« 経済産業省 サプライチェーン強化に向けたセキュリティ対策評価制度(SCS評価制度)に係る不適切な勧誘に御注意ください (2026.04.27) | Main | Anthropic Claude Opus 4.7のプライバシー影響評価 (2026.04.16) と性能比較 »

2026.04.29

米国 NIST DevSecOps Practice (2026.03.24)

こんにちは、丸山満彦です。

NISTが、DevSecOps Practiceのウェブページを公開していますね...これからもどんどん加筆修正されていくのだろうと思います...

パブコメ期間はすぎてるけど (^^;;

まだまだ、たまっていまして...

 

NIST - ITL

・2026.03.24 Other (Initial Preliminary Draft) Secure Software Development, Security, and Operations (DevSecOps) Practices

Other (Initial Preliminary Draft) Secure Software Development, Security, and Operations (DevSecOps) Practices その他(初期ドラフト)セキュアなソフトウェア開発、セキュリティ、および運用(DevSecOps)の実践
Announcement お知らせ
The NIST National Cybersecurity Center of Excellence (NCCoE) is releasing this live document as part of its Secure Software Development, Security, and Operations (DevSecOps) project. This project demonstrates how organizations can implement the security practices and tasks recommended in the NIST Secure Software Development Framework (SSDF) using modern DevSecOps pipelines and commercially available technology. The live document is open for public comment until April 24, 2026. NIST国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、セキュアなソフトウェア開発、セキュリティ、および運用(DevSecOps)プロジェクトの一環として、このライブドキュメントを公開する。本プロジェクトは、組織が最新のDevSecOpsパイプラインと市販の技術を活用し、NISTセキュアソフトウェア開発枠組み(SSDF)で推奨されるセキュリティプラクティスやタスクをどのように実装できるかを実証するものである。このライブドキュメントは、2026年4月24日まで一般からのコメントを受け付けている。
This release provides several components of the NCCoE DevSecOps demonstration, including: 本リリースでは、NCCoEのDevSecOps実証プロジェクトの以下の構成要素を提供する:
1. An updated Executive Summary and Introduction, highlighting the purpose and background of this project. 1. 本プロジェクトの目的と背景を強調した、更新されたエグゼクティブサマリーおよび序論
2. notional reference model for DevSecOps to demonstrate the NIST SSDF. 2. NIST SSDFを実証するためのDevSecOpsの概念的な参照モデル
3. Details on the first example implementation, which demonstrates DevSecOps practices in a Microsoft Azure-based environment. 3. Microsoft Azureベースの環境におけるDevSecOpsプラクティスを実証する、最初の実装例の詳細。
4. An appendix highlighting industry collaborators in the project and their technologies used in the demonstration environment. 4. 本プロジェクトの業界パートナーおよび実証環境で使用された技術を記載した附属書
Background 背景
The live document shares findings from the NCCoE's collaborative, demonstrative applied research project with 14 technology companies, who contributed technologies, expertise, and operational insights. This project demonstrates and documents practical approaches for integrating SSDF practices into modern DevSecOps pipelines using commercially available technologies. By automating and standardizing security considerations throughout the development lifecycle, the project aims to help organizations improve efficiency, strengthen software supply chain security, and provide greater assurance that secure software development practices are consistently applied. この公開文書は、技術、専門知識、運用上の知見を提供した14社のテクノロジー企業との共同による、NCCoEの実証的応用研究プロジェクトの成果を共有するものである。本プロジェクトは、市販の技術を用いてSSDFの実践を最新のDevSecOpsパイプラインに統合するための実践的なアプローチを実証し、文書化するものである。開発ライフサイクル全体を通じてセキュリティ上の考慮事項を自動化および標準化することにより、本プロジェクトは、組織が効率性を向上させ、ソフトウェアサプライチェーンのセキュリティを強化し、安全なソフトウェア開発の実践が一貫して適用されているという確信をより強めることを支援することを目的としている。
