å¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ï¼4ï¼æçµå· ï¼å¶å¾¡ç³»ã·ã¹ãã ã®èªè¨¼å¶åº¦ï¼
ã¯ããã«
å¶å¾¡ç³»ã·ã¹ãã ã«ã¯ãæ±ç¨å¶å¾¡ã·ã¹ãã ã対象ã¨ããã»ãã¥ãªãã£ã«é¢ããå½éæ¨æºã®IEC62443ããã¼ã¹ã«ãã2ã¤ã®èªè¨¼å¶åº¦ãããã¾ããå¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã (CSMS)ã¨å¶å¾¡æ©å¨èªè¨¼ããã°ã©ã (EDSA)ã§ããæ¬å·ã§ã¯ãCSMSã®å¶åº¦ã«ã¤ãã¦è§£èª¬ãã¾ãã
1. èªè¨¼å¶åº¦ã®æ¦è¦
æ¨æºåå£ä½ãªã©ãè¦å®ããã»ãã¥ãªãã£ã«é¢ããåºæºãå¶å¾¡ç³»ã·ã¹ãã ã®è£½åãã·ã¹ãã å
¨ä½ãæºããã¦ãããã¨ãã第ä¸è
æ©é¢ãèªè¨¼ããå¶åº¦ã§ãã
製åã«é¢ããèªè¨¼å¶åº¦ã¯ãå½éè¨æ¸¬å¶å¾¡å¦ä¼ã®ã¡ã³ãã¼ãä¸å¿ã¨ããISCS(ISA Security Compliance Institute)ãéçºããå¶å¾¡æ©å¨èªè¨¼ããã°ã©ã (EDSA: Embedded Device Security Assurance)ã§ãããã®ããã°ã©ã ã®ä¸é¨ã¯ãIEC62443ã«åãè¾¼ã¾ãã¦ãã¾ããæ¥æ¬ã®èªè¨¼æ©é¢ã¨ãã¦æè¡ç 究çµåå¶å¾¡ã·ã¹ãã ã»ãã¥ãªãã£ã»ã³ã¿ã¼(CSSC)ãèªè¨¼æ¥åãè¡ã£ã¦ãã¾ãã
å¶å¾¡ç³»ã·ã¹ãã ã«é¢ããèªè¨¼å¶åº¦ã¯ãå¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã (CSMS: Cyber Security Management Systems for IACS(Industrial Automation and Control System))ã§ãIEC62443ã®ä¸ã®IEC62443-2-1(Requirements for an IACS security management system)ã®åºæºãé©ç¨ããèªè¨¼å¶åº¦ã§ããæ¬å¶åº¦ã¯ãæ¥æ¬ããææ¡ãã¦æ§ç¯ããèªè¨¼å¶åº¦ã§ãããèªè¨¼æ©é¢ã¨ãã¦ä¸è¬è²¡å£æ³äººæ¥æ¬å質ä¿è¨¼æ©æ§ããã³BSIã°ã«ã¼ãã¸ã£ãã³æ ªå¼ä¼ç¤¾ãèªè¨¼æ¥åãè¡ã£ã¦ãã¾ãã
2ã¤ã®èªè¨¼å¶åº¦ã¨IEC62443ã®é¢ä¿ãå³1ã«ç¤ºãã¾ãã
2. CSMSèªè¨¼å¶åº¦ã®æ¦è¦
æ
å ±ç³»ã·ã¹ãã ã¯ã社å
å¤ã®ãããã¯ã¼ã¯ã¨æ¥ç¶ããã¦ãããã·ã¹ãã ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ãããªã¹ã¯ã注ç®ããããã¾ãã¾ãªç¥è¦ããã¦ãã¦ãèç©ããã¦ãã¦ãã¾ãããã®ãªã¹ã¯ã«å¯¾å¿ããããã®ã½ãªã¥ã¼ã·ã§ã³ãã»ãã¥ãªãã£æ©å¨ã®éçºãè¡ãããã»ãã¥ãªãã£ã¬ãã«ãåä¸ãã¦ãã¾ããä¸æ¹ãå¶å¾¡ç³»ã·ã¹ãã ã¯ãHSE(Healthï¼å¥åº·ï¼ãSafeï¼å®å
