Five eyes(英国除く)低軌道衛星通信システムのリスクと緩和に関する共同ガイダンス (2026.03.25)
こんにちは、丸山満彦です。
オーストラリアのCyber Security Centre、Space Agency、カナダのCCCS、ニュージーランドのNCSC、米国のNSAが共同で、低軌道衛星通信システムのリスクと緩和に関する共同ガイダンスを公表していますね...
オーストラリアが主導したのに、他国が乗ってきた?
3つのセグメントに分けるのは、共通的ですね...
● Australian Cyber Security Centre: ACSC
・2026.03.26 Securing space – Cyber security for LEO SATCOM
| Securing space – Cyber security for LEO SATCOM | 宇宙の安全確保 ― 低軌道(LEO)衛星通信のサイバーセキュリティ |
| Low Earth Orbit (LEO) satellite communication (SATCOM) services are expanding rapidly, offering new connectivity options but also introducing new cyber security risks. | 低軌道(LEO)衛星通信(SATCOM)サービスは急速に拡大しており、新たな接続手段を提供する一方で、新たなサイバーセキュリティリスクももたらしている。 |
| ASD’s ACSC, together with the Australian Space Agency, the Canadian Centre for Cyber Security, the National Security Agency, and the New Zealand National Cyber Security Centre have released guidance to help organisations understand these risks and make informed decisions when procuring or using LEO SATCOM services. | ASDのACSCは、オーストラリア宇宙庁、カナダサイバーセキュリティセンター、国家安全保障局、およびニュージーランド国家サイバーセキュリティセンターと共同で、組織がこれらのリスクを理解し、LEO SATCOMサービスの調達や利用時に情報に基づいた意思決定を行えるよう支援するためのガイダンスを発表した。 |
| The guidance outlines risks and mitigations across space, ground and user segments. It also highlights broader risks relating to communication links, supply chains and data management. | このガイダンスでは、宇宙、地上、ユーザー各セグメントにわたるリスクと緩和策を概説している。また、通信リンク、サプライチェーン、データ管理に関連するより広範なリスクについても強調している。 |
| Organisations can also use the set of key questions when engaging with LEO SATCOM service providers to help assess their security measures and resiliency. | 組織は、LEO SATCOMプロバイダと契約する際、一連の重要質問項目を活用し、そのセキュリティ対策やレジリエンシーを評価することもできる。 |
| If your organisation depends on LEO SATCOM for operations, remote connectivity or critical services, now is the time to review your risks and uplift your security. | もし貴組織が業務、遠隔接続、または重要サービスにおいてLEO SATCOMに依存しているなら、今こそリスクを見直し、セキュリティを強化すべき時だ。 |
| Read the full guidance to learn more about cyber security for LEO SATCOM systems. | LEO SATCOMシステムのサイバーセキュリティについて詳しく知るには、ガイダンス全文を参照のこと。 |
・2026.03.25 Securing space
| Introduction | はじめに |
| Intended audience | 対象読者 |
| Background | 背景 |
| Emerging trends in LEO SATCOM technologies | LEO SATCOM技術の新たな動向 |
| LEO SATCOM cyber security risks and mitigation strategies | LEO SATCOMのサイバーセキュリティリスクと緩和策 |
| Further information | 詳細情報 |
・[PDF]
・[DOCX][PDF]仮訳
更なる情報...
米国...
