ç±³åœã®ã»ãã¥ãªãã£åºæºãåŠãŒãïŒ
NIST SP800-171ã£ãŠãããããäœïŒ ð€
NIST SP800-171ã¯ãã¢ã¡ãªã«ã®æ¿åºæ©é¢ã§ããNISTïŒãã¹ãïŒç±³åœåœç«æšæºæè¡ç 究æïŒãçºè¡ããã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ïŒã«ãŒã«ããã¯ã®ãããªãã®ïŒã§ãã
æ£åŒå称ã¯ãé£éŠæ¿åºå€ã®ã·ã¹ãã ãšçµç¹ã«ããã管çãããéæ Œä»ãæ å ±ã®ä¿è·ããšãããŸãããã¡ãã£ãšé£ããã§ãã ð ç°¡åã«èšããšããæ¿åºã®æ©å¯æ å ±ã§ã¯ãªãããã©ãä¿è·ãå¿ èŠãªéèŠæ å ±ïŒCUIïŒããæ¿åºæ©é¢ä»¥å€ã®äŒç€ŸïŒæ°éäŒæ¥ãªã©ïŒãæ±ããšãã«å®ãã¹ãã»ãã¥ãªãã£ã«ãŒã«ãã®ããšã§ãã
ç¹ã«ãã¢ã¡ãªã«ã®æ¿åºæ©é¢ïŒç¹ã«åœé²ç·çãªã©ïŒãšååŒãããäŒæ¥ãããã®ãµãã©ã€ãã§ãŒã³ïŒéšåäŸçµŠãªã©ã®ååŒé¢ä¿ïŒã«å«ãŸããäŒæ¥ã«ãšã£ãŠããã®ã«ãŒã«ãå®ãããšãæ±ããããŠããŸã ð¢ðºðžã
ãªãã§NIST SP800-171ãéèŠã«ãªã£ãã®ïŒ
ã€ã³ã¿ãŒããããæ®åãããµã€ããŒæ»æã®æå£ãã©ãã©ãå·§åŠã«ãªã£ãŠããŸããæ¿åºæ©é¢ã ãã§ãªããååŒå ã®äŒæ¥ããæ å ±ãæŒããŠããŸãäºä»¶ãçºçããŸããïŒäŸãã°ã2016幎é ã«çºèŠããF35æŠéæ©ã®æ å ±æµåºäºäŸãªã©ïŒã
ããã§ã¢ã¡ãªã«æ¿åºã¯ãæ¿åºããå§èšãããæ¥åãè¡ãäŒæ¥ïŒãµãã©ã€ã€ãŒïŒã«ããæ¿åºãšåãã¬ãã«ã§ãã£ããæ å ±ãå®ã£ãŠãããå¿ èŠããããšèããŸããã ãã®ããã«äœãããã®ãããã®NIST SP800-171ã§ãã
ç¹ã«ç±³åœé²ç·ç (DoD) ã¯ãDFARSïŒãã£ãŒãã¡ãŒã¹ïŒåœé²é£éŠèª¿éèŠåè£éºïŒãšããèŠåã§ãååŒäŒæ¥ã«å¯ŸããŠNIST SP800-171ãžã®æºæ ãæ確ã«èŠæ±ããŠããŸããããããå€ãã®äŒæ¥ã察å¿ãè¿«ããã倧ããªçç±ã®äžã€ã§ãã
CUIã£ãŠã©ããªæ å ±ïŒ ð
NIST SP800-171ãå®ãããšããŠããã®ã¯ãCUIïŒControlled Unclassified InformationïŒç®¡çãããéæ Œä»ãæ å ±ïŒãšåŒã°ããæ å ±ã§ãã
ããã¯ãæ¿åºãæ±ããæ©å¯æ å ±ïŒClassified Information: CIïŒããšã¯åºå¥ãããŸãããããã§ãäžè¬ã«å ¬éãã¹ãã§ã¯ãªããé©åã«ç®¡çã»ä¿è·ããå¿ èŠãããæ å ±ã®ããšã§ãã
å ·äœçã«ã¯ã以äžã®ãããªæ å ±ãå«ãŸããå¯èœæ§ããããŸãïŒäŸïŒïŒ
- æè¡ããŒã¿ïŒèšèšå³ãä»æ§æžãªã©ïŒ
- 茞åºç®¡çæ å ±
- ãã©ã€ãã·ãŒã«é¢ããæ å ±
- æ³å·è¡ã«é¢ããæ å ±
- éèŠã€ã³ãã©ã«é¢ããæ å ±ïŒé»åå¶åŸ¡ã·ã¹ãã ã®ããŒã¿ãªã©ïŒ
- 調éãååŸã«é¢ããæ å ±
ã©ããªæ å ±ãCUIã«ããããã¯ãå¥çŽå 容ãæ¿åºæ©é¢ã®æ瀺ã«ãã£ãŠæ±ºãŸããŸãã
ã©ããªã«ãŒã«ïŒèŠä»¶ïŒãããã®ïŒ ð»ð¡ïž
NIST SP800-171ã«ã¯ãCUIãå®ãããã®å ·äœçãªã»ãã¥ãªãã£å¯ŸçïŒèŠä»¶ïŒãå®ããããŠããŸãã ææ°çã®Revision 3ïŒRev.3ã2024幎5æçºè¡ïŒã§ã¯ããããã®èŠä»¶ã17ã®ã«ããŽãªïŒãã¡ããªãŒãšåŒã°ããŸãïŒã«åé¡ãããåèš97åã®å ·äœçãªèŠä»¶ããããŸãã
以åã®Rev.2ã§ã¯14ãã¡ããªãŒã110èŠä»¶ã§ããããèŠçŽããçµ±åãè¡ãããŸããã
17ã®ãã¡ããªãŒã¯ä»¥äžã®éãã§ãïŒRev.3ïŒãRev.2ãããèšç»ããã·ã¹ãã ãšãµãŒãã¹ã®èª¿éãããµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ãããè¿œå ãããŸããã
ãã¡ããªãŒçªå· | ãã¡ããªãŒåïŒæ¥æ¬èªåèèš³ïŒ | ç°¡åãªèª¬æ |
---|---|---|
3.1 | ã¢ã¯ã»ã¹å¶åŸ¡ (Access Control) | 誰ãæ å ±ã«ã¢ã¯ã»ã¹ã§ãããã管çãã |
3.2 | æèåäžãšèšç·Ž (Awareness and Training) | åŸæ¥å¡ã«ã»ãã¥ãªãã£æè²ãè¡ã |
3.3 | ç£æ»ãšèª¬æ責任 (Audit and Accountability) | 誰ãäœããããã®èšé²ãæ®ãã远跡ã§ããããã«ãã |
3.4 | æ§æ管ç (Configuration Management) | ã·ã¹ãã ã®æ§æã管çããå®å šãªç¶æ ãä¿ã€ |
3.5 | èå¥ãšèªèšŒ (Identification and Authentication) | ã¢ã¯ã»ã¹ãã人ãã·ã¹ãã ãæ£ããèå¥ã»èªèšŒãã |
3.6 | ã€ã³ã·ãã³ãå¯Ÿå¿ (Incident Response) | ã»ãã¥ãªãã£äºæ ãèµ·ãããšãã®å¯Ÿå¿èšç»ãç«ãŠãå®è¡ãã |
3.7 | ã¡ã³ããã³ã¹ (Maintenance) | ã·ã¹ãã ãå®æçã«ä¿å®ããå®å šãªç¶æ ãç¶æãã |
3.8 | ã¡ãã£ã¢ä¿è· (Media Protection) | USBã¡ã¢ãªãæžé¡ãªã©ãæ å ±ãèšé²ããåªäœãä¿è·ãã |
3.9 | 人çã»ãã¥ãªã㣠(Personnel Security) | åŸæ¥å¡ãæ¡çšããéãéè·æã®ã»ãã¥ãªãã£ç®¡çãè¡ã |
3.10 | ç©ççä¿è· (Physical Protection) | ã³ã³ãã¥ãŒã¿ããµãŒããŒã«ãŒã ãªã©ãç©ççã«ä¿è·ãã |
3.11 | èšç» (Planning) Rev.3 æ°èš | ã»ãã¥ãªãã£å¯Ÿçãèšç»ããææžåãã |
3.12 | ãªã¹ã¯è©äŸ¡ (Risk Assessment) | ã·ã¹ãã ãæ å ±ã«å¯Ÿãããªã¹ã¯ãè©äŸ¡ãã察çãæ€èšãã |
3.13 | ã»ãã¥ãªãã£è©äŸ¡ (Security Assessment) | ã»ãã¥ãªãã£å¯Ÿçãæå¹ãå®æçã«ãã§ãã¯ãã |
3.14 | ã·ã¹ãã ãšéä¿¡ã®ä¿è· (System and Communications Protection) | ãããã¯ãŒã¯ãéä¿¡çµè·¯ãä¿è·ãã |
3.15 | ã·ã¹ãã ãšæ å ±ã®å®å šæ§ (System and Information Integrity) | æ å ±ãã·ã¹ãã ãæ¹ãããããŠããªããç£èŠããä¿è·ãã |
3.16 | ã·ã¹ãã ãšãµãŒãã¹ã®èª¿é (System and Services Acquisition) Rev.3 æ°èš | å€éšã®ã·ã¹ãã ããµãŒãã¹ãå°å ¥ããéã®ã»ãã¥ãªãã£ã確ä¿ãã |
3.17 | ãµãã©ã€ãã§ãŒã³ãªã¹ã¯ç®¡ç (Supply Chain Risk Management) Rev.3 æ°èš | 補åããµãŒãã¹ã®äŸçµŠç¶²ïŒãµãã©ã€ãã§ãŒã³ïŒã«é¢ãããªã¹ã¯ã管çãã |
ãããã®èŠä»¶ããã¹ãŠæºããã«ã¯ãæè¡çãªå¯Ÿçã ãã§ãªãã瀟å ã«ãŒã«ã®æŽåãåŸæ¥å¡æè²ãªã©ãçµç¹å šäœã§ã®åãçµã¿ãå¿ èŠã§ãã
æ¥æ¬äŒæ¥ãžã®åœ±é¿ã¯ïŒ ð¯ðµ
NIST SP800-171ã¯ã¢ã¡ãªã«ã®åºæºã§ãããæ¥æ¬äŒæ¥ã«ãç¡é¢ä¿ã§ã¯ãããŸããã
- ç±³åœäŒæ¥ïŒç¹ã«é²è¡ç£æ¥ïŒãšååŒãããäŒæ¥ãããã®ãµãã©ã€ãã§ãŒã³ã«å«ãŸããäŒæ¥ã¯ãååŒå ããNIST SP800-171ãžã®æºæ ãæ±ããããããšããããŸãã
- æ¥æ¬ã®é²è¡çãã2023幎床ããNIST SP800-171ãšåçã®ã»ãã¥ãªãã£åºæºïŒé²è¡ç£æ¥ãµã€ããŒã»ãã¥ãªãã£åºæºïŒãå°å ¥ããŠããŸããé²è¡çãšååŒã®ããäŒæ¥ã¯å¯Ÿå¿ãå¿ èŠã§ãã
- æ¿åºæ©é¢ãéèŠã€ã³ãã©äŒæ¥ãªã©ãã調éã®éã«NIST SP800-171ãåèã«ããããæºæ ãæ±ãããããåããåºãã£ãŠããŸãã
ã€ãŸããã°ããŒãã«ã«ããžãã¹ãå±éããäŒæ¥ããé²è¡ã»éèŠã€ã³ãã©ã«é¢ããäŒæ¥ã«ãšã£ãŠã¯ãNIST SP800-171ãžã®å¯Ÿå¿ããŸããŸãéèŠã«ãªã£ãŠããŸãã
CMMCãšã®é¢ä¿ã¯ïŒ ð€
NIST SP800-171ãšé¢é£ããŠãCMMCïŒCybersecurity Maturity Model CertificationïŒãµã€ããŒã»ãã¥ãªãã£æç床ã¢ãã«èªèšŒïŒãšããèšèãããèãããŸãã
CMMCã¯ãç±³åœé²ç·çãå°å ¥ããèªèšŒå¶åºŠã§ãåœé²ç·çãšå¥çŽããäŒæ¥ãNIST SP800-171ãªã©ã®ã»ãã¥ãªãã£èŠä»¶ãã©ã®çšåºŠæºãããŠããããè©äŸ¡ããèªèšŒããä»çµã¿ã§ãã
NIST SP800-171ããå®ãã¹ãã«ãŒã«ãã ãšãããšãCMMCã¯ãã®ã«ãŒã«ãã¡ãããšå®ããŠãããã第äžè ããã§ãã¯ããŠãã墚ä»ãããäžããå¶åºŠããšã€ã¡ãŒãžãããšåããããããããããŸãããå°æ¥çã«ã¯ãåœé²ç·çãšã®å¥çŽã«ã¯CMMCèªèšŒãå¿ èŠã«ãªãèŠèŸŒã¿ã§ãã
ãŸãšã âš
NIST SP800-171ã¯ãã¢ã¡ãªã«çºã®ã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ã§ãããã°ããŒãã«ãªãµãã©ã€ãã§ãŒã³ãæ¥æ¬ã®æ¿åºèª¿éã«ã圱é¿ãäžããéèŠãªåºæºã§ãã
ç¹ã«CUIïŒç®¡çãããéæ Œä»ãæ å ±ïŒãæ±ãäŒæ¥ã«ãšã£ãŠã¯ããã®å 容ãç解ããå¿ èŠãªå¯Ÿçãè¬ããããšããããžãã¹ç¶ç¶ãä¿¡é Œç¢ºä¿ã®ããã«äžå¯æ¬ ã«ãªã£ãŠããŸãã
ã»ãã¥ãªãã£å¯Ÿçã¯è€éã«èŠãããããããŸããããäžã€äžã€ã®èŠä»¶ãç解ããèšç»çã«åãçµãããšã倧åã§ã ðªã
ã³ã¡ã³ã