« 米国 一般調達局 FPKI統合テスト環境(CITE)参加ガイド (2026.04.21) | Main | 欧州 ENISA NIS360 NIS2 -重要度の高いNISセクターにおけるサイバーセキュリティの成熟度と重大度に関する最新の知見- »

2026.05.29

米国 FBI SECへの報告要件 - サイバーインシデントの被害者に対するFBIの指針

こんにちは、丸山満彦です。

備忘録です...

米国のSECが [PDF] サイバーセキュリティ・リスクマネジメント、戦略、ガバナンス、およびインシデント開示に関する規則」(88 Fed. Reg. 51896)を公布し、原則2023年12月からForm 10-K/20-Fによるサイバーセキュリティ関連の年次開示、Form 8-K/6-Kによる適時開示が義務化されました。

投資家に対して企業のサイバーリスクへのエクスポージャーと管理能力を評価可能な情報を提供することを目的としていると言えます。

しかし、Form 8-K等による適時開示で国家安全保障又は公共の安全上の理由から開示をしないほうが良い状況も考えられるため、サイバー被害企業が、開示の延期を要請することが認められています。この取り扱いに対するFBIの指針の紹介。おそらく制度開始時から公表されていたと思いますが(^^;;

 

FBI - SEC Reporting Requirements FBI Guidance to Victims of Cyber Incidents

SEC Reporting Requirements SECの報告要件
FBI Guidance to Victims of Cyber Incidents サイバーインシデントの被害者に対するFBIのガイダンス
In 2023, the Securities and Exchange Commission (SEC) published rules for Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (88 Fed. Reg. 51896) requiring certain companies ("registrants") to disclose material cybersecurity incidents. The FBI, in coordination with the Department of Justice, is providing guidance on how victims can request related disclosure delays for national security or public safety reasons. The FBI recommends all publicly traded companies establish a relationship with the cyber squad at their local FBI field office.  2023年、米国証券取引委員会(SEC)は、サイバーセキュリティリスク管理、戦略、ガバナンス、およびインシデント開示に関する規則(88 Fed. Reg. 51896)を公布し、特定の企業(「登録企業」)に対し、重要なサイバーセキュリティインシデントの開示を義務付けた。FBIは司法省と連携し、被害者が国家安全保障または公共の安全上の理由から、関連する開示の延期をどのように申請できるかについてガイダンスを提供している。FBIは、すべての上場企業に対し、管轄のFBI現地事務所のサイバー対策チームと連携体制を構築することを推奨している。
Click on the buttons at the bottom of this page to read the guidance on requesting a delay and providing necessary information to the FBI, to view the SEC rules, to view the Justice Department's guidelines on material cybersecurity incident delay determinations, and to read the FBI’s Policy Directive about how victim requests are processed.     このページの下部にあるボタンをクリックすると、開示の延期を要請しFBIに必要な情報を提供するためのガイダンス、SECの規則、重大なサイバーセキュリティインシデントの開示延期判断に関する司法省のガイドライン、および被害者からの要請がどのように処理されるかに関するFBIの政策指令を読むことができる。
The FBI strongly encourages companies to contact the FBI directly or through the U.S. Secret Service (USSS), another federal law enforcement agency, the Cybersecurity and Infrastructure Security Agency (CISA), or another sector risk management agency soon after a registrant believes disclosure of a newly-discovered cybersecurity incident may pose a substantial risk to national security or public safety. This early outreach allows the FBI to familiarize itself with the facts and circumstances of an incident before the company makes a materiality determination. If the victim of a cyber intrusion engages with the FBI or another U.S. government agency, this engagement doesn't trigger a determination of materiality. However, it could assist with the FBI’s review if the company determines that a cybersecurity incident is material and seeks a disclosure delay.    FBIは、登録企業が新たに発見されたサイバーセキュリティインシデントの開示が国家安全保障または公共の安全に重大なリスクをもたらす可能性があると判断した場合、直ちにFBIに直接、あるいは別の連邦法執行機関である米国シークレットサービス(USSS)、サイバーセキュリティ・インフラセキュリティ庁(CISA)、またはその他のセクター別リスク管理機関を通じて連絡することを強く推奨する。こうした早期の連絡により、企業が重要性の判断を行う前に、FBIはインシデントの事実関係や状況を把握することができる。サイバー侵入の被害者がFBIやその他の米国政府機関と接触した場合でも、その接触自体が重要性の判断を引き起こすことはない。ただし、企業がサイバーセキュリティインシデントを重要と判断し、開示の遅延を求めた場合、この接触はFBIの審査に役立つ可能性がある。
Please note that delay requests won't be processed unless they are received by the FBI immediately upon a company’s determination to disclose a cyber incident via 8k. なお、開示遅延の要請は、企業が8-Kを通じてサイバーインシデントを開示すると決定した直後にFBIに受理されない限り、処理されないことに留意されたい。

 

SEC - Request Delay Icon

Request a Delay*

FBI Guidance to Victims of Cyber Incidents on SEC Reporting Requirements: Request a Delay サイバーインシデントの被害企業に対するSEC報告要件に関するFBIのガイダンス:報告の延期申請
To request a reporting delay, victim companies must contact the FBI directly by filling out the form located at sec8k.ic3.gov or through the U.S. Secret Service, the Cybersecurity and Infrastructure Security Agency, the Department of Defense, or another sector risk management agency.  告の延期を申請するには、被害企業はsec8k.ic3.govにあるフォームに記入してFBIに直接連絡するか、米国シークレットサービス、サイバーセキュリティ・インフラセキュリティ庁(CISA)、国防総省、またはその他のセクター別リスク管理機関を通じて連絡しなければならない。
*Each request must contain all of the following information:  *各申請には、以下の情報をすべて記載しなければならない:
1. What is the name of your company?  1. 貴社の名称は何か?
2. When did the cyber incident occur?  2. サイバーインシデントはいつ発生したか?
3. When did you make a determination to disclose a cyber incident via 8k? Include the date, time, and time zone. (Note: Failure to report this information immediately upon determination will cause your delay-referral request to be denied.)  3. 8-Kを通じてサイバーインシデントを開示すると決定したのはいつか?日付、時刻、およびタイムゾーンを含めること。(注:決定後直ちにこの情報を報告しない場合、延期申請は却下される。)
4. Are you already in contact with the FBI or another U.S. government agency regarding this incident? If so, provide the names and field offices of the FBI points of contact or information regarding the U.S. government agency with whom you're in contact.  4. 本インシデントに関して、すでにFBIまたはその他の米国政府機関と連絡を取っているか。その場合、FBIの連絡担当者の氏名および管轄事務所、または連絡を取っている米国政府機関に関する情報を提供すること。
5. Describe the incident in detail. Include the following details, at minimum:  5. インシデントの詳細を記述すること。少なくとも以下の詳細を含めること:
 a. What type of incident occurred?   a. どのような種類のインシデントが発生したか?
 b. What are the known or suspected intrusion vectors, including any identified vulnerabilities if known?   b. 既知または疑われる侵入経路は何か。特定されている脆弱性があれば、それも含めてほしい。
 c. What infrastructure or data were affected (if any) and how were they affected?   c. どのようなインフラやデータが影響を受けたか(該当する場合)、またどのように影響を受けたか。
 d. What is the operational impact on the company, if known?   d. 企業への業務上の影響は何か(分かっている場合)。
6. Is there confirmed or suspected attribution of the cyber actors responsible?  6. 責任のあるサイバー攻撃者の帰属が確認されているか、または疑われているか。
7. What is the current status of any remediation or mitigation efforts?  7. 是正または軽減措置の現在の状況はどうか? 
8. Where did the incident occur? Provide the street address, city, and state where the incident occurred.  8. インシデントはどこで発生したか? インシデントが発生した住所、都市、州を記載すること。
9. Who are your company’s points of contact for this matter? Provide the name, phone number, and email address of personnel you want the FBI to contact to discuss this request.  9. この件に関する貴社の連絡担当者は誰か? この要請について協議するため、FBIに連絡してほしい担当者の氏名、電話番号、メールアドレスを記載すること。 
10. Has your company previously submitted a delay referral request or is this the first time? If you have previously submitted a delay request, please include details about when DOJ made its last delay determination(s), on what grounds, and for how long it granted the delay (if applicable).  10. 貴社は過去に延期要請を提出したことがあるか、それとも今回が初めてか?過去に延期要請を提出したことがある場合は、司法省が前回いつ延期決定を行ったか、その根拠、および延期が認められた期間(該当する場合)の詳細を記載すること。
*Other U.S. government agencies that are in receipt of a requested delay and that are seeking FBI submission to the Department of Justice for Attorney General approval must immediately send the request to the FBI by filling out the form located at sec8k.ic3.gov. *延期要請を受領し、司法長官の承認を得るためにFBIによる司法省への提出を求めている他の米国政府機関は、sec8k.ic3.govにあるフォームに記入し、直ちにFBIへ要請を送付しなければならない。

 

 

SEC - SEC Rule Icon

SEC Rule

20230728-70058

・[DOCX] [PDF] 仮訳

 