● US. Natilanl Security Agency/Cnetral Security Service: NSA/CSS
・2026.03.24 NSA and ASD’s ACSC Release Joint Guidance on LEO SATCOM System Risks and Mitigations
| NSA and ASD’s ACSC Release Joint Guidance on LEO SATCOM System Risks and Mitigations | NSAとASD傘下のACSC、低軌道衛星通信システムのリスクと緩和に関する共5同ガイダンスを発表 |
| FORT MEADE, Md.–- March 24, 2026 --The National Security Agency (NSA) joins the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in collaboration with the Australian Space Agency and others in releasing the Cybersecurity Information Sheet (CSI), "Securing space: Cyber security for low earth orbit satellite communications.” | メリーランド州フォート・ミード――2026年3月24日――国家安全保障局(NSA)は、オーストラリア信号局傘下のオーストラリア・サイバーセキュリティ・センター(ASDのACSC)と共同で、オーストラリア宇宙局らと連携し、サイバーセキュリティ情報シート(CSI)『宇宙の安全確保:低軌道衛星通信のサイバーセキュリティ』を公表した。 |
| The report highlights high-level cybersecurity risks and mitigation strategies for users of Low Earth Orbit (LEO) satellite communication (SATCOM) systems. The risks and mitigations are detailed through the lens of the space segment comprising the satellites themselves; the ground segment encompassing satellite control centers, ground stations, gateways, and user terminals; the user segment that includes end-user devices, applications, and associated interfaces that connect to LEO SATCOM services; and the communication links and broader supply chain for LEO SATCOM systems. | 本報告書は、低軌道(LEO)衛星通信(SATCOM)システムの利用者に向けた、主要なサイバーセキュリティリスクと緩和策を明らかにしている。リスクと緩和策は、衛星そのものを構成する宇宙セグメント、衛星管制センター、地上局、ゲートウェイ、ユーザー端末を含む地上セグメント、LEO SATCOMサービスに接続するエンドユーザーデバイス、アプリケーション、および関連インターフェースを含むユーザーセグメント、ならびにLEO SATCOMシステムの通信リンクおよび広範なサプライチェーンという観点から詳細に説明されている。 |
| The CSI suggests numerous mitigation strategies for the space segment and legacy space equipment, including implementing tailored security measures, and using frequency-hopping signals, redundant communication paths, and anti-jam antennas. For the ground segment, continuous monitoring and anomaly detection are essential. The user segment should focus on strengthening endpoint security and enforcing secure access practices. | CSIは、宇宙セグメントおよびレガシー宇宙機器に対して、個別のセキュリティ対策の実施、周波数ホッピング信号の活用、通信経路の冗長化、妨害対策アンテナの使用など、数多くの緩和策を提案している。地上セグメントにおいては、継続的な監視と異常検知が不可欠である。ユーザーセグメントでは、エンドポイントセキュリティの強化と安全なアクセス慣行の徹底に重点を置くべきである。 |
| The report also provides frameworks for maintaining the resilience of critical networks, while offering valuable insights and guidelines for users to understand their roles and responsibilities in securing LEO SATCOM systems. | 本報告書は、重要ネットワークのレジリエンスを維持するための枠組みを提供するとともに、LEO SATCOMシステムのセキュリティ確保における自身の役割と責任を理解するための、ユーザー向けの貴重な知見とガイドラインも提示している。 |