¨ï¼ãEnvironmentï¼ç°å¢))ãèæ
®ãããã·ã¹ãã ã®åæ¢ã«ããäºæ¥ã®ä¸æãåé¿ããããã«å¯ç¨æ§ãéè¦ããã¦ãã¾ãããµã¤ãã¼ã»ãã¥ãªãã£ã®è¦³ç¹ã§ã¯ãå¤é¨ãããã¯ã¼ã¯ã«æ¥ç¶ãã¦ããªãã·ã¹ãã ãªã®ã§ããä¸æ£ã¢ã¯ã»ã¹ãä¸æ£ä¾µå
¥ãèµ·ãããªããããæ©å¨ãè£
ç½®ã¯å°ç¨ã®ãã¼ãã¦ã§ã¢ãã½ããã¦ã§ã¢ã®ããã«ã»ãã¥ãªãã£ããããé©ç¨ããªãã¦ãã¦ã¤ã«ã¹ææãèµ·ããã«ããããªã©ã®å¤æãããµã¤ãã¼ã»ãã¥ãªãã£ã¸ã®å¯¾å¿ãé
ãã¦ãã¾ããããããå¶å¾¡ç³»ã·ã¹ãã ã«ããã¦ãå¤é¨ãããã¯ã¼ã¯ã¸ã®æ¥ç¶ãè¡ããã¨ãå¤ããªããå¶å¾¡ç³»ã·ã¹ãã æ©å¨ãè£
ç½®ã®å°ç¨ã½ããã¦ã§ã¢ãçã£ãã¦ã¤ã«ã¹ææã®å ±åãããã¾ããã¾ãããããã®æ©å¨ãè£
ç½®ã«æ±ç¨OSãé©ç¨ããå ´åãå¤ããªã£ã¦ãã¦ããããã«ãOSã®ãããã®é©ç¨ã¯é¿ããããªãç¶æ³ã§ããå¶å¾¡ç³»ã·ã¹ãã ã«ããã¦ããµã¤ãã¼ã»ãã¥ãªãã£ã¸ã®å¯¾å¿ãå¿
è¦ã«ãªã£ã¦ãã¦ãã¾ããCSMSã¯ãã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã ãç¶ç¶ãããã¨ã«ããå¶å¾¡ç³»ã·ã¹ãã ã¸ã®ã»ãã¥ãªãã£ã¬ãã«ã®åä¸ãç®æãã¦ãã¾ãã
CSMSã®å¯¾è±¡è
ã¯ãå¶å¾¡ç³»ã·ã¹ãã ãä¿æããäºæ¥è
ã®ä»ã«ãå¶å¾¡ç³»ã·ã¹ãã ã®éç¨ã»ä¿å®ãè¡ãäºæ¥è
ãå¶å¾¡ç³»ã·ã¹ãã ãæ§ç¯ããã·ã¹ãã ã¤ã³ãã°ã¬ã¼ã¿ã¼ã対象ã¨ãªã£ã¦ãã¾ãã
æ
å ±ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã¸ã¡ã³ãã¨ãã¦ISO27001ãåºæºã¨ããISMS(Information Security Management System)ãããã¾ããCSMSã¯ãIEC62443-2-1ãåºæºã«ããå¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã ã§ããISMSã¯æ
å ±è³ç£ã®å
¨ã¦ã対象ã¨ãã¦ããã®ã«å¯¾ããCSMSã¯å¶å¾¡ç³»ã·ã¹ãã ã対象ã«ãã¦ãã¾ãããã®ãããªéããããã¾ãããIEC62443-2-1ã¯ãISO27001ãåèã«ãã¦åºæºãæ¤è¨ãã¦ããããã«å
±éç¹ãå¤ãããã¾ããIEC62443-2-1ã¨ISO27001ã®è¦ä»¶ã®æ¯è¼ã表1ã«ç¤ºãã¾ãã
IEC62443-2-1 | ISO/IEC27001 | |
---|---|---|
è¦ä»¶æ° | 126 | 100 |
åºæè¦ä»¶ | 26 | 27 |
å ±éè¦ä»¶ | 100 | 73 |
