« 英国 NCSCが開発した脆弱なディスプレイ接続を保護するプラグアンドプレイ型のデバイス「SilentGlass」 (2026.04.22) | Main | 英国 NCSC 各国のサイバー機関が、中国と関連する秘密ネットワークへの対策として新たな指針を共有 (2026.04.23) »

2026.05.03

米国 NIST IR 8259 Rev. 1 IoT製品製造事業者のための基礎的なサイバーセキュリティ活動 (2026.04.20)

こんにちは、丸山満彦です。

消費者向け製品は特にですが、IoT 製品のセキュリティは、顧客任せではなく メーカーが設計段階から責任を持って「securable」な状態を作り込むべきですよね...

キーボード叩いて運用でなんとかリカバリーできるところもあるので運用にまかせてしまったPCがデフォルトだと思われているかもしれないけど、普通はセキュアな状態で市場にだすのが当然ですよね...

とくに、運動エネルギーへの変換や、人間の体に直接作用をしてしまうようなデバイスについてはセキュアな状態での販売が当然ですよね...

ただ、すべてを製造事業者に責任を追わせると製品が使いづらくなったり、高価になってしまうこともあるので、顧客側も安全な利用の仕方ということを理解しようとすべきですよね...

製造事業者もセキュアな状態を技術的な機能だけで実装しようとせず、顧客のニーズを理解し、適切な手段を選んで、ライフサイクル全体でセキュアになるようにする。そして、顧客等への適切な情報提供を通じて、全体として安全に使われる環境を作り出すということが重要なんでしょうね...

で、NIST IR 8259r1は、IoT製品製造事業者が実施すべきセキュリティ活動を説明していますね...参考になると思います...

 

Activity 0: Prioritize Cybersecurity and Maintain Cybersecurity Posture  活動0:サイバーセキュリティを優先し、サイバーセキュリティ態勢を維持する 
Activity 1: Identify Expected Customers and Define Expected Use Cases  活動1:想定顧客の識別と想定ユースケースの定義 
Activity 2: Research Customer Cybersecurity Needs and Goals  活動2:顧客のサイバーセキュリティのニーズと目標を調査する 
Activity 3: Determine Appropriate Means to Support Customer Needs and Goals   活動3:顧客のニーズと目標を支援するための適切な手段を決定する  
Activity 4: Define IoT Product Cybersecurity Capabilities Based on Appropriate Means  活動4:適切な手段に基づくIoT製品のサイバーセキュリティ機能の定義 
Activity 5: Plan for Adequate Support of Customer Needs and Goals  活動5:顧客のニーズと目標を適切に支援するための計画 
Product Goes to Market  製品の市場投入 
Activity 6: On-Going Support of Product Cybersecurity through-out the Lifecyle  End-of-Life  活動6:ライフサイクル全体を通じた製品のサイバーセキュリティに対する継続的なサポート  サポート終了 
Activity 7: Define Approaches for Communicating to Customers  活動7:顧客へのコミュニケーション手法の定義 
Activity 8: Decide What to Communicate to Customers and How to Communicate It  活動8:顧客への伝達内容および伝達方法の決定 

 

 

● NIST - ITL

・2026.04.20 NIST IR 8259 Rev. 1 Foundational Cybersecurity Activities for IoT Product Manufacturers

 

NIST IR 8259 Rev. 1 Foundational Cybersecurity Activities for IoT Product Manufacturers NIST IR 8259 Rev. 1 IoT製品製造事業者のための基礎的なサイバーセキュリティ活動
Abstract 概要
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises. IoT製品には、顧客(組織や個人)がサイバーセキュリティリスクの緩和に活用できるサイバーセキュリティ機能が欠けている場合が多い。製造事業者は、必要なサイバーセキュリティ機能を提供し、顧客が必要とするサイバーセキュリティ関連情報を提供することで、IoT製品のセキュリティ性を向上させ、顧客を支援することができる。本刊行物は、製造事業者がIoT製品を顧客に販売する前に実施を検討すべき、サイバーセキュリティに関連する推奨活動を記述している。これらの基礎的なサイバーセキュリティ活動は、製造事業者が顧客が必要とするサイバーセキュリティ関連の取り組みを軽減するのに役立ち、ひいては侵害の発生率と深刻度を低減することができる。

