米国 NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ (2026.05.21)
こんにちは、丸山満彦です。
NISTがSP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティを公表し、意見募集をしていますね...
附属書にあるシナリオは、各シナリオはNISTIR 8428(OT向けDFIRフレームワーク)のワークフローに従い、検知から封じ込め、根絶、復旧までの技術的・手順的ステップを詳細に解説しています...
可用性が高く求められるシステムについては、完全に防御できるわけではないという前提のもと、復旧計画とそれに従った準備が必要で、昔から金融機関の対策として同じといえば、同じ考え方ですかね...
● NIST - ITL
| NIST SP 1800-41 (Initial Public Draft) Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector | NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ |
| Announcement | お知らせ |
| The NIST National Cybersecurity Center of Excellence (NCCoE) has released this initial public draft NIST Cybersecurity Practice Guide, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026. | NIST国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、産業用制御システム(ICS)環境における対応および復旧活動に関するガイドラインと、運用レジリエンスを向上させるための推奨事項を提示する、本NISTサイバーセキュリティ実践ガイドの初期ドラフトを公表した。本出版物に対する意見募集期間は2026年7月8日までである。 |
| Background | 背景 |
| As Operational Technology (OT) systems like ICS become increasingly interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience. | ICSのような運用技術(OT)システムがITネットワークとますます相互接続されるにつれ、これらはサイバー脅威の標的となりやすくなっており、工場の操業、安全、および資産にリスクを招いている。製造事業者などのこれらのシステムを運用する組織は、サイバーインシデントに対応し、操業を復旧させて全体的なレジリエンスを向上させるための計画と能力を整備する必要がある。 |
| The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities. | NCCoEは11の業界パートナーと協力し、リファレンスアーキテクチャの策定、対応および復旧シナリオの記述、関連するアプローチや能力の実証を行った。 |
| This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to: | 本ドラフトは、製造環境におけるサイバー攻撃への対応および復旧に関する実践的なガイドラインを提供する。以下の方法について確認できる: |
| ・Understand the risks and potential impact of cyber incidents on your operations | ・サイバーインシデントが業務に及ぼすリスクと潜在的な影響を理解する |
| ・Develop a comprehensive response and recovery plan | ・包括的な対応および復旧計画を策定する |
| ・Implement best practices to minimize downtime and restore operations quickly | ・ダウンタイムを最小限に抑え、迅速に業務を復旧させるためのベストプラクティスを実施する |
| Comment Now! | 今すぐコメントを! |
| We encourage you to review the publication and share your feedback by July 8, 2026. If you’re interested in staying up-to-date on this project, you can join the NCCoE Manufacturing Community of Interest by signing up on our project page. | 2026年7月8日までに、本資料を確認し、フィードバックを共有することを推奨する。本プロジェクトの最新情報を入手したい場合は、プロジェクトページから登録して、NCCoE製造関心コミュニティに参加することができる。 |
| Abstract< | 概要 |
| Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience. | 製造環境を運用する産業用制御システム(ICS)は、サプライチェーンにおいて極めて重要な役割を果たしている。製造事業者は、一般消費向けの製品を生産する物理的プロセスを監視・制御するために、制御システムに依存している。しかし、これらのシステムはサイバーインシデントの増加に直面しており、安全性や生産に対する現実的な脅威となり、製造事業者の経済的パフォーマンスに影響を及ぼしている。多層防御のセキュリティアーキテクチャはサイバーリスクの緩和に役立つが、すべてのサイバーリスクを排除することはできない。したがって、製造事業者は、サイバーインシデントが業務に影響を与えた場合に備え、業務を復旧・回復させる計画も策定すべきである。本実践ガイドでは、業界の協力者と共に策定した様々なサイバー攻撃シナリオを紹介し、製造環境における対応および復旧措置の採用と実施を可能にする方法論を提示することで、業務のレジリエンスを強化する。 |
・[PDF] sp1800-41ipd
エグゼクティブサマリー...