| LEO SATCOM systems improve network resilience and enable emergency communications across both government and private sectors; however, as LEO satellite constellations grow, the attack surface open to adversaries increases, significantly increasing the risk to the system if the correct cybersecurity measures are not applied. | LEO SATCOMシステムはネットワークのレジリエンスを向上させ、政府および民間セクター双方における緊急通信を可能にする。しかし、LEO衛星コンステレーションが拡大するにつれ、攻撃者に対して開かれた攻撃対象領域も拡大し、適切なサイバーセキュリティ対策が講じられない場合、システムへのリスクが著しく高まる。 |
| In LEO SATCOM networks, Confidentiality, Integrity, and Availability — known as the CIA triad — are critical to maintaining secure and reliable operations. LEO SATCOM systems face unique challenges due to their distributed architecture and limited physical access to space-based assets. They also rely on radio frequency links that are susceptible to jamming, spoofing, and interception. | LEO SATCOMネットワークにおいて、機密性、完全性、可用性(いわゆるCIAトライアド)は、安全かつ信頼性の高い運用を維持するために不可欠である。LEO SATCOMシステムは、その分散型アーキテクチャと宇宙資産への物理的アクセスが限られていることから、特有の課題に直面している。また、ジャミング、スプーフィング、傍受の影響を受けやすい無線周波数リンクに依存している。 |
| Organizations that use LEO SATCOM services are encouraged to review this guidance and adopt the outlined cybersecurity mitigations. | LEO SATCOMサービスを利用する組織は、本ガイダンスを確認し、記載されたサイバーセキュリティの緩和を採用することが推奨される。 |
| Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), and Australian Space Agency. | 本CSIに共同署名した他の機関には、カナダ・サイバーセキュリティセンター(Cyber Centre)、ニュージーランド国立サイバーセキュリティセンター(NCSC-NZ)、およびオーストラリア宇宙局が含まれる。 |
| Read the full report here. | 報告書全文はこちらで閲覧できる。 |
ニュージーランド
● NZ National Cyber Security Centre
・2026.03.25 Cyber security for low earth orbit satellite communications
| Cyber security for low earth orbit satellite communications | 低軌道衛星通信のサイバーセキュリティ |
| This guidance is intended for users of LEO SATCOM services. It highlights key cyber security risks and corresponding mitigation strategies to support informed decision-making. | 本ガイダンスは、LEO SATCOMサービスの利用者を対象としている。情報に基づいた意思決定を支援するため、主要なサイバーセキュリティリスクと、それに対応する緩和策を明らかにする。 |
| The rapid expansion and increasing reliance on Low Earth Orbit (LEO) satellite communication (SATCOM) systems have introduced significant cyber security challenges. As LEO satellite constellations grow, the attack surface for adversaries increases. This growth puts critical networks that depend on these satellite services at greater risk. Securing this infrastructure is essential to ensuring the resilience of commercial communications, national security systems and emergency response capabilities. | 低軌道(LEO)衛星通信(SATCOM)システムの急速な拡大と依存度の高まりは、重大なサイバーセキュリティ上の課題をもたらしている。LEO衛星コンステレーションが拡大するにつれ、攻撃者の攻撃対象領域も拡大する。この拡大により、これらの衛星サービスに依存する重要ネットワークは、より大きなリスクにさらされることになる。このインフラを保護することは、商用コミュニケーション、国家安全保障システム、および緊急対応能力のレジリエンスを確保するために不可欠である。 |
| When procuring LEO SATCOM services, users should have a clear understanding of their roles and responsibilities for securing their equities as well as the responsibilities of the service provider. | LEO SATCOMサービスを調達する際、利用者は、自社の資産を保護するための役割と責任、およびプロバイダの責任について明確に理解しておくべきである。 |
