NISTï¼ç±³å½æ¨æºæè¡ç 究æï¼ã¨ã»ãã¥ãªãã£ï¼ãã®3ï¼ï½NIST SP800-82/ NIST SP800-161/ NIST SP800-171ã®æ¦è¦ï½
æ¬å·ã§ã¯ãç±³å½å½ç«æ¨æºæè¡ç 究æ(NIST)ãçºè¡ããç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICSï¼ã»ãã¥ãªãã£ã¬ã¤ããNIST SP800-82ããé£é¦æ¿åºã®ããã®æ å ±ã·ã¹ãã ããã³çµç¹ã®ãµãã©ã¤ãã§ã¼ã³ã»ãªã¹ã¯ã»ããã¼ã¸ã¡ã³ãã»ãã©ã¯ãã£ã¹ãNIST SP800-161ããé£é¦æ¿åºå¤ã®ã·ã¹ãã ã¨çµç¹ã«ããã管çãããéæ ¼ä»ãæ å ±ã®ä¿è·ãNIST SP800-171ãã®æ¦è¦ã«ã¤ãã¦è§£èª¬ããã
1.NIST SP800-82 (Guide to Industrial Control Systems (ICS) Security)
ï¼1ï¼NIST SP800-82ã®æ¦è¦
NIST SP800-82â
°ã¯ãå®å
¨ãå®å¿ãªç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICS: Industrial Control Systemsï¼ãæ§ç¯ããããã®ã¬ã¤ãã³ã¹ã§ããã
ICSã¯ãé»æ°ãä¸ä¸æ°´éãç³æ²¹ã»åå¦ãã¬ã¹ã輸éãå»è¬åãé£åã»é£²æããã³çµç«è£½é æ¥çãªã©ã§å©ç¨ãããé«åº¦ã«é£æºã»ç¸äºä¾åããã·ã¹ãã ã¨ãªããéè¦ã¤ã³ãã©ã®éå¶ã«ç·è¦ãªå½¹å²ãæããã¦ããã
åæã®ICSã¯ãå°ç¨ã®ãã¼ãã¦ã§ã¢ã¨ã½ããã¦ã§ã¢ã使ç¨ããå°ç¨ã®å¶å¾¡ç¨ãããã³ã«ãå®è¡ããé絶ãããã·ã¹ãã ã®ãããå¾æ¥ã®ITã·ã¹ãã ã¨ã¯é¡ä¼¼ç¹ãã»ã¨ãã©ãªãã£ããããããæè¿ã¯ãåºãå©ç¨å¯è½ãªä½ã³ã¹ãã®ã¤ã³ã¿ã¼ããããããã³ã«ï¼IPï¼ããã¤ã¹ãå°ç¨ã½ãªã¥ã¼ã·ã§ã³ã«ä»£ãããæ±ç¨ã®ITæè¡ã使ãããã«ãªã£ã¦ãããã¾ããã¤ã³ã¿ã¼ãããã¸ã®æ¥ç¶ã«ããITã®ä¸çã§åé¡ã¨ãªã£ã¦ãããµã¤ãã¼ã»ãã¥ãªãã£ã®èå¼±æ§ã®é²è¦ãã¤ã³ã·ãã³ããçããå¯è½æ§ãé«ã¾ã£ã¦ããã
