米国 NIST SP 800-70 第5版 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドライン (2026.05.08)
こんにちは、丸山満彦です。
NISTが、SP 800-70 Rev. 5 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドラインを公表していますね...
SP 800-37は、「権威あるセキュリティ設定チェックリストを一元化し、自動化・標準化を通じて、組織がリスクベースにシステムを安全構成できる基盤」を提供する、NIST主導の国家プログラムという感じですかね...
もともとIT 製品のデフォルト設定が脆弱である(機能性と相互運用性を優先する必要もあるため)問題があり、セキュアにするための実装チェックリストが必要であるが、ベンダーの任せていると項目や品質のばらつきが生じ、運用しにくいこと、また最新版がどれか分かりにくくなるなどの問題もあり、信頼できる中央レポジトリを作ろうという話になり、作成されているように思います。
そして、連邦政府は、調達するIT製品に対して共通セキュリティ構成チェックリストの使用を義務化した(連邦調達要件(FAR 39.101(Federal Acquisition Regulation 39.101)))。
でこれをセキュリティの自動化の流れもあり、機械可読な形式(SCAP)に統一しています...
SP 800‑70 は、NCPに準拠した “セキュリティ構成チェックリスト” を作成・公開・維持するための公式ガイドということになります...
● NIST - ITL
| NIST SP 800-70 Rev. 5 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers | NIST SP 800-70 第5版 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドライン |
| Abstract | 概要 |
| A security configuration checklist is a document that contains instructions, procedures, or machine-readable and executable content to configure an IT product to a specific risk posture for an operational environment, verify that the product has been configured properly, identify unauthorized configuration changes to the product, and/or produce artifacts that show the security posture of the product. Using these checklists can minimize the attack surface, reduce vulnerabilities, lessen the impact of successful attacks, and identify changes that might otherwise go undetected. NIST established the National Checklist Program (NCP) to facilitate the generation of security checklists from authoritative sources, centralize the location of checklists, and make checklists broadly accessible. This publication explains how to use the NCP to find and retrieve checklists and describes the policies, procedures, and general requirements for participation in the NCP. | セキュリティ構成チェックリストとは、運用環境における特定のリスク態勢に合わせてIT製品を構成し、製品が適切に構成されていることを検証し、製品への不正な構成変更を識別し、および/または製品のセキュリティ態勢を示す成果物を作成するための、指示、手順、あるいは機械可読かつ実行可能なコンテンツを含む文書である。これらのチェックリストを使用することで、攻撃対象領域を最小限に抑え、脆弱性を低減し、攻撃が成功した場合の影響を軽減し、そうでなければ検出されなかったかもしれない変更を識別することができる。NISTは、信頼できる情報源からのセキュリティチェックリストの作成を促進し、チェックリストの保管場所を一元化し、チェックリストを広く利用可能にするために、National Checklist Program(NCP)を設立した。本書は、NCPを利用してチェックリストを検索・取得する方法を説明するとともに、NCPへの参加に関する方針、手順、および一般的な要件について記述している。 |
・[PDF] SP.800-70r5
・[DOCX][PDF] 仮訳
目次...
| Executive Summary | エグゼクティブサマリー |
| 1. Introduction | 1. 序論 |
| 1.1. Purpose and Scope | 1.1. 目的と範囲 |
| 1.2. Document Organization | 1.2. 文書の構成 |
| 2. NIST National Checklist Program | 2. NIST 国家チェックリストプログラム |
| 2.1. Overview of the NCP | 2.1. NCP の概要 |
| 2.2. Security Configuration Checklists | 2.2. セキュリティ構成チェックリスト |
| 2.3. Benefits of Using Security Checklists | 2.3. セキュリティチェックリストの利用メリット |
| 2.4. Additional Considerations | 2.4. その他の考慮事項 |
| 2.4.1. Mapping and Acquisition Considerations | 2.4.1. マッピングおよび導入に関する考慮事項 |
| 2.4.2. Selecting Checklists | 2.4.2. チェックリストの選定 |
| 2.4.3. Checklist Considerations | 2.4.3. チェックリストに関する考慮事項 |
| 2.5. Types of Checklists Listed by NCP | 2.5. NCP に掲載されているチェックリストの種類 |
| 3. Operational Environments for Checklists | 3. チェックリストの運用環境 |
| 3.1. Stand-Alone Environment | 3.1. スタンドアロン環境 |
| 3.2. Managed Environment (Enterprise) | 3.2. 管理環境(エンタープライズ) |
| 3.3. Custom Environments | 3.3. カスタム環境 |
| 3.3.1. Specialized Security-Limited Functionality Environment | 3.3.1. 特殊セキュリティ・機能制限環境(SSLF) |
| 3.3.2. Legacy Environment | 3.3.2. レガシー環境( ) |
| 4. Checklist Usage | 4. チェックリストの使用方法 |
| 4.1. Determining Local Requirements | 4.1. 組織固有の要件の決定 |
| 4.2. Browsing and Retrieving Checklists | 4.2. チェックリストの閲覧と取得 |
| 4.3. Reviewing, Customizing, Documenting, and Testing Checklists | 4.3. チェックリストの確認、カスタマイズ、文書化、およびテスト |
| 4.4. Applying Checklists to IT Products | 4.4. IT製品へのチェックリストの適用 |