SEC - FBI Policy Icon

FBI Policy Directive

FBI Guidance to Victims of Cyber Incidents サイバーインシデントの被害者に対するFBIのガイダンス
on SEC Reporting Requirements: FBI Policy Directive Summary SEC報告要件について:FBI方針指令の概要
A summary of the FBI’s Policy Directive regarding cyber victim requests to delay disclosure pursuant to the Securities and Exchange Commission's rules and Department of Justice (DOJ) guidance is, as follows: 証券取引委員会(SEC)の規則および司法省(DOJ)のガイダンスに基づき、開示の延期を求めるサイバー被害者からの要請に関するFBIの方針指令の概要は、以下の通りである。
・As per the Securities and Exchange Commission (SEC) requirement, if a registrant experiences a cybersecurity incident that the registrant determines to be material, the registrant must disclose certain facts about that incident. ・証券取引委員会(SEC)の要件によれば、登録企業が重要であると判断したサイバーセキュリティインシデントを経験した場合、当該企業はそのインシデントに関する特定の事実を開示しなければならない。
・・The SEC defines “cybersecurity incident” to mean “an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant’s information systems that jeopardizes the confidentiality, integrity, or availability of a registrant’s information systems or any information residing therein.”  ・・SECは、「サイバーセキュリティインシデント」を、「登録企業の情報システム上、または同システムを通じて行われた、登録企業の情報システムもしくはそこに保存されている情報の機密性、完全性、または可用性を脅かす不正な事象、または一連の関連する不正な事象」と定義している。
・Once a company makes a materiality determination, the company has four business days to disclose the incident by filing a SEC Form 8-K Item 1.05 in the SEC’s publicly accessible Electronic Data Gathering, Analysis, and Retrieval (EDGAR) system. ・企業が重要性の判断を下した場合、企業は4営業日以内に、SECの一般公開されている電子データ収集・分析・検索(EDGAR)システムにSECフォーム8-Kの項目1.05を提出し、当該インシデントを開示しなければならない。
・The SEC rules included a provision—Item 1.05(c)—that allows the DOJ Attorney General to grant a disclosure delay based on substantial risk to national security or public safety.  ・SEC規則には、国家安全保障または公共の安全に対する重大なリスクを理由に、司法長官が開示の延期を認めることを可能とする規定(項目1.05(c))が含まれている。
・A delay may be granted for up to 30 days. If the Attorney General determines that disclosure continues to pose a substantial risk to national security, the disclosure delay may be extended for an additional period of up to 30 days. In extraordinary circumstances, the Attorney General may extend the disclosure delay an additional 60 days due to substantial national security risks. ・開示の延期は最大30日間認められる。司法長官が開示が引き続き国家安全保障に重大なリスクをもたらすと判断した場合、開示の延期はさらに最大30日間延長されることがある。極めて例外的な状況下において、司法長官は、重大な国家安全保障上のリスクを理由として、開示の延期をさらに60日間延長することができる。
・Delays cannot exceed a total of 120 days (or 60 days in instances that solely relate to public safety) without an exemptive order from the SEC.  ・SECからの免除命令がない限り、延期の総期間は120日(公共の安全のみに関連する事例の場合は60日)を超えてはならない。
・The FBI is responsible for:  ・FBIは以下の責任を負う:
・・Intaking delay requests on behalf of DOJ   ・・司法省(DOJ)に代わって開示遅延の要請を受け付ける
・・Documenting those requests  ・・それらの要請を記録する
・・Coordinating checks of U.S. government national security and public safety equities, including consulting with the U.S. Secret Service (USSS), Cybersecurity and Infrastructure Security Agency (CISA), and sector risk management agencies (SRMAs) as appropriate ・・米国政府の国家安全保障および公共の安全に関する利害関係の確認を調整する。これには、必要に応じて米国シークレットサービス(USSS)、サイバーセキュリティ・インフラセキュリティ庁(CISA)、およびセクターリスク管理機関(SRMA)との協議が含まれる
・・Referring information to the DOJ  ・・情報を司法省(DOJ)に照会する
・The FBI encourages victims to engage with the FBI directly or through the USSS, CISA, or SRMAs prior to the company’s determination to disclose details of a cyber incident via an SEC Form 8-K Item 1.05.  ・FBIは、企業がSECフォーム8-Kの項目1.05を通じてサイバーインシデントの詳細を開示することを決定する前に、被害者がFBIに直接、あるいはUSSS、CISA、またはSRMAを通じて連絡を取るよう推奨している。
・・If the FBI doesn't receive the delay request from the victim directly or through the USSS, another law enforcement agency, CISA, or another SRMA immediately upon this determination, the FBI won't process the request. ・・この決定直後に、被害者から直接、あるいはUSSS、他の法執行機関、CISA、または他のSRMAを通じて遅延要請がFBIに届かない場合、FBIはその要請を処理しない。
・・In other words, failure to report the cyber incident immediately upon this determination will cause a delay-referral request to be denied.    ・・言い換えれば、この決定直後にサイバーインシデントを報告しなかった場合、開示遅延の照会要請は却下されることになる。   
・After the FBI makes a referral based on equities checks and fact-finding procedures, the Justice Department will issue a delay determination. This determination will be communicated in writing to the victim and the SEC.  ・FBIが利益衡量および事実確認手続きに基づき照会を行った後、司法省が開示遅延の決定を下す。この決定は、被害者およびSECに対して書面で通知される。
・If DOJ approves the delay request, the FBI should invite the victim to submit any requests for delay extensions to the FBI by filling out the form located at sec8k.ic3.gov. Requests for delay extensions should be submitted no later than five business days before the expiration of a granted delay. ・司法省が遅延要請を承認した場合、FBIは被害者に対し、sec8k.ic3.govにあるフォームに記入してFBIへ遅延延長の要請を提出するよう促すべきである。遅延延長の要請は、承認された遅延期間の満了日の5営業日前までに提出しなければならない。
・Please note this summary is written for convenience only and isn't intended to replace or supersede the FBI’s Policy Directive.   ・なお、この要約は便宜上作成されたものであり、FBIの政策指令に代わるものではないことに留意されたい。

 

 

SEC - DOJ Memo Icon

DOJ Memo

 

