米国NIST SP 800-172 Rev. 3 管理対象非機密情報の保護に関する強化されたセキュリティ要件、SP 800-172A Rev. 3 管理対象非機密情報(CUI)に対する強化されたセキュリティ要件の評価
こんにちは、丸山満彦です。
NISTがNIST SP 800-172 Rev. 3 管理対象非機密情報の保護に関する強化されたセキュリティ要件とその評価手法を規定したSP 800-172A Rev. 3 管理対象非機密情報(CUI)に対する強化されたセキュリティ要件の評価を公表していますね...国防総省のCMMIのレベル3はSP800-172の一部が含まれていますね...
SP800-172は連邦政府の管理対象非機密情報に対するセキュリティ要件を定めたSP800-171の強化セキュリティ版でよりセキュリティが要求される情報等に関するセキュリティ要件を定めたものですね。
SP800-172Aはその評価手法を規定したものとなります。SP800-171とSP800-171Aの関係と同じです。
● NIST
・2024.05.13 NIST SP 800-172 Rev. 3 Enhanced Security Requirements for Protecting Controlled Unclassified Information
| NIST SP 800-172 Rev. 3 Enhanced Security Requirements for Protecting Controlled Unclassified Information | NIST SP 800-172 Rev. 3 管理対象非機密情報の保護に関する強化されたセキュリティ要件 |
| Planning Note (05/13/2026): | 計画に関する注記(2026年5月13日): |
| The enhanced security requirements in SP 800-172r3 are available in multiple data formats. The PDF of SP 800-172r3 is the authoritative source of the enhanced security requirements. If there are any discrepancies noted in the content between the CPRT dataset, OSCAL dataset, and the SP 800-172r3 PDF, please contact sec-cert@nist.gov and refer to the PDF as the normative source. | SP 800-172r3 の強化されたセキュリティ要件は、複数のデータ形式で入手可能である。SP 800-172r3のPDFは、強化されたセキュリティ要件の正式な情報源である。CPRTデータセット、OSCALデータセット、およびSP 800-172r3のPDFの間で内容に不一致が見られる場合は、sec-cert@nist.gov までご連絡いただき、規範的な情報源としてPDFをご参照すること。 |
| Abstract | 概要 |
| The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with a set of recommended enhanced security requirements for providing additional protection to the confidentiality, integrity, and availability of CUI when it is resident in a nonfederal system and organization and associated with a critical program or high value asset (HVA). It is designed as a supplement to NIST Special Publication (SP) 800-171 to protect against advanced persistent threats (APTs). The security requirements apply to the components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components only when selected and required by federal agencies to manage risks to CUI. The enhanced security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations. There is no expectation that all of the enhanced security requirements will be selected by federal agencies. The decision to select a particular set of enhanced security requirements will be based on the mission and business needs of federal agencies and guided and informed by agencies’ ongoing risk assessments. | 非連邦システムおよび組織に保存されている管理対象非機密情報(CUI)の保護は、連邦機関にとって極めて重要であり、連邦政府がその重要な任務と機能を成功裏に遂行する能力に直接的な影響を及ぼす可能性がある。本刊行物は、非連邦システムおよび組織に保存され、かつ重要プログラムまたは高価値資産(HVA)に関連するCUIの機密性、完全性、および可用性をさらに保護するための、推奨される強化されたセキュリティ要件のセットを連邦機関に提供するものである。これは、高度持続的脅威(APT)から保護するために、NIST特別刊行物(SP)800-171の補足として設計されている。これらのセキュリティ要件は、CUIを処理、保存、または伝送する非連邦システムの構成要素、あるいはそのような構成要素に対する保護を提供する構成要素に適用されるが、それは連邦機関がCUIに対するリスクを管理するためにそれらを選択し、要求した場合に限られる。強化されたセキュリティ要件は、連邦機関と非連邦組織との間で締結された契約やその他の合意において、連邦機関が利用することを意図している。連邦機関がすべての強化されたセキュリティ要件を選択することが期待されているわけではない。特定の強化されたセキュリティ要件セットを選択する決定は、連邦機関の任務および業務上のニーズに基づき、かつ各機関の継続的なリスク評価によって導かれ、裏付けられるものである。 |
