NIST SP 800-161r1ã«ã¿ããµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼1ï¼
ï½ãã«ãã¬ãã«ãªã¹ã¯ç®¡çã¨C-SCRMãã¼ãã©ã¯ãã£ã¹ï½
ããæ°å¹´ã§ãµãã©ã¤ãã§ã¼ã³ã»ãã¥ãªãã£ã¨ãããã¼ã¯ã¼ããåºãèãããããã«ãªãã¾ãããIPAãæ¯å¹´çºè¡¨ãã¦ããæ
å ±ã»ãã¥ãªãã£10大è
å¨ã®2021ã2022ã2023ã«ããã¦ããããµãã©ã¤ãã§ã¼ã³ã®å¼±ç¹ãæªç¨ããæ»æãã¯å¸¸ã«ä¸ä½ã«ã©ã³ã¯ã¤ã³ãã¦ãã¾ããä¸æ¹ã§ããµãã©ã¤ãã§ã¼ã³ã®ã»ãã¥ãªãã£ã示ãç¯å²ã¯é常ã«å¹
åºãããã®å¯¾å¦ãã¾ãåºç¯ãªãã®ã¨ãªãã¾ãã
ããã§æ¬ã³ã©ã ã§ã¯ãç±³å½NISTã®ã»ãã¥ãªãã£ææ¸NIST SP 800-161 revision1ããã¼ã¹ã«ãªã¹ã¯ããã¸ã¡ã³ãã®è¦³ç¹ãããµãã©ã¤ãã§ã¼ã³ã»ãã¥ãªãã£ã¸ã®å¯¾å¿æ¹æ³ã«ã¤ãã¦æããã«ãã¦ã¿ããã¨æãã¾ãã
1. ãµãã©ã¤ãã§ã¼ã³ã®ã»ãã¥ãªãã£è å¨ã¨ãµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼C-SCRMï¼
ãµãã©ã¤ãã§ã¼ã³æ»æã¨ã¯
ãµãã©ã¤ãã§ã¼ã³ã«é¢ããã»ãã¥ãªãã£è å¨ã«ã¯ããã¤ãã®è¦³ç¹ãããã¾ããIPAã®ãæ å ±ã»ãã¥ãªãã£10大è å¨ 2023ãã§ã¯ããµãã©ã¤ãã§ã¼ã³ã«ã¤ãã¦ä»¥ä¸ã®ããã«èª¬æãã¦ãã¾ãã
- ã»ãµãã©ã¤ãã§ã¼ã³
âååã®ä¼ç»ã»éçºããã調éã製é ãå¨åº«ç®¡çãç©æµã販売ã¾ã§ã®ä¸é£ã®ããã»ã¹ãããã³ãã®åæµã«é¢ããçµç¹ç¾¤â - ã»ã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³
âã½ããã¦ã§ã¢éçºã®ã©ã¤ããµã¤ã¯ã«ã«é¢ä¸ããå ¨ã¦ã®ã¢ãï¼ã³ã¼ããã©ã¤ãã©ãªããã©ã°ã¤ã³ãå種ãã¼ã«çï¼ã人ï¼éçºè ãéç¨è çï¼ã®ç¹ããâ
ä¸è¨ã®ãããªãµãã©ã¤ãã§ã¼ã³ã«å¯¾ããæ»æã¯ãµãã©ã¤ãã§ã¼ã³æ»æã¨è¨ããã¾ãããããã¯ç¹å®ã®æ»æææ³ã¨ããããè¤æ°ã®æ»æææ³ã®çµã¿åãããã¾ãã¯ãã®ç·ç§°ã§ããã»ãã¥ãªãã£å¯¾çãèå¼±ãªçµç¹ãã·ã¹ãã ã³ã³ãã¼ãã³ããæåã®æ¨çã¨ãããããè¸ã¿å°ã¨ãã¦æ¬å½ã®æ¨çãæ»æããæ»æå
¨è¬ã¨èããã¨è¯ãã§ãããã
ãµãã©ã¤ãã§ã¼ã³æ»æã®å
·ä½ä¾ã¯ä»¥ä¸ã®ãã®ãããã¾ãã
- ã»ãã¸ãã¹ãµãã©ã¤ãã§ã¼ã³æ»æ
2022å¹´ã«å§è¨å ã®ã·ã¹ãã ã¸ã®ä¾µå ¥ãä»ãã¦å½å å»çæ©é¢ã¸ãããã¯ã¼ã¯ä¾µå®³ãè¡ãããçµæçã«ã©ã³ãµã ã¦ã§ã¢ææã«ããå»çæ¥åãåæ¢ããã - ã»ãµã¼ãã¹ãµãã©ã¤ãã§ã¼ã³æ»æ
