NISTï¼ç±³å½æ¨æºæè¡ç 究æï¼ã¨ã»ãã¥ãªãã£ï¼ãã®1ï¼ï½æ¦è¦ç·¨ï½
æ¬ã³ã©ã ã¯ãç±³å½å½ç«æ¨æºæè¡ç 究æã®æ´»åã®ä¸ã§ãç¹ã«ã»ãã¥ãªãã£ã«é¢ããæ´»åã«ã¤ãã¦çç®ãã¦è§£èª¬ãã¦ããã
1. NISTã®æ¦è¦ã¨æ å ±æè¡ç 究æã®ä½ç½®ã¥ã
NISTã®æ£å¼å称ã¯ãNational Institute of Standards and Technologyã§ãæ¥æ¬ã§ã¯ç±³å½å½ç«æ¨æºæè¡ç 究æã¨å¼ã°ãã¦ãããNISTã¯ã1901å¹´ã«è¨ç«ãããæå¤ã®ç©çç§å¦ç 究æã§ãããç¾å¨ã¯ãç±³å½ååçï¼Department of Commerceï¼DoCï¼ã®åä¸ã®ç 究æ©é¢ã§ããã NISTã®ææã¯ãã¹ãã¼ãé»å網ãé»åå¥åº·è¨é²ããååæè¨ãå
é²ã®ããææãããã¦ã³ã³ãã¥ã¼ã¿ãããã¾ã§å¹
åºããITæ¥çã§ãNISTãæä¾ããææ°æè¡ã測å®æè¡ãæè¡æ¨æºã«ä¾åãããã¨ãå¤ããªã£ã¦ãã¦ããã
NISTã®ããã·ã§ã³ã¨ãã¦ã¯ãçµæ¸çå®å
¨ä¿éãé«ããçæ´»ã®è³ªãåä¸ããããããªæ¹æ³ã§æ¸¬å®ç§å¦ãæ¨æºãããã³æè¡ãé²æ©ããããã¨ã«ãã£ã¦ãç±³å½ã®æè¡é©æ°ããã³ç£æ¥ç«¶äºåãä¿é²ãããã¨ãæ²ãã¦ããâ
°ã
NISTã®ãã¸ã§ã³ã¨ãã¦ã¯ãNISTããéè¦ãªæ¸¬å®ã½ãªã¥ã¼ã·ã§ã³ãä½æããå
¬å¹³ãªåºæºãæ¨é²ãããã¨ã§ä¸çã®ãªã¼ãã¼ã«ãªããNISTã®åªåãã¤ããã¼ã·ã§ã³ãåºæ¿ããç£æ¥ã®ç«¶äºåãä¿é²ããããã¦çæ´»ã®è³ªãæ¹åãããã¨ãæ²ãã¦ããã
NISTã®çµç¹æ§æã¯ã5ã¤ã®ç 究æã¨ï¼ã¤ã®ã¦ã¼ã¶ã¼ç¨æ½è¨ã§æ§æããã¦ãããâ
±
å³1ãNISTã®ç 究æã®æ§æ
æ¬ã³ã©ã ã§ã¯ãã»ãã¥ãªãã£ã«çç®ãã¦è§£èª¬ãããã»ãã¥ãªãã£ã«é¢ãã¦ã¯æ å ±æè¡ç 究æ(ITL)ãæ å½ãã¦ããããã®ç 究æã«ã¯7ã¤ã®é¨éããããã³ã³ãã¥ã¼ã¿ã»ãã¥ãªãã£é¨ã¨å¿ç¨ãµã¤ãã¼ã»ãã¥ãªãã£é¨ãã»ãã¥ãªãã£é¢ä¿ã®ç 究ãéçºãè¡ã£ã¦ãããâ ²å³2ã«çµç¹ã®é¢ä¿ã示ãã
https://www.nist.gov/org/information-technology-laboratory/divisionsããã¨ã«ä½æ
å³2ãNISTã®æ å ±æè¡ç 究æã®æ§æ
2. æ å ±æè¡ç 究æ(ITL)ã®æ´»å
ï¼1ï¼ITLã®æ¦è¦
ITLã¯ãé£é¦æ¿åºæ©é¢ããã³ç±³å½æ¥çåãã®ãµã¤ãã¼ã»ãã¥ãªãã£æ¨æºããã³ã¬ã¤ãã©ã¤ã³ãå«ããæ¨æºã測å®ãç¸äºéç¨æ§ã®ãã¹ããã»ãã¥ãªãã£ãæç¨æ§ãããã³æ
å ±ã·ã¹ãã ã®ä¿¡é ¼æ§ã«é¢ããæè¡ãéçºããæ®åãããããã·ã§ã³ãæã£ã¦ããã
ITLã®æ¦ç¥ã¯ããã©ã³ã¹ã®åããIT測å®ç§å¦ã¨3ã¤ã®ä¸»è¦ãªæ´»åã®æ¨æºãã¼ããã©ãªãªãéãã¦ãæ
å ±æè¡ï¼ITï¼ã社ä¼ã«ããããå©çãæ大åãããã¨ã§ããã3ã¤ã®ä¸»è¦åéã¨ã¯ãâ æ°å¦ãçµ±è¨ãããã³ITã«é¢ããåºç¤ç 究ãâ¡ITã®å¿ç¨ç 究ã¨éçºãâ¢æ¨æºè¦æ ¼ã®éçºã¨æè¡ç§»è»¢ã§ãããITLã¯ã5ã¤ã®åªå
åéãç¹å®ããã5ã¤ã®åéã¯ãâ ãµã¤ãã¼ã»ãã¥ãªãã£ãâ¡IoTãâ¢äººå·¥ç¥è½ãâ£é«ä¿¡é ¼ã³ã³ãã¥ã¼ãã£ã³ã°ãâ¤å°æ¥ã®ã³ã³ãã¥ã¼ãã£ã³ã°æè¡ã§ãããâ
³
