æ¥æ¬ã®IoT製åã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦ã¨EUãµã¤ãã¼ã¬ã¸ãªã¨ã³ã¹æ³ã«ã¤ãã¦
æ¬ã³ã©ã ã§ã¯ããµã¤ãã¼æ»æã®è å¨ãå¢å¤§ãã¦ããIoT製åã«å¯¾ãã¦ãæ¥æ¬ã§æºåãé²ãããã¦ããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦ã¨ãããã¨ä¸¦è¡ãã¦å¶åº¦æ§ç¯ãé²ãããã¦ããEUãµã¤ãã¼ã¬ã¸ãªã¨ã³ã¹æ³ï¼EU Cyber Resilience Actã以éCRAï¼ã«ãããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦ã®å ±éç¹ã»ç¸éç¹ã«ã¤ãã¦æ¦èª¬ãã¾ãããªããæ¬ã³ã©ã ã¯ãIoT製åã«å¯¾ããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦æ§ç¯æ¹éå ¬è¡¨æï¼ããã³æè¦å ¬åæï¼ã®å 容ããCRAæ¡ææã®å 容ã«åºã¥ãã¦ãããæ£å¼ãªå¶åº¦éå§æã«ã¯ç°ãªãé¨åãããå¯è½æ§ããããã¨ããèªèãã ããã
èæ¯
社ä¼ã»çµæ¸æ´»åãæ¯ããæ§ã
ãªããã»ã¢ãã»çµç¹ãã¤ã³ã¿ã¼ãããã«æ¥ç¶ããIoTåã®é²å±ã«ä¼´ããIoT製åã¯æ¥å¸¸çæ´»ã«æ¬ ãããªããªã£ã¦ãã¦ããããã®å°æ°ã¯ä¸ççã«æ¥éã«å¢å ãã¦ãã¾ãã
ããã¯ãIoT製åã®èå¼±æ§ãçã£ããµã¤ãã¼æ»æã®è
å¨ã®å¢å¤§ã«ãã¤ãªãã£ã¦ãã¾ããé©åãªç®¡çãè¡ãå±ãã«ããä¸ã«ãã¤ã³ã¿ã¼ãããã«æ¥ç¶ããä¸çä¸ããæ»æ対象ã«ãªãããã¨ããIoT製åã®æ§è³ªããããã®ã»ãã¥ãªãã£å¯¾çã«åããåãçµã¿ã¯ä¸çåå½ã§æ±ãããã¦ãããåå½ã§å¶åº¦æ¤è¨ãé²ãããã¦ãã¾ãã
æ¥æ¬ã§ã¯ã2022å¹´ããæ¬æ ¼æ¤è¨ãå§ã¾ã£ãIoT製åã®ã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦ï¼ä»¥ä¸ãIoT製åé©åæ§è©ä¾¡å¶åº¦ï¼ã®æ§ç¯æ¹éã2024å¹´8æ23æ¥ã«å ¬è¡¨ããã¾ãããããã¦ã2025å¹´3æé ã«ã¯ãã»ãã¥ãªãã£é©ååºæºã«å¯¾ããèªå·±é©å宣è¨ã®åä»ããã³ã©ãã«ä»ä¸éå§ãç®æããã¹ãã¼ã ãªã¼ãã¼ã§ããç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼ä»¥ä¸ãIPAï¼ããæ¡å ãè¡ãããäºå®ã§ãã
欧å·ã§ãããããã¯ã¼ã¯ã«æ¥ç¶ãããã¨ãåæã¨ãããã¸ã¿ã«è¦ç´ ãåãã製åï¼products with digital elementsã以ä¸ããã¸ã¿ã«è£½åï¼ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã¸ã®åãçµã¿ãå¼·åããæ çµã¿ãé©åæ§è©ä¾¡ã«ã¤ãã¦å®ããCRAã®æ½è¡ã«åããæºåãé²ãããã¦ãã¾ããCRAã¯ã2024å¹´3æ12æ¥ã«æ¬§å·è°ä¼ã§æ¡æããã¦ããããè¦åï¼Regulationï¼ãï¼ãã¹ã¦ã®å çå½ãææããå çå½å æ³ä½ç³»