â» IEC62443-2-1ã¨ISO/IEC27001ã§ã¯å ±éè¦ä»¶ã®è¨è¼ã¬ãã«ãç°ãªããä¸ã¤ã®è¦ä»¶ã«è¤æ°ã®è¦ä»¶ããããã³ã°ããããã¨ãããæ°ãä¸è´ãã¦ããªã
åºå ¸ :ãå¶å¾¡ã·ã¹ãã ã«ãããã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã ã®æ§ç¯ã«åãã¦ã(IPA)
IEC6243-2-1ã§ã¯ã26é
ç®ã®åºæè¦ä»¶ãå¶å®ãã¦ãã¾ãããããã¯ãå¶å¾¡ç³»ã·ã¹ãã ã«åºæãªè¦ä»¶ãCSMSã¨ãã¦ããã¸ã¡ã³ãã·ã¹ãã ãç¶ç¶ããããã«å¿
è¦ãªè¦ä»¶ãå ãã¦ãã¾ãã
CSMSã®èªè¨¼åºæºã¯ãIEC62443-2-1ãåºã«èªè¨¼ããããã®åºæºãå¶å®ãã¦ãã¾ããå
容ã¨ãã¦ã¯ãã»ã¼åçã®å
容ã¨ãªã£ã¦ãã¾ããèªè¨¼åºæºã¯ãä¸è¬è²¡å£æ³äººæ¥æ¬æ
å ±çµæ¸ç¤¾ä¼æ¨é²åä¼(JIPDEC)ãããCSMSèªè¨¼åºæº(IEC62443-2-1) Ver.2.0ã(JIP-CSCC100-2.0)ãã¨ãã¦å
¬éãã¦ãã¾ããIEC62443-2-1ã«è¿½å ããã26ã®åºæè¦ä»¶ã®æ¦è¦ã¨å¯¾å¿ããèªè¨¼åºæºã®é
çªã表2ã«ç¤ºãã¾ãã
大é ç® | ä¸é ç® | å°é ç® | é ç®çªå· | å 容 | èªè¨¼åºæºã¨ã®å¯¾å¿ |
---|---|---|---|---|---|
4.2ãªã¹ã¯åæ | 4.2.3ãªã¹ã¯èå¥ãåé¡åã³è©ä¾¡ | - | 4.2.3.2 | ãªã¹ã¯è©ä¾¡ã®èæ¯æ å ±ãæä¾ãã | 4.2.3.2 |
4.2.3.5 | åç´ãªãããã¯ã¼ã¯å³ãæ§ç¯ãã | 4.2.3.5 | |||
4.2.3.11 | ç©ççã人çãç°å¢ç,åã³ãµã¤ãã¼çãªã»ãã¥ãªãã£ãªã¹ã¯è©ä¾¡ãçµ±åãã | 4.2.3.11 | |||
4.2.3.12 | IACSã®å ¨ã©ã¤ããµã¤ã¯ã«ãéãã¦ãªã¹ã¯è©ä¾¡ãå®æ½ãã | 4.2.3.12 | |||
4.3CSMSã«ããããªã¹ã¯æ¤è¨ | 4.3.2ã»ãã¥ãªãã£æ¹éãçµç¹ãåã³èªè | 4.3.2.3ã»ãã¥ãªãã£ã®ããã®çµç¹å | 4.3.2.3.2 | ã»ãã¥ãªãã£çµç¹ã確ç«ãã | 4.3.2.3.2 |
4.3.2.4ã¹ã¿ããã®è¨ç·´ã¨ã»ãã¥ãªãã£çµç¹ | 4.3.2.4.5 | æéçµéã¨å ±ã«è¨ç·´è¨ç»ãæ¹è¨ãã | 4.3.2.4.5 | ||
4.3.2.6ã»ãã¥ãªãã£ããªã·ã¼ã¨æé | 4.3.2.6.3 | ãªã¹ã¯ç®¡çã·ã¹ãã éã®ä¸è²«æ§ã管çãã | 4.3.2.6.3 | ||
4.3.3é¸ã°ããã»ãã¥ãªãã£å¯¾æç | 4.3.3.2è¦å¡ã»ãã¥ãªã㣠| 4.3.3.2.3 | è¦å¡ãç¶ç¶çã«é¸å¥ãã | 5.2.3 | |