 

・[PDF] IR.8259r1

20260501-94341

・[DOCX][PDF] 仮訳

 

Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
1.1. Purpose and Scope 1.1. 目的と範囲
1.2. Publication Structure 1.2. 出版物の構成
2. Background 2. 背景
2.1. Product Cybersecurity and System Cybersecurity 2.1. 製品のサイバーセキュリティとシステムのサイバーセキュリティ
2.2. Composition of IoT Products 2.2. IoT製品の構成
2.3. Entities in an IoT Product Ecosystem 2.3. IoT製品エコシステムにおける事業体
2.4. The Role of the Manufacturer in Cybersecurity 2.4. サイバーセキュリティにおける製造事業者の役割
2.5. IoT Product Customer Cybersecurity Needs and Goals 2.5. IoT製品の顧客のサイバーセキュリティ上のニーズと目標
2.6. Relationships between Needs and Goals, Capabilities, and Means 2.6. ニーズと目標、能力、および手段の関係
3. Manufacturer Activities Impacting the IoT Product Pre-Market Phase 3. IoT製品の市場投入前段階に影響を与える製造事業者の活動
3.1. Activity 0: Prioritize Cybersecurity and Maintain Cybersecurity Posture 3.1. 活動0:サイバーセキュリティの優先順位付けとサイバーセキュリティ態勢の維持
3.2. Activity 1: Identify Expected Customers and Define Expected Use Cases 3.2. 活動1:想定される顧客の識別と想定されるユースケースの定義
3.3. Activity 2: Research Customer Cybersecurity Needs and Goals 3.3. 活動2:顧客のサイバーセキュリティのニーズと目標の調査
3.4. Activity 3: Determine Appropriate Means to Support Customer Needs and Goals in the Context of the IoT Product 3.4. 活動3:IoT製品の文脈において顧客のニーズと目標を支援するための適切な手段を決定する
3.5. Activity 4: Define IoT Product Cybersecurity Capabilities Based on Appropriate Means 3.5. 活動4:適切な手段に基づくIoT製品のサイバーセキュリティ機能の定義
3.6. Activity 5: Plan for Adequate Support of Customer Needs and Goals 3.6. 活動5:顧客のニーズと目標に対する適切な支援の計画
4. Manufacturer Activities Impacting the IoT Product Post-Market Phase 4. IoT製品の市販後段階に影響を与える製造事業者の活動
4.1. Activity 6: On-Going Support of Product Cybersecurity throughout the Lifecycle and through End-of-Life 4.1. 活動6:ライフサイクル全体および製品寿命終了までの製品サイバーセキュリティの継続的支援
4.2. Activity 7: Define Approaches for Communicating to Customers 4.2. 活動7:顧客へのコミュニケーションアプローチの定義
4.3. Activity 8: Decide What to Communicate to Customers and How to Communicate It 4.3. 活動8:顧客に何を、どのように伝えるかを決定する
4.3.1. Cybersecurity Risk-Related Assumptions 4.3.1. サイバーセキュリティリスクに関する前提条件
4.3.2. Support and Lifespan Expectations 4.3.2. サポートおよびライフサイクルに関する期待
4.3.3. Product Composition and Capabilities 4.3.3. 製品の構成と機能
4.3.4. Software Updates 4.3.4. ソフトウェアの更新
4.3.5. Product Retirement Options 4.3.5. 製品の廃止に関する選択肢
4.3.6. Technical and Non-Technical Cybersecurity Capabilities 4.3.6. 技術的および非技術的なサイバーセキュリティ機能
5. Conclusion 5. 結論
References 参考文献
Appendix A. List of Abbreviations and Acronyms 附属書A. 略語および頭字語一覧
Appendix B. Glossary 附属書B. 用語集
Appendix C. Change Log 附属書C. 変更履歴