ï¼2ï¼NISTã®åºçç©
NISTã®ä¸»è¦åéã®æ´»åã¨ãã¦ãæ å ±ããã³æ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã«é¢ããæ¨æºãã¬ã¤ãã©ã¤ã³ãæ¨å¥¨äºé ãããã³ç 究ã®åºç¯ãªã³ã¬ã¯ã·ã§ã³ãéçºããã³ç¶æãããã ããã«ã¯ããã¾ãã¾ãªNISTæè¡åºçç©ã·ãªã¼ãºãå«ã¾ãããåºçç©ã«ãã£ã¦ã次ã®ãããªåé¡ã¨ãªã£ã¦ãããâ ´
ããã¥ã¡ã³ãã®ã¿ã¤ãã« | å 容 | |
---|---|---|
FIPSï¼é£é¦æ å ±å¦çæ¨æºï¼ | NISTã¯ãæ³ä»¤ã§è¦æ±ããã¦ããå ´åãããã³/ã¾ãã¯ãµã¤ãã¼ã»ãã¥ãªãã£ã«å¯¾ãã説å¾åã®ããé£é¦æ¿åºã®è¦ä»¶ãããå ´åã«ãFIPSåºçç©ãä½æããã | |
SPï¼ç¹å¥åè¡ç©ï¼ | SP 800 | NIST SP 800ã·ãªã¼ãºã®åºçç©ã¯ãç±³å½é£é¦æ¿åºã®æ å ±ããã³æ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ã®ãã¼ãºã«å¯¾å¦ããµãã¼ãããããã«éçºããã¦ããã |
SP 1800 | NIST SP 1800ã·ãªã¼ãºã®åºçç©ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ã³ãã¥ããã£ã«å®ç¨çã§ä½¿ç¨å¯è½ãªãµã¤ãã¼ã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ãæä¾ããã | |
SP 500 | NIST SP 500ã·ãªã¼ãºã®åºçç©ã¯ãæ å ±æè¡ã«é¢é£ããææ¸ãçºè¡ããã | |
NISTIRï¼NIST社å ã¾ãã¯æ©é¢éå ±åï¼ | FIPSã¨SPã®èæ¯æ å ±ãå«ãç 究çµæãå ±åããã | |
ITL Bulletin(ITLéå ±) | NISTã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ã«é¢ããåºçç©ãããã°ã©ã ãããã³ããã¸ã§ã¯ãã®æ次æ¦è¦ãå ±åããã |
FIPS | : Federal Information Processing Standard |
SP | : NIST Special Publications |
NISTIR | : NIST Internal or Interagency Report |
ITL Bulletin | : NIST Information Technology Laboratory (ITL) Bulletins |
3. SP800ã·ãªã¼ãº
SP 800 ã·ãªã¼ãºã®ææ¸ã¯ãæ
å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãããªã¹ã¯ããã¸ã¡ã³ããæ
å ±ã»ãã¥ãªãã£æè¡ãæ
å ±ã»ãã¥ãªãã£ã®è¦ä»¶ãæºãã管ççãæ
å ±ã»ãã¥ãªãã£ã®ã½ãªã¥ã¼ã·ã§ã³ãæ
å ±ã»ãã¥ãªãã£ã®å¯¾çç¶æ³ãè©ä¾¡ããææ¨ãæ
å ±ã»ãã¥ãªãã£æè²ãã¤ã³ã·ãã³ã対å¿ãªã©ãæ
å ±ã»ãã¥ãªãã£å
¨è¬ãå¹
åºã網ç¾
ãã¦ãããç¾å¨ãSP800ã·ãªã¼ãºã¨ãã¦ãæçµæ¿èªããã¦å
¬éããã¦ããææ¸æ°ã¯150ããã
ããããã®ã»ãã¥ãªãã£ãéæããããã®ç®¡ççãè¨å®ãã¦ããã¬ã¤ãã©ã¤ã³ããããæ¬å·ã§ã¯ãSP800ã·ãªã¼ãºã®ç®¡ççã«ããããææ¸ã«ã¤ãã¦ã®æ¦è¦ã示ããåºæ¬ã¯ãNIST SP800-53â
µï¼é£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡ççï¼ã§é£é¦æ¿åºã®æ