4.3.3.2.7 | é©æ£ãªãã§ãã¯ã¨æ¨©éã®ãã©ã³ã¹ãç¶æããããã«è·åãåé¢ãã | 5.2.7 | |||
4.3.3.3ç©ççç°å¢çã»ãã¥ãªã㣠| 4.3.3.3.1 | ç©ççããã³ãµã¤ãã¼çãªã»ãã¥ãªãã£ããªã·ã¼ã確ç«ãã | 5.3.1 | ||
4.3.3.3.10 | éè¦è³ç£ã®æ«å®çä¿è·ã®ããã®æé ã確ç«ãã | 5.3.10 | |||
4.3.3.5ã¢ã¯ã»ã¹å¶å¾¡ï¼ã¢ã«ã¦ã³ã管ç | 4.3.3.5.5 | ä¸è¦ã¢ã«ã¦ã³ãã使ç¨åæ¢åã¯é¤å»ãã | 5.5.5 | ||
4.3.3.6ã¢ã¯ã»ã¹å¶å¾¡ï¼èªè¨¼ | 4.3.3.6.3 | ã·ã¹ãã 管çãã¢ããªæ§æ管çã«å¯¾ããå¼·åãªèªè¨¼æ¹æ³ã®è¦æ± | 5.6.3 | ||
4.3.3.6.7 | é éãã°ã¤ã³å¤±ææã®ã¢ã«ã¦ã³ãç¡å¹å | 5.6.7 | |||
4.3.3.6.9 | ã¿ã¹ã¯ééä¿¡ã®ããã®èªè¨¼ãæ¡ç¨ãã | 5.6.9 | |||
4.3.3.7ã¢ã¯ã»ã¹å¶å¾¡ï¼æ¨©éä»ä¸ | 4.3.3.7.2 | IACSããã¤ã¹ã¸ã®ã¢ã¯ã»ã¹ã«å¯¾ããé©æ£ãªè«ççç©çç許å¯æ¹æ³ã確ç«ãã | 5.7.2 | ||
4.3.3.7.3 | ãã¼ã«ãã¼ã¹ã¢ã«ã¦ã³ãçµç±ã§æ å ±ãã·ã¹ãã ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã | 5.7.3 | |||
4.3.3.7.4 | éè¦IACSã«å¯¾ãã¦ã¯å¤èªå¯ææ³ãæ¡ç¨ãã | 5.7.4 | |||
4.3.4å®è¡ | 4.3.4.3ã·ã¹ãã éçºã¨ã¡ã³ããã³ã¹ | 4.3.4.3.4 | ã·ã¹ãã éçºãã¡ã³ããã³ã¹å¤æ´ã«å¯¾ããã»ãã¥ãªãã£ããªã·ã¼ã®è¦æ± | 5.8.4 | |
4.3.4.3.5 | ãµã¤ãã¼ã»ãã¥ãªãã£ã¨ããã»ã¹ã»ã¼ããã£ç®¡çï¼PSM)ã®å¤æ´ç®¡çãçµ±åãã | 5.8.5 | |||
4.3.4.3.6 | ããªã·ã¼ã¨æé ãè¦ç´ããç¶æ管çãã | 5.8.6 | |||
4.3.4.4æ å ±ã»ææ¸ç®¡ç | 4.3.4.4.6 | æ å ±åé¡ãç¶æ管çãã | 5.9.5 | ||
4.3.4.5ã¤ã³ã·ãã³ã対å¿è¨ç» | 4.3.4.5.2 | ã¤ã³ã·ãã³ã対å¿è¨ç»ãæ®åããã | 5.10.2 | ||
4.3.4.5.10 | çºè¦ãããåé¡ãæ¤è¨ãè¨æ£ãã | 5.10.10 | |||
4.4.3CSMSã®è¦ç´ãã»æ¹åã»ç¶æ | - | 4.4.3.1 | CSMSã«å¯¾ããå¤æ´ã管çããå°å ¥ããçµç¹ãå²ãå½ã¦ã | 4.4.3.1 | |
4.4.3.8 | ã»ãã¥ãªãã£ææ¡ã«å¯¾ããå¾æ¥å¡ã®ãã£ã¼ãããã¯ãè¦æ±ãå ±åãã | 4.4.3.8 |