| This guidance provides a set of critical questions that organisations can ask when discussing security with LEO SATCOM providers. | 本ガイダンスは、組織がLEO SATCOMプロバイダーとセキュリティについて協議する際に提示できる一連の重要な質問を提供する。 |
| These questions help ensure that security and resilience are considered alongside performance and capability requirements in the context of evolving threats in the space domain. | これらの質問は、宇宙領域における脅威の進化という文脈において、性能や機能要件と並行してセキュリティとレジリエンスが考慮されることを確実にするのに役立つ。 |
| The authoring agencies acknowledge that many of the cyber security risks and mitigation strategies outlined in this publication may be broadly relevant to satellite communications, beyond just LEO SATCOM services. | 作成機関は、本刊行物で概説されているサイバーセキュリティリスクおよび緩和戦略の多くが、単なるLEO SATCOMサービスにとどまらず、衛星通信全般に広く関連し得ることを認識している。 |
● まるちゃんの情報セキュリティ気まぐれ日記
・2025.03.30 欧州ENISA 宇宙脅威状況 2025 (2025.03.26)
・2024.10.22 中国 端末設備を使用する衛星直接サービスに関する管理規定案 (2024.09.27)
・2024.08.28 米国 国家安全保障局 (NSA) 商用超小型地球局(VSAT)ネットワークの保護
・2024.07.01 防衛省 防衛研究所 「商業宇宙戦争」の時代における防衛組織の課題 + 米国国防総省の商業宇宙統合戦略
・2024.04.24 ドイツ BSIが人工衛星の地上セグメント用のITベースライン保護プロファイルを公表
・2024.04.06 米国 国防総省 商業宇宙統合戦略2024 - 新宇宙戦略は国防総省と民間企業の努力の統合を目指す
・2024.03.29 経済産業省 民間宇宙システムにおけるサイバーセキュリティ対策ガイドライン Ver 2.0
・2024.02.19 ENISA 低軌道(LEO)衛星通信のサイバーセキュリティ評価
・2023.09.26 NIST IR 8441 ハイブリッド衛星ネットワーク(HSN)のサイバーセキュリティフレームワーク・プロファイル
・2023.08.01 NIST NIST IR 8270 商業衛星運用のためのサイバーセキュリティ入門
・2023.06.10 NIST NISTIR 8441(ドラフト)ハイブリッド衛星ネットワークのためのサイバーセキュリティフレームワークプロファイル (2023.06.06)
・2023.05.31 ENISA 海底ケーブルから低軌道衛星通信までのセキュリティの確保 (2023.05.24)
・2023.04.02 経済産業省 民間宇宙システムにおけるサイバーセキュリティ対策ガイドライン Ver1.1
・2023.03.08 欧州 安全な宇宙ベースの接続プログラムを欧州理事会が承認
・2023.01.08 NISTIR 8401 衛星地上セグメント:衛星の指揮・統制を保証するためのサイバーセキュリティフレームワークの適用 (2022.12.30)
・2022.11.06 NIST ホワイトペーパー NIST CSWP 27:ハイブリッド衛星ネットワーク (HSN) 用サイバーセキュリティフレームワーク・プロファイル:注釈付きアウトライン最終版
・2022.08.05 ドイツ BSI 宇宙インフラのためのサイバーセキュリティ
・2022.07.16 経済産業省 令和3年度委託調査報告書(サイバーセキュリティ関係) 2022.07.14現在
・2022.07.14 NIST NCCoE ハイブリッド衛星ネットワーク(HSN)サイバーセキュリティ(ドラフト)
・2022.07.06 NISTIR 8323 Rev. 1 (ドラフト) 基礎的な PNT プロファイル:測位・航法・計時(PNT)サービスの責任ある使用のためのサイバーセキュリティフレームワークの適用 (2022.06.29)
・2022.04.21 NISTIR 8401 (ドラフト) 衛星地上セグメント:衛星の指揮・統制を保証するためのサイバーセキュリティフレームワークの適用
・2022.02.28 NISTIR 8270(ドラフト)商用衛星運用のためのサイバーセキュリティ入門(第2稿)
・2022.02.27 経済産業省 意見募集 「民間宇宙システムにおけるサイバーセキュリティ対策ガイドラインβ版」
・2021.07.02 NISTIR 8270(ドラフト)商用衛星運用のためのサイバーセキュリティ入門
・2021.05.23 GPSの二重化は現在のところ経済効率的ではないようですね。。。
・2021.04.16 U.S. Rand研究所 衛星インターネットサービスは独裁者にとって吉?凶?
・2021.04.12 宇宙経済をサイバー攻撃から守り抜くために by The Center for Security Studies at ETH Zürich at 2021.01.07
・2020.11.21 MITREがサイバーセキュリティを含む宇宙関連の5つの技術報告書を公開していますね。。。
・2020.10.23 NISTが測位・航法・計時(PNT)に関連するサービスに関連したセキュリティプロファイルに関する文書(NISTIR 8323)のパブコメを募集していますね。
・2020.09.21 イランのハッカー3名が衛星会社から知財を盗んだ理由等により起訴されていますね。。。
« 英国 金融行動監視機構・情報コミッショナー事務局は金融機関が脆弱な顧客を支援するために個人データを取り扱う際の留意事項を公表 (2026.03.27) | Main | 経済産業省 パブコメ ファミリーガバナンス・ガイダンス(案) (2026.03.30) »


Comments