| 4.5. Providing Feedback on Checklists | 4.5. チェックリストへのフィードバックの提供 |
| 5. Checklist Development | 5. チェックリストの開発 |
| 5.1. Developer Steps for Creating, Testing, and Submitting Checklists | 5.1. チェックリストの作成、テスト、および提出に関する開発者の手順 |
| 5.2. Initial Checklist Development | 5.2. 初期チェックリストの開発 |
| 5.3. Checklist Testing | 5.3. チェックリストのテスト |
| 5.4. Checklist Documented | 5.4. 文書化されたチェックリスト |
| 5.5. Checklist Submitted to NIST | 5.5. NISTに提出するチェックリスト |
| 5.6. NIST Steps for Reviewing and Finalizing Checklists for Publication | 5.6. 公開用チェックリストの審査および確定に関するNISTの手順 |
| 5.7. NIST Screening of the Checklist Package | 5.7. チェックリストパッケージのNISTによる審査 |
| 5.8. Public Review and Feedback for the Candidate Checklist | 5.8. 候補チェックリストに対する公開レビューとフィードバック |
| 5.9. Final Listing on Checklist Repository | 5.9. チェックリストリポジトリへの最終掲載 |
| 5.10. Checklist Maintenance and Archival | 5.10. チェックリストの保守およびアーカイブ |
| References | 参考文献 |
| Appendix A. Checklist Program Operational Procedures | 附属書A. チェックリストプログラム運用手順 |
| A.1. Overview and General Considerations | A.1. 概要および一般的な考慮事項 |
| A.2. Checklist Submission and Screening | A.2. チェックリストの提出とスクリーニング |
| A.3. Candidate Checklist Public Review | A.3. 候補チェックリストの公開レビュー |
| A.4. Final Checklist Listing | A.4. 最終チェックリストの掲載( ) |
| A.5. Final Checklist Update, Archival, and Delisting | A.5. 最終チェックリストの更新、アーカイブ、およびリストからの削除 |
| A.6. Record Keeping | A.6. 記録の保管 |
| Appendix B. Participation and Logo Usage Agreement Form | 附属書B. 参加およびロゴ使用同意書 |
| Appendix C. Automating NIST CSF 2.0 | 附属書C. NIST CSF 2.0の自動化 |
| C.1. How the Path Connects Policy to Automation | C.1. ポリシーと自動化を結びつける経路 |
| C.2. Implementation and Traceability | C.2. 実装とトレーサビリティ |
| C.3. Checklist Development Guidance | C.3. チェックリスト作成ガイダンス |
| C.4. Operational Environment Tailoring and Considerations | C.4. 運用環境への適応と考慮事項 |
| C.5. Checklist Submission and Maintenance | C.5. チェックリストの提出と保守 |
| C.6. Appendix References | C.6. 附属書の参考文献 |
| Appendix D. List of Symbols, Abbreviations, and Acronyms | 附属書 D. 記号、略語、頭字語の一覧 |
| Appendix E. Glossary | 附属書E. 用語集 |
| Appendix F. Change Log | 附属書F. 変更履歴 |
エグゼクティブサマリー...
| Executive Summary | エグゼクティブサマリー |
| A security configuration checklist (also called a lockdown, hardening guide, or benchmark) is a series of instructions or procedures for securely configuring an IT product to a particular risk tolerance for an operational environment, verifying that the product has been configured properly, and/or identifying unauthorized changes to the product. The checklist may be for a commercial, open-source, or government-off-the-shelf (GOTS) IT product. | セキュリティ構成チェックリスト(ロックダウン、強化ガイド、またはベンチマークとも呼ばれる)とは、運用環境における特定のリスク許容度に合わせてIT製品を安全に構成し、製品が適切に構成されていることを確認し、および/または製品への不正な変更を識別するための一連の指示または手順である。このチェックリストは、商用、オープンソース、または政府調達既製品(GOTS)のIT製品を対象とする場合がある。 |
| Checklists can comprise a mix of templates, automated scripts, patch information, Extensible Markup Language (XML) files, and other procedures. Typically, checklists are created by IT vendors for their own products; however, checklists are also created by other organizations, such as academia, consortia, and government agencies. The use of well-written, standardized checklists can markedly reduce the attack surface and vulnerability exposure of IT products. | チェックリストは、テンプレート、自動化スクリプト、パッチ情報、XML(Extensible Markup Language)ファイル、その他の手順などを組み合わせて構成されることがある。通常、チェックリストはITベンダーが自社の製品向けに作成するが、学術機関、コンソーシアム、政府機関などの他の組織によって作成されることもある。適切に作成された標準化されたチェックリストを使用することで、IT製品の攻撃対象領域や脆弱性の露出を大幅に低減できる。 |