ãµã¤ãã¼ã»ãã¥ãªãã£ã¯ãç¾å¨ã®ICSãå®å ¨ãã¤é«ãä¿¡é ¼æ§ããã£ã¦éç¨ããä¸ã§ä¸å¯æ¬ ã§ãããICSã®ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã¯ãåºç¯ãªICSã®å®å ¨æ§ã»ä¿¡é ¼æ§å¯¾çã®ä¸é¨ã¨ãªãã¹ãã§ãããICSã«å¯¾ããã¤ã³ã·ãã³ãã®è å¨ã®çºçæºã¯å¤å²ã«ãããããããªã¹ãã°ã«ã¼ããä¸æºãæã¤å¾æ¥å¡ãæªæãæã¤ä¾µå ¥è ãè¤éæ§ãäºæ ãèªç¶ç½å®³ãå é¨é¢ä¿è ã®æå³çåã¯å¶çºçè¡çºãªã©ããããããã«ãICSã®ã»ãã¥ãªãã£ã®ç®çã¯ITã¨ã¯ç°ãªããä¸è¬çã«å¯ç¨æ§ã¨å®å ¨æ§ãåªå äºé ã¨ããæ©å¯æ§ã¨ãªãã¨ããã«ç¹å¾´ãããã
æ¬ã¬ã¤ãã©ã¤ã³ã§ã¯ãICSã®ãªã¹ã¯ç®¡çã¨ã¢ã»ã¹ã¡ã³ããICSã®ã»ãã¥ãªãã£ããã°ã©ã ã®éçºã¨å±éãICSã®ã»ãã¥ãªãã£ã¢ã¼ããã¯ãã£ã¼ãICSã¸ã®ã»ãã¥ãªãã£å¯¾çã®é©ç¨ã«ã¤ãã¦è§£èª¬ãã¦ãããICSã¸ã®ã»ãã¥ãªãã£å¯¾çã®é©ç¨ã§ã¯ãNIST SP800-53ã®ç®¡ççãå©ç¨ãã¦ãICSã¸ã®é©ç¨ã«ã¤ãã¦è¨è¼ãã¦ããã
ï¼2ï¼ç®¡ççã®æ¦è¦
NIST SP800-53ã®ç®¡ççãããICSç¹æã®æ¡ä»¶ãèæ ®ãã¦æ¬¡ã®ãããªç®¡ççãé¸å®ãã¦ããã管ççã®ã«ãã´ãªã¼ãã¨ã«é¸å®ãã管ççã®æ°ã表1ã«ç¤ºãã
表1ãIST SP800-82ã§é¸å®ãã管ççã¨ç®¡ççã®æ°
ï¼3ï¼ç®¡ççã®åç §æ¹æ³
NIST SP800-82ã§é¸å®ãã管ççãæ¡å¼µç®¡ççã¯ãNIST SP800-82ä»é²Gã«è¨è¼ããã¦ããã
è¨è¼æ¹æ³ã¨ãã¦
â NIST SP800-53ã®ãã¼ã¹ç®¡ççãæ¡å¼µç®¡ççãé¸æããNIST SP800-82ã¨ãã¦è¿½å ããã£ãå ´åã«ã¯ããã¼ã¹ç®¡ççã®åã«ã追å ãã®è¨è¼ããããããã¼ã¹ã©ã¤ã³ã«ç®¡ççã追å ããçç±ããè¨è¼ãããã
â¡ç®¡ççãæ¡å¼µç®¡ççã®è£è¶³çã¬ã¤ãã³ã¹ã§ãICSã¨ãã¦ã¬ã¤ãã³ã¹ãå¿
è¦ãªå ´åã«ã¯ããICSè£è¶³çã¬ã¤ãã³ã¹ããè¨è¼ãããã
åã ã®ç®¡ççã®è¨è¼æ¹æ³ã¯NIST SP800-53ããã¼ã¹ã«ãã¦ããããNIST SP800-82ã¨ãã¦ã®è¨è¼æ¹æ³ããå³1ã«ç¤ºãã
å³1ãIST SP800-82ã®ç®¡ççã®åç §æ¹æ³
管ççãæ¡å¼µç®¡ççã®è©³ç´°ã¯ãNISP SP800-82ã®ä»é²Gãåç §ãã ããã
2.NIST SP800-161 (Supply Chain Risk Management Practices for Federal Information Systems and Organizations)
