情報セキュリティ / サイバーセキュリティ

2026.06.09

金融庁 「取引モニタリングの検知能力強化に向けた横断的レビューにかかる調査業務」報告書 (2026.05.28)

こんにちは、丸山満彦です。

金融庁が、「取引モニタリングの検知能力強化に向けた横断的レビューにかかる調査業務」報告書を公表していますね...

金融犯罪の巧妙化に対応するため、金融機関は取引モニタリングの検知について、手法の多層化・高度化(AI利用含む)、即時検知等により高度化し、業界全体で底上げをしていく必要がありますよね...

ただ、リソース(人、資金等)が十分にとれない地域金融機関の底上げというのが課題となるでしょうね...

特殊詐欺等については、海外では金融機関は知らないではすまない...という報告になってきているようですから、今から検知能力を強化していかなければ、金融機関も生き残れない状況になってきていますね...

 

金融庁

・2026.05.28 「取引モニタリングの検知能力強化に向けた横断的レビューにかかる調査業務」報告書の公表について

・・[PDF]

20260608-65304

| | Comments (0)

2026.06.08

米国 NIST IR 8320E(初期ドラフト)ハードウェア支援型セキュリティ:クラウドワークロードにおけるデータの機密コンピューティング

こんにちは、丸山満彦です。

NISTが、 IR 8320E(初期ドラフト)ハードウェア支援型セキュリティ:クラウドワークロードにおけるデータの機密コンピューティングが公表され、意見募集がされています。

この文書は、クラウド環境においてAIワークロードが処理する機密データやAIモデル自体を、ハードウェアベースの「機密コンピューティング(Confidential Computing)」技術を用いて保護するための実践的な技術ガイドということのようです。。。

従来のクラウドセキュリティでは、ディスクに保存されている時(保存時)やネットワークを流れている時(転送時)のデータは暗号化されているが、AIが計算を行うためにCPUがデータを読み込む「使用中(In Use)」の瞬間、メモリ上では一度復号(平文化)される必要がある。

この状況では、クラウド事業者の特権管理者や、OS・ハイパーバイザーの脆弱性を突いた攻撃者、同じサーバーを使う他のテナントからデータが覗き見られるリスクが残る。

ということで、OSすら入れないハードウェアレベルで物理的な隔離空間」(CPU内部に作られる信頼実行環境(TEE:Trusted Execution Environment) )をCPUの中に作成するということで解決できる...ただ、TEEが本物か、改ざんされていない安全な状況であるか、などを確認する必要もありますよね...

 

このシリーズのIR 8320Cは2022年にドラフトだしたまま、IR 8320Dは2023年にドラフトをだしたまま、最終化されていないです。。。

 

NIST - ITL

・2026.05.29 NIST IR 8320E (Initial Public Draft) Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads

NIST IR 8320E (Initial Public Draft) Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads NIST IR 8320E(初期ドラフト)ハードウェア支援型セキュリティ:クラウドワークロードにおけるデータの機密コンピューティング
Announcement 通知
The National Cybersecurity Center of Excellence (NCCoE) invites public comments NIST Interagency Report (NIST IR) 8320E ipd (initial public draft), Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads. This is the latest in a series of reports on hardware-enabled security techniques and technologies. 国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、NIST省庁間報告書(NIST IR)8320E ipd(初期ドラフト)『ハードウェア支援型セキュリティ:クラウドワークロードにおけるデータの機密コンピューティング』について、一般からのコメントを募集している。これは、ハードウェア支援型セキュリティの手法および技術に関する一連の報告書の最新版である。
 Confidential computing addresses data security and privacy concerns for organizations that move sensitive workloads to the cloud. It is a critical advancement that enables the encryption of data while it is being processed in memory, extending encryption coverage to data in active use. As cloud adoption continues to grow, confidential computing will play a pivotal role in improving security and privacy in cloud environments. 機密コンピューティングは、機密性の高いワークロードをクラウドに移行する組織におけるデータセキュリティおよびプライバシーの懸念に対処するものである。これは、メモリ内で処理中のデータを暗号化し、暗号化の対象をアクティブに使用中のデータにまで拡大することを可能にする重要な進歩である。クラウドの導入が拡大し続ける中、機密コンピューティングはクラウド環境におけるセキュリティとプライバシーの改善において極めて重要な役割を果たすことになる。
 IR 8320E describes an example approach to protecting data being acted upon by artificial intelligence workloads on cloud infrastructures so that the datasets are protected from malware, data theft, and other security-related vulnerabilities. This report is intended to be a blueprint that the general security community can use to validate and utilize the described implementation. IR 8320Eでは、クラウドインフラ上で人工知能(AI)ワークロードによって処理されるデータを防御し、データセットをマルウェア、データ盗難、およびその他のセキュリティ関連の脆弱性から守るためのアプローチ例を記述している。本報告書は、セキュリティコミュニティ全体が、記述された実装の妥当性確認および活用を行うための青写真となることを意図している。
 The public comment period for this draft is open through July 13, 2026. See the publication details for a copy of the draft and instructions for submitting comments. You can also contact the authors at hwsec@nist.gov. 本ドラフトに対するパブリックコメントの受付期間は、2026年7月13日までである。ドラフトのコピーおよびコメント提出方法については、出版物の詳細を参照のこと。また、hwsec@nist.gov 宛てに著者に連絡することも可能である。
Abstract 概要
Confidential computing addresses data security and privacy concerns for organizations that move sensitive workloads to the cloud. It is a critical advancement that enables the encryption of data both while it is being processed in memory and in active use. As cloud adoption continues to grow, confidential computing will play a pivotal role in improving security and privacy in cloud environments. This report describes an effective approach to protecting data being acted upon by artificial intelligence workloads on cloud infrastructures so that the datasets are protected from malware, data theft, and other security-related vulnerabilities. コンフィデンシャル・コンピューティングは、機密性の高いワークロードをクラウドに移行する組織におけるデータセキュリティおよびプライバシーの懸念に対処するものである。これは、メモリ内で処理されている間およびアクティブに使用されている間のデータの両方を暗号化することを可能にする、極めて重要な進歩である。クラウドの導入が進むにつれ、機密コンピューティングはクラウド環境におけるセキュリティとプライバシーの改善において極めて重要な役割を果たすことになる。本レポートでは、クラウドインフラ上で人工知能(AI)ワークロードによって処理されるデータを防御し、データセットをマルウェア、データ盗難、その他のセキュリティ関連の脆弱性から守るための効果的なアプローチについて説明する。

 

・[PDF]

20260604-62722

 

 

関係文書

Release Date Series Number Title タイトル Status
Hardware-Enabled Security : ハードウェアによるセキュリティ:
2026.05.29 IR 8320E Confidential Computing of Data in Cloud Workloads クラウドワークロードにおけるデータの機密コンピューティング Draft
2023.02.23 IR 8320D Hardware-Based Confidential Computing ハードウェアベースの機密コンピューティング Draft
2022.05.04 IR 8320 Enabling a Layered Approach to Platform Security for Cloud and Edge Computing Use Cases クラウドおよびエッジコンピューティングのユースケースに向けた、プラットフォームセキュリティの多層的アプローチの実現 Final
2022.04.20 IR 8320B Policy-Based Governance in Trusted Container Platforms 信頼できるコンテナプラットフォームにおけるポリシーベースのガバナンス Final
2022.04.20 IR 8320C Machine Identity Management and Protection マシンIDの管理と保護 Draft
2021.10.27 IR 8320B Policy Based Governance in Trusted Container Platforms 信頼されたコンテナプラットフォームにおけるポリシーベースのガバナンス Draft (Obsolete)
2021.10.27 IR 8320 Enabling a Layered Approach to Platform Security for Cloud and Edge Computing Use Cases クラウドおよびエッジコンピューティングのユースケースに向けたプラットフォームセキュリティの多層的アプローチの実現 Draft (Obsolete)
2021.06.17 IR 8320A Container Platform Security Prototype コンテナプラットフォームセキュリティのプロトタイプ Final
2021.05.27 IR 8320 Enabling a Layered Approach to Platform Security for Cloud and Edge Computing Use Cases クラウドおよびエッジコンピューティングのユースケースに向けたプラットフォームセキュリティの多層的アプローチの実現 Draft (Obsolete)
2020.12.07 IR 8320A Container Platform Security Prototype コンテナプラットフォームセキュリティのプロトタイプ Draft (Obsolete)

 

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2023.02.24 NISTIR 8320D(ドラフト)ハードウェア対応セキュリティ:ハードウェアベース・コンフィデンシャル・コンピューティング

・2022.05.07 NISTIR 8320 ハードウェア対応セキュリティ:クラウドおよびエッジ・コンピューティングのユースケースにおけるプラットフォーム・セキュリティへの階層型アプローチの実現

・2022.04.21 NISTIR 8320C (ドラフト) ハードウェア対応セキュリティ:マシン・アイデンティティの管理と保護

・2022.04.21 NISTIR 8320B ハードウェア対応セキュリティ:信頼できるコンテナプラットフォームにおけるポリシーベースのガバナンス

・2021.10.29 NISTIR 8320 (Draft) ハードウェア対応セキュリティ:クラウドおよびエッジ・コンピューティングのユースケースにおけるプラットフォーム・セキュリティへの階層型アプローチの実現(第二次ドラフト)

・2021.10.29 NISTIR 8320B (ドラフト) ハードウェア対応のセキュリティ:信頼できるコンテナプラットフォームにおけるポリシーベースのガバナンス

・2021.06.19 NISTIR 8320A ハードウェア対応セキュリティ:コンテナ・プラットフォーム・セキュリティ・プロトタイプ

・2021.05.28 NISTIR 8320 (Draft) ハードウェア対応セキュリティ:クラウドおよびエッジ・コンピューティングのユースケースにおけるプラットフォーム・セキュリティへの階層型アプローチの実現

・2020.12.13 NISTIR 8320A マルチテナントクラウド環境におけるコンテナを保護するためのハードウェア対応のセキュリティ技術とその技術に基づくアプローチに関する文書の意見募集

 

 

 

| | Comments (0)

米国 USCYBERCOM 司令官による2026年姿勢表明書 (2026.06.05)

こんにちは、丸山満彦です。

米国サイバー軍(USCYBERCOM)司令官が米議会へ提出した姿勢表明書が公表されていますね...

 

サイバー空間は現代戦の中核領域となっていて、米軍の作戦遂行能力はサイバー能力に大きく依存していますよね...おそらく他の国の軍もそうなると思いますが...

敵対的な国といえる、中国、ロシア、イラン、北朝鮮や、場合によっては犯罪組織も、米軍ネットワークや重要インフラを継続的に標的としているので、それを防御するのもサイバー軍の仕事ですね...

中国を中心とする高度化するサイバー脅威に対抗するため、AI・人材・同盟・権限を強化し、USCYBERCOM を米国の統合抑止戦略の中核戦力へ発展させる必要がありますね。

USCYBERCOM の司令官が、NSA 長官を兼務し(dual-hat)、情報収集と作戦実行を統合することで作戦上位意味のある速度(speed of relevance)を実現していると説明していますが、日本はどうですかね...軍事作戦より、テロ、傍受を含む公安的な要素が強いですかね...

あと、気になったのが、米国外の外国勢力が何を企んでいるかを、迅速に把握するための情報収集制度であるFISA702法律)ですね...

これは、日本でも気にしていて、国家情報会議設置法(内閣官房 概要 要綱 法律案・理由 新旧対照表 参照条文 衆議院 国家情報会議設置法案)の成立をはかりましたね...これから諜報活動の強化に向けて具体的な内容が深まるかもしれません...

日本は能力の問題ばかり気にしているように見えます、しかし問題は、能力に比例した国民監視の実効性ですよね...このあたりは、少なくともFISAに学ぶべきことが多いと思います。ただ、それでもEUと米国の個人データ移転に関するPrivacy Shield制度がSchrems II判決により無効となりましたよね...そういうことも意識しておく必要があります...

 

U.S. Cyber Command

・2026.06.05 Posture Statement of General Joshua M. Rudd

Posture Statement of General Joshua M. Rudd ジョシュア・M・ラッド大将の所信表明
Chairman Wicker, Ranking Member Reed, and distinguished members of the committee, thank you for your support through my recent confirmation process and for the privilege of representing the men and women of U.S. Cyber Command (USCYBERCOM) and the Cyber Mission Force (CMF). I value our partnership and this opportunity to discuss the changing strategic landscape, the Command’s accomplishments in 2025, and its way ahead in 2026. Last year the Command demonstrated its proficiency in integrating cyberspace operations with the Joint Force. This year, the Command continues to build upon our warfighting successes in defense of the nation, evidenced by on-going support to current operations.</ ウィッカー委員長、リード筆頭委員、そして委員会の皆様、私の最近の承認手続きにおけるご支援、ならびに米国サイバー軍(USCYBERCOM)およびサイバー任務部隊(CMF)の将兵を代表するこの光栄な機会を賜り、心より感謝申し上げます。私は、皆様との連携、そして変化する戦略的状況、2025年の当司令部の成果、そして2026年に向けた今後の方向性について議論するこの機会を大変重視しております。昨年、当司令部はサイバー空間作戦と統合部隊との統合においてその能力を実証しました。今年、当司令部は、現在進行中の作戦への継続的な支援が示す通り、国家防衛における戦闘上の成功をさらに発展させていきます。
I've witnessed our critical role in integrating cyber operations across the Joint Force; including in South America, the Middle East, and the Indo-Pacific. We deliver and integrate capabilities that support Combatant Commanders while mitigating risk for the Department of War (DoW), and enhancing mastery in our cyber forces, all of which depend on our congressionally granted Service-like authorities, such as Joint Force Trainer, Enhanced Budget Control, and acquisition. These authorities allow USCYBERCOM to shape the force that the nation requires in cyberspace – and we are executing them as intended. 私は、南米、中東、インド太平洋地域を含め、統合軍全体におけるサイバー作戦の統合において、我々が果たす極めて重要な役割を目の当たりにしてきました。我々は、戦闘指揮官を支援する能力を提供・統合すると同時に、国防総省(DoW)のリスクを軽減し、サイバー部隊の能力を向上させています。これらすべては、統合軍トレーナー、強化予算管理、調達といった、議会から付与された軍種と同等の権限に依存しています。これらの権限により、USCYBERCOMは国家がサイバー空間に求める戦力を構築することが可能となっており、我々はそれらを意図通りに実行しています。
OUR MISSION AND PARTNERS 我々の任務とパートナー
USCYBERCOM, through its subordinate unified commands and components, executes three assigned missions in support of the Department’s and Administration’s priorities outlined in the National Security Strategy, the Cyber Strategy for America, and National Defense Strategy. The Cyber National Mission Force (CNMF) defends the nation from malicious cyberspace actors who threaten our homeland. The Department of War Cyber Defense Command (DCDC) operates, secures and defends the Department of War Information Networks (DoWIN) to ensure our warfighters can execute missions globally. Our Service-led Joint Force Headquarters-Cyber – JFHQ-C (Navy), JFHQ-C (Army), JFHQ-C (Marines), and JFHQ-C (Air Force) – enable full spectrum cyber operations in support of Combatant Commands’ missions to meet the Department’s priorities. Finally, I should also mention that Coast Guard Cyber, under the Department of Homeland Security (DHS) serves as a component of USCYBERCOM, bringing important capacity and authorities to support our operations. All our components enhance the effectiveness of our allies and partners, collaborating and enabling them to bear greater common defense burdens. Also, the recently published Cyber Strategy for America affords additional operational latitude for cyber to support national security objectives. This range of duties and activities demands effective coordination, robust intelligence, and a deep understanding of both the cyber domain and broader geopolitical contexts. USCYBERCOMは、その傘下の統合司令部および構成部隊を通じて、『国家安全保障戦略』、『米国のサイバー戦略』、および『国防戦略』に概説された国防総省および行政当局の優先事項を支援するため、3つの任務を遂行しています。サイバー国家任務部隊(CNMF)は、我が国の国土を脅かす悪意あるサイバー空間の行為者から国家を防衛する。国防総省サイバー防衛司令部(DCDC)は、国防総省情報ネットワーク(DoWIN)を運用、保護、防衛し、我が軍の戦闘要員が世界中で任務を遂行できるようにする。各軍主導の合同部隊司令部・サイバー(JFHQ-C)――海軍、陸軍、海兵隊、空軍――は、国防総省の優先事項を達成するための戦闘指揮部の任務を支援し、全領域にわたるサイバー作戦を可能にしています。最後に、国土安全保障省(DHS)傘下の沿岸警備隊サイバー部門がUSCYBERCOMの一翼を担い、我々の作戦を支援するための重要な能力と権限を提供している点にも言及すべきでしょう。我々のすべての構成要素は、同盟国やパートナー国の有効性を高め、彼らと協力し、共通の防衛負担をより多く担えるよう支援しています。また、最近公表された『米国のサイバー戦略』は、国家安全保障上の目標を支援するために、サイバー分野にさらなる作戦上の裁量権を与えています。こうした幅広い任務と活動には、効果的な調整、強固な情報収集、そしてサイバー領域とより広範な地政学的状況の両方に対する深い理解が求められます。
I also serve as the Director of the National Security Agency (NSA), which is USCYBERCOM’s closest partner. The Agency is simultaneously a Combat Support Agency, a key component of the Intelligence Community, and the security overseer for vital national security systems. NSA’s roles, responsibilities, and capabilities complement those of USCYBERCOM. The synergy between these two organizations drives a unity of effort and unity of Command that strengthens the Joint Force, the Intelligence Community, and ultimately the nation. With the dual-hat command relationship between USCYBERCOM and NSA, I can make and execute decisions at the speed of war and speed of relevance, contributing substantially to the nation’s defense and the Department’s ability to fulfill its mission. 私はまた、USCYBERCOMの最も緊密なパートナーである国家安全保障局(NSA)の長も務めています。NSAは、戦闘支援機関であると同時に、情報コミュニティの主要構成要素であり、重要な国家安全保障システムのセキュリティ監督機関でもあります。NSAの役割、責任、能力は、USCYBERCOMのそれらを補完するものです。これら二つの組織間の相乗効果は、共同作戦部隊、情報コミュニティ、そして最終的には国家そのものを強化する「努力の一致」と「指揮の一致」を推進します。USCYBERCOMとNSAとの二重指揮関係により、私は「戦争の速度」と「状況に応じた迅速さ」で意思決定を行い実行することができ、国家の防衛および国防総省が任務を遂行する能力に大きく貢献しています。
DEFENDING THE HOMELAND 国土防衛
U.S. Cyber Command is in daily contact with malicious cyber actors, including state-sponsored entities working for our nation’s adversaries. We have witnessed persistent efforts by state-sponsored cyber actors to achieve strategic objectives against the United States and its allies and partners. We see these actors probing the DoWIN, weapons systems, and critical infrastructure with the intent to hold our economic and national institutions at-risk. DoW systems and data – as well as critical civilian infrastructure in the United States – are being targeted, and our responsibility to defend them remains a no-fail mission for the Department and the nation. 米国サイバー軍は、わが国の敵対勢力のために活動する国家支援組織を含む、悪意あるサイバー攻撃者たちと日々対峙している。我々は、米国およびその同盟国・パートナー国に対して戦略的目標を達成しようと、国家支援を受けたサイバー攻撃者たちが執拗な努力を続けているのを目の当たりにしてきた。これらの攻撃者たちは、わが国の経済・国家機関を危険にさらす意図を持って、国防情報網(DoWIN)、兵器システム、重要インフラを偵察している。国防総省のシステムやデータ、そして米国内の重要な民間インフラが標的となっており、これらを防衛する我々の責任は、国防総省および国家にとって絶対に失敗が許されない任務であり続けています。
I am pleased to report that we are also increasing CMF talent, resources, and focus on behalf of the Combatant Commands directly engaged in defending the American homeland within their areas of responsibility and functional missions. To meet the demand, we continually reassess our force allocation and have realigned forces to ensure complete alignment with the National Security Strategy, the Cyber Strategy for America, and the National Defense Strategy. また、各戦域軍がそれぞれの責任地域および機能的任務の範囲内で米国の国土防衛に直接従事できるよう、CMF(サイバー戦力)の人材、資源、および注力度を強化していることをご報告できることを嬉しく思います。この需要に応えるため、我々は部隊配置を継続的に見直し、国家安全保障戦略、米国サイバー戦略、および国防戦略との完全な整合性を確保するために部隊の再編を行ってきました。
We are in direct support to U.S. Southern Command (USSOUTHCOM) in its operations with partners to counter foreign drug cartels, build meaningful partner capacity, and bring stability to the Western Hemisphere. This has entailed a wide range of cyberspace operations, including force protection, hardening DoW systems, hunt forward missions (more on these below), and integration across the full spectrum of military capability. In particular, I am proud of the proficiency and impact of USCYBERCOM’s recent participation in Operation ABSOLUTE RESOLVE. Command personnel showed remarkable dedication, expertise, and sheer stamina in pivoting to integrate cyber effects and intelligence with USSOUTHCOM’s mission in Venezuela. We support U.S. Northern Command (USNORTHCOM) in securing our borders. This means not only tracking and disrupting the supply chain that delivers fentanyl into America, but also assisting bilateral efforts against cartels that profit from the drug trade and human trafficking. We also support U.S. Strategic Command (USSTRATCOM), U.S. Space Command (USSPACECOM), and other DoW entities in bolstering defenses against attacks against the United States. USCYBERCOM, for example, is a key contributor to the President’s Golden Dome for America initiative. 我々は、外国の麻薬カルテルに対抗し、パートナーの能力を実質的に構築し、西半球に安定をもたらすためのパートナーとの共同作戦において、米国南方軍(USSOUTHCOM)を直接支援しています。これには、部隊の防護、DoW(国防)システムの強化、ハンティング・フォワード任務(詳細は後述)、および軍事能力の全領域にわたる統合など、幅広いサイバー空間作戦が含まれています。特に、USCYBERCOMが最近「オペレーション・アブソリュート・リゾルブ」に参加した際の熟練度と成果を誇りに思います。司令部の要員たちは、ベネズエラにおけるUSSOUTHCOMの任務にサイバー効果と情報を統合するために迅速に対応し、並外れた献身、専門知識、そして驚異的な持久力を示しました。我々は、国境の安全確保において米国北方軍(USNORTHCOM)を支援しています。これは、フェンタニルを米国に流入させる供給網を追跡・遮断するだけでなく、麻薬取引や人身売買で利益を得るカルテルに対する二国間の取り組みを支援することも意味します。また、我々は米国戦略軍(USSTRATCOM)、米国宇宙軍(USSPACECOM)、およびその他の国防総省(DoD)機関に対し、米国に対する攻撃への防衛体制強化を支援している。例えば、米サイバー軍(USCYBERCOM)は、大統領の「ゴールデン・ドーム・フォー・アメリカ」イニシアチブにおいて重要な役割を果たしている。
Our efforts to defend the homeland flow through our Service components and the CNMF. CNMF personnel have deployed more than a hundred times in recent years to over 30 countries in partner-enabled missions to hunt on host networks. They conducted more than two dozen such “hunt forward” missions in 2025, generating insights and constraining adversary freedom of maneuver around the globe. These missions frequently lead to public releases of malware samples for analysis by the global cybersecurity community. Such disclosures have made Internet users in America and around the world, as well as in host countries, safer on-line. They also frustrate the military and intelligence operations of authoritarian regimes. 国土防衛に向けた我々の取り組みは、各軍種およびCNMFを通じて展開されています。CNMF要員は近年、パートナー国の支援を受けた任務として、ホストネットワーク上での脅威探索を行うため、30カ国以上に100回以上展開してきました。2025年には、こうした「ハンティング・フォワード」任務を20回以上実施し、知見を生み出し、世界中で敵対勢力の行動の自由を制限しました。これらの任務は、しばしばマルウェアサンプルの公開につながり、世界中のサイバーセキュリティコミュニティによる分析が可能となっています。こうした情報の公開により、米国や世界中のインターネットユーザー、さらにはホスト国のユーザーも、オンライン上でより安全に過ごせるようになりました。また、これらは独裁政権による軍事・諜報活動を阻害する効果も持っています。
Our Command secures, defends, and operates the military systems and data that provide warning, situational awareness, synchronization, and sustainment for our fellow Combatant Commands. This work focuses on the defense of our warfighting networks. That is our supported mission at USCYBERCOM. Every Combatant Command’s operational plan depends on the ability of leaders and commanders to communicate orders and share data securely. 当司令部は、他の戦闘司令部に対し、警戒、状況認識、連携、および持続的支援を提供する軍事システムとデータを、保護・防衛・運用しています。この活動は、我々の戦闘ネットワークの防衛に重点を置いている。これこそが、USCYBERCOMにおける我々の支援任務である。各戦闘司令部の作戦計画は、指導者や指揮官が命令を伝達し、データを安全に共有する能力に依存している。
USCYBERCOM coordinates with Geographic Combatant Commands to identify key cyber ‘terrain’ to inform and prioritize DCDC and Service component’s Defensive Cyber Operations (DCO) efforts. We seek to ensure our partners fully understand key mission systems and execute clearly defined roles and assignments for defending that terrain. When necessary, our Cyber Protection Teams work with local network defenders to secure and defend Joint Force systems, networks, and data. USCYBERCOMは、地域戦闘司令部と連携し、重要なサイバー「戦場」を特定することで、DCDCおよび各軍構成部隊の防御的サイバー作戦(DCO)の取り組みに情報を提供し、優先順位を決定している。我々は、パートナーが主要な任務システムを完全に理解し、その戦域を防衛するための明確に定義された役割と任務を遂行できるよう努めています。必要に応じて、我々のサイバー保護チームは現地のネットワーク防衛担当者と協力し、統合部隊のシステム、ネットワーク、およびデータを保護・防衛します。
One of USCYBERCOM’s primary sources of intelligence to identify and counter cyber threats such as ransomware attacks on U.S. critical infrastructure is FISA Section 702 collection. Intelligence derived from FISA Section 702 collection has proven invaluable in protecting our nation and warfighters overseas from terrorist attacks, adversary state actors, and malicious cyber activity. I assess there is no substitute for the speed and reliability of FISA Section 702 collection, or the specific and actionable insights that FISA Section 702 collection yields in defense of the homeland and warfighter networks. 米国の重要インフラに対するランサムウェア攻撃などのサイバー脅威を特定し、対処するためのUSCYBERCOMの主要な情報源の一つが、FISA第702条に基づく情報収集です。FISA第702条に基づく情報収集から得られる知見は、テロ攻撃、敵対的な国家主体、および悪意あるサイバー活動から、我が国および海外に展開する戦闘員を保護する上で極めて貴重なものであることが実証されています。私は、FISA第702条に基づく情報収集の迅速性と信頼性、あるいは同収集がもたらす具体的かつ実行可能な知見に代わるものはないと評価しています。これらは、国土および戦闘員ネットワークの防衛において不可欠なものです。
USCYBERCOM is strengthening the network defenses of our warfighting networks in several ways. We are emplacing stronger, more dynamic cybersecurity measures; investing in artificial intelligence and machine learning to improve threat detection, response times, and predictive analysis; enhancing the knowledge, skills, and capabilities of our workforce; leveraging new and legacy authorities; and working with Allies, partners, and industry to make the DoWIN a more difficult target for our adversaries. USCYBERCOMは、いくつかの方法で戦闘ネットワークの防御を強化しています。より強力で動的なサイバーセキュリティ対策を導入し、脅威の検知、対応時間、予測分析を改善するために人工知能(AI)と機械学習に投資し、要員の知識、技能、能力を向上させ、新規および既存の権限を活用し、同盟国、パートナー、産業界と協力して、DoWINを敵対者にとってより攻撃しにくい標的にしています。
Defending Joint Force systems and data parallels our efforts to support those who defend adjacent cyber terrain, particularly government, critical infrastructure, and partner networks. We work across the Joint Force and with a variety of partners to do this – something we call “Setting the Globe” – because systems in one region often depend on the functionality and the security of U.S. and foreign systems hundreds or even thousands of miles away. 統合軍(Joint Force)のシステムとデータを防衛することは、隣接するサイバー領域、特に政府、重要インフラ、およびパートナーのネットワークを防衛する人々を支援する我々の取り組みと並行するものです。我々はこれを実現するために、統合軍全体および多様なパートナーと連携しています。これは我々が「Setting the Globe(地球規模での展開)」と呼ぶ取り組みです。なぜなら、ある地域のシステムは、数百、あるいは数千マイル離れた場所にある米国や外国のシステムの機能やセキュリティに依存していることが多いためです。
We collaborate with an array of U.S. and foreign partners to ensure that adversaries cannot impair that connectivity – or our decisionmakers’ trust in its security. Foreign adversaries continuously sharpen how they operate, and frequently work through (unwitting) American-owned networks and systems. USCYBERCOM fosters unity of action across partners like the Service counterintelligence agencies, the Federal Bureau of Investigation (FBI)-led National Counterintelligence Task Force, and DHS’s Cybersecurity and Infrastructure Security Agency (CISA), sharing insights that enhance network defenses and counter adversary tactics. In addition, USCYBERCOM (with NSA) enables efforts by the Department of the Treasury, the FBI, and other partners to disrupt ransomware, cryptocurrency theft, and other criminal activities. 我々は、敵対勢力がその接続性を損なうこと、あるいは意思決定者がそのセキュリティに対する信頼を損なうことができないよう、米国および外国の多様なパートナーと協力している。外国の敵対勢力は、その活動手法を絶えず洗練させており、しばしば(知らぬ間に)米国が所有するネットワークやシステムを介して活動しています。USCYBERCOMは、各軍の情報機関、連邦捜査局(FBI)主導の国家対諜報タスクフォース、国土安全保障省(DHS)のサイバーセキュリティ・インフラセキュリティ庁(CISA)といったパートナー間で行動の一致を図り、ネットワーク防御を強化し、敵対勢力の戦術に対抗するための知見を共有しています。さらに、USCYBERCOMは(NSAと連携して)、財務省、FBI、その他のパートナーによるランサムウェア、暗号資産窃盗、その他の犯罪活動を阻止する取り組みを支援している。
Consistent with Congressional intent, USCYBERCOM engages in a two-way voluntary sharing of information with industry to help bolster private companies’ ability to defend themselves against exploitation by malicious cyber actors and enhance our ability to act against those same actors. We aim to broaden the sharing of insights, ensuring mutual gain from this collaboration. Our UNDERADVISEMENT program, a voluntary collaboration with more than a hundred companies, links cybersecurity expertise across industry and government. This partnership has cued significant operational successes, enabling network owners to close vulnerabilities and eradicate threats from their systems. Such efforts by design frustrate adversaries and make their campaigns more expensive for them and less consequential for us. 議会の意図に沿い、USCYBERCOMは産業界と双方向の自発的な情報共有を行い、民間企業が悪意あるサイバー攻撃者による悪用から自らを守る能力を強化し、我々がそれらの攻撃者に対して行動する能力を高めることを支援している。我々は、この協力から相互の利益が得られるよう、知見の共有を拡大することを目指している。100社以上の企業と自発的に連携する「UNDERADVISEMENT」プログラムは、産業界と政府のサイバーセキュリティ専門知識を結びつけている。このパートナーシップは、ネットワーク所有者が脆弱性を修正し、システムから脅威を根絶することを可能にし、重要な運用上の成功をもたらしてきた。こうした取り組みは、意図的に敵対者を挫き、彼らの作戦コストを増加させると同時に、我々への影響を軽減するものである。
ENABLING DETERRENCE 抑止力の強化
China seeks a world order more amenable to the Chinese Communist Party (CCP)’s vision and ideology – and views cyber as a critical domain for modern warfare. Not only is China confronting us in cyberspace, it is also expanding its sway in the Pacific while insisting that it is only acting to defend itself. China has constructed a substantial cyberspace operations force, supported by capable and adaptive enablers in its native defense, cybersecurity, and information technology industries. 中国は、中国共産党(CCP)のビジョンとイデオロギーに合致した世界秩序を追求しており、サイバー空間を現代戦争における極めて重要な領域と見なしている。中国はサイバー空間で我々と対峙しているだけでなく、自国の防衛のために行動しているに過ぎないと主張しつつ、太平洋地域での影響力を拡大させている。中国は、自国の防衛、サイバーセキュリティ、情報技術産業における有能かつ適応力のある支援体制に支えられ、大規模なサイバー作戦部隊を構築している。
Focusing on the strategic and operational challenges that China presents in cyberspace, our Command recognizes the vital role that we play in supporting the Joint Force in Pacific-area contingencies. We support U.S. Indo-Pacific Command (USINDOPACOM) in its mission to deter aggression and defend its area of responsibility. This commitment extends to the other Combatant Commands that would be involved in a Pacific crisis, particularly U.S. Transportation Command (USTRANSCOM), U.S. Special Operations Command (USSOCOM), and USSPACECOM. As noted, we also work daily with U.S. Government partners and industry to deny China-based cyber threats to our homeland, allies, and partners. We are countering China’s cyber operators’ efforts to burrow into U.S. critical infrastructure systems and pre-position for attack in a contingency or crisis scenario. We are also hardening DoW’s cyber “terrain” across the Pacific region to make it more secure and defensible against any attacker. Our Command gratefully acknowledges the importance that our allies and partners provide in defending our common interests in the Pacific. 我が司令部は、サイバー空間において中国がもたらす戦略的・作戦上の課題に焦点を当て、太平洋地域における不測の事態において統合軍を支援する上で我々が果たす極めて重要な役割を認識している。我々は、侵略を阻止し、その責任地域を防衛するという米インド太平洋軍(USINDOPACOM)の任務を支援する。この取り組みは、太平洋地域の危機に関与する他の戦闘指揮部、特に米国輸送軍(USTRANSCOM)、米国特殊作戦軍(USSOCOM)、および米国宇宙軍(USSPACECOM)にも及ぶ。前述の通り、我々はまた、米国政府のパートナーや産業界と日々連携し、自国、同盟国、およびパートナーに対する中国発のサイバー脅威を阻止している。我々は、中国のサイバー攻撃者が米国の重要インフラシステムに潜入し、不測の事態や危機発生時に攻撃を行うための準備を整えようとする動きに対抗している。また、太平洋地域全域において、DoWのサイバー「戦域」を強化し、いかなる攻撃者に対してもより安全で防御可能な状態にするよう取り組んでいる。当司令部は、太平洋における共通の利益を守る上で、同盟国やパートナーが果たす重要な役割に深く感謝している。
We also support USINDOPACOM and U.S. Forces Korea in upholding deterrence on the Korean Peninsula. North Korea, like Iran, sponsors increasingly capable cyber actors. Pyongyang focuses cyber activities on the circumvention of international sanctions and the generation of illicit revenue through cryptocurrency exploitation that supports the regime’s nuclear weapons and ballistic missile programs. また、朝鮮半島における抑止力の維持において、米インド太平洋軍(USINDOPACOM)および在韓米軍を支援している。北朝鮮はイランと同様、能力を増大させているサイバーアクターを支援している。平壌は、国際制裁の回避と、体制の核兵器および弾道ミサイル計画を支援する仮想通貨の悪用を通じた不正収益の獲得に、サイバー活動を集中させている。
We support U.S. European Command (USEUCOM) in stabilizing the security environment in Europe. Russia remains a threat to the peace of the Continent and to the global order. Moscow violates international norms with its aggression in Ukraine, coupled with its overt and covert campaigns to intimidate Ukraine’s friends. As with China, Russia’s military and intelligence cyber forces serve the Kremlin’s strategic objectives – as we have seen time and again in the Ukraine war, the first major conflict with a full-fledged cyber front. Russian cyber actors work to subvert Ukraine and divide its Western allies, seeking to undermine them abroad and internally. In the Russian case, the Kremlin encourages, or at least tolerates, brazen cyber-criminal entities that indirectly serve state purposes against foreign targets. 我々は、欧州における安全保障環境の安定化に向け、米欧州軍(USEUCOM)を支援する。ロシアは、欧州大陸の平和および世界秩序に対する脅威であり続けている。モスクワは、ウクライナへの侵略に加え、ウクライナの友好国を威嚇するための公然たる、あるいは秘密裏の作戦を展開することで、国際規範に違反している。中国と同様、ロシアの軍事・諜報サイバー部隊はクレムリンの戦略的目標に奉仕している。これは、本格的なサイバー戦線が展開された初の主要な紛争であるウクライナ戦争において、我々が繰り返し目にしてきた通りである。ロシアのサイバー攻撃主体は、ウクライナを転覆させ、その西側同盟国を分断しようと働きかけ、国外および国内でそれらの国々を弱体化させようとしている。ロシアの場合、クレムリンは、外国の標的に対して間接的に国家の目的を果たす、厚かましいサイバー犯罪組織を奨励しているか、少なくとも容認している。
USCYBERCOM supports U.S. Central Command (USCENTCOM) and USSOCOM in their campaigns to counter Iranian aggression. With USCENTCOM, we have helped bolster the cyber defenses of Israel and other regional partners, including support for regional stability efforts. The Command has focused on securing key partners and networks in the region, and provides actionable information, insights, and options to policy makers. 米サイバー軍(USCYBERCOM)は、イランの侵略に対抗する米中央軍(USCENTCOM)および米特殊作戦軍(USSOCOM)の作戦を支援している。USCENTCOMと連携し、我々はイスラエルやその他の地域パートナーのサイバー防衛を強化する支援を行っており、これには地域の安定化に向けた取り組みへの支援も含まれる。同軍は、地域内の主要なパートナーやネットワークの安全確保に注力しており、政策立案者に対して実用的な情報、洞察、および選択肢を提供している。
Non-state cyber actors remain a threat in cyberspace. Cyber criminals continue to find new victims in the United States and globally. We are concerned about the criminal enablers of such activities, such as those providing ransomware-as-a-service. In addition, violent extremist groups still spread propaganda and incite attacks in cyberspace. Though their capabilities have been eroded, the Islamic State in Iraq and Syria (ISIS), al Qaida, and their offshoots maintain the intent to target Americans. Our Joint Force Headquarters- Cyber (Marines) works in conjunction with U.S. military and diplomatic efforts, supporting allies and partners who are disrupting terrorist messaging and mobilization online as well as providing critical intelligence. 非国家主体のサイバーアクターは、依然としてサイバー空間における脅威である。サイバー犯罪者は、米国内および世界中で新たな被害者を見つけ続けている。我々は、ランサムウェア・アズ・ア・サービス(RaaS)を提供する者など、こうした活動を助長する犯罪者について懸念を抱いている。さらに、暴力的な過激派グループは、依然としてサイバー空間でプロパガンダを拡散し、攻撃を扇動している。その能力は弱体化しているものの、イラク・シリア・イスラム国(ISIS)、アルカイダ、およびそれらの分派組織は、依然として米国人を標的とする意図を維持している。我々の海兵隊サイバー統合部隊司令部(JFHQ-Cyber)は、米軍の軍事・外交活動と連携し、オンライン上でのテロリストのメッセージ発信や動員を妨害する同盟国・パートナーを支援するとともに、重要な情報を提供している。
Strong partnerships with government, industry, academia, and foreign colleagues amplify our operational effectiveness and in turn create advantages for our partners. Such advantages force dilemmas upon our adversaries, and broaden the perspectives and insights we can utilize and exploit. Our components, when working in unison with diplomatic, military, law enforcement, homeland security, and intelligence capabilities, make a powerful combination that can disrupt the plans of malicious cyber actors wherever they hide. In addition, our Regional Cybersecurity and Engagement Strategy in the Indo-Pacific guides efforts with partners to counter and contest foreign adversaries. These efforts at USCYBERCOM go into fostering capacity building among partners, promoting interoperability, burden-sharing, and reducing barriers to information sharing and combined activities. 政府、産業界、学界、および海外の同僚との強固なパートナーシップは、我々の作戦上の有効性を高め、ひいてはパートナーにとっての優位性を生み出します。こうした優位性は敵対者にジレンマを強いるとともに、我々が活用し、利用し得る視点や洞察を広げます。我々の構成要素が、外交、軍事、法執行、国土安全保障、および情報能力と一体となって活動する際、それは強力な組み合わせとなり、悪意あるサイバーアクターがどこに潜んでいようとも、その計画を阻止することができます。さらに、インド太平洋地域における「地域サイバーセキュリティ・エンゲージメント戦略」は、外国の敵対勢力に対抗し、牽制するためのパートナーとの取り組みを導くものである。USCYBERCOMにおけるこれらの取り組みは、パートナー間の能力構築の促進、相互運用性の推進、負担分担、そして情報共有や共同活動における障壁の低減に注力している。
USING OUR AUTHORITIES 権限の活用
USCYBERCOM employs unique Service-like authorities to enhance readiness, improve capabilities, and advance partnerships. These authorities help to ensure that innovation adds speed, agility, and scale across operations, capability deployment, data sharing, and procurement. USCYBERCOMは、独自の軍種並みの権限を活用して、即応態勢の強化、能力の向上、およびパートナーシップの推進を図っています。これらの権限は、作戦、能力展開、データ共有、および調達において、イノベーションがスピード、機動力、そして規模をもたらすことを確実にするのに役立ちます。
The Enhanced Budgetary Control (EBC) authority and resources granted by Congress are crucial to the execution of our Service-like functions. This portfolio of fiscal authorities has transformed our relations with DoW, the Services, and our Components. EBC entrusts nearly $4 billion of the DoW budget to USCYBERCOM, and streamlines how we engage the Department’s planning, programing, budgeting, and execution processes. EBC also promotes the transparency that aligns authorities, responsibility, and accountability in cyberspace operations. Greater accountability in turn facilitates better cybersecurity as well as faster development and fielding of new capabilities. 議会から付与された「強化予算管理(EBC)」の権限と資源は、我々の軍種並みの機能を遂行する上で極めて重要です。この一連の財政権限は、国防総省(DoW)、各軍種、および我々の構成組織との関係を大きく変革しました。EBCは、国防総省(DoW)予算のうち約40億ドルをUSCYBERCOMに委任し、同省の計画、プログラム策定、予算編成、および実行プロセスへの関与方法を合理化します。また、EBCは、サイバー空間作戦における権限、責任、説明責任を整合させる透明性を促進します。説明責任の強化は、結果としてサイバーセキュリティの向上に加え、新能力の開発および配備の迅速化を可能にします。
Agile acquisition is key to creating advantage for our commanders, components, and operators. The Command collaborates and partners closely with the Services, the Defense Advanced Research Projects Agency (DARPA), the Strategic Capabilities Office (SCO), Defense Innovation Unit (DIU), and others, to ensure our acquisition strategies enable agility, scale, and precision at the rapid pace demanded to keep the United States ahead of our adversaries in the cyber domain. For example, USCYBERCOM partners with DARPA through an acquisition initiative called CONSTELLATION to bridge the proverbial “valley of death” for new capabilities, which it can now transition more rapidly from concepts to operational use. アジャイルな調達体制は、指揮官、各軍種、および運用要員に優位性をもたらすための鍵である。当司令部は、各軍種、国防高等研究計画局(DARPA)、戦略能力局(SCO)、国防イノベーションユニット(DIU)などと緊密に連携・協力し、米国のサイバー領域における敵対勢力に対する優位性を維持するために求められる迅速なペースで、調達戦略が俊敏性、規模、および精度を実現できるよう確保している。例えば、USCYBERCOMは「CONSTELLATION」と呼ばれる調達イニシアチブを通じてDARPAと提携し、新能力が直面するいわゆる「死の谷」を乗り越えることで、概念段階から実戦運用への移行をより迅速に行えるようにしている。
Many of our missions depend on the Joint Cyber Warfighting Architecture (JCWA), a suite of systems with associated capabilities that facilitate a full range of cyberspace missions and foster overmatch against malicious adversaries. Our Command is employing its Department-approved systems engineering and integration authorities to ensure JCWA develops efficiently in accord with a shared vision. Common standards between the Service-managed subcomponents of JCWA have accelerated its interoperability, tool development capacity, and data flows within and across the Command and mission partners. Finally, the Department is working with USCYBERCOM through our JCWA Program Executive Office (PEO) to provide our Command with milestone decision authority for the Service-managed JCWA programs of record. 我々の任務の多くは、合同サイバー戦闘アーキテクチャ(JCWA)に依存している。これは、サイバー空間におけるあらゆる任務を円滑にし、悪意ある敵対者に対する圧倒的優位性を確立するための、関連能力を備えた一連のシステムである。当司令部は、国防総省が承認したシステム工学および統合に関する権限を行使し、JCWAが共通のビジョンに沿って効率的に発展するよう確保している。JCWAの各軍が管理するサブコンポーネント間の共通基準により、相互運用性、ツール開発能力、および司令部内および司令部と任務パートナー間のデータフローが加速されました。最後に、国防総省は、JCWAプログラム執行部(PEO)を通じてUSCYBERCOMと連携し、各軍が管理する公式JCWAプログラムについて、当司令部にマイルストーン決定権限を付与するよう取り組んでいます。
USCYBERCOM’s designation as a federal laboratory for technology transfer empowered our work with industry and academia. Using our authorities as a federal lab, USCYBERCOM signs Cooperative Research and Development Agreements (CRADAs) with industry and academic partners. With thanks to Congress for amending this authority in the FY25 NDAA, we are now able to engage our territorial partners in such key areas as Guam. These agreements allow tighter collaboration between our operators and technical experts and, for example, local network defenders seeking to enhance their capabilities to detect whether their systems have been compromised. USCYBERCOM has also signed Education Partnership Agreements (EPAs) with a variety of institutions. Finally, our Academic Engagement Network (AEN) of more than 120 institutions is facilitating new partnerships and bringing fresh ideas to shared challenges. USCYBERCOMが技術移転のための連邦研究所として指定されたことは、産業界や学界との連携を強化する原動力となった。連邦研究所としての権限を活用し、USCYBERCOMは産業界や学術パートナーと共同研究開発協定(CRADA)を締結している。2025会計年度国防権限法(NDAA)において議会がこの権限を改正してくれたおかげで、我々は現在、グアムなどの重要な地域における現地パートナーと協力することが可能となっている。これらの協定により、当司令部の運用要員や技術専門家と、例えば自システムの侵害検知能力の向上を目指す現地のネットワーク防衛担当者との間で、より緊密な連携が可能となります。また、USCYBERCOMは様々な機関と教育連携協定(EPA)を締結しています。最後に、120以上の機関からなる当司令部の学術連携ネットワーク(AEN)は、新たなパートナーシップを促進し、共通の課題に対して斬新なアイデアをもたらしています。
Artificial intelligence (AI) holds the potential to change the character of war. Automation and autonomy – in cases enabled by AI – are transforming ideas from theory into reality and even disruptive weapons and tools on battlefields and in competition around the world. Our allies, partners, and adversaries are all engaged and propelling this technological progress. Adversaries employ AI for similar purposes as we do. 人工知能(AI)は、戦争の様相を一変させる可能性を秘めています。AIによって可能となる自動化と自律化は、理論上の構想を現実のものとし、さらには世界中の戦場や競争の場において、従来の枠組みを覆すような兵器やツールを生み出しています。同盟国、パートナー、そして敵対勢力のすべてが、この技術的進歩に関与し、それを推進しています。敵対勢力も、我々と同様の目的でAIを活用しています。
Congress made a significant and strategic investment in our AI capabilities, and we are employing those resources effectively. USCYBERCOM's acquisition and programming authorities promote agile methodologies for rapid AI development and iteration, accelerating adaptation to evolving cyber threats and operational needs. The Command is implementing its framework for ensuring AI solution interoperability and integration across the cyber domain. This supports rapid prototyping, streamlined software acquisition, and the integration of commercial AI advances. USCYBERCOM is leveraging AI to enhance our capabilities in collection, detection, exploitation, maneuver, and command and control, generating greater speed and scale. A general officer in our headquarters is now leading our Command’s effort to explore and apply artificial intelligence to the cyber mission set. He works with the AI Task Force in CNMF and already sees success in a growing series of pilot projects, many of which are having operational impacts today. 議会は我々のAI能力に対し、重要かつ戦略的な投資を行っており、我々はそれらの資源を効果的に活用している。USCYBERCOMの調達およびプログラム策定権限は、AIの迅速な開発と反復のためのアジャイル手法を促進し、進化するサイバー脅威や作戦上のニーズへの適応を加速させている。同司令部は、サイバー領域全体におけるAIソリューションの相互運用性と統合を確保するための枠組みを実施している。これは、迅速なプロトタイピング、効率化されたソフトウェア調達、および商用AI技術の進歩の統合を支援するものである。USCYBERCOMは、AIを活用して情報収集、検知、活用、機動、指揮統制における能力を強化し、より高い速度と規模を実現している。現在、本部の将官が、サイバー任務群への人工知能の活用と適用を推進する当司令部の取り組みを主導している。同将官はCNMFのAIタスクフォースと連携しており、すでに増加するパイロットプロジェクトで成果を上げており、その多くは今日、作戦上の影響を及ぼしている。
In an environment transformed by AI and big data, operational and strategic advantage accrues to the side that sustains speed and efficiency in collecting and ingesting reams of data, building and employing models and algorithms, and deploying and updating them at-scale, while also denying similar advantages to adversaries seeking to exploit our systems and data. We are focused on ensuring our data and analytic infrastructures deliver advantage, and that those systems attain sufficient resilience to function even under attack. Some of this work proceeds under the auspices of the DoW and USCYBERCOM-developed five-year AI Roadmap. This guides the appropriate people, data, organizations, and infrastructure to deliver AI capabilities for all cyber mission sets; to counter AI threats and seize emerging opportunities; and to enable AI adoption. AIとビッグデータによって変革された環境において、膨大なデータの収集・取り込み、モデルやアルゴリズムの構築・運用、そしてそれらを大規模に展開・更新する上で、速度と効率を維持できる側に、作戦上および戦略上の優位性がもたらされます。同時に、我々のシステムやデータを悪用しようとする敵対勢力に対し、同様の優位性を与えないようにする必要があります。我々は、データおよび分析インフラが優位性をもたらすことを確実にすることに注力しており、それらのシステムが攻撃下にあっても機能し得る十分なレジリエンス(回復力)を獲得するよう取り組んでいます。こうした取り組みの一部は、国防総省(DoW)と米サイバー軍(USCYBERCOM)が策定した5カ年AIロードマップの下で進められています。これは、あらゆるサイバー任務セットに向けたAI能力を提供し、AIによる脅威に対抗して新たな機会を捉え、AIの導入を可能にするために、適切な人材、データ、組織、インフラを導くものです。
BUILDING AND SUSTAINING MASTERY 専門性の構築と維持
I am pleased to report that all our Service cyber components and the forces they present to our Command remain mission ready, while consistently working to get better. This achievement rested on sustained efforts by the Services to improve the manning, training, and equipping of their respective forces. The staffing and training of our teams is improving, and the Command’s cyber readiness system shares data directly with the Defense Readiness and Reporting System (DRRS). While our current force is meeting readiness standards, they are insufficiently scaled for the threat environment. The next year provides us a great opportunity to attack this problem. 各軍種のサイバー部隊および当司令部に配備されている部隊は、常に改善に努めつつ、任務遂行態勢を維持していることを報告できることを嬉しく思います。この成果は、各軍種がそれぞれの部隊の人員配置、訓練、装備の改善に向けて継続的に取り組んできたことに支えられています。各チームの人員配置と訓練は改善されており、当司令部のサイバー準備態勢システムは、国防準備・報告システム(DRRS)とデータを直接共有しています。現在の部隊は即応基準を満たしてはいますが、脅威環境に対応するには規模が不十分です。来年は、この問題に取り組む絶好の機会となります。
When the Department established USCYBERCOM in 2010 and authorized our Cyber Mission Force in 2012, it did not fully project the requirement to sustain cyberspace operations at-scale. The Assistant Secretary of War for Cyber Policy (ASW/CP), as the Department’s Principal Cyber Advisor, is a key partner in meeting this challenge and has sharpened the Department’s focus on cyber matters, which is instrumental to USCYBERCOM as we implement new authorities and evolve to increase domain mastery and warfighting readiness. 国防総省が2010年にUSCYBERCOMを設立し、2012年にサイバー任務部隊を承認した際、大規模なサイバー空間作戦を持続させる必要性を十分に予測していませんでした。サイバー政策担当国防次官補(ASW/CP)は、国防総省の首席サイバー顧問として、この課題に対処する上での重要なパートナーであり、サイバー問題に対する国防総省の焦点を明確化してきた。これは、我々が新たな権限を実施し、領域の掌握と戦闘準備態勢を強化するために進化していく上で、USCYBERCOMにとって極めて重要な役割を果たしている。
With the ASW/CP, we are implementing our Revised Cyber Force Generation Model (commonly referred to as CYBERCOM 2.0). The Secretary of War recently endorsed several concepts to update USCYBERCOM’s force generation and the ways in which we build and sustain specialization and expertise in our teams. Our revised model establishes policy, implements programs, and executes new approaches to recruiting, developing, and retaining cyber talent. In short, it will foster mastery across the force so we can overmatch quantity with quality. These steps were prompted and facilitated by Congressionally approved provisions on readiness and force generation that collectively gave the Department the opportunity to modernize the cyber force and reshape USCYBERCOM. ASW/CPと共に、我々は改訂版サイバー戦力構築モデル(通称CYBERCOM 2.0)を実施している。国防長官は最近、USCYBERCOMの戦力構築を更新し、各チームにおける専門性と知見を構築・維持する方法を刷新するためのいくつかの構想を承認した。この改訂モデルは、サイバー人材の採用、育成、定着に向けた政策を確立し、プログラムを実施し、新たなアプローチを実行するものである。要するに、これは部隊全体での熟達度を高め、量ではなく質で優位に立つことを可能にするものです。これらの措置は、議会が承認した戦備および戦力構成に関する規定によって促され、促進されたものであり、これらが総合的に、国防総省にサイバー戦力を近代化し、USCYBERCOMを再構築する機会をもたらしました。
CYBERCOM 2.0 calls for several new entities, which are currently under construction. These include a Cyber Talent Management Organization planned for the near year, followed by an Advanced Cyber Training and Education Center and a Cyber Innovation Warfare Center. These are slated to be operational in the near term. The Department and Command had the opportunity to explore these entities in a hearing before the Cybersecurity Subcommittee last month. Together they will help change the Department’s approach to generating cyber forces, emphasizing domain mastery, strengthening specialized skills, and enhancing mission agility. Coupled with the readiness improvements highlighted above and organizational efforts to streamline the force, the end result will be a more experienced, better-trained, and better-equipped cyber force capable of adapting in the dynamic cyberspace environment. I look forward to providing regular updates on the implementation of these initiatives to enhance lethality in the future. CYBERCOM 2.0では、現在構築中のいくつかの新たな組織が求められています。これには、来年中に設立が予定されている「サイバー人材管理組織」に加え、続いて「高度サイバー訓練・教育センター」および「サイバー・イノベーション・ウォーフェア・センター」が含まれます。これらは近い将来に運用開始される予定です。先月、サイバーセキュリティ小委員会での公聴会において、国防総省および司令部はこれらの組織について説明する機会を得ました。これら組織は一体となって、ドメインの熟達を重視し、専門技能を強化し、任務遂行の機動性を高めることで、サイバー戦力の編成に対する国防総省のアプローチを変革する一助となるでしょう。前述の戦備態勢の改善や、部隊の効率化に向けた組織的な取り組みと相まって、その結果として、ダイナミックなサイバー空間環境に適応できる、より経験豊富で、より高度な訓練を受け、より優れた装備を備えたサイバー部隊が誕生することになるでしょう。今後、戦闘能力を強化するためのこれらの取り組みの実施状況について、定期的に最新情報をお伝えできることを楽しみにしています。
At USCYBERCOM, our Code is “We win with People.” This principle guides a culture where initiative, innovation, collaboration, and the expertise of our personnel drive mission success. The people of USCYBERCOM are determined to defend our networks, counter threats, strengthen our partners, and provide decisive advantages for policymakers and military commanders. We amplify the impact of federal, military, foreign, and private-sector partner activities, synergizing the application of all instruments of national power against our adversaries. We seek to ensure our people have the necessary resources to optimize readiness and resilience. USCYBERCOMのモットーは「We win with People(人材こそが勝利の鍵)」です。この原則は、職員の主体性、革新性、協調性、そして専門知識が任務の成功を牽引する文化を導くものです。USCYBERCOMの職員は、ネットワークを防衛し、脅威に対抗し、パートナーを強化し、政策立案者や軍事指揮官に決定的な優位性を提供することに決意しています。我々は、連邦政府、軍、外国、民間セクターのパートナーによる活動のインパクトを増幅させ、敵対勢力に対して国家のあらゆる力の手段を相乗的に適用します。我々は、要員が即応性と回復力を最適化するために必要なリソースを確保できるよう努めています。
USCYBERCOM’s efforts depend on the initiative, motivation, and excellence it sustains in its people. We must hire and retain critical expertise while ensuring all our personnel remain ready to meet the challenges of competition, crisis, and conflict in and through cyberspace. We are working to cultivate uniformed cyber leaders at all levels, up to and including the officers who will eventually succeed me in this post. Furthermore, USCYBERCOM’s authorities as Joint Cyberspace Trainer facilitates joint training standards across the entire Department, boosting DoW’s ability to defend networks while enabling CMF teams to focus on hunting and contesting foreign adversaries. USCYBERCOMの取り組みは、要員が維持する主体性、意欲、そして卓越性に依存しています。サイバー空間内およびサイバー空間を通じた競争、危機、紛争の課題に全要員が常に対応できるよう確保しつつ、重要な専門知識を持つ人材を採用・定着させなければなりません。我々は、最終的にこのポストで私の後任となる将校を含む、あらゆるレベルの制服を着たサイバーリーダーを育成するために取り組んでいます。さらに、合同サイバー空間訓練機関としてのUSCYBERCOMの権限は、国防総省全体における合同訓練基準の整備を促進し、国防総省のネットワーク防衛能力を強化すると同時に、CMF(サイバー戦部隊)チームが外国の敵対勢力の追跡と対抗に注力できるようにしています。
The Department of the Army acts as our Combatant Command Support Agency. Army specialists are helping us fill our civilian billets and facilitating hiring actions to onboard exceptional civilians across the Command. We are leveraging the DoW Cyber Excepted Service authority to streamline civilian hiring and offer competitive employment incentives. We also employ special hiring authorities offered in 10 U.S.C. 4092 to attract top technical talent to join USCYBERCOM, and look forward to hiring more experts in 2026. 陸軍省は、我々の戦闘指揮部支援機関としての役割を果たしています。陸軍の専門家たちは、民間職の補充を支援し、司令部全体で優秀な民間人材を採用するための手続きを円滑に進めています。我々は、国防総省のサイバー例外職権を活用して民間人の採用を効率化し、競争力のある雇用インセンティブを提供している。また、10 U.S.C. 4092に規定された特別採用権限を活用し、USCYBERCOMにトップクラスの技術人材を惹きつけており、2026年にはさらに多くの専門家を採用できることを期待している。
Finally, USCYBERCOM is exploring innovative ways to enhance our capabilities using the expertise resident in the National Guard and Reserves. Our personnel operate daily alongside activated members of the Reserve Component integrated into our teams, and we collaborate with National Guard units on State Active Duty and State Partnership Program engagements. We look forward to expanding ways to make the Reserve Component integral to our efforts. In particular, in a hearing before this committee on CYBERCOM 2.0, we noted options to improve USCYBERCOM’s ability to leverage expertise in the Guard and Reserve, such as the establishment of a Joint Cyber Reserve Component or funded reimbursable authority. 最後に、USCYBERCOMは、州兵および予備役が有する専門知識を活用して能力を強化するための革新的な方法を模索しています。当司令部の人員は、チームに統合された予備役構成員の動員要員と日々連携して活動しており、州兵部隊とは、州動員任務や州パートナーシップ・プログラムにおける活動において協力しています。予備役構成員を当司令部の取り組みに不可欠な存在とするための方法をさらに拡大していくことを期待しています。特に、本委員会における「CYBERCOM 2.0」に関する公聴会では、合同サイバー予備役部隊の創設や資金提供可能な償還権限の付与など、USCYBERCOMが州兵および予備役の専門知識を活用する能力を向上させるための選択肢について言及しました。
CONCLUSION 結論
U.S. Cyber Command creates advantage for the Joint Force, for the Department, for our partners at home and abroad, and for the nation. We operate in and through cyberspace to support national strategic goals and set conditions for the Joint Force to prevail in crisis and win our nation’s wars. We must do so with greater agility and at a larger scale in 2026 because the United States and our allies face increasingly dangerous cyber threats from both state and non-state actors. We are meeting that need, and posturing our people and organization to accelerate their efforts. And we proceed with scrupulous regard for the privacy and civil liberties of U.S. persons, and in an objective, non-partisan manner. 米国サイバーコマンドは、統合軍、国防総省、国内外のパートナー、そして国家のために優位性を創出します。我々は、国家の戦略的目標を支援し、危機において統合軍が優位に立ち、国家の戦争に勝利するための条件を整えるべく、サイバー空間において、またサイバー空間を通じて活動しています。米国および同盟国は、国家主体および非国家主体双方からのますます危険なサイバー脅威に直面しているため、2026年には、より高い機動力とより大規模な規模でこれを行う必要があります。我々は、そのニーズに応え、人員と組織体制を整え、取り組みを加速させています。そして我々は、米国人のプライバシーと市民的自由を厳格に尊重し、客観的かつ超党派的な姿勢で活動を進めている。
Our operational experience at USCYBERCOM reinforces the central role of cyberspace in enhancing Joint Force combat credibility, lethality, and deterrence and contributing to overall national strategic objectives. The Command is executing its Service-like authorities to set and validate requirements, to plan and execute programs, and to administer budgets and resources. It is working with the Services to organize, train, and equip the nation’s military cyber force, sustaining its readiness. USCYBERCOM’s goal now is promoting mastery in our personnel by using the new resources and authorities Congress and the Executive Branch have provided. I am dedicated to creating a more lethal cyber force, operating with the speed, scale, agility, and precision required in the cyber strategic landscape. USCYBERCOMにおける我々の作戦経験は、合同部隊の戦闘信頼性、殺傷能力、抑止力を高め、国家の戦略的目標全体に貢献する上で、サイバー空間が果たす中心的な役割を裏付けている。本司令部は、各軍と同様の権限を行使し、要件の設定と検証、計画とプログラムの遂行、予算と資源の管理を行っている。また、各軍と連携し、米国の軍事サイバー部隊の編成、訓練、装備を整え、その即応態勢を維持しています。USCYBERCOMの現在の目標は、議会および行政府から付与された新たな資源と権限を活用し、要員の能力を向上させることです。私は、サイバー戦略環境において求められる速度、規模、機動力、そして精度をもって運用できる、より強力なサイバー部隊の構築に尽力しています。
The warfighters at USCYBERCOM are grateful for the partnership with your Committee. I am proud and somewhat humbled that the President and the Congress have entrusted to me the duty of leading and representing our Service members and civilians, and I look forward to demonstrating how they are effectively managing their responsibilities, employing the resources that you have provided, and accomplishing our missions to defend our nation. With continued strong partnership with Congress, we will succeed. Thank you. USCYBERCOMの戦士たちは、貴委員会との連携に深く感謝しております。大統領および議会が、我が軍の将兵と文官を率い、代表する責務を私に託してくださったことを誇りに思うと同時に、謙虚な気持ちにもなっております。彼らが如何に効果的に責任を果たし、皆様から提供された資源を活用し、国家防衛という我々の任務を遂行しているかを示すことを楽しみにしております。議会との強固な連携を継続することで、我々は成功を収めるでしょう。ありがとうございました。

 

1_20260607220001

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2026.05.06 もし、国民の政治への関心が高くなく、マスコミが現政府の政策に対して積極的に批判をしない社会において情報機関の機能強化が行われた場合、どのような社会になりそうか?

 

・2026.04.10 内閣官房 国家情報会議設置法案他 (2028.03.13-04.07)

 

・2026.03.24 米国 ODNI 2026 米国インテリジェンス・コミュニティの年次脅威アセスメント (2026.03.18)

・2026.01.26 欧州 EDPB EU-米国データ・プライバシー枠組みに関するFAQ等 (2026.01.23)

 

・2025.11.17 米国 国家情報長官室の話...

 

・2025.10.24 オーストラリア サイバー脅威年次報告 2024-2025

・2025.09.10 カナダ 通信保安庁 年次報告書 2024-2025 (2025.06.27)

・2025.03.28 米国 ODNI 2025 米国インテリジェンス・コミュニティの年次脅威アセスメント (2025.03.25)

・2024.08.29 OXFORD JOURNAL of Cybersecurity 戦争においてサイバー作戦の有用性は限界的

・2024.03.14 米国 インテリジェンス・コミュニティによる2024年の脅威評価 

・2023.09.27 米国 国家情報局 ナカソネ将官、サイバーセキュリティとシギントの将来について洞察を語る

 

・2023.08.11 米国 国家情報戦略 2023

 

・2023.07.31 米国 FBI長官がサイバー脅威サミットで人工知能に対するFBIの姿勢を示す

・2023.04.09 米国 インテリジェンスコミュニティーによる2023年脅威評価 (2023.02.06)

・2023.03.02 EDPB EU-米国データ・プライバシー・フレームワークにおける改善を歓迎するが、いいたいことは54ページ分ほどある(^^)

・2022.12.16 欧州委員会 米国との安全なデータの流れを確保するための適切な決定の採択に向けたプロセスを開始

・2022.10.11 米国 米国におけるシグナル・インテリジェンス活動のための安全保障の強化に関する大統領令(GDPR対応)

・2022.06.04 米国 FBI サイバーセキュリティに関するボストン会議2022でのFBI長官の基調講演

2022.03.27 米国と欧州委員会が米国ー欧州間のデータプライバシーフレームワークに合意したと発表していますね。。。

・2021.06.06 米国 インテリジェンスコミュニティーによる2021年脅威評価 by ODNI at 2021.04.09

・2021.03.28 EU-USプライバシーシールドを強化するための交渉を推進 - 米国商務長官と欧州司法長官による共同記者会見

・2020.08.13 プライバシーシールド無効の判決を受けて、米国商務長官と欧州司法長官が共同プレス声明していますね

・2020.07.21 プライバシーシールド無効判決後のアメリカとイギリス

 

・2020.07.16 EU-USのプライバシーシールドを無効にしま〜す by EU裁判所

 

Continue reading "米国 USCYBERCOM 司令官による2026年姿勢表明書 (2026.06.05)"

| | Comments (0)

2026.06.07

経済産業省 産業サイバーセキュリティ研究会 WG3 サイバーセキュリティ・サービス事業者の信頼性強化に向けた検討会 中間とりまとめ (2026.06.05)

こんにちは、丸山満彦です。

地味に発表していますが、サイバーセキュリティ関連事業を(特に、「情報セキュリティサービス審査登録制度」を利用)している企業にとっては、影響のある話です...

サイバーセキュリティ・サービス提供事業者に起因する機微情報流出等のリスクに対応するため、政府機関・重要インフラ、安全保障に関係する事業者等が「適切な運営体制」を有しているサービス提供事業者を選定、活用できる制度を経済産業省が検討しています。

その検討状況を中間とりまとめとして公表していますね...

私もこの制度を検討する委員です...

まず、この検討している制度を理解する前提として「情報セキュリティサービス審査登録制度」について説明しますね...

この制度は、経済産業省の施策で、IPAが運営を行っています。審査と登録企業の台帳については、JASAが運営しています。

情報セキュリティサービスについては、

(1)情報セキュリティ監査サービス
(2)脆弱性診断サービス及びペネトレーションテスト(侵入試験)サービス
(3)デジタルフォレンジックサービス
(4)セキュリティ監視・運用サービス
(5)機器検証サービス

の5種類があり、それぞれの登録サービス数は、以下のようになっています。

 

サービス分野 件数
情報セキュリティ監査サービス 84 
脆弱性診断サービス 188 
( )内は、ペネトレーションテスト(侵入試験)サービスオプションありの件数 (51)
デジタルフォレンジックサービス 43 
セキュリティ監視・運用サービス 51 
機器検証サービス 32 
合計 398 

 

どのようなサービスが登録されているかは、JASAの情報セキュリティサービス台帳のウェブページから検索できます。


今回は、これらの登録サービスを運営している会社について、さらに「適切な運用体制」をとっているか?ということを確認できる制度を検討しているということになります。

経済安保情報についての取り扱いは、いわゆるセキュリティクリアランス制度で対応をすることになりますが、CUI(Controlled Unclassified Information)的な情報を取り扱いをする対象に対する情報セキュリティサービスをする組織が適切であるかを確認できる制度となります。

ただ、その情報の重要性については、グラデーションがあることから、一律にレベルを定めるのではなく、一定レベルの基準を満たした上でさらにどのような運用体制をとっているのか、確認ができるようにする制度を考えています。

例えば、サプライチェーンセキュリティ評価制度(SCS評価制度)の★4ISMSの両方を取得していること...ということも考えています...

予定を超える?議論を重ねてこの中間報告を公表しています...

ということを頭に入れながら...

 

経済産業省 - 産業サイバーセキュリティ研究会 - WG3 - サイバーセキュリティ・サービス事業者の信頼性強化に向けた検討会

・2026.06.05 産業サイバーセキュリティ研究会 ワーキンググループ3 サイバーセキュリティ・サービス事業者の信頼性強化に向けた検討会 中間とりまとめ

・・間とりまとめ(概要)

20260607-12958

 

・・中間とりまとめ

20260607-21237

関係すると思われる事業者の方はよく読んでおいた方が良いと思います。また、考え方に対する意見があれば、それも伝えた方が良いと思います。

 

 

参考

◼️ 今回の制度を検討している委員会

経済産業省 - 産業サイバーセキュリティ研究会 - WG3(産業振興・人材育成)

サイバーセキュリティ・サービス事業者の信頼性強化に向けた検討会

2026.06.05 中間とりまとめ 発表資料 中間とりまとめ(概要)
中間とりまとめ
2026.06.01 第5回 開催資料 資料1 議事次第・配布資料一覧
資料2 委員等名簿
資料3 事務局説明資料
議事要旨  
2026.02.17 第4回 開催資料 資料1 議事次第・配布資料一覧
資料2 委員等名簿
資料3 事務局説明資料(非公表)
議事要旨  
2025.12.19 第3回 開催資料 資料1 議事次第・配布資料一覧
資料2 委員等名簿
資料3 事務局説明資料(非公表)
議事要旨  
2025.10.08 第2回 開催資料 資料1 議事次第・配布資料一覧
資料2 委員等名簿
資料3 株式会社ラック 発表資料(非公表)
資料4 日本電気株式会社 発表資料(非公表)
資料5 独立行政法人情報処理推進機構(IPA)発表資料
資料6 事務局説明資料(一部非公表)
議事要旨  
2025.08.18 第1回 開催資料 資料1 議事次第・配布資料一覧
資料2 委員等名簿
資料3 本検討会の運営について
資料4 サイバーセキュリティ・サービス事業者の信頼性強化に向けた検討について(一部非公開)
資料5 情報セキュリティサービス審査登録制度における審査の課題(特定非営利活動法人日本セキュリティ監査協会 永宮様からの情報提供)(非公開)
議事要旨  

 

 

 

 

◼️ 情報セキュリティサービス審査登録制度

制度全般

● 経済産業省

情報セキュリティサービス審査登録制度

・・2026.03.31 [PDF] 情報セキュリティサービス基準第4.1版

・・2026.03.31 [PDF] 情報セキュリティサービスにおける技術及び品質確保に資する取組の例示令和7年3月版

・・2026.03.31 [PDF] 情報セキュリティサービスに関する審査登録機関基準第2.1版

 

適合サービスリスト

● IPA情報セキュリティサービス基準適合サービスリスト

・[PDF] 情報セキュリティ監査サービス

・[PDF] 脆弱性診断サービス

 ・[PDF] ペネトレーションテスト(侵入試験)サービス

・[PDF] デジタルフォレンジックサービス

・[PDF] セキュリティ監視・運用サービス

・[PDF] 機器検証サービス

 

サービス検索、審査登録

日本セキュリティ監査協会 (JASA) 情報セキュリティサービス基準審査登録制度

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2025.09.07 国家サイバー統括室 (NCO) 政府機関等の対策基準策定のためのガイドライン(令和7年度版)の一部改訂 (2025.09.05)

・2020.07.01 経済産業省 第5回 産業サイバーセキュリティ研究会

 

| | Comments (0)

2026.06.06

JNSA CISOがおさえておきたいAIセキュリティの基本 (2026.05.25)

こんにちは、丸山満彦です。

JNSAが、「CISOがおさえておきたいAIセキュリティの基本」を公表しています...

一般企業、つまりAIを主に利用する企業のCISOが理解しておいたほうがよいAIセキュリティの基本について、AIの仕組みの図解も交えながら、丁寧に説明しています...

Nythosの何が問題なのかなども説明しています...

この文書の主要な制作者の高橋正和さんが、1990年代からサイバーセキュリティに関わってきて、現在はAI会社(Preferred Networks)のCISOですからね...

 

文書の主な範囲...

20260605-01731

 

 

● JNSA

・2026.05.25「CISOがおさえておきたいAIセキュリティの基本」

・[PDF

20260605-01602

 

で...

20260605-02737

 

参考になります...

 

| | Comments (0)

2026.06.05

米国 NIST SP 800-238 2025会計年度サイバーセキュリティおよびプライバシー年次報告書

こんにちは、丸山満彦です。

NISTが2025年の成果について報告書を公表していますね...

昨年の報告書から新しい番号がつく報告書は1つしか出していないってことですね...

 

● NIST - ITL

・2026.05.21 NIST SP 800-238 Fiscal Year 2025 Cybersecurity and Privacy Annual Report

 

NIST SP 800-238 Fiscal Year 2025 Cybersecurity and Privacy Annual Report NIST SP 800-238 2025会計年度サイバーセキュリティおよびプライバシー年次報告書
Abstract 概要
Throughout Fiscal Year 2025 (FY 2025) — from October 1, 2024, through September 30, 2025 — the NIST Information Technology Laboratory (ITL) Cybersecurity and Privacy Program successfully responded to numerous challenges and opportunities in security and privacy. This Annual Report highlights the ITL Cybersecurity and Privacy Program’s FY 2025 research activities, including the ongoing participation and development of international standards, research, and practical applications in several key priority, including improved software and supply chain cybersecurity, work on IoT cybersecurity guidelines, National Cybersecurity Center of Excellence (NCCoE) projects, a new comment site for NIST’s Risk Management Framework, the release of a Phish scale, and progress in the Identity and Access Management program. 2025会計年度(FY 2025)——2024年10月1日から2025年9月30日まで——を通じて、NIST情報技術研究所(ITL)サイバーセキュリティ・プライバシー・プログラムは、セキュリティとプライバシーにおける数多くの課題と機会に対し、適切に対応した。本年次報告書では、ITLサイバーセキュリティ・プライバシー・プログラムの2025会計年度の研究活動について概説する。これには、国際標準への継続的な参画と策定、ソフトウェアおよびサプライチェーンのサイバーセキュリティ強化、IoTサイバーセキュリティガイドラインに関する取り組み、 国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)のプロジェクト、NISTリスクマネジメントフレームワーク向けの新しいコメントサイト、フィッシング・スケールの公開、およびID・アクセス管理プログラムの進展などが含まれる。

 

・[PDF] SP.800-238

20260604-54525

・[DOCX][PDF] 仮訳

 

 

FOREWORD まえがき  
Cryptography 暗号 詳細
Cybersecurity & AI サイバーセキュリティとAI 詳細
Education & Workforce 教育・人材育成 詳細
Hardware & Software Security ハードウェアおよびソフトウェアのセキュリティ 詳細
Infrastructure Security インフラセキュリティ 詳細
Risk Management リスクマネジメント 詳細

 

過去の目次...

2025 2024 2023 2022 2021 2020 2019 2018 2017
SP800-238 SP800-236 SP800-229 SP800-225 SP800-220 SP800-214 SP800-211 SP800-206  SP800-203
暗号 暗号 暗号 暗号 暗号の標準と検証 サイバーセキュリティの啓発と教育  サイバーセキュリティとプライバシーの標準化の進化 サイバーセキュリティとプライバシー基準の推進 国際ITセキュリティ標準へのITLの関与
サイバーセキュリティとAI 教育・人材 教育、トレーニング、人材開発  教育、トレーニング、人材開発 サイバーセキュリティの測定 アイデンティティとアクセス管理 リスク管理の強化 リスクマネジメントの強化 リスク管理
教育・人材育成 新興技術 新興技術  アイデンティティとアクセス管理 教育と労働力 測定基準と測定 暗号標準と検証の強化 暗号の標準と検証の強化 バイオメトリクス標準と関連する適合性評価試験ツール
ハードウェアおよびソフトウェアのセキュリティ 人間中心のサイバーセキュリティ 人間中心のサイバーセキュリティ プライバシー アイデンティティとアクセス管理 リスクマネジメント 先端サイバーセキュリティ研究・応用開発 サイバーセキュリティの研究・応用開発の推進 サイバーセキュリティアプリケーション
インフラセキュリティ アイデンティティとアクセス管理 アイデンティティとアクセス管理 リスクマネジメントと計測 プライバシーエンジニアリング プライバシーエンジニアリング  サイバーセキュリティについての意識向上、トレーニング、教育、人材育成 サイバーセキュリティの意識向上、トレーニング、教育、人材開発 ソフトウェアの保証と品質
リスクマネジメント プライバシー プライバシー 信頼できるネットワークとプラットフォーム リスクマネジメント 新規技術 アイデンティティとアクセス管理の強化 アイデンティティとアクセス管理の強化 連邦サイバーセキュリティ調査研究
  リスクマネジメント リスクマネジメント 利用可能なサイバーセキュリティ 信頼できるネットワーク 暗号の標準化と検証 通信・インフラ保護の強化 必インフラストラクチャの保護強化  コンピュータ・フォレンジック
  信頼されるネットワークとプラットフォーム 信頼できるネットワークとプラットフォーム   信頼できるプラットフォーム 信頼性の高いネットワーク 新技術の確保 新規技術の保護 サイバーセキュリティに関する知識・訓練・教育・アウトリーチ
  国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE) NIST 国立サイバーセキュリティ・センター・オブ・エクセレンス     信頼性の高いプラットフォーム セキュリティテストと測定ツールの進化 セキュリティのテストと測定ツールの推進 暗号標準化プログラム
                バリデーションプログラム
                ID ・アクセス管理
                新規技術の研究
                ナショナル・サイバーセキュリティ・センター・オブ・エクセレンス
(NCCoE)
                インターネットインフラ保護
                高度なセキュリティ試験と測定
                技術的な安全性の指標
                利便性とセキュリティ

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2025.05.03 米国 NIST SP 800-236 2024会計年度サイバーセキュリティ・プライバシー年次報告書 (2025.04.28)

・2024.05.24 米国 NIST SP 800-229 2023会計年度サイバーセキュリティ・プライバシー年次報告書

・2023.06.09 NIST SP 800-225 2022年度サイバーセキュリティ・プライバシー年次報告書 (2023.05.30)

・2022.10.02 NIST SP 800-220 2021年度サイバーセキュリティ・プライバシー年次報告書 (2022.09.26)

・2021.10.01 NIST SP 800-214 2020年度サイバーセキュリティ・プライバシー年次報告書

・2020.08.26 NIST/ITLのサイバーセキュリティプログラム年次報告書2019

・2020.03.15 NIST SP 800-206 Annual Report 2018: NIST/ITL Cybersecurity Program

| | Comments (0)

2026.06.04

米国 NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ (2026.05.21)

こんにちは、丸山満彦です。

NISTがSP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティを公表し、意見募集をしていますね...

附属書にあるシナリオは、各シナリオはNISTIR 8428(OT向けDFIRフレームワーク)のワークフローに従い、検知から封じ込め、根絶、復旧までの技術的・手順的ステップを詳細に解説しています...

可用性が高く求められるシステムについては、完全に防御できるわけではないという前提のもと、復旧計画とそれに従った準備が必要で、昔から金融機関の対策として同じといえば、同じ考え方ですかね...

 

NIST - ITL

・2026.05.21 NIST SP 1800-41 (Initial Public Draft) Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector

NIST SP 1800-41 (Initial Public Draft) Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector NIST SP 1800-41(初期ドラフト) サイバー攻撃への対応と復旧:製造業セクターのためのサイバーセキュリティ
Announcement お知らせ
The NIST National Cybersecurity Center of Excellence (NCCoE) has released this initial public draft NIST Cybersecurity Practice Guide, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026. NIST国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、産業用制御システム(ICS)環境における対応および復旧活動に関するガイドラインと、運用レジリエンスを向上させるための推奨事項を提示する、本NISTサイバーセキュリティ実践ガイドの初期ドラフトを公表した。本出版物に対する意見募集期間は2026年7月8日までである。
Background 背景
As Operational Technology (OT) systems like ICS become increasingly interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience. ICSのような運用技術(OT)システムがITネットワークとますます相互接続されるにつれ、これらはサイバー脅威の標的となりやすくなっており、工場の操業、安全、および資産にリスクを招いている。製造事業者などのこれらのシステムを運用する組織は、サイバーインシデントに対応し、操業を復旧させて全体的なレジリエンスを向上させるための計画と能力を整備する必要がある。
The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities. NCCoEは11の業界パートナーと協力し、リファレンスアーキテクチャの策定、対応および復旧シナリオの記述、関連するアプローチや能力の実証を行った。
This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to: 本ドラフトは、製造環境におけるサイバー攻撃への対応および復旧に関する実践的なガイドラインを提供する。以下の方法について確認できる:
・Understand the risks and potential impact of cyber incidents on your operations ・サイバーインシデントが業務に及ぼすリスクと潜在的な影響を理解する
・Develop a comprehensive response and recovery plan ・包括的な対応および復旧計画を策定する
・Implement best practices to minimize downtime and restore operations quickly ・ダウンタイムを最小限に抑え、迅速に業務を復旧させるためのベストプラクティスを実施する
Comment Now! 今すぐコメントを!
We encourage you to review the publication and share your feedback by July 8, 2026. If you’re interested in staying up-to-date on this project, you can join the NCCoE Manufacturing Community of Interest by signing up on our project page. 2026年7月8日までに、本資料を確認し、フィードバックを共有することを推奨する。本プロジェクトの最新情報を入手したい場合は、プロジェクトページから登録して、NCCoE製造関心コミュニティに参加することができる。
Abstract< 概要
Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience. 製造環境を運用する産業用制御システム(ICS)は、サプライチェーンにおいて極めて重要な役割を果たしている。製造事業者は、一般消費向けの製品を生産する物理的プロセスを監視・制御するために、制御システムに依存している。しかし、これらのシステムはサイバーインシデントの増加に直面しており、安全性や生産に対する現実的な脅威となり、製造事業者の経済的パフォーマンスに影響を及ぼしている。多層防御のセキュリティアーキテクチャはサイバーリスクの緩和に役立つが、すべてのサイバーリスクを排除することはできない。したがって、製造事業者は、サイバーインシデントが業務に影響を与えた場合に備え、業務を復旧・回復させる計画も策定すべきである。本実践ガイドでは、業界の協力者と共に策定した様々なサイバー攻撃シナリオを紹介し、製造環境における対応および復旧措置の採用と実施を可能にする方法論を提示することで、業務のレジリエンスを強化する。

 

・[PDF]  sp1800-41ipd

20260603-55146

 

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
Manufacturing systems play a critical role in the supply chain and are essential to the nation’s economic security. Manufacturing organizations rely on Industrial Control Systems (ICS) to monitor and control physical processes to improve business agility and operational efficiencies. These same systems are facing an increasing number of cyber incidents from destructive malware, malicious insider activity, hardware failures, or unintended human error. Potential outages can be significant in scope and downtime, and may result in a loss of production, affecting safety controls for personnel, or the loss of millions of dollars to the organization. While defense-in-depth security architecture can help mitigate these risks, it cannot guarantee the elimination of cyber incidents. Therefore, manufacturing organizations should have a plan in place to maintain a resilient infrastructure in the event of cyber incidents that impact operations. To help with these challenges, this practice guide was developed using the NIST Cybersecurity Framework (CSF) 2.0 [1] as the basis for a response and recovery effort. The CSF defines standardized outcomes upon which organizations can base response and recovery objectives.  製造システムはサプライチェーンにおいて極めて重要な役割を果たしており、国家の経済的安全保障に不可欠である。製造企業は、ビジネスの俊敏性と運用効率を向上させるため、物理的プロセスの監視と制御に産業用制御システム(ICS)に依存している。しかし、これらのシステムは、破壊的なマルウェア、内部関係者による悪意のある活動、ハードウェアの故障、あるいは意図しない人的ミスなど、増加するサイバーインシデントに直面している。発生しうる停止は、その規模やダウンタイムが甚大であり、生産の損失、従業員の安全制御への影響、あるいは組織にとって数百万ドル規模の損失につながる可能性がある。多層防御のセキュリティアーキテクチャはこれらのリスクを緩和するのに役立つが、サイバーインシデントの完全な排除を保証することはできない。したがって、製造事業者は、業務に影響を及ぼすサイバーインシデントが発生した場合に備え、レジリエンスを持つインフラを維持するための計画を策定しておくべきである。こうした課題への対応を支援するため、本実践ガイドは、対応および復旧活動の基盤としてNISTサイバーセキュリティフレームワーク(CSF)2.0 [1] を用いて作成された。CSFは、組織が対応および復旧の目標を策定するための基準となる標準化された成果を定義している。
For organizations without established cybersecurity controls, establishing and implementing response and recovery procedures can be a daunting task. In addition, guidelines and frameworks alone can be difficult to follow without practical applications. In response, the National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) worked with stakeholders and industry collaborators specializing in response and recovery to demonstrate the practical application of cybersecurity technologies in a discrete-based manufacturing system that emulates a typical manufacturing environment. The effort resulted in this Practice Guide, providing three functional scenarios that demonstrate implementation of response and recovery procedures using commercially available technologies. The aim is to illustrate effective execution of response and recovery fundamentals, as well as highlight the benefits that result from the deployment of technologies that improve operational resilience.  確立されたサイバーセキュリティ対策を持たない組織にとって、対応および復旧手順の策定と実施は困難な課題となり得る。さらに、ガイドラインやフレームワークだけでは、実用的な応用がなければ従うのが難しい場合もある。これに対応するため、国立標準技術研究所(NIST)の国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)は、対応および復旧を専門とするステークホルダーや業界パートナーと協力し、典型的な製造環境を模したディスクリート型製造システムにおいて、サイバーセキュリティ技術の実用的な応用を実証した。この取り組みの結果として作成された本実践ガイドでは、市販の技術を用いた対応および復旧手順の実装を示す3つの機能シナリオを提供する。その目的は、対応および復旧の基本原則の効果的な実行を具体例で示すとともに、運用レジリエンスを向上させる技術の展開によって得られるメリットを強調することにある。
Key takeaways from the development of this Practice Guide are as follows:  本実践ガイドの作成を通じて得られた主な知見は以下の通りである:
•  Planning and preparation are critical in responding to and recovering from cyber incidents, since risks still exist despite efforts to implement defense-in-depth protections against known threats.  •  既知の脅威に対する多層防御の導入に努めてもリスクは依然として存在するため、サイバーインシデントへの対応および復旧においては、計画と準備が極めて重要である。
•  Logging and visibility across assets and the supporting ecosystem improve investigation, diagnostics, and protection, and shorten the time between detection and containment.  •  資産および支援エコシステム全体にわたるロギングと可視化は、調査、診断、保護を向上させ、検知から封じ込めまでの時間を短縮する。
•  Robust monitoring goes beyond simple event logging and should include behavioral analysis and ongoing coordination between the OT engineering and the Security Operations Center (SOC) team.  •  堅牢な監視は単なるイベントロギングにとどまらず、振る舞い分析や、OTエンジニアリングチームとセキュリティ・オペレーションセンター(SOC)チーム間の継続的な連携を含めるべきである。
•  Human factors, such as employee training on the stages of response and recovery, communicating between IT and ICS administrators, and working with OT product vendors, will allow for effective plan implementation in addition to technical solutions. •  対応および復旧の各段階に関する従業員のトレーニング、ITとICS管理者間のコミュニケーション、OT製品ベンダーとの連携といった人的要因は、技術的ソリューションに加え、効果的な計画の実行を可能にする。

 

目次...

Contents  目次
Executive Summary エグゼクティブサマリー
1  Introduction 1 序論
1.1  Scope 1.1  範囲
1.2 Audience 1.2 対象読者
1.3 How to Use This Guide 1.3 本ガイドの活用方法
2 Project Overview 2 プロジェクト概要
2.1  Project Approach & Assumptions 2.1  プロジェクトのアプローチと前提条件
2.2  Response and Recovery Challenges 2.2  対応および復旧における課題
2.3  Project Collaborators 2.3  プロジェクト協力者
2.4  Build Architecture & Collaborator 2.4  ビルドアーキテクチャと協力者
2.4.1  Product Control Mappings 2.4.1  製品管理マッピング
2.4.2  Build Components 2.4.2  ビルドコンポーネント
2.4.3  Build Details 2.4.3  ビルドの詳細
2.5  Assumptions 2.5  前提条件
2.5.1  Attack Assumptions 2.5.1  攻撃に関する前提条件
2.5.2 Preparation Assumptions 2.5.2 準備に関する前提条件
2.5.3 General Project Assumptions 2.5.3 プロジェクト全般に関する前提条件
3  Functional Demonstrations 3  機能デモ
3.1  Demonstration Methodology 3.1  デモの方法論
3.2  Demonstration Use Cases 3.2  デモのユースケース
3.2.1  Scenario A: Compromise Human Machine Interface (HMI) or Operator Console 3.2.1  シナリオA:ヒューマン・マシン・インターフェース(HMI)またはオペレーターコンソールの侵害
3.2.2  Scenario A: Response Execution 3.2.2  シナリオ A:対応の実行
3.2.3  Scenario A: Recovery Execution 3.2.3  シナリオ A:復旧の実行
3.2.4  Scenario B: Data Exfiltration 3.2.4  シナリオ B:データの持ち出し
3.2.5  Scenario B: Response Execution 3.2.5  シナリオ B:対応の実行
3.2.6  Scenario B: Recovery Execution 3.2.6  シナリオ B:復旧の実行
3.2.7  Scenario C: Unauthorized Command Message 3.2.7  シナリオ C:不正なコマンドメッセージ
3.2.8  Scenario C: Response Execution 3.2.8  シナリオ C:対応の実行
3.2.9  Scenario C: Recovery Execution 3.2.9  シナリオ C:復旧の実行
4  General Findings 4  一般的な調査結果
Appendix A List of Acronyms 附属書 A 略語一覧
Appendix B References 附属書 B 参考文献
Appendix C Build Implementation Instructions 附属書 C ビルド実装手順
C.1  Scenario A: Technical Details - Preparation C.1  シナリオ A:技術的詳細 - 準備
C.1.1  Creating a Splunk Dashboard to detect USB Activity C.1.1  USB アクティビティを検知するための Splunk ダッシュボードの作成
C.1.2  Backup the Rockwell PanelView™ HMI C.1.2  Rockwell PanelView™ HMIのバックアップ
C.1.3  ForceField Zero Trust Storage C.1.3  ForceField Zero Trust Storage
C.1.4  FactoryTalk® Logs in Windows Event Viewer C.1.4  Windowsイベントビューアー内のFactoryTalk®ログ
C.2  Scenario A: Technical Details – Response C.2  シナリオA:技術的詳細 – 対応
C.2.1  Dragos Case Creation C.2.1  Dragosケースの作成
C.2.2  Disconnect WAN from Cisco ISA Firewall C.2.2  Cisco ISAファイアウォールからのWAN切断
C.2.3  Isolation of HMI C.2.3  HMIの隔離
C.2.4  Inductive Automation, Data Historian C.2.4  Inductive Automation、データヒストリアン
C.2.5  Rockwell FactoryTalk® Transfer Utility C.2.5  Rockwell FactoryTalk® 転送ユーティリティ
C.2.6  Rockwell Automation FactoryTalk® AssetCentre, Log Review C.2.6  Rockwell Automation FactoryTalk® AssetCentre、ログの確認
C.2.7  Update Dragos Case C.2.7  Dragosケースの更新
C.2.8  Remove Virtual Machine from Network C.2.8  ネットワークからの仮想マシンの削除
C.2.9  Taking Snapshots of VMs C.2.9  仮想マシンのスナップショット取得
C.2.10 Remove Physical Device from the Network C.2.10 ネットワークから物理デバイスを削除する
C.2.11 Antivirus Scan C.2.11 ウイルススキャン
C.2.12 Search for Malicious File C.2.12 悪意のあるファイルの検索
C.2.13 Script for Finding Malicious File C.2.13 悪意のあるファイルを見つけるためのスクリプト
C.3  Scenario A: Technical Details – Recovery C.3  シナリオ A:技術的詳細 – 復旧
C.3.1  Downloading Backups from Authoritative Source C.3.1  信頼できるソースからのバックアップのダウンロード
C.3.2  Restore the HMI C.3.2  HMIの復元
C.3.3  Close Dragos Ticket C.3.3  Dragosチケットのクローズ
C.4  Scenario B: Technical Details – Preparation C.4  シナリオB:技術的詳細 – 準備
C.4.1  Configuring Garland to Enable Multiple Detections C.4.1  Garlandの設定による複数検知の有効化
C.4.2  Creating Graphic Interface in ConsoleWorks C.4.2  ConsoleWorksでのグラフィカルインターフェースの作成
C.4.3  Creating a Redundant Ignition Instance in AWS C.4.3  AWSでの冗長Ignitionインスタンスの作成
C.4.4  Creating a Baseline in Dragos C.4.4  Dragosでのベースラインの作成
C.4.5  Creating a Baseline Policy in Tenable C.4.5  Tenableでのベースラインポリシーの作成
C.4.6  Creating a Splunk Dashboard for SQL protocol Activity C.4.6  SQLプロトコルアクティビティ用のSplunkダッシュボードの作成
C.5  Scenario B: Technical Details – Response C.5  シナリオB:技術的詳細 – 対応
C.5.1  Detection using Splunk Dashboard C.5.1  Splunkダッシュボードを使用した検知
C.5.2  Analyzing Tenable Alert C.5.2  Tenableアラートの分析
C.5.3  Analyzing Dragos Deviation Alert C.5.3  Dragosの逸脱アラートの分析
C.5.4  Dragos Case Management C.5.4  Dragosのケース管理
C.5.5  Isolate ICS DMZ using ISA3000 C.5.5  ISA3000を使用したICS DMZの隔離
C.5.6  Disconnect JumpHost VM from Network C.5.6  JumpHost VMのネットワークからの切断
C.5.7  Take Snapshot of JumpHost VM C.5.7  JumpHost VMのスナップショットの取得
C.5.8  Isolate Local Database and Historian Gateway C.5.8  ローカルデータベースおよびヒストリアンゲートウェイの隔離
C.5.9  Validate Redundant AWS Cloud Historian C.5.9 冗長化された AWS Cloud Historian の妥当性確認
C.5.10 Detecting Large Data Transfer in Dragos C.5.10 Dragos での大容量データ転送の検知
C.5.11 Detecting Policy Deviation in Tenable C.5.11 Tenable でのポリシー逸脱の検知
C.5.12 Browsing Packet Captures from Tenable C.5.12 Tenable からのパケットキャプチャの閲覧
C.5.13 Reviewing ConsoleWorks User Session C.5.13 ConsoleWorks ユーザーセッションの確認
C.5.14 Disable Compromised Accounts C.5.14 侵害されたアカウントの無効化
C.6  Scenario B: Technical Details – Recovery C.6  シナリオ B:技術的詳細 – 復旧
C.7  Scenario C: Technical Details – Preparation C.7  シナリオ C:技術的詳細 – 準備
C.7.1  Creating Siemens Traffic Detection Policy in Tenable C.7.1  Tenable での Siemens トラフィック検出ポリシーの作成
C.7.2  Creating Splunk dashboard for unauthorized Siemens traffic C.7.2  不正な Siemens トラフィック用の Splunk ダッシュボードの作成
C.8  Scenario C: Technical Details – Response C.8  シナリオ C:技術的詳細 – 対応
C.8.1  View Tags in Data Historian C.8.1  Data Historian でのタグの表示
C.8.2  Managing Dragos Tickets C.8.2  Dragos チケットの管理
C.8.3  Isolate ICS Network using SIBERprotect C.8.3  SIBERprotect を使用した ICS ネットワークの隔離
C.8.4  Viewing policy violations in Tenable C.8.4  Tenable でのポリシー違反の確認
C.8.5  TIA Portal Diagnostics C.8.5  TIA Portal の診断
C.8.6  Windows Task Manager C.8.6  Windows タスク マネージャー
C.8.7  Review ConsoleWorks Sessions for User Activity C.8.7  ユーザーアクティビティに関する ConsoleWorks セッションの確認
C.9  Scenario C: Technical Details – Recovery C.9  シナリオ C: 技術的詳細 – 復旧
C.9.1  TIA Portal Reinstall C.9.1  TIA Portalの再インストール
C.9.2  Download PLC Backup Program File from ForceField C.9.2  ForceFieldからのPLCバックアッププログラムファイルのダウンロード
C.9.3  Add Password and Restore from Backup with TIA Portal C.9.3  TIA Portalでのパスワード追加およびバックアップからの復元

 

20260603-83115

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

SP 800-61関連

・2026.02.02 IPA AIインシデントレスポンス・アプローチ (2025.01.09)

・2025.10.03 米国 NIST IR 8183 Rev. 2 (初期公開ドラフト) サイバーセキュリティ・フレームワーク2.0 製造業プロファイル (2025.09.29)

・2025.04.07 米国 NIST SP 800-61 Rev. 3 サイバーセキュリティリスク管理のためのインシデント対応に関する推奨事項および考慮事項:CSF 2.0 コミュニティプロファイル (2025.04.03)

・2025.01.26 米国 NIST IR 8374 Rev.1(初期公開ドラフト)ランサムウェアのリスクマネジメント: サイバーセキュリティフレームワーク2.0コミュニティ (2025.01.13)

・2024.09.02 米国 CISA サイバー報告の改善に向けた新しいポータルを開設 (2024.08.29)

・2024.04.05 米国 意見募集 NIST SP 800-61 Rev.3(初期公開ドラフト) サイバーセキュリティリスクマネジメントのためのインシデント対応の推奨と考慮事項: CSF 2.0 コミュニティプロファイル

 

IR 8428

・2022.06.25 米国 NISTIR 8428 運用技術(OT)向けデジタルフォレンジックおよびインシデント対応(DFIR)フレームワーク (2022.06.22)

 

 

| | Comments (0)

米国 NIST IR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)(2026.05.19)

こんにちは、丸山満彦です。

NISTがIR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)を公表し、意見募集をしていますね...

現在のシステムは複雑になり、システムを構成するソフトウェアもまたサプライチェーンに依存し、複雑になっている。財弱性管理を含む、ソフトウェア管理の重要性が増している一方で、ソフトウェア資産管理が適切に行えなくなっている。

ということで、連邦政府むけにブロックチェーン技術を活用したソフトウェア資産管理の概念モデル「BloSS@M」を提案しているのがこの文書ということですかね...

このBloSS@Mは、各連邦政府機関が個別に調達・ライセンス管理を行うのではなく、ブロックチェーンを用いてソフトウェアライセンスを共有資産として管理・再配分する「ソフトウェアリースサービス」モデルという感じですかね...

で、パーミッションドブロックチェーン、OSCAL、SWID、MITREフレームワーク等を統合し、

(1) 資産構成の機械可読な可視化と、脆弱性・脅威・ライセンス情報の自動関連付け

(2) 参加組織間でのソフトウェアライセンスの共有・再配分による調達効率化とコスト削減

(3) OSCALを用いた継続的評価(cATO)による、動的環境下でのリスクベース承認の実現

ということを考えているようで、継続的な運用(OSCALとの連携を含め)を非常に意識していると思います。また、調達時における類似製品の価格比較等も可能となるようにし、調達の効率化、コスト削減にも寄与しようとしているようです。

 

ブロックチェーン技術を使うメリットは、十分な信頼関係が成立していない環境においても共通の記録を維持し、資産情報を検証可能な状態で共有できることですかね...

一方、厳格なアクセス制御や(OSCALを利用した)証拠管理が必要であり、複雑な運用というのが実装にむけたチャレンジという感じですかね...

 

NIST - ITL

・2026.05.19 NIST IR 8500A (Initial Public Draft) Blockchain-Based Secure Software Assets Management (BloSS@M)

 

NIST IR 8500A (Initial Public Draft) Blockchain-Based Secure Software Assets Management (BloSS@M) NIST IR 8500A(初期ドラフト)ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)
Announcement お知らせ
NIST Internal Report (IR) 8500A ipd (initial public draft), Blockchain-Based Secure Software Assets Management (BloSS@M), outlines a modernized conceptual approach for transforming how software assets are acquired, tracked, and secured across an interagency ecosystem. NIST内部報告書(IR)8500A ipd(初期ドラフト)『ブロックチェーンベースのセキュアなソフトウェア資産管理(BloSS@M)』は、省庁間エコシステム全体におけるソフトウェア資産の取得、追跡、および保護の方法を変革するための、近代化された概念的アプローチを概説するものである。
The conceptual approach for BloSS@M was developed in consideration of federal asset inventory and management requirements — including OMB Circular A-130 and OMB M-13-13 — as well as NIST SP 800-37 and SP 800-53 guidelines. BloSS@M establishes a shared infrastructure for software acquisition that promotes asset reuse, eliminates duplicative procurement, and strengthens supply chain security at scale. Its key capabilities include: BloSS@Mの概念的アプローチは、OMB Circular A-130やOMB M-13-13を含む連邦資産の棚卸しおよび管理要件、ならびにNIST SP 800-37およびSP 800-53のガイドラインを考慮して策定された。BloSS@Mは、資産の再利用を促進し、重複した調達を排除し、大規模なサプライチェーンのセキュリティを強化する、ソフトウェア調達のための共有インフラを確立する。その主な機能は以下の通りだ:
Federal purchasing power: A consolidated model that reduces redundant spending and increases collective leverage with vendors through government-wide aggregation  連邦政府の購買力:政府全体での集約を通じて、重複した支出を削減し、プロバイダに対する集団的な交渉力を高める統合モデル
Immutable life cycle tracking: Utilizes blockchain’s tamper-resistance to provide a verifiable, continuous record of asset provenance from acquisition to retirement       改ざん不可能なライフサイクル追跡:ブロックチェーンの改ざん耐性を活用し、取得から廃棄に至るまでの資産の来歴証明に関する検証可能な継続的な記録を提供する      
Automated vulnerability management: Real-time integration with the National Vulnerability Database (NVD) to continuously surface newly disclosed vulnerabilities associated with deployed assets        自動化された脆弱性管理:National Vulnerability Database(NVD)とのリアルタイム統合により、導入済み資産に関連する新たに公開された脆弱性を継続的に特定する
Machine-processable compliance: Leverages the Open Security Controls Assessment Language (OSCAL) to enable automated risk assessments, continuous monitoring, and scalable life cycle management across heterogeneous environments 機械処理可能なコンプライアンス:Open Security Controls Assessment Language(OSCAL)を活用し、異種環境全体での自動リスクアセスメント、継続的なモニタリング、およびスケーラブルなライフサイクル管理を実現する
While BloSS@M is optimized for software, where end-to-end automation is most achievable, the approach is architected to support hardware assets when integrated with appropriate physical delivery and retrieval mechanisms. BloSS@Mは、エンドツーエンドの自動化が最も実現しやすいソフトウェア向けに最適化されているが、適切な物理的な配送・回収メカニズムと統合することで、ハードウェア資産もサポートできるよう設計されている。
Abstract 概要
The report proposes a conceptual aggregation model for software acquisitions. The proposed approach relies on the immutability and auditability of blockchain technology. The model also enables automated, dynamic queries to the National Vulnerability Database (NVD) to continuously identify newly disclosed vulnerabilities associated with leased software assets. In parallel, the digitization of asset-level security and compliance information using the Open Security Controls Assessment Language (OSCAL) supports machine-readable and tool-consumable risk assessment, continuous monitoring, and life cycle-based risk management workflows. This proposed approach could be utilized for federal software acquisition to enable interagency sharing, reuse, and lifecycle management of software assets. It also has the potential to significantly increase collective purchasing power, reduce duplicative procurements, and strengthen supply chain security and IT asset management practices. 本報告書は、ソフトウェア調達のための概念的な集約モデルを提案する。提案されたアプローチは、ブロックチェーン技術の不変性と監査可能性に依存している。また、このモデルは、National Vulnerability Database(NVD)への自動的かつ動的なクエリを可能にし、リースされたソフトウェア資産に関連する新たに公開された脆弱性を継続的に識別する。並行して、Open Security Controls Assessment Language(OSCAL)を用いた資産レベルのセキュリティおよびコンプライアンス情報のデジタル化は、機械可読かつツールで処理可能なリスクアセスメント、継続的監視、およびライフサイクルベースのリスクマネジメントワークフローを支援する。この提案されたアプローチは、連邦政府のソフトウェア調達において、ソフトウェア資産の省庁間での共有、再利用、およびライフサイクル管理を可能にするために活用できる。また、集合的な購買力を大幅に高め、重複した調達を減らし、サプライチェーンのセキュリティおよびIT資産管理の実践を強化する可能性も秘めている。

 

 

・[PDF] IR.8500A.ipd

20260602-154550

 

目次...

1. Introduction 1. 序論
2. BloSS@M: The Proposed Solution 2. BloSS@M:提案されるソリューション
2.1. BloSS@M Capabilities 2.1. BloSS@Mの機能
2.1.1. Operational Capabilities 2.1.1. 運用機能
2.1.2. Technical Capabilities 2.1.2. 技術的機能
2.2. Blossom Members ATO 2.2. BlossomメンバーのATO
3. Leveraged Technologies 3. 活用技術
3.1. Blockchain and Next Generation Access Control. 3.1. ブロックチェーンと次世代アクセス管理
3.1.1. Permissioned Blockchain 3.1.1. 許可型ブロックチェーン
3.1.2. Next Generation Access Control 3.1.2. 次世代アクセス管理
3.2. Open Security Controls Assessment Language 3.2. オープン・セキュリティ・コントロールアセスメント言語
3.3. SWID for Assets Traceability 3.3. アセットのトレーサビリティのためのSWID
3.4. Asset Security 3.4. アセットのセキュリティ
3.4.1. Secure Configuration and Controls Satisfaction With OSCAL 3.4.1. OSCALを用いたセキュアな構成と制御の適合性
3.4.2. NVD and Assets Vulnerabilities .. 3.4.2. NVDとアセットの脆弱性 ..
3.4.3. Leveraging MITRE ATT&CK and D3FEND for Software Asset Resilience Assessment 3.4.3. ソフトウェア・アセットのレジリエンスアセスメントにおけるMITRE ATT&CKおよびD3FENDの活用
4. Technologies Integration Into Blossom. 4. Blossomへの技術統合
4.1. Information Access Control in BloSS@M 4.1. BloSS@Mにおける情報アクセス管理
4.2. Onboarding Process 4.2. オンボーディングプロセス
4.2.1. OSCAL Support for cATO 4.2.1. cATOに対するOSCALのサポート
5. Use-Case-Driven Walkthrough: End-to-End Application of BloSS@M 5. ユースケース主導のウォークスルー:BloSS@Mのエンドツーエンド適用
5.1. Use Case Overview. 5.1. ユースケースの概要
5.2. Asset Discovery and Initial Filtering. 5.2. アセットの発見と初期フィルタリング
5.3. Cost and Leasing Evaluation 5.3. コストおよびリースアセスメント
5.4. Security Configuration and Control Review 5.4. セキュリティ構成および制御のレビュー
5.5. Vulnerability and Threat Analysis 5.5. 脆弱性および脅威の分析
5.6. Al-Assisted Provisional Assessment. 5.6. AIを活用した暫定アセスメント
5.7. Selection and Ongoing Monitoring.. 5.7. 選定および継続的なモニタリング
6. BloSS@M Benefits 6. BloSS@Mのメリット
References 参考文献

 

 

 

 

 

| | Comments (0)

2026.06.03

米国 大統領令 先進的人工知能(AI)のイノベーションとセキュリティの推進 (2026.06.02)

こんにちは、丸山満彦です。

先進的AIに関する大統領令が公表されていますね...

AIについても、アメリカファーストですね...

で、規制ではなく自由競争で...

国家安全保障システムや国防総省、連邦政府機関のサイバー防衛を優先するかんじですね...AIサイバーセキュリティの「クリアリングハウス(脆弱性スキャンやパッチ配布を調整する機関)」をCISAに設立すると...

 

The White House - News

・2026.06.02 PROMOTING ADVANCED ARTIFICIAL INTELLIGENCE INNOVATION AND SECURITY

PROMOTING ADVANCED ARTIFICIAL INTELLIGENCE INNOVATION AND SECURITY  先進的人工知能(AI)のイノベーションとセキュリティの推進
By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered: 米国憲法および米国法に基づき、大統領として私に付与された権限により、ここに以下の通り命ずる。
Section 1. Purpose. The United States continues to lead the world in Artificial Intelligence (AI) because of the enormous talent and innovation of our AI industry, and because we refuse to stifle this innovation with overly burdensome regulation. My Administration has unleashed tremendous technological growth and economic investment in AI by slashing the bureaucratic constraints that the prior administration placed on America’s AI developers and researchers, and by instead encouraging AI innovation and accelerating responsible AI adoption across government and industry.  第1条 目的。 米国が人工知能(AI)の分野で世界をリードし続けているのは、わが国のAI産業が持つ膨大な人材と革新力によるものであり、また、過度に負担の大きい規制によってこの革新を阻害することを拒んできたからである。わが政権は、前政権が米国のAI開発者や研究者に課していた官僚的な制約を大幅に撤廃し、その代わりにAIの革新を奨励し、政府および産業界全体における責任あるAIの導入を加速させることで、AI分野における驚異的な技術的成長と経済的投資を解き放ってきた。
Advanced AI capabilities make our Nation stronger, but also introduce new national security considerations that require coordinated action across executive departments and agencies (agencies), and components. As these capabilities evolve, my Administration will continue to work closely with industry to ensure that the best and most secure technology is deployed rapidly to confront any and all threats to our country. We will continue to lead an America First cybersecurity effort that enhances both our national security and our global AI dominance. 高度なAI能力は我が国をより強固にする一方で、行政部門や機関(エージェンシー)、および構成組織全体での協調的な行動を必要とする新たな国家安全保障上の考慮事項ももたらす。これらの能力が進化するにつれ、わが政権は産業界と緊密に連携し続け、我が国に対するあらゆる脅威に立ち向かうため、最良かつ最も安全な技術が迅速に展開されるよう確保する。我々は、国家安全保障と世界的なAI優位性の両方を強化する「アメリカ・ファースト」のサイバーセキュリティへの取り組みを引き続き主導する。
It is the policy of the United States to promote AI innovation and security by working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats; to protect American ingenuity and intellectual property from exploitation and theft by adversaries; and to cultivate America’s advanced AI-enabled capabilities. 米国の方針は、民間セクターと協力して政府および民間セクターの情報システムを近代化し、外部の脅威に対して強固なものとすることで、AIのイノベーションとセキュリティを促進することである。また、敵対者による悪用や窃取から米国の創意工夫と知的財産を防御し、米国の高度なAI活用能力を育成することである。
Sec. 2. Upgrading American Systems for Advanced AI. (a) Within 30 days of the date of this order, the Committee on National Security Systems shall prioritize the cyber defense of National Security Systems, as defined in 44 U.S.C. 3552(b)(6)(A), by taking appropriate and expeditious action consistent with the purpose of this order. 第2条 高度なAIに向けた米国システムのアップグレード。 (a) 本命令の発令日から30日以内に、国家安全保障システム委員会は、本命令の目的に沿った適切かつ迅速な措置を講じ、合衆国法典第44編第3552条(b)(6)(A)に定義される国家安全保障システムのサイバー防衛を優先するものとする。
(b) Within 30 days of the date of this order, the Secretary of War shall prioritize the cyber defense of Department of War information systems by taking appropriate and expeditious action consistent with the purpose of this order. (b) 本命令の発令日から30日以内に、陸軍長官は、本命令の目的に沿った適切かつ迅速な措置を講じ、国防総省の情報システムのサイバー防衛を優先的に実施しなければならない。
(c) Within 30 days of the date of this order, the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), in consultation with the Director of the Office of Management and Budget (OMB), the Assistant to the President for National Security Affairs, and the National Cyber Director, shall release Binding Operational Directives and other guidance as appropriate to: (c) 本命令の発令日から30日以内に、国土安全保障長官は、サイバーセキュリティ・インフラセキュリティ庁(CISA)長官を通じ、行政管理予算局(OMB)局長、大統領国家安全保障問題担当補佐官、および国家サイバー長官室と協議の上、以下の目的のために、拘束的運用指令およびその他の適切な指針を公表しなければならない:
(i) expedite and prioritize the cyber defense of civilian Federal Government information systems in order to protect our Nation’s vital functions; (i) わが国の重要機能を防御するため、連邦政府の民間情報システムのサイバー防衛を迅速化し、優先順位を付けること;
(ii) establish or expand Federal programs and cybersecurity services that enhance AI-enabled defensive tools; and (ii) AIを活用した防御ツールを強化する連邦プログラムおよびサイバーセキュリティサービスを確立または拡大すること;および
(iii) facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models for agencies, State and local authorities, and operators of critical infrastructure such as rural hospitals, community banks, and local utilities. (iii) 連邦機関、州および地方自治体、ならびに地方の病院、地域銀行、地方公益事業体などの重要インフラの運営者に対し、サイバーセキュリティツールおよびサービスへのアクセスを促進すること。これには、適切な場合には、対象となるフロンティアモデルを含む。
(d) Within 30 days of the date of this order, the Secretary of the Treasury, in consultation with the National Cyber Director, the Secretary of War, through the Director of the National Security Agency (NSA), and the Secretary of Homeland Security, through the Director of CISA, shall form an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and operators of critical infrastructure, that coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritizes remediation and distribution of vulnerability patches. (d) 本命令の発令日から30日以内に、財務長官は国家サイバー担当長官と協議の上、国防長官は国家安全保障局(NSA)局長を通じて、 並びに国土安全保障長官は、CISA長官を通じて、AI業界および重要インフラの運営者と自発的に協力し、ソフトウェアの脆弱性スキャンを調整・調整し、当該脆弱性を発見・妥当性確認し、修正および脆弱性パッチの配布を調整・優先順位付けするAIサイバーセキュリティ・クリアリングハウスを設立しなければならない。
(e) Within 30 days of the date of this order, the Director of OMB, in coordination with the National Cyber Director and the Director of CISA, shall determine whether any Federal grant programs have available and relevant funding that can be directed toward applicants developing advanced AI vulnerability detection. (e) 本命令の発令日から30日以内に、OMB長官は、国家サイバー長官室およびCISA長官と連携し、高度なAI脆弱性検知技術を開発する申請者に対して充てることができる、利用可能かつ関連性のある資金が連邦助成プログラムに存在するかどうかを判断しなければならない。
(f) Within 60 days of the date of this order, the Director of the Office of Personnel Management shall expand the United States Tech Force Information Cybersecurity Specialist hiring and placement pathways. (f) 本命令の発令日から60日以内に、人事管理局長官は、米国テックフォース情報サイバーセキュリティ専門家の採用および配置の経路を拡大しなければならない。
Sec. 3. Secure Frontier Model Deployment. Within 60 days of the date of this order, the Secretary of the Treasury, the Secretary of War, through the Director of NSA, and the Secretary of Homeland Security, through the Director of CISA, in consultation with the White House Chief of Staff, through the National Cyber Director, the Assistant to the President for Science and Technology (APST), and the Secretary of Commerce, through the Director of the National Institute of Standards and Technology, and in coordination with other agencies, as appropriate, shall: 第3条 セキュア・フロンティア・モデルの展開。本命令の発令日から60日以内に、財務長官、国防長官(NSA長官を通じて)、および国土安全保障長官(CISA長官を通じて)は、ホワイトハウス首席補佐官(国家サイバー担当長官を通じて)、大統領科学技術担当補佐官(APST)、 ならびに商務長官は、国立標準技術研究所(NIST)所長を通じて、また必要に応じて他の機関と調整の上、以下の措置を講じなければならない:
(a) develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a “covered frontier model” for the purposes of this order, sharing such assessments with AI developers and researchers as appropriate. Such a determination shall be made by the Director of NSA, in consultation with the National Cyber Director, the APST, the Director of CISA, and other representatives of the Department of War, as appropriate. (a) AIモデルの高度なサイバー能力を評価し、本命令の目的上、AIモデルを「対象フロンティアモデル」として指定すべき閾値を決定するための機密扱いのベンチマークプロセスを策定・維持し、必要に応じて当該アセスメントをAI開発者および研究者と共有すること。 かかる決定は、NSA長官が、国家サイバー担当長官、APST、CISA長官、および必要に応じて国防総省のその他の代表者と協議の上、行うものとする。
(b) design a voluntary framework with AI developers through which developers would be able to: (b) AI開発者と共に、開発者が以下を行えるような自主的なフレームワークを設計する:
(i) engage the Federal Government to determine whether model(s) under development meet the designation of “covered frontier model”; (i) 開発中のモデルが「対象フロンティアモデル」の指定要件を満たすかどうかを判断するため、政府と協議すること;
(ii) provide the Federal Government with access to covered frontier models, subject to appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements, for a period of up to 30 days before they plan to release such models to other trusted partners; and  (ii) 適切な機密保持、サイバーセキュリティ、内部者リスク、および知的財産の保護、利用、非開示の要件を遵守した上で、対象となるフロンティアモデルを、他の信頼できるパートナーに公開する予定の日から最大30日前に、連邦政府に提供すること;および 
(iii) collaborate with the Federal Government to select trusted partners that will have early access to covered frontier models to promote secure innovation and strengthen the cybersecurity of critical infrastructure. (iii) 安全なイノベーションを促進し、重要インフラのサイバーセキュリティを強化するため、対象となるフロンティアモデルに早期アクセスできる信頼できるパートナーを選定するよう、連邦政府と協力すること。
(c) Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models. (c) 本節のいかなる規定も、フロンティアモデルを含む新たなAIモデルの開発、公表、公開、または配布に対する、政府による強制的なライセンス、事前承認、または許可要件の創設を認可しない。
Sec. 4. Protection Against Criminal Actors. The Attorney General shall prioritize the enforcement of 18 U.S.C. 1028, 18 U.S.C. 1030, 18 U.S.C. 1343, and all other applicable Federal criminal laws against anyone who utilizes AI to illegally access or damage a computer without authorization, or who utilizes AI while engaged in such illegal access to further any other crime. This includes breaching any public or private information technology system, or employing AI agents to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose. 第4条 犯罪者に対する防御。 司法長官は、AIを利用して無断でコンピュータに違法にアクセスし、または損害を与える者、あるいはそのような違法なアクセスに従事する際にAIを利用してその他の犯罪を助長する者に対し、合衆国法典第18編第1028条、第1030条、第1343条、およびその他すべての適用法の執行を優先するものとする。 これには、公的または私的な情報技術システムへの侵入、あるいはAIエージェントを用いてデータや情報に不法にアクセスし、その後、犯罪的または違法な目的のために使用することが含まれる。
Sec. 5. General Provisions. (a) Nothing in this order shall be construed to impair or otherwise affect: 第5条 一般規定 (a) 本命令のいかなる規定も、以下を損なうもの、またはその他の方法で影響を及ぼすものと解釈してはならない。
(i) the authority granted by law to an executive department or agency, or the head thereof; or (i) 法律により行政部門、行政機関、またはその長に付与された権限、または
(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals. (ii) 予算、行政、または立法上の提案に関する行政管理予算局長の機能。
(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations. (b) 本命令は、適用法に従い、かつ予算の確保を条件として実施されるものとする。
(c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person. (c) 本命令は、いかなる当事者も、米国、その省庁、機関、または事業体、その職員、従業員、代理人、またはその他の者に対して、法または衡平法に基づき執行可能な、実体法上または手続法上のいかなる権利または利益も創設することを意図しておらず、また創設するものではない。
(d) The costs for publication of this order shall be borne by the Department of War. (d) 本命令の公布にかかる費用は、陸軍省が負担する。
DONALD J. TRUMP ドナルド・J・トランプ
THE WHITE HOUSE, ホワイトハウス、
June 2, 2026. 2026年6月2日。

 

・2026.06.02 Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security

Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security ファクトシート:ドナルド・J・トランプ大統領、先進的人工知能(AI)のイノベーションとセキュリティを推進
PROMOTING AMERICAN AI INNOVATION AND SECURITY: Today, President Donald J. Trump signed an Executive Order to advance American artificial intelligence (AI) innovation to strengthen America’s cybersecurity, protect critical infrastructure, and ensure the United States remains the global leader in AI innovation.  米国のAIイノベーションとセキュリティの推進:本日、ドナルド・J・トランプ大統領は、米国のサイバーセキュリティを強化し、重要インフラを防御し、米国がAIイノベーションにおける世界的なリーダーであり続けることを確保するため、米国のAIイノベーションを推進する大統領令に署名した。
・The Order directs appropriate agencies to prioritize the cyber defense of National Security Systems, Department of War information systems, and civilian Federal government information systems.  ・本大統領令は、関係機関に対し、国家安全保障システム、国防総省の情報システム、および民間連邦政府の情報システムのサイバー防衛を優先するよう指示する。
・This includes the Secretary of Homeland Security, in consultation with the Director of the Office of Management and Budget, the Assistant to the President for National Security Affairs, and the National Cyber Director, issuing binding operational directives and other guidance to facilitate access to AI-enabled cybersecurity tools and services for Federal agencies, State and local authorities, and operators of critical infrastructure, including rural hospitals, community banks, and local utilities.  ・これには、国土安全保障長官が、行政管理予算局局長、大統領国家安全保障問題担当補佐官、および国家サイバー長官室と協議の上、連邦機関、州および地方自治体、ならびに地方の病院、地域銀行、地方公益事業体を含む重要インフラの運営者に対し、AIを活用したサイバーセキュリティツールやサービスへのアクセスを促進するための拘束的運用指令やその他の指針を発出することが含まれる。
・The Order establishes an AI cybersecurity clearinghouse, in voluntary coordination with the AI industry and critical infrastructure operators, to identify and remediate software vulnerabilities at scale. ・本大統領令は、AI業界および重要インフラ運営者と自発的に連携し、ソフトウェアの脆弱性を大規模に特定・是正するためのAIサイバーセキュリティ情報共有拠点を設立する。
・The Order directs the Office of Management and Budget and the Office of Personnel Management to identify funding opportunities for advanced AI cybersecurity capabilities and expand Federal cybersecurity hiring and placement pathways.  ・本大統領令は、行政管理予算局および人事管理局に対し、高度なAIサイバーセキュリティ能力のための資金調達機会を識別し、連邦政府におけるサイバーセキュリティ人材の採用および配置経路を拡大するよう指示する。
・The Order calls for the development of a classified benchmarking process against which industry may assess their models for advanced AI cyber capabilities, identifying covered frontier models. ・本大統領令は、業界が自社のモデルを高度なAIサイバー能力の観点からアセスメントし、対象となる最先端モデルを識別するための、機密扱いのベンチマークプロセスの策定を求めている。
・The Order directs the Federal government to establish a voluntary framework in collaboration with AI developers regarding covered frontier models, which would provide the Federal government with secure early access for trusted partners to strengthen cybersecurity and promote secure innovation. ・本大統領令は、連邦政府に対し、対象となる最先端モデルに関してAI開発者と協力して自主的なフレームワークを確立するよう指示している。これにより、連邦政府は信頼できるパートナーに対して安全な早期アクセス権を提供し、サイバーセキュリティを強化するとともに、安全なイノベーションを促進することになる。
・The Order expressly states that nothing shall be construed to authorize creation of any mandatory governmental licensing, pre-clearance, or permitting requirement for the development, publication, release or distribution of AI models.  ・本大統領令は、AIモデルの開発、公表、公開、または配布に関して、政府による強制的なライセンス、事前承認、または許可要件の創設を認可してはならないことを明示している。
・The Order directs the Attorney General to prioritize enforcement against individuals who use AI to illegally access or damage computer systems, steal data, or facilitate other criminal activity.  ・本大統領令は、AIを利用してコンピュータシステムに違法にアクセスしたり損害を与えたり、データを盗んだり、その他の犯罪活動を助長したりする個人に対する取り締まりを優先するよう、司法長官に指示している。
STRIKING THE RIGHT BALANCE BETWEEN INNOVATION AND SECURITY: President Trump believes America must lead the world in AI without burdening innovators with unnecessary regulation. イノベーションとセキュリティの適切なバランス: トランプ大統領は、不必要な規制でイノベーターに負担をかけることなく、米国がAI分野で世界をリードすべきだと考えている。
・Unlike the Biden Administration’s top-down regulatory approach, President Trump is working hand-in-hand with American industry to strike the right balance between innovation and national security.  ・バイデン政権のトップダウン型の規制アプローチとは異なり、トランプ大統領は米国産業界と緊密に連携し、イノベーションと国家安全保障の適切なバランスを図っている。
・President Trump recognizes that America’s private sector leads the world in AI innovation and that government should partner with innovators – not stifle them. ・トランプ大統領は、米国の民間セクターがAIイノベーションにおいて世界をリードしていることを認識しており、政府はイノベーターを抑制するのではなく、彼らと協力すべきだと考えている。
・As AI capabilities increase, new cyber and national security considerations emerge that require coordinated action between the Federal government and the private sector. ・AIの能力が高まるにつれ、連邦政府と民間セクターの協調的な行動を必要とする、新たなサイバーセキュリティおよび国家安全保障上の課題が生じている。
・The United States must protect American ingenuity, intellectual property, and critical systems from exploitation and cyberattacks by adversaries.  ・米国は、敵対勢力による悪用やサイバー攻撃から、米国の独創性、知的財産、および重要インフラを防御しなければならない。
・President Trump and his Administration are not in the business of picking winners and losers. This Administration has one goal: ensure the best and safest tech is deployed rapidly to defeat any and all threats. ・トランプ大統領とその政権は、勝者と敗者を選別するようなことはしない。この政権には一つの目標がある。それは、あらゆる脅威を打ち負かすために、最良かつ最も安全な技術が迅速に展開されることを確実にすることだ。
・Protecting American ingenuity and critical infrastructure requires the full power of both the public and private sectors working together, and President Trump’s common-sense, America First approach will ensure the United States continues to dominate globally. ・米国の独創性と重要インフラを防御するには、官民双方の全力を結集して協力することが必要であり、トランプ大統領の常識的な「アメリカ・ファースト」のアプローチにより、米国が世界的に優位性を維持し続けることが保証される。
LEADING THE WORLD IN INNOVATION AND CYBERSECURITY: President Trump is the most forward leaning President on innovation in American history. イノベーションとサイバーセキュリティにおける世界のリーダー:トランプ大統領は、米国史上最もイノベーションに前向きな大統領である。
・Immediately upon returning to office, President Trump eliminated the Biden Administration’s overreaching and harmful AI policies, unleashing a new era of innovation.  ・再任直後、トランプ大統領はバイデン政権の行き過ぎた有害なAI政策を撤廃し、イノベーションの新時代を切り開いた。
・In July 2025, President Trump released his AI Action Plan, which called for examining and removing onerous regulations that hinder America’s ability to lead in this key technology.  ・2025年7月、トランプ大統領はAI行動計画を発表し、この重要技術における米国の主導力を阻害する過度な規制の検討と撤廃を求めた。
・In July 2025, he signed an Executive Order preventing the Federal government from using AI models that include ideological biases or social agendas. ・2025年7月、彼は、イデオロギー的なバイアスや社会的アジェンダを含むAIモデルを政府が使用することを禁止する大統領令に署名した。
・In December 2025, he signed an Executive Order to protect American AI innovation from an inconsistent and costly compliance regime resulting from varying State laws. ・2025年12月、彼は、州ごとの法律の相違に起因する一貫性を欠き、コストのかかるコンプライアンス体制から米国のAIイノベーションを防御するための大統領令に署名した。
・In March 2026, President Trump released his National Cyber Strategy for America, which outlines his priorities for ensuring that America remains unrivaled in cyberspace, calling for unprecedented coordination across government and the private sector to invest in the best technologies and continue world-class innovation, and to make the most of America’s cyber capabilities for both offensive and defensive missions. ・2026年3月、トランプ大統領は「米国のための国家サイバー戦略」を発表した。同戦略は、米国がサイバー空間において比類なき地位を維持するための優先事項を概説し、政府と民間部門の未曾有の連携を通じて最先端技術への投資と世界最高水準のイノベーションを継続し、攻撃・防御双方の任務において米国のサイバー能力を最大限に活用するよう求めている。
・In March 2026, President Trump unveiled his comprehensive national legislative framework that addresses the most pressing policy topics that AI presents. ・2026年3月、トランプ大統領は、AIが提起する最も差し迫った政策課題に対処する包括的な国家立法フレームワークを発表した。
・Today’s Executive Order advances President Trump’s ongoing effort to position the United States as the global leader in AI, cybersecurity, and next-generation technologies.  ・本日の大統領令は、AI、サイバーセキュリティ、次世代技術において米国を世界のリーダーとして位置づけるという、トランプ大統領の継続的な取り組みを推進するものである。

 

1_20260603122201¥

| | Comments (0)

中国 人工知能アプリケーションの倫理・安全ガイドライン 1.0 (2026.05.22)

こんにちは、丸山満彦です。

中国のTC260が、人工知能アプリケーションの倫理・安全ガイドライン 1.0 を公表していますね...

この文書は、AIの応用における倫理的・安全上の影響を提示し、AI応用の倫理的・安全上の理念と原則を提唱し、AIアプリケーションの開発、サービスの提供、および利用に関する安全指針を規定するものということのようです...

 

《人工智能应用伦理安全指引1.0》发布 『人工知能応用倫理・安全ガイドライン1.0』を発表
5月19日,在2026年中国网络文明大会人工智能赋能网络文明建设分论坛上,全国网络安全标准化技术委员会(以下简称“网安标委”)发布了《人工智能应用伦理安全指引1.0》(以下简称《指引》)。 5月19日、2026年中国ネットワーク文明大会の「人工知能によるネットワーク文明建設の促進」分科会において、全国サイバーセキュリティ標準化技術委員会(以下、「網安標委」)は『人工知能応用倫理・安全ガイドライン1.0』(以下、『ガイドライン』)を発表した。
为进一步引导人工智能应用坚持以人为本、智能向善,推动人工智能应用相关方正确认识和妥善应对应用活动中的伦理安全影响,促进人工智能应用在规范有序、安全可控的轨道上健康发展,《指引》给出了人工智能应用伦理安全理念与原则,明确了人工智能应用开发、服务提供和应用使用等安全指引。 人工知能(AI)の応用において「人間中心」の理念を堅持し、AIが善のために活用されるようさらに導くとともに、AI応用関係者が応用活動における倫理・安全への影響を正しく認識し適切に対処するよう促し、規範的かつ秩序ある、安全で管理可能な軌道の上でAI応用の健全な発展を促進するため、『指針』はAI応用の倫理・安全に関する理念と原則を示し、AI応用の開発、サービス提供、利用などに関する安全指針を明確にした。
网安标委秘书处相关负责同志表示,《指引》的发布,正是对引导人工智能应用尊重人的主体地位、维护公平正义、保障合法权益、促进社会信任,推动人工智能技术始终朝着有益、安全、公平方向发展这一时代课题的积极回应,体现了人工智能治理坚持积极稳妥、开放包容、协同共治的实践导向,也体现了网络文明建设对人工智能时代技术向善、价值引领和秩序塑造的主动回应。 サイバーセキュリティ標準化委員会の事務局関係責任者は、「指針」の発表は、AIの応用において人の主体的地位を尊重し、公平と正義を守り、合法的権益を保障し、社会的信頼を促進するとともに、AI技術が常に有益かつ安全で公平な方向へと発展するよう導くという時代の課題に対する積極的な対応であり、AIガバナンスが積極的かつ着実で、 開放・包容、協調・共治という実践志向を堅持していることを体現しており、また、ネットワーク文明の建設が、AI時代の「技術による善」、価値のリード、秩序の形成に対して能動的に応えていることも示している。

 

・[PDF]《人工智能应用伦理安全指引1.0》

20260602-125032

 

・[DOCX][PDF] 仮訳

 

・2026.05.22 一图读懂|TC260-005《人工智能应用伦理安全指引1.0》

 

1_20260602152401

 

| | Comments (0)

より以前の記事一覧