As part of NIST’s response to Executive Order (EO) 14306Sustaining Select Efforts to Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144, this project will showcase examples of secure software development practices that fundamentally bolster the security of DevSecOps practices by implementing the SSDF's recommendations. 大統領令(EO)14306「国家のサイバーセキュリティ強化に向けた選定された取り組みの維持、および大統領令13694および大統領令14144の改正」に対するNISTの対応の一環として、本プロジェクトは、SSDFの推奨事項を実装することでDevSecOpsプラクティスのセキュリティを根本的に強化する、セキュアなソフトウェア開発プラクティスの事例を紹介する。
Next Steps 今後の予定
Unlike traditional static publications, this live document will be updated on a rolling basis with additional implementations and technical findings as the work with collaborators in the laboratory continues. In the coming months, the NCCoE will publish use case scenarios for the initial example implementation, as well as details on other example implementations showcasing several development platforms and tools. The NCCoE will also release an analysis that decomposes NIST SSDF practices and tasks into more granular and actionable tasks, illustrating their application within the project's DevSecOps model. 従来の静的な出版物とは異なり、このライブドキュメントは、研究所内の協力者との作業が進むにつれ、追加の実装や技術的な知見に基づき、随時更新される。今後数ヶ月のうちに、NCCoEは初期の実装例に関するユースケースシナリオに加え、複数の開発プラットフォームやツールを活用したその他の実装例の詳細を公開する予定だ。また、NCCoEはNIST SSDFの実践手法とタスクをより細分化された実行可能なタスクに分解し、プロジェクトのDevSecOpsモデル内での適用例を示す分析結果も公開する。
Abstract 概要
Today’s software applications are typically constructed by combining a diverse range of elements, including components, frameworks, libraries, and tools. Rather than building everything from the ground up, developers often leverage a mix of internally developed and externally sourced components. This modular development approach, coupled with Development Operations (DevOps) practices that integrate development and operations teams, enables a modern software development process that delivers improved quality, reliability, agility, and efficiency, while also fostering collaboration among various teams. The adoption of Development, Security, and Operations (DevSecOps), a methodology that builds on the DevOps philosophy and integrates security into every phase of software development, is further accelerating this trend. Additionally, the utilization of cloud-native technologies and AI is enhancing security and optimizing efficiency. However, the complexities and rapid pace of modern software development can still introduce security risks, highlighting the need for continuous security monitoring and improvement. To address this challenge, the NCCoE is undertaking a project that demonstrates and documents risk-based approaches and recommendations for DevSecOps practices aligned with the NIST Secure Software Development Framework (SSDF). This project showcases secure software development by implementing example processes that adhere to the SSDF’s recommended practices. 今日のソフトウェアアプリケーションは、通常、コンポーネント、枠組み、ライブラリ、ツールなど、多様な要素を組み合わせて構築される。開発者は、すべてを一から構築するのではなく、社内で開発されたコンポーネントと外部から調達したコンポーネントを組み合わせて活用することが多い。このモジュール型開発アプローチは、開発チームと運用チームを統合するDevOps(開発・運用)プラクティスと相まって、品質、信頼性、俊敏性、効率性を改善すると同時に、様々なチーム間のコラボレーションを促進する、現代的なソフトウェア開発プロセスを可能にする。DevOpsの哲学を基盤とし、ソフトウェア開発のあらゆる段階にセキュリティを統合する手法であるDevSecOps(開発・セキュリティ・運用)の採用は、この傾向をさらに加速させている。さらに、クラウドネイティブ技術やAIの活用により、セキュリティが強化され、効率が最適化されている。しかし、現代のソフトウェア開発の複雑さと急速な進展は依然としてセキュリティリスクをもたらす可能性があり、継続的なセキュリティの継続的なモニタリングと改善の必要性を浮き彫りにしている。この課題に対処するため、NCCoEは、NISTセキュアソフトウェア開発枠組み(SSDF)に沿ったDevSecOpsプラクティスに向けた、リスクベースのアプローチと推奨事項を実証・文書化するプロジェクトを推進している。本プロジェクトでは、SSDFの推奨プラクティスに準拠したサンプルプロセスを実装することで、セキュアなソフトウェア開発を実証する。

 

 