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
Manufacturers are creating an incredible variety and volume of internet-ready products and systems broadly known as the Internet of Things (IoT). Many of these IoT products and systems do not fit the standard definitions of information technology (IT) (e.g., smartphones, servers, laptops) that have been used as the basis for defining product cybersecurity capabilities.   製造事業者は、広く「モノのインターネット(IoT)」として知られる、インターネット対応製品やシステムを、驚くほど多種多様かつ大量に生み出している。これらのIoT製品やシステムの多くは、製品のサイバーセキュリティ能力を定義する基礎として用いられてきた情報技術(IT)の標準的な定義(例:スマートフォン、サーバー、ノートパソコン)には当てはまらない。  
The purpose of this publication is to give manufacturers recommendations for improving the securability of their IoT products. Securability means the IoT products offer product cybersecurity capabilities—cybersecurity features or functions that the IoT devices and other product components provide through their own technical means (i.e., hardware and software) or related non-technical services from the manufacturer (i.e., vulnerability disclosure programs). An IoT product that is resilient to attacks, supports forensic analysis following an incident, recovers quickly after an incident, keeps customer data confidential and free of tampering, develops a reputation of being trustworthy, etc. is one that customers can adopt and trust. Thus, investing in producing a secure IoT product contributes to the success of the IoT product in the market, increasing innovation, protecting the nation, and supporting individuals in their daily lives. Cybersecurity of an IoT product must begin in the product planning phase when the decision-makers are able to allocate resources towards modeling and prioritizing threats, then designing and implementing effective product cybersecurity capabilities that help address these threats. Additionally, allocating resources for post-market support of the product when it’s deployed in the field goes a long way to establishing a relationship of trust with the customer. Constantly evaluating the ever-changing threat landscape, investigating security incidents, and maintaining the IoT product’s ability to remain securable in the field all help the customer manage their cybersecurity risks while also enhancing the reputation of the IoT product and its manufacturer.   本出版物の目的は、製造事業者に対し、自社のIoT製品の「セキュラビリティ」を向上させるための提言を行うことにある。「セキュラビリティ」とは、IoT製品がサイバーセキュリティ機能を提供することを意味する。すなわち、IoTデバイスやその他の製品コンポーネントが、独自の技術的手段(ハードウェアおよびソフトウェア)や、製造事業者による関連する非技術的サービス(脆弱性開示プログラムなど)を通じて提供するサイバーセキュリティ機能や機能のことである。 攻撃に対してレジリエンスがあり、インシデント発生後のフォレンジック分析に対応し、インシデント発生後に迅速に復旧し、顧客データを機密保持し改ざんから守り、信頼できるという評判を築くことのできるIoT製品こそが、顧客が採用し信頼できる製品である。したがって、安全なIoT製品の製造に投資することは、市場におけるIoT製品の成功、イノベーションの促進、国家の防御、そして人々の日常生活の支援に寄与する。 IoT製品のサイバーセキュリティは、意思決定者がリソースを割り当てて脅威のモデリングと優先順位付けを行い、それらの脅威に対処するのに役立つ効果的な製品サイバーセキュリティ機能を設計・実装できる製品企画段階から始めなければならない。 さらに、製品が現場に展開された後の市場投入後のサポートにリソースを割り当てることは、顧客との信頼関係を築く上で極めて重要である。絶えず変化する脅威の状況を継続的に評価し、セキュリティインシデントを調査し、現場においてIoT製品のセキュリティ維持能力を保つことは、顧客がサイバーセキュリティリスクを管理するのを支援すると同時に、IoT製品とその製造事業者の評判を高めることにもつながる。  
This publication describes nine recommended foundational cybersecurity activities that manufacturers should consider performing to improve the securability of their IoT products. Six of the activities primarily impact decisions and actions performed by the manufacturer before a product is sent out for sale (pre-market), and the remaining three activities primarily impact decisions and actions performed by the manufacturer after product sale (post-market). Performing all activities can help manufacturers provide IoT products that better support the cybersecurity-related efforts needed by customers, which can reduce the prevalence and severity of IoT product compromises. These activities are intended to fit within a manufacturer’s existing development process and may already be achieved in whole or part by that existing process. They are presented sequentially and are mostly intended to be performed sequentially, but some activities and parts of activities may be able to be performed in parallel. Also, activities are not mapped to an organizational structure, and in practice these activities may touch on the roles and responsibilities of multiple individuals and departments within an IoT product manufacturer’s organization. This allows flexibility for organizations with different structures to adopt the activities and assign them appropriately within their organization. By the end of each activity, IoT product manufacturers will have an increasingly detailed and informed plan to ensure the IoT product they are developing is securable by customers.  本書では、IoT製品のセキュリティ性を改善するために、製造事業者が実施を検討すべき9つの推奨される基礎的なサイバーセキュリティ活動について説明する。そのうち6つの活動は、主に製品が販売される前(市場投入前)に製造事業者が行う意思決定や行動に影響し、残りの3つの活動は、主に製品販売後(市場投入後)に製造事業者が行う意思決定や行動に影響する。 すべての活動を実施することで、製造事業者は顧客が必要とするサイバーセキュリティ関連の取り組みをより適切に支援するIoT製品を提供できるようになり、IoT製品の侵害の発生率と深刻度を低減できる。これらの活動は、製造事業者の既存の開発プロセスに組み込むことを意図しており、その既存プロセスによってすでに全体または一部が達成されている可能性がある。活動は順序立てて提示されており、主に順次実施することを想定しているが、一部の活動や活動の一部については並行して実施できる場合もある。 また、活動は特定の組織構造に紐付けられておらず、実際には、IoT製品製造事業者の組織内における複数の個人や部門の役割と責任にまたがる場合がある。これにより、異なる組織構造を持つ組織でも、これらの活動を柔軟に採用し、組織内で適切に割り当てることが可能となる。各活動の終了時点において、IoT製品製造事業者は、開発中のIoT製品が顧客によってセキュリティを確保できるものであることを保証するための、より詳細かつ情報に基づいた計画を策定することになる。 

 

 

 

 


 

● まるちゃんの情報セキュリティ気まぐれ日記

ちょっと古いけどIoT関連NIST文書

・2022.05.19 NIST IoTセキュリティ関連の文書についてNISTのブログで簡単に説明されていますね。。。

 

SP 800-213, IR 8259,関連

・2025.05.16 米国 NIST IR 8259 Rev.1(初期公開ドラフト)IoT製品製造者のための基礎的サイバーセキュリティ活動の5年振りの改訂関係...IR 8572も...(2025.05.13)

・2021.11.30 NIST SP 800-213 連邦政府のためのIoTデバイスサイバーセキュリティ・ガイダンス:IoTデバイスのサイバーセキュリティ要件の確立、SP 800-213A 連邦政府のためのIoTデバイスサイバーセキュリティ・ガイダンス:IoTデバイス・サイバーセキュリティ要件カタログ


・2021.08.29 NISTIR 8259B IoT非技術的支援能力コアベースライン

・2020.12.17 NIST SP 800-213 (Draft) 連邦政府向け「 IoTデバイスサイバーセキュリティ要件の確立」、NISTIR 8259B、8259C、8259D

・2020.05.30 NIST IoT機器製造者向けセキュリティの実践資料 NISTIR 8259 Foundational Cybersecurity Activities for IoT Device Manufacturers, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline

 

 

直接は関係ないけど...サイバートラストマーク制度関連...

・2025.12.23 米国 FCC サイバートラストマーク関連文書 (2025.06.18)

・2024.09.13 米国 FCC IoTのためのサイバーセキュリティ・ラベリングFAQと管理者の申請プロセス (2024.09.10)

・2024.08.02 米国 FCC IoTのためのサイバーセキュリティ・ラベリング最終規則

・2024.03.20 米国 連邦通信委員会 (FCC) がIoTサイバーセキュリティ表示プログラム(サイバートラストマーク)の規則を採択 (2024.03.14)

・2023.07.19 米国 消費者向けIoT製品のセキュリティ認証制度、サイバートラスト・マーク (U.S. Cyber Trust Mark) を発表

|

« 英国 NCSCが開発した脆弱なディスプレイ接続を保護するプラグアンドプレイ型のデバイス「SilentGlass」 (2026.04.22) | Main | 英国 NCSC 各国のサイバー機関が、中国と関連する秘密ネットワークへの対策として新たな指針を共有 (2026.04.23) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 英国 NCSCが開発した脆弱なディスプレイ接続を保護するプラグアンドプレイ型のデバイス「SilentGlass」 (2026.04.22) | Main | 英国 NCSC 各国のサイバー機関が、中国と関連する秘密ネットワークへの対策として新たな指針を共有 (2026.04.23) »