åºå ¸ :ã å¶å¾¡ã·ã¹ãã ã«ããã ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã ã®æ§ç¯ã«åãã¦ï½ IEC62443-2-1ã®æ´»ç¨ã®ã¢ããã¼ã ï½ ã(IPA)ã®ä»é²1ããã³ä»é²2ãããã³ã CSMSèªè¨¼åºæºï¼IEC62443-2-1)ã(JIPDEC)ãåºã«ä½æ
3. CSMSã®æ´åããã³éç¨
CSMSèªè¨¼åºæºã¯ãISMSã¨åæ§ã«ãªã¹ã¯ã¢ããã¼ãã®ããã¸ã¡ã³ãã·ã¹ãã ãæ¡ç¨ãã¦ãã¾ããããã¸ã¡ã³ãã·ã¹ãã ã®ããã¼ã¨ãã¦ããªã¹ã¯ãåæããIACSã«å¯¾ãããªã¹ã¯ã¢ã»ã¹ã¡ã³ããè¡ãã¾ãã次ã«ããªã¹ã¯ã«å¿ãã対å¦ãæ¤è¨ãã管ççãå°å
¥ãã¾ããããã«å°å
¥ç¶æ³ãç£è¦ããå¿
è¦ã«å¿ãã¦è¦ç´ããè¡ãã¾ãããããã®ãããã¸ã¡ã³ãã·ã¹ãã ã®PDCAãç¶ç¶çã«è¡ããã¨ã«ãããå¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ã¬ãã«ã®ç¶æãåä¸ãå³ãã¾ãã
CSMSèªè¨¼åºæºã®ä¸»ãªããã¸ã¡ã³ãã·ã¹ãã ã®ããã¼ãå³2ã«ç¤ºãã¾ãã
JIPDECããèªè¨¼åå¾ã«åãã¦èªè¨¼åºæºã®è§£èª¬æ¸ã¨ãã¦ãCSMSèªè¨¼åå¾ãæ¤è¨ãã¦ããäºæ¥è ã¸ã®ã¦ã¼ã¶ã¼ãºã¬ã¤ãã¨ãã¦ãCSMSã¦ã¼ã¶ã¼ãºã¬ã¤ã-CSMSèªè¨¼åºæº(IEC 62443-2-1)対å¿-ãVer.1.2åºæºããå ¬éããã¦ãã¾ããã¾ããã·ã¹ãã ã¤ã³ãã°ã¬ã¼ã¿ã¼åãã®ã¦ã¼ã¶ã¼ãºã¬ã¤ãã¨ãã¦ãCSMSã·ã¹ãã ã¤ã³ãã°ã¬ã¼ã¿ã¼åãã¬ã¤ãï¼CSMSèªè¨¼åºæºï¼IEC 62443-2-1ï¼å¯¾å¿ï¼ãVer.1.0ããå ¬éããã¦ãã¾ãããããã®ã¬ã¤ãã«ã¯ãCSMSèªè¨¼ãåå¾ããã«ããã£ã¦ã®ããã¸ã¡ã³ãã·ã¹ãã ã®æ§ç¯ã®é²ãæ¹ãèªè¨¼ãåå¾ããæç¶ãã®é²ãæ¹ãªã©ã«ã¤ãã¦è¨è¼ããã¦ãã¾ãã
4åã«ããã£ã¦å¶å¾¡ç³»ã·ã¹ãã ã®ã»ãã¥ãªãã£ã®ååã解説ãã¾ãããå¶å¾¡ç³»ã·ã¹ãã ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã¸ã®åãçµã¿ã¯ãäºæ¥è ã®ã¿ãªãããæ¥çå£ä½ã§ãåãçµã¿ãå§ãã段éã§ãããã»ãã¥ãªãã£ãã³ãã¼ãå¶å¾¡ç³»ã·ã¹ãã ã«å¯¾å¿ããã»ãã¥ãªãã£è£½åãéçºãæä¾ãå§ããã¨ããã§ããå¶å¾¡ç³»ã·ã¹ãã ãåãå·»ãã¹ãã¼ã¯ãã©ã«ãã¼ã®ä»å¾ã®ã»ãã¥ãªãã£ã¸ã®åãçµã¿ãå éãããã¨ãæã¾ãã¾ãã
Writer Profile
ã»ãã¥ãªãã£äºæ¥é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°æ
å½ ã¨ã°ã¼ã¯ãã£ãã³ã³ãµã«ã¿ã³ã
ãµã¤ãã¼ã»ãã¥ãªãã£æ¦ç¥æ¬é¨éè¦ã¤ã³ãã©å°é調æ»ä¼ å§å¡
æ¾ç° æ ä¹
Tweet