« 欧州 EDPB GDPR第46条(3)(a)に基づく契約条項の認可、およびGDPR第46条(2)(d)に基づく標準契約条項の採択に関する協力手続きを定めたEDPB文書 | Main | 米国 NIST IR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイル »

2026.01.29

米国 NIST SP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始 (2026.01.22)

こんにちは、丸山満彦です。

NISTがm2023年9月に公表された、NIST SP 800-82 Rev.3の発表後に得られた教訓を反映し、関連するNISTガイダンス(例:サイバーセキュリティ枠組み(CSF)2.0、NIST IR 8286 Rev. 1、NIST SP 800-53 Rev. 5.2.0)およびOTサイバーセキュリティ標準・実践と整合させ、OT脅威環境の変化に対応するため、Rev.4への改訂をすすめているようですね...

NIST - ITL

・2026.01.22 NIST SP 800-82 Rev. 4 (Initial Preliminary Draft) Pre-Draft Call for Comments: Guide to Operational Technology (OT) Security

 

NIST SP 800-82 Rev. 4 (Initial Preliminary Draft) Pre-Draft Call for Comments: Guide to Operational Technology (OT) Security NIST SP 800-82 Rev. 4(初期ドラフト)ドラフト前の意見募集:運用技術(OT)セキュリティガイド
Announcement お知らせ
NIST has initiated the process of revising SP 800-82, Guide to Operational Technology (OT) Security, to incorporate lessons learned, align with relevant NIST guidance (e.g., Cybersecurity Framework (CSF) 2.0, NIST IR 8286 Rev. 1, NIST SP 800-53 Rev. 5.2.0) and OT cybersecurity standards and practices, and address changes in the OT threat landscape. NISTはSP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始した。これは、得られた教訓を反映し、関連するNISTガイダンス(例:サイバーセキュリティ枠組み(CSF)2.0、NIST IR 8286 Rev. 1、NIST SP 800-53 Rev. 5.2.0)およびOTサイバーセキュリティ標準・実践と整合させ、OT脅威環境の変化に対応するためである。
NIST invites the public to suggest improvements on the document’s effectiveness, relevance, and general use to better help the OT community understand and manage their cybersecurity risk. NISTは、OTコミュニティがサイバーセキュリティリスクを理解し管理する上でより役立つよう、本文書の有効性、関連性、一般的な利用性に関する改善提案を公衆から募集する。
The public comment period is open through February 23, 2026. Submit comments to sp800-82rev4@nist.gov with the subject “Comments on SP 800-82.” パブリックコメントの受付期間は2026年2月23日までである。コメントは件名を「SP 800-82に関するコメント」としてsp800-82rev4@nist.gov宛に提出すること。
Specifically, NIST requests input on the following proposed changes: 具体的には、NISTは以下の変更案について意見を求めます:
1. Expanded guidance for different types of OT systems 1. 様々な種類のOTシステムに対するガイダンスの拡充
The proposed revision would expand guidance for different types of OT systems (e.g., building automation systems, transit systems, maritime systems). What types of OT systems should be highlighted in this expanded guidance? 提案された改訂では、様々な種類のOTシステム(例:ビルオートメーションシステム、交通システム、海事システム)に対するガイダンスを拡充する。この拡充されたガイダンスで特に強調すべきOTシステムの種類は何か?
2. Expanded guidance for the application of technologies and capabilities in OT environments 2. OT環境における技術・機能の適用に関する拡張ガイダンス
The proposed revision would provide new or expanded guidance on the use of various technologies and capabilities (e.g., behavioral anomaly detection, digital twins, Internet of Things, artificial intelligence, machine learning, zero trust, cloud, 5G and advanced wireless, edge computing) in OT environments. What technologies and capabilities should be highlighted in the revised guidance? 提案された改訂では、OT環境における様々な技術・機能(例:行動異常検知、デジタルツイン、モノのインターネット、人工知能、機械学習、ゼロトラスト、クラウド、5G及び先進無線技術、エッジコンピューティング)の使用に関する新規または拡張されたガイダンスを提供する。改訂ガイダンスで強調すべき技術・機能は何か?
3. Updates to OT threats, vulnerabilities, standards, and recommended practices 3. OT脅威、脆弱性、標準、推奨実践の更新
The proposed revision would update guidance throughout the document to align with current OT cybersecurity standards and recommended practices. Updates would also be made to the OT threat landscape, vulnerabilities, incidents that have occurred, current activities in OT cybersecurity, and the cybersecurity capabilities, tools, and mitigations sections. How can NIST best both capture theses updates and provide an ongoing reference to other resources? 提案された改訂では、現在のOTサイバーセキュリティ標準および推奨実践に整合させるため、文書全体のガイダンスを更新する。また、OT脅威状況、脆弱性、発生したインシデント、OTサイバーセキュリティにおける現在の活動、ならびにサイバーセキュリティ能力、ツール、緩和策のセクションについても更新が行われる。NISTはこれらの更新をどのように捉え、他のリソースへの継続的な参照を提供するのが最適か?
4. Move various appendices to separate documents or web resources 4. 各種附属書を別文書またはウェブリソースへ移動
The proposed revision would move Appendix F (OT Overlay), to its own separate document. The proposed revision would also move Appendix C (Threat Sources, Vulnerabilities, and Incidents), Appendix D (OT Security Organizations, Research, and Activities), and Appendix E (OT Security Capabilities and Tools) to dynamic web resources. Would moving these Appendices improve the readability of the document? 提案された改訂では、附属書F(OTオーバーレイ)を独立した文書に移す。また附属書C(脅威源、脆弱性、インシデント)、附属書D(OTセキュリティ組織、研究、活動)、附属書E(OTセキュリティ能力とツール)を動的なウェブリソースに移す。これらの附属書を移すことで文書の読みやすさは向上するか?
5. Removal of material from the current document 5. 現行文書からの内容削除
The proposed revision would consider removing material that is outdated, unneeded, or no longer applicable. What material is seen as no longer needed or applicable in the document? When providing comments, please be specific and include the rationale for any proposed additions or deletions of material. 提案された改訂では、時代遅れ、不要、または適用されなくなった内容の削除を検討する。文書内で不要または適用されなくなったと見なされる内容は何か。コメントを提出する際は、具体的に記載し、内容の追加または削除提案の根拠を含めること。

