« 米国 大統領令 先進的人工知能(AI)のイノベーションとセキュリティの推進 (2026.06.02) | Main | 米国 NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ (2026.05.21) »

2026.06.04

米国 NIST IR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)(2026.05.19)

こんにちは、丸山満彦です。

NISTがIR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)を公表し、意見募集をしていますね...

現在のシステムは複雑になり、システムを構成するソフトウェアもまたサプライチェーンに依存し、複雑になっている。財弱性管理を含む、ソフトウェア管理の重要性が増している一方で、ソフトウェア資産管理が適切に行えなくなっている。

ということで、連邦政府むけにブロックチェーン技術を活用したソフトウェア資産管理の概念モデル「BloSS@M」を提案しているのがこの文書ということですかね...

このBloSS@Mは、各連邦政府機関が個別に調達・ライセンス管理を行うのではなく、ブロックチェーンを用いてソフトウェアライセンスを共有資産として管理・再配分する「ソフトウェアリースサービス」モデルという感じですかね...

で、パーミッションドブロックチェーン、OSCAL、SWID、MITREフレームワーク等を統合し、

(1) 資産構成の機械可読な可視化と、脆弱性・脅威・ライセンス情報の自動関連付け

(2) 参加組織間でのソフトウェアライセンスの共有・再配分による調達効率化とコスト削減

(3) OSCALを用いた継続的評価(cATO)による、動的環境下でのリスクベース承認の実現

ということを考えているようで、継続的な運用(OSCALとの連携を含め)を非常に意識していると思います。また、調達時における類似製品の価格比較等も可能となるようにし、調達の効率化、コスト削減にも寄与しようとしているようです。

 

ブロックチェーン技術を使うメリットは、十分な信頼関係が成立していない環境においても共通の記録を維持し、資産情報を検証可能な状態で共有できることですかね...

一方、厳格なアクセス制御や(OSCALを利用した)証拠管理が必要であり、複雑な運用というのが実装にむけたチャレンジという感じですかね...

 

NIST - ITL

・2026.05.19 NIST IR 8500A (Initial Public Draft) Blockchain-Based Secure Software Assets Management (BloSS@M)

 

NIST IR 8500A (Initial Public Draft) Blockchain-Based Secure Software Assets Management (BloSS@M) NIST IR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)
Announcement お知らせ
NIST Internal Report (IR) 8500A ipd (initial public draft), Blockchain-Based Secure Software Assets Management (BloSS@M), outlines a modernized conceptual approach for transforming how software assets are acquired, tracked, and secured across an interagency ecosystem. NIST内部報告書(IR)8500A ipd(初期ドラフト)『ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)』は、省庁間エコシステム全体におけるソフトウェア資産の取得、追跡、および保護の方法を変革するための、近代化された概念的アプローチを概説するものである。
The conceptual approach for BloSS@M was developed in consideration of federal asset inventory and management requirements — including OMB Circular A-130 and OMB M-13-13 — as well as NIST SP 800-37 and SP 800-53 guidelines. BloSS@M establishes a shared infrastructure for software acquisition that promotes asset reuse, eliminates duplicative procurement, and strengthens supply chain security at scale. Its key capabilities include: BloSS@Mの概念的アプローチは、OMB Circular A-130やOMB M-13-13を含む連邦資産の棚卸しおよび管理要件、ならびにNIST SP 800-37およびSP 800-53のガイドラインを考慮して策定された。BloSS@Mは、資産の再利用を促進し、重複した調達を排除し、大規模なサプライチェーンのセキュリティを強化する、ソフトウェア調達のための共有インフラを確立する。その主な機能は以下の通りだ:
Federal purchasing power: A consolidated model that reduces redundant spending and increases collective leverage with vendors through government-wide aggregation  連邦政府の購買力:政府全体での集約を通じて、重複した支出を削減し、プロバイダに対する集団的な交渉力を高める統合モデル
Immutable life cycle tracking: Utilizes blockchain’s tamper-resistance to provide a verifiable, continuous record of asset provenance from acquisition to retirement       改ざん不可能なライフサイクル追跡:ブロックチェーンの改ざん耐性を活用し、取得から廃棄に至るまでの資産の来歴証明に関する検証可能な継続的な記録を提供する      
Automated vulnerability management: Real-time integration with the National Vulnerability Database (NVD) to continuously surface newly disclosed vulnerabilities associated with deployed assets        自動化された脆弱性管理:National Vulnerability Database(NVD)とのリアルタイム統合により、導入済み資産に関連する新たに公開された脆弱性を継続的に特定する
Machine-processable compliance: Leverages the Open Security Controls Assessment Language (OSCAL) to enable automated risk assessments, continuous monitoring, and scalable life cycle management across heterogeneous environments 機械処理可能なコンプライアンス:Open Security Controls Assessment Language(OSCAL)を活用し、異種環境全体での自動リスクアセスメント、継続的なモニタリング、およびスケーラブルなライフサイクル管理を実現する
While BloSS@M is optimized for software, where end-to-end automation is most achievable, the approach is architected to support hardware assets when integrated with appropriate physical delivery and retrieval mechanisms. BloSS@Mは、エンドツーエンドの自動化が最も実現しやすいソフトウェア向けに最適化されているが、適切な物理的な配送・回収メカニズムと統合することで、ハードウェア資産もサポートできるよう設計されている。
Abstract 概要
The report proposes a conceptual aggregation model for software acquisitions. The proposed approach relies on the immutability and auditability of blockchain technology. The model also enables automated, dynamic queries to the National Vulnerability Database (NVD) to continuously identify newly disclosed vulnerabilities associated with leased software assets. In parallel, the digitization of asset-level security and compliance information using the Open Security Controls Assessment Language (OSCAL) supports machine-readable and tool-consumable risk assessment, continuous monitoring, and life cycle-based risk management workflows. This proposed approach could be utilized for federal software acquisition to enable interagency sharing, reuse, and lifecycle management of software assets. It also has the potential to significantly increase collective purchasing power, reduce duplicative procurements, and strengthen supply chain security and IT asset management practices. 本報告書は、ソフトウェア調達のための概念的な集約モデルを提案する。提案されたアプローチは、ブロックチェーン技術の不変性と監査可能性に依存している。また、このモデルは、National Vulnerability Database(NVD)への自動的かつ動的なクエリを可能にし、リースされたソフトウェア資産に関連する新たに公開された脆弱性を継続的に識別する。並行して、Open Security Controls Assessment Language(OSCAL)を用いた資産レベルのセキュリティおよびコンプライアンス情報のデジタル化は、機械可読かつツールで処理可能なリスクアセスメント、継続的監視、およびライフサイクルベースのリスクマネジメントワークフローを支援する。この提案されたアプローチは、連邦政府のソフトウェア調達において、ソフトウェア資産の省庁間での共有、再利用、およびライフサイクル管理を可能にするために活用できる。また、集合的な購買力を大幅に高め、重複した調達を減らし、サプライチェーンのセキュリティおよびIT資産管理の実践を強化する可能性も秘めている。

