations.  • 交通運営を支援するため、サイバーリスクを評価しサイバーセキュリティプログラムを実施する上級セキュリティ担当者。
•  Affiliated entities, such as federal agencies and county governments that oversee and/or fund transit agencies.  • 交通機関を監督および/または資金提供する連邦機関や郡政府などの関連事業体。
•  Transit industry associations and researchers seeking to understand the unique cybersecurity needs of transit systems.  • 交通システムの特有のサイバーセキュリティニーズを理解しようとする交通業界団体および研究者。
1.3. Document Structure  1.3. 文書構成
The remainder of the Transit Profile is divided into the following sections:  本交通プロファイルの残りの部分は以下のセクションに分かれる:
•  Section 2 provides a summary of challenges to securing transit systems.  • セクション2は交通システムのセキュリティ確保における課題の概要を提供する。
•  Section 3 provides an overview of the NIST CSF 2.0.  • セクション3はNIST CSF 2.0の概要を説明する。
•  Section 4 describes the Transit Profile development methodology.  • セクション4は交通プロファイルの開発手法を記述する。
•  Section 5 provides the transit sector-specific rationale, guidelines, and considerations for prioritized CSF Subcategories.   • セクション5は優先順位付けされたCSFサブカテゴリーに関する交通セクター固有の根拠、ガイドライン、考慮事項を提供する。
•  References provide a list of references used in the development of this document.  • 参考文献は、本文書作成に使用した参考文献の一覧を提供する。
•  Appendix A provides a selected bibliography of resources used to inform the Profile.  • 附属書Aは、プロファイル作成の参考とした選定文献目録を提供する。
•  Appendix B provides a complete listing of all CSF Subcategory designations.  • 附属書Bは、全てのCSFサブカテゴリーの名称を完全なリストとして提供する。
•  Appendix C provides a list of acronyms and abbreviations used in this document.   • 附属書Cは、本文書で使用した頭字語と略語の一覧を提供する。
2. Challenges to Securing Transit Systems  2. 公共交通システムのセキュリティ確保における課題 
Transit agencies manage a complex network of business and operational systems in service to their mission. Examples can include:   公共交通機関は、その使命を果たすために複雑な業務・運用システムのネットワークを管理している。例としては以下が挙げられる:
•  Rail signaling and train control systems   • 鉄道信号および列車制御システム
•  Bus fueling, battery-electric charging, and charge management systems   • バス燃料補給、バッテリー電気充電、充電管理システム
•  Scheduling and dispatching   • 運行計画と配車
•  Facility management systems   • 施設管理システム
•  Emergency communications systems   • 緊急通信システム
•  Control and communication systems   • 制御およびコミュニケーションシステム
•  Ticketing systems   • チケットシステム
•  Command centers   • 指令センター  
•  Revenue collection systems, including back office and fare payment systems   • 収益徴収システム、バックオフィスおよび運賃支払いシステムを含む
•  Public information systems, such as station-based electronic signage and web and mobile applications/systems   公共情報システム、例えば駅に設置された電子看板やウェブ・モバイルアプリケーション/システムなど
Traditionally, many of these systems relied on direct connections for communications. Today, communication between and among these systems is digital and network-based, including through the extensive use of wireless connectivity. This dependence on digital technology and interconnections to sustain daily operations has widened the cyber attack surface for transit agencies. Operators must now manage the cybersecurity risk of their IT and OT systems while meeting increasingly demanding safety and operating requirements.    従来、こうしたシステムの多くはコミュニケーションに直接接続に依存していた。今日では、これらのシステム間のコミュニケーションはデジタル化されネットワークベースとなり、無線接続の広範な利用も含まれる。日常業務を維持するためのデジタル技術と相互接続への依存は、交通機関のサイバー攻撃対象領域を拡大させた。運営者は今や、ますます厳しくなる安全性と運用要件を満たしつつ、ITシステムとOTシステムのサイバーセキュリティリスクを管理しなければならない。
Several aspects of the transit sector make it uniquely challenging to protect and require a more tailored approach to prioritize and apply cybersecurity risk management measures. These include:   交通部門には、防御が特に困難で、サイバーセキュリティリスクマネジメント措置の優先順位付けと適用により特化したアプローチを必要とする点がいくつかある。具体的には以下の通りだ:  
•  Safety-centric culture. A transit agency’s top responsibility is safety. Cybersecurity knowledge and awareness in many agencies is still maturing. The American Public Transportation Association (APTA), federal agencies, suppliers, and the operating agencies themselves have worked to develop and organize resources to advance cybersecurity awareness and protections specific to transit operations. Cybersecurity measures and training must continue to be integrated into an agency’s overall safety framework to improve effectiveness.   • 安全中心の文化。交通機関の最優先責任は安全である。多くの機関ではサイバーセキュリティに関する知識と認識がまだ成熟段階にある。米国公共交通協会(APTA)、連邦機関、サプライヤー、そして運営機関自身が連携し、公共交通事業に特化したサイバーセキュリティ意識向上および保護策を推進するための資源開発・体系化に取り組んできた。効果を高めるためには、サイバーセキュリティ対策と訓練を機関全体の安全枠組みに継続的に統合する必要がある。  
•  Safety-critical control systems. Safety-critical control systems—such as signaling and train control for rail, and steering, acceleration, and brake control for buses—are governed by standards which may not fully account for cybersecurity risk. Cybersecurity risk mitigations for these systems must be carefully implemented to ensure they meet safety and industry standards without triggering the need for safety recertification.   • 安全上重要な制御システム。鉄道の信号・列車制御システムや、バスの操舵・加速・ブレーキ制御システムなど、安全上重要な制御システムは、サイバーセキュリティリスクを完全に考慮していない標準によって管理されている。これらのシステムに対するサイバーセキュリティリスク緩和策は、安全基準や業界基準を満たしつつ、安全再認証の必要性を引き起こさないよう慎重に実施されねばならない。  