2022å¹´ã«å½å ã¯ã©ã¦ããµã¼ãã¹äºæ¥è ãæä¾ããWebå ¥åãµã¼ãã¹ãæ¹ãããããåå¼å ãå ¥åããå人æ å ±ãå¤é¨ã«æµåºããã - ã»ã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³æ»æ
2020å¹´ã«æµ·å¤ãããã¯ã¼ã¯ç®¡çã½ããã¦ã§ã¢ãã³ãã¼ã®ãããã¯ã¼ã¯ç£è¦ãã¼ã«ã«ãã«ã¦ã§ã¢ãä»è¾¼ã¾ã1ä¸7å社以ä¸ã®é¡§å®¢ã«é å¸ããã顧客ã·ã¹ãã ã侵害ãããã
å³1ï¼ãµãã©ã¤ãã§ã¼ã³ããã³æ»æã®ã¤ã¡ã¼ã¸
C-SCRMã¨ã¯ï¼
ãã®ãããªãµãã©ã¤ãã§ã¼ã³æ»æã¸ã®å¯¾å¿ã®ã¢ããã¼ãã¨ãã¦ãNISTï¼ç±³å½æ¨æºæè¡ç 究æï¼ã§ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼C-SCRMï¼ã«é¢ããææ¸NIST SP 800-161 revision1ã2022å¹´5æã«å ¬éãã¦ãã¾ãã
- ã»NIST SP 800-161 revision1
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
ï¼ã·ã¹ãã ããã³çµç¹ã®ãµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãã®å®è·µï¼
å½ææ¸ã®ç®çã¯ããµãã©ã¤ãã§ã¼ã³å
¨ä½ã«ããããµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ã®ç®¡çãæ¯æ´ããããã«ããªã¹ã¯ç®¡çããã»ã¹ãç¹å®ãè©ä¾¡ãé¸æãå®è£
ããæ¹æ³ããã³ä¼æ¥å
¨ä½ã®ã³ã³ããã¼ã«ãç·©åããæ¹æ³ã«é¢ããã¬ã¤ãã³ã¹ãä¼æ¥ã«æä¾ãããã¨ã§ãã
ããã¦ããµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼C-SCRMï¼Cybersecurity Supply Chain Risk Managementï¼ã¯ãâãµãã©ã¤ãã§ã¼ã³å
¨ä½ã§ãµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ã¸ã®é²åºï¼exposureï¼ã管çããé©åãªå¯¾å¿æ¦ç¥ãããªã·ã¼ãããã»ã¹ãããã³æé ãéçºããããã®ä½ç³»çãªããã»ã¹âã§ãã
- â»æ¬ã³ã©ã ã§ã¯ããã以éããµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ããC-SCRMã¨å¼ç§°ãã¾ãã
- â»æ¬ã³ã©ã ã§ã¯ããã以éãNIST SP 800-161 revision1ãNIST SP 800-161r1ã¨å¼ç§°ãã¾ãã
2. 3ã¤ã®ã¬ãã«ã®ãªã¹ã¯ç®¡ç
ãã«ãã¬ãã«ãªã¹ã¯ç®¡ç
NIST SP 800-161r1ã§ã¯ãC-SCRMã®å®æ½ã«ããã¦ä»¥ä¸ã®ï¼ã¤ã®ã¬ãã«ã§æ§æãããªã¹ã¯ç®¡çãæå±ãã¦ãã¾ãã
- ã»ã¬ãã«1ï¼ã¨ã³ã¿ã¼ãã©ã¤ãºï¼ï¼é«ã¬ãã«ã®C-SCRMã®æ¦ç¥ãå®è£ è¨ç»ãããªã·ã¼
- ã»ã¬ãã«2ï¼ããã·ã§ã³ã¨ãã¸ãã¹ããã»ã¹ï¼ï¼ä¸ã¬ãã«ã®C-SCRMã®æ¦ç¥ãå®è£ è¨ç»ãããªã·ã¼
- ã»ã¬ãã«3ï¼éç¨ï¼ï¼C-SCRMè¨ç»