・[PDF] SP.800-172r3
| 1. Introduction | 1. 序論 |
| 1.1. Purpose and Applicability | 1.1. 目的および適用範囲 |
| 1.2. Organization of This Publication | 1.2. 本出版物の構成 |
| 2.The Fundamentals | 2.基本事項 |
| 2.1. Enhanced Security Requirement Assumptions | 2.1. 拡張セキュリティ要件の前提 |
| 2.2. Enhanced Security Requirement Development Methodology | 2.2. 拡張セキュリティ要件の開発方法論 |
| 3. The Requirements | 3. 要件 |
| 3.1. Access Control | 3.1. アクセス管理 |
| 3.2. Awareness and Training | 3.2. 意識向上およびトレーニング |
| 3.3. Audit and Accountability | 3.3. 監査と説明責任 |
| 3.4. Configuration Management | 3.4. 構成管理 |
| 3.5. Identification and Authentication | 3.5. 識別と認証 |
| 3.6. Incident Response | 3.6. インシデント対応 |
| 3.7. Maintenance | 3.7. 保守 |
| 3.8. Media Protection | 3.8. 媒体保護 |
| 3.9. Personnel Security | 3.9. 職員のセキュリティ |
| 3.10. Physical Protection | 3.10. 物理的保護 |
| 3.11. Risk Assessment | 3.11. リスクアセスメント |
| 3.12. Security Assessment and Monitoring | 3.12. セキュリティアセスメントおよび監視 |
| 3.13. System and Communications Protection | 3.13. システムおよび通信の保護 |
| 3.14. System and Information Integrity | 3.14. システムおよび情報の完全性 |
| 3.15. Planning | 3.15. 計画 |
| 3.16. System and Services Acquisition | 3.16. システムおよびサービスの調達 |
| 3.17. Supply Chain Risk Management | 3.17. サプライチェーンリスクマネジメント |
| References | 参考文献 |
| Appendix A. Acronyms | 附属書A. 略語 |
| Appendix B. Glossary | 附属書 B. 用語集 |
| Appendix C. Summary of Enhanced Security Requirements | 附属書C. 拡張セキュリティ要件の概要 |
| Appendix D. Adversary Effects | 附属書D. 攻撃者の影響 |
| Appendix E. Organization-Defined Parameters | 附属書 E. 組織定義パラメータ |
| Appendix F. Change Log | 附属書F. 変更履歴 |
・2026.05.13 NIST SP 800-172A Rev. 3 Assessing Enhanced Security Requirements for Controlled Unclassified Information
| NIST SP 800-172A Rev. 3 Assessing Enhanced Security Requirements for Controlled Unclassified Information | NIST SP 800-172A Rev. 3 管理対象非機密情報(CUI)に対する強化されたセキュリティ要件の評価 |
| Planning Note (05/13/2026): | 計画に関する注記(2026年5月13日): |
| The assessment procedures in SP 800-172Ar3 are available in multiple data formats. The PDF of SP 800-172Ar3 is the authoritative source of the assessment procedures. If there are any discrepancies noted in the content between the CPRT dataset, OSCAL dataset, and the SP 800-172Ar3 PDF, please contact sec-cert@nist.gov and refer to the PDF as the normative source. | SP 800-172Ar3 の評価手順は、複数のデータ形式で利用可能である。SP 800-172Ar3のPDFが、評価手順の正式な情報源となります。CPRTデータセット、OSCALデータセット、およびSP 800-172Ar3 PDFの内容間に不一致が見られる場合は、sec-cert@nist.gov までご連絡いただき、規範的な情報源としてPDFをご参照すること。 |
| Abstract | 概要 |