Secure Software Development, Security, and Operations (DevSecOps) Practices

DevSecOps Practices DevSecOpsの実践
Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
1.1. Background 1.1. 背景
1.1.1. Development, Security, and Operations (DevSecOps) 1.1.1. 開発、セキュリティ、運用(DevSecOps)
1.1.2. The Role of AI in Software Development 1.1.2. ソフトウェア開発におけるAIの役割
1.1.3. The Role of Zero Trust in Software Development 1.1.3. ソフトウェア開発におけるゼロトラストの役割
1.2. Audience 1.2. 対象読者
1.3. Scope 1.3. 範囲
1.4. Challenges 1.4. 課題
2. Project Overview 2. プロジェクトの概要
3. Notional Reference Model for DevSecOps for Demonstration of NIST SSDF 3. NIST SSDF を実証するための DevSecOps 概念参照モデル
3.1. Phases of the Continuous DevSecOps Lifecycle 3.1. 継続的 DevSecOps ライフサイクルのフェーズ
3.1.1. Plan 3.1.1. 計画
3.1.2. Develop 3.1.2. 開発
3.1.3. Build 3.1.3. ビルド
3.1.4. Test 3.1.4. テスト
3.1.5. Release 3.1.5. リリース
3.1.6. Deploy 3.1.6. 展開
3.1.7. Operate 3.1.7. 運用
3.2. Continuous Improvements, Security and Monitoring 3.2. 継続的改善、セキュリティ、および監視
3.3. Continuous Feedback 3.3. 継続的フィードバック
3.4. Continuous Integration/Continuous Delivery (CI/CD) Pipeline 3.4. 継続的インテグレーション/継続的デリバリー(CI/CD)パイプライン
3.5. Zero Trust Security 3.5. ゼロトラストセキュリティ
3.6. Artificial Intelligence 3.6. 人工知能
4. Example Implementations 4. 実装例
4.1. Example Implementation 1 (E1) 4.1. 実装例 1 (E1)
4.1.1. Plan 4.1.1. 計画
4.1.2. Develop 4.1.2. 開発
4.1.3. Build 4.1.3. ビルド
4.1.4. Test 4.1.4. テスト
4.1.5. Release 4.1.5. リリース
4.1.6. Deploy 4.1.6. 展開
4.1.7. Operate 4.1.7. 運用
4.1.8. Continuous Improvements, Security and Monitoring 4.1.8. 継続的改善、セキュリティ、および監視
5. Next Steps 5. 今後の手順
Appendix A List of Acronyms 附属書A 略語一覧
Appendix B Component Description 附属書B コンポーネントの説明
Appendix C Collaborators and their Contribution 附属書C 協力者とその貢献
C.1. AMI C.1. AMI
C.1.1. Meridian Firmware Management Service C.1.1. Meridianファームウェア管理サービス
C.1.2. Meridian Security Services: VMS and SBOM C.1.2. Meridian セキュリティサービス:VMS および SBOM
C.2. Black Duck C.2. Black Duck
C.2.1. Polaris Platform C.2.1. Polaris プラットフォーム
C.2.2. Black Duck SCA C.2.2. Black Duck SCA
C.2.3. Black Duck Coverity C.2.3. Black Duck Coverity
C.2.4. Continuous Dynamic C.2.4. Continuous Dynamic
C.2.5. Software Risk Manager (SRM) C.2.5. ソフトウェア・リスクマネジメント・マネージャー (SRM)
C.3. CyberArk Software C.3. CyberArk Software
C.3.1. CyberArk Privilege Cloud C.3.1. CyberArk Privilege Cloud
C.3.2. CyberArk Endpoint Privilege Manager C.3.2. CyberArk Endpoint Privilege Manager
C.3.3. CyberArk Code Sign Manager C.3.3. CyberArk Code Sign Manager
C.3.4. CyberArk Secrets Hub C.3.4. CyberArk Secrets Hub
C.3.5. CyberArk Conjur Cloud C.3.5. CyberArk Conjur Cloud
C.3.6. CyberArk Workload Identity C.3.6. CyberArk Workload Identity
C.3.7. CyberArk Certificate Manager SaaS C.3.7. CyberArk Certificate Manager SaaS
C.3.8. CyberArk Certificate Manager (Self-Hosted) C.3.8. CyberArk Certificate Manager (セルフホスト型)
C.4. Dell Technologies C.4. Dell Technologies
C.5. DigiCert C.5. DigiCert
C.5.1. DigiCert Software Trust Manager C.5.1. DigiCert Software Trust Manager
C.6. Endor Labs C.6. Endor Labs
C.6.1. Reachability-Based SCA C.6.1. 到達可能性ベースの SCA
C.6.2. Endor Code (SAST + Secret Scanning) C.6.2. Endor Code (SAST + シークレットスキャン)
C.6.3. Container Scanning C.6.3. コンテナスキャン
C.6.4. Endor Patches C.6.4. Endor Patches