DEPARTMENT OF JUSTICE MATERIAL CYBERSECURITY INCIDENT DELAY DETERMINATIONS  司法省 重大なサイバーセキュリティインシデントに関する報告期限の延長決定
12-Dec-23 2023年12月12日
These departmental guidelines outline the process that companies subject to the reporting requirements in Section 13 or 15(d) of the Securities Exchange Act of 1934 (“registrants”), or U.S. Government agencies in coordination with registrants, may use to request that the Attorney General[1] authorize delays of cyber incident disclosures required by the U.S. Securities and Exchange Commission (“Commission”) pursuant to Form 8-K Item 1.05.  本省ガイドラインは、1934年証券取引法第13条または第15条(d)項の報告義務の対象となる企業(「登録企業」)、あるいは登録企業と連携する米国政府機関が、米国 証券取引委員会(「委員会」)がForm 8-Kの項目1.05に基づき要求するサイバーインシデントの開示の延期を、司法長官[1]に承認するよう要請するために利用できる手順を概説するものである。
When a registrant “experiences a cybersecurity incident that is determined by the registrant to be material,” SEC Form 8-K Item 1.05(a) requires the registrant to disclose “the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.” Instruction 4 to Item 1.05 provides that: “A registrant need not disclose specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant’s response or remediation of the incident.” Item 1.05(c) contains an exception to the general disclosure requirement:  登録者が「登録者自身によって重要であると判断されるサイバーセキュリティインシデントを経験した場合」、SECフォーム8-Kの項目1.05(a)は、登録者に対し、「インシデントの性質、範囲、および発生時期に関する重要な側面、ならびに登録者(その財務状況および経営成績を含む)に対する重要な影響または合理的に予想される重要な影響」を開示することを求めている。項目1.05の指示4では、次のように規定されている。「登録者は、当該インシデントへの対応計画、サイバーセキュリティシステム、関連するネットワークおよびデバイス、あるいは潜在的なシステムの脆弱性について、登録者のインシデントへの対応や是正を妨げるほどの詳細な具体的または技術的な情報を開示する必要はない。」 項目1.05(c)には、一般的な開示要件に対する例外が定められている:
…if the United States Attorney General determines that disclosure required by paragraph (a) of this Item 1.05 poses a substantial risk to national security or public safety, and notifies the Commission of such determination in writing, the registrant may delay providing the disclosure required by this Item 1.05 for a time period specified by the Attorney General, up to 30 days following the date when the disclosure required by this Item 1.05 was otherwise required to be provided. Disclosure may be delayed for an additional period of up to 30 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security or public safety and notifies the Commission of such determination in writing. In extraordinary circumstances, disclosure may be delayed for a final additional period of up to 60 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security and notifies the Commission of such determination in writing. Beyond the final 60-day delay under this paragraph, if the Attorney General indicates that further delay is necessary, the Commission will consider additional requests for delay and may grant such relief through Commission exemptive order.  …米国司法長官が、本項目1.05の(a)項で要求される開示が国家安全保障または公共の安全に重大なリスクをもたらすと判断し、その判断を委員会に書面で通知した場合、 登録者は、司法長官が指定する期間(本項1.05に基づく開示が本来行われるべきであった日から起算して最大30日間)に限り、本項1.05に基づく開示の提供を遅延させることができる。司法長官が、開示が引き続き国家安全保障または公共の安全に重大なリスクをもたらすと判断し、その判断を委員会に書面で通知した場合、開示はさらに最大30日間遅延させることができる。極めて例外的な状況において、司法長官が開示が引き続き国家安全保障に重大なリスクをもたらすと判断し、その判断を委員会に書面で通知した場合、開示は最終的に最大60日間までさらに延期することができる。本項に基づく最終的な60日間の延期を超えて、司法長官がさらなる延期が必要であると示した場合、委員会は追加の延期要請を検討し、委員会の免除命令を通じてそのような救済を認めることができる。
This document outlines the approach the Department of Justice (“Department”) will take in making the determinations described in Item 1.05(c).  本文書は、司法省(「省」)が項目1.05(c)に記載された決定を行う際に採用するアプローチを概説するものである。
1. Limited circumstances for finding a substantial risk to national security or public safety  1. 国家安全保障または公共の安全に対する重大なリスクが認められる限定的な状況 
The primary inquiry for the Department is whether the public disclosure of a cybersecurity incident threatens public safety or national security, not whether the incident itself poses a substantial risk to public safety and national security. While cybersecurity incidents themselves frequently threaten public safety and national security, the disclosure to the public that those incidents have occurred poses threats less often. In many circumstances, the prompt public disclosure of relevant information about a cybersecurity incident provides an overall benefit for investors, public safety, and national security.  本省が主に検討するのは、サイバーセキュリティインシデントの公開が公共の安全または国家安全保障を脅かすかどうかであり、インシデント自体が公共の安全および国家安全保障に重大なリスクをもたらすかどうかではない。サイバーセキュリティインシデント自体は頻繁に公共の安全および国家安全保障を脅かすが、それらのインシデントが発生したことを公に開示することが脅威となることは、それほど頻繁ではない。多くの場合、サイバーセキュリティインシデントに関する関連情報を速やかに一般に開示することは、投資家、公共の安全、および国家安全保障にとって全体的な利益をもたらす。
Form 8-K Item 1.05 requires registrants to “describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.” Typically, registrants will be able to publicly disclose this material information at a level of generality that does not pose a substantial risk to national security or public safety. In certain circumstances, however, the disclosure of some or all of the information required by Item 1.05 could pose such a risk. Those circumstances of which a registrant would be aware are expected to be limited to the following categories:  フC198ォーム8-Kの項目1.05は、登録者に対し、「インシデントの性質、範囲、および発生時期に関する重要な側面、ならびに登録者(その財務状況および経営成績を含む)に対する重要な影響または合理的に予想される重要な影響」を記述することを求めている。通常、登録者は、国家安全保障や公共の安全に重大なリスクをもたらさない程度の概略的なレベルで、この重要な情報を公表することができる。しかし、特定の状況下では、項目1.05で要求される情報の一部または全部を開示することが、そのようなリスクをもたらす可能性がある。登録者が認識しうるそのような状況は、以下のカテゴリーに限定されると予想される:
a) The cybersecurity incident occurred because the illicit cyber activities were reasonably suspected to have involved a technique for which there is not yet well-known mitigation— for example, exploiting a software vulnerability for which there is no patch or other reasonably available mitigation—and the disclosure required by Item 1.05 could lead to more incidents, thereby posing a substantial risk to national security or public safety.  a) サイバーセキュリティインシデントが、まだ広く知られた対策が存在しない手法(例えば、パッチやその他の合理的に利用可能な対策が存在しないソフトウェアの脆弱性の悪用など)を用いた不正なサイバー活動によるものと合理的に疑われる場合に発生し、かつ項目1.05で要求される開示がさらなるインシデントを招き、それによって国家安全保障または公共の安全に重大なリスクをもたらす恐れがある場合。
b) The cybersecurity incident primarily impacts a system operated or maintained by a registrant that contains sensitive U.S. Government information, or information the U.S. Government would consider sensitive, and public disclosure required by Item 1.05 would make that information and/or system vulnerable to further exploitation by illicit cyber activity, thereby posing a substantial risk to national security or public safety. This category includes systems operated or maintained for the government as well as systems not specifically operated or maintained for the government that contain information the government would view as sensitive, such as that regarding national defense or research and development performed pursuant to government contracts.  b) サイバーセキュリティインシデントが、登録者が運用または保守するシステムに主に影響を及ぼし、そのシステムには機密性の高い米国政府情報、または米国政府が機密とみなす情報が含まれており、項目1.05で要求される公開開示を行うと、当該情報および/またはシステムが不正なサイバー活動によるさらなる悪用に対して脆弱となり、それによって国家安全保障または公共の安全に重大なリスクをもたらす場合。このカテゴリーには、政府のために運用または保守されているシステムに加え、政府のために特に運用または保守されているわけではないが、国防や政府契約に基づき実施される研究開発に関する情報など、政府が機密とみなす情報を含むシステムも含まれる。
c) The registrant is conducting remediation efforts for any critical infrastructure or critical system, and any disclosure required by Item 1.05(a) revealing that the registrant is aware of the incident would undermine those remediation efforts and thus pose a substantial risk to national security or public safety.  c) 登録者が重要インフラまたは重要システムに対する是正措置を実施している場合、項目1.05(a)で要求される開示により、登録者が当該インシデントを認識していることが明らかになることで、その是正措置が損なわれ、ひいては国家安全保障または公共の安全に重大なリスクをもたらす場合。
d) The circumstances described below in Section 3, after a government agency has made the registrant aware of them.  d) 政府機関から登録者に対し通知がなされた後、第3節に記載される状況。
2. Procedure for registrants to follow when Item 1.05(c)’s exception might apply  2. 項目1.05(c)の例外が適用される可能性がある場合における登録者の手順
When a registrant discovers a cybersecurity incident and believes that disclosure may pose a substantial risk to national security or public safety, the registrant should, directly or through another U.S. Government agency (e.g., the U.S. Secret Service, another federal law enforcement agency, the Cybersecurity & Infrastructure Security Agency (CISA), or another sector risk management agency (SRMA)), immediately contact the FBI consistent with reporting instructions the FBI has issued. The registrant should convey in its report a concise description of the facts forming the basis of the registrant’s belief that disclosure required under Item 1.05 may pose a substantial risk to national security or public safety, citing one or more of the categories described above. The most relevant facts will pertain to the potential consequences to national security or public safety that would result from a disclosure within the timeframe required by Item 1.05. The Attorney General must invoke the provision permitting a delay in disclosing an incident under the Commission rule within four business days of a determination by the registrant that the registrant has experienced a material cybersecurity incident. As such, it is important that the registrant provide to the FBI, directly or indirectly through another U.S. Government agency, information about a cybersecurity incident likely to meet the requirements for delayed disclosure as soon as possible, even beginning well before the registrant has completed its materiality analysis or its investigation into the incident. The FBI will document the facts of the incident provided by the registrant and findings from related FBI national security and public safety records, equity checks, and appropriate consultations with other U.S. Government agencies including USSS, CISA, or SRMAs. The FBI’s referral of a delay request to the Department will include an evaluation of whether the public disclosure required by Form 8-K Item 1.05 within its prescribed timeframe would pose a substantial risk to national security or public safety.  登録者がサイバーセキュリティインシデントを発見し、その開示が国家安全保障または公共の安全に重大なリスクをもたらす可能性があると判断した場合、登録者は、直接、または他の米国政府機関(例:米国シークレットサービス、他の連邦法執行機関、サイバーセキュリティ・インフラセキュリティ庁(CISA)、または他のセクターリスク管理機関(SRMA))を通じて、FBIが発行した報告指示に従い、直ちにFBIに連絡しなければならない。登録者は、項目1.05に基づく開示が国家安全保障または公共の安全に重大なリスクをもたらす可能性があるという自身の判断の根拠となる事実について、上記のカテゴリーのいずれか一つ以上を引用しつつ、報告書に簡潔に記述しなければならない。最も関連性の高い事実は、項目1.05で要求される期間内での開示によって生じうる、国家安全保障または公共の安全への潜在的な影響に関するものである。司法長官は、登録者が重大なサイバーセキュリティインシデントを経験したと判断してから4営業日以内に、委員会規則に基づきインシデントの開示を遅延させることを認める規定を発動しなければならない。したがって、登録者は、重大性分析やインシデントの調査を完了するかなり前からであっても、開示遅延の要件を満たす可能性のあるサイバーセキュリティインシデントに関する情報を、直接、あるいは他の米国政府機関を通じて間接的に、できるだけ速やかにFBIに提供することが重要である。FBIは、登録者から提供されたインシデントの事実関係、およびFBIの国家安全保障・公共安全に関する記録、身元調査、ならびにUSSS、CISA、SRMAを含む他の米国政府機関との適切な協議から得られた知見を文書化する。FBIによる開示遅延要請の省への付託には、所定の期間内に行われるForm 8-K項目1.05に基づく公開開示が、国家安全保障または公共の安全に重大なリスクをもたらすかどうかの評価が含まれる。
3. Procedure for a U.S. Government agency to follow when Item 1.05(c)’s exception might apply  3. 項目1.05(c)の例外が適用される可能性がある場合における米国政府機関の手順
Whenever any U.S. Government agency becomes aware of a cybersecurity incident pertaining to a registrant’s information system and believes the available facts show that a disclosure potentially required by paragraph (a) of Item 1.05 poses a substantial risk to national security or public safety, that U.S. Government agency should, in consultation with the FBI and other U.S. Government agencies as appropriate, determine whether the U.S. Government should notify and coordinate with the registrant to determine the timing and content of information the registrant plans to disclose, absent an Item 1.05(c) exemption; and whether the registrant would agree to a delayed disclosure should the Attorney General make the necessary determination. If a delay in public disclosure is believed to be warranted by the relevant U.S. Government agency and is agreed to by the registrant, then the U.S. Government agency should immediately contact the Department through the FBI, communicate the relevant facts, explain why a delay is appropriate, and recommend a period for delay. The Department anticipates that the following are the types of scenarios in which, at least initially, a recommending U.S. Government agency, rather than a registrant, is likely to be aware of a substantial risk to national security or public safety:  米国政府機関が、登録者の情報システムに関連するサイバーセキュリティインシデントを把握し、入手可能な事実から、項目1.05(a)項に基づき開示が求められる可能性のある情報が、国家安全保障または公共の安全に重大なリスクをもたらすと判断した場合、当該米国政府機関は、FBIおよびその他の米国政府機関と適切に協議の上、以下の事項を決定すべきである。政府が、項目1.05(c)の免除がない場合、登録者に対し通知を行い、登録者が開示を予定している情報の時期および内容を決定するために調整を行うべきか、また、司法長官が必要な決定を行った場合、登録者が開示の延期に同意するか否かを判断すべきである。関連する米国政府機関が公表の遅延が正当であると判断し、かつ登録者がこれに同意する場合、当該米国政府機関は直ちにFBIを通じて司法省に連絡し、関連する事実を伝え、遅延が適切である理由を説明し、遅延期間を推奨すべきである。司法省は、少なくとも当初においては、国家安全保障または公共の安全に対する重大なリスクを認識しているのは、登録者ではなく勧告を行う米国政府機関である可能性が高いと想定している。
a) Disclosure to the public of the cybersecurity incident as required by Item 1.05 would risk revealing a confidential source, information relating to U.S. national security, or law enforcement sensitive information and thereby pose a substantial threat to national security or public safety. The risk that disclosure will pose a substantial threat to national security or public safety is higher where the registrant learned of the cybersecurity incident only because a U.S. Government agency alerted the registrant to the cybersecurity incident or its possibility of occurrence.  a) 項目1.05で要求されるサイバーセキュリティインシデントの一般への開示は、機密情報源、米国の国家安全保障に関する情報、または法執行上の機密情報の暴露を招き、それによって国家安全保障または公共の安全に重大な脅威をもたらすリスクがある。登録者が当該サイバーセキュリティインシデント、またはその発生の可能性について、米国政府機関から通報を受けたために初めてその事実を知った場合、開示が国家安全保障または公共の安全に重大な脅威をもたらすリスクはより高くなる。
b) The U.S. Government is prepared to execute, or is aware of, an operation to disrupt ongoing illicit cyber activity that poses a substantial risk to national security or public safety, such as through freezing or seizing information, assets, or infrastructure involved in illicit cyber activity, or by effecting the arrest of an individual or individuals for illicit cyber activity, and public disclosure of the cybersecurity incident as required by Item 1.05 would pose a demonstrable threat or impediment to the success of such an operation.  b) 米国政府が、国家安全保障または公共の安全に重大なリスクをもたらす進行中の違法なサイバー活動を阻止するための作戦(情報の凍結や差し押さえ、 資産、またはインフラの凍結・差し押さえ、あるいはサイバー違法活動に関与した個人の逮捕などを通じて、進行中のサイバー違法活動を阻止する作戦を実行する準備があるか、またはその存在を把握している場合、かつ項目1.05で要求されるサイバーセキュリティインシデントの公開が、当該作戦の成功に対して明白な脅威または障害となる場合。
c) The U.S. Government is aware of or conducting remediation efforts for any critical infrastructure or critical system, and any disclosure required by Item 1.05(a) revealing that the registrant is aware of the incident would undermine those remediation efforts and thus pose a substantial risk to national security or public safety.  c) 米国政府が重要インフラまたは重要システムに対する修復措置を把握しているか、または実施している場合、かつ、項目1.05(a)で要求される開示により登録者が当該インシデントを把握していることが明らかになることが、それらの修復措置を損ない、ひいては国家安全保障または公共の安全に重大なリスクをもたらす場合。
4. Procedures following the Department’s determination of whether an Item 1.05(c) exception might apply  4. 項目1.05(c)の例外が適用されるか否かの省による判断後の手続き 
The Department has sole discretionary authority to determine whether and how long a substantial risk to national security or public safety exists such that a delay in disclosure is necessary consistent with Item 1.05. In making this determination and as referenced in section 2, the Department, through the FBI, will consult with other relevant U.S. Government agencies, such as USSS, CISA, and SRMAs, as appropriate. When the Attorney General determines that disclosure of all or part of the information required by Item 1.05 poses a substantial risk to national security or public safety, the Department will notify the Commission of such determination in writing. That notice will specify a period for the delay, up to 30 days. The Attorney General’s determination might pertain to only part of the information that Item 1.05 requires; for example, that disclosure of the timing of the incident would not pose a substantial risk to national security or public safety, but disclosure of the nature or scope of the incident would pose such a risk. The Department will, at or near the same time, also notify the recommending agency and the registrant of the determination, including the scope of information described in Item 1.05 covered by the determination, and the period for the delay.  省は、項目1.05に準拠して開示の遅延が必要となるほど、国家安全保障または公共の安全に対する重大なリスクが存在するか否か、またその期間について、単独の裁量権を有する。この判断を行うにあたり、第2項で言及されている通り、同省はFBIを通じて、必要に応じてUSSS、CISA、SRMAなどの他の関連する米国政府機関と協議する。司法長官が、項目1.05で要求される情報の全部または一部の開示が国家安全保障または公共の安全に重大なリスクをもたらすと判断した場合、同省はその判断を委員会に書面で通知する。当該通知には、最大30日間の開示遅延期間が明記される。司法長官の判断は、項目1.05で要求される情報の一部のみを対象とする場合がある。例えば、事件の発生時期の開示は国家安全保障または公共の安全に重大なリスクをもたらさないが、事件の性質または範囲の開示はそうしたリスクをもたらす、といった場合である。同省は、これと同時またはほぼ同時に、勧告機関および登録者に対しても、当該決定について通知する。その際、決定の対象となる項目1.05に記載された情報の範囲および遅延期間を含めるものとする。
When the Department determines, in its discretion, that the standard is not met for a disclosure delay, it will inform the recommending agency and the registrant, where applicable. If the recommending agency disagrees with the Department’s determination, it should inform the Department immediately and, time permitting, provide additional information or supporting material.  省が、その裁量により、開示遅延の基準が満たされていないと判断した場合は、推奨機関および登録者(該当する場合)にその旨を通知する。推奨機関が省の決定に同意しない場合は、直ちに省にその旨を通知し、時間が許せば、追加情報または裏付け資料を提出すべきである。
5. Changes in circumstances during a delay period  5. 遅延期間中の状況の変化
The recommending agency should inform the registrant of the ongoing need to apprise the recommending agency of any new or changed information relevant or potentially relevant to the national security or public safety risks of public disclosure that arises during the delay period. If, during the period of delay, the recommending agency assesses that public disclosure as required by Item 1.05 would no longer pose a substantial risk to national security or public safety, it will immediately notify the Department through the FBI. If the Department determines that the circumstances no longer meet Item 1.05(c)’s requirements for delaying disclosure, it will notify the recommending U.S. Government agency, the Commission, and the registrant of that determination in writing.  推薦機関は、開示遅延期間中に生じた、公開による国家安全保障または公共の安全へのリスクに関連する、あるいは関連する可能性のある新たな情報または変更された情報について、引き続き推薦機関に報告する必要がある旨を登録者に通知しなければならない。開示遅延期間中、推薦機関が、項目1.05で要求される公開がもはや国家安全保障または公共の安全に対する重大なリスクをもたらさないと判断した場合、FBIを通じて直ちに当省に通知する。同省が、当該状況がもはや項目1.05(c)の開示遅延要件を満たさないと判断した場合、その判断を推薦した米国政府機関、委員会、および登録者に書面で通知する。
6. Subsequent periods of delay  6. その後の遅延期間 
Item 1.05(c) refers to an initial delay of up to 30 days, a possible “additional” period of up to 30 days, a possible “final additional” period of delay of up to 60 days, and a possible further delay “beyond the final 60-day delay.”  項目1.05(c)は、最大30日間の初期遅延、最大30日間の「追加」遅延期間、最大60日間の「最終追加」遅延期間、および「最終60日間の遅延を超えて」さらに遅延する可能性について言及している。
“Additional” periods of delay after initial delay  初期の遅延後の「追加」遅延期間
Item 1.05(c) provides that “[d]isclosure may be delayed for an additional period of up to 30 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security or public safety and notifies the Commission of such determination in writing.”  項目1.05(c)は、「司法長官が、開示が引き続き国家安全保障または公共の安全に重大なリスクをもたらすと判断し、その判断を委員会に書面で通知した場合、開示は最大30日間の追加期間遅延されることがある」と規定している。
If, during an initial delay period, the recommending agency, the registrant, or another U.S. Government agency assesses that the substantial risk to national security or public safety from public disclosure will continue to exist beyond the initial delay period, then a request to the FBI for an “additional period” of delay is appropriate. A request for an “additional period” should be made at least five business days before the end of the initial period of delay and include a description of the continued substantial risk that disclosure poses to national security or public safety and an estimate of the duration that such risk may last.  初期の遅延期間中、勧告機関、登録者、または他の米国政府機関が、公開による国家安全保障または公共の安全に対する重大なリスクが初期の遅延期間を超えて存続すると判断した場合、FBIに対し「追加期間」の遅延を要請することが適切である。「追加期間」の要請は、最初の延期期間の終了の少なくとも5営業日前に行われ、開示が国家安全保障または公共の安全に及ぼす継続的な重大なリスクの説明、および当該リスクが継続すると見込まれる期間の見積もりを含める必要がある。
When the Attorney General determines that public disclosure continues to pose a substantial risk to national security or public safety and that a specific additional period of delay is justified, the Department will notify the Commission, the recommending agency, and the registrant of the nature and scope of such determination and the duration of the additional delay period in writing.  司法長官が、公開が引き続き国家安全保障または公共の安全に対する重大なリスクをもたらし、かつ特定の追加の開示遅延期間が正当化されると判断した場合、同省は、当該判断の性質と範囲、および追加の遅延期間について、委員会、勧告機関、および登録者に書面で通知する。
When the Department determines that the standard is not met for an additional delay in disclosure, it will inform the recommending agency and the registrant, where applicable. If the recommending agency disagrees with the Department’s determination, it may inform the Department immediately and, time permitting, provide additional information or supporting material.  司法省が、開示の追加遅延に関する基準が満たされていないと判断した場合は、勧告機関および登録者(該当する場合)にその旨を通知する。勧告機関が司法省の判断に同意しない場合は、直ちに司法省にその旨を通知し、時間が許せば、追加情報または裏付け資料を提出することができる。
“Final additional” periods of delay  「最終的な追加」遅延期間 
Item 1.05(c) provides that “[i]n extraordinary circumstances, disclosure may be delayed for a final additional period of up to 60 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security and notifies the Commission of such determination in writing.”  第1.05(c)項は、「極めて例外的な状況において、司法長官が開示が引き続き国家安全保障に重大なリスクをもたらすと判断し、その判断を委員会に書面で通知した場合、開示を最大60日間の最終的な追加期間遅延させることができる」と規定している。
If, during an “additional period” of delay, the recommending agency, the registrant, or another U.S. Government agency assesses that there is an extraordinary circumstance in which public disclosure continues to pose a substantial risk to national security beyond the additional delay period, the recommending agency, registrant, or other relevant U.S. Government agency will inform the FBI and the  「追加の延期期間」中に、勧告機関、登録者、または他の米国政府機関が、追加の延期期間を超えてもなお、公開が国家安全保障に重大なリスクをもたらし続けるような特段の事情があると判断した場合、勧告機関、登録者、またはその他の関連する米国政府機関は、FBIおよび
Department as soon as possible. A request for a “final additional period” should include a description of the extraordinary circumstances and continued substantial risk that public disclosure poses to national security. As with the earlier periods of delay, the Department’s determination might pertain to only part of the information that Item 1.05(a) requires and might be narrower in scope than the determination for the additional period of delay. If the Attorney General determines that public disclosure continues to pose a substantial risk to national security or public safety (as described in Section 2 above), the Department will notify the Commission, the recommending agency, and the registrant of the nature and scope of such determination and the duration of the final additional delay period in writing.  同省にできるだけ速やかに通知する。「最終追加期間」の要請には、特段の事情および公開が国家安全保障に及ぼし続ける重大なリスクに関する説明を含める必要がある。以前の延期期間と同様、司法省の判断は、項目1.05(a)で要求される情報の一部のみを対象とする場合があり、追加延期期間の判断よりも範囲が狭くなる可能性がある。司法長官が、公開が引き続き国家安全保障または公共の安全に重大なリスクをもたらすと判断した場合(上記第2項に記載の通り)、同省は、当該判断の性質と範囲、および最終的な追加遅延期間の期間について、委員会、勧告機関、および登録者に書面で通知する。
When the Department determines that the standard is not met for an additional disclosure delay, it will inform the recommending agency and the registrant, where applicable. If the recommending agency disagrees with the Department’s determination, it may inform the Department immediately and, time permitting, provide additional information or supporting material.  司法省が、開示の追加遅延に関する基準が満たされていないと判断した場合、当該省は、勧告機関および登録者(該当する場合)にその旨を通知する。勧告機関が司法省の判断に同意しない場合、直ちに司法省にその旨を通知し、時間が許せば、追加情報または裏付け資料を提出することができる。
Periods “beyond the final 60-day delay”  「最終60日間の延期期間」を超える期間
Item 1.05(c) provides that “[b]eyond the final 60-day delay under this paragraph, if the Attorney General indicates that further delay is necessary, the Commission will consider additional requests for delay and may grant such relief through Commission exemptive order.”  項目1.05(c)は、「本項に基づく最終60日間の延期期間を超えて、司法長官がさらなる延期が必要であると示した場合、委員会は追加の延期要請を検討し、委員会の免除命令を通じてそのような救済を認めることができる」と規定している。
If, during a “final additional” period of delay, the recommending agency, the registrant, or another U.S. Government agency assesses that public disclosure continues to pose a substantial risk to national security beyond the final additional period of delay, the recommending agency, registrant, or other relevant U.S. Government agency will so inform the FBI and the Department. If the Attorney General determines that public disclosure continues to pose a substantial risk to national security, the Department will so indicate in writing to the Commission, which will consider the merits of issuing an exemptive order allowing additional delay. If any additional delay is allowed, the Department will notify the recommending agency and the registrant of the nature and scope of such determination and the duration of the additional delay period in writing.  「最終的な追加」延期期間中、勧告機関、登録者、または他の米国政府機関が、公開が最終的な追加延期期間を超えてもなお国家安全保障に重大なリスクをもたらし続けると判断した場合、勧告機関、登録者、またはその他の関連する米国政府機関は、その旨をFBIおよび司法省に通知する。司法長官が、公開が引き続き国家安全保障に重大なリスクをもたらすと判断した場合、司法省は委員会に対し書面でその旨を通知し、委員会は追加の延期を認める免除命令の発令の是非を検討する。追加の延期が認められる場合、司法省は、その決定の内容と範囲、および追加の延期期間について、勧告機関および登録者に書面で通知する。
When the Department determines that the standard is not met for an additional disclosure delay, it will inform the recommending agency and the registrant, where applicable. If the recommending agency disagrees with the Department’s determination, it may inform the Department immediately and, time permitting, provide additional information or supporting material.  司法省が、開示の追加延期に関する基準が満たされていないと判断した場合は、勧告を行った機関および登録者(該当する場合)にその旨を通知する。勧告を行った機関が司法省の判断に同意しない場合は、直ちに司法省にその旨を通知し、時間が許せば、追加情報または裏付け資料を提出することができる。
7. This document’s limited scope  7. 本文書の限定的な範囲
These guidelines do not address processes or procedures for interagency sharing of registrantrelated information. While the Department anticipates considerable coordination and consultation with other agencies, this document does not purport to describe that work.  本ガイドラインは、登録者関連情報の省庁間共有に関するプロセスや手続きについては扱わない。当省は他省庁との相当な調整や協議を見込んでいるが、本文書はそのような業務について記述するものではない。
These guidelines do not attempt to describe every situation in which the law might require a cybersecurity disclosure, or when cybersecurity disclosures are advisable even if not required. Aside from the Commission’s public disclosure requirements contained in Item 1.05, additional or concurrent reporting to the Commission pursuant to other statutory or regulator provisions or other government agencies (such as to CISA, SRMAs, or regulators) may be legally required or advisable.  本ガイドラインは、法律によりサイバーセキュリティ開示が義務付けられるあらゆる状況、あるいは義務付けられていない場合でも開示が望ましい状況について、すべてを網羅するものではない。項目1.05に含まれる委員会の公開開示要件とは別に、他の法令や規制当局の規定、あるいは他の政府機関(CISA、SRMA、規制当局など)への追加的または並行的な報告が、法的に義務付けられているか、あるいは推奨される場合がある。
This document provides no legal advice about the meaning of Item 1.05, or about the nature or extent of the Commission’s reporting requirements.  本文書は、項目1.05の意味、あるいは委員会の報告要件の性質や範囲について、法的助言を提供するものではない。
Future rulemaking pursuant to the Cyber Incident Reporting Act for Critical Infrastructure  重要インフラ向けサイバーインシデント報告法(CIRCIA)
(CIRCIA) and the Cyber Incident Reporting Council’s directive to harmonize mandatory cyber incident reporting under CIRCIA (see 6 U.S.C. §§ 681f and 681g) may affect the contents of these guidelines. The Department will reassess these guidelines after CIRCIA rulemaking is complete, with consideration of any relevant recommendations from the Council on harmonization and streamlined reporting processes.  に基づく今後の規則制定、およびCIRCIAに基づく義務的なサイバーインシデント報告の調和を図るためのサイバーインシデント報告評議会の指示(6 U.S.C. §§ 681f および 681g 参照)は、本ガイドラインの内容に影響を与える可能性がある。当省は、CIRCIAに基づく規則制定が完了した後、調和および報告プロセスの合理化に関する評議会からの関連する提言を考慮し、本ガイドラインを再評価する。
These guidelines have no regulatory effect, confer no rights or remedies, and do not have the force of law. See United States v. Caceres, 440 U.S. 741 (1979).  本ガイドラインは規制上の効力を有さず、いかなる権利や救済手段も付与せず、法的拘束力を持たない。United States v. Caceres, 440 U.S. 741 (1979) を参照のこと。
[1] References to “the Attorney General” throughout this document refer to the Attorney General and authorized designees at the Department of Justice.  [1] 本文書における「司法長官」への言及は、司法長官および司法省内の権限を付与された指名者を指す。