| NIST maintains the National Checklist Repository, a publicly available resource of security configuration checklists for IT products. The repository, [web], contains metadata describing each checklist and links to the website where a checklist is hosted. Having a centralized checklist repository makes it easier for organizations to find current, authoritative versions of security checklists and to determine which ones best meet their needs. | NISTは、IT製品向けのセキュリティ構成チェックリストを公開しているリソースである「National Checklist Repository」を管理している。このリポジトリ([web] )には、各チェックリストを説明するメタデータと、チェックリストがホストされているウェブサイトへのリンクが含まれている。チェックリストのリポジトリを一元化することで、組織は最新かつ信頼性の高いセキュリティチェックリストを容易に見つけ、自組織のニーズに最も適したものを判断できるようになる。 |
| This document is intended for users and developers of security configuration. For checklist users, this document makes recommendations on how they should select checklists from the NIST National Checklist Repository, evaluate and test checklists, and apply them to IT products. For checklist developers, this document sets forth the policies, procedures, and general requirements for participation in the NIST National Checklist Program (NCP). | 本文書は、セキュリティ設定のユーザーおよび開発者を対象としている。チェックリストのユーザーに対しては、NIST National Checklist Repositoryからチェックリストを選択し、評価・テストを行い、IT製品に適用する方法について推奨事項を示す。チェックリストの開発者に対しては、NIST National Checklist Program(NCP)への参加に関する方針、手順、および一般的な要件を定める。 |
| Major recommendations made in this document for checklist users and developers include the following: | 本文書において、チェックリストの利用者および開発者に対して提示される主な推奨事項は以下の通りである: |
| • Organizations should apply checklists to operating systems and applications to reduce the number of weaknesses that can be exploited and to lessen the impact of security breaches, if they occur. | • 組織は、悪用される可能性のある脆弱性の数を減らし、万一セキュリティ侵害が発生した場合の影響を軽減するために、オペレーティングシステムやアプリケーションにチェックリストを適用すべきである。 |
| • When selecting checklists, users should carefully consider each checklist’s degree of automation, source, use of standards, and other relevant characteristics. | • チェックリストを選択する際、利用者は各チェックリストの自動化の程度、出典、標準規格の採用状況、およびその他の関連する特性を慎重に検討すべきである。 |
| • Checklist users should consider their operational environments when selecting checklists and should customize and test checklists in a non-production environment before applying them to production systems. | • チェックリストの利用者は、チェックリストを選定する際に自組織の運用環境を考慮し、本番システムに適用する前に、非本番環境でチェックリストをカスタマイズし、テストを行うべきである。 |
| • Checklist creators are encouraged to adopt a “catalog of controls” approach for products to facilitate custom checklist reuse. | • チェックリストの作成者は、カスタムチェックリストの再利用を容易にするため、製品に対して「制御カタログ」アプローチを採用することが推奨される。 |
| • IT product vendors are strongly encouraged to develop security configuration checklists for their products and contribute them to the NIST National Checklist Repository. | • IT 製品ベンダーは、自社製品向けのセキュリティ設定チェックリストを作成し、NIST 国家チェックリスト・リポジトリに提供することが強く推奨される。 |
| • Checklists should be incorporated into continuous monitoring and configuration results and deviation monitoring used in automated data feeds for near real-time posture checks. | • チェックリストは、継続的な監視および設定結果、ならびにほぼリアルタイムのセキュリティ態勢チェックのための自動データフィードで使用される逸脱監視に組み込まれるべきである。 |
国家チェックリストプログラム
・2017.02.15 National Checklist Program NCP
チェックリストのレポジトリ...
全部で883のチェックリストがあります(2026.05.14確認時)
例えば、MacOSOS (Tahoe) 26.0.0を選んだ画面...
でマッチしたのが、
https://ncp.nist.gov/repository?product=Apple+macOS+%28Tahoe%29+26.0.0&sortBy=modifiedDate%7Cdesc
上の方は、米国国防総省(DOD)の情報システムのセキュリティを向上させるためのツールとして公開されているもののようです。
で、これの下の方のリンクをクリックすると
・2025.09.17 Tahoe Guidance Revision 1.0 Checklist Details
ダウンロード
・・[ZIP] Download ZIP - Tahoe Guidance, Revision 1.0
ダウンロードして内容を確認してみてくださいませ。充実した内容となっております...
こんな感じでファイルが格納されています...
例えば、
SP800-53
・800-53r5_high.html (downloaded)
国家安全保障システム委員会 (Committee on National Security Systems; CNSS) 用のCNSSI-1253チェックリスト
・CNSSI - 1253_high.html (downloaded)
● Github
● まるちゃんの情報セキュリティ気まぐれ日記
・2025.12.14 米国 NIST SP 800-70 第5版 (初期公開ドラフト) IT製品向け国家チェックリストプログラム:チェックリスト利用者および開発者向けガイドライン
« 米国 NIST IR 8323 Rev. 2(初期ドラフト) 基礎的PNTプロファイル:測位・航法・計時(PNT)サービスの責任ある利用に向けたサイバーセキュリティ・フレームワークの適用 (2026.05.06) | Main | 金融庁 「AI脅威に対する金融分野のサイバーセキュリティ対策強化に関する官民連携会議」の作業部会の開催 (2026.05.14) »






Comments