ã»ãã¥ãªãã£æç度ã¢ãã«ï¼ãã®2ï¼ ï½C2M2ã®æ¦è¦ï½
æ¬å·ã§ã¯ã»ãã¥ãªãã£è½åæç度ã¢ãã«ã®ï¼ã¤ã§ããï¼£ï¼ï¼ï¼ï¼Cybersecurity Capability Maturity Modelï¼ããã³æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã«ã¤ãã¦ååã解説ããã
1. C2M2ã®ã¢ãã«ã®éçºã®åå
ç±³å½ã¨ãã«ã®ã¼çï¼DOE: Department of Energyï¼ãå種ã®ãµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ãéçºããå ¬éãããã¯ããã«ãé»åæ¥çåãã®ã»ãã¥ãªãã£è½åæç度ã¢ãã«ï¼ ES-C2M2: Electricity Subsector Cybersecurity Capability Maturity Modelï¼ã®ãã¼ã¸ã§ã³1.0ï¼2012å¹´5æï¼ãå ¬éãããã¼ã¸ã§ã³1.1 *1ã2014å¹´2æã«å ¬éãããES-C2M2ãã¼ã¸ã§ã³1.0ããã¨ã«ãç³æ²¹ããã³å¤©ç¶ã¬ã¹æ¥çåãã®ãµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ï¼ONG-C2M2: Oil and Natural Gas Subsector Cybersecurity Capability Maturity Modelï¼ãéçºããç¾å¨ãã¼ã¸ã§ã³1.1*2ï¼2014å¹´2æï¼ãå ¬éãã¦ãããããã«ãç±³å½ã¨ãã«ã®ã¼çã®ç 究æ©é¢ã§ããPNNLï¼Pacific Northwest National Laboratoryï¼ãES-C2M2ããã¨ã«ã建ç©ç®¡çã«ç¦ç¹ãå½ã¦ããµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ï¼B-C2M2:Buildings Cybersecurity Capability Maturity Modelï¼ãéçºããB-C2M2ãã¼ã¸ã§ã³1.1*3ãå ¬éãã¦ããã
ç±³å½ã¨ãã«ã®ã¼çãåæ¥çåãã®ãµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ã¨ã¯å¥ã«ãES-C2M2ã®é»åã®ç¹æã®é¨åãé¤ãã¦ãµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ï¼C2M2: Cybersecurity Capability Maturity Modelï¼ãéçºããC2M2ã®ãã¼ã¸ã§ã³1.1ã2014å¹´2æã«ããã¼ã¸ã§ã³2.0ã2019å¹´6æã«å ¬éããã
ãããã®ã¢ãã«ã®å¤é·ã¯å³1ã®ããã«æ´çã§ããã
å³1ããµã¤ãã¼ã»ãã¥ãªãã£è½åæç度ã¢ãã«ã®å¤é·ï¼é¢é£è³æãåºã«æ´çï¼
2. æç度ã¢ãã«ã®ã¢ã¼ããã¯ãã£
2.1 ãã¡ã¤ã³ãç®æ¨ãå®æ½é ç®
C2M2ããã³æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã«ã¯ã10ã®ãã¡ã¤ã³ãå®ç¾©ãã¦ããããã¡ã¤ã³ã«ã¯ããã¡ã¤ã³ã«åºæã®ã¢ããã¼ãç®æ¨ï¼Objectivesï¼ã¨ãã®ç®æ¨ã«å¯¾ããå®æ½é ç®ï¼ãã©ã¯ãã£ã¹ï¼ãããã³ãã¡ã¤ã³ã«ï¼ã¤ã®ç®¡çç®æ¨ï¼Management Objectiveï¼ã¨ãã®ç®æ¨ã«å¯¾ãã管çã®ããã®å®æ½é ç®ãè¨å®ããã¦ãããåãã¡ã¤ã³ã«ã¯è¤æ°ã®ç®æ¨ãè¨å®ããã¦ãããåç®æ¨ã«ã¯ããã®ç®æ¨ãéæããããã®å®æ½é ç®ããããå®æ½é ç®ã¯1ãã3ã®ã¬ãã«ã«åãã¦è¨å®ããã¦ãããã¢ãã«ã®æ§æãå³2ã«ç¤ºãã
