CSA NIST AIエージェントのセキュリティ:レッドチーム活動に関するガイダンスとエンタープライズコンプライアンス (2026.03.31)
こんにちは、丸山満彦です。
CSAがNISTがAIエージェントのレッドチーミングの標準の作成を始めたが、エージェント特有の自律的行動に基づくリスクを評価するためには、エージェント・トラスト・フレームワークのような実務的なフレームワークが必要ということですかね...特に金融分野とかには重要かもですね...
NISTがMCPの開発に関与しているようですね...MCPが将来NISTの標準になるのですかね...その時には、MCPにセキュリティ機能(認証、認可、署名、スコープ制御等)が拡張機能として載ってくるのですかね...
● Cloud Security Agent (CSA)
・2026.03.31 NIST AI Agent Security: Red-Teaming Guidance and Enterprise Compliance
| Key Takeaways | 主なポイント |
| NIST’s Center for AI Standards and Innovation (CAISI) formally launched the AI Agent Standards Initiative on February 17, 2026 [1], establishing a three-pillar program to standardize agent security, interoperability, and identity — representing NIST’s most explicit and comprehensive treatment of agentic AI as a distinct standardization priority, and the first time NIST has established a dedicated organizational initiative around agent security as a category. | NISTのAI標準・イノベーションセンター(CAISI)は、2026年2月17日に「AIエージェント標準化イニシアティブ」を正式に発足させた[1]。これにより、エージェントのセキュリティ、相互運用性、およびアイデンティティを標準化するための3本柱からなるプログラムが確立された。これは、エージェンティックAIを独自の標準化優先事項としてNISTが最も明確かつ包括的に取り上げた事例であり、NISTがエージェントのセキュリティをカテゴリーとして、専用の組織的イニシアティブを確立したのは今回が初めてである。 |
| NIST’s own red-team research found that novel attack techniques targeting AI agents achieved an 81% task-hijacking success rate, compared to 11% for the strongest known baseline attacks — a result suggesting that agent-specific offensive research can dramatically outperform defenses calibrated to known attack taxonomies [2]. | NIST自身のレッドチーム調査によると、AIエージェントを標的とした新たな攻撃手法は、タスク乗っ取りの成功率が81%に達した。これは、既知の最も強力なベースライン攻撃の成功率11%と比較して極めて高い数値であり、エージェントに特化した攻撃研究が、既知の攻撃分類に基づいて調整された防御策を劇的に上回る可能性を示唆する結果である[2]。 |
| The March 2025 update to NIST AI 100-2 (Adversarial Machine Learning Taxonomy) extended NIST’s adversarial ML attack taxonomy to cover autonomous AI agent vulnerabilities for the first time, including indirect prompt injection, agent memory poisoning, and supply chain attacks on agent tools [3]. | 2025年3月のNIST AI 100-2(敵対的機械学習分類法)の更新により、NISTの敵対的ML攻撃分類法は初めて自律型AIエージェントの脆弱性を対象範囲に拡大した。これには、間接的プロンプト・インジェクション、エージェントのメモリポイズニング、およびエージェントツールに対するサプライチェーン攻撃が含まれる[3]。 |
| The NCCoE’s February 2026 concept paper proposes a demonstration project for AI agent identity and authorization using OAuth 2.0, SPIFFE/SPIRE, and Model Context Protocol — offering enterprises an early preview of likely NIST technical guidance on agent identity ahead of formal special publications [4]. | NCCoEの2026年2月のコンセプトペーパーは、OAuth 2.0、SPIFFE/SPIRE、およびModel Context Protocolを用いたAIエージェントの識別と認可に関する実証プロジェクトを提案している。これにより、正式なNIST 特別刊行物に先立ち、エンタープライズはエージェントの識別に関するNISTの技術ガイダンスの概要を早期に把握できる[4]。 |
| COSAiS (Control Overlays for Securing AI Systems), NIST’s forthcoming extension of SP 800-53 to AI use cases, will include dedicated overlays for single-agent and multi-agent deployments; once finalized, these overlays may provide the basis for future FedRAMP AI requirements — a compliance trajectory that organizations in regulated sectors should monitor [5]. | NISTがAIユースケース向けにSP 800-53を拡張する予定のCOSAiS(Control Overlays for Securing AI Systems)には、単一エージェントおよびマルチエージェント展開向けの専用オーバーレイが含まれる。これらが確定すれば、将来のFedRAMP AI要件の基礎となる可能性があり、規制対象セクターの組織は、このコンプライアンスの動向を注視すべきである[5]。 |
| The NIST CAISI Request for Information on AI agent security (NIST-2025-0035) drew formal responses from the OpenID Foundation and a financial services industry coalition — BITS, the Bank Policy Institute, and the American Bankers Association — signaling that identity federation standards and financial sector risk management are among the highest-priority topics that industry and standards bodies are raising in formal NIST engagement processes [6][7]. | NISTのAIエージェントセキュリティに関するCAISI情報提供要請(NIST-2025-0035)に対し、OpenID Foundationおよび金融サービス業界連合(BITS、Bank Policy Institute、American Bankers Association)から正式な回答が寄せられた。これは、IDフェデレーション標準と金融セクターのリスクマネジメントが、業界および標準化団体がNISTの正式な関与プロセスにおいて提起している最優先課題の一つであることを示唆している[6][7]。 |
・[PDF]
● まるちゃんの情報セキュリティ気まぐれ日記
・

Comments