欧州 ENISA NIS360 NIS2 -重要度の高いNISセクターにおけるサイバーセキュリティの成熟度と重大度に関する最新の知見-
こんにちは、丸山満彦です。
ENISAが、NIS360報告書を公表しています。NIS360報告書は、NIS2指令の附属書Iで特定された重要度の高い全セクターについて、サイバーセキュリティの成熟度と重要度を評価した報告書で、今年の報告書で3回目のとなりますね。
ポイント...
- AIの急速な進展:攻撃側・防御側の双方に影響。攻撃側の技術普及が先行し、検知・対応の時間枠短縮が求められる。
- サプライチェーン・第三者リスク:組織の信頼関係が連鎖し、単一の侵害がセクター全体に波及するシステムリスクが増大。
- 地政学的変動の激化:制裁、輸出規制、地域不安定化がサイバーセキュリティに直接影響。国家主体の攻撃やデジタル主権への関心が高まっている。
どこも同じような話になりますね...
● ENISA
・2026.05.28 ENISA NIS360
・[PDF] ENISA NIS360
目次...
| Executive Summary | エグゼクティブサマリー |
| 1. Cybersecurity maturity overview of NIS2 sectors of high criticality | 1. 重要度の高いNIS2セクターにおけるサイバーセキュリティ成熟度の概要 |
| 1.1 Assessing progress in maturity and criticality of sectors | 1.1 セクターの成熟度および重要度に関する進捗状況の評価 |
| 1.2 Cross-sector progress overview | 1.2 セクター横断的な進捗状況の概要 |
| 1.3 Emerging context | 1.3 新たな動向 |
| 2. Sector-by-sector cybersecurity maturity overview |
2. セクター別のサイバーセキュリティ成熟度概要 |
| 2.1 Energy | 2.1 エネルギー |
| 2.2 Digital infrastructure | 2.2 デジタルインフラ |
| 2.3 Transport | 2.3 運輸 |
| 2.4 Finance | 2.4 金融 |
| 2.5 Health | 2.5 医療 |
| 2.6 ICT service management | 2.6 ICTサービス管理 |
| 2.7 Public administrations | 2.7 行政 |
| 2.8 Space | 2.8 宇宙 |
| 2.9 Drinking and Waste water | 2.9 飲料水・廃水 |
| A Annex: Overview of maturity dimensions per sector | A 附属書:セクターごとの成熟度次元の概要 |
| A.1 Energy | A.1 エネルギー |
| A.2 Digital Infrastructure | A.2 デジタルインフラ |
| A.3 Transport | A.3 運輸 |
| A.4 Finance | A.4 金融 |
| A.5 Health | A.5 医療 |
| A.6 ICT service management | A.6 ICTサービス管理 |
| A.7 Public administrations | A.7 行政 |
| A.8 Space | A.8 宇宙 |
| A.9 Drinking water and Waste water | A.9 飲料水・廃水 |
| B Annex: NIS360 methodology | B 附属書:NIS360の方法論 |
| C Annex: Abbreviations and key legislation | C 附属書:略語および主要な法規制 |
エグゼクティブサマリー...