å ±ã·ã¹ãã åã³é£é¦çµç¹ã®ã»ãã¥ãªãã£ç®¡ççã示ããã¬ã¤ãã©ã¤ã³ãããããããå¼ç¨ãã¦ããã¬ã¤ãã©ã¤ã³ã¨ãã¦ãå¶å¾¡ç³»ã·ã¹ãã ã対象ã¨ããã¬ã¤ãã©ã¤ã³NIST SP800-82â
¶ï¼ç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICSï¼ã»ãã¥ãªãã£ã¬ã¤ãï¼ãæµéã«ããããªã¹ã¯ããã¸ã¡ã³ãã®ã¬ã¤ãã©ã¤ã³NIST SP800-161â
·ï¼é£é¦æ¿åºã®ããã®æ
å ±ã·ã¹ãã åã³çµç¹ã®ãµãã©ã¤ãã§ã¼ã³ã»ãªã¹ã¯ã»ããã¼ã¸ã¡ã³ãã»ãã©ã¯ãã£ã¹ï¼ãé£é¦æ¿åºä»¥å¤ã®çµç¹ãæ±ãæ
å ±ã®ä¿è·ã®ã¬ã¤ãã©ã¤ã³NIST SP800-171â
¸ï¼é£é¦æ¿åºå¤ã®ã·ã¹ãã ã¨çµç¹ã«ããã管çãããéæ ¼ä»ãæ
å ±ã®ä¿è·ï¼ãããã
ãããã®ã¬ã¤ãã©ã¤ã³ã®æ¦è¦ã表1ã«ç¤ºãã次å·ä»¥éã§ãã¬ã¤ãã©ã¤ã³ã®è©³ç´°ã解説ãã¦ããã
çºè¡çªå· | SP800-53 rev4 | SP800-82 rev2 | SP800-161 | SP800-171 rev1 |
---|---|---|---|---|
è¦æ ¼åï¼åæ¬ï¼ | Security and Privacy Controls for Federal Information Systems and Organizations | Guide to Industrial Control Systems (ICS) Security | Supply Chain Risk Management Practices for Federal Information Systems and Organizations | Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations |
è¦æ ¼åï¼åè¨³ï¼ | é£é¦æ¿åºæ å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡çç | ç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICSï¼ã»ãã¥ãªãã£ã¬ã¤ã | é£é¦æ¿åºã®ããã®æ å ±ã·ã¹ãã åã³çµç¹ã®ãµãã©ã¤ãã§ã¼ã³ã»ãªã¹ã¯ã»ããã¼ã¸ã¡ã³ãã»ãã©ã¯ãã£ã¹ | é£é¦æ¿åºå¤ã®ã·ã¹ãã ã¨çµç¹ã«ããã管çãããéæ ¼ä»ãæ å ±ã®ä¿è· |
ææ°çºè¡æ¥ | 2013å¹´4æ | 2015å¹´5æ | 2015å¹´4æ | 2016å¹´12æ |
æ¦è¦ | P800-53ã¯ãã»ãã¥ãªãã£ããã³å人æ å ±ä¿è·ãã¯ãããèªç¶ç½å®³ã人çãã¹ããµã¤ãã¼æ»æãæ§é ä¸ã®æ¬ é¥çããã®è å¨ãã対å¿ãæ©è½ãã¤ã¡ã¼ã¸ãè©å¤ãå«ãçµç¹éå¶ãè³ç£ãå人ãä»çµç¹ãå½å®¶ãä¿è·ããããã®å¤å²ã«ããã管ççãé¸æããã¬ã¤ãã©ã¤ã³ã§ããã | NIST SP800-82ã¯ãICSã®ç¾ç¶ã®ãªã¹ã¯åæåã³è©ä¾¡ããã®å¯¾å¿æ¹æ³ã®è§£èª¬ããªã¹ã¯å¯¾çã®ããã®ã»ãã¥ãªãã£ã®ã¢ã¼ããã¯ãã£è¨è¨ãã½ãªã¥ã¼ã·ã§ã³ã®å°å ¥ãªã©ã®ã¬ã¤ãã©ã¤ã³ãæ示ãã¦ãããã»ãã¥ãªãã£ã®ã¬ã¤ãã©ã¤ã³ã¨ãã¦ãNIST SP800-53ããã¨ã«NIST SP800-82ã®ç®¡ççãæ示ãã¦ããã | NIST 800-161ã¯ãICTãµãã©ã¤ãã§ã¼ã³ã®ãªã¹ã¯ã«ã¯ã模å£åã®æ¿å ¥ãä¸æ£ãªçç£ãæ¹ãããçé£ãæªæã®ããã½ããã¦ã§ã¢ã¨ãã¼ãã¦ã§ã¢ã®æ¿å ¥ãªã©ã®ãªã¹ã¯ãç·©åããããã®ç®¡ççã¨ãã¦ãNIST SP 800-53ã®18ã®ç®¡çç群ãæ¡ç¨ããæ°ãã«Provenanceï¼åºæï¼ã¨ãã管ç群ã追å ãã19ã®ç®¡çç群ããæ§æããã¦ãããã«ãµãã©ã¤ãã§ã¼ã³ç¹æã®è£è¶³ã¬ã¤ãã©ã¤ã³ãä½æãã¦ããã | NIST SP800-171ã¯ãé£é¦æ¿åºã管çããæ å ±ã§ã¯ãªãããé£é¦æ¿åºãæå®ããããã·ã§ã³ã¨ãã¸ãã¹éç¨ãéè¡ããããã®è½åã«ç´æ¥å½±é¿ãåã¼ãå¯è½æ§ã®ããæ å ±ãã管çãããéæ ¼ä»ããããæ å ±(CUI)ã¨å¼ã³ãä¼æ¥çã«å¯¾ãã¦ãã®æ å ±ã®ä¿è·ãæ±ããã¬ã¤ãã©ã¤ã³ã§ãããCUIã®ä¿è·ã®ã»ãã¥ãªãã£è¦ä»¶ã¨ãã¦14ã®ã»ãã¥ãªãã£ç®¡çç群ãè¨å®ããå ·ä½çãªã»ãã¥ãªãã£è¦ä»¶ã¯ãNIST SP800-53ã®17ã®ç®¡ççããä¸ç¨åº¦ã®ã¬ãã«ã®ç®¡ççããå°åºãã¦ããã |
ãã¼ã¹ã©ã¤ã³ã®ç®¡ççã®å¯¾å¿ | ||||
ã¢ã¯ã»ã¹å¶å¾¡ | â | â | â | â |
ç£æ»ããã³ãã®èª¬æ | â | â | â | â |
ã»ãã¥ãªãã£ã¢ã»ã¹ã¡ã³ãããã³èªå¯ | â | â | â | â |
æ§æ管ç | â | â | â | â |
ç·æ¥æ対å¿è¨ç» | â | â | â | â |
èå¥ããã³èªè¨¼ | â | â | â | â |
ã¤ã³ã·ãã³ãå¯¾å¿ | â | â | â | â |
ã¡ã³ããã³ã¹ | â | â | â | â |
ã¡ãã£ã¢ã®ä¿è· | â | â | â | â |
ç©ççä¿è·ããã³ç°å¢ä¿è· | â | â | â | â |
è¨ç»ä½æ | â | â | â | â |
è·å¡ã«ããã»ãã¥ãªã㣠| â | â | â | â |
ãªã¹ã¯è©ä¾¡ | â | â | â | â |
ã·ã¹ãã ããã³ãµã¼ãã¹ã®èª¿é | â | â | â | â |
ã·ã¹ãã ããã³éä¿¡ã®ä¿è· | â | â | â | â |
ã·ã¹ãã ã®å®å ¨æ§ããã³æ å ±ã®æ´åæ§ | â | â | â | â |
ããã°ã©ã ããã¸ã¡ã³ã管çç | â | â | â | â |
ãã®ä» | - | - | Provenanceï¼åºæï¼ã追å | - |
注é
- â °: https://www.nist.gov/about-nist/our-organization/mission-vision-values
- â ±: https://www.nist.gov/labs-major-programs
- â ²: https://www.nist.gov/org/information-technology-laboratory/divisions
- â ³: https://www.nist.gov/itl/about-itl
- â ´: https://csrc.nist.gov/publications
- â µ: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
- â ¶: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf
- â ·: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf
- â ¸: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r1.pdf
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½
ã¨ã°ã¼ã¯ãã£ãã³ã³ãµã«ã¿ã³ã
ãµã¤ãã¼ã»ãã¥ãªãã£æ¦ç¥æ¬é¨éè¦ã¤ã³ãã©å°é調æ»ä¼ å§å¡
æ¾ç° æ ä¹
Tweet