 

 

 


 

 

・2025.02.28 [PDF] FEDERAL BUREAU OF INVESTIGATION POLICY DIRECTIVE Cyber Victim Requests to Delay Securities and Exchange Commission Public Disclosure Policy Directive 1355D

20260529-61355

 

FEDERAL BUREAU OF INVESTIGATION POLICY DIRECTIVE  連邦捜査局(FBI)方針指令
Cyber Victim Requests to Delay Securities and Exchange Commission Public Disclosure Policy Directive 1355D  証券取引委員会(SEC)への情報開示延期を求めるサイバー被害者からの要請に関する方針指令 1355D
General Information  概要
Proponent Cyber Division (CyD)  提案者:サイバー部門(CyD)
Publication Date 2025-02-28  公表日 2025-02-28
Last Updated N/A  最終更新日 該当なし
Supersession Cyber Victim Requests to Delay Securities and Exchange Commission Public Disclosure Policy Notice (1297N)  廃止 サイバー被害者による証券取引委員会(SEC)への公開開示延期要請に関する方針通知(1297N)
1. Authorities  1. 根拠
• Volume 88 Federal Register (Fed. Reg.), No. 51896, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Securities and Exchange Commission (SEC) (2023)  • 連邦官報(Fed. Reg.)第88巻、第51896号、「サイバーセキュリティリスク管理、戦略、ガバナンス、およびインシデント開示」、証券取引委員会(SEC)(2023年)
Department of Justice (DOJ) Material Cybersecurity Incident Delay Determinations  (2023)  司法省(DOJ)重要サイバーセキュリティインシデントの開示延期決定 (2023) 
• Securities Exchange Act of 1934  • 1934年証券取引法 
2. Purpose  2. 目的 
2.1. This policy directive (PD) implements the DOJ Material Cybersecurity Incident Delay Determinations guidelines and establishes procedures by which Federal Bureau of Investigation (FBI) personnel will document cybersecurity incident public disclosure delay requests, related incident details, and United States government (USG) national security or public safety checks in an FD-1219, “Federal Bureau of Investigation 8-K Cyber Delay Referral Form.” This PD also establishes the roles, responsibilities, and procedures by which FBI personnel will send these forms to DOJ to facilitate delay determinations.  2.1. 本方針指令(PD)は、司法省(DOJ)の「重大なサイバーセキュリティインシデントに関する公表延期決定」ガイドラインを実施するものであり、連邦捜査局(FBI)職員が、サイバーセキュリティインシデントの公表延期要請、関連するインシデントの詳細、および米国政府(USG)による国家安全保障または公共の安全に関する審査を、FD-1219「連邦捜査局 8-K サイバーセキュリティインシデント公表延期照会書」に記録するための手順を定めるものである。また、本PDは、遅延決定を円滑に進めるため、FBI職員がこれらの様式を司法省(DOJ)に送付する際の役割、責任、および手順を定めるものである。
2.2. Per the SEC’s Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule (88 Fed. Reg. 51896), publicly traded companies are required to determine whether each cybersecurity incident that they experience is a material cybersecurity incident pursuant to the rule. This determination is the responsibility of publicly traded companies subject to the rule and the Securities Exchange Act. Once a company makes a materiality determination, the company has four business days to publicly disclose the incident by filing an SEC Form 8-K in the SEC’s EDGAR database.  2.2. SECの「サイバーセキュリティ・リスク管理、戦略、ガバナンス、およびインシデント開示に関する規則」(88 Fed. Reg. 51896)に基づき、上場企業は、自社で発生した各サイバーセキュリティインシデントが、同規則に従い重要なサイバーセキュリティインシデントに該当するかどうかを判断することが義務付けられている。この判断は、同規則および証券取引法の適用を受ける上場企業の責任である。企業が重要性の判断を下した後、同社は4営業日以内にSECのEDGARデータベースへSECフォーム8-Kを提出し、当該インシデントを公表しなければならない。
2.3. The SEC rule permits DOJ to notify these companies that they may delay public filing if the Attorney General (AG) (or designee) determines that disclosure through a public filing poses a substantial risk to national security or public safety and notifies the SEC of such determination in writing. Initially, disclosure may be delayed for a timeframe specified by the AG but must only last up to 30 calendar days following the date when the SEC disclosure was otherwise required to be provided (i.e., four business days from determining materiality). If the AG determines that disclosure continues to pose a substantial risk to national security or public safety, the disclosure delay may be extended for an additional period of up to 30 calendar days, and DOJ will notify the SEC of such determination in writing. In extraordinary circumstances, if the AG determines that disclosure continues to pose a substantial risk to national security and notifies the SEC of such determination in writing, disclosure may be delayed for a final additional period of up to 60 calendar days. The DOJ Material Cybersecurity Incident Delay Determinations memo explains how DOJ and the AG will make these determinations and notify the requesting victim, the SEC, and the referring agency (including the FBI) of determinations. Through this memo, the FBI is responsible for intaking all such requests (either from a victim directly, the Cybersecurity and Infrastructure Security Agency [CISA], or other government agencies [OGA]) on behalf of DOJ; coordinating checks of USG national security and public safety equities; and reporting the outcome of these checks to DOJ.  2.3. SEC規則は、司法長官(AG)(またはその指名者)が、公的届出による開示が国家安全保障または公共の安全に重大なリスクをもたらすと判断し、その判断をSECに書面で通知した場合、DOJが当該企業に対し、公的届出を遅延させることができる旨を通知することを認めている。当初、開示は司法長官が指定した期間だけ遅延させることができるが、その期間は、本来SECへの開示が義務付けられていた日(すなわち、重要性の判断から4営業日後)から起算して30暦日以内にとどめなければならない。司法長官が開示が引き続き国家安全保障または公共の安全に重大なリスクをもたらすと判断した場合、開示の延期は最大30暦日延長され、司法省は当該判断をSECに書面で通知する。極めて例外的な状況において、司法長官が開示が引き続き国家安全保障に重大なリスクをもたらすと判断し、その判断をSECに書面で通知した場合、開示は最終的に最大60暦日延長されることがある。司法省の「重大なサイバーセキュリティインシデントに関する開示遅延の決定」に関する覚書は、司法省および司法長官がこれらの決定をどのように行い、要請を行った被害者、SEC、および照会機関(FBIを含む)に決定を通知するかを説明している。この覚書を通じて、 FBIは、司法省に代わって、被害者本人、サイバーセキュリティ・インフラセキュリティ庁(CISA)、またはその他の政府機関(OGA)からのすべての当該要請を受け付けること、米国政府の国家安全保障および公共の安全に関する利益の照合を調整すること、およびこれらの照合結果を司法省に報告することを担当する。
3. Scope  3. 適用範囲
This PD applies to all FBI personnel.  本PDは、すべてのFBI職員に適用される。
4. Exemptions  4. 適用除外 
There are no exemptions to this PD.  本PDには適用除外はない。
5. Policy Statement  5. 方針声明 
5.1. This PD applies to all requests from cyber incident victims for a referral of their incident to DOJ for a delay of SEC public filing requirements, regardless of whether:  5.1. 本PDは、サイバーインシデントの被害者から、SECの公開提出要件の延期を目的として、当該インシデントをDOJに照会するよう求めるすべての要請に適用される。以下のいずれの場合であっても適用される:
5.1.1. The request is the FBI’s first notice of the incident or the request is made after the FBI is already aware of the incident.  5.1.1. 当該要請がFBIにとってのインシデントに関する最初の通知であるか、またはFBIが既に当該インシデントを把握している後に要請がなされたか。
5.1.2. The victim is requesting a delay determination for the first time or an extension of an existing delay determination.  5.1.2. 被害者が遅延決定を初めて請求しているか、既存の遅延決定の延長を請求しているか。
5.2. This PD establishes roles, responsibilities, and procedures of FBI personnel for:  5.2. 本PDは、以下の事項に関するFBI職員の役割、責任、および手順を定める:
5.2.1. The intake of delay referral requests from cyber incident victims directly or via CISA or OGAs.  5.2.1. サイバーインシデントの被害者から直接、またはCISAやOGAを通じて行われる遅延照会請求の受付。
5.2.2. Coordinating checks of USG national security and public safety equities for each delay referral request.  5.2.2. 各遅延照会要請について、米国政府の国家安全保障および公共の安全上の利益に関する確認を調整すること。
5.2.3. Documenting these requests and checks in an FD-1219.  5.2.3. これらの要請および確認内容をFD-1219に記録すること。
5.2.4. Submitting approved and completed FD-1219 forms to DOJ.  5.2.4. 承認済みかつ記入済みのFD-1219フォームを司法省(DOJ)に提出すること。
5.2.5. Conducting follow-up victim engagement, as appropriate.  5.2.5. 必要に応じて、被害者とのフォローアップ対応を行うこと。
5.2.6. Coordinating and documenting requests for additional delay referrals.  5.2.6. 追加の遅延付託要請について調整し、記録する。
5.3. This PD complements and does not supersede other cyber incident response, victim notification, or coordination requirements found in the Cyber Division Policy Guide (1181PG) [Redacted].  5.3. 本PDは、『サイバー部門ポリシーガイド(1181PG)』[削除済み]に記載されている他のサイバーインシデント対応、被害者通知、または調整要件を補完するものであり、それらに優先するものではない。
6. Roles and Responsibilities  6. 役割と責任 
6.1. All FBI personnel who are in receipt of a request from a cyber incident victim, either directly or via CISA or OGAs, for a referral of their incident to DOJ for a delay of SEC public filing requirements must as soon as possible direct victims to make these delay requests by filling out the online “SEC Reporting Requirements Delay Request Form” <https://sec8k.ic3.gov>.  6.1. サイバーインシデントの被害者から、直接、あるいはCISAやOGAを通じて、SECの公開提出要件の延期を目的としたDOJへのインシデント照会要請を受けたすべてのFBI職員は、被害者に対し、オンラインの「SEC報告要件延期要請フォーム」<https://sec8k.ic3.gov>に記入して、これらの延期要請を行うよう、できるだけ速やかに指示しなければならない。
6.2. The time requirements of the following subsections of this policy must be actioned for all initial requests for a disclosure delay. If a victim is granted a disclosure delay by DOJ and submits a request for an extension at least five business days prior to the expiration of the granted delay, then CyWatch may adjust the timeliness requirements of the following subsections as appropriate per its judgement.  6.2. 本方針の以下の各節に定める時間要件は、開示遅延に関するすべての初回要請に対して適用されなければならない。被害者が司法省(DOJ)から開示遅延の許可を受け、かつ許可された遅延期間の満了日の少なくとも5営業日前までに延長要請を提出した場合、CyWatchはその判断に基づき、以下の各節の適時性要件を適切に調整することができる。
6.3. CyWatch must:  6.3. CyWatchは以下を行わなければならない:
6.3.1. Within two hours of receipt of a request submitted through the online form, conduct the following actions (although, if the online form is submitted during a non-business day, these designated time requirements commence at the next opening of business hours):  6.3.1. オンラインフォームを通じて提出された要請を受領してから2時間以内に、以下の措置を講じなければならない(ただし、オンラインフォームが非営業日に提出された場合、これらの指定された時間要件は次の営業時間の開始時に適用される):
6.3.1.1. Verify the request has been made by a publicly traded company.  6.3.1.1. 要請が上場企業によって行われたことを確認する。
6.3.1.2. Verify the request has been made immediately upon the company’s determination to disclose details of a cyber incident via an SEC Form 8-K.  6.3.1.2. 当該企業がSECフォーム8-Kを通じてサイバーインシデントの詳細を開示することを決定した直後に、リクエストが行われたことを確認する。
6.3.1.3. Upon verification of the criteria asked in the above subsections 6.3.1.1. and 6.3.1.2. of this PD, conduct initial record checks of FBI databases for information specifically related to the incident, including but not limited to a past or present investigation or [Redacted] on the request's referenced cyber incident and the attributed threat activity or actors responsible for the incident, if known. If the victim is not a publicly traded company, or if the victim does not make this request to CyWatch immediately upon the company’s determination to disclose details of a cyber incident via an SEC Form 8-K, CyWatch should not process the request. If CyWatch determines not to process a request based on these criteria, it must document this determination in an administrative case file maintained [Redacted] by CyWatch.  6.3.1.3. 本PDの上記6.3.1.1.および6.3.1.2.項で求められた基準の確認後、当該インシデントに特に関連する情報について、FBIデータベースの初期記録照会を行う。これには、リクエストで言及されたサイバーインシデントおよび、判明している場合は当該インシデントの原因となった脅威活動または責任あるアクターに関する、過去または現在の調査、あるいは[削除済み]などが含まれるが、これらに限定されない。被害者が上場企業でない場合、または被害者がSECフォーム8-Kを通じてサイバーインシデントの詳細を開示することを決定した直後にCyWatchに本要請を行わない場合、CyWatchは当該要請を処理してはならない。CyWatchがこれらの基準に基づき要請を処理しないと判断した場合、CyWatchが[削除]で管理する行政案件ファイルに、その判断を記録しなければならない。
6.3.1.4. Populate questions one through six of a new draft FD-1219 based on the information provided in the victim’s request and initial record checks, per the above subsection 6.3.1.3. of this PD. If responses to the online delay request form satisfy any or all of questions one through six of the FD-1219, CyWatch should not alter the provided information but may add to it, as appropriate (e.g., using information found during record checks). CyWatch must designate in the FD-1219 which text was provided by the victim and which was new text added by CyWatch.  6.3.1.4. 本PDの上記6.3.1.3項に従い、被害者の要請および初期記録照会により提供された情報に基づき、新規FD-1219草案の質問1から6までを記入する。オンライン遅延要請フォームへの回答が、FD-1219の質問1から6のいずれかまたはすべてを満たす場合、CyWatchは提供された情報を変更してはならないが、必要に応じて(例:記録照会中に発見された情報を使用するなど)追加することはできる。CyWatchは、FD-1219において、どのテキストが被害者によって提供されたものであり、どのテキストがCyWatchによって新たに追加されたものであるかを明記しなければならない。
6.3.1.5. If a field office (FO) has an open investigation on the request’s referenced cyber incident, send a [Redacted] email to the corresponding appropriate FO cyber squad(s) for the investigation. If no FO has an open investigation on the request’s referenced cyber incident, send a [Redacted] email to the corresponding appropriate FO cyber squad(s) of the victim’s local FO. These emails should include, at minimum:  6.3.1.5. 現地事務所(FO)が、当該要請で言及されたサイバーインシデントについて未解決の調査を行っている場合、当該調査を担当する適切なFOサイバーチームに対し、[Redacted]メールを送信する。どのFOも当該要請で言及されたサイバーインシデントについて未解決の調査を行っていない場合、被害者の管轄FOの適切なFOサイバーチームに対し、[Redacted]メールを送信する。これらのメールには、少なくとも以下を含めること:
6.3.1.5.1. A subject line stating, “SEC Disclosure Delay Referral: Request by [Insert Victim Identity].”  6.3.1.5.1. 「SEC開示遅延の照会:[被害者の身元を挿入]による要請」と記載した件名。
6.3.1.5.2. The draft FD-1219, initiated per the above subsection 6.3.1.4. of this PD [Redacted].  6.3.1.5.2. 本PD [Redacted]の上記6.3.1.4項に基づき作成されたFD-1219の草案。
6.3.1.5.3. A summary of the incoming request from the cyber incident victim, including where the incident occurred.  6.3.1.5.3. サイバーインシデント被害者からの要請の概要(インシデントの発生場所を含む)。
6.3.1.5.4. The following statement: "The FO in receipt of this email must complete the roles and responsibilities assigned in subsection 6.4. of the Cyber Victim Requests to Delay Securities and Exchange Commission Public Disclosure Policy Directive (1355D) within 24 hours of receipt.”  6.3.1.5.4. 以下の文言:「本メールを受領した現地事務所(FO)は、受領後24時間以内に、『サイバー被害者による証券取引委員会(SEC)への公開開示遅延要請に関する方針指令(1355D)』の第6.4項で割り当てられた役割と責任を履行しなければならない。」
6.3.1.5.5. A copy to the appropriate CyD operational desk program managers (PMs) and Cyber Threat Team (CTT), if applicable; the section chief (SC) of the Cyber Operations Support Section (COSS).  6.3.1.5.5. 該当する場合、適切なCyD運用デスクのプログラムマネージャー(PM)およびサイバー脅威チーム(CTT)への写し;サイバー運用支援課(COSS)の課長(SC)。
6.3.1.6. Following the FO’s return of the draft FD-1219 to CyWatch, CyWatch must share this returned copy of the FD-1219 with the appropriate CyD operational desk PMs. This notification must task these PMs to commence completing the roles and responsibilities assigned in subsection 6.8. of this PD within 28 hours of the receipt of the draft FD-1219.  6.3.1.6. FOがFD-1219草案をCyWatchに返送した後、CyWatchは、この返送されたFD-1219の写しを、適切なCyD運用デスクのPMと共有しなければならない。この通知において、当該PMに対し、FD-1219草案の受領から28時間以内に、本PDの第6.8項で割り当てられた役割と責任の履行を開始するよう指示しなければならない。
6.3.1.7. Concurrent with the notifications made per subsection 6.3.1.5. and the above 6.3.1.6. of this PD, notify the appropriate OGAs (as determined by CyWatch’s list) with national security and public safety equities of the incoming request from a cyber incident victim.  6.3.1.7. 本PDの6.3.1.5.項および上記の6.3.1.6.項に基づく通知と並行して、国家安全保障および公共の安全に関わる利害関係を有する適切なOGA(CyWatchのリストに基づき決定される)に対し、サイバーインシデント被害者からの要請が寄せられたことを通知しなければならない。
6.3.1.7.1. This notification must include the incident information provided through the victim’s request and information documented per subsection 6.3.1.4. of this PD. The notification must task these OGAs to conduct equity checks to help determine if public filing of the incident would pose a substantial risk to national security or public safety; return results of these equity checks to CyWatch within 24 hours; and handle enclosed victim information in accordance with the Framework for Improved Cyber Information Sharing and Interagency Coordination for Critical Infrastructure Engagements Regarding Cyber Threats and Incidents, also known as the Federal Senior Leadership Council (FSLC) Framework, approved by the National Security Council Cyber Policy Coordination Committee on April 22, 2020.  6.3.1.7.1. 本通知には、被害者の要請を通じて提供されたインシデント情報および本PDの6.3.1.4項に基づき記録された情報を含めなければならない。また、本通知においては、当該インシデントの公開が国家安全保障または公共の安全に重大なリスクをもたらすかどうかを判断するため、これらのOGAに対し、公平性チェックの実施を指示しなければならない; これらの公平性チェックの結果を24時間以内にCyWatchに報告すること;および、2020年4月22日に国家安全保障会議サイバー政策調整委員会により承認された、「サイバー脅威およびインシデントに関する重要インフラへの関与のためのサイバー情報共有および省庁間調整の改善に関する枠組み」(通称:連邦上級指導者評議会(FSLC)枠組み)に従って、添付された被害者情報を扱うこと。
6.3.1.8. Notify DOJ of the request with a confirmation that CyD intends to process the request.  6.3.1.8. CyDが当該要請を処理する意向であることを確認した上で、その要請を司法省(DOJ)に通知する。
6.3.2. Maintain a list of OGAs eligible to submit online delay request forms on behalf of cyber incident victims.  6.3.2. サイバーインシデントの被害者に代わってオンライン遅延要請フォームを提出する資格を有するOGAのリストを維持する。
6.3.3. Within two hours of receipt of responses from the relevant FO, CyD operational desk PMs, and OGAs, per the concurrent tasks assigned in subsection 6.3.1.5. through the above subsection 6.3.1.7. of this PD, must:  6.3.3. 本PDの6.3.1.5.項から上記の6.3.1.7.項までに割り当てられた並行タスクに従い、関連するFO、CyD運用デスクPM、およびOGAからの回答を受領してから2時間以内に、以下を行わなければならない:
6.3.3.1. Complete the remainder of FD-1219, Section Two. This action must include ensuring that documentation of record checks was performed by CyD operational desk PMs for question six of the FD-1219, per the above subsection 6.3.1.6. and subsection 6.8. of this PD; completing question seven of the FD-1219, based on responses provided by appropriate OGAs, per the above subsection 6.3.1.7. of this PD; and providing a summary of the findings of risk for public disclosure to national security or public safety in response to questions eight and nine of the FD-1219.  6.3.3.1. FD-1219の第2セクションの残りの部分を記入する。この措置には、本PDの上記6.3.1.6項および6.8項に基づき、FD-1219の質問6についてCyD運用デスクPMによる記録照会が実施されたことを確認することが含まれなければならない; 本PDの上記6.3.1.7項に基づき、適切なOGAsから提供された回答に基づいて、FD-1219の質問7を記入すること;およびFD-1219の質問8および9に対する回答として、国家安全保障または公共の安全に対するリスクの調査結果の概要を提示すること。
6.3.3.2. Request and gain, if applicable, verbal or written approval of the final FD-1219 from the COSS SC (delegable to the DAD or AD) per subsection 6.5. to subsection 6.7.2. of this PD. An acting official may not approve the FD-1219.  6.3.3.2. 本PDの第6.5項から第6.7.2項に基づき、COSS SC(DADまたはADに委任可能)に対し、最終的なFD-1219について、該当する場合、口頭または書面による承認を要請し、取得すること。代理の役職者はFD-1219を承認してはならない。