| Executive Summary | エグゼクティブサマリー |
| This edition of the ENISA NIS360 report is the third to assess the cybersecurity maturity and criticality of all sectors of high criticality as identified under Annex I of the NIS2 directive. The assessment covers the entire ecosystem of a sector, where each sector is understood to comprise relevant actors (i.e., national authorities, entities, EU bodies) and applicable rules (EU legislation). The assessment relies on a structured methodology developed and continuously refined by ENISA. This methodology, takes into account the structural and gradually evolving nature of sectoral cybersecurity maturity and criticality, and builds on evidence gathered over time from: organisations operating in sectors that are within the scope of NIS2 and national authorities supervising those organisations, but also EU-level data, to reflect our latest evidence-informed understanding of where each sector stands. | 本版ENISA NIS360報告書は、NIS2指令の附属書Iに基づき特定された、重要度の高い全セクターのサイバーセキュリティ成熟度および重要度を評価する3回目の報告書である。本評価はセクター全体のエコシステムを対象としており、各セクターは関連する主体(すなわち、国家当局、組織、EU機関)および適用される規則(EU法)から構成されると理解される。本評価は、ENISAが開発し継続的に改良を重ねてきた体系的な方法論に基づいている。この方法論は、セクターごとのサイバーセキュリティの成熟度および重要性の構造的かつ漸進的に変化する性質を考慮に入れ、NIS2の適用範囲内にあるセクターで事業を行う組織や、それらを監督する国家当局から長期間にわたり収集された証拠に加え、EUレベルのデータも活用することで、各セクターの現状に関する最新の証拠に基づく理解を反映している。 |
| Since the previous edition of this report, cybersecurity maturity across sectors of high criticality in the EU, has been steadily improving as organisations respond to evolving policy requirements and cyber threats they face. Banking, electricity and telecommunications remain the most mature and critical sectors, while three sectors, trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. Four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health. Several compounding factors contribute to these improvements, including developments in cybersecurity legislation, increased political attention, but also progress across specific maturity dimensions assessed. Overall, maturity is steadily improving across critical sectors, but progress still remains uneven both across and within sectors. A number of factors contribute to these variations including skill shortages, sector-specific characteristics and even organisational size. | 本報告書の前回版以降、EU内の重要度の高いセクターにおけるサイバーセキュリティの成熟度は、組織が進化する政策要件や直面するサイバー脅威に対応するにつれ、着実に向上している。銀行、電力、通信は依然として最も成熟度が高く重要なセクターである一方、信頼サービス、航空、金融市場インフラ(FMI)の3つのセクターは、高い成熟度帯へと移行した。ガス、道路、海運、医療の4セクターは、中程度の成熟度帯において成熟度を強化した。こうした改善には、サイバーセキュリティ関連法規の整備や政治的関心の高まりに加え、評価対象となった特定の成熟度指標における進展など、複数の複合的な要因が寄与している。全体として、重要セクター全体で成熟度は着実に向上しているが、セクター間およびセクター内においても進捗には依然としてばらつきが見られる。こうした差異には、スキル不足、セクター固有の特性、さらには組織規模など、多くの要因が影響している。 |
| Sector criticality, under the ENISA NIS360, is assessed based on factors such as its level of digitalisation, the socioeconomic impact of incidents affecting it, and its time-criticality i.e. how quickly the impact of incidents affecting it can be felt on the ground considering interconnections with other sectors. As these factors typically change gradually, criticality scores tend to remain relatively stable from year to year. For instance, sectors such as banking, electricity, aviation, space, and digital infrastructure (including telecommunications, cloud, and data centres) remain the most critical. Nevertheless, in this NIS360 edition, limited adjustments were introduced to the criticality dimension of certain sectors to better reflect the evolving socio-economic conditions and threat landscape. In particular, the criticality score for the space and railway sectors has been revised to reflect changes in how society or other sectors depend on them, and the extent to which they are being targeted. | ENISAのNIS360におけるセクターの重要度は、デジタル化のレベル、当該セクターに影響を及ぼすインシデントの社会経済的影響、および時間的緊急性(すなわち、他セクターとの相互接続性を考慮した際、当該セクターに影響を及ぼすインシデントの影響が現場でどの程度迅速に感じられるか)といった要因に基づいて評価される。