C.6.5. AI Code Security Review C.6.5. AIコードセキュリティレビュー
C.7. GitLab C.7. GitLab
C.7.1. The GitLab Platform C.7.1. GitLabプラットフォーム
C.7.2. GitLab Duo (AI) C.7.2. GitLab Duo (AI)
C.8. Google C.8. Google
C.8.1. Cloud Workstations C.8.1. Cloud Workstations
C.8.2. Google Cloud Build C.8.2. Google Cloud Build
C.8.3. Artifact Registry and Artifact Analysis C.8.3. Artifact RegistryおよびArtifact分析
C.8.4. Binary Authorization C.8.4. バイナリ認証
C.8.5. Cloud Deploy C.8.5. Cloud Deploy
C.8.6. Google Kubernetes Engine C.8.6. Google Kubernetes Engine
C.8.7. Cloud Run C.8.7. Cloud Run
C.8.8. Security Command Center C.8.8. Security Command Center
C.8.9. deps.dev C.8.9. deps.dev
C.9. IBM C.9. IBM
C.9.1 IBM Cloud and DevSecOps C.9.1 IBM Cloud および DevSecOps
C.9.2 IBM Cloud Continuous Delivery C.9.2 IBM Cloud Continuous Delivery
C.9.3 IBM Cloud Container Registry and Vulnerability Advisor C.9.3 IBM Cloud Container Registry および Vulnerability Advisor
C.9.4 IBM Cloud Kubernetes Service and Red Hat OpenShift Services C.9.4 IBM Cloud Kubernetes Service および Red Hat OpenShift Services
C.9.5 IBM Cloud Secrets Manager C.9.5 IBM Cloud Secrets Manager
C.9.6 IBM Cloud Key Protect C.9.6 IBM Cloud Key Protect
C.9.7 IBM Cloud Object Storage (S3‑Compatible) C.9.7 IBM Cloud Object Storage (S3 互換)
C.10. Microsoft and GitHub Advanced Security (GHAzDO) C.10. Microsoft および GitHub Advanced Security (GHAzDO)
C.10.1. Azure Container Registry (ACR) C.10.1. Azure Container Registry (ACR)
C.10.2. Azure DevOps (AzDO) C.10.2. Azure DevOps (AzDO)
C.10.3. Azure Entra ID C.10.3. Azure Entra ID
C.10.4. Azure Key Vault (AKV) C.10.4. Azure Key Vault (AKV)
C.10.5. Azure Managed DevOps Pool (MDP) C.10.5. Azure Managed DevOps Pool (MDP)
C.10.6. Azure Privileged Identity Management (PIM) C.10.6. Azure Privileged Identity Management (PIM)
C.10.7. Azure Sentinel C.10.7. Azure Sentinel
C.10.8. Bicep and Azure Resource Manager (ARM) C.10.8. Bicep および Azure Resource Manager (ARM)
C.10.9. GitHub Advanced Security (GHAS) C.10.9. GitHub Advanced Security (GHAS)
C.10.10. GitHub Copilot C.10.10. GitHub Copilot
C.10.11. IDEs – Visual Studio and Visual Studio Code (VS Code) C.10.11. IDE – Visual Studio および Visual Studio Code (VS Code)
C.10.12. Microsoft Defender for Cloud (MDC) C.10.12. Microsoft Defender for Cloud (MDC)
C.10.13. Microsoft SBOM Tool C.10.13. Microsoft SBOM ツール
C.10.14. Notary Project C.10.14. Notary Project
C.11. NextLabs C.11. NextLabs
C.11.1. NextLabs CloudAz Zero Trust Policy Platform C.11.1. NextLabs CloudAz ゼロトラスト ポリシー プラットフォーム
C.11.2. NextLabs Policy Enforcer C.11.2. NextLabs Policy Enforcer
C.11.2.1. Application Enforcer – Externalized Authorization Management & ABAC C.11.2.1. Application Enforcer – 外部化された認可管理および ABAC
C.11.2.2. Data Access Enforcer – Secure Global Data Access C.11.2.2. Data Access Enforcer – 安全なグローバル データ アクセス
C.11.2.3. SkyDRM – Enterprise Digital Rights Management C.11.2.3. SkyDRM – エンタープライズ・デジタル・ライツ・マネジメント
C.12. Palo Alto Networks C.12. パロアルト・ネットワークス
C.12.1. Cortex Cloud Security Platform C.12.1. Cortex クラウド・セキュリティ・プラットフォーム
C.13. Sagittal AI C.13. Sagittal AI
C.13.1. Neo C.13.1. Neo
C.14. Scribe Security C.14. Scribe Security
C.14.1. ScribeHub C.14.1. ScribeHub
C.14.2. Heyman C.14.2. Heyman
Appendix D Change Log 附属書 D 変更履歴