ï¼1ï¼NIST SP800-161â ± ã®æ¦è¦
NIST SP800-161ã¯ãé£é¦æ¿åºæ©é¢ï¼çµç¹ï¼ã«å¯¾ããçµç¹ã®ããããã¬ãã«ã§ICTãµãã©ã¤ãã§ã¼ã³ã®ãªã¹ã¯ãç¹å®ãè©ä¾¡ãç·©åããããã®ã¬ã¤ãã³ã¹ã§ããã
æ å ±éä¿¡æè¡ï¼ICTï¼ã¯ãå°ççã«å¤æ§ãªã«ã¼ããæã¡ãè¤æ°ã®é¢é£è ã®ã¢ã¦ãã½ã¼ã·ã³ã°ã§æ§æãããè¤éã§ã°ãã¼ãã«ã«åæ£ããç¸äºã«é¢ä¿ãæã¤ãµãã©ã¤ãã§ã¼ã³ã«ä¾åãã¦ããããã®ãµãã©ã¤ãã§ã¼ã³ã¯ãICTã®è¨è¨ã製ä½ãé å¸ã使ç¨ã«é¢ããæè¡ãæ³å¾ãæ¿çãæé ãå ¬å ±ããã³æ°éé¨éã®äºæ¥ä½ã§æ§æããã¦ãããé£é¦æ¿åºã®æ å ±ã·ã¹ãã ã¯ãå¸è²©ã®è£½åãã«ã¹ã¿ã ã·ã¹ãã ã®ã·ã¹ãã ã¤ã³ãã°ã¬ã¼ã¿ã¼ã®ãµãã¼ããå¤é¨ãµã¼ãã¹ãããã¤ãã¼ãæ¥éã«æ¡ç¨ããICTãµãã©ã¤ãã§ã¼ã³ã®è¤éæ§ãå¤æ§æ§ãè¦æ¨¡ãå¢å¤§ããããã®çµæãä½ã³ã¹ããç¸äºéç¨æ§ãè¿ éãªã¤ããã¼ã·ã§ã³ããã¾ãã¾ãªè£½åæ©è½ã競åãããã³ãã¼éã®é¸æãªã©ã大ããªã¡ãªããããããããããããã模å£åã®æ¿å ¥ãä¸æ£ãªçç£ãæ¹ãããçé£ãæªæã®ããã½ããã¦ã§ã¢ã¨ãã¼ãã¦ã§ã¢ã®æ··å ¥ãICTãµãã©ã¤ãã§ã¼ã³ã«ããã製é ã¨éçºã®ä¸åãªã©ã®ãªã¹ã¯ãããããããæªæã®ããå人ãçµç¹ãã¾ãã¯å½å®¶ã«ãã£ã¦ãããããè å¨ã¨èå¼±æ§ã¯ãå·§å¦ã¨ãªãããã°ãã°æ¤åºãå°é£ã§ãããçµç¹ã«é大ãªãªã¹ã¯ããããããã¨ãããã
ç¾å¨ãçµç¹ãå¤ãã®æ°éé¨éã®ã¤ã³ãã°ã¬ã¼ã¿ã¼ããµãã©ã¤ã¤ã¼ã¯ãæ¨æºåããã¦ããªãæ§ã ãªè£½åã使ç¨ãã¦ãããããç°ãªãçµç¹éã§ICTãµãã©ã¤ãã§ã¼ã³ã®ãªã¹ã¯ãä¸è²«ãã¦è©ä¾¡ã管çãããã¨ãå°é£ã«ãªã£ã¦ãããæ¬ã¬ã¤ãã©ã¤ã³ã§ç¤ºãICTãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼ICT SCRMï¼ã¯ãICT製åã¨ãµã¼ãã¹ãµãã©ã¤ãã§ã¼ã³ã®ã°ãã¼ãã«ãã¤åæ£ããæ§è³ªã«é¢é£ãããªã¹ã¯ãç¹å®ãè©ä¾¡ãä½æ¸ããããã»ã¹ã示ããICT SCRMã¯ãâ æ©å¯æ§ãå®å ¨æ§ãå¯ç¨æ§ã®æ å ±ã»ãã¥ãªãã£ãâ¡æ¬ç©ã§ãããå¤æ´ããã¦ããªããã¨ãä¿è¨¼ããå®å ¨æ§ãâ¢é害ã«å¯¾ãã¦ICT製åããµã¼ãã¹ãæä¾ããèé害æ§ï¼ã¬ã¸ãªã¨ã³ã¹ï¼ãâ£é害ãæªæã®ããä¸æ£ãªã©ã«å¯¾ããå質ãã®4ã¤ã®æ±ã«å¯¾å¿ãã¦ããã