 

現在のものは、

・[PDF] NIST.SP.800-82r3

20260129-62928

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2025.10.03 米国 NIST SP 1334 OT環境における可搬保管媒体のサイバーセキュリティリスク低減 (2025.09.30)

・2025.07.24 米国 NIST SP 1334( 初期公開ドラフト) OT 環境における可搬保管媒体のサイバーセキュリティリスクの軽減 (2025.07.15)

・2023.10.01 NIST SP 800-82 第3版 OTセキュリティガイド

・2022.04.28 NIST SP 800-82 第3版 OTセキュリティガイド(ドラフト)

・2021.08.02 米国 連邦政府 重要インフラ制御システムのサイバーセキュリティの向上に関する国家安全保障に関する覚書

少し昔ですが...

・2011.06.10 NIST Special Publication 800-82, Guide to Industrial Control System (ICS) Security.

 

|

« 欧州 EDPB GDPR第46条(3)(a)に基づく契約条項の認可、およびGDPR第46条(2)(d)に基づく標準契約条項の採択に関する協力手続きを定めたEDPB文書 | Main | 米国 NIST IR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイル »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 欧州 EDPB GDPR第46条(3)(a)に基づく契約条項の認可、およびGDPR第46条(2)(d)に基づく標準契約条項の採択に関する協力手続きを定めたEDPB文書 | Main | 米国 NIST IR 8576(初期ドラフト) 公共交通サイバーセキュリティ枠組み コミュニティプロファイル »