 

 

エグゼクティブサマリー...

Executive Summary エグゼクティブサマリー
In today’s world, Development Operations (DevOps) represents a modern approach to software development that fosters collaboration among development, operations, and other teams that have traditionally worked in silos. This enables a software development process that delivers higher quality, reliability, agility, and efficiency. Additionally, many organizations are now integrating security into their DevOps environments, tools, and processes—a practice known as DevSecOps (Development, Security, and Operations). 今日の世界において、DevOps(開発・運用)は、従来はサイロ化して活動していた開発、運用、その他のチーム間の連携を促進する、ソフトウェア開発における現代的なアプローチである。これにより、より高い品質、信頼性、俊敏性、効率性を備えたソフトウェア開発プロセスが実現される。さらに、多くの組織が現在、DevOps環境、ツール、プロセスにセキュリティを統合しており、この取り組みはDevSecOps(開発、セキュリティ、運用)として知られている。
In traditional software development, security was often an afterthought, tacked on at the end of the development process. DevSecOps offers a different model, one that integrates security practices from the outset and throughout the development process, adopting a “before-thought” approach rather than treating security as a separate concern in later stages or post-deployment, which is characteristic of an “after-thought” approach. There are various reasons for growing adoption of DevSecOps: 従来のソフトウェア開発では、セキュリティは往々にして後付けの要素であり、開発プロセスの最後に付け加えられることが多かった。DevSecOpsはこれとは異なるモデルを提供する。それは、セキュリティ対策を最初から開発プロセス全体に統合し、「事後対応」型のアプローチの特徴である、後段階や展開後にセキュリティを別個の課題として扱うのではなく、「事前対応」型のアプローチを採用するものである。DevSecOpsの採用が拡大している理由は多岐にわたる:
・The growing complexity and volume of cyber threats have made software development environments prime targets for various forms of attacks and cybersecurity breaches. Bad actors are preying on overlooked security practices in software development practices, infrastructures and tools, developer endpoints, misconfigurations in cloud environments, and weak access controls that lead to vulnerabilities. DevSecOps practices are helping organizations build more resilient systems to protect against these types of threats. ・サイバー脅威の複雑さと規模の拡大により、ソフトウェア開発環境は様々な形態の攻撃やサイバーセキュリティ侵害の格好の標的となっている。悪意ある攻撃者は、ソフトウェア開発の実践、インフラストラクチャやツール、開発者のエンドポイント、クラウド環境における設定ミス、脆弱性につながる脆弱なアクセス管理など、見落とされがちなセキュリティ対策の隙を突いている。DevSecOpsの実践は、組織がこうした脅威から身を守るために、よりレジリエンスのあるシステムを構築するのを支援している。
・Most software today relies on one or more components, including third-party components, yet organizations often have little or no visibility into or understanding of how these components are developed, integrated, deployed, and maintained, as well as the practices used to ensure the components’ security. DevSecOps practices automate tools to scan, identify, discover, and help eliminate vulnerabilities in third-party components early in the development lifecycle. ・今日のソフトウェアの多くは、サードパーティ製コンポーネントを含む1つ以上のコンポーネントに依存しているが、組織は、これらのコンポーネントがどのように開発、統合、展開、保守されているか、またコンポーネントのセキュリティを確保するためにどのようなプラクティスが用いられているかについて、ほとんど、あるいは全く可視性や理解を持っていないことが多い。DevSecOpsのプラクティスは、開発ライフサイクルの早い段階でサードパーティ製コンポーネントの脆弱性をスキャン、特定、発見し、排除するのに役立つツールを自動化する。