ICT SCRMããã»ã¹ã¯ã3ã¤ã®Tierï¼é層ï¼ã«ããã£ã¦å®æ½ããããTier 1ï¼çµç¹ï¼ã¯ãçµç¹ã¬ãã«ã®ããã·ã§ã³/ãã¸ãã¹è¦ä»¶ã¨ããªã·ã¼ããªã¹ã¯ç®¡çï¼æ©è½ï¼ãªã©ã®ã¬ããã³ã¹æ§é ãããã³ICT SCRMã®çµç¹å ¨ä½ã®ãªã½ã¼ã¹é åã使ç¨ãã¦ãçµç¹ã«ã¨ã£ã¦æ¦ç¥çãªICT SCRMã®æ¹åæ§ãæä¾ãããTier2ï¼ããã·ã§ã³/ãã¸ãã¹ããã»ã¹ï¼ã¯ãããã·ã§ã³/ãã¸ãã¹ããã»ã¹ã®è¦³ç¹ãããªã¹ã¯ã«å¯¾å¦ãããªã¹ã¯ã³ã³ããã¹ãããªã¹ã¯æ±ºå®ãããã³ãªã¹ã¯æ´»åã«ãã£ã¦éç¥ãããTier 3ï¼æ å ±ã·ã¹ãã ï¼ã§ã¯ãICT SCRMæ´»åãçµç¹ã®æ å ±ã·ã¹ãã ã¨ã·ã¹ãã ã³ã³ãã¼ãã³ãã«é¢é£ãã ICT SCRMã«é¢é£ããæ å ±ã»ãã¥ãªãã£è¦ä»¶ã使ç¨ãã¦ããµãã©ã¤ãã§ã¼ã³ãéãã¦å¤ãã®è å¨ããã®ã¬ãã«ã§å¯¾å¦ããã¦ãããICT SCRMã®ç®¡ççã¯ãNIST SP 800-53ããã¨ã«æ§æãããICT SCRMé¢é£ã®ç®¡ççã¨ãã¦ã追å è£è¶³çãªã¬ã¤ãã³ã¹ãè£å¼·ããå¿ è¦ã«å¿ãã¦æ°ãã管ççãæä¾ãã¦ãããå管ççã¯ãã©ã®Tierã§å¯¾å¿ãããã®ä¾ç¤ºãå«ã¾ãã¦ããã
ï¼2ï¼ç®¡ççã®æ¦è¦
ICT SCRMã®ç®¡ççã¯ãNIST SP 800-53ã®18ã®ç®¡çç群ãããICT SCRMã®ç®¡ççãé¸å®ããããã«ICT SCRMç¹æã®ãã¡ããªãProvenanceï¼èµ·æºãåºæï¼ã追å ããã19ã®ICT SCRMã®ç®¡çç群ã§æ§æããã¦ãããICT SCRMã¨ãã¦ã次ã®é ç®ã追å ã«ãªã£ã¦ããã
â Provenanceï¼èµ·æºãåºæï¼ã®ç®¡çç群ã追å ã«ãªãã3ã¤ã®ç®¡ççãçå®ãããã
â¡ãä¿å®ãã®ã»ãã¥ãªãã£ç®¡çç群ã«MA-7ï¼ä¿å®ã¢ãã¿ãªã³ã°ï¼ã®ç®¡ççã追å ãããã
â¢ãã·ã¹ãã 調éããã³ãµã¼ãã¹ã®èª¿éãã®ç®¡çç群ã«æ¡å¼µç®¡ççSA-15ï¼3ï¼- èã¿ã³ãã¼æ§ -
ã追å ãããã
管ççã®ã«ãã´ãªã¼ãã¨ã«é¸å®ãã管ççã®æ°ã表2ã«ç¤ºãã