 

 

・[PDF] IR.8500A.ipd

20260602-154550

 

目次...

1. Introduction 1. 序論
2. BloSS@M: The Proposed Solution 2. BloSS@M:提案されるソリューション
2.1. BloSS@M Capabilities 2.1. BloSS@Mの機能
2.1.1. Operational Capabilities 2.1.1. 運用機能
2.1.2. Technical Capabilities 2.1.2. 技術的機能
2.2. Blossom Members ATO 2.2. BlossomメンバーのATO
3. Leveraged Technologies 3. 活用技術
3.1. Blockchain and Next Generation Access Control. 3.1. ブロックチェーンと次世代アクセス管理
3.1.1. Permissioned Blockchain 3.1.1. 許可型ブロックチェーン
3.1.2. Next Generation Access Control 3.1.2. 次世代アクセス管理
3.2. Open Security Controls Assessment Language 3.2. オープン・セキュリティ・コントロールアセスメント言語
3.3. SWID for Assets Traceability 3.3. アセットのトレーサビリティのためのSWID
3.4. Asset Security 3.4. アセットのセキュリティ
3.4.1. Secure Configuration and Controls Satisfaction With OSCAL 3.4.1. OSCALを用いたセキュアな構成と制御の適合性
3.4.2. NVD and Assets Vulnerabilities .. 3.4.2. NVDとアセットの脆弱性 ..
3.4.3. Leveraging MITRE ATT&CK and D3FEND for Software Asset Resilience Assessment 3.4.3. ソフトウェア・アセットのレジリエンスアセスメントにおけるMITRE ATT&CKおよびD3FENDの活用
4. Technologies Integration Into Blossom. 4. Blossomへの技術統合
4.1. Information Access Control in BloSS@M 4.1. BloSS@Mにおける情報アクセス管理
4.2. Onboarding Process 4.2. オンボーディングプロセス
4.2.1. OSCAL Support for cATO 4.2.1. cATOに対するOSCALのサポート
5. Use-Case-Driven Walkthrough: End-to-End Application of BloSS@M 5. ユースケース主導のウォークスルー:BloSS@Mのエンドツーエンド適用
5.1. Use Case Overview. 5.1. ユースケースの概要
5.2. Asset Discovery and Initial Filtering. 5.2. アセットの発見と初期フィルタリング
5.3. Cost and Leasing Evaluation 5.3. コストおよびリースアセスメント
5.4. Security Configuration and Control Review 5.4. セキュリティ構成および制御のレビュー
5.5. Vulnerability and Threat Analysis 5.5. 脆弱性および脅威の分析
5.6. Al-Assisted Provisional Assessment. 5.6. AIを活用した暫定アセスメント
5.7. Selection and Ongoing Monitoring.. 5.7. 選定および継続的なモニタリング
6. BloSS@M Benefits 6. BloSS@Mのメリット
References 参考文献

 

 

 

 

 

|

« 米国 大統領令 先進的人工知能(AI)のイノベーションとセキュリティの推進 (2026.06.02) | Main | 米国 NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ (2026.05.21) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 米国 大統領令 先進的人工知能(AI)のイノベーションとセキュリティの推進 (2026.06.02) | Main | 米国 NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ (2026.05.21) »