•  Long-lived and legacy systems. Most transit agencies simultaneously manage both modern and legacy IT and OT infrastructure and systems. Many systems and assets in the transit sector have long lifecycles measured in decades, not years, and may not be able to accommodate modern cybersecurity controls (e.g., multifactor authentication (MFA), advanced encryption). This is evident in legacy systems and also applies to longlived OT systems that are remote, difficult to access, or challenging to update. Retrofitting these systems for cybersecurity purposes can be cost-prohibitive and disruptive, and compensating cybersecurity controls may be needed to meet security outcomes.    • 長寿命かつレガシーなシステム。ほとんどの交通機関は、現代的なIT・OTインフラとレガシーなIT・OTインフラ・システムを同時に管理している。交通分野の多くのシステムや資産は、数年ではなく数十年単位の長いライフサイクルを持ち、現代的なサイバーセキュリティ対策(例:多要素認証(MFA)、高度な暗号化)に対応できない場合がある。これはレガシーシステムに顕著であり、遠隔地にある、アクセスが困難な、更新が難しい長寿命のOTシステムにも当てはまる。これらのシステムをサイバーセキュリティ対策のために改修することは、費用がかかりすぎて現実的ではなく、業務に支障をきたす可能性がある。そのため、セキュリティ目標を達成するには、代替となるサイバーセキュリティ対策が必要となる場合がある。   
•  Communication systems. Communication systems (e.g., Wi-Fi, radio, cellular, satellite, wired) are the backbone of public transit operations, supporting coordination between buses, vehicles, trains, control centers, and infrastructure. They facilitate real-time updates, signaling, dispatching, and monitoring. Any disruption or compromise of these systems can lead to operational failures and delays, adversely affecting the safety and reliability of transit systems.   • コミュニケーションシステム。コミュニケーションシステム(例:Wi-Fi、無線、携帯電話、衛星、有線)は公共交通運営の基盤であり、バス、車両、列車、管制センター、インフラ間の連携を支えている。これらはリアルタイムの更新、信号伝達、配車、監視を可能にする。これらのシステムの障害や侵害は、運行の失敗や遅延を引き起こし、交通システムの安全性と信頼性に悪影響を及ぼす。  
•  Vendor supply chain. Transit agency systems and components are supplied by a large variety of domestic and global suppliers. Likewise, transit agencies rely heavily on vendor services and contractors to install, manage, and maintain their IT and OT systems and infrastructure. Cybersecurity supply chain risk management must be part of an organization-wide risk management strategy.    • ベンダーのサプライチェーン。交通機関のシステムや構成部品は、国内外の多様なサプライヤーから供給されている。同様に、交通機関はITシステムやOTシステム、インフラの設置・管理・保守においてベンダーサービスや請負業者に大きく依存している。サイバーセキュリティのサプライチェーンリスクマネジメントは、組織全体のリスクマネジメント戦略の一部でなければならない。
•  Distributed and mobile operations. Transit operations and their support systems are geographically dispersed with rolling stock. Rail operators, for example, manage systems and sensors that encompass the rail network and associated facilities. Likewise, bus operators support moving assets, garages, and maintenance facilities that are deployed across a metropolitan region.    • 分散型・移動型運用。交通運用とその支援システムは、車両と共に地理的に分散している。例えば鉄道事業者は、線路網と関連施設を網羅するシステムやセンサーを管理する。同様にバス事業者は、大都市圏全体に展開された移動資産、車庫、保守施設を支援する。
•  Physical security concerns. Transit assets and infrastructure are both accessible to and used by the public. Many of the supporting systems are also distributed across a broad region, making physical security more challenging and exposing certain elements, such as telecommunications systems or wayside equipment, to potential unauthorized physical and logical access by malicious actors.   • 物理的セキュリティ上の懸念。公共交通資産とインフラは一般市民が利用可能であり、実際に利用されている。多くの支援システムも広域に分散しているため、物理的セキュリティの確保がより困難であり、通信システムや沿線設備などの特定要素が悪意ある者による不正な物理的・論理的アクセスに晒されるリスクがある。
•  Funding. Transit agencies, as public sector entities, generally rely on subsidies to cover their capital and operating costs. This creates a unique challenge in obtaining the necessary funds to implement and manage cybersecurity measures for protecting their systems. While agencies can pursue a variety of funding sources, such as capital funding, operating funding, and grant funding, these sources must address multiple competing priorities. Additionally, even when funding is approved, it typically involves a lengthy authorization process, making it difficult to secure resources for cybersecurity needs. This unpredictability and long lead time can work against efforts to address  cybersecurity needs promptly.  • 資金調達。公共交通機関は公共部門の事業体として、一般的に資本コストと運営コストを賄うために補助金に依存している。このため、システム防御のためのサイバーセキュリティ対策を実施・管理するに必要な資金調達が特有の課題となる。機関は資本資金、運営資金、助成金など多様な資金源を追求できるが、これらの資金源は複数の競合する優先事項に対応しなければならない。さらに、資金が承認された場合でも、通常は長い認可プロセスを伴うため、サイバーセキュリティのニーズに対応する資源を確保するのは困難だ。この予測不可能性と長いリードタイムは、サイバーセキュリティのニーズに迅速に対応する取り組みの妨げとなり得る。