å³2ãæç度ã¢ãã«ã®ã¢ã¼ããã¯ãã£ï¼é¢é£è³æãåºã«æ´çï¼
2.2 ãã¡ã¤ã³
C2M2ãã¼ã¸ã§ã³2.0ããã³æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã®ãã¼ã¸ã§ã³1.1ã«ã¯ã10ã®ãã¡ã¤ã³ãå®ç¾©ããã¦ãããåã¢ãã«ã§å ±éãããã¡ã¤ã³ã¯ã次ã®9ãã¡ã¤ã³ã§ããã
- Risk Managementï¼ãªã¹ã¯ç®¡çï¼
- Asset, Change, and Configuration Managementï¼è³ç£ãå¤æ´ããã³æ§æ管çï¼
- Identity and Access Managementï¼ã¢ã¤ãã³ãã£ãã£ã¨ã¢ã¯ã»ã¹ç®¡çï¼
- Threat and Vulnerability Managementï¼è å¨ããã³èå¼±æ§ç®¡çï¼
- Situational Awarenessï¼ç¶æ³èªèï¼
- Event and Incident Response, Continuity of Operationsï¼ã¤ãã³ãã»ã¤ã³ã·ãã³ãã¸ã®å¯¾å¿ãæ¥åç¶ç¶ï¼
- Supply Chain and External Dependencies Managementï¼ãµãã©ã¤ãã§ã¼ã³ããã³å¤é¨ä¾åæ§ç®¡çï¼
- Workforce Managementï¼è¦å¡ç®¡çï¼
- Cybersecurity Program Managementï¼ãµã¤ãã¼ã»ãã¥ãªãã£ããã°ã©ã 管çï¼
C2M2ã«ã¯ãããã«æ¬¡ã®1ãã¡ã¤ã³ãå®ç¾©ããã¦ããã
- Cybersecurity Architectureï¼ãµã¤ãã¼ã»ãã¥ãªã¢ã¼ããã¯ãã£ï¼
ä¸æ¹ãæ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã«ã¯æ¬¡ã®1ãã¡ã¤ã³ãå®ç¾©ããã¦ããã
- Information Sharing and Communicationsï¼æ å ±å ±æããã³ã³ãã¥ãã±ã¼ã·ã§ã³ï¼
表1ã«ãã¡ã¤ã³ã®æ¦è¦ã示ãã
表ï¼ããã¡ã¤ã³ã®ä¸è¦§ã¨æ¦è¦ï¼é¢é£è³æãåºã«ä½æï¼
2.3 ç®æ¨ã¨å®æ½é ç®
C2M2ã«ã¯ã10ã®ãã¡ã¤ã³ã«å¯¾ãã¦39ã®ç®æ¨ãè¨å®ããã299ã®å®æ½é
ç®ãè¨å®ããã¦ãããä¸æ¹ãæ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã§ã¯ã10ã®ãã¡ã¤ã³ã«å¯¾ãã¦37ã®ç®æ¨ãããã312ã®å®æ½é
ç®ãè¨å®ããã¦ããã
C2M2ãã¼ã¸ã§ã³2.0ã¨æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã®ãã¼ã¸ã§ã³1.1ã®ãã¡ã¤ã³ããã³ç®æ¨ã®æ¯è¼ã表2ã«ç¤ºããé»è²ãé¨åã¯ãC2M2ã¨æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã§ç°ãªãåã示ãã
表2ãC2M2ã¨æ¥çå¥ã®ES-C2M2ãONG-C2M2ãB-C2M2ã®æ¯è¼ï¼é¢é£è³æãåºã«ä½æï¼
ã¢ããã¼ãç®æ¨ã¯ããã¡ã¤ã³ã«å¯¾ãã¦è¤æ°ã®ç®æ¨ãè¨å®ãã¦ããã管çç®æ¨ã¯ãåãã¡ã¤ã³ã«ï¼ã¤è¨å®ãããã»ã¼åæ§ãªç®æ¨ã¨ãªã£ã¦ããããã¡ã¤ã³ã®åºæç®æ¨ã«ã¯åãã¡ã¤ã³ã«ããã¦å®æ½ãå¿