| Executive Summary | エグゼクティブサマリー |
| Manufacturing systems play a critical role in the supply chain and are essential to the nation’s economic security. Manufacturing organizations rely on Industrial Control Systems (ICS) to monitor and control physical processes to improve business agility and operational efficiencies. These same systems are facing an increasing number of cyber incidents from destructive malware, malicious insider activity, hardware failures, or unintended human error. Potential outages can be significant in scope and downtime, and may result in a loss of production, affecting safety controls for personnel, or the loss of millions of dollars to the organization. While defense-in-depth security architecture can help mitigate these risks, it cannot guarantee the elimination of cyber incidents. Therefore, manufacturing organizations should have a plan in place to maintain a resilient infrastructure in the event of cyber incidents that impact operations. To help with these challenges, this practice guide was developed using the NIST Cybersecurity Framework (CSF) 2.0 [1] as the basis for a response and recovery effort. The CSF defines standardized outcomes upon which organizations can base response and recovery objectives. | 製造システムはサプライチェーンにおいて極めて重要な役割を果たしており、国家の経済的安全保障に不可欠である。製造企業は、ビジネスの俊敏性と運用効率を向上させるため、物理的プロセスの監視と制御に産業用制御システム(ICS)に依存している。しかし、これらのシステムは、破壊的なマルウェア、内部関係者による悪意のある活動、ハードウェアの故障、あるいは意図しない人的ミスなど、増加するサイバーインシデントに直面している。発生しうる停止は、その規模やダウンタイムが甚大であり、生産の損失、従業員の安全制御への影響、あるいは組織にとって数百万ドル規模の損失につながる可能性がある。多層防御のセキュリティアーキテクチャはこれらのリスクを緩和するのに役立つが、サイバーインシデントの完全な排除を保証することはできない。したがって、製造事業者は、業務に影響を及ぼすサイバーインシデントが発生した場合に備え、レジリエンスを持つインフラを維持するための計画を策定しておくべきである。こうした課題への対応を支援するため、本実践ガイドは、対応および復旧活動の基盤としてNISTサイバーセキュリティフレームワーク(CSF)2.0 [1] を用いて作成された。CSFは、組織が対応および復旧の目標を策定するための基準となる標準化された成果を定義している。 |
| For organizations without established cybersecurity controls, establishing and implementing response and recovery procedures can be a daunting task. In addition, guidelines and frameworks alone can be difficult to follow without practical applications. In response, the National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) worked with stakeholders and industry collaborators specializing in response and recovery to demonstrate the practical application of cybersecurity technologies in a discrete-based manufacturing system that emulates a typical manufacturing environment. The effort resulted in this Practice Guide, providing three functional scenarios that demonstrate implementation of response and recovery procedures using commercially available technologies. The aim is to illustrate effective execution of response and recovery fundamentals, as well as highlight the benefits that result from the deployment of technologies that improve operational resilience. | 確立されたサイバーセキュリティ対策を持たない組織にとって、対応および復旧手順の策定と実施は困難な課題となり得る。さらに、ガイドラインやフレームワークだけでは、実用的な応用がなければ従うのが難しい場合もある。これに対応するため、国立標準技術研究所(NIST)の国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、対応および復旧を専門とするステークホルダーや業界パートナーと協力し、典型的な製造環境を模したディスクリート型製造システムにおいて、サイバーセキュリティ技術の実用的な応用を実証した。この取り組みの結果として作成された本実践ガイドでは、市販の技術を用いた対応および復旧手順の実装を示す3つの機能シナリオを提供する。その目的は、対応および復旧の基本原則の効果的な実行を具体例で示すとともに、運用レジリエンスを向上させる技術の展開によって得られるメリットを強調することにある。 |
| Key takeaways from the development of this Practice Guide are as follows: | 本実践ガイドの作成を通じて得られた主な知見は以下の通りである: |
| • Planning and preparation are critical in responding to and recovering from cyber incidents, since risks still exist despite efforts to implement defense-in-depth protections against known threats. | • 既知の脅威に対する多層防御の導入に努めてもリスクは依然として存在するため、サイバーインシデントへの対応および復旧においては、計画と準備が極めて重要である。 |
| • Logging and visibility across assets and the supporting ecosystem improve investigation, diagnostics, and protection, and shorten the time between detection and containment. | • 資産および支援エコシステム全体にわたるロギングと可視化は、調査、診断、保護を向上させ、検知から封じ込めまでの時間を短縮する。 |
| • Robust monitoring goes beyond simple event logging and should include behavioral analysis and ongoing coordination between the OT engineering and the Security Operations Center (SOC) team. | • 堅牢な監視は単なるイベントロギングにとどまらず、振る舞い分析や、OTエンジニアリングチームとセキュリティ・オペレーションセンター(SOC)チーム間の継続的な連携を含めるべきである。 |
| • Human factors, such as employee training on the stages of response and recovery, communicating between IT and ICS administrators, and working with OT product vendors, will allow for effective plan implementation in addition to technical solutions. | • 対応および復旧の各段階に関する従業員のトレーニング、ITとICS管理者間のコミュニケーション、OT製品ベンダーとの連携といった人的要因は、技術的ソリューションに加え、効果的な計画の実行を可能にする。 |
目次...
| Contents | 目次 |
| Executive Summary | エグゼクティブサマリー |
| 1 Introduction | 1 序論 |
| 1.1 Scope | 1.1 範囲 |
| 1.2 Audience | 1.2 対象読者 |
| 1.3 How to Use This Guide | 1.3 本ガイドの活用方法 |
| 2 Project Overview | 2 プロジェクト概要 |
| 2.1 Project Approach & Assumptions | 2.1 プロジェクトのアプローチと前提条件 |
| 2.2 Response and Recovery Challenges | 2.2 対応および復旧における課題 |
| 2.3 Project Collaborators | 2.3 プロジェクト協力者 |
| 2.4 Build Architecture & Collaborator | 2.4 ビルドアーキテクチャと協力者 |
| 2.4.1 Product Control Mappings | 2.4.1 製品管理マッピング |
| 2.4.2 Build Components | 2.4.2 ビルドコンポーネント |
| 2.4.3 Build Details | 2.4.3 ビルドの詳細 |
| 2.5 Assumptions | 2.5 前提条件 |
| 2.5.1 Attack Assumptions | 2.5.1 攻撃に関する前提条件 |
| 2.5.2 Preparation Assumptions | 2.5.2 準備に関する前提条件 |
| 2.5.3 General Project Assumptions | 2.5.3 プロジェクト全般に関する前提条件 |
| 3 Functional Demonstrations | 3 機能デモ |
| 3.1 Demonstration Methodology | 3.1 デモの方法論 |
| 3.2 Demonstration Use Cases | 3.2 デモのユースケース |
| 3.2.1 Scenario A: Compromise Human Machine Interface (HMI) or Operator Console | 3.2.1 シナリオA:ヒューマン・マシン・インターフェース(HMI)またはオペレーターコンソールの侵害 |
| 3.2.2 Scenario A: Response Execution | 3.2.2 シナリオ A:対応の実行 |
| 3.2.3 Scenario A: Recovery Execution | 3.2.3 シナリオ A:復旧の実行 |
| 3.2.4 Scenario B: Data Exfiltration | 3.2.4 シナリオ B:データの持ち出し |
| 3.2.5 Scenario B: Response Execution | 3.2.5 シナリオ B:対応の実行 |
| 3.2.6 Scenario B: Recovery Execution | 3.2.6 シナリオ B:復旧の実行 |
| 3.2.7 Scenario C: Unauthorized Command Message | 3.2.7 シナリオ C:不正なコマンドメッセージ |
| 3.2.8 Scenario C: Response Execution | 3.2.8 シナリオ C:対応の実行 |
| 3.2.9 Scenario C: Recovery Execution | 3.2.9 シナリオ C:復旧の実行 |
| 4 General Findings | 4 一般的な調査結果 |
| Appendix A List of Acronyms | 附属書 A 略語一覧 |
| Appendix B References | 附属書 B 参考文献 |
| Appendix C Build Implementation Instructions | 附属書 C ビルド実装手順 |
| C.1 Scenario A: Technical Details - Preparation | C.1 シナリオ A:技術的詳細 - 準備 |
| C.1.1 Creating a Splunk Dashboard to detect USB Activity | C.1.1 USB アクティビティを検知するための Splunk ダッシュボードの作成 |
| C.1.2 Backup the Rockwell PanelView™ HMI | C.1.2 Rockwell PanelView™ HMIのバックアップ |
| C.1.3 ForceField Zero Trust Storage | C.1.3 ForceField Zero Trust Storage |
| C.1.4 FactoryTalk® Logs in Windows Event Viewer | C.1.4 Windowsイベントビューアー内のFactoryTalk®ログ |
| C.2 Scenario A: Technical Details – Response | C.2 シナリオA:技術的詳細 – 対応 |
| C.2.1 Dragos Case Creation | C.2.1 Dragosケースの作成 |
| C.2.2 Disconnect WAN from Cisco ISA Firewall | C.2.2 Cisco ISAファイアウォールからのWAN切断 |
| C.2.3 Isolation of HMI | C.2.3 HMIの隔離 |
| C.2.4 Inductive Automation, Data Historian | C.2.4 Inductive Automation、データヒストリアン |
| C.2.5 Rockwell FactoryTalk® Transfer Utility | C.2.5 Rockwell FactoryTalk® 転送ユーティリティ |
| C.2.6 Rockwell Automation FactoryTalk® AssetCentre, Log Review | C.2.6 Rockwell Automation FactoryTalk® AssetCentre、ログの確認 |
| C.2.7 Update Dragos Case | C.2.7 Dragosケースの更新 |
| C.2.8 Remove Virtual Machine from Network | C.2.8 ネットワークからの仮想マシンの削除 |
| C.2.9 Taking Snapshots of VMs | C.2.9 仮想マシンのスナップショット取得 |
| C.2.10 Remove Physical Device from the Network | C.2.10 ネットワークから物理デバイスを削除する |
| C.2.11 Antivirus Scan | C.2.11 ウイルススキャン |
| C.2.12 Search for Malicious File | C.2.12 悪意のあるファイルの検索 |
| C.2.13 Script for Finding Malicious File | C.2.13 悪意のあるファイルを見つけるためのスクリプト |
| C.3 Scenario A: Technical Details – Recovery | C.3 シナリオ A:技術的詳細 – 復旧 |
| C.3.1 Downloading Backups from Authoritative Source | C.3.1 信頼できるソースからのバックアップのダウンロード |
| C.3.2 Restore the HMI | C.3.2 HMIの復元 |
| C.3.3 Close Dragos Ticket | C.3.3 Dragosチケットのクローズ |
| C.4 Scenario B: Technical Details – Preparation | C.4 シナリオB:技術的詳細 – 準備 |
| C.4.1 Configuring Garland to Enable Multiple Detections | C.4.1 Garlandの設定による複数検知の有効化 |
| C.4.2 Creating Graphic Interface in ConsoleWorks | C.4.2 ConsoleWorksでのグラフィカルインターフェースの作成 |
| C.4.3 Creating a Redundant Ignition Instance in AWS | C.4.3 AWSでの冗長Ignitionインスタンスの作成 |
| C.4.4 Creating a Baseline in Dragos | C.4.4 Dragosでのベースラインの作成 |
| C.4.5 Creating a Baseline Policy in Tenable | C.4.5 Tenableでのベースラインポリシーの作成 |
| C.4.6 Creating a Splunk Dashboard for SQL protocol Activity | C.4.6 SQLプロトコルアクティビティ用のSplunkダッシュボードの作成 |
| C.5 Scenario B: Technical Details – Response | C.5 シナリオB:技術的詳細 – 対応 |
| C.5.1 Detection using Splunk Dashboard | C.5.1 Splunkダッシュボードを使用した検知 |
| C.5.2 Analyzing Tenable Alert | C.5.2 Tenableアラートの分析 |
| C.5.3 Analyzing Dragos Deviation Alert | C.5.3 Dragosの逸脱アラートの分析 |
| C.5.4 Dragos Case Management | C.5.4 Dragosのケース管理 |
| C.5.5 Isolate ICS DMZ using ISA3000 | C.5.5 ISA3000を使用したICS DMZの隔離 |
| C.5.6 Disconnect JumpHost VM from Network | C.5.6 JumpHost VMのネットワークからの切断 |
| C.5.7 Take Snapshot of JumpHost VM | C.5.7 JumpHost VMのスナップショットの取得 |
| C.5.8 Isolate Local Database and Historian Gateway | C.5.8 ローカルデータベースおよびヒストリアンゲートウェイの隔離 |
| C.5.9 Validate Redundant AWS Cloud Historian | C.5.9 冗長化された AWS Cloud Historian の妥当性確認 |
| C.5.10 Detecting Large Data Transfer in Dragos | C.5.10 Dragos での大容量データ転送の検知 |
| C.5.11 Detecting Policy Deviation in Tenable | C.5.11 Tenable でのポリシー逸脱の検知 |
| C.5.12 Browsing Packet Captures from Tenable | C.5.12 Tenable からのパケットキャプチャの閲覧 |
| C.5.13 Reviewing ConsoleWorks User Session | C.5.13 ConsoleWorks ユーザーセッションの確認 |
| C.5.14 Disable Compromised Accounts | C.5.14 侵害されたアカウントの無効化 |
| C.6 Scenario B: Technical Details – Recovery | C.6 シナリオ B:技術的詳細 – 復旧 |
| C.7 Scenario C: Technical Details – Preparation | C.7 シナリオ C:技術的詳細 – 準備 |
| C.7.1 Creating Siemens Traffic Detection Policy in Tenable | C.7.1 Tenable での Siemens トラフィック検出ポリシーの作成 |
| C.7.2 Creating Splunk dashboard for unauthorized Siemens traffic | C.7.2 不正な Siemens トラフィック用の Splunk ダッシュボードの作成 |
| C.8 Scenario C: Technical Details – Response | C.8 シナリオ C:技術的詳細 – 対応 |
| C.8.1 View Tags in Data Historian | C.8.1 Data Historian でのタグの表示 |
| C.8.2 Managing Dragos Tickets | C.8.2 Dragos チケットの管理 |
| C.8.3 Isolate ICS Network using SIBERprotect | C.8.3 SIBERprotect を使用した ICS ネットワークの隔離 |
| C.8.4 Viewing policy violations in Tenable | C.8.4 Tenable でのポリシー違反の確認 |
| C.8.5 TIA Portal Diagnostics | C.8.5 TIA Portal の診断 |
| C.8.6 Windows Task Manager | C.8.6 Windows タスク マネージャー |
| C.8.7 Review ConsoleWorks Sessions for User Activity | C.8.7 ユーザーアクティビティに関する ConsoleWorks セッションの確認 |
| C.9 Scenario C: Technical Details – Recovery | C.9 シナリオ C: 技術的詳細 – 復旧 |
| C.9.1 TIA Portal Reinstall | C.9.1 TIA Portalの再インストール |
| C.9.2 Download PLC Backup Program File from ForceField | C.9.2 ForceFieldからのPLCバックアッププログラムファイルのダウンロード |
| C.9.3 Add Password and Restore from Backup with TIA Portal | C.9.3 TIA Portalでのパスワード追加およびバックアップからの復元 |
● まるちゃんの情報セキュリティ気まぐれ日記
SP 800-61関連
・2026.02.02 IPA AIインシデントレスポンス・アプローチ (2025.01.09)
・2025.10.03 米国 NIST IR 8183 Rev. 2 (初期公開ドラフト) サイバーセキュリティ・フレームワーク2.0 製造業プロファイル (2025.09.29)
・2025.04.07 米国 NIST SP 800-61 Rev. 3 サイバーセキュリティリスク管理のためのインシデント対応に関する推奨事項および考慮事項:CSF 2.0 コミュニティプロファイル (2025.04.03)
・2025.01.26 米国 NIST IR 8374 Rev.1(初期公開ドラフト)ランサムウェアのリスクマネジメント: サイバーセキュリティフレームワーク2.0コミュニティ (2025.01.13)
・2024.09.02 米国 CISA サイバー報告の改善に向けた新しいポータルを開設 (2024.08.29)
・2024.04.05 米国 意見募集 NIST SP 800-61 Rev.3(初期公開ドラフト) サイバーセキュリティリスクマネジメントのためのインシデント対応の推奨と考慮事項: CSF 2.0 コミュニティプロファイル
IR 8428
・2022.06.25 米国 NISTIR 8428 運用技術(OT)向けデジタルフォレンジックおよびインシデント対応(DFIR)フレームワーク (2022.06.22)
« 米国 NIST IR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)(2026.05.19) | Main | 米国 NIST SP 800-238 2025会計年度サイバーセキュリティおよびプライバシー年次報告書 »


Comments