å³2ï¼C-SCRMã«ããããã«ãã¬ãã«ãªã¹ã¯ç®¡ç
ãã¤ã³ãã¯ãC-SCRMã«ããã¦å¯¾çãå¹æçã«æ¡ç¨ã»å®è£
ããããã«ã¯æ¦ç¥ãæ¬ ãããªãã¨ãããã¨ã§ããã¬ãã«1ã¯æ¦ç¥ãã¬ãã«3ã¯å¯¾çã®è¨ç»ã¨å®è£
ãããã¦ã¬ãã«2ã¯ãã®éãã¤ãªããå½¹å²ã§ãã
æãç¹å¾´çãªã¬ãã«1ã§ã¯ãä¼æ¥ã®C-SCRMæ¦ç¥ã決ããããªã¹ã¯ç®¡çæ¹éã決ãããC-SCRM PMOã決ãããã¨ãã£ãæ´»åãè¡ãã¾ãã
C-SCRM PMOã¨ã¯ãä¼æ¥ã®C-SCRMãæ¨é²ã»æ¯æ´ãã社å
çµç¹ã§ãåãããããè¨ãã¨C-SCRMã®äºåå±çãªçµç¹ã§ããC-SCRM PMOãæä¾ãã¹ã主è¦ãªæ©è½ã¨ãã¦ä»¥ä¸ã®ãã®ãæãããã¾ãã
C-SCRM PMOãæä¾ãã¹ã主è¦ãªæ©è½
- ã»C-SCRMã«é¢ããã¢ããã¤ã¶ãªã¼ãµã¼ãã¹ããã³å¯¾è±¡åéã®å°éç¥è
- ã»ç¤¾å ã®C-SCRMã¯ã¼ãã³ã°ã°ã«ã¼ãããè©è°ä¼ãã¾ãã¯ãã®ä»ã®èª¿æ´æ©é¢ã®è°é·
- ã»C-SCRMã«é¢ãããã¼ã«ãæé æ¸ãæèåä¸ããã¬ã¼ãã³ã°ãã³ãã¬ã¼ãã®ä¸å¿çå½¹å²
- ã»ãµãã©ã¤ã¤ã¼ããã³è£½åã®ãªã¹ã¯ã¢ã»ã¹ã¡ã³ã
- ã»å¤é¨ã¹ãã¼ã¯ãã«ãã¼ã¨ã®é£çµ¡
- ã»ç¤¾å çµç¹ã社å¤çµç¹ã¨ã®æ å ±å ±æããã¸ã¡ã³ã
- ã»C-SCRMãªã¹ã¯ä¸è¦§è¡¨ã®ç®¡ç
- ã»ã¨ã³ã¿ã¼ãã©ã¤ãºC-SCRMã¬ããã³ã¹ã®äºåå±ã»äººå¡é ç½®æ©è½
- ã»C-SCRMã®ããã¸ã§ã¯ã管çããã³ããã©ã¼ãã³ã¹ç®¡ç
- ã»C-SCRMã®ããªã¼ãã£ã³ã°ããã¬ã¼ã³ãã¼ã·ã§ã³ãããã³ã¬ãã¼ã
C-SCRM PMOã¯å¤§è¦æ¨¡ã§è¤éãªä¼æ¥ã«é©ãã¦ããã¨ããã¦ãã¾ãããã®ããå¿ é ã®çµç¹ã§ã¯ããã¾ãããããµãã©ã¤ãã§ã¼ã³ã®å©å®³é¢ä¿è ãå¤ããªãã»ã©ãã®ãããªæ©è½ãæ±ããããã¨èãããã¾ãã
C-SCRMã®æ¦ç¥ãå®è£ è¨ç»ãããªã·ã¼ãè¨ç»ã¨ã¯
ããã§ã¯C-SCRMã®æ¦ç¥ãå®è£
è¨ç»ã¨ã¯ä½ã§ãããããã¾ããåæ§ã«C-SCRMã®ããªã·ã¼ãè¨ç»ã¨ã¯ä½ã§ãããã
NIST SP 800-161r1ã§ã¯ãä»é²Dã«ãããã®çå®ã«åãããã³ãã¬ã¼ãä¾ãæ示ããã¦ãããåèã«ãããã¨ãã§ãã¾ãã以ä¸ã«ãã®é
ç®ãåæãã¾ãã
C-SCRMæ¦ç¥ããã³å®è£ è¨ç» | C-SCRMããªã·ã¼ | C-SCRMè¨ç» |
---|---|---|
|
|
ï¼ä»¥ä¸çç¥ï¼ |
ã¾ããåèã¨ãã¦C-SCRMæ¦ç¥ããã³å®è£ è¨ç»ã®ãã³ãã¬ã¼ãã®è¨è¼ä¾ï¼ä¸é¨ï¼ãç´¹ä»ãã¾ããï¼ä¼æ¥åã¯ä»®ã«ï¼¡ç¤¾ã¨ãã¦ãã¾ãï¼
表2ï¼C-SCRMæ¦ç¥ããã³å®è£ è¨ç»ã®è¨è¼ä¾ï¼ä¸é¨æç²ï¼
3. C-SCRMã®ãã¼ãã©ã¯ãã£ã¹
C-SCRMã«æ±ãããããã©ã¯ãã£ã¹ï¼å®è·µè¦ç¯ï¼
ããã¾ã§ãC-SCRMã®å®è·µã®ãããæ§ã