6.3.3.3. Send a copy of the approved form to the designated DOJ email inboxes. This email must include confirmation that CyD is making the referral following internal records checks and OGA equity checks; a copy of the FD-1219, approved per subsection 6.5. through subsection 6.7. of this PD; and a request for confirmation from DOJ of its delay determination.  6.3.3.3. 承認された書式の写しを、指定された司法省(DOJ)の電子メール受信箱に送付する。この電子メールには、CyDが内部記録確認およびOGA公平性確認を経て照会を行っていることの確認、本PDの第6.5項から第6.7項に従って承認されたFD-1219の写し、および司法省(DOJ)による遅延決定の確認を求める要請を含めなければならない。
6.3.4. Within 10 business days of receipt of approval of the final FD-1219, per subsection 6.3.3.2. of this PD, upload the email chain containing SC approval of the completed FD1219 to the appropriate [Redacted] file maintained by CyWatch.  6.3.4. 本PDの6.3.3.2項に従い、最終的なFD-1219の承認を受領してから10営業日以内に、完成したFD-1219に対するSCの承認を含むメールのやり取りを、CyWatchが管理する適切な[削除済み]ファイルにアップロードする。
6.3.5. Upon receipt of DOJ’s delay determination (which DOJ will make concurrently to the victim and the SEC):  6.3.5. DOJの遅延決定(DOJは被害者およびSECに対して同時に通知する)を受領した時点で:
6.3.5.1. Contact the victim via formal written communication, as appropriate, to confirm that the FBI is aware of DOJ’s determination. If DOJ approves the delay request, CyWatch’s contact with the victim should include an invitation for the victim to submit any requests for delay extensions no later than five business days before the expiration of the granted delay. CyWatch should advise the victim to submit this renewal request through the online form referred to in subsection 6.1. of this PD. CyWatch must make the relevant FO(s), relevant CyD operational desk PMs, and the COSS SC aware of this contact, as appropriate. This will enable additional relevant FO engagement with the victim.  6.3.5.1. 必要に応じて、正式な書面による連絡を通じて被害者に連絡し、FBIが司法省の決定を把握していることを確認する。司法省が遅延要請を承認した場合、CyWatchによる被害者への連絡には、承認された遅延期間の満了の5営業日前までに、遅延延長の要請を提出するよう被害者に促す内容を含めるべきである。CyWatchは、本PDの第6.1項で言及されているオンラインフォームを通じて、この更新要請を提出するよう被害者に助言すべきである。CyWatchは、必要に応じて、関連するFO、関連するCyD運用デスクのPM、およびCOSS SCに対し、この連絡を行ったことを通知しなければならない。これにより、被害者に対する関連FOによる追加的な関与が可能となる。
6.3.5.2. Document DOJ’s delay determination [Redacted].  6.3.5.2. DOJの延期決定を文書化する [削除済み]。
6.3.6. Manage related communications with DOJ following the referral of an FD-1219 to DOJ. These communications may include, but not be limited to, follow-up questions related to the contents of the FD-1219 and the process by which FBI arrived at the facts and findings documented therein.  6.3.6. FD-1219がDOJに照会された後の、DOJとの関連する連絡を管理する。これらの連絡には、FD-1219の内容、およびFBIがそこに記載された事実と結論に到達したプロセスに関する追跡質問が含まれるが、これらに限定されない。
6.3.7. Manage communication mechanisms (e.g., email inboxes or telephone lines) for the victim request intake and referral process and monitor them on a 24/7 basis.  6.3.7. 被害者からの要請受付および照会手続きのための連絡手段(例:電子メール受信箱や電話回線)を管理し、24時間365日体制で監視する。
6.3.8. Develop, update, and provide appropriate training materials and communications to stakeholders of the processes outlined in this PD, in coordination with CyD’s Cyber Education and Training Unit (CETU), Executive Staff Unit (ESU), the Cyber Policy Team, and the Office of the General Counsel (OGC), as appropriate.  6.3.8. 本PDに概説されたプロセスの関係者に対し、必要に応じてCyDのサイバー教育・訓練ユニット(CETU)、執行スタッフユニット(ESU)、サイバー政策チーム、および法務総局(OGC)と連携し、適切な研修資料および連絡事項を作成、更新、提供すること。
6.4. FO heads (delegable to assistant special agents in charge [ASAC]):  6.4. 現地事務所(FO)長(副特別捜査官(ASAC)に委任可能):
6.4.1. Must establish and execute a process by which their subordinate personnel respond to CyWatch emails sent to FOs, per subsection 6.3.1.5. of this PD. The established process must, at minimum, execute the following actions within 24 hours:  6.4.1. 本PDの6.3.1.5項に従い、FO宛てに送信されるCyWatchメールに対し、配下の職員が対応するプロセスを確立し、実行しなければならない。確立されたプロセスでは、少なくとも24時間以内に以下の措置を講じなければならない:
6.4.1.1. Intake the request and engage with the victim, as appropriate.  6.4.1.1. 要請を受け付け、必要に応じて被害者と接触する。
6.4.1.2. Review and edit the drafted FD-1219, Section One based on information learned during victim engagement, when applicable.  6.4.1.2. 該当する場合、被害者との接触中に得た情報に基づき、作成済みのFD-1219第1セクションを精査・修正する。
6.4.1.3. Respond to CyWatch’s email per subsection 6.3.1.5. of this PD with an attached, completed FD-1219, Section One; [Redacted]; and as appropriate, a recommendation of other FOs with whom CyD should consult as it determines potential related national security or public safety equities.  6.4.1.3. 本PDの6.3.1.5項に従い、記入済みのFD-1219第1セクションを添付してCyWatchの電子メールに返信する; [削除済み];および必要に応じて、CyDが潜在的な関連する国家安全保障または公共の安全上の利害関係を判断する際に協議すべき他のFOに関する推奨事項を添付する。
6.4.2. Should ensure that their FOs provide timely input, as appropriate, if CyD operational desk PMs notify the FO of a pending request and related equities in the FO’s investigative records, per subsection 6.8.2. of this PD.  6.4.2. 本PDの6.8.2項に基づき、CyDの運用デスクPMがFOに対し、未処理の要請および当該FOの捜査記録に関連する利害関係について通知した場合、当該FOが適切かつ適時に意見を提供するよう確保しなければならない。
6.5. The COSS SC must approve or deny FD-1219s, per subsection 6.3.3.2. of this PD, within CyWatch’s two-hour deadline. The COSS SC must not delegate this task or reassign it to another SC.  6.5. COSS SCは、本PDの6.3.3.2項に従い、CyWatchの2時間という期限内にFD-1219を承認または却下しなければならない。COSS SCは、この任務を委任したり、他のSCに再割り当てしたりしてはならない。
6.6. The deputy assistant director (DAD) of CyD’s Cyber Operations Branch (COB), in the absence of the COSS SC, must approve or deny FD-1219s within CyWatch’s two-hour deadline, per subsection 6.3.3.2. of this PD.  6.6. COSS SCが不在の場合、CyDサイバー運用部(COB)の副次長(DAD)は、本PDの6.3.3.2項に従い、CyWatchの2時間という期限内にFD-1219を承認または却下しなければならない。
6.7. The assistant director (AD) of CyD must:  6.7. CyDの次長(AD)は、以下を行わなければならない:
6.7.1. In the absence of both the COSS SC and the COB DAD, approve or deny FD-1219s within CyWatch’s 2-hour deadline, per subsection 6.3.3.2. of this PD.  6.7.1. COSS SCおよびCOB DADの両方が不在の場合、本PDの6.3.3.2項に従い、CyWatchの2時間という期限内にFD-1219を承認または却下しなければならない。
6.7.2. Designate an approver of FD-1219s in the joint absence of the COSS SC; DAD, COB; and AD, CyD.  6.7.2. COSS SC、COB DAD、およびCyD ADが同時に不在の場合、FD-1219の承認者を指定しなければならない。
6.8. CyD operational desk PM(s) must, within 28 hours of receipt of the draft FD-1219 from CyWatch, per subsection 6.3.1.6. of this PD:  6.8. CyD運用デスクのPMは、本PDの6.3.1.6項に従い、CyWatchからFD-1219草案を受領してから28時間以内に、以下の措置を講じなければならない:
6.8.1. Review the incident information provided.  6.8.1. 提供されたインシデント情報を確認する。
6.8.2. Conduct additional record checks in FBI systems and information holdings of their operational desk, as appropriate, and amend question six of the draft FD-1219 to reflect additional findings of specific and credible national security or public safety concerns with the victim’s public filing of the cyber incident in the SEC’s Electronic Data Gathering, Analysis, and Retrieval (EDGAR) database.  6.8.2. 必要に応じて、FBIのシステムおよび当該運用デスクが保有する情報について追加の記録照会を行い、被害者がSECの電子データ収集・分析・検索(EDGAR)データベースにサイバーインシデントを公開したことに伴う、具体的かつ信憑性のある国家安全保障または公共の安全上の懸念に関する追加の所見を反映させるため、FD-1219草案の質問6を修正すること。
6.8.2.1. If a related national security or public safety equity in the investigative records of an FO is identified, the operational desk PM(s) must notify the appropriate FO points of contact (POC). The operational desk PM(s) must incorporate related FO feedback into the amendments of question six, as appropriate.  6.8.2.1. 担当事務所(FO)の捜査記録において、関連する国家安全保障または公共の安全上の懸念事項が特定された場合、運用デスクのPMは、適切なFOの連絡担当者(POC)に通知しなければならない。運用デスクのPMは、必要に応じて、関連するFOからのフィードバックを質問6の修正に反映させなければならない。
6.8.2.2. If the incident has been attributed to a specific threat actor, the operational desk PM(s) also must notify the appropriate Cyber Threat Team FO POCs. The operational desk PM(s) must incorporate related FO feedback resulting from this notification into the amendments of question six, as appropriate.  6.8.2.2. 当該インシデントが特定の脅威アクターによるものと特定された場合、オペレーショナルデスクのPMは、適切なサイバー脅威チームFOのPOCにも通知しなければならない。オペレーショナルデスクのPMは、この通知に基づくFOからのフィードバックを、必要に応じて質問6の修正に反映させなければならない。
7. References  7. 参考文献
• Cyber Division Policy Guide (1181PG) [Redacted]  • サイバー部門ポリシーガイド (1181PG) [一部非公開]
DOJ Material Cybersecurity Incident Delay Determinations (2023)  司法省(DOJ)重大サイバーセキュリティインシデント遅延決定(2023年) 
• FD-1219, “Federal Bureau of Investigation 8-K Cyber Delay Referral Form”  • FD-1219、「連邦捜査局(FBI)8-Kサイバー遅延照会フォーム」
• National Security Council Cyber Policy Coordination Committee, Framework for Improved Cyber Information Sharing and Interagency Coordination for Critical Infrastructure Engagements Regarding Cyber Threats and Incidents (2020)  • 国家安全保障会議サイバー政策調整委員会、『サイバー脅威およびインシデントに関する重要インフラへの関与における、サイバー情報共有および省庁間調整の改善のための枠組み』(2020年)
SEC’s Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (88 Fed. Reg. 51896)  SECのサイバーセキュリティ・リスク管理、戦略、ガバナンス、およびインシデント開示(88 Fed. Reg. 51896)
8. Definitions and Acronyms  8. 定義および略語 
8.1. Definitions  8.1. 定義
8.1.1. Federal Bureau of Investigation personnel: FBI employees, task force officers (TFO), task force members (TFM), task force participants (TFP), detailees, and contractors  8.1.1. 連邦捜査局(FBI)職員:FBI職員、タスクフォース担当官(TFO)、タスクフォースメンバー(TFM)、タスクフォース参加者(TFP)、出向者、および契約業者 
8.2. Acronyms  8.2. 略語