・Organizations are increasingly incorporating artificial intelligence (AI) into DevSecOps to automate tasks in software development, such as code integration, testing, deployment, and monitoring. As a result, this can potentially enhance the security, efficiency, and quality of their software development processes. ・組織は、コードの統合、テスト、展開、監視といったソフトウェア開発のタスクを自動化するため、DevSecOpsに人工知能(AI)を組み込むケースが増えている。その結果、ソフトウェア開発プロセスのセキュリティ、効率性、品質を向上させる可能性がある。
While DevSecOps practices are essential for enhancing security in software development environments, implementing the NIST Secure Software Development Framework (SSDF) recommended security practices can foundationally bolster the security of the software development lifecycle. To that end, the NCCoE is undertaking a project to demonstrate and document effective DevSecOps practices that align with the SSDF. By putting the SSDF’s recommendations into practice, this project will showcase examples of secure software development that strengthen DevSecOps practices at their core. DevSecOpsの実践はソフトウェア開発環境のセキュリティ強化に不可欠だが、NISTのセキュアソフトウェア開発枠組み(SSDF)が推奨するセキュリティ実践を導入することで、ソフトウェア開発ライフサイクルのセキュリティを根本的に強化できる。その目的のため、NCCoEはSSDFに沿った効果的なDevSecOpsプラクティスを実証・文書化するプロジェクトを推進している。SSDFの推奨事項を実践することで、本プロジェクトはDevSecOpsプラクティスの根幹を強化するセキュアなソフトウェア開発の事例を示すものである。
Initially, this project will focus on securing cloud-based environments that resemble typical closed-source software development settings, highlighting the dynamic enforcement of least-privileged access through a practical Zero Trust Architecture (ZTA) implementation. Moreover, the project will illustrate a holistic approach to secure software development, embedding security considerations and best practices throughout the software development lifecycle, and leveraging AI to automate builds, integrations, deliveries, and deployments, resulting in more efficient software development. 当初、本プロジェクトは、典型的なクローズドソースのソフトウェア開発環境に類似したクラウドベース環境のセキュリティ確保に焦点を当て、実用的なゼロトラストアーキテクチャ(ZTA)の実装を通じて、最小権限アクセス原則の動的な適用を強調する。さらに、本プロジェクトは、ソフトウェア開発ライフサイクル全体にセキュリティ上の考慮事項とベストプラクティスを組み込み、AIを活用してビルド、統合、デリバリー、展開を自動化することで、より効率的なソフトウェア開発を実現する、包括的なセキュアソフトウェア開発アプローチを示す。
This project will provide additional insights into the potential implementations of DevSecOps that are often not available to the broader community. These insights are intended to help practitioners evaluate, compare, and identify gaps in existing software practices, ultimately enhancing cybersecurity for both software producers and consumers. 本プロジェクトは、一般のコミュニティでは得難いDevSecOpsの実装可能性に関する新たな知見を提供する。これらの知見は、実務者が既存のソフトウェア実践を評価・比較し、そのギャップを識別することを支援することを目的としており、最終的にはソフトウェアの生産者と消費者の双方におけるサイバーセキュリティの強化につながる。

 

1_20260429090901

 

 

 

|

« 経済産業省 サプライチェーン強化に向けたセキュリティ対策評価制度(SCS評価制度)に係る不適切な勧誘に御注意ください (2026.04.27) | Main | Anthropic Claude Opus 4.7のプライバシー影響評価 (2026.04.16) と性能比較 »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 経済産業省 サプライチェーン強化に向けたセキュリティ対策評価制度(SCS評価制度)に係る不適切な勧誘に御注意ください (2026.04.27) | Main | Anthropic Claude Opus 4.7のプライバシー影響評価 (2026.04.16) と性能比較 »