表2ã ICT SCRMã§çå®ãã管ççã¨ç®¡ççã®æ°
ï¼3ï¼ç®¡ççã®åç §æ¹æ³
ICT SCRMã§é¸å®ã追å ãã管ççãNIST SP800-161ã®3.5ãICT SCRMã»ãã¥ãªãã£ç®¡ççã«è¨è¼ããã¦ãããICT SCRMã»ãã¥ãªãã£ç®¡ççã«ã¯ãé¸å®ã追å ãã管ççãæ¡å¼µç®¡ççãè¨è¼ãããICT SCRMã¨ãã¦ã®è£å©çãªã¬ã¤ãã³ã¹ã¨å¯¾è±¡ã¨ãªãTierãè¨è¼ããã¦ãããNIST SP 800-53ã§çå®ããã管ççãæ¡å¼µç®¡ççã®èª¬æã¯ãNIST SP800-161ã®ãä»é²B NIST SP 800-53ã®ICT SCRMã«é¢é£ãã管çç群ãã«ãªã³ã¯ããããä»é²Bãåç §ããããã«ãªã£ã¦ããã
å³2ã IST SP800-161ã®ç®¡ççã®åç §æ¹æ³
ICT SCRMã®ç®¡ççãæ¡å¼µç®¡ççã®è©³ç´°ã¯ãNISP SP800-161ã®3.5ç« ãåç §ãã ããã
3ï¼NIST SP800-171
ï¼1ï¼NIST SP800-171â ²ã®æ¦è¦
é£é¦æ¿åºã¯æ å ±ã·ã¹ãã ãéç¨ãã¦ããããå¤ãã®ãã³ãã¼ãå¤é¨ãµã¼ãã¹æä¾è ã«ä¾åãã¦ãæ¥å¸¸çãªå¦çãä¿åãéä¿¡ãã¦ãããã¾ããé£é¦æ¿åºã®æ å ±ã¯ãå·æ¿åºããã³å°æ¹æ¿åºã大å¦ãããã³ç¬ç«ç 究æ©é¢ã®ãããªå ¬çãªçµç¹ã¨ã®éã§ãé »ç¹ã«æä¾ã¾ãã¯å ±æããã¦ãããããã§æ±ããã¦ããé£é¦æ¿åºã®æ©å¾®ãªæ å ±ã®ä¿è·ã¯ãé£é¦æ¿åºæ©é¢ã«ã¨ã£ã¦æãéè¦ã§ãããéå¶ã«ç´æ¥çã«å½±é¿ãåã¼ãå¯è½æ§ãããã
é£é¦æ¿åºå¤ã®ã·ã¹ãã ããã³çµç¹ããã¦ãæ¿åºãå¤äº¤ã»è»ãªã©ã®æ©å¯æ å ±ã®ãããªæ©å¯æ§ã¯ãªããå ¬éãæ¼æ´©ãããã¨æ¿åºãªã©ã«å¤§ããªå½±é¿ãããæ å ±ã管çãããéæ ¼ä»ãæ å ±ï¼Controlled Unclassified Informationï¼ã¨å¼ã³ãæ°éã®ãã³ãã¼ããµã¼ãã¹äºæ¥è ã«ä¿è·ãè¦æ±ããããã«ãªã£ãã2010 å¹´11 æ4 æ¥ã«ããªãã大統é ã¯ã大統é 令 13556(ï¼Executive Order 13556ï¼ã«ç½²åãã管çãããéæ ¼ä»ãæ å ±ï¼Controlled Unclassified Informationï¼ã¨ãã¦å ¬è¡¨ãããæ¬å¤§çµ±é 令ã¯ãè¡æ¿æ©é¢(ç)ãä¿è·ãè¦æ±ãããããªéæ ¼ä»ãæ å ±ãåãæ±ãæ¹æ³ãè¦æ ¼åãããããæ¿åºå ¨ä½ã®ç®¡çãããéæ ¼ä»ãæ å ± (CUI)ããã°ã©ã ã確ç«ããæ¬ããã°ã©ã å®æ½ããè¡æ¿æ©é¢(å±)ã¨ãã¦å½ç«å ¬ææ¸è¨é²ç®¡çå±(NARA)ãæå®ãããã¾ããæ½çã®å®æ½ã«å½ããNISTã§çºè¡ããæ¨æºè¦æ ¼ã¨ã¬ã¤ãã©ã¤ã³ã§å®æ½ãããã¨ãè¦æ±ãã¦ãããå ·ä½çã«ã¯ãFIPS 199â ³ãFIPS 200â ´ãNISTãSP800-53â µãNIST SP800-60â ¶ã«é©åãããã¨ãè¦æ±ãã¦ããã
æ¬ã¬ã¤ãã©ã¤ã³ã®ç¬¬2ç« ã§ã¯ãCUIã®ã»ãã¥ãªãã£è¦ä»¶éçºã®ããã®åææ¡ä»¶ã¨è¦ä»¶ããã³NIST æ¨æºã¨ã¬ã¤ãã³ã¹ã«é©ç¨ãããåºæºã«ã¤ãã¦è¨è¿°ãã¦ãããCUIã¨ãã¦è¦æ±ãã14ã®ã»ãã¥ãªãã£è¦ä»¶ãå®ç¾©ãã¦ããã第3ç« ã§ã¯ãCUI ã®æ©å¯æ§ã®ä¿è·ã®ããã®14ã®ã»ãã¥ãªãã£è¦ä»¶ã«ã¤ãã¦ãå ·ä½çã«å®ç¾©ãã¦ãããããã«ãä»é²Dã§ã¯ãCUIã®ã»ãã¥ãªãã£è¦ä»¶ã¨NIST SP800-53ã®ç®¡ççã®ãããã³ã°ãæ´çãã¦ãããä»é²Eã§ã¯ãNIST SP800-53ã®ä¸ç¨åº¦ã®ãã¼ã¹ã©ã¤ã³ã®ç®¡ççã«ã¤ãã¦ãããããã®é ç®ããâ CUIã«é¢ä¿ãªãé ç®ãâ¡æ¿åºã®è²¬ä»»ã§å®æ½ããé ç®ãâ¢ä¸è¬çã«å®æ½ãã¦ããé ç®ãâ£CUIã¨ãã¦è¦æ±ãããé ç®ãã«åãã¦æ´çãã¦ããã
ï¼2ï¼ç®¡ççã®æ¦è¦
CUIã¨ãã¦è¦æ±ãã14ã®åºæ¬ã¨ãªãã»ãã¥ãªãã£è¦ä»¶ã¯ãFIPS 200ã§æ¢å®ããã¦ãã14ã®æä½éã®ã»ãã¥ãªãã£è¦ä»¶ãç¨ãã¦ããã14ã®ã»ãã¥ãªãã£è¦ä»¶ããå¾ãããåºæ¬çãªè¦ä»¶ã¨ãNIST SP800-53ã®ç®¡ççããå°åºãããã»ãã¥ãªãã£è¦ä»¶ããã¨ã«ãCUIã®ã»ãã¥ãªãã£è¦ä»¶ãæ´çãã¦ãããCUIã¨ãã¦è¨å®ããã»ãã¥ãªãã£è¦ä»¶ã¨è¨å®æ°ã表3ã«ç¤ºãã
ã»ãã¥ãªãã£è¦ä»¶ | è¦ä»¶æ° | ã»ãã¥ãªãã£è¦ä»¶ | è¦ä»¶æ° | ||
---|---|---|---|---|---|
åºæ¬ | å°åº | åºæ¬ | å°åº | ||
ã¢ã¯ã»ã¹å¶å¾¡ | 2 | 20 | æèåä¸ããã³ãã¬ã¼ãã³ã° | 2 | 1 |
ç£æ»ããã³è²¬ä»»è¿½è·¡æ§ | 2 | 7 | æ§æ管ç | 2 | 7 |
èå¥ããã³èªè¨¼ | 2 | 9 | ã¤ã³ã·ãã³ãå¯¾å¿ | 2 | 1 |
ä¿å® | 2 | 4 | ã¡ãã£ã¢ã®ä¿è· | 3 | 6 |
人çã»ãã¥ãªã㣠| 2 | 0 | ç©ççãªä¿è· | 2 | 4 |
ãªã¹ã¯è©ä¾¡ | 2 | 1 | ã»ãã¥ãªãã£è©ä¾¡ | 4 | 0 |
ã·ã¹ãã ä¿è·ããã³éä¿¡ã®ä¿è· | 2 | 12 | ã·ã¹ãã ããã³æ å ±ã®å®å ¨æ§ | 3 | 4 |
CUIã¨ãã¦ã®ã»ãã¥ãªãã£è¦ä»¶ã¨NIST SP800-53ã®ç®¡çç群ã®é¢ä¿ãå³3ã«ç¤ºãã
å³3ãCUIã¨NIST SP800-53ã®ã»ãã¥ãªãã£è¦ä»¶ã¨ç®¡çç群ã®é¢ä¿
ï¼3ï¼ç®¡ççã®åç §æ¹æ³
NIST SP800-171ã§ã¯ãã»ãã¥ãªãã£è¦ä»¶ã«å¯¾å¿ããã¨NIST SP800-53ã®ç®¡ççãè¨è¼ããã®ã¿ã¨ãªã£ã¦ãããNIST SP800-171ã®ä»é²Dã«CUIã®ã»ãã¥ãªãã£è¦ä»¶ã¨NIST SP800-53ã®ç®¡ççã®å¯¾å¿è¡¨ãæ示ããã¦ããããã®å±éããã管ççããã¨ã«å ·ä½çã«CUIã¸ã®é©å¿ç¶æ³ã®è©ä¾¡ãè¡ããã¨ã«ãªããä»é²Dã®å¯¾å¿è¡¨ã®ä¸é¨ãå³4ã«ç¤ºãã
å³4ãCUIã»ãã¥ãªãã£è¦ä»¶ã¨NIST SP800-53ã®å¯¾å¿é¢ä¿ã®ä¾ç¤º
ã»ãã¥ãªãã£è¦ä»¶ã®è©³ç´°ã«ã¤ãã¦ã¯ãNIST SP800-171ã®ç¬¬3ç« ããã³ä»é²Dãåç §ãã ããã
ä»å¾ããNIST SP800-53ã®ç®¡ççãå©ç¨ããã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ãªã©ã«ã¤ãã¦è§£èª¬ãäºå®ãã¦ãã¾ãã
注é
- â
°:
NIST SP800-82
ç£æ¥ç¨å¶å¾¡ã·ã¹ãã (ICS)ã»ãã¥ãªãã£ã¬ã¤ãSCADAãDCSãPLCããã®ä»ã®å¶å¾¡ã·ã¹ãã ã®è¨å® æ¥è±å¯¾è¨³ç
- â
±:
NIST SP800-161 - â
²:
NIST SP800-171
é£é¦æ¿åºå¤ã®ã·ã¹ãã ã¨çµç¹ã«ããã管çãããéæ ¼ä»ãæ
å ±ã®ä¿è·
- â
³:
FIPS 199 - â
´:
FIPS 200 - â
µ:
NIST SP800-53 - â
¶:
NIST SP800-60
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½
ã¨ã°ã¼ã¯ãã£ãã³ã³ãµã«ã¿ã³ã
ãµã¤ãã¼ã»ãã¥ãªãã£æ¦ç¥æ¬é¨éè¦ã¤ã³ãã©å°é調æ»ä¼ å§å¡
æ¾ç° æ ä¹
Tweet