è¦ãªãµã¤ãã¼ã»ãã¥ãªãã£æ½çãå«ã¾ãã管çç®æ¨ã«ã¯ãµã¤ãã¼ã»ãã¥ãªãã£æ½çã®ç®¡çã®ç®æ¨ãå«ã¾ãã¦ããã
å®æ½é
ç®ã«ã¤ãã¦ã¯ã4ã¤ã®ã¢ãã«ã«ã¤ãã¦åãç®æ¨ã§åãå®æ½é
ç®ã®å ´åãã¢ãã«ã®ç¹æ§ã«ããè¨è¿°ãç°ãªãå ´åãããããã»ã¼åãå
容ã®å®æ½é
ç®ã¨ãªã£ã¦ããã
2.4 æç度ã¬ãã«ã¨å®æ½é ç®
ï¼1ï¼æç度ã®èãæ¹
ãã¡ã¤ã³ã®å®æ½é ç®ã«å¯¾ãã¦ãæç度ï¼MIL: Maturity Indicator Levelï¼ã1ï½3ã®ã¬ãã«ã§è¨å®ããã¦ãããæç度ã¯ã表3ã«ç¤ºãç¹æ§ãæã£ã¦ããã
表3ãæç度ã®ç¹æ§
ï¼2ï¼ãã¡ã¤ã³åºæã®å®æ½é ç®ã®ç¶æ³
ãã¡ã¤ã³åºæã®å®æ½é ç®ã®ç¶æ³ã¯åãã¡ã¤ã³ã«ããããµã¤ãã¼ã»ãã¥ãªãã£ã¢ã¯ãã£ããã£ã®å®æ½ç¶æ³ã示ããå®æ½é ç®ã®é²æç¶æ³ã¯ããã¡ã¤ã³å ã®ã¢ã¯ãã£ããã£ã®ç¶²ç¾ æ§ãå®å ¨æ§ãçºå±æ§ã«ãã£ã¦æ¸¬ããã¨ãã§ããæç度ã®ã¬ãã«ãä¸ããã¨ããçµç¹ã¯ããå®å ¨ãªãã¾ãã¯ããé«åº¦ãªå®æ½é ç®ãå®ç¾ãããã¨ã«ãªããMIL1ã§ããã¡ã¤ã³ã®åæ段éã®å®æ½é ç®ã®å®ç¾ãè¨å®ããã¦ããå ´åã§ããããé«ãMILã®å®æ½é ç®ã®å®ç¾ã妨ããªãã
ãµã¤ãã¼ããã°ã©ã 管çï¼CPMï¼ãã¡ã¤ã³ã®ãµã¤ãã¼ã»ãã¥ãªãã£ããã°ã©ã æ¦ç¥ã®çå®ã®ã¢ããã¼ãã®å®æ½ç¶æ³ã®ä¾ã表4ã«ç¤ºãã
MIL1ã§ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ããã°ã©ã æ¦ç¥ã¯ãã¾ãã¾ãªå½¢ã§åå¨ããããMIL2ã§ã¯ç®æ¨å®ç¾©ã®å¿ è¦æ§ãçµç¹æ¦ç¥å ¨ä½ã¨ã®é£æºã責任è ã®æ¿èªãªã©ãæ¦ç¥ã«è¿½å è¦ä»¶ãå ãããã¦ãããMIL3ã¯ãMIL1ã¨MIL2ã®å®æ½é ç®ã«å ãããã¸ãã¹ã®å¤æ´ãéç¨ç°å¢ã®å¤æ´ãè å¨ç¶æ³ã®å¤æ´ãåæ ããããã«æ¦ç¥ãæ´æ°ããããã¨ãè¦å®ãã¦ããã
表4ããµã¤ãã¼ããã°ã©ã 管çï¼CPMï¼ã®ãµã¤ãã¼ã»ãã¥ãªãã£ããã°ã©ã æ¦ç¥ã®çå®ã®ä¾
ãªããåã ã®å®æ½é ç®ã«ã¤ãã¦ã¯ãããããã®ã¢ãã«ã®å®æ½é ç®ãåç §ãã ããã
ï¼3ï¼ç®¡çé¢ã®ç¶æ³
管çé¢ã®ç¶æ³ã¯ããã¡ã¤ã³åºæã®å®æ½é ç®ã®å®æ½ç¶æ³ã¨ã¯ç°ãªãããµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ããå®æ½é ç®ã®å®æ½ç¶æ³ãçµç¹ã®éå¶ã¸ã®æµ¸é度åãã示ããã¤ã¾ããçµç¹ã¯å®æ½é ç®ãé·æéãç¹°ãè¿ãå®æ½ãããã¨ã§ãçµæã«ä¸è²«æ§ãæããããã¨ãã§ããå質ãé«ãããã¨ã«ãªãã
管çé¢ã®å®æ½ç¶æ³ã¯ããã¡ã¤ã³æ¯ã«ç®¡çã¢ã¯ãã£ããã£ï¼Management Activityï¼ã¨ãã¦ã管çé¢ã®å®æ½é ç®ã§è¦å®ããã¦ããããã®å®æ½é ç®ã¯å ¨ãã¡ã¤ã³ã«ããã£ã¦ã»ã¼åæ§ã§ããã管çå®æ½é ç®ãå¼ã¶ããã¡ã¤ã³åºæç®æ¨ã«ãããå®æ½é ç®ã®å®æ½ç¶æ³ã¯ã管çå®æ½é ç®ã®å®æ½ç¶æ³ã«ç¸å½ããããå¿ ããã管çå®æ½é ç®ã¨ãã¡ã¤ã³åºæã®å®æ½é ç®ã対å¿ãã¦ããå¿ è¦ã¯ãªãã
表5ã«ç®¡çé¢ã®æç度ã®ç¹æ§ã示ãã
表5ã管çé¢ã®æç度ã®ç¹æ§
3. ã¢ãã«ã®å©ç¨
ã»ãã¥ãªãã£è½åæç度ã¢ãã«ã¯ãçµç¹ããµã¤ãã¼ã»ãã¥ãªãã£æ©è½ãè©ä¾¡ããçæ³ã¨ããã¢ãã«ã¨ã®ã®ã£ãããæ確ã«ãããµã¤ãã¼ã»ãã¥ãªãã£æè³ã®åªå é ä½ã決ããããã«ä½¿ç¨ãããã¨ãç®çã¨ãã¦ããã å³3ã¯ãæ¬ã¢ãã«ã使ç¨ããããã®æ¨å¥¨ã¢ããã¼ãã示ãã çµç¹ã¯ã¢ãã«ã«å¯¾ãã¦è©ä¾¡ãè¡ãããã®è©ä¾¡ã使ç¨ãã¦è½åã®ã®ã£ãããç¹å®ãããããã®ã®ã£ããã«åªå é ä½ãä»ãããããã«å¯¾å¦ããè¨ç»ãçå®ããæçµçã«ã®ã£ããã«å¯¾å¦ããè¨ç»ãå®æ½ããã
å³3ãã¢ãã«ã®æ¨å¥¨å©ç¨æ¹æ³
ES-C2M2ãä¾ã«ãçµç¹ã§ã®æ¬ã¢ãã«ã®å©ç¨æ¹æ³ã®ï¼ã¤ã®ã¹ãããã«ã¤ãã¦ãåã¹ãããã®å ¥åãå®æ½ãããã¨ï¼ã¢ã¯ãã£ããã£ï¼ãåºåï¼ææï¼ãå³4ã«ç¤ºãã
å³4ãåã¹ãããã®å®æ½å 容ï¼åºå±ï¼ES-C2M2ãåºã«ä½æï¼
ãªããèªå·±è©ä¾¡ã«ã¤ãã¦ã¯ãåã¢ãã«ã§ãã¼ã«*4ãæä¾ããã¦ããããã®ãã¼ã«ã使ã£ã¦å®æ½é ç®ã®æç度ãå ¥åããã¨ãè©ä¾¡çµæãåºåããããå³5ã«C2M2 Verion2.0ã®ä¾ã示ãã
å³5ãã»ãã¥ãªãã£è½åæç度ã®è©ä¾¡ä¾ï¼åºå±ï¼C2M2 Verion2.0ï¼
ã»ãã¥ãªãã£è½åæç度ãé«ããããã«ã¯ãå³4ã®ã¢ãã«ãç¶ç¶ãã¦å®æ½ãã¦ãããã¨ã«ãªãããããããPDCAãåããã¨ã«ãªãã
æ¬å·ã§ã¯ãC2M2ã®åã¢ãã«ã®æ¦è¦ã解説ããã次å·ã§ã¯ãç±³å½å½é²çãæ¤è¨ãé²ãã¦ããCMMCï¼Cybersecurity Maturity Model Certificationï¼ã«ã¤ãã¦è§£èª¬ããã
注é
- *1ï¼ES-C2M2 version2.0
https://www.energy.gov/sites/prod/files/2019/08/f65/C2M2%20v2.0%2006202019%20DOE%20for%20Comment.pdf - *2ï¼ONG-C2M2
https://www.energy.gov/sites/prod/files/2014/03/f13/ONG-C2M2-v1-1_cor.pdf - *3ï¼B-C2M2
https://bc2m2.pnnl.gov/ - *4ï¼C2M2ã®è©ä¾¡ãã¼ã«
- ã»C2M2ï¼[email protected]ã«ã¡ã¼ã«ã§è¦æ±ãã
- ã»ES-C2M2ã®ãã¼ã«ï¼
https://esc2m2.pnnl.gov/
https://www.ipa.go.jp/files/000077751.xlsx - ã»ONG-C2M2ã®ãã¼ã«ï¼[email protected]ã«ã¡ã¼ã«ã§è¦æ±ãã
- ã»B-C2M2ã®ãã¼ã«ï¼
https://bc2m2.pnnl.gov/
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½
ã¨ã°ã¼ã¯ãã£ãã³ã³ãµã«ã¿ã³ã
ãµã¤ãã¼ã»ãã¥ãªãã£æ¦ç¥æ¬é¨éè¦ã¤ã³ãã©å°é調æ»ä¼ å§å¡
æ¾ç° æ ä¹
Tweet