ãªè¦³ç¹ãè¦ã¦ãã¾ããããããããä¸åº¦ã«ãã¹ã¦å®ç¾ããã®ã¯ãªããªãé£ããã¨æãã¾ããããã§ãNIST SP 800-161r1ã§ã¯ãåºç¤çãã©ã¯ãã£ã¹ï¼Foundational Practicesï¼ãæç¶çãã©ã¯ãã£ã¹ï¼Sustaining Practicesï¼ãå¼·åãã©ã¯ãã£ã¹ï¼Enhancing Practicesï¼ã®3段éã®ãã©ã¯ãã£ã¹ï¼å®è·µè¦ç¯ï¼ã示ãã¦ãã¾ããä¼æ¥ã¯ãèªç¤¾ã®ç¶æ³ã«åããã¦ããããé¸æã»èª¿æ´ãã¦å®è¡ãããã¨ãæã¾ããã§ãã
ãã®ä¸é¨ã以ä¸ã«ç´¹ä»ãã¾ãã
å³3ï¼C-SCRMã®ãã¼ãã©ã¯ãã£ã¹
åºç¤çãã©ã¯ãã£ã¹
åºç¤çãã©ã¯ãã£ã¹ã¯æãåºæ¬çãªãã¼ãã©ã¯ãã£ã¹ã§ããä¼æ¥ã¯ä½ããã®å½¢ã§ãã®ãã©ã¯ãã£ã¹ãå®è·µãããã¨ãæ¨å¥¨ãã¾ãã
åºç¤çãã©ã¯ãã£ã¹ï¼Foundational Practicesï¼ |
---|
|
- *1ææ¢åï¼æå¶ã¨åè¡¡ï¼checks and balancesï¼ããã®å ´åãã³ã³ãã©ã¤ã¢ã³ã¹éåããããªãããã®ä»çµã¿ã®ãã¨ã
æç¶çãã©ã¯ãã£ã¹
æç¶çãã©ã¯ãã£ã¹ã¯ãC-SCRMã®ãªã¹ã¯ç®¡çæ©è½ãåä¸ããããã¼ãã©ã¯ãã£ã¹ã§ããåºç¤çãã©ã¯ãã£ã¹ãå®è£ ããä¼æ¥ã¯ã次ã®ã¹ãããã¨ãã¦ããããå®è·µãããã¨ãæ¨å¥¨ãã¾ãã
æç¶çãã©ã¯ãã£ã¹ï¼Sustaining Practicesï¼ |
---|
|
- *2ãªã¹ã¯é¸å¥½åº¦ï¼Risk Appetiteãæ欲çã«åãå ¥ãããªã¹ã¯ã®ç¨åº¦ã
- *3ãªã¹ã¯è¨±å®¹åº¦ï¼Risk Toleranceãèãããããªã¹ã¯ã®ç¨åº¦ã
å¼·åãã©ã¯ãã£ã¹
å¼·åãã©ã¯ãã£ã¹ã¯ãé©å¿åããã³äºæ¸¬åã® C-SCRMæ©è½ãç®æããã¼ãã©ã¯ãã£ã¹ã§ããæç¶çãã©ã¯ãã£ã¹ãå®è£ ããä¼æ¥ã¯ã次ã®ã¹ãããã¨ãã¦ããããå®è·µãããã¨ãæ¨å¥¨ãã¾ãã
å¼·åãã©ã¯ãã£ã¹ï¼Enhancing Practicesï¼ |
---|
|
4. ã¾ã¨ã
ä»åã¯ãµã¤ãã¼ã»ãã¥ãªãã£ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼C-SCRMï¼ã«ããããã«ãã¬ãã«ã®ãªã¹ã¯ç®¡çã¨ãC-SCRMã®ãã¼ãã©ã¯ãã£ã¹ã«ã¤ãã¦è§£èª¬ãã¾ããããµãã©ã¤ãã§ã¼ã³ã¯ã社å
ã»ç¤¾å¤ã®å¤ãã®çµç¹ãæ¥åãé¢ä¿ããé常ã«ç¯å²ãåºãã§ãããã®ãããå
·ä½çãªã»ãã¥ãªãã£å¯¾ç以åã«ãªã¹ã¯ç®¡çã¨ãã¦ã©ããããã決ãã¦éç¨ããããã«ãã©ããã¦ãããç¨åº¦ã®ãªã½ã¼ã¹ãå²ãå¿
è¦ãããã¾ãã
次åã¯NIST SP 800-161r1ã«ããã管ççã¨ãã¦ã®ãµãã©ã¤ãã§ã¼ã³ã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦è§£èª¬ãã¾ãã
åèè³æ
- â»æä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã