IoT

2026.06.05

米国 NIST SP 800-238 2025会計年度サイバーセキュリティおよびプライバシー年次報告書

こんにちは、丸山満彦です。

NISTが2025年の成果について報告書を公表していますね...

昨年の報告書から新しい番号がつく報告書は1つしか出していないってことですね...

 

● NIST - ITL

・2026.05.21 NIST SP 800-238 Fiscal Year 2025 Cybersecurity and Privacy Annual Report

 

NIST SP 800-238 Fiscal Year 2025 Cybersecurity and Privacy Annual Report NIST SP 800-238 2025会計年度サイバーセキュリティおよびプライバシー年次報告書
Abstract 概要
Throughout Fiscal Year 2025 (FY 2025) — from October 1, 2024, through September 30, 2025 — the NIST Information Technology Laboratory (ITL) Cybersecurity and Privacy Program successfully responded to numerous challenges and opportunities in security and privacy. This Annual Report highlights the ITL Cybersecurity and Privacy Program’s FY 2025 research activities, including the ongoing participation and development of international standards, research, and practical applications in several key priority, including improved software and supply chain cybersecurity, work on IoT cybersecurity guidelines, National Cybersecurity Center of Excellence (NCCoE) projects, a new comment site for NIST’s Risk Management Framework, the release of a Phish scale, and progress in the Identity and Access Management program. 2025会計年度(FY 2025)——2024年10月1日から2025年9月30日まで——を通じて、NIST情報技術研究所(ITL)サイバーセキュリティ・プライバシー・プログラムは、セキュリティとプライバシーにおける数多くの課題と機会に対し、適切に対応した。本年次報告書では、ITLサイバーセキュリティ・プライバシー・プログラムの2025会計年度の研究活動について概説する。これには、国際標準への継続的な参画と策定、ソフトウェアおよびサプライチェーンのサイバーセキュリティ強化、IoTサイバーセキュリティガイドラインに関する取り組み、 国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)のプロジェクト、NISTリスクマネジメントフレームワーク向けの新しいコメントサイト、フィッシング・スケールの公開、およびID・アクセス管理プログラムの進展などが含まれる。

 

・[PDF] SP.800-238

20260604-54525

・[DOCX][PDF] 仮訳

 

 

FOREWORD まえがき  
Cryptography 暗号 詳細
Cybersecurity & AI サイバーセキュリティとAI 詳細
Education & Workforce 教育・人材育成 詳細
Hardware & Software Security ハードウェアおよびソフトウェアのセキュリティ 詳細
Infrastructure Security インフラセキュリティ 詳細
Risk Management リスクマネジメント 詳細

 

過去の目次...

2025 2024 2023 2022 2021 2020 2019 2018 2017
SP800-238 SP800-236 SP800-229 SP800-225 SP800-220 SP800-214 SP800-211 SP800-206  SP800-203
暗号 暗号 暗号 暗号 暗号の標準と検証 サイバーセキュリティの啓発と教育  サイバーセキュリティとプライバシーの標準化の進化 サイバーセキュリティとプライバシー基準の推進 国際ITセキュリティ標準へのITLの関与
サイバーセキュリティとAI 教育・人材 教育、トレーニング、人材開発  教育、トレーニング、人材開発 サイバーセキュリティの測定 アイデンティティとアクセス管理 リスク管理の強化 リスクマネジメントの強化 リスク管理
教育・人材育成 新興技術 新興技術  アイデンティティとアクセス管理 教育と労働力 測定基準と測定 暗号標準と検証の強化 暗号の標準と検証の強化 バイオメトリクス標準と関連する適合性評価試験ツール
ハードウェアおよびソフトウェアのセキュリティ 人間中心のサイバーセキュリティ 人間中心のサイバーセキュリティ プライバシー アイデンティティとアクセス管理 リスクマネジメント 先端サイバーセキュリティ研究・応用開発 サイバーセキュリティの研究・応用開発の推進 サイバーセキュリティアプリケーション
インフラセキュリティ アイデンティティとアクセス管理 アイデンティティとアクセス管理 リスクマネジメントと計測 プライバシーエンジニアリング プライバシーエンジニアリング  サイバーセキュリティについての意識向上、トレーニング、教育、人材育成 サイバーセキュリティの意識向上、トレーニング、教育、人材開発 ソフトウェアの保証と品質
リスクマネジメント プライバシー プライバシー 信頼できるネットワークとプラットフォーム リスクマネジメント 新規技術 アイデンティティとアクセス管理の強化 アイデンティティとアクセス管理の強化 連邦サイバーセキュリティ調査研究
  リスクマネジメント リスクマネジメント 利用可能なサイバーセキュリティ 信頼できるネットワーク 暗号の標準化と検証 通信・インフラ保護の強化 必インフラストラクチャの保護強化  コンピュータ・フォレンジック
  信頼されるネットワークとプラットフォーム 信頼できるネットワークとプラットフォーム   信頼できるプラットフォーム 信頼性の高いネットワーク 新技術の確保 新規技術の保護 サイバーセキュリティに関する知識・訓練・教育・アウトリーチ
  国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE) NIST 国立サイバーセキュリティ・センター・オブ・エクセレンス     信頼性の高いプラットフォーム セキュリティテストと測定ツールの進化 セキュリティのテストと測定ツールの推進 暗号標準化プログラム
                バリデーションプログラム
                ID ・アクセス管理
                新規技術の研究
                ナショナル・サイバーセキュリティ・センター・オブ・エクセレンス
(NCCoE)
                インターネットインフラ保護
                高度なセキュリティ試験と測定
                技術的な安全性の指標
                利便性とセキュリティ

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2025.05.03 米国 NIST SP 800-236 2024会計年度サイバーセキュリティ・プライバシー年次報告書 (2025.04.28)

・2024.05.24 米国 NIST SP 800-229 2023会計年度サイバーセキュリティ・プライバシー年次報告書

・2023.06.09 NIST SP 800-225 2022年度サイバーセキュリティ・プライバシー年次報告書 (2023.05.30)

・2022.10.02 NIST SP 800-220 2021年度サイバーセキュリティ・プライバシー年次報告書 (2022.09.26)

・2021.10.01 NIST SP 800-214 2020年度サイバーセキュリティ・プライバシー年次報告書

・2020.08.26 NIST/ITLのサイバーセキュリティプログラム年次報告書2019

・2020.03.15 NIST SP 800-206 Annual Report 2018: NIST/ITL Cybersecurity Program

| | Comments (0)

2026.05.15

米国 NIST SP 800-70 第5版 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドライン (2026.05.08)

こんにちは、丸山満彦です。

NISTが、SP 800-70 Rev. 5 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドラインを公表していますね...

SP 800-37は、「権威あるセキュリティ設定チェックリストを一元化し、自動化・標準化を通じて、組織がリスクベースにシステムを安全構成できる基盤」を提供する、NIST主導の国家プログラムという感じですかね...

もともとIT 製品のデフォルト設定が脆弱である(機能性と相互運用性を優先する必要もあるため)問題があり、セキュアにするための実装チェックリストが必要であるが、ベンダーの任せていると項目や品質のばらつきが生じ、運用しにくいこと、また最新版がどれか分かりにくくなるなどの問題もあり、信頼できる中央レポジトリを作ろうという話になり、作成されているように思います。

そして、連邦政府は、調達するIT製品に対して共通セキュリティ構成チェックリストの使用を義務化した(連邦調達要件(FAR 39.101(Federal Acquisition Regulation 39.101)))。

でこれをセキュリティの自動化の流れもあり、機械可読な形式(SCAP)に統一しています...

SP 800‑70 は、NCPに準拠した “セキュリティ構成チェックリスト” を作成・公開・維持するための公式ガイドということになります...

 

● NIST - ITL

・2026.05.08 NIST SP 800-70 Rev. 5 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers

 

NIST SP 800-70 Rev. 5 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers NIST SP 800-70 第5版 IT製品向け国家チェックリストプログラム:チェックリストの利用者および開発者向けガイドライン
Abstract 概要
A security configuration checklist is a document that contains instructions, procedures, or machine-readable and executable content to configure an IT product to a specific risk posture for an operational environment, verify that the product has been configured properly, identify unauthorized configuration changes to the product, and/or produce artifacts that show the security posture of the product. Using these checklists can minimize the attack surface, reduce vulnerabilities, lessen the impact of successful attacks, and identify changes that might otherwise go undetected. NIST established the National Checklist Program (NCP) to facilitate the generation of security checklists from authoritative sources, centralize the location of checklists, and make checklists broadly accessible. This publication explains how to use the NCP to find and retrieve checklists and describes the policies, procedures, and general requirements for participation in the NCP. セキュリティ構成チェックリストとは、運用環境における特定のリスク態勢に合わせてIT製品を構成し、製品が適切に構成されていることを検証し、製品への不正な構成変更を識別し、および/または製品のセキュリティ態勢を示す成果物を作成するための、指示、手順、あるいは機械可読かつ実行可能なコンテンツを含む文書である。これらのチェックリストを使用することで、攻撃対象領域を最小限に抑え、脆弱性を低減し、攻撃が成功した場合の影響を軽減し、そうでなければ検出されなかったかもしれない変更を識別することができる。NISTは、信頼できる情報源からのセキュリティチェックリストの作成を促進し、チェックリストの保管場所を一元化し、チェックリストを広く利用可能にするために、National Checklist Program(NCP)を設立した。本書は、NCPを利用してチェックリストを検索・取得する方法を説明するとともに、NCPへの参加に関する方針、手順、および一般的な要件について記述している。

 

・[PDF] SP.800-70r5

20260514-233656

・[DOCX][PDF] 仮訳

 

 

目次...

Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
1.1. Purpose and Scope 1.1. 目的と範囲
1.2. Document Organization 1.2. 文書の構成
2. NIST National Checklist Program 2. NIST 国家チェックリストプログラム
2.1. Overview of the NCP 2.1. NCP の概要
2.2. Security Configuration Checklists 2.2. セキュリティ構成チェックリスト
2.3. Benefits of Using Security Checklists 2.3. セキュリティチェックリストの利用メリット
2.4. Additional Considerations 2.4. その他の考慮事項
2.4.1. Mapping and Acquisition Considerations 2.4.1. マッピングおよび導入に関する考慮事項
2.4.2. Selecting Checklists 2.4.2. チェックリストの選定
2.4.3. Checklist Considerations 2.4.3. チェックリストに関する考慮事項
2.5. Types of Checklists Listed by NCP 2.5. NCP に掲載されているチェックリストの種類
3. Operational Environments for Checklists 3. チェックリストの運用環境
3.1. Stand-Alone Environment 3.1. スタンドアロン環境
3.2. Managed Environment (Enterprise) 3.2. 管理環境(エンタープライズ)
3.3. Custom Environments 3.3. カスタム環境
3.3.1. Specialized Security-Limited Functionality Environment 3.3.1. 特殊セキュリティ・機能制限環境(SSLF)
3.3.2. Legacy Environment 3.3.2. レガシー環境( )
4. Checklist Usage 4. チェックリストの使用方法
4.1. Determining Local Requirements 4.1. 組織固有の要件の決定
4.2. Browsing and Retrieving Checklists 4.2. チェックリストの閲覧と取得
4.3. Reviewing, Customizing, Documenting, and Testing Checklists 4.3. チェックリストの確認、カスタマイズ、文書化、およびテスト
4.4. Applying Checklists to IT Products 4.4. IT製品へのチェックリストの適用
4.5. Providing Feedback on Checklists 4.5. チェックリストへのフィードバックの提供
5. Checklist Development 5. チェックリストの開発
5.1. Developer Steps for Creating, Testing, and Submitting Checklists 5.1. チェックリストの作成、テスト、および提出に関する開発者の手順
5.2. Initial Checklist Development 5.2. 初期チェックリストの開発
5.3. Checklist Testing 5.3. チェックリストのテスト
5.4. Checklist Documented 5.4. 文書化されたチェックリスト
5.5. Checklist Submitted to NIST 5.5. NISTに提出するチェックリスト
5.6. NIST Steps for Reviewing and Finalizing Checklists for Publication 5.6. 公開用チェックリストの審査および確定に関するNISTの手順
5.7. NIST Screening of the Checklist Package 5.7. チェックリストパッケージのNISTによる審査
5.8. Public Review and Feedback for the Candidate Checklist 5.8. 候補チェックリストに対する公開レビューとフィードバック
5.9. Final Listing on Checklist Repository 5.9. チェックリストリポジトリへの最終掲載
5.10. Checklist Maintenance and Archival 5.10. チェックリストの保守およびアーカイブ
References 参考文献
Appendix A. Checklist Program Operational Procedures 附属書A. チェックリストプログラム運用手順
A.1. Overview and General Considerations A.1. 概要および一般的な考慮事項
A.2. Checklist Submission and Screening A.2. チェックリストの提出とスクリーニング
A.3. Candidate Checklist Public Review A.3. 候補チェックリストの公開レビュー
A.4. Final Checklist Listing A.4. 最終チェックリストの掲載( )
A.5. Final Checklist Update, Archival, and Delisting A.5. 最終チェックリストの更新、アーカイブ、およびリストからの削除
A.6. Record Keeping A.6. 記録の保管
Appendix B. Participation and Logo Usage Agreement Form 附属書B. 参加およびロゴ使用同意書
Appendix C. Automating NIST CSF 2.0 附属書C. NIST CSF 2.0の自動化
C.1. How the Path Connects Policy to Automation C.1. ポリシーと自動化を結びつける経路
C.2. Implementation and Traceability C.2. 実装とトレーサビリティ
C.3. Checklist Development Guidance C.3. チェックリスト作成ガイダンス
C.4. Operational Environment Tailoring and Considerations C.4. 運用環境への適応と考慮事項
C.5. Checklist Submission and Maintenance C.5. チェックリストの提出と保守
C.6. Appendix References C.6. 附属書の参考文献
Appendix D. List of Symbols, Abbreviations, and Acronyms 附属書 D. 記号、略語、頭字語の一覧
Appendix E. Glossary 附属書E. 用語集
Appendix F. Change Log 附属書F. 変更履歴

 

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
A security configuration checklist (also called a lockdown, hardening guide, or benchmark) is a series of instructions or procedures for securely configuring an IT product to a particular risk tolerance for an operational environment, verifying that the product has been configured properly, and/or identifying unauthorized changes to the product. The checklist may be for a commercial, open-source, or government-off-the-shelf (GOTS) IT product.  セキュリティ構成チェックリスト(ロックダウン、強化ガイド、またはベンチマークとも呼ばれる)とは、運用環境における特定のリスク許容度に合わせてIT製品を安全に構成し、製品が適切に構成されていることを確認し、および/または製品への不正な変更を識別するための一連の指示または手順である。このチェックリストは、商用、オープンソース、または政府調達既製品(GOTS)のIT製品を対象とする場合がある。 
Checklists can comprise a mix of templates, automated scripts, patch information, Extensible Markup Language (XML) files, and other procedures. Typically, checklists are created by IT vendors for their own products; however, checklists are also created by other organizations, such as academia, consortia, and government agencies. The use of well-written, standardized checklists can markedly reduce the attack surface and vulnerability exposure of IT products.  チェックリストは、テンプレート、自動化スクリプト、パッチ情報、XML(Extensible Markup Language)ファイル、その他の手順などを組み合わせて構成されることがある。通常、チェックリストはITベンダーが自社の製品向けに作成するが、学術機関、コンソーシアム、政府機関などの他の組織によって作成されることもある。適切に作成された標準化されたチェックリストを使用することで、IT製品の攻撃対象領域や脆弱性の露出を大幅に低減できる。 
NIST maintains the National Checklist Repository, a publicly available resource of security configuration checklists for IT products. The repository, [web], contains metadata describing each checklist and links to the website where a checklist is hosted. Having a centralized checklist repository makes it easier for organizations to find current, authoritative versions of security checklists and to determine which ones best meet their needs.  NISTは、IT製品向けのセキュリティ構成チェックリストを公開しているリソースである「National Checklist Repository」を管理している。このリポジトリ([web] )には、各チェックリストを説明するメタデータと、チェックリストがホストされているウェブサイトへのリンクが含まれている。チェックリストのリポジトリを一元化することで、組織は最新かつ信頼性の高いセキュリティチェックリストを容易に見つけ、自組織のニーズに最も適したものを判断できるようになる。 
This document is intended for users and developers of security configuration. For checklist users, this document makes recommendations on how they should select checklists from the NIST National Checklist Repository, evaluate and test checklists, and apply them to IT products. For checklist developers, this document sets forth the policies, procedures, and general requirements for participation in the NIST National Checklist Program (NCP).  本文書は、セキュリティ設定のユーザーおよび開発者を対象としている。チェックリストのユーザーに対しては、NIST National Checklist Repositoryからチェックリストを選択し、評価・テストを行い、IT製品に適用する方法について推奨事項を示す。チェックリストの開発者に対しては、NIST National Checklist Program(NCP)への参加に関する方針、手順、および一般的な要件を定める。 
Major recommendations made in this document for checklist users and developers include the following:  本文書において、チェックリストの利用者および開発者に対して提示される主な推奨事項は以下の通りである: 
• Organizations should apply checklists to operating systems and applications to reduce the number of weaknesses that can be exploited and to lessen the impact of security breaches, if they occur.  • 組織は、悪用される可能性のある脆弱性の数を減らし、万一セキュリティ侵害が発生した場合の影響を軽減するために、オペレーティングシステムやアプリケーションにチェックリストを適用すべきである。 
• When selecting checklists, users should carefully consider each checklist’s degree of automation, source, use of standards, and other relevant characteristics.  • チェックリストを選択する際、利用者は各チェックリストの自動化の程度、出典、標準規格の採用状況、およびその他の関連する特性を慎重に検討すべきである。 
• Checklist users should consider their operational environments when selecting checklists and should customize and test checklists in a non-production environment before applying them to production systems.  • チェックリストの利用者は、チェックリストを選定する際に自組織の運用環境を考慮し、本番システムに適用する前に、非本番環境でチェックリストをカスタマイズし、テストを行うべきである。 
• Checklist creators are encouraged to adopt a “catalog of controls” approach for products to facilitate custom checklist reuse.  • チェックリストの作成者は、カスタムチェックリストの再利用を容易にするため、製品に対して「制御カタログ」アプローチを採用することが推奨される。 
• IT product vendors are strongly encouraged to develop security configuration checklists for their products and contribute them to the NIST National Checklist Repository.  • IT 製品ベンダーは、自社製品向けのセキュリティ設定チェックリストを作成し、NIST 国家チェックリスト・リポジトリに提供することが強く推奨される。 
• Checklists should be incorporated into continuous monitoring and configuration results and deviation monitoring used in automated data feeds for near real-time posture checks. • チェックリストは、継続的な監視および設定結果、ならびにほぼリアルタイムのセキュリティ態勢チェックのための自動データフィードで使用される逸脱監視に組み込まれるべきである。 

 

 

 


 

国家チェックリストプログラム

・2017.02.15 National Checklist Program NCP

チェックリストのレポジトリ...

Checklist Repository

全部で883のチェックリストがあります(2026.05.14確認時)

例えば、MacOSOS (Tahoe) 26.0.0を選んだ画面...

20251213-103431

でマッチしたのが、

20260515-11146

https://ncp.nist.gov/repository?product=Apple+macOS+%28Tahoe%29+26.0.0&sortBy=modifiedDate%7Cdesc

 

上の方は、米国国防総省(DOD)の情報システムのセキュリティを向上させるためのツールとして公開されているもののようです。

で、これの下の方のリンクをクリックすると

・2025.09.17 Tahoe Guidance Revision 1.0 Checklist Details 

ダウンロード

・・[ZIP] Download ZIP - Tahoe Guidance, Revision 1.0

ダウンロードして内容を確認してみてくださいませ。充実した内容となっております...

こんな感じでファイルが格納されています...

20251213-140110

例えば、

SP800-53

・800-53r5_high.html (downloaded)

20251213-141956 

 

 

国家安全保障システム委員会 (Committee on National Security Systems; CNSS) 用のCNSSI-1253チェックリスト

・CNSSI - 1253_high.html (downloaded)

20251213-141801_20251213141801

 

Github

/macos_security

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2025.12.14 米国 NIST SP 800-70 第5版 (初期公開ドラフト) IT製品向け国家チェックリストプログラム:チェックリスト利用者および開発者向けガイドライン

 

 

 

 

 

| | Comments (0)

2026.05.14

米国 NIST IR 8323 Rev. 2(初期ドラフト) 基礎的PNTプロファイル:測位・航法・計時(PNT)サービスの責任ある利用に向けたサイバーセキュリティ・フレームワークの適用 (2026.05.06)

こんにちは、丸山満彦です。

NISTがIR 8323 Rev. 2(初期ドラフト) 基礎的PNTプロファイル:測位・航法・計時(PNT)サービスの責任ある利用に向けたサイバーセキュリティ・フレームワークの適用を公表し、意見募集をしていますね...

日本の事業者もPNTサービスの利用についてのリスクについてはよく考えておくべきですよね...米国のGPSや中国の北斗に技術的な障害がでたことがあったようにも思いますし、以前中国が、米国がGPSを妨害(ジャミング)していると批判したケースがありましたよね...

もし、GPSを含めてPNTが使えなくなった場合の事業継続については考えておくべきだろうと思います。もちろん、「そうなれば、昔通りにするんだ!」ということであればそれで良いのですが、その意思決定は組織として事前にしておくべきだろうということです...

ところで、PNTシステムにかなり依存している業務ってどのくらいあるのでしょうね...

測位・航法情報でいうと

・輸送・物流(航空、海事、自動車、鉄道...)とかはかなり依存しているよね...

・マイニング、建設、測量(ドローン)

・災害対策(位置情報...)

・地震予知計測

時間でいうと

・通信・放送、電力、金融取引、天文観測とかも依存していますよね

といった分野ですかね...

 

NIST - ITL

・2026.05.06 NIST IR 8323 Rev. 2 (Initial Public Draft) Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services

NIST IR 8323 Rev. 2 (Initial Public Draft) Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services NIST IR 8323 Rev. 2(初期ドラフト) 基礎的PNTプロファイル:測位・航法・計時(PNT)サービスの責任ある利用に向けたサイバーセキュリティ・フレームワークの適用
Announcement 通知
This profile helps organizations manage risks to systems, networks, and assets that use PNT services, such as Global Positioning Systems (GPS), public NIST and United States Naval Observatory (USNO) Network Time Protocol (NTP) servers, commercial services, and internal systems. 本プロファイルは、組織が、全地球測位システム(GPS)、NISTおよび米国海軍天文台(USNO)の公開ネットワークタイムプロトコル(NTP)サーバー、商用サービス、内部システムなど、PNTサービスを利用するシステム、ネットワーク、および資産に対するリスクを管理するのに役立つ。
Originally developed based on NIST Cybersecurity Framework version 1.1, this profile has been updated to align with the NIST CSF 2.0 and includes updated references to standards, guidelines, and practices to provide practical guidelines to help an organization achieve the desired outcome for each Subcategory in the profile.  当初はNISTサイバーセキュリティフレームワークバージョン1.1に基づいて開発されたが、本プロファイルはNIST CSF 2.0に準拠するよう更新されており、組織がプロファイル内の各サブカテゴリーにおいて望ましい成果を達成できるよう支援する実践的な指針を提供するため、標準、ガイドライン、および実践例への参照が更新されている。
Organizations can apply the Profile to govern cybersecurity risk management, identify systems dependent on PNT, identify appropriate PNT sources, protect PNT user equipment from adversaries, detect anomalies and manipulation of PNT services, and respond to and recover from PNT service disruptions. 組織はこのプロファイルを適用し、サイバーセキュリティリスクマネジメントのガバナンス、PNTに依存するシステムの特定、適切なPNTソースの特定、敵対者からのPNTユーザー機器の防御、PNTサービスの異常や改ざんの検知、およびPNTサービスの中断への対応と復旧を行うことができる。
We encourage you to review the revised publication draft and submit comments until July 6, 2026, using the instructions provided on the project page. NIST is seeking targeted feedback to ensure the profile is practical and aligned to real-world use. 改訂版公開ドラフトを確認し、プロジェクトページに記載された手順に従って、2026年7月6日までにコメントを提出することを推奨する。NISTは、本プロファイルが実用的であり、実世界の利用状況に合致していることを確認するため、具体的なフィードバックを求めている。
Specific questions are included in the draft document. In particular, we are interested in:   ドラフト文書には具体的な質問が記載されている。特に、以下の点に関心がある:
・Whether additional references to support PNT systems and data, or additional Categories or Subcategories from NIST CSF 2.0 should be added  ・PNTシステムおよびデータを支援するための追加の参照先、あるいはNIST CSF 2.0からの追加のカテゴリーやサブカテゴリーを追加すべきかどうか
・How emerging technologies (including AI) impact the use of PNT systems and data  ・新興技術(AIを含む)がPNTシステムおよびデータの利用に与える影響
・Whether the profile appropriately addresses third-party and data dependency risks ・本プロファイルが、サードパーティおよびデータ依存のリスクに適切に対処しているか否か
Abstract 概要
The national and economic security of the United States (U.S.) is dependent upon the reliable operation and responsible use of Positioning, Navigation, and Timing (PNT) services. This document provides the Cybersecurity Framework (CSF) Version 2.0 Community Profile developed for supporting positioning, navigation, and timing (PNT) services and can be used as part of a risk management program to help organizations manage risks to systems, networks, and assets that use PNT services. The PNT Profile is intended to be broadly applicable and can serve as a foundation for the development of sector-specific guidance. This PNT Profile provides a flexible framework for users of PNT to manage risks when forming and using PNT signals and data, which are susceptible to disruptions and manipulations that can be natural, manufactured, intentional, or unintentional. 米国の国家安全保障および経済安全保障は、測位・航法・計時(PNT)サービスの信頼性の高い運用と責任ある利用に依存している。本書は、測位・航法・計時(PNT)サービスを支援するために策定されたサイバーセキュリティ・フレームワーク(CSF)バージョン2.0コミュニティ・プロファイルを提供するものであり、組織がPNTサービスを利用するシステム、ネットワーク、および資産に対するリスクを管理するためのリスクマネジメントプログラムの一環として活用できる。本PNTプロファイルは、広範に適用されることを意図しており、セクター固有のガイダンス策定の基礎となり得る。本PNTプロファイルは、PNTの利用者に対し、自然災害、人為的要因、意図的または非意図的な操作による妨害や改ざんを受けやすいPNT信号やデータを形成・利用する際のリスクを管理するための柔軟なフレームワークを提供する。

 

・[PDF] IR.8323r2.ipd

20260514-53850

 

 

 

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー
The PNT Profile provides a flexible framework for users of PNT services to manage risks when forming or using PNT signals or data, which are susceptible to disruptions and manipulations that can be natural, manufactured, intentional, or unintentional. It was created by applying the NIST Cybersecurity Framework (CSF) version 2.0 and can be applied to all organizations that use PNT services, irrespective of the level of familiarity or knowledge that they have with the NIST CSF. Organizations that have fully or partially adopted, or who have not adopted the NIST CSF can benefit by considering and adopting the recommendations in the Profile. Organizations can apply the PNT Profile within risk management programs to protect their systems and assets from the disruption or manipulation of PNT services and data. The Profile is intended to guide users in establishing responsible strategies for managing PNT cybersecurity risks.  PNTプロファイルは、PNTサービスの利用者が、自然災害、人為的要因、意図的または非意図的な要因による妨害や改ざんの影響を受けやすいPNT信号やデータを生成・利用する際に、リスクを管理するための柔軟なフレームワークを提供する。本プロファイルは、NISTサイバーセキュリティフレームワーク(CSF)バージョン2.0を適用して作成されたものであり、NIST CSFに対する習熟度や知識の有無にかかわらず、PNTサービスを利用するすべての組織に適用可能である。NIST CSFを完全または部分的に採用している組織、あるいは未採用の組織であっても、本プロファイルの推奨事項を検討・採用することで恩恵を受けることができる。組織は、リスクマネジメントプログラムの一環としてPNTプロファイルを適用し、PNTサービスやデータの混乱や改ざんから自組織のシステムや資産を保護することができる。本プロファイルは、PNTサイバーセキュリティリスクを管理するための責任ある戦略を策定する際、ユーザーを導くことを目的としている。
The PNT Profile is voluntary and does not: constitute regulations, define mandatory practices, provide a checklist for compliance, or carry statutory authority. It is intended to be a foundational set of guidelines. Sector Risk Management Agencies (SRMAs) and entities may wish to augment or further develop their own PNT cybersecurity efforts via full or partial implementation of the recommended practices in this document. Any implementation of its recommendations will not necessarily protect organizations from all PNT disruption or manipulation. Each organization is encouraged to make their risk management decisions in the context of their own cyber ecosystem, architecture, and components. The PNT Profile’s strategic focus is to supplement preexisting resilience measures and elevate the postures of less mature initiatives.  PNTプロファイルは任意のものであり、規制を構成したり、義務的な慣行を定義したり、コンプライアンスのためのチェックリストを提供したり、法的認可を有したりするものではない。これは、基礎的なガイドラインのセットとなることを意図している。セクター・リスク管理機関(SRMA)および事業体は、本書で推奨される実践を全面的または部分的に実施することにより、独自のPNTサイバーセキュリティ対策を強化または発展させることが望ましい。推奨事項を実施したからといって、必ずしも事業体がすべてのPNTの混乱や改ざんから防御されるわけではない。各事業体は、自事業体のサイバーエコシステム、アーキテクチャ、および構成要素の文脈において、リスクマネジメント上の意思決定を行うことが推奨される。PNTプロファイルの戦略的焦点は、既存のレジリエンス対策を補完し、成熟度の低い取り組みの態勢を向上させることにある。
This revision updates the PNT Profile to align with the NIST CSF 2.0. CSF 2.0 can serve all organizations, regardless of sector or size, with the objective to provide accessible and actionable guidance for all users, including but not limited to critical infrastructures, private industry, and small businesses. Organizations can apply the profile to align their PNT use with their broader enterprise risk management strategy. Because PNT services can be critical to modern services and operations, key updates from the previous version include the integration of the CSF Govern Function, updates to Functions, and Categories to reflect the need for executive-level risk management strategies and oversight to achieve PNT resilience. PNT services often rely on external suppliers, such as the satellites’ signals and the third-party manufacturers of receivers and antennas. CSF 2.0 elevates cybersecurity supply chain risk management in the Govern  本改訂版は、NIST CSF 2.0に整合させるためPNTプロファイルを更新したものである。CSF 2.0は、重要インフラ、民間企業、中小企業を含む(ただしこれらに限定されない)すべてのユーザーに対し、アクセスしやすく実行可能なガイダンスを提供することを目的としており、セクターや規模を問わずあらゆる組織に活用できる。組織はこのプロファイルを適用し、自社のPNT利用を、より広範なエンタープライズリスクマネジメント戦略と整合させることができる。PNTサービスは現代のサービスや運用において極めて重要となり得るため、前バージョンからの主な更新点には、CSFガバナンス機能の統合、およびPNTレジリエンスを達成するための経営層レベルのリスクマネジメント戦略と監督の必要性を反映した機能およびカテゴリーの更新が含まれる。PNTサービスは、衛星信号や受信機・アンテナのサードパーティ製造事業者など、外部サプライヤーに依存することが多い。CSF 2.0では、「ガバナンス」
function. Updates to informative references have also been made throughout the document to reflect the latest guidance and risk mitigations.   機能において、サイバーセキュリティのサプライチェーンリスクマネジメントの重要性を高めている。また、最新のガイダンスやリスク緩和策を反映するため、文書全体を通じて参考資料の更新も行われた。

 

目次...

Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
1.1. Purpose and Objectives 1.1. 目的と目標
1.2. Scope 1.2. 適用範囲
1.3. Audience 1.3. 対象読者
2. Intended Use 2. 使用目的
3. Overview 3. 概要
3.1. Risk Management Overview 3.1. リスクマネジメントの概要
3.2. Cybersecurity Framework Overview 3.2. サイバーセキュリティ・フレームワークの概要
4. The PNT Profile 4. PNTプロファイル
4.1. Govern Function 4.1. ガバナンス機能
4.1.1. Organizational Context (GV.OC) 4.1.1. 組織的文脈 (GV.OC)
4.1.2. Risk Management Strategy (GV.RM) 4.1.2. リスクマネジメント戦略 (GV.RM)
4.1.3. Roles, Responsibilities and Authorities (GV.RR) 4.1.3. 役割、責任および権限 (GV.RR)
4.1.4. Supply Chain Risk Management (GV.SC) 4.1.4. サプライチェーンリスクマネジメント (GV.SC)
4.2. Identify Function 4.2. 識別機能
4.2.1. Asset Management (ID.AM) 4.2.1. 資産管理 (ID.AM)
4.2.2. Risk Assessment (ID.RA) 4.2.2. リスクアセスメント (ID.RA)
4.2.3. Improvement (ID.IM) 4.2.3. 改善 (ID.IM)
4.3. Protect Function 4.3. 防御機能
4.3.1. Identity Management, Authentication and Access Control (PR.AA) 4.3.1. アイデンティティ管理、認証/アクセス制御 (PR.AA)
4.3.2. Awareness and Training (PR.AT) 4.3.2. 意識向上およびトレーニング (PR.AT)
4.3.3. Data Security (PR.DS) 4.3.3. データセキュリティ (PR.DS)
4.3.4. Platform Security (PR.PS) 4.3.4. プラットフォームセキュリティ (PR.PS)
4.3.5. Technology Infrastructure Resilience (PR.IR) 4.3.5. 技術インフラのレジリエンス (PR.IR)
4.4. Detect Function 4.4. 検知機能
4.4.1. Continuous Monitoring (DE.CM) 4.4.1. 継続的監視 (DE.CM)
4.4.2. Anomalies and Events (DE.AE) 4.4.2. 異常とイベント (DE.AE)
4.5. Respond Function 4.5. 対応機能
4.5.1. Incident Management (RS.MA) 4.5.1. インシデント管理 (RS.MA)
4.5.2. Incident Analysis (RS.AN) 4.5.2. インシデント分析 (RS.AN)
4.5.3. Incident Response and Communication (RS.CO) 4.5.3. インシデント対応およびコミュニケーション (RS.CO)
4.5.4. Incident Mitigation (RS.MI) 4.5.4. インシデントの緩和 (RS.MI)
4.6. Recover Function 4.6. 復旧機能
4.6.1. Incident Recovery Plan Execution (RC.RP) 4.6.1. インシデント復旧計画の実行 (RC.RP)
References 参考文献
Appendix A. Selected Bibliography 附属書A. 選定文献一覧
Appendix B. List of Symbols, Abbreviations, and Acronyms 附属書B. 記号、略語、頭字語一覧
Appendix C. Glossary 附属書C. 用語集
Appendix D. Applying the PNT Profile to Cybersecurity Risk Management 附属書D. PNTプロファイルのサイバーセキュリティリスクマネジメントへの適用
List of Tables 表一覧
Table 1. Cybersecurity Framework Functions and Categories 表1. サイバーセキュリティ・フレームワークの機能とカテゴリー
Table 2. Govern - Organizational Context Subcategories Applicable to PNT 表2. ガバナンス - PNTに適用可能な組織的文脈のサブカテゴリー
Table 3. Govern - Risk Management Applicable to PNT 表3. ガバナンス - PNTに適用可能なリスクマネジメント
Table 4. Govern - Roles, Responsibilities and Authorities Subcategories Applicable to PNT 表4. ガバナンス - PNTに適用可能な役割、責任、権限のサブカテゴリー
Table 5. Govern - Supply Chain Risk Management Subcategories Applicable to PNT 表5. ガバナンス - PNTに適用可能なサプライチェーンリスクマネジメントのサブカテゴリー
Table 6. Identify - Asset Management Subcategories Applicable to PNT 表6. 識別 - PNTに適用可能な資産管理のサブカテゴリー
Table 7. Identify - Risk Assessment Subcategories Applicable to PNT 表7. 識別 - PNTに適用可能なリスクアセスメントのサブカテゴリー
Table 8. Identify - Improvement Subcategories Applicable to PNT 表8. 識別 - PNTに適用可能な改善のサブカテゴリー
Table 9. Protect - Access Control Categories Applicable to PNT 表9. 防御 - PNTに適用可能なアクセス管理のカテゴリー
Table 10. Protect - Awareness and Training Subcategory Applicable to PNT 表10. 防御 - PNTに適用可能な意識向上およびトレーニングのサブカテゴリー
Table 11. Protect - Data Security Subcategories Applicable to PNT 表11. 防御 - PNTに適用されるデータセキュリティのサブカテゴリー
Table 12. Protect - Platform Security Subcategories Applicable to PNT 表12. 防御 - PNTに適用されるプラットフォームセキュリティのサブカテゴリー
Table 13. Protect - Technology Infrastructure Resilience Applicable to PNT 表13. 防御 - PNTに適用される技術インフラのレジリエンス
Table 14. Detect - Security Continuous Monitoring Subcategories Applicable to PNT 表14. 検知 - PNTに適用されるセキュリティの継続的なモニタリングのサブカテゴリー
Table 15. Detect - Anomalies and Events Subcategories Applicable to PNT 表15. 検知 - PNTに適用される異常とイベントのサブカテゴリー
Table 16. Respond - Incident Management Subcategories Subcategory Applicable to PNT 表16. 対応 - インシデント管理サブカテゴリー PNTに適用されるサブカテゴリー
Table 17. Respond - Incident Analysis Subcategories Applicable to PNT 表17. 対応 - インシデント分析 PNTに適用されるサブカテゴリー
Table 18. Respond - Communications Subcategories Applicable to PNT 表18. 対応 - コミュニケーション PNTに適用されるサブカテゴリー
Table 19. Respond - Incident Mitigation Subcategories Applicable to PNT 表19. 対応 - インシデント緩和 PNTに適用されるサブカテゴリー
Table 20. Recover - Incident Recovery Plan Execution Subcategories Applicable to PNT 表20. 復旧 - インシデント復旧計画の実行 PNTに適用可能なサブカテゴリー
Table 21. Applying the PNT Profile to User Risk Management 表21. ユーザーリスクマネジメントへのPNTプロファイルの適用
List of Figures 図一覧
Fig. 1. Example of How the PNT Profile Applies to GNSS 図1. PNTプロファイルがGNSSに適用される例
Fig. 2. Cybersecurity Framework Subcategory Example 図2. サイバーセキュリティフレームワークのサブカテゴリー例
Fig. 3. Organizational PNT Profile Creation Process 図3. 組織におけるPNTプロファイル作成プロセス
Fig. 4. Components of the PNT Profile 図4. PNTプロファイルの構成要素

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2023.02.04 NIST NISTIR 8323 Rev. 1 基礎的なPNTプロファイル:測位・航法・計時(PNT)サービスの責任ある使用のためのサイバーセキュリティ・フレームワークの適用 (2023.01.31)

・2022.07.06 NISTIR 8323 Rev. 1 (ドラフト) 基礎的な PNT プロファイル:測位・航法・計時(PNT)サービスの責任ある使用のためのサイバーセキュリティフレームワークの適用 (2022.06.29)

 

・2021.02.13 NIST NISTIR 8323 基本的なPNTプロファイル:測位・航法・計時(PNT)サービスの責任ある使用のためのサイバーセキュリティフレームワークの適用

・2020.10.23 NISTが測位・航法・計時(PNT)に関連するサービスに関連したセキュリティプロファイルに関する文書(NISTIR 8323)のパブコメを募集していますね。

 

 

| | Comments (0)

2026.05.05

米国 CISA CISAおよび連邦政府機関、OT分野におけるゼロトラスト導入を加速するためのガイドを発表 (2026.04.29)

こんにちは、丸山満彦です。

CISA等が、OT分野におけるゼロトラスト導入を加速するためのガイドを公表しています...日本では、経産省の工場システムにおけるサイバー・フィジカル・セキュリティ対策ガイドラインがありますが、米国のガイドライン等も参照すれば良いかもですね...


● CISA

・2026.04.29 CISA and U.S. Government Partners Unveil Guide to Accelerate Zero Trust Adoption in Operational Technology 

CISA and U.S. Government Partners Unveil Guide to Accelerate Zero Trust Adoption in Operational Technology CISAおよび米国政府のパートナー機関、OT分野におけるゼロトラスト導入を加速するためのガイドを発表
Guidance for OT Organizations: Comprehensive Asset Visibility, Secure Supply Chains, Robust Identity and Access Controls OT組織向けガイダンス:包括的な資産可視化、安全なサプライチェーン、強固なIDおよびアクセス管理
WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), along with the Department of War (DoW), Department of Energy (DOE), Federal Bureau of Investigation (FBI) and Department of State (DOS) today published a joint guide to assist organizations with operational technology (OT) systems - including government systems – with applying Zero Trust principles. The guide, Adapting Zero Trust Principles to Operational Technology, provides OT owners and operators and Zero Trust practitioners with practical insights on overcoming unique constraints, addressing potential challenges, and prioritizing key areas for integrating Zero Trust into OT environments
ワシントン発 – サイバーセキュリティ・インフラセキュリティ庁(CISA)は本日、国防総省(DoW)、エネルギー省(DOE)、連邦捜査局(FBI)、国務省(DOS)と共同で、政府システムを含むオペレーショナルテクノロジー(OT)システムを運用する組織がゼロトラストの原則を適用できるよう支援するためのガイドを公表した。このガイド『運用技術へのゼロトラスト原則の適応』は、OTの所有者・運用者およびゼロトラストの実践者に対し、特有の制約を克服し、潜在的な課題に対処し、OT環境へのゼロトラスト統合に向けた重点分野を優先するための実践的な知見を提供する。
New attack vectors, expanded attack surface and magnified cybersecurity risks are more prevalent because OT systems are becoming increasingly interconnected, digitally monitored, and remotely operated. Improperly secured pathways create opportunities or threat actors to gain access to information technology (IT) and OT networks. Adapting and applying Zero Trust principles to fit the operational realities of the OT environment can help owners and operators close cyber risk gaps, however, it must be done carefully without disrupting their own systems in the process. Zero Trust strategies can prevent adversaries from compromising, manipulating, degrading, and disrupting the critical physical processes these systems control. OTシステムがますます相互接続され、デジタル監視され、遠隔操作されるようになるにつれ、新たな攻撃ベクトル、拡大する攻撃対象領域、増大するサイバーセキュリティリスクがより顕著になっている。セキュリティ対策が不十分な経路は、脅威アクターが情報技術(IT)およびOTネットワークにアクセスする機会を生み出す。OT環境の運用実態に合わせてゼロトラストの原則を適応・適用することは、所有者や運用者がサイバーリスクのギャップを埋めるのに役立つが、その過程で自社のシステムに支障をきたさないよう慎重に行う必要がある。ゼロトラスト戦略は、これらのシステムが制御する重要な物理的プロセスを、敵対者が侵害、操作、機能低下、または混乱させることを防ぐことができる。
“CISA has observed threat actors like Volt Typhoon targeting OT systems to compromise, escalate, and maintain access within operational environments. Zero Trust architecture is critical to preventing cyber incidents that could cause operators to lose visibility or control of essential systems,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “This guide equips organizations to methodically navigate the complexities of adopting Zero Trust principles in OT environments. Together with our partners, CISA urges OT owners, operators, and integrators to use this resource to make informed decisions that reduce exposure and strengthen resilience—without jeopardizing mission-critical operations.” 「CISAは、Volt Typhoonのような脅威アクターがOTシステムを標的とし、運用環境内でアクセスを侵害、権限昇格、維持しようとしているのを確認している。ゼロトラストアーキテクチャは、運用者が重要システムの可視性や制御を失う可能性のあるサイバーインシデントを防ぐために不可欠だ」と、CISAのサイバーセキュリティ担当代理執行副局長クリス・ブテラは述べた。「本ガイドは、組織がOT環境においてゼロトラストの原則を導入する際の複雑さを体系的に乗り越えるための指針となる。CISAはパートナーと連携し、OTの所有者、運用者、インテグレーターに対し、ミッションクリティカルな運用を危険にさらすことなく、エクスポージャーを低減しレジリエンスを強化するための情報に基づいた意思決定を行うために、このリソースを活用するよう強く推奨する」
"The Department of War is driving Zero Trust for operational technology at an accelerated pace," said Honorable Kirsten A. Davies, DoW Chief Information Officer. "In lockstep with our federal and industry partners, we are fortifying the infrastructure and interconnected weapon systems our Warfighters demand to fight and win. This is how we deliver peace through technical strength." 「国防総省は、運用技術におけるゼロトラストの導入を加速させている」と、国防総省最高情報責任者(CIO)のカーステン・A・デイヴィス氏は述べた。「連邦政府や産業界のパートナーと緊密に連携し、我々の戦闘員が戦い、勝利するために必要とするインフラと相互接続された兵器システムを強化している。これこそが、技術力によって平和をもたらす方法である。」
"Operational technology underpins the systems Americans rely on every day, and adversaries know it,” said FBI Cyber Division Assistant Director Brett Leatherman. "Nation-state actors are pre-positioning on these networks because OT controls critical physical processes, and because these environments often lack the visibility to detect them early. This guide moves owners and operators from reactive to proactive. Resilience in OT isn't achieved through any single control; it requires layered defenses that raise the cost for adversaries at every stage. Alongside our partners, we're putting practical steps in the hands of the people who need them most." 「運用技術(OT)は、アメリカ国民が日々頼りにしているシステムの基盤であり、敵対勢力はそれを承知している」と、FBIサイバーディビジョンのブレット・レザーマン副部長は述べた。「国家主体の攻撃者は、OTが重要な物理的プロセスを制御していること、またこれらの環境では早期に検知するための可視性が欠如していることが多いことから、こうしたネットワークに事前に潜伏している。本ガイドは、所有者や運用者を事後対応型から事前対応型へと移行させるものである。OTにおけるレジリエンスは、単一の対策では達成できない。あらゆる段階で敵対者のコストを高める多層的な防御が必要だ。我々はパートナーと共に、それを最も必要とする人々の手に実用的な対策を届けている。」
“Operational technology sits at the intersection of cybersecurity and physical consequence. That reality demands dedicated attention. In line with this joint guide, the State Department prioritizes sustained collaboration to establish shared discipline and systematically address concerns raised by OT engineers, network architects, and cybersecurity professionals,” said U.S. Department of State’s Diplomatic Security Service, Deputy Assistant Secretary for Cyber and Technology Security Gharun S. Lacy. “These integrated efforts combine multiple skillsets and put personnel onsite to safeguard critical infrastructure across U.S. missions worldwide.” 「運用技術は、サイバーセキュリティと物理的影響の交差点に位置する。その現実には、特別な注意が求められる。この共同ガイドに沿い、国務省は、共通の規律を確立し、OTエンジニア、ネットワークアーキテクト、サイバーセキュリティ専門家が提起する懸念に体系的に対処するため、持続的な協力を優先している」と、米国国務省外交保安局のサイバー・技術セキュリティ担当次官補代理、ガラン・S・レイシーは述べた。「これらの統合的な取り組みは、複数のスキルセットを組み合わせ、世界中の米国在外公館における重要インフラを保護するために現場に要員を配置するものである。」
This guide helps organizations overcome the unique challenges such as technology gaps from legacy infrastructure, operational constraints, and the safety requirements that come from the critical link between cybersecurity and physical processes. Key focus areas in this guide include establishing zones and conduits, proactively addressing supply chain risks, and implementing robust identity and access management.  本ガイドは、レガシーインフラによる技術的ギャップ、運用上の制約、そしてサイバーセキュリティと物理的プロセスとの重要な関連性から生じる安全要件といった、特有の課題を組織が克服するのを支援する。本ガイドの主な重点分野には、ゾーンと経路の確立、サプライチェーンリスクへの積極的な対応、そして堅牢なIDおよびアクセス管理の実施が含まれる。
CISA offers a variety of resources—including guidance, services, tools, and training—applicable to zero trust and OT stakeholders and organizations at all levels of cybersecurity maturity. For more information, please visit Industrial Control Systems or Zero Trust on CISA.gov. CISAは、ゼロトラストおよびOTのステークホルダーや、あらゆるレベルのサイバーセキュリティ成熟度にある組織に適用可能な、ガイダンス、サービス、ツール、トレーニングを含む多様なリソースを提供している。詳細については、CISA.govの「産業用制御システム」または「ゼロトラスト」のページを参照のこと。

 

・2026.04.29 Adapting Zero Trust Principles to Operational Technology

Adapting Zero Trust Principles to Operational Technology  運用技術へのゼロトラスト原則の適用
CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, released Adapting Zero Trust Principles to Operational Technology, joint guidance for organizations applying zero trust (ZT) principles to operational technology (OT). Zero trust is a modern, adaptive approach to cybersecurity that eliminates implicit trust and requires continuously validating access based on identity, context, and risk. CISAは、国防総省、エネルギー省、連邦捜査局(FBI)、国務省と連携し、運用技術(OT)にゼロトラスト(ZT)原則を適用する組織向けの共同ガイダンス『運用技術へのゼロトラスト原則の適用』を発表した。ゼロトラストとは、暗黙の信頼を排除し、ID、コンテキスト、リスクに基づいてアクセスの妥当性確認を継続的に行うことを求める、サイバーセキュリティに対する現代的で適応性の高いアプローチである。
With advancements in technology, OT systems that were traditionally isolated or manually operated are now increasingly interconnected, digitally monitored, and remotely controlled. This IT-OT convergence introduces new cybersecurity risks that make perimeter-based defenses and implicit trust models inadequate for safeguarding OT systems and the critical physical processes they control. 技術の進歩に伴い、従来は隔離されていたり手動で操作されていたOTシステムは、現在では相互接続され、デジタルで監視され、遠隔操作されることが増えている。このITとOTの融合は新たなサイバーセキュリティリスクをもたらし、境界ベースの防御や暗黙の信頼モデルでは、OTシステムおよびそれらが制御する重要な物理的プロセスを保護するには不十分となっている。
This guidance supports OT owners and operators in addressing the unique challenges of transitioning to a ZT architecture, considering technology gaps from legacy infrastructure, operational constraints, and safety requirements. It focuses on establishing comprehensive asset visibility, proactively addressing supply chain risks, and implementing robust identity and access management while stressing the importance of layered security measures—including network segmentation, secure communication protocols, and vulnerability management. 本ガイダンスは、レガシーインフラからの技術的ギャップ、運用上の制約、安全要件を考慮しつつ、ZTアーキテクチャへの移行に伴う特有の課題に対処するOTの所有者および運用者を支援するものである。ネットワークのセグメンテーション、安全な通信プロトコル、脆弱性管理を含む多層的なセキュリティ対策の重要性を強調しつつ、包括的な資産可視性の確立、サプライチェーンリスクマネジメント、堅牢なIDおよびアクセス管理の実施に焦点を当てている。
To learn more about ZT principles, visit Zero Trust   ZTの原則について詳しくは、Zero Trust 

 

・[PDF]

20260504-184335

 

・[DOCX][PDF] 仮訳

 

目次...

Executive Summary エグゼクティブサマリー
Introduction 序論
Audience and Scope 対象読者および適用範囲
Evolving Threat Landscape and the Need for Zero Trust 進化する脅威の状況とゼロトラストの必要性
Unique Constraints for Zero Trust in OT OTにおけるゼロトラストの固有の制約
Govern ガバナンス
Governance Structures ガバナンス構造
Overcoming Zero Trust for OT Constraints Through Procurement 調達を通じたOTにおけるゼロトラストの制約の克服
Supply Chain and Third-Party Risk Management サプライチェーンおよびサードパーティリスク管理
Identify 識別
Comprehensive Asset Inventory and Asset Discovery 包括的な資産インベントリおよび資産発見
Configuration and Change Management 構成および変更管理
Risk Management, Threat Modeling, and Cyber-Physical Consequences リスクマネジメント、脅威モデリング、およびサイバーフィジカルな影響
Risk Assessment Methodology: A Practical Approach リスクアセスメントの手法:実践的なアプローチ
Threat Modeling for OT: Mapping the Attack Surface OT向け脅威モデリング:攻撃対象領域のマッピング
Cyber-Physical Consequences: Real-World Impact サイバー・フィジカルな影響:現実世界への影響
Integrating Risk Assessments With Zero Trust Principles: A Proactive Approach リスクアセスメントとゼロトラスト原則の統合:予防的アプローチ
Prioritization and Mitigation: Focused Security Efforts 優先順位付けと緩和策:焦点を絞ったセキュリティ対策
Protect 防御
Network and Microsegmentation ネットワークおよびマイクロセグメンテーション
IT Segmentation Vs. OT Segmentation ITセグメンテーションとOTセグメンテーションの比較
Implementing OT Segmentation OTセグメンテーションの実施
Microsegmentation for Enhanced Security セキュリティ強化のためのマイクロセグメンテーション
Identity, Credential, and Access Management for OT OT向けID、認証情報、およびアクセス管理
Secure Remote Access: Jump Hosts and Privileged Access  In OT セキュアなリモートアクセス:OTにおけるジャンプホストと特権アクセス
Jump Hosts (Bastion Hosts) ジャンプホスト(バスティオンホスト)
Privileged Access Management 特権アクセス管理
Agent-Based vs. Agentless エージェント型とエージェントレス型
Secure Communication, Data Integrity, and Encryption セキュアなコミュニケーション、データの完全性、および暗号化
Vulnerability and Patch Management in OT Environments OT環境における脆弱性およびパッチ管理
Detect 検知
Continuous Monitoring Across IT and OT Boundaries ITとOTの境界を越えた継続的監視
Baseline-based Detection ベースラインベースの検知
Specification-based Detection 仕様ベースの検知
Endpoint Detection and Response Considerations for Embedded Systems 組み込みシステムにおけるエンドポイント検知および対応(EDR)の考慮事項
Respond 対応
Incident Response Planning for OT-Specific Scenarios OT固有のシナリオに対するインシデント対応計画
Threat Containment Strategies 脅威封じ込め戦略
Coordinate Incident Response for Critical Infrastructure 重要インフラにおけるインシデント対応の調整
Recover 復旧
Data, Configuration, and System State Backups データ、構成、およびシステム状態のバックアップ
System Restoration and Integrity Validation システムの復旧と妥当性確認
Business Continuity and Cyber Resilience in Industrial Systems 産業システムにおける事業継続とサイバーレジリエンシー
Summary 要約
Feedback フィードバック
Resources リソース
Disclaimer 免責事項
Acknowledgements 謝辞
Version History 改訂履歴
Appendix: Acronyms 附属書:略語
References 参考文献

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
Authoring Agencies: The Zero Trust Operational Technologies Security Working Group developed this document. The Working Group is a joint initiative led by the Cybersecurity and Infrastructure Security Agency (CISA), Department of War (DoW), and Department of Energy (DOE)—with the aim of supporting organizations in applying zero trust (ZT) principles to operational technology (OT). The Zero Trust Operational Technologies Security Working Group gratefully acknowledges the contributions of the following participating agencies: Department of State (DOS), Federal Bureau of Investigation (FBI), and the National Institute of Standards and Technology (NIST).  作成機関:本文書は、ゼロトラスト・オペレーショナル・テクノロジー・セキュリティ・ワーキンググループによって作成された。同ワーキンググループは、サイバーセキュリティ・インフラセキュリティ庁(CISA)、戦争省(DoW)、およびエネルギー省(DOE)が主導する共同イニシアチブであり、組織がオペレーショナル・テクノロジー(OT)にゼロトラスト(ZT)の原則を適用することを支援することを目的としている。 ゼロトラスト運用技術セキュリティ作業部会は、以下の参加機関からの貢献に深く感謝する:国務省(DOS)、連邦捜査局(FBI)、および国立標準技術研究所(NIST)。 
Purpose of Document: This paper provides considerations for applying ZT principles to OT systems and environments to system owners, operators, and security personnel. It addresses the unique challenges of transitioning to a ZT architecture within OT, considering technology gaps from legacy infrastructure, operational constraints, and the safety requirements that come from the critical link between cybersecurity and physical processes.  文書の目的:本稿は、システム所有者、運用者、およびセキュリティ担当者に、OTシステムおよび環境へのZT原則の適用に関する考慮事項を提供するものである。本稿では、レガシーインフラからの技術的ギャップ、運用上の制約、およびサイバーセキュリティと物理的プロセスとの間の重要な関連性から生じる安全要件を考慮し、OT内でのZTアーキテクチャへの移行に伴う特有の課題に対処する。 
Intended Audience: ZT practitioners and OT owners and operators who are responsible for implementing ZT in OT but may have limited understanding of OT environments and their unique constraints. While this document has specific references for applying ZT to federal OT systems, any organization with OT systems can apply the information provided.  対象読者:OT環境におけるZTの実装を担当するものの、OT環境やその特有の制約について理解が限られている可能性のある、ZTの実務者およびOTの所有者・運用者である。本資料には連邦政府のOTシステムへのZT適用に関する具体的な言及が含まれているが、OTシステムを有するあらゆる組織が、ここで提供される情報を適用できる。 
Summary of Important Topics: Key focus areas include establishing comprehensive asset visibility, proactively addressing supply chain risks, and implementing robust identity and access management. The document emphasizes layered security controls—encompassing network segmentation, secure communication protocols and vulnerability management—alongside a fundamental shift in security philosophy that assumes a breach occurred and prioritizes uninterrupted operations, safety, and reliability. The document aligns with the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF) 2.0 functions of Govern, Identify, Protect, Detect, Respond, and Recover.  重要なトピックの概要:主な重点分野には、包括的な資産可視性の確立、サプライチェーンリスクへの積極的な対応、および堅牢なIDおよびアクセス管理の導入が含まれる。本資料では、ネットワークのセグメンテーション、セキュアな通信プロトコル、脆弱性管理を網羅する多層的なセキュリティ制御に加え、侵害が発生したと仮定し、業務の継続性、安全性、信頼性を優先するというセキュリティ哲学の根本的な転換を強調している。 本資料は、米国国立標準技術研究所(NIST)のサイバーセキュリティフレームワーク(CSF)2.0における「ガバナンス」「識別」「防御」「検知」「対応」「復旧」の各機能と整合している。 
Summary of Document’s Conclusion: Successful implementation requires a holistic approach, adaptation of ZT principles to the specific characteristics of each OT environment, and strong collaboration between IT, OT, and cybersecurity teams. By applying ZT to OT, organizations can significantly enhance the security and resilience of their OT environments, from industrial control systems to facility automation, helping ensure a more secure and reliable future for both critical infrastructure and mission operations.  文書の結論の要約:実装を成功させるには、包括的なアプローチ、各OT環境の特性に合わせたZT原則の適応、およびIT、OT、サイバーセキュリティチーム間の強力な連携が必要である。OTにZTを適用することで、組織は産業用制御システムから施設自動化に至るまで、OT環境のセキュリティとレジリエンスを大幅に向上させることができ、重要インフラとミッションオペレーションの両方にとって、より安全で信頼性の高い未来を確保するのに役立つ。 

 

 

Industrial Control Systems

Industrial Control Systems  産業用制御システム
Practical tools, guidance, and up-to-date information to support asset owners and cyber defenders 資産所有者やサイバー防衛担当者を支援するための実用的なツール、ガイダンス、最新情報

CISA collaborates with the OT community to address immediate operational cyber events and long-term risk affecting ICS.

CISAはOTコミュニティと連携し、ICSに影響を及ぼす差し迫った運用上のサイバーインシデントや長期的なリスクに対処している。
ICS Cybersecurity Challenges ICSサイバーセキュリティの課題
Many ICS environments operate with existing “legacy” technologies and proprietary protocols due to their original design priorities, which focused on operability and reliability rather than cybersecurity. Historically, ICS environments functioned in isolated networks with limited external connectivity, reducing the perceived need for robust security measures. These systems relied heavily on vendor-specific hardware, software, and communication technologies, making them less adaptable to modern security practices. As a result, many legacy ICS devices continue to use outdated operating systems as well as older protocols that lack encryption or authentication mechanisms, leaving them vulnerable to cyber threats. 多くのICS環境は、当初の設計優先事項がサイバーセキュリティよりも運用性と信頼性に重点を置いていたため、既存の「レガシー」技術や独自プロトコルで運用されている。歴史的に、ICS環境は外部接続が限定された孤立したネットワーク内で機能しており、堅牢なセキュリティ対策の必要性は低いと認識されていた。これらのシステムはベンダー固有のハードウェア、ソフトウェア、通信技術に大きく依存していたため、現代のセキュリティ慣行への適応性が低かった。その結果、多くのレガシーICSデバイスは、暗号化や認証メカニズムを欠く古いプロトコルや時代遅れのオペレーティングシステムを使い続けており、サイバー脅威に対して脆弱なままである。
ICS and Brownfield Challenges ICSとブラウンフィールドの課題
A cybersecurity challenge unique to ICS is brownfield deployments, which refer to the integration of new technologies or systems into existing “legacy” infrastructure. Specifically, these deployments layer legacy infrastructure with modern OT systems, such as building management systems, energy management systems, internet-of-things (IoT) devices, automation, and robotics. These modern systems commonly use protocols that support higher bandwidth, ultra-low latency, and connectivity for large fleets of devices.  ICSに特有のサイバーセキュリティ上の課題として、ブラウンフィールド展開が挙げられる。これは、既存の「レガシー」インフラに新しい技術やシステムを統合することを指す。具体的には、ビル管理システム、エネルギー管理システム、モノのインターネット(IoT)デバイス、自動化、ロボット工学などの現代的なOTシステムを、レガシーインフラに重ねて導入するものである。これらの現代的なシステムは、一般的に、より高い帯域幅、超低遅延、および多数のデバイス群への接続性をサポートするプロトコルを使用している。
ICS stakeholders—including owners, operators, cyber defenders, and vendors—must carefully consider the nuances of these layered OT systems, networks, and environments when implementing mitigations and compensating controls that address security risks and vulnerabilities. 所有者、運用者、サイバー防衛担当者、ベンダーを含むICSのステークホルダーは、セキュリティリスクや脆弱性に対処するための緩和策や代償的制御策を実施する際、こうした多層化されたOTシステム、ネットワーク、環境の微妙な違いを慎重に考慮しなければならない。
CISA Resources for ICS Cybersecurity ICSサイバーセキュリティに関するCISAのリソース
CISA offers a variety of resources—including guidance, services, tools, and training—applicable to ICS stakeholders and organizations at all levels of cybersecurity maturity. These resources include general cybersecurity and safety guidance, as well as deployable tools and shared services directly provided by CISA. The tabs at the top of this page provide information about resources that stakeholders can immediately put into practice or reference.   CISAは、サイバーセキュリティの成熟度がどのレベルにあるICSのステークホルダーや組織にも適用可能な、ガイダンス、サービス、ツール、トレーニングなど、多様なリソースを提供している。これらのリソースには、一般的なサイバーセキュリティおよび安全に関するガイダンスに加え、CISAが直接提供する展開可能なツールや共有サービスが含まれる。このページ上部のタブには、関係者が直ちに実践したり参照したりできるリソースに関する情報が掲載されている。
The broader OT community can use these resources to raise awareness around security risks and threats to OT and ICS systems. CISA continues to collaborate with owners and operators of critical infrastructure, industry, manufacturers, information sharing and analysis centers (ISACs), and the interagency to protect vital systems and defend against our adversaries. より広範なOTコミュニティは、これらのリソースを活用して、OTおよびICSシステムに対するセキュリティリスクや脅威に関する認識を高めることができる。CISAは、重要インフラの所有者や運営者、産業界、製造事業者、情報共有・分析センター(ISAC)、および省庁間連携と引き続き協力し、重要なシステムを保護し、敵対者から防御している。
The following section provides ICS-related resources. Visit [web] for the full catalogue of CISA services, tools, and products. 以下のセクションでは、ICS関連のリソースを紹介する。CISAのサービス、ツール、製品の完全なカタログについては、[web] を参照のこと。

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2026.01.29 米国 NIST SP 800-82「運用技術(OT)セキュリティガイド」の改訂プロセスを開始 (2026.01.22)

・2025.10.03 米国 NIST SP 1334 OT環境における可搬保管媒体のサイバーセキュリティリスク低減 (2025.09.30)

・2025.07.24 米国 NIST SP 1334( 初期公開ドラフト) OT 環境における可搬保管媒体のサイバーセキュリティリスクの軽減 (2025.07.15)

・2023.10.01 NIST SP 800-82 第3版 OTセキュリティガイド

・2022.04.28 NIST SP 800-82 第3版 OTセキュリティガイド(ドラフト)

・2021.08.02 米国 連邦政府 重要インフラ制御システムのサイバーセキュリティの向上に関する国家安全保障に関する覚書

 

 

| | Comments (0)

2026.05.03

米国 NIST IR 8259 Rev. 1 IoT製品製造事業者のための基礎的なサイバーセキュリティ活動 (2026.04.20)

こんにちは、丸山満彦です。

消費者向け製品は特にですが、IoT 製品のセキュリティは、顧客任せではなく メーカーが設計段階から責任を持って「securable」な状態を作り込むべきですよね...

キーボード叩いて運用でなんとかリカバリーできるところもあるので運用にまかせてしまったPCがデフォルトだと思われているかもしれないけど、普通はセキュアな状態で市場にだすのが当然ですよね...

とくに、運動エネルギーへの変換や、人間の体に直接作用をしてしまうようなデバイスについてはセキュアな状態での販売が当然ですよね...

ただ、すべてを製造事業者に責任を追わせると製品が使いづらくなったり、高価になってしまうこともあるので、顧客側も安全な利用の仕方ということを理解しようとすべきですよね...

製造事業者もセキュアな状態を技術的な機能だけで実装しようとせず、顧客のニーズを理解し、適切な手段を選んで、ライフサイクル全体でセキュアになるようにする。そして、顧客等への適切な情報提供を通じて、全体として安全に使われる環境を作り出すということが重要なんでしょうね...

で、NIST IR 8259r1は、IoT製品製造事業者が実施すべきセキュリティ活動を説明していますね...参考になると思います...

 

Activity 0: Prioritize Cybersecurity and Maintain Cybersecurity Posture  活動0:サイバーセキュリティを優先し、サイバーセキュリティ態勢を維持する 
Activity 1: Identify Expected Customers and Define Expected Use Cases  活動1:想定顧客の識別と想定ユースケースの定義 
Activity 2: Research Customer Cybersecurity Needs and Goals  活動2:顧客のサイバーセキュリティのニーズと目標を調査する 
Activity 3: Determine Appropriate Means to Support Customer Needs and Goals   活動3:顧客のニーズと目標を支援するための適切な手段を決定する  
Activity 4: Define IoT Product Cybersecurity Capabilities Based on Appropriate Means  活動4:適切な手段に基づくIoT製品のサイバーセキュリティ機能の定義 
Activity 5: Plan for Adequate Support of Customer Needs and Goals  活動5:顧客のニーズと目標を適切に支援するための計画 
Product Goes to Market  製品の市場投入 
Activity 6: On-Going Support of Product Cybersecurity through-out the Lifecyle  End-of-Life  活動6:ライフサイクル全体を通じた製品のサイバーセキュリティに対する継続的なサポート  サポート終了 
Activity 7: Define Approaches for Communicating to Customers  活動7:顧客へのコミュニケーション手法の定義 
Activity 8: Decide What to Communicate to Customers and How to Communicate It  活動8:顧客への伝達内容および伝達方法の決定 

 

 

● NIST - ITL

・2026.04.20 NIST IR 8259 Rev. 1 Foundational Cybersecurity Activities for IoT Product Manufacturers

 

NIST IR 8259 Rev. 1 Foundational Cybersecurity Activities for IoT Product Manufacturers NIST IR 8259 Rev. 1 IoT製品製造事業者のための基礎的なサイバーセキュリティ活動
Abstract 概要
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises. IoT製品には、顧客(組織や個人)がサイバーセキュリティリスクの緩和に活用できるサイバーセキュリティ機能が欠けている場合が多い。製造事業者は、必要なサイバーセキュリティ機能を提供し、顧客が必要とするサイバーセキュリティ関連情報を提供することで、IoT製品のセキュリティ性を向上させ、顧客を支援することができる。本刊行物は、製造事業者がIoT製品を顧客に販売する前に実施を検討すべき、サイバーセキュリティに関連する推奨活動を記述している。これらの基礎的なサイバーセキュリティ活動は、製造事業者が顧客が必要とするサイバーセキュリティ関連の取り組みを軽減するのに役立ち、ひいては侵害の発生率と深刻度を低減することができる。

 

・[PDF] IR.8259r1

20260501-94341

・[DOCX][PDF] 仮訳

 

Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
1.1. Purpose and Scope 1.1. 目的と範囲
1.2. Publication Structure 1.2. 出版物の構成
2. Background 2. 背景
2.1. Product Cybersecurity and System Cybersecurity 2.1. 製品のサイバーセキュリティとシステムのサイバーセキュリティ
2.2. Composition of IoT Products 2.2. IoT製品の構成
2.3. Entities in an IoT Product Ecosystem 2.3. IoT製品エコシステムにおける事業体
2.4. The Role of the Manufacturer in Cybersecurity 2.4. サイバーセキュリティにおける製造事業者の役割
2.5. IoT Product Customer Cybersecurity Needs and Goals 2.5. IoT製品の顧客のサイバーセキュリティ上のニーズと目標
2.6. Relationships between Needs and Goals, Capabilities, and Means 2.6. ニーズと目標、能力、および手段の関係
3. Manufacturer Activities Impacting the IoT Product Pre-Market Phase 3. IoT製品の市場投入前段階に影響を与える製造事業者の活動
3.1. Activity 0: Prioritize Cybersecurity and Maintain Cybersecurity Posture 3.1. 活動0:サイバーセキュリティの優先順位付けとサイバーセキュリティ態勢の維持
3.2. Activity 1: Identify Expected Customers and Define Expected Use Cases 3.2. 活動1:想定される顧客の識別と想定されるユースケースの定義
3.3. Activity 2: Research Customer Cybersecurity Needs and Goals 3.3. 活動2:顧客のサイバーセキュリティのニーズと目標の調査
3.4. Activity 3: Determine Appropriate Means to Support Customer Needs and Goals in the Context of the IoT Product 3.4. 活動3:IoT製品の文脈において顧客のニーズと目標を支援するための適切な手段を決定する
3.5. Activity 4: Define IoT Product Cybersecurity Capabilities Based on Appropriate Means 3.5. 活動4:適切な手段に基づくIoT製品のサイバーセキュリティ機能の定義
3.6. Activity 5: Plan for Adequate Support of Customer Needs and Goals 3.6. 活動5:顧客のニーズと目標に対する適切な支援の計画
4. Manufacturer Activities Impacting the IoT Product Post-Market Phase 4. IoT製品の市販後段階に影響を与える製造事業者の活動
4.1. Activity 6: On-Going Support of Product Cybersecurity throughout the Lifecycle and through End-of-Life 4.1. 活動6:ライフサイクル全体および製品寿命終了までの製品サイバーセキュリティの継続的支援
4.2. Activity 7: Define Approaches for Communicating to Customers 4.2. 活動7:顧客へのコミュニケーションアプローチの定義
4.3. Activity 8: Decide What to Communicate to Customers and How to Communicate It 4.3. 活動8:顧客に何を、どのように伝えるかを決定する
4.3.1. Cybersecurity Risk-Related Assumptions 4.3.1. サイバーセキュリティリスクに関する前提条件
4.3.2. Support and Lifespan Expectations 4.3.2. サポートおよびライフサイクルに関する期待
4.3.3. Product Composition and Capabilities 4.3.3. 製品の構成と機能
4.3.4. Software Updates 4.3.4. ソフトウェアの更新
4.3.5. Product Retirement Options 4.3.5. 製品の廃止に関する選択肢
4.3.6. Technical and Non-Technical Cybersecurity Capabilities 4.3.6. 技術的および非技術的なサイバーセキュリティ機能
5. Conclusion 5. 結論
References 参考文献
Appendix A. List of Abbreviations and Acronyms 附属書A. 略語および頭字語一覧
Appendix B. Glossary 附属書B. 用語集
Appendix C. Change Log 附属書C. 変更履歴

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
Manufacturers are creating an incredible variety and volume of internet-ready products and systems broadly known as the Internet of Things (IoT). Many of these IoT products and systems do not fit the standard definitions of information technology (IT) (e.g., smartphones, servers, laptops) that have been used as the basis for defining product cybersecurity capabilities.   製造事業者は、広く「モノのインターネット(IoT)」として知られる、インターネット対応製品やシステムを、驚くほど多種多様かつ大量に生み出している。これらのIoT製品やシステムの多くは、製品のサイバーセキュリティ能力を定義する基礎として用いられてきた情報技術(IT)の標準的な定義(例:スマートフォン、サーバー、ノートパソコン)には当てはまらない。  
The purpose of this publication is to give manufacturers recommendations for improving the securability of their IoT products. Securability means the IoT products offer product cybersecurity capabilities—cybersecurity features or functions that the IoT devices and other product components provide through their own technical means (i.e., hardware and software) or related non-technical services from the manufacturer (i.e., vulnerability disclosure programs). An IoT product that is resilient to attacks, supports forensic analysis following an incident, recovers quickly after an incident, keeps customer data confidential and free of tampering, develops a reputation of being trustworthy, etc. is one that customers can adopt and trust. Thus, investing in producing a secure IoT product contributes to the success of the IoT product in the market, increasing innovation, protecting the nation, and supporting individuals in their daily lives. Cybersecurity of an IoT product must begin in the product planning phase when the decision-makers are able to allocate resources towards modeling and prioritizing threats, then designing and implementing effective product cybersecurity capabilities that help address these threats. Additionally, allocating resources for post-market support of the product when it’s deployed in the field goes a long way to establishing a relationship of trust with the customer. Constantly evaluating the ever-changing threat landscape, investigating security incidents, and maintaining the IoT product’s ability to remain securable in the field all help the customer manage their cybersecurity risks while also enhancing the reputation of the IoT product and its manufacturer.   本出版物の目的は、製造事業者に対し、自社のIoT製品の「セキュラビリティ」を向上させるための提言を行うことにある。「セキュラビリティ」とは、IoT製品がサイバーセキュリティ機能を提供することを意味する。すなわち、IoTデバイスやその他の製品コンポーネントが、独自の技術的手段(ハードウェアおよびソフトウェア)や、製造事業者による関連する非技術的サービス(脆弱性開示プログラムなど)を通じて提供するサイバーセキュリティ機能や機能のことである。 攻撃に対してレジリエンスがあり、インシデント発生後のフォレンジック分析に対応し、インシデント発生後に迅速に復旧し、顧客データを機密保持し改ざんから守り、信頼できるという評判を築くことのできるIoT製品こそが、顧客が採用し信頼できる製品である。したがって、安全なIoT製品の製造に投資することは、市場におけるIoT製品の成功、イノベーションの促進、国家の防御、そして人々の日常生活の支援に寄与する。 IoT製品のサイバーセキュリティは、意思決定者がリソースを割り当てて脅威のモデリングと優先順位付けを行い、それらの脅威に対処するのに役立つ効果的な製品サイバーセキュリティ機能を設計・実装できる製品企画段階から始めなければならない。 さらに、製品が現場に展開された後の市場投入後のサポートにリソースを割り当てることは、顧客との信頼関係を築く上で極めて重要である。絶えず変化する脅威の状況を継続的に評価し、セキュリティインシデントを調査し、現場においてIoT製品のセキュリティ維持能力を保つことは、顧客がサイバーセキュリティリスクを管理するのを支援すると同時に、IoT製品とその製造事業者の評判を高めることにもつながる。  
This publication describes nine recommended foundational cybersecurity activities that manufacturers should consider performing to improve the securability of their IoT products. Six of the activities primarily impact decisions and actions performed by the manufacturer before a product is sent out for sale (pre-market), and the remaining three activities primarily impact decisions and actions performed by the manufacturer after product sale (post-market). Performing all activities can help manufacturers provide IoT products that better support the cybersecurity-related efforts needed by customers, which can reduce the prevalence and severity of IoT product compromises. These activities are intended to fit within a manufacturer’s existing development process and may already be achieved in whole or part by that existing process. They are presented sequentially and are mostly intended to be performed sequentially, but some activities and parts of activities may be able to be performed in parallel. Also, activities are not mapped to an organizational structure, and in practice these activities may touch on the roles and responsibilities of multiple individuals and departments within an IoT product manufacturer’s organization. This allows flexibility for organizations with different structures to adopt the activities and assign them appropriately within their organization. By the end of each activity, IoT product manufacturers will have an increasingly detailed and informed plan to ensure the IoT product they are developing is securable by customers.  本書では、IoT製品のセキュリティ性を改善するために、製造事業者が実施を検討すべき9つの推奨される基礎的なサイバーセキュリティ活動について説明する。そのうち6つの活動は、主に製品が販売される前(市場投入前)に製造事業者が行う意思決定や行動に影響し、残りの3つの活動は、主に製品販売後(市場投入後)に製造事業者が行う意思決定や行動に影響する。 すべての活動を実施することで、製造事業者は顧客が必要とするサイバーセキュリティ関連の取り組みをより適切に支援するIoT製品を提供できるようになり、IoT製品の侵害の発生率と深刻度を低減できる。これらの活動は、製造事業者の既存の開発プロセスに組み込むことを意図しており、その既存プロセスによってすでに全体または一部が達成されている可能性がある。活動は順序立てて提示されており、主に順次実施することを想定しているが、一部の活動や活動の一部については並行して実施できる場合もある。 また、活動は特定の組織構造に紐付けられておらず、実際には、IoT製品製造事業者の組織内における複数の個人や部門の役割と責任にまたがる場合がある。これにより、異なる組織構造を持つ組織でも、これらの活動を柔軟に採用し、組織内で適切に割り当てることが可能となる。各活動の終了時点において、IoT製品製造事業者は、開発中のIoT製品が顧客によってセキュリティを確保できるものであることを保証するための、より詳細かつ情報に基づいた計画を策定することになる。 

 

 

 

 


 

● まるちゃんの情報セキュリティ気まぐれ日記

ちょっと古いけどIoT関連NIST文書

・2022.05.19 NIST IoTセキュリティ関連の文書についてNISTのブログで簡単に説明されていますね。。。

 

SP 800-213, IR 8259,関連

・2025.05.16 米国 NIST IR 8259 Rev.1(初期公開ドラフト)IoT製品製造者のための基礎的サイバーセキュリティ活動の5年振りの改訂関係...IR 8572も...(2025.05.13)

・2021.11.30 NIST SP 800-213 連邦政府のためのIoTデバイスサイバーセキュリティ・ガイダンス:IoTデバイスのサイバーセキュリティ要件の確立、SP 800-213A 連邦政府のためのIoTデバイスサイバーセキュリティ・ガイダンス:IoTデバイス・サイバーセキュリティ要件カタログ


・2021.08.29 NISTIR 8259B IoT非技術的支援能力コアベースライン

・2020.12.17 NIST SP 800-213 (Draft) 連邦政府向け「 IoTデバイスサイバーセキュリティ要件の確立」、NISTIR 8259B、8259C、8259D

・2020.05.30 NIST IoT機器製造者向けセキュリティの実践資料 NISTIR 8259 Foundational Cybersecurity Activities for IoT Device Manufacturers, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline

 

 

直接は関係ないけど...サイバートラストマーク制度関連...

・2025.12.23 米国 FCC サイバートラストマーク関連文書 (2025.06.18)

・2024.09.13 米国 FCC IoTのためのサイバーセキュリティ・ラベリングFAQと管理者の申請プロセス (2024.09.10)

・2024.08.02 米国 FCC IoTのためのサイバーセキュリティ・ラベリング最終規則

・2024.03.20 米国 連邦通信委員会 (FCC) がIoTサイバーセキュリティ表示プログラム(サイバートラストマーク)の規則を採択 (2024.03.14)

・2023.07.19 米国 消費者向けIoT製品のセキュリティ認証制度、サイバートラスト・マーク (U.S. Cyber Trust Mark) を発表

| | Comments (0)

2026.05.02

英国 NCSCが開発した脆弱なディスプレイ接続を保護するプラグアンドプレイ型のデバイス「SilentGlass」 (2026.04.22)

こんにちは、丸山満彦です。

 

英国 NCSC が 世界初のディスプレイ接続防御デバイス「SilentGlass」 を発表していますね...

1_20260502103301

HDMI/DisplayPort の間に挿入し、不正・異常な信号を物理層で遮断するというもので、「物理接続を信頼境界ではなく制御ポイントとして扱う」という思想(ゼロトラストの“物理層版?)に基づいているようです。

モニターにはいろいろな情報が表示されていますからね...その信号情報が取られたら...という話は昔からありましたよね...(ケーブルから漏れる電磁波と拾うとか...)ということで、モニターは攻撃者にとっては魅了的な標的の一つといえますよね...(HDMI/DP はサプライチェーン改ざん・悪意あるケーブル・物理アクセスなどの盲点がある)

ということで、NSCS謹製のSilentGlass...すでに政府機関では利用されて始めているようです。 NCSC の知財を Goldilock Labs が製造し、Sony UK Technology Centre が量産しているようで、民間に開放という話のようです...。国家技術を民間に開放する英国モデルですね...

日本企業でも検証をした上で、導入の検討はできそうですね...

 

 

UK. National Cyber Security Centre: NCSC

・2026.04.22 World-first NCSC-engineered device secures vulnerable display links

World-first NCSC-engineered device secures vulnerable display links NCSCが開発した世界初のデバイスが、脆弱なディスプレイ接続を保護
SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections. プラグアンドプレイ型のデバイス「SilentGlass」は、予期せぬ接続や悪意のあるHDMIおよびDisplayPort接続を積極的に遮断する。
・New device designed by the National Cyber Security Centre protects against malicious connections between monitors and laptops ・英国国家サイバーセキュリティセンター(NCSC)が設計した新デバイスが、モニターとノートパソコン間の悪意ある接続から保護する
・First commercially available product licensed to use NCSC branding granted to Goldilock Labs in manufacturing partnership with Sony UK Technology Centre ・ソニーUKテクノロジーセンターとの製造提携により、Goldilock LabsがNCSCブランドの使用許諾を得た初の市販製品
・UK government and businesses to be protected at scale by the affordable plug-in cyber security device ・手頃な価格のプラグイン型サイバーセキュリティデバイスにより、英国政府および企業が広範に防御される
An innovative device which protects video connections from cyber attacks is being launched to the global market at CYBERUK, the UK government’s flagship cyber security conference. ビデオ接続をサイバー攻撃から守る革新的なデバイスが、英国政府の旗艦サイバーセキュリティ会議「CYBERUK」にて世界市場に投入される。
The National Cyber Security Centre (NCSC) – a part of GCHQ – created the intellectual property for a new cyber security device and has now licensed Goldilock Labs to manufacture and sell it globally. GCHQの一部である英国国家サイバーセキュリティセンター(NCSC)が、新しいサイバーセキュリティデバイスの知的財産権を創出し、Goldilock Labsに対し、その製造事業者としての製造および世界的な販売をライセンス供与した。
SilentGlass, a plug-and-play device, actively blocks anything unexpected or malicious between HDMI and Display Port connections and screens. プラグアンドプレイ型のデバイス「SilentGlass」は、HDMIおよびDisplayPort接続とディスプレイの間で発生する予期せぬ動作や悪意のある行為を積極的に遮断する。
Already successfully deployed on Government estates, SilentGlass is now available for anyone to buy and use. It has been approved for use in the most high-threat environments. すでに政府施設での展開実績があるSilentGlassは、現在、誰でも購入・利用できるようになった。最も脅威の高い環境での使用も承認されている。
The NCSC assesses that monitors can be a hugely attractive target for threat actors as they can hold and process valuable, sensitive or personal data. Monitors are ‘highly likely’ to be used to gain access to a network for espionage purposes, disruption or financial gain, with mitigations often costly and inefficient. NCSCは、モニターが価値ある機密データや個人データを保持・処理できるため、脅威アクターにとって極めて魅力的な標的となり得ると評価している。モニターは、スパイ活動、業務妨害、または金銭的利益を得る目的でネットワークへのアクセス権を取得するために使用される可能性が「極めて高い」とされ、その緩和には多額の費用がかかり、非効率的であることが多い。
Over the years, an increasing array of more sophisticated devices have become available, as more connections increases the risk of attack. SilentGlass has been developed to help protect against malicious connections and shut down this attack vector. 接続が増えるにつれて攻撃のリスクが高まる中、ここ数年でより高度なデバイスが次々と登場している。SilentGlassは、悪意のある接続から防御し、この攻撃経路を遮断するために開発された。
”Display screens and monitors are everywhere in modern business environments, and the SilentGlass device will help protect previously vulnerable IT infrastructure with unprecedented ease. 「現代のビジネス環境ではディスプレイやモニターが至る所に存在するが、SilentGlassデバイスは、これまで脆弱性があったITインフラを前例のないほど容易に防御する助けとなるだろう。
Its development and commercialisation shows the impact that the NCSC can have, alongside industry partners, with an affordable and effective product now globally available. その開発と商品化は、NCSCが業界パートナーと共にどのような影響力を発揮できるかを示しており、手頃な価格で効果的な製品が現在世界中で利用可能となっている。
By helping to launch a UK company onto the global market with this world-class innovation, we are breaking new ground and helping to strengthen national prosperity. この世界クラスのイノベーションを通じて英国企業をグローバル市場に送り出すことで、我々は新たな地平を切り拓き、国の繁栄を強化することに貢献している。
Ollie Whitehouse, NCSC Chief Technology Officer NCSC最高技術責任者(CTO) オリー・ホワイトハウス
Following a competitive process, the exploitation licence has been awarded to Goldilock Labs, a UK-based small business with expertise in cyber security innovation and secure manufacture. They have partnered with Sony UK Technology Centre, and the product is available globally now. 競争的なプロセスを経て、このエクスプロイテーションライセンスは、サイバーセキュリティのイノベーションとセキュアな製造事業者に専門知識を持つ英国の中小企業、Goldilock Labsに授与された。同社はソニーUKテクノロジーセンターと提携しており、製品は現在世界中で入手可能となっている。
”SilentGlass addresses a gap that has been widely overlooked. The hardware interfaces people rely on every day have rarely been treated as security boundaries, despite being exposed to risk through supply chains, third-party servicing, and direct physical access. 「SilentGlassは、これまで広く見過ごされてきた課題に対処するものだ。人々が日々依存しているハードウェアインターフェースは、サプライチェーン、サードパーティによる保守、直接的な物理的アクセスを通じてリスクにさらされているにもかかわらず、セキュリティ境界として扱われることはほとんどなかった。
Originating in NCSC-led work and brought into the commercial domain through its IP exploitation programme, SilentGlass turns high-assurance innovation into a practical, deployable security solution. NCSC主導の取り組みに端を発し、その知的財産活用プログラムを通じて商用化されたSilentGlassは、高信頼性のイノベーションを実用的で展開可能なセキュリティソリューションへと変える。
What was once confined to national security environments is now being applied with a low-cost, easy to deploy solution for CNI and businesses where the same risks exist. かつては国家安全保障環境に限定されていた技術が、今や同様のリスクを抱える重要インフラ(CNI)や企業向けに、低コストで展開しやすいソリューションとして適用されている。
SilentGlass is the first step in a wider effort to enforce behaviour at hardware interfaces before it reaches complex software. It reflects a shift toward treating physical connectivity as a point of control rather than an assumed trust boundary. SilentGlassは、複雑なソフトウェアに到達する前にハードウェアインターフェースでの動作を制御するという、より広範な取り組みの第一歩だ。これは、物理的な接続性を「信頼できる境界」として前提視するのではなく、制御ポイントとして扱うという方向への転換を反映している。
Stephen Kines, Co-Founder, Goldilock Labs Goldilock Labs共同創業者、スティーブン・キーンズ
Through this innovative partnership with Goldilock, and their partner Sony UK Technology Centre, the NCSC expects rapid global adoption of SilentGlass by governments and risk-conscious organisations, positioning it as a flagship example of how Government’s intellectual property can be successfully commercialised to drive national prosperity. GoldilockおよびそのパートナーであるSony UK Technology Centreとのこの革新的な提携を通じて、NCSCは、政府やリスク意識の高い組織によるSilentGlassの急速な世界的な採用を見込んでおり、政府の知的財産をいかにして国家の繁栄を推進するために成功裏に商業化できるかを示す代表的な事例として位置づけている。

 

 

 

| | Comments (0)

2026.05.01

米国 NIST CSWP 52 バスベースのコンピュータシステムにおけるファームウェアベースの監視 (2026.04.15)

こんにちは、丸山満彦です。

NISTもWPになるとなかなか意欲的なものを出してきますよね...

「国防総省が使用するシステムを含む多くの重要コンピューティングシステムは、依然としてバスベースのアーキテクチャに依存している」...これが出発点ということね...

CPU, GPU, memory, などのコンポーネントが同じバス上の共通の通信路(バス)を共有して接続される構造であれば、お互いが暗黙に信頼してしまうことになります。1つのコンポーネントが侵害されるとバスを通じて他のコンポーネントにも影響が及ぶ可能っ性がありますよね。。。そして、OSより下のレイヤー(ファームウェア、ハードウェア)はOSから監視ができないため、攻撃が成立してしまう...ということで、この文書...

ではどうするか?というと、主要なコンポーネントのファームウェアに軽量な監視ロジックを追加する。。。そして、電力消費量の変化、DMAの読み取りバイト数などを把握し、異常を検知した場合、証拠パケットを“怪しいデバイス”に送り、そのデバイスが自分で異常と判断したら、たとえば自律防御する。。。ということなのでしょうかね。。。

 

● NIST - ITL

・2026.04.15 NIST CSWP 52 Firmware-Based Monitoring for Bus-Based Computer Systems

NIST CSWP 52 Firmware-Based Monitoring for Bus-Based Computer Systems NIST CSWP 52 バスベースのコンピュータシステムにおけるファームウェアベースの監視
Abstract 概要
This paper describes design mechanisms that reconfigure component firmware as a network of forensic units that passively observe bus traffic to extract and share forensic data beyond typical communication. By employing consensus-building algorithms among these distributed units, the augmented firmware can collaboratively detect compromised nodes within a zero trust architecture to enable future system defense solutions. 本論文では、コンポーネントのファームウェアを再構成し、バストラフィックを受動的に監視して、通常のコミュニケーションを超えたフォレンジックデータを抽出・共有するフォレンジックユニットのネットワークとする設計メカニズムについて述べる。これらの分散ユニット間で合意形成アルゴリズムを採用することにより、拡張されたファームウェアは、ゼロトラストアーキテクチャ内で侵害されたノードを協調的に検知し、将来のシステム防御ソリューションを実現する。

 

・[PDF] CSWP.52

20260430-180255

・[DOCX][PDF] 仮訳

 

目次...

Executive Summary エグゼクティブサマリー
1. Introduction 1. 序論
2. Threat Model 2. 脅威モデル
3. Proposed System Architecture 3. 提案するシステムアーキテクチャ
3.1. Challenges in Existing Approaches 3.1. 既存手法の課題
3.2. Firmware Instrumentation for Attack Detection 3.2. 攻撃検知のためのファームウェア計測
3.2.1. Direct Event Collection From the System Bus (Preferred Method) 3.2.1. システムバスからの直接イベント収集(推奨手法)
3.2.2. Indirect Event Collection Through Event Synthesis 3.2.2. イベント合成による間接的なイベント収集
3.3. Detection Methods for Compromised Component Analysis 3.3. 侵害されたコンポーネントの分析における検知手法
3.3.1. Local Data Fusion for Event Reconstruction 3.3.1. イベント再構築のためのローカルデータ融合
3.4. Efficient Local Trust Management for Attack Monitoring 3.4. 攻撃監視のための効率的なローカル・トラスト管理
3.4.1. Structure and Content of the LTT 3.4.1. LTTの構造と内容
3.4.2. Enhancing Trustworthiness Through Cross-Validation 3.4.2. 妥当性確認による信頼性の向上
3.5. Hierarchical Detection 3.5. 階層的検知
3.5.1. Threat-Specific Detection 3.5.1. 脅威固有の検知
3.5.2. Consensus-Informed Detection 3.5.2. コンセンサスに基づく検知
3.5.3. Default 3.5.3. デフォルト
4. Conclusions and Future Work 4. 結論と今後の課題
References 参考文献

 

図1. LTTを備えたバス接続ノードの侵害を検知・修復するために用いられる、分散合意に基づくゼロトラストアーキテクチャ

1_20260430212901

 

 

エグゼクティブサマリー...

Executive Summary  エグゼクティブサマリー 
The inherent vulnerabilities of bus-based computing systems that operate under implicit trust  and the limitations of existing recovery methods due to a lack of detailed forensic data underline the need for more resilient and proactive system defense strategies. Tackling the ongoing risks associated with cascading implicit trust, especially in bus-based computing systems, calls for innovative solutions.  暗黙の信頼の下で動作するバスベースのコンピューティングシステムに内在する脆弱性、および詳細なフォレンジックデータの欠如による既存の復旧手法の限界は、よりレジリエントで予防的なシステム防御戦略の必要性を浮き彫りにしている。特にバスベースのコンピューティングシステムにおいて、連鎖する暗黙の信頼に伴う継続的なリスクに対処するには、革新的な解決策が求められる。 
This paper describes a novel, low-cost approach to effectively monitoring security attacks in bus-based systems and designing mechanisms that can repurpose component firmware as a network of forensic units. These units enable a more comprehensive monitoring of system activity by providing observation vantage points for attacks that are not typically visible to OS- and application-level monitors. The system is built on distributed hardware components and uses consensus-building algorithms that can aggregate knowledge about a system’s state from individual components to identify compromised nodes within a zero trust environment. It can also use indirect methods (e.g., event synthesis) to generate attack-related data for attack analyzer modules.  本論文では、バスベースシステムにおけるセキュリティ攻撃を効果的に監視し、コンポーネントのファームウェアをフォレンジックユニットのネットワークとして再利用できるメカニズムを設計するための、新規かつ低コストなアプローチを説明する。これらのユニットは、OS やアプリケーションレベルのモニターでは通常可視化できない攻撃に対する観測拠点を提供することで、システムアクティビティのより包括的な監視を可能にする。 本システムは分散型ハードウェアコンポーネント上に構築されており、個々のコンポーネントからシステム状態に関する情報を集約して、ゼロトラスト環境内で侵害されたノードを識別できる合意形成アルゴリズムを採用している。また、間接的な手法(例:イベント合成)を用いて、攻撃解析モジュール向けの攻撃関連データを生成することも可能である。 
To minimize the system performance costs introduced by the firmware-based monitor, there is also a distributed local trust management mechanism enabled by a local trust table (LTT) at each node. The LTT tracks the trustworthiness of nearby nodes to enable fast, localized detection of malicious behavior without relying on expensive centralized monitoring methods. This consensus building helps validate the information held across individual nodes and improves an individual node’s ability to borrow the system-wide knowledge collectively held by others. Finally, this hierarchical detection approach seeks to efficiently handle previously wellknown threats within the node and resort to consensus-based detection when a local node does not have sufficient confidence in detecting the attack.  ファームウェアベースのモニターによって生じるシステムパフォーマンスの負荷を最小限に抑えるため、各ノードにローカル・トラスト・テーブル(LTT)を備えた分散型ローカル・トラスト管理メカニズムも実装されている。LTTは近隣ノードの信頼性を追跡し、コストのかかる集中型監視手法に依存することなく、悪意のある動作を迅速かつ局所的に検知することを可能にする。この合意形成は、個々のノードが保持する情報の妥当性確認に役立ち、他のノードが集団的に保持するシステム全体の知識を個々のノードが活用する能力を向上させる。 最後に、この階層的な検知アプローチは、ノード内で既知の脅威を効率的に処理すると同時に、ローカルノードが攻撃の検知に十分な確信を持てない場合に、コンセンサスベースの検知に切り替えることを目指している。 

 

 

 

| | Comments (0)

2026.04.28

米国 NIST CSWP 36 5Gサイバーセキュリティおよびプライバシー機能の適用:ホワイトペーパーシリーズ (2026.03.19)

こんにちは、丸山満彦です。

NISTがCSWP 36 5Gサイバーセキュリティおよびプライバシー機能の適用:ホワイトペーパーシリーズを公表しています...

序論もあわせると全6文書です...

NIST - ITL

文書番号 表題 主な目的 扱う 5G セキュリティ機能・テーマ
CSWP 36 5Gサイバーセキュリティおよびプライバシー機能の適用:ホワイトペーパーシリーズへの序論 5G セキュリティ全体像と NCCoE 実装プロジェクトの概要を示す 5G セキュリティ課題の全体像、NCCoE の実装方針、シリーズ全体の位置づけ
CSWP 36A サブスクリプション・コンシールド・アイデンティファイア(SUCI)による加入者識別子の防御:5Gサイバーセキュリティおよびプライバシー機能の適用 SUPI を暗号化する SUCI の仕組みと導入方法を説明 SUCI(ECIES による SUPI 暗号化)、加入者プライバシー保護、ローミング時の挙動
CSWP 36B ハードウェア対応セキュリティを用いた 5G システムプラットフォームの完全性の確保:5G サイバーセキュリティおよびプライバシー機能の適用 5G コア基盤の完全性をハードウェアルートオブトラストで確保する方法を示す HRoT、TPM、リモートアテステーション、Kubernetes/CNF との連携
CSWP 36C 一時的なIDの再割り当て:5Gサイバーセキュリティおよびプライバシー機能の適用 一時 ID(5G-GUTI)の頻繁な再割り当てによる追跡防止を説明 一時 ID の再割り当て、追跡困難化、4G との比較、ローミング時の挙動
CSWP 36D SUPI 非依存のページング方式:Applying 5G サイバーセキュリティとプライバシー能力 ページングに SUPI を使わない 5G の新方式を説明 5G-S-TMSI のみを用いたページング、PO 計算、GUTI 再割り当てとの連動
CSWP 36E 5Gネットワークセキュリティ設計原則:5Gサイバーセキュリティおよびプライバシー機能の適用 5G ネットワークのデータ/制御/O&M トラフィックを論理的に分離する設計原則を示す VRF、ネットワーク分離、スパイン・リーフ構成、BGP/ECMP、O&M 保護

 

NIST CSWP 36 Applying 5G Cybersecurity and Privacy Capabilities: Introduction to the White Paper Series NIST CSWP 36 「5Gサイバーセキュリティおよびプライバシー機能の適用:ホワイトペーパーシリーズへの序論」
Abstract 概要
This document introduces the white paper series titled Applying 5G Cybersecurity and Privacy Capabilities. This series is being published by the National Cybersecurity Center of Excellence (NCCoE) 5G Cybersecurity project. 5G introduced new security capabilities in the standards focusing on securing interoperable interfaces rather than the underlying IT infrastructure, leaving gaps and options in specified cybersecurity and privacy protections that complicate how organizations assess, deploy, and supplement security for 5G systems. The 5G Cybersecurity project implemented security capabilities within the 5G standards and for the underlying IT infrastructure not specified in 5G standards and demonstrated their effectiveness. Each paper in the series includes implementation guidelines and testbed-derived implementation findings for an individual technical cybersecurity- or privacy-supporting capability available in 5G systems or their supporting infrastructures. Each of the capabilities has been implemented in the NCCoE 5G Cybersecurity testbed as part of the NCCoE project, and each white paper reflects the results of that implementation and its testing. 本書は、「5Gサイバーセキュリティおよびプライバシー機能の適用」と題されたホワイトペーパーシリーズを紹介するものである。本シリーズは、国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)の5Gサイバーセキュリティ・プロジェクトによって発行されている。5Gは、基盤となるITインフラストラクチャではなく、相互運用可能なインターフェースのセキュリティ確保に重点を置いた新たなセキュリティ機能を標準に導入した。その結果、規定されたサイバーセキュリティおよびプライバシー保護にはギャップや選択肢が残され、組織が5Gシステムのセキュリティをアセスメント、展開、補完する方法を複雑化させている。5Gサイバーセキュリティプロジェクトは、5G標準内にセキュリティ機能を実装するとともに、5G標準で規定されていない基盤となるITインフラストラクチャ向けのセキュリティ機能も実装し、その有効性を実証した。本シリーズの各文書には、5Gシステムまたはその支援インフラストラクチャで利用可能な、個々の技術的なサイバーセキュリティまたはプライバシー支援機能に関する実装ガイドラインと、テストベッドから得られた実装結果が含まれている。各機能はNCCoEプロジェクトの一環としてNCCoE 5Gサイバーセキュリティテストベッドに実装されており、各ホワイトペーパーはその実装およびテストの結果を反映している。
20260426-172242
CSWP.36

NIST CSWP 36A Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI): Applying 5G Cybersecurity and Privacy Capabilities NIST CSWP 36A サブスクリプション・コンシールド・アイデンティファイア(SUCI)による加入者識別子の防御:5Gサイバーセキュリティおよびプライバシー機能の適用
Abstract 概要
This white paper describes how Subscription Concealed Identifier (SUCI) protection can be enabled in 5G networks. SUCI protection is defined by 5G standards as an optional security capability for operator deployments. Although it is optional, it provides important security and privacy protections for subscriber identifiers. By enabling SUCI on their 5G networks and subscriber SIMs, and configuring SUCI to use a non-null encryption cipher scheme, 5G network operators can provide their customers with the advantages of SUCI’s protections. The network operators should carefully evaluate the risks of not enabling this critical capability. This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity and privacy-supporting capabilities that were demonstrated and verified on the National Cybersecurity Center of Excellence (NCCoE)’s 5G Cybersecurity testbed. 本ホワイトペーパーでは、5Gネットワークにおいてサブスクリプション・コンシールド・アイデンティファイア(SUCI)防御を有効化する方法について説明する。SUCI保護は、5G標準において、通信事業者の展開に向けたオプションのセキュリティ機能として定義されている。オプションではありますが、加入者識別子に対して重要なセキュリティおよびプライバシー保護を提供する。5Gネットワークおよび加入者のSIM上でSUCIを有効化し、SUCIを非ヌル暗号化方式を使用するように設定することで、5Gネットワーク事業者は顧客にSUCIの保護機能による利点を提供できる。ネットワーク事業者は、この重要な機能を有効にしないことによるリスクを慎重に評価する必要がある。本ホワイトペーパーは、「5Gサイバーセキュリティおよびプライバシー機能の適用」と題されたシリーズの一部であり、国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)の5Gサイバーセキュリティ・テストベッド上で実証および検証された、5Gのサイバーセキュリティおよびプライバシー支援機能について取り上げている。
20260426-172254
CSWP.36A

NIST CSWP 36B Using Hardware-Enabled Security to Ensure 5G System Platform Integrity: Applying 5G Cybersecurity and Privacy Capabilities NIST CSWP 36B ハードウェア対応セキュリティを用いた 5G システムプラットフォームの完全性の確保:5G サイバーセキュリティおよびプライバシー機能の適用
Abstract 概要
This white paper provides an overview and an example of employing hardware-enabled security capabilities to provision, measure, attest to, and enforce the integrity of the compute platform to foster trust in a 5G system’s server infrastructure. It discusses security threats within computing environments and how leveraging hardware roots of trust (HRoT) and remote attestation can help mitigate specific threats. This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity- and privacy- supporting capabilities that were demonstrated as part of the 5G Cybersecurity project at the National Cybersecurity Center of Excellence (NCCoE). 本ホワイトペーパーでは、5G システムのサーバーインフラストラクチャに対する信頼を醸成するために、ハードウェア対応セキュリティ機能を活用して、コンピューティングプラットフォームの完全性をプロビジョニング、測定、証明、および強制する手法の概要と事例を紹介しる。本稿では、コンピューティング環境内のセキュリティ脅威について論じ、ハードウェア・ルート・オブ・トラスト(HRoT)およびリモートアテステーションを活用することで、特定の脅威を緩和する方法について解説する。本ホワイトペーパーは、「5Gサイバーセキュリティおよびプライバシー機能の適用」と題されたシリーズの一部であり、国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)における5Gサイバーセキュリティプロジェクトの一環として実証された、5Gサイバーセキュリティおよびプライバシーを支援する機能について扱っている。
20260426-172303
CSWP.36B

NIST CSWP 36C Reallocation of Temporary Identities: Applying 5G Cybersecurity and Privacy Capabilities NIST CSWP 36C 一時的なIDの再割り当て:5Gサイバーセキュリティおよびプライバシー機能の適用
Abstract 概要
This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity- and privacy-supporting capabilities that were implemented as part of the 5G Cybersecurity project at the National Cybersecurity Center of Excellence (NCCoE). This white paper describes how 5G standards have enhanced the implementation guideline to protect subscriber identities (IDs), specifically how the network reallocates temporary IDs to protect users from being identified and located by an attacker. Unlike previous generations of cellular systems, new requirements in 5G explicitly define when the temporary ID must be reallocated (refreshed). 5G network operators should know how this standards-defined security capability protects their users and subscribers. Operators should ensure that their 5G technologies are refreshing temporary identities as described in the 5G standards. 本ホワイトペーパーは、「5Gサイバーセキュリティおよびプライバシー機能の適用」というシリーズの一部であり、国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)における5Gサイバーセキュリティプロジェクトの一環として実装された、5Gのサイバーセキュリティおよびプライバシーを支援する機能について取り上げている。本ホワイトペーパーでは、5G標準が加入者ID(ID)を防御するための実装ガイドラインをどのように強化したか、具体的には、攻撃者によるユーザーの識別や位置情報の把握からユーザーを防御するために、ネットワークが一時IDを再割り当てする仕組みについて説明する。従来の世代のセルラーシステムとは異なり、5Gの新たな要件では、一時IDをいつ再割り当て(更新)しなければならないかが明示的に定義されている。5Gネットワーク事業者は、この標準で定義されたセキュリティ機能がユーザーや加入者をどのように防御するのかを理解しておく必要がある。事業者は、自社の5G技術が5G標準に記述されているとおりに一時IDを更新していることを確認する必要がある。
20260426-172309
CSWP.36C

NIST CSWP 36D No SUPI-Based Paging: Applying 5G Cybersecurity and Privacy Capabilities NIST CSWP 36D SUPI 非依存のページング方式:Applying 5G サイバーセキュリティとプライバシー能力
Abstract 概要
This white paper provides an overview of “no Subscription Permanent Identifier (SUPI) based paging,” a 5G capability for protecting users from being identified and located by an attacker. Unlike previous generations of cellular systems, new requirements in 5G standards protect subscriber confidentiality by using a temporary identity (ID) instead of SUPI for the paging protocol, and explicitly define when the temporary ID must be reallocated (refreshed). 5G network operators and organizations using 5G technologies are encouraged to verify that the paging is happening as described in the 5G standards. This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity- and privacy-supporting capabilities that were implemented as part of the 5G Cybersecurity project at the National Cybersecurity Center of Excellence (NCCoE). 本ホワイトペーパーは、攻撃者によるユーザーの識別や位置情報の把握からユーザーを防御するための5G機能である、「サブスクリプション永続識別子(SUPI)非依存のページング」の概要を説明する。従来の携帯電話システムとは異なり、5G標準の新たな要件では、ページングプロトコルにおいてSUPIの代わりに一時的な識別子を使用することで加入者の機密性を保護し、一時的な識別子をいつ再割り当て(更新)すべきかを明確に定義している。5Gネットワーク事業者および5G技術を利用する組織は、ページングが5G標準に記載されているとおりに実施されていることを確認することが推奨される。本ホワイトペーパーは、「5Gサイバーセキュリティおよびプライバシー機能の適用」と題されたシリーズの一部であり、国立サイバーセキュリティ・センター・オブ・エクセレンス(NCCoE)における5Gサイバーセキュリティプロジェクトの一環として実装された、5Gのサイバーセキュリティおよびプライバシーを支援する機能について取り上げている。
20260426-172323
SWP.36D


NIST CSWP 36E 5G Network Security Design Principles: Applying 5G Cybersecurity and Privacy Capabilities NIST CSWP 36E 5Gネットワークセキュリティ設計原則:5Gサイバーセキュリティおよびプライバシー機能の適用
Abstract 概要
This white paper describes the network infrastructure design principles that commercial and private 5G network operators can use to improve cybersecurity and privacy. Such a network infrastructure isolates types of 5G network traffic from each other: data plane, control plane, and operation and maintenance (O&M) traffic. This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity and privacy-supporting capabilities that were demonstrated on the NIST National Cybersecurity Center of Excellence (NCCoE) 5G security testbed as part of the 5G Cybersecurity project at the NCCoE. 本ホワイトペーパーでは、商用およびプライベート5Gネットワーク事業者がサイバーセキュリティとプライバシーを向上させるために活用できるネットワークインフラストラクチャの設計原則について説明する。このようなネットワークインフラストラクチャは、データプレーン、コントロールプレーン、および運用・保守(O&M)トラフィックといった5Gネットワークトラフィックの種類を互いに分離する。本ホワイトペーパーは、「5Gサイバーセキュリティおよびプライバシー機能の適用」と題されたシリーズの一部であり、NCCoE(国立サイバーセキュリティ・センター・オブ・エクセレンス)における5Gサイバーセキュリティプロジェクトの一環として、NCCoEの5Gセキュリティテストベッド上で実証された5Gサイバーセキュリティおよびプライバシー支援機能について取り上げている。
20260426-172330
CSWP.36E

 

 


 

● まるちゃんの情報セキュリティ気まぐれ日記

・2025.06.22 米国 NIST CSWP 36E (初期公開ドラフト) 5G ネットワークセキュリティ設計原則:5G サイバーセキュリティおよびプライバシー機能の適用 (2025.06.17)

・2025.02.02 米国 NIST CSWP 36D(初期公開ドラフト)非SUPI ベースのページング:5G サイバーセキュリティおよびプライバシー機能の適用 (2025.01.30)

・2024.11.14 米国 NIST CSWP 36C (初期公開ドラフト) 一時的な ID の再割り当て: 5Gサイバーセキュリティとプライバシー機能の適用 (2024.11.06)

・2024.10.09 米国 NIST NIST CSWP 36B(初期公開草案) ハードウェア対応セキュリティによる5Gシステムプラットフォームの完全性の確保:5Gのサイバーセキュリティおよびプライバシー機能の適用

・2024.08.16 米国 NIST CSWP 36 5Gのサイバーセキュリティとプライバシー機能の適用:ホワイトペーパーシリーズ序文、36A Subscription Concealed Identifier(SUCI)による加入者識別子の保護


 

 

| | Comments (0)

2026.04.17

中国 サイバーセキュリティラベル管理弁法を公布 適用は2026.07.01から (2026.04.10)

こんにちは、丸山満彦です。

昨年11月に意見募集をした中国のIoT機器のセキュリティ認証制度について、法制化されましたね...JC-STARの中国版ですね...

星(等級)は3段階。ラベルには、等級と生産者名、製品型番、有効期間の記載だけでなく、QRコードをスキャンすると検査報告書や詳細なセキュリティ情報が見られるようにするようです...

星3は第三者機関のペネトレーションテストが必要のようです...

ドイツ、日本、米国、中国で似たような制度になっているので、国際標準にしてしまえばよいのにと思いました...

 

国家互联网信息办公室(国家サイバースペース管理局)

・2026.04.10 关于印发《网络安全标识管理办法》的通知

关于印发《网络安全标识管理办法》的通知 『サイバーセキュリティラベル管理弁法』の公布に関する通知
国信办发文〔2026〕4号 国信弁発〔2026〕4号
各省、自治区、直辖市网信办、通信管理局、公安厅,新疆生产建设兵团网信办、公安局,中央和国家机关有关部门,各有关单位: 各省・自治区・直轄市のインターネット情報弁公室、通信管理局、公安庁、新疆生産建設兵団のインターネット情報弁公室、公安局、中央および国家機関の関連部門、各関係機関:
现将《网络安全标识管理办法》印发给你们,请遵照执行。 ここに『サイバーセキュリティラベル管理弁法』を公布する。これに従い執行すること。
国家互联网信息办公室 国家サイバースペース管理局
工业和信息化部 工業情報化部
公安部 公安部
2026年4月2日 2026年4月2日
网络安全标识管理办法 サイバーセキュリティラベル管理弁法
第一章 总则 第一章 総則
第一条 为提升产品的网络安全能力,加强消费者权益保护,维护网络安全和公共利益,根据《中华人民共和国网络安全法》等法律法规,制定本办法。 第一条 製品のサイバーセキュリティ能力を向上させ、消費者の権益保護を強化し、サイバーセキュリティ及び公共の利益を維持するため、『中華人民共和国サイバーセキュリティ法』等の法律・法規に基づき、本弁法を制定する。
第二条 本办法所称网络安全标识,是指能够反映产品本身网络安全能力水平的信息标识。 第二条 本弁法において「サイバーセキュリティラベル」とは、製品自体のサイバーセキュリティ能力のレベルを反映し得る情報ラベルをいう。
具有互联网联网功能的产品适用于本办法,具体产品实施目录管理。 インターネット接続機能を有する製品は本弁法の適用対象とし、具体的な製品については目録管理を実施する。
第三条 网络安全标识管理工作坚持统筹发展和安全,产品生产者按照自愿原则参与。 第三条 サイバーセキュリティラベルの管理業務は、発展と安全の統一的な調整を堅持し、製品製造者は自発的な原則に基づき参加する。
鼓励产品生产者依据本办法提升产品网络安全能力,标注网络安全标识。 製品製造者が本弁法に基づき製品のサイバーセキュリティ能力を向上させ、サイバーセキュリティラベルを表示することを奨励する。
鼓励消费者优先选用标注网络安全标识的产品。 消費者がサイバーセキュリティラベルが表示された製品を優先的に選択することを奨励する。
第四条 国家互联网信息办公室、工业和信息化部、公安部负责网络安全标识管理工作,分批制定公布《实施网络安全标识的产品目录》,明确每类产品的具体实施规则和依据的国家标准或技术文件,组织开展网络安全标识宣传教育,委托中国电子技术标准化研究院(以下简称备案机构)承担网络安全标识备案、信息发布等工作。 第四条 国家サイバースペース管理局、工業情報化部、公安部は、サイバーセキュリティラベルの管理業務を担当し、『サイバーセキュリティラベルを実施する製品目録』を段階的に策定・公表し、各製品類の具体的な実施規則および根拠となる国家標準または技術文書を明確にし、サイバーセキュリティラベルに関する広報・教育活動を組織・展開し、中国電子技術標準化研究院(以下、「届出機関」という)にサイバーセキュリティラベルの届出、情報公開等の業務を委託する。
第二章 标识实施 第二章 セキュリティラベルの実施
第五条 网络安全标识对应的网络安全能力由低到高依次为基础级、增强级、领先级,相应的标识等级分别用一星、二星、三星表示。基础级要求产品应当满足相关国家标准的基本安全要求,如不存在弱口令或通用默认口令、建立漏洞管理机制并动态修复漏洞、保持软件更新等;增强级要求产品网络安全能力达到同类产品先进水平;领先级要求产品网络安全能力达到同类产品领先水平,同时还应通过渗透性测试方法,检测抵御高级别网络攻击的能力。 第五条 サイバーセキュリティラベルに対応するサイバーセキュリティ能力は、低い順に基礎級、強化級、先進級とし、それぞれのラベル等級は一星、二星、三星で表示する。基礎級では、製品が関連する国家標準の基本的安全要件を満たすことを求める。例えば、脆弱なパスワードや一般的なデフォルトパスワードが存在しないこと、脆弱性管理メカニズムを確立し脆弱性を動的に修正すること、ソフトウェアの更新を維持することなどである。強化級では、製品のサイバーセキュリティ能力が同種の製品の先進的な水準に達していることを求める。最先端級では、製品のサイバーセキュリティ能力が同種の製品の最先端水準に達していることを求めると同時に、ペネトレーションテスト手法を通じて、高レベルのサイバー攻撃に対する防御能力を検証しなければならない。
每类产品的标识等级具体安全要求,在实施规则中确定。安全要求应当和现行国家标准、国际标准做好衔接,充分借鉴吸收其它实施网络安全标识制度国家和地区的相关经验。 各製品カテゴリーのラベル等級の具体的な安全要件は、実施規則において定める。安全要件は、現行の国家標準および国際標準と整合させ、サイバーセキュリティラベル制度を実施している他の国や地域の関連経験を十分に参考にし、取り入れるものとする。
第六条 网络安全标识(英文名称为China Cybersecurity Label)应当包括以下基本内容: 第六条 サイバーセキュリティラベル(英語名称:China Cybersecurity Label)には、以下の基本内容を含めるものとする:
(一)产品生产者名称; (一)製品製造者の名称;
(二)产品规格型号; (二)製品の仕様・型番;
(三)网络安全能力等级; (三)サイバーセキュリティ能力等級;
(四)网络安全标识有效期; (四)サイバーセキュリティラベルの有効期間;
(五)检测实验室名称; (五)検査機関の名称;
(六)依据的国家标准或技术文件编号; (六)根拠となる国家標準または技術文書の番号;
(七)备案信息码,通过扫码可以获取检测报告、关键指标、产品生产者符合性声明等信息。 (七)登録情報コード。これをスキャンすることで、検査報告書、主要指標、製品製造者の適合宣言などの情報を取得できる。
网络安全标识基本样式如下: サイバーセキュリティラベルの基本様式は以下の通りである:
1_20251130085401
每类产品标识的具体样式应当在对应的实施规则中明确,可根据产品实际形态在上述基本样式基础上适当调整。 各製品カテゴリーのセキュリティラベルの具体的な様式は、対応する実施規則において明確にするものとし、製品の実際の形態に応じて、上記の基本様式を基に適切に調整することができる。
第七条 需要标注网络安全标识的产品,产品生产者应当依据实施规则相关要求开展网络安全能力检测,确定网络安全能力等级,并取得检测报告。 第七条 サイバーセキュリティラベルの表示が必要な製品について、製品製造者は実施規則の関連要件に基づきサイバーセキュリティ能力検査を実施し、サイバーセキュリティ能力等級を確定するとともに、検査報告書を取得しなければならない。
(一)需要标注一星级、二星级的产品,产品生产者可以利用自有检测实验室或者委托依法取得资质认定的第三方检测机构开展检测; (一)一星級、二星級の表示が必要な製品については、製品製造者は自社の検査実験室を利用するか、または法に基づき資格認定を受けた第三者検査機関に委託して検査を実施することができる;
(二)需要标注三星级的产品,产品生产者在满足有关检测要求基础上,还应当委托符合条件的第三方检测机构开展渗透性测试。 (二)三星級の表示が必要な製品については、製品製造者は関連する検査要件を満たすことに加え、条件を満たす第三者検査機関にペネトレーションテストの実施を委託しなければならない。
第八条 备案机构建设网络安全标识备案管理平台,产品生产者备案网络安全标识通过平台线上办理。 第八条 届出機関はサイバーセキュリティラベル届出管理プラットフォームを構築し、製品製造者は同プラットフォームを通じてオンラインでサイバーセキュリティラベルの届出を行うものとする。
备案时应当提交以下材料的电子版: 届出の際には、以下の資料の電子版を提出しなければならない:
(一)网络安全标识备案表; (一)サイバーセキュリティラベル届出書;
(二)网络安全能力等级检测报告; (二)サイバーセキュリティ能力等級検査報告書;
(三)依据实施规则设计的本产品网络安全标识样式; (三)実施規則に基づき設計された当該製品のサイバーセキュリティラベルの様式;
(四)产品生产者符合性声明; (四)製品製造者の適合性宣言;
(五)产品生产者营业执照; (五)製品製造者の営業許可証;
(六)自有检测实验室的相关检测能力证明材料,或者第三方检测机构相关资质认定证书; (六)自社検査室の関連検査能力を証明する資料、または第三者検査機関の関連資格認定証明書;
(七)由代理人提交备案材料的,还应当提交产品生产者的委托代理文件等。 (七)代理人が届出資料を提出する場合は、製品製造者の委任状等を併せて提出しなければならない。
产品生产者及代理人应当对上述材料的真实性、准确性、完整性负责。 製品製造者及び代理人は、上記資料の真実性、正確性、完全性について責任を負うものとする。
第九条 备案机构应当自收到完整备案材料之日起10个工作日内,对材料的真实性、准确性、完整性进行形式审查,完成备案工作并公告产品相关备案信息。 第九条 届出受理機関は、完全な届出資料を受領した日から10営業日以内に、資料の真実性、正確性、完全性について形式審査を行い、届出手続きを完了させ、製品に関する届出情報を公告しなければならない。
备案完成后,产品生产者可以按照实施规则要求印制、使用和展示网络安全标识。 届出完了後、製品製造者は実施規則の要件に従い、サイバーセキュリティラベルを印刷、使用、および表示することができる。
第十条 网络安全标识有效期在相关产品实施规则中明确。备案完成的产品,关键技术参数等发生变更可能影响产品网络安全能力的,或者标识超过有效期的,应当重新备案。 第十条 サイバーセキュリティラベルの有効期間は、関連製品の実施規則において明確にされる。届出が完了した製品について、主要な技術パラメータ等の変更により製品のサイバーセキュリティ能力に影響を及ぼす可能性がある場合、またはラベルの有効期間が満了した場合は、再届出を行わなければならない。
第十一条 任何组织和个人不得伪造、冒用网络安全标识或者利用网络安全标识进行虚假宣传。 第十一条 いかなる組織および個人も、サイバーセキュリティラベルを偽造、不正使用してはならず、またサイバーセキュリティラベルを利用して虚偽の宣伝を行ってはならない。
第十二条 备案机构应当建立健全网络安全标识备案工作规范,客观、公正开展网络安全标识备案相关工作。 第十二条 届出機関は、サイバーセキュリティラベルの届出業務規範を確立・整備し、客観的かつ公正にサイバーセキュリティラベルの届出関連業務を実施しなければならない。
产品生产者自有检测实验室或者第三方检测机构应当严格按照有关标准开展检测,保证检测结果客观公正、真实准确,不得伪造检测结果或者出具虚假检测报告。 製品製造者の自社検査室または第三者検査機関は、標準に厳格に従って検査を実施し、検査結果が客観的かつ公正で、真実かつ正確であることを保証し、検査結果を偽造したり、虚偽の検査報告書を発行したりしてはならない。
备案机构和检测机构不得泄露在工作中知悉的国家秘密、商业秘密。 届出機関および検査機関は、業務上知り得た国家機密、営業秘密を漏洩してはならない。
第三章 监督管理 第三章 監督管理
第十三条 国家互联网信息办公室、工业和信息化部、公安部负责组织对网络安全标识备案、使用情况进行监督检查,发现有违反本办法规定行为的,按照有关规定及时处理。 第十三条 国家サイバースペース管理局、工業情報化部、公安部は、セキュリティラベルの届出および使用状況に対する監督検査を組織する責任を負い、本弁法の規定に違反する行為を発見した場合は、関連規定に基づき速やかに処理する。
地方网信部门、通信管理局、公安机关负责组织对本区域内网络安全标识使用进行监督检查,强化信息共享,发现有违反本办法规定行为的,应当会同相关部门按照有关规定处理,并及时通知备案机构。 地方のインターネット情報部門、通信管理局、公安機関は、管轄区域内におけるセキュリティラベルの使用に対する監督検査を組織する責任を負い、情報共有を強化する。本弁法の規定に違反する行為を発見した場合は、関連部門と協力して関連規定に基づき処理し、速やかに届出機関に通知しなければならない。
第十四条 发现以下情况,备案机构应当撤销备案并及时公告: 第十四条 以下の状況が判明した場合、届出受理機関は届出を取り消し、速やかに公告しなければならない:
(一)备案材料弄虚作假的; (一)届出資料に虚偽の記載がある場合;
(二)网络安全标识与实际网络安全能力不相符的; (二)サイバーセキュリティラベルが実際のサイバーセキュリティ能力と一致しない場合;
(三)使用的网络安全标识不符合有关样式、规格等标注规定的; (三)使用されているサイバーセキュリティラベルが、様式、規格等の表示規定に適合しない場合;
(四)产品生产者终止对备案产品开展技术支持服务的; (四)製品製造者が、届出製品に対する技術サポートサービスを終了した場合;
(五)其他应当撤销备案的违规行为。 (五)その他、届出を取り消すべき違反行為。
第十五条 产品生产者伪造、冒用网络安全标识或者利用网络安全标识进行虚假宣传的,备案机构应当撤销相关产品的网络安全标识备案,对产品生产者违规行为予以公告,自公告之日起一年内不再受理其产品备案。 第十五条 製品製造者がサイバーセキュリティラベルを偽造・不正使用し、またはサイバーセキュリティラベルを利用して虚偽の宣伝を行った場合、届出機関は当該製品のサイバーセキュリティラベルの届出を取り消し、製品製造者の違反行為を公告し、公告の日から一年間は当該製品の届出を受け付けないものとする。
第十六条 产品生产者自有检测实验室或者第三方检测机构伪造检测结果或者出具虚假检测报告的,备案机构应当撤销相关产品的网络安全标识备案,对检测机构违规行为予以公告,自公告之日起一年内不再采信其检测结果。 第十六条 製品製造者の自社検査室または第三者検査機関が検査結果を偽造し、または虚偽の検査報告書を発行した場合、届出機関は当該製品のサイバーセキュリティラベルの届出を取り消し、検査機関の違反行為を公告し、公告の日から一年間、その検査結果を認めないものとする。
第十七条 产品生产者、第三方检测机构等发生网络安全能力检测弄虚作假、伪造冒用网络安全标识等行为的,由有关主管部门按照《中华人民共和国网络安全法》、《检验检测机构监督管理办法》等法律法规进行处罚。 第十七条 製品製造者、第三者検査機関等が、サイバーセキュリティ能力検査における不正行為、セキュリティラベルの偽造・不正使用等の行為を行った場合、関係主管部門は『中華人民共和国サイバーセキュリティ法』、『検査・測定機関監督管理弁法』等の法律法規に基づき処罰を行う。
第十八条 任何组织和个人发现违反本办法规定的行为,可以向地方网信部门、通信管理局、公安机关举报。地方网信部门、通信管理局、公安机关应当及时调查处理,并为举报人保密,调查过程中备案机构应当予以配合。 第十八条 いかなる組織または個人も、本弁法の規定に違反する行為を発見した場合は、地方のインターネット情報部門、通信管理局、公安機関に通報することができる。地方のインターネット情報部門、通信管理局、公安機関は、速やかに調査・処理を行い、通報者の秘密を保持しなければならない。調査過程において、届出受理機関はこれに協力しなければならない。
第十九条 网络安全能力检测过程中发现或者获知产品安全漏洞的,应当按照《网络产品安全漏洞管理规定》有关要求进行报告、修补和发布。 第十九条 サイバーセキュリティ能力検査の過程において製品のセキュリティ脆弱性が発見または判明した場合は、『ネットワーク製品セキュリティ脆弱性管理規定』の関連要件に従い、報告、修正および公表を行わなければならない。
第二十条 国家互联网信息办公室、工业和信息化部、公安部等对违反本办法规定的行为建立信用记录,并纳入全国信用信息共享平台。 第二十条 国家サイバースペース管理局、工業情報化部、公安部等は、本弁法の規定に違反する行為について信用記録を作成し、全国信用情報共有プラットフォームに組み入れるものとする。
第四章 附则 第四章 附則
第二十一条 本办法所称网络安全能力,是指产品生产者通过采取必要技术和管理措施,使产品本身具备防范攻击、侵入、干扰、破坏和非法使用,保障产品稳定可靠运行和网络数据完整性、保密性、可用性的能力。 第二十一条 本弁法において「サイバーセキュリティ能力」とは、製品製造者が必要な技術的・管理的措置を講じることで、製品自体が攻撃、侵入、妨害、破壊および不正使用を防止し、製品の安定的かつ信頼性の高い稼働ならびにネットワークデータの完全性、機密性、可用性を保障する能力を指す。
第二十二条 网络关键设备和网络安全专用产品依据国家互联网信息办公室、工业和信息化部、公安部、财政部、国家认证认可监督管理委员会《关于调整网络安全专用产品安全管理有关事项的公告》(2023年第1号)开展安全管理,不列入《实施网络安全标识的产品目录》。 第二十二条 ネットワーク重要設備およびサイバーセキュリティ専用製品は、国家サイバースペース管理局、工業情報化部、公安部、財政部、国家認証認可監督管理委員会の『サイバーセキュリティ専用製品の安全管理に関する事項の調整についての公告』(2023年第1号)に基づき安全管理を実施し、『サイバーセキュリティラベルを実施する製品目録』には含まれない。
第二十三条 本办法自2026年7月1日起施行。 第二十三条 本弁法は2026年7月1日から施行する。

 

 

 


 

● まるちゃんの情報セキュリティ気まぐれ日記

中国...

・2025.11.30 中国 国家サイバースペース管理局 意見募集「サイバーセキュリティラベル管理弁法」(2025.11.21)

・2022.02.15 中国 国家サイバースペース管理局 専門家の解説 ネットワーク重要機器のセキュリティ認証とセキュリティテストによるネットワークセキュリティの基本ディスクの維持

・2025.11.30 中国 サイバースペース管理局 意見募集「サイバーセキュリティラベル管理弁法」(2025.11.21)

 

日本

・2025.11.07 経済産業省 JC-STARと英国PSTI法の相互承認に関する覚書に署名 (2025.11.06)

・2025.05.30 IPA セキュリティ要件適合評価及びラベリング制度(JC-STAR)適合製品の公開 (2025.05.21)

・2025.05.27 経済産業省 「産業サイバーセキュリティ研究会」が「政策の方向性」と「産業界へのメッセージ」を発出(2025.05.23)

・2025.02.06 Five Eyes + チェコ、日本、韓国、オランダ エッジ・デバイスの安全に関する報告書...

・2024.10.01 IPA セキュリティ要件適合評価及びラベリング制度(JC-STAR)のページを開設

・2024.03.17 経済産業省 IoT製品に対するセキュリティ適合性評価制度構築に向けた検討会の最終とりまとめを公表し、制度構築方針案に対する意見公募を開始

・2023.05.17 経済産業省 産業サイバーセキュリティ研究会 WG3 IoT製品に対するセキュリティ適合性評価制度構築に向けた検討会 中間とりまとめ

・2022.11.04 経済産業省 第1回 産業サイバーセキュリティ研究会 ワーキンググループ3 IoT製品に対するセキュリティ適合性評価制度構築に向けた検討会

 

EU

・2024.10.12 欧州理事会 サイバーレジリエンス法を採択 (2024.10.10)

・2024.03.19 欧州議会 AI法 (2024.03.13) とサイバーレジリエンス法を採択 (2024.03.12)

・2024.02.02 欧州委員会 サイバーセキュリティ認証制度 (EUCC) を採択

・2024.01.17 欧州 欧州議会の投票にかけられるサイバーレジリエンス法案 (Cyber Resilience Act)

・2023.12.04 欧州理事会、欧州議会がサイバーレジリエンス法について政治的合意

・2023.05.31 ENISA 新技術に対応したEUサイバーセキュリティ認証の実現可能性を探る

・2023.03.21 ENISA サイバーセキュリティ認証のウェブページを開設

・2023.03.01 IPA 欧州規格 ETSI EN 303 645 V2.1.1 (2020-06)の翻訳の公開

・2023.02.02 ドイツ スペースネットAG社のサービスにITセキュリティラベルを渡す

・2022.12.15 ドイツ フランス IT製品のセキュリティ認証に関する共同文書を発行 (固定時間制認証制度)

・2022.10.31 ドイツ シンガポール 消費者向けIoT製品のサイバーセキュリティ・ラベルの相互承認 (2022.10.20)

・2022.05.09 ドイツ ITセキュリティラベル for 消費者向けスマート製品

・2022.02.03 ドイツ BSI Mail.deの電子メールサービスにITセキュリティラベルを付与

・2021.07.18 独国 BSIがITセキュリティラベルについてのウェブページを公開していますね。。。

 

米国...

・2025.06.14 米国 大統領令14306 国家のサイバーセキュリティを強化するための厳選された取り組みを維持し、大統領令13694と大統領令14144を改正する (2025.06.06)

・2025.05.16 米国 NIST IR 8259 Rev.1(初期公開ドラフト)IoT製品製造者のための基礎的サイバーセキュリティ活動の5年振りの改訂関係...IR 8572も...(2025.05.13)

・2025.01.10 米国 ホワイトハウス サイバートラストマークを開始...

・2024.12.28 米国 NIST IR 8498 スマートインバーターのサイバーセキュリティ:住宅および小規模商業用ソーラーエネルギーシステムのためのガイドライン(2024.12.20)

・2024.09.14 米国 NIST IR 8425A 一般消費者向けルーター製品に推奨されるサイバーセキュリティ要件 (2024.09.10)

・2024.09.13 米国 FCC IoTのためのサイバーセキュリティ・ラベリングFAQと管理者の申請プロセス (2024.09.10) 

・2024.08.02 米国 FCC IoTのためのサイバーセキュリティ・ラベリング最終規則

・2024.03.20 米国 連邦通信委員会 (FCC) がIoTサイバーセキュリティ表示プログラム(サイバートラストマーク)の規則を採択 (2024.03.14)

・2023.07.19 米国 消費者向けIoT製品のセキュリティ認証制度、サイバートラスト・マーク (U.S. Cyber Trust Mark) を発表

・2022.09.24 NIST NISTIR 8425 消費者向けIoT製品のIoTコアベースラインのプロファイル、NISTIR 8431 「NIST基礎の上に築く:IoTセキュリティの次のステップ」ワークショップ概要報告書

・2022.06.19 NISTIR 8425 (ドラフト) 消費者向けIoT製品のIoTコアベースラインのプロファイル

・2022.02.07 NIST ホワイトペーパー :消費者向けソフトウェアのサイバーセキュリティラベルの推奨規準

・2022.02.06 NIST ホワイトペーパー :消費者向けIoT製品のサイバーセキュリティラベルの推奨規準

・2021.11.04 NIST 消費者向けソフトウェアのサイバーセキュリティに関するラベリングについての意見募集

・2021.09.02 NIST ホワイトペーパー(ドラフト):消費者向けIoTデバイスのベースライン・セキュリティ基準

・2021.08.29 NISTIR 8259B IoT非技術的支援能力コアベースライン

・2021.05.13 米国 国家のサイバーセキュリティ向上に関する大統領令

・2020.12.17 NIST SP 800-213 (Draft) 連邦政府向け「 IoTデバイスサイバーセキュリティ要件の確立」、NISTIR 8259B、8259C、8259D

・2020.05.30 NIST IoT機器製造者向けセキュリティの実践資料 NISTIR 8259 Foundational Cybersecurity Activities for IoT Device Manufacturers, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline

・2020.02.06 NISTがIoT機器製造者向けセキュリティの実践資料のドラフト(Ver.2)を公開していますね。。。

 

英国...

・2025.11.07 経済産業省 JC-STARと英国PSTI法の相互承認に関する覚書に署名 (2025.11.06)

・2025.06.24 英国 ICO 意見募集 消費者向けIoT製品およびサービスに関するガイダンス (2025.06.16)

・2023.05.04 英国 インターネットに接続するすべての消費者向け製品に適用される最低セキュリティ基準制度が1年後にはじまりますよ〜 (2023.04.29)

・2023.04.25 Five Eyesの国々が安全なスマートシティを作るための共同ガイダンスを発表 (2023.04.20)

・2022.12.11 英国 製品セキュリティおよび電気通信インフラストラクチャ(PSTI)法成立 at 2022.12.06

・2022.01.27 英国 スマートデバイスのサイバーセキュリティ新法に一歩近づくと発表

・2021.12.09 英国 製品セキュリティおよび電気通信インフラストラクチャ(PSTI)法案 at 2021.11.24

 

| | Comments (0)

2026.04.12

総務省 EU、情報通信技術委員会(TTC) ETSIの協力についての公表... (2026.03)

こんにちは、丸山満彦です。

総務省とEU、TTCとETSIの連携についての発表がそれぞれされているので、参考まで...

 

● 総務省

・2026.03.31 日EU・ICTラウンドテーブル及び日EU・ICT政策対話(第31回)の結果

総務省は、3月27日(金)、欧州委員会 通信ネットワーク・コンテンツ・技術総局とともに、日EU・ICTラウンドテーブル及び日EU・ICT政策対話(第31回)を東京にて開催した。

 

1 日EU・ICTラウンドテーブル 2 日EU・ICT政策対話(第31回)
(1)概要 (1)概要
本ラウンドテーブルは、デジタル分野における政策、取組について日EUの官民で相互理解を深め、連携・協力を推進することを目的としている枠組みであり、ICT分野に関する幅広い議題が取り上げられ官民で活発な意見交換が行われました。 本政策対話は、ICT分野における政策について日EUの政府間で相互理解を深め、連携・協力を推進することを目的としています。今回の会合では、日EU間におけるICT分野の重要テーマに関し、双方の最新の取組について活発な議論が行われました。
(2)主な成果 (2)主な成果
ア Beyond 5G/6G ア 5G・Beyond 5G/6G
日本側から、オール光ネットワーク(APN)に係る取組、データセンターの分散化等データセンターに係る取組、日EU間における国際共同研究を含む最新の取組、オープンRANに関する取組を説明しました。EU側からは、6G研究開発における日EU産学連携、民間の標準化活動の状況、目標とする6Gの在り方等についての説明がありました。双方の説明を踏まえ、日EUで更なる協力を推進していくことの重要性が確認されました。 日本側から、デジタル海外展開総合戦略2030、オープンRANの第三国展開、AI RANの推進等について説明を行い、また、日EU双方にてBeyond5G/6Gの標準化を見据え昨年4月から開始された国際共同研究プロジェクトの進捗状況等を確認した上で、双方の取組について議論を行いました。
イ AI RAN ウ AI
日EU双方で、AIによるRAN最適化・自動化の進展を踏まえた、ネットワーク効率化、運用コスト削減、新収益モデル、物流ロボット制御の実証、相互運用性確保に向けた協力の方向性や標準化の重要性について議論を行い、日欧協調のもと、最適なAI実行基盤と移行の重要性が確認されました。 日本側から、広島AIプロセスの報告枠組み、フレンズグループ及びパートナーズコミュニティの状況、AI推進法、AI基本計画等について説明を行い、EU側からは、AI法及び行動規範、AIセーフティ・インスティテュート等について説明があり、双方の取組について議論を行いました。
ウ オンラインプラットフォーム(偽・誤情報対策) エ オンラインプラットフォーム
日本側から、偽・誤情報や新たなAIリスクへの対応を目的として昨年創立された国際コンソーシアム「Frontria(フロントリア)」の取組について説明を行い、EU側からはデジタルサービス法(DSA)や欧州民主主義の盾(EUDS)などの取組、リテラシー向上のための市民教育の取組等の紹介が行われ、双方の連携も含めた偽・誤情報対策について議論を行いました。 日本側から、青少年インターネット環境整備法及び政府における取組・議論の状況、総務省の青少年のインターネット利用環境整備の取組を紹介し、EU側からはDSAの施行状況、体制強化、スナップチャットの調査等青少年保護の取組について説明があり、双方の取組について議論を行いました。
エ ワイヤレス給電  
日本側から、ワイヤレス給電技術及びその商用化の取組について説明を行い、普及の課題も含めた議論を行いました。  
オ 量子 イ 量子
日本側から、量子鍵配送、耐量子暗号を組み合わせた量子セキュアネットワークの取組及び量子インターネットに向けた量子通信システム、量子中継器等関連技術の開発動向の説明をしました。EU側からは、日EU共同研究「Q-NEKO」の取組につき紹介があり、日EU双方で、安全性向上や国際標準化、相互接続性確保に向けた協力の可能性や今後の課題等について議論を行いました。 日本側から、量子エコシステム構築に向けた推進方策、量子技術イノベーションハブ、量子通信技術の研究開発、Q-STARとの連携等について説明を行い、EU側からは、欧州における量子通信ネットワーク構築のための「EuroQCI」プロジェクトの進捗につき説明が行われました。
カ サイバーセキュリティ オ サイバーセキュリティ
日EU双方から、高度化するサイバー脅威への対応に向け、アクティブ・サイバーディフェンスの取組、サプライチェーンの安全確保に向けた取組等につき説明を行い、情報共有の在り方や国際協力の深化に関する連携の方向性について議論を行いました。 日本側から、サイバー対処能力強化法を始めとする政府全体の取組や、日ASEANサイバーセキュリティ能力構築センター(AJCCBC)等における能力構築支援等の総務省の取組について説明を行い、EU側からは、サイバーレジリエンス法、重要インフラ・サプライチェーンの安全保障の取組、人材育成の取組について説明があり、双方の取組について議論を行いました。
キ 官民連携  
日本側から、海外において通信・放送・郵便事業を行う者等に対しリスクマネー供給等の支援を行う官民ファンドである株式会社 海外通信・放送・郵便事業支援機構(JICT)の取組を紹介し、EU側からは、日・EUビジネス・ラウンドテーブル(BRT)の取組につき紹介を行いました。  
ク データスペース  
日本側から、日本のデータスペース基盤「ウラノス・エコシステム」の取組につき紹介し、日EU双方で、産業間データ連携の高度化に向け、相互運用性、ガバナンス、標準化の在り方を共有し、日本のDFFT(信頼性のある自由なデータ流通)とも整合した、安全かつ円滑なデータ流通を実現するための協力可能性や今後の課題について議論しました。  
  カ デジタルインフラ
  日EU双方から、昨年5月に立ち上げに合意した日EU海底ケーブルワーキンググループにおける議論の進捗につき報告があり、今後の協力について議論を行いました。
(参考)日EU・ICTラウンドテーブル出席者 (参考)日EU・ICT政策対話(第31回)出席者
日本側:総務省 今川総務審議官、国立研究開発法人情報通信研究機構(NICT)、 株式会社海外通信・放送・郵便事業支援機構(JICT)、関連企業 ほか 日本側:総務省 今川総務審議官 ほか
EU側: 欧州委員会 通信ネットワーク・コンテンツ・技術総局スコルダス次長、関連企業 ほか EU側: 欧州委員会 通信ネットワーク・コンテンツ・技術総局スコルダス次長 ほか

 

 

● ETSI

・2026.03.25 From vision to action: Strengthening EU–Japan standards cooperation for trusted digital futures

From vision to action: Strengthening EU–Japan standards cooperation for trusted digital futures ビジョンから行動へ:信頼できるデジタルの未来に向けたEU・日本の標準化協力の強化
Today, ETSI-TTC Workshop, “How European and Japanese SDOs can support the EU-Japan Digital Partnership”, building on the momentum of ETSI’s mission led by Director General Jan Ellsberger in May 2025, highlighted how ETSI and the 𝗧𝗲𝗹𝗲𝗰𝗼𝗺𝗺𝘂𝗻𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗧𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝘆 𝗖𝗼𝗺𝗺𝗶𝘁𝘁𝗲𝗲 (𝗧𝗧𝗖) are shaping the next generation of global standards across new and emerging digital technologies. 本日開催されたETSI-TTCワークショップ「欧州と日本の標準化団体がEU・日本デジタル・パートナーシップをいかに支援できるか」は、2025年5月にヤン・エルスベルガー事務局長が率いたETSIのミッションの勢いを踏まえ、 ETSI情報通信技術委員会(TTC)が、新興のデジタル技術分野における次世代のグローバル標準をいかに形成しているかを強調した
Keynote speakers, Olivier Bringer, Head of Unit for International Affairs and Policy Outreach at the European Commission; Yasushi Furukawa, Director of the ICT Standardization Division at Japan’s Ministry of Internal Affairs and Communications; Hideyuki Iwata, President and Director General of TTC; and Martin Chatel, Chief Policy Officer at ETSI, set a powerful tone. Their messages reinforced that we are at a pivotal moment with AI, quantum technologies, 6G, and trusted data infrastructures rapidly evolving, and that coordinated action between Europe and Japan through ETSI and TTC is essential to shape secure, interoperable, and globally relevant standards. 基調講演者として登壇した、欧州委員会の国際問題・政策連携ユニット長オリヴィエ・ブリンガー氏、総務省情報通信標準化ディビジョン長の古川康氏、TTCの岩田英之理事長兼事務局長、およびETSIのチーフ・ポリシー・オフィサーであるマーティン・シャテル氏は、力強い基調を示した。彼らのメッセージは、AI、量子技術、6G、信頼できるデータインフラが急速に進化する中、我々が重要な分岐点に立っていること、そして安全で相互運用可能かつ世界的に意義のある標準を形作るためには、ETSIとTTCを通じた欧州と日本の協調行動が不可欠であることを強調した。
Throughout the Technical Sessions, moderated by Igor Minaev, Director of External Relations, and Eriko Hondo, Senior Expert at KDDI Corporation, several clear takeaways emerged: 対外関係担当ディレクターのイゴール・ミナエフ氏とKDDI株式会社のシニアエキスパートである本堂恵理子氏が司会を務めた技術セッションを通じて、いくつかの明確な結論が導き出された:
Mobile & Wireless Communications: Trusted and interoperable frameworks remain essential. 6G-Mirai, an EU-Japan collaboration, aims at developing reliable and robust AI-native wireless communication systems. Greater alignment between standardisations bodies, open-source communities and regulators will accelerate innovation and deployment. Specific use cases of Network Functions Virtualisation (NFV) standardized by ETSI ISG NFV represent a successful foundation to build upon. モバイル・ワイヤレスコミュニケーション:信頼性が高く相互運用可能な枠組みは依然として不可欠である。EUと日本の共同プロジェクトである「6G-Mirai」は、信頼性が高く堅牢なAIネイティブの無線通信システムの開発を目指している。標準化団体、オープンソースコミュニティ、規制当局間の連携を強化することで、イノベーションと展開が加速するだろう。ETSI ISG NFVによって標準化されたネットワーク機能仮想化(NFV)の具体的なユースケースは、今後の発展に向けた成功の基盤となっている。
Quantum Technologies & QKD: Quantum technologies will underpin future trust infrastructures for governments and industry. Standards must be interoperable-by-design, testable, and certification-ready to enable scaling. With PQC and QKD nearing deployment, hybrid approaches create new standardisation opportunities. Crypto-agility and global standards will be key to long-term resilience. Proposal for “Quantum-safe Security Profile” as one deliverable usable in both EU and Japan markets. 量子技術とQKD: 量子技術は、政府や産業界における将来の信頼インフラを支える基盤となる。標準は、スケーラビリティを実現するために、設計段階から相互運用性を備え、テスト可能かつ認証対応でなければならない。PQC(量子耐性暗号)とQKD(量子鍵配送)の展開が目前に迫る中、ハイブリッドなアプローチが新たな標準化の機会を生み出す。暗号の俊敏性とグローバルな標準が、長期的なレジリエンシーの鍵となる。「量子耐性セキュリティプロファイル」の提案は、EUと日本の両市場で活用可能な成果物の一つである。
・Artificial Intelligence: apan’s ambition to become the “world’s most AI-friendly country” aligns closely with EU priorities. As stressed by Michaela Klopstra, Vice-Chair of TC SAIsecure-by-design, transparent, and accountable AI, supported by practical lifecycle-based standards EN 304 223, will underpin trustworthy AI adoption. 人工知能:日本が掲げる「世界で最もAIに優しい国」となるという目標は、EUの優先事項と密接に合致している。TC SAIの副議長であるミカエラ・クロプストラが強調したように、実用的なライフサイクルベースの標準EN 304 223に裏打ちされた、設計段階から安全性を確保し、透明性があり、説明責任を果たすAIこそが、信頼できるAIの普及を支える基盤となる。
Data Governance & Data Spaces: AI is reshaping business systems but cannot deliver without trusted data flows. Standardisation drives trust and scale but must balance rigor with flexibility to support evolving and diverse needs, as well as rapid technological evolution. As stressed by Franck Le Gall, Vice-Chair of TC DATA, standards like EN 304 199 and EN 303 760 provide foundational specifications supporting trusted data sharing, interoperability, and governance across data spaces. データガバナンスとデータ空間:AIはビジネスシステムを変革しているが、信頼できるデータフローがなければ成果を上げられない。標準化は信頼と規模拡大を促進するが、進化し続ける多様なニーズや急速な技術的進化に対応するため、厳格さと柔軟性のバランスを取らなければならない。TC DATAの副議長であるフランク・ル・ガルが強調したように、EN 304 199やEN 303 760のような標準は、データ空間全体における信頼できるデータ共有、相互運用性、およびガバナンスを支える基礎的な仕様を提供する。
Stronger EU-Japan cooperation through ETSI and TTC will be key to delivering secure, interoperable, and globally scalable digital solutions. ETSIおよびTTCを通じたEUと日本のより強固な協力関係は、安全で相互運用性があり、グローバルに拡張可能なデジタルソリューションを実現するための鍵となる。

 

EN 304 223 

・・2025 .12 [PDF] Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems

EN 304 199

・・2026.03 [PDF] Data Solutions (DATA); Data catalogue implementation framework; Guidelines for Data Catalogue
Framework


EN 303 760 

・・2024.10 [PDF] SmartM2M; SAREF Guidelines for IoT Semantic Interoperability; Develop, apply and evolve Smart Applications ontologies



 

1_20260411151801

 

 

 

 

| | Comments (0)

より以前の記事一覧