これらの要因は通常、徐々に変化するため、重要度スコアは年ごとに比較的安定している傾向にある。例えば、銀行、電力、航空、宇宙、およびデジタルインフラ(通信、クラウド、データセンターを含む)といったセクターは、依然として最も重要度が高い。しかしながら、今回のNIS360版では、変化する社会経済状況や脅威の状況をより適切に反映させるため、特定のセクターの重要度評価に限定的な調整が加えられた。特に、宇宙および鉄道セクターの重要度スコアは、社会や他のセクターがこれらに依存する状況の変化、および標的とされる度合いを反映するよう改訂された。 |
| Combining and jointly interpreting the criticality and maturity dimensions helps identify mismatches between the two and helps define the risk zone. The risk zone includes sectors with lower-thanaverage maturity and criticality that exceeds their maturity. Its composition changes over time as overall maturity improves across sectors. This is one of the reasons why three sectors previously at the risk zone boundary - rail, drinking water, and waste water are now within the risk zone. The positive development is that the gas sector has started moving out of the risk zone. This shift is driven by improved information sharing, stronger collaboration, and better implementation of risk management measures that are to higher maturity. | 重大度と成熟度の両次元を組み合わせて解釈することで、両者の不一致を特定し、リスクゾーンを定義するのに役立つ。リスクゾーンには、平均以下の成熟度を持ち、かつその成熟度を上回る重要度を有するセクターが含まれる。その構成は、セクター全体で成熟度が向上するにつれて時間とともに変化する。これが、以前はリスクゾーンの境界線上にあった鉄道、飲料水・廃水の3つのセクターが、現在ではリスクゾーン内に位置している理由の一つである。前向きな進展として、ガスセクターがリスクゾーンから脱却し始めていることが挙げられる。この変化は、情報共有の改善、連携の強化、そしてより高い成熟度に向けたリスク管理措置の適切な実施によって推進されている。 |
| It is expected that, as factors such as cybersecurity legislation, perceived cyber risk and threat exposure, past experience, interdependencies, and ecosystem expectations continue to act as key drivers for both cybersecurity investment and preparedness efforts, more sectors will be moving out of the risk zone. | サイバーセキュリティ関連法規、認識されるサイバーリスクや脅威への曝露、過去の経験、相互依存関係、エコシステムの期待といった要因が、サイバーセキュリティへの投資と準備態勢の両方における主要な推進力として引き続き作用するにつれ、より多くのセクターがリスクゾーンから脱却していくものと予想される。 |
成熟度と重大度のマトリックス...
矢印で前回からの変化を示しています...
どの分野がやばいという図...
● まるちゃんの情報セキュリティ気まぐれ日記
昨年の...
・2025.03.09 欧州 ENISA NIS360 2024 (2025.03.05) 重要インフラのセキュリティの状況...
脅威...
・2025.11.09 欧州 ENISA セクター別脅威状況 - 公共行政 (2025.11.06)
・2025.10.05 ENISA 脅威状況 2025 (2025.10.01)
・2025.08.07 ENISA サイバーセキュリティ脅威状況の評価方法 (2025.08.01)
・2025.03.30 欧州ENISA 宇宙脅威状況 2025 (2025.03.26)
・2025.02.23 欧州 ENISA 脅威状況 (2023.01-2024.06):金融セクター
・2024.09.26 ENISA 脅威状況2024
・2023.12.09 ENISA 戦争と地政学がDoS攻撃に拍車をかけている - DoS攻撃に関する脅威状況
・2023.10.26 ENISA 脅威状況2023 - AIによる情報操作の台頭でEUの選挙がリスクにさらされる
・2023.09.20 ENISA 2030の脅威の展望 (2023.09.13)
・2023.03.22 ENISA 輸送セクターのサイバー脅威状況
・2022.12.14 ENISA 外国人による情報操作と干渉(FIMI)とサイバーセキュリティ - 脅威状況
・2022.11.08 ENISA 脅威状況 2022:不安定な地政学がサイバーセキュリティ脅威状況の傾向を揺るがす
・2022.08.01 ENISA ランサムウェアについての脅威状況
・2022.07.29 ENISA サイバーセキュリティ脅威ランドスケープの方法論 (2022.07.06) ENISA流サイバーインテリジェンスの方法論?
・2020.12.18 ENISA AI サイバーセキュリティのチャレンジ - AI脅威状況報告を公表していますね。
・2020.12.15 ENISA 5Gネットワークの脅威状況報告書のアップデート
・2020.10.21 ENISA Threat Landscape 2020 : サイバー脅威トップ15 サイバー攻撃はより高度化し、標的化が進み、対象も広範囲になり、検知もされにくくなる。。。
投資...
・2025.12.21 欧州 ENISA NIS投資報告書 2025 (2025.12.08)
・2024.11.25 欧州 ENISA NIS投資報告書 2024
・2023.11.18 ENISA EUにおけるサイバーセキュリティ投資 2023
・2022.11.25 ENISA EUにおけるサイバーセキュリティ投資 2022
・2021.11.26 ENISA NIS投資動向報告書2021 at 2021.11.17
« 米国 FBI SECへの報告要件 - サイバーインシデントの被害者に対するFBIの指針 | Main | 経済産業省 サプライチェーン強化に向けたセキュリティ対策評価制度(SCS評価制度)特設サイト (2026.05.29) »




Comments