 

 

 


 

● まるちゃんの情報セキュリティ気まぐれ日記

・2025.12.26 米国 NIST IR 8596(初期ドラフト)人工知能向けサイバーセキュリティ枠組みプロファイル(Cyber AI Profile):NISTコミュニティプロファイル (2025.12.16)

・2025.10.03 米国 NIST IR 8183 Rev. 2 (初期公開ドラフト) サイバーセキュリティ・フレームワーク2.0 製造業プロファイル (2025.09.29)

・2025.08.22 米国 NIST CSWP 51(初期公開ドラフト) 交通機関のサイバーセキュリティフレームワークコミュニティプロファイルの開発:プロジェクトの最新情報

・2025.04.07 米国 NIST SP 800-61 Rev. 3 サイバーセキュリティリスク管理のためのインシデント対応に関する推奨事項および考慮事項:CSF 2.0 コミュニティプロファイル (2025.04.03)

・2025.03.11 米国 NIST IR 8546(初期公開ドラフト)サイバーセキュリティフレームワーク2.0 半導体製造プロファイル (2025.02.27)

・2025.01.26 米国 NIST IR 8374 Rev.1(初期公開ドラフト)ランサムウェアのリスクマネジメント: サイバーセキュリティフレームワーク2.0コミュニティ (2025.01.13)

・2024.12.26 米国 NIST CSWP 35(初期公開ドラフト) ゲノムデータシーケンスワークフローのサイバーセキュリティ脅威モデリング:ゲノムデータシーケンスおよび分析のための脅威モデル実装例

・2024.12.26 米国 NIST IR 8467 (第2次公開ドラフト) ゲノムデータのサイバーセキュリティとプライバシーフレームワーク コミュニティプロファイル (2024.12.16)

・2024.07.31 米国 NIST SP 800-218A 生成的AIとデュアルユース基盤モデルのための安全なソフトウェア開発プラクティス: SSDFコミュニティプロファイル

・2024.04.05 米国 意見募集 NIST SP 800-61 Rev.3(初期公開ドラフト) サイバーセキュリティリスクマネジメントのためのインシデント対応の推奨と考慮事項: CSF 2.0 コミュニティプロファイル

・2024.03.07 米国 NSIT サイバーセキュリティ・フレームワーク(CSF)2.0 関連 SP 1299, 1300, 1301, 1302, 1303, 1305 (2024.02.26)

・2024.03.06 米国 NIST CSWP 32(初期公開ドラフト)サイバーセキュリティフレームワーク 2.0: コミュニティプロファイル作成ガイド (2024.02.26)

・2024.02.28 米国 NIST CSWP 29 NISTサイバーセキュリティフレームワーク(CSF)2.0

 

|

« 米国 NIST SP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始 (2026.01.22) | Main | IPA 「情報セキュリティ10大脅威 2026」を公開 (2026.01.29) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 米国 NIST SP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始 (2026.01.22) | Main | IPA 「情報セキュリティ10大脅威 2026」を公開 (2026.01.29) »