以下、略...

 

 


 

 

まるちゃんの情報セキュリティ気まぐれ日記

適用後...

・2025.07.30 SEC Cybersecurity の開示昨年からの比較...

・2024.10.25 米国 SEC Unisys、Checkpointほか、年次報告書における誤解を与えるセキュリティ開示で罰金を支払う...

・2024.07.19 SECのルールの改正によるサイバーセキュリティ開示 (20-F) 阿里巴巴 (Alibaba)、捜狐 (SOHU)、網易 (NETEASE) の場合

・2024.07.15 SECのルールの改正によるサイバーセキュリティ開示 (20-F) 三井住友ファイナンシャル、ORIX、みずほファイナンシャル、野村、タケダ、ソニー、トヨタ、ホンダの場合 (MUFGも追加)

・2024.07.14 SECのルールの改正によるサイバーセキュリティ開示 (10-K) IBM, Intel, Boeing, AMEX, Jonson & Johnson, Pfizer, Coca-Cola. McDonaldsの場合

 

採択後...
・2023.11.08 米国 SEC ソーラーウィンズ社と最高情報セキュリティ責任者を詐欺と内部統制の不備で告発 (2023.10.30)

・2023.09.24 米国 AICPA SECの新しいサイバーセキュリティ開示規則について経営者が知っておくべきこと

・2023.09.16 米国 カジノホテルグループのシーザーズがサイバー攻撃を受けて8-Kを公表していますね。。。

 

これが採択された段階...

・2023.07.28 米国 SEC 上場企業によるサイバーセキュリティリスクマネジメント、戦略、ガバナンス、インシデント開示に関する規則を採択



案をだしている段階...

・2022.03.11 米国 SEC 公開企業によるサイバーセキュリティのリスク管理、戦略、ガバナンス、インシデントの開示に関する規則案

その他...

・2020.11.07 民間刑務所施設、更生施設を経営している米国 GEO Groupがランサムウェアの攻撃を受けてForm 8-Kを提出していますね

・2020.07.11 US-GAOの報告書 サイバーセキュリティに関する10-Kの開示は一般的な内容が多くあまり参考にならないので追加の開示を希望している by 年金基金代表者

 

|

« 米国 一般調達局 FPKI統合テスト環境(CITE)参加ガイド (2026.04.21) | Main | 欧州 ENISA NIS360 NIS2 -重要度の高いNISセクターにおけるサイバーセキュリティの成熟度と重大度に関する最新の知見- »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 米国 一般調達局 FPKI統合テスト環境(CITE)参加ガイド (2026.04.21) | Main | 欧州 ENISA NIS360 NIS2 -重要度の高いNISセクターにおけるサイバーセキュリティの成熟度と重大度に関する最新の知見- »