| The protection of controlled unclassified information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with assessment procedures for the enhanced security requirements in NIST SP 800-172. The assessment procedures are flexible and can be tailored to the needs of federal agencies and assessors. Security requirement assessments can be conducted as (1) self-assessments; (2) independent, third-party assessments; or (3) government-sponsored assessments. The assessments can be conducted with varying degrees of rigor based on federal agency-defined depth and coverage attributes. The findings and evidence produced during the assessments can be used to facilitate risk-based decisions by organizations related to the security requirements. | 非連邦システムおよび組織に存在する管理対象非機密情報(CUI)の保護は、連邦機関にとって極めて重要であり、連邦政府が不可欠な任務や機能を円滑に遂行する能力に直接的な影響を及ぼす可能性がある。本刊行物は、NIST SP 800-172 に規定された強化されたセキュリティ要件に関する評価手順を連邦機関に提供します。これらの評価手順は柔軟性があり、連邦機関や評価者のニーズに合わせて調整することが可能である。セキュリティ要件の評価は、(1) 自己評価、(2) 独立した第三者による評価、または (3) 政府主導の評価として実施することができる。評価は、連邦機関が定義した深度および対象範囲の属性に基づき、様々な厳格度で実施することが可能である。評価の過程で得られた所見および証拠は、セキュリティ要件に関連する組織によるリスクベースの意思決定を促進するために活用できる。 |
・[PDF] SP.800-172Ar3
| 1. Introduction | 1. 序論 |
| 1.1 Purpose and Applicability | 1.1 目的および適用範囲 |
| 1.2 Organization of This Publication | 1.2 本出版物の構成 |
| 2. The Fundamentals | 2. 基礎 |
| 2.1. Assessment Procedures | 2.1. アセスメント手順 |
| 2.2. Assurance Cases | 2.2. 保証ケース |
| 3. The Procedures | 3. 手順 |
| 3.1. Access Control | 3.1. アクセス管理 |
| 3.2. Awareness and Training | 3.2. 意識向上およびトレーニング |
| 3.3. Audit and Accountability | 3.3. 監査と説明責任 |
| 3.4. Configuration Management | 3.4. 構成管理 |
| 3.5. Identification and Authentication | 3.5. 識別と認証 |
| 3.6. Incident Response | 3.6. インシデント対応 |
| 3.7. Maintenance | 3.7. 保守 |
| 3.8. Media Protection | 3.8. 媒体保護 |
| 3.9. Personnel Security | 3.9. 職員のセキュリティ |
| 3.10. Physical Protection | 3.10. 物理的保護 |
| 3.11. Risk Assessment | 3.11. リスクアセスメント |
| 3.12. Security Assessment and Monitoring | 3.12. セキュリティアセスメントおよび監視 |
| 3.13. System and Communications Protection | 3.13. システムおよび通信の保護 |
| 3.14. System and Information Integrity | 3.14. システムおよび情報の完全性 |
| 3.15. Planning | 3.15. 計画 |
| 3.16. System and Services Acquisition | 3.16. システムおよびサービスの調達 |
| 3.17. Supply Chain Risk Management | 3.17. サプライチェーンリスクマネジメント |
| References | 参考文献 |
| Appendix A. Acronyms | 附属書A. 略語 |
| Appendix B. Glossary | 附属書B. 用語集 |
| Appendix C. Summary of Enhanced Security Requirements | 附属書C. 拡張セキュリティ要件の概要 |
| Appendix D. Security Requirement Assessments | 附属書D. セキュリティ要件のアセスメント |
| D.1. Preparing for Assessments | D.1. アセスメントの準備 |
| D.2. Developing Assessment Plans | D.2. アセスメント計画の策定 |
| D.3. Conducting Assessments | D.3. アセスメントの実施 |
| D.4. Analyzing, Documenting, and Reporting Assessment Results | D.4. アセスメント結果の分析、文書化、および報告 |
| Appendix E. Organization-Defined Parameters | 附属書E. 組織が定義するパラメータ |
| Appendix F. Change Log | 附属書F. 変更履歴 |
« 内閣官房 AI 性能の高度化を踏まえたサイバーセキュリティ対策の強化について (2026.05.18) | Main | 米国 NIST IR 8610 NISTポスト量子暗号標準化プロセスにおける追加デジタル署名スキームの第2ラウンドに関する進捗報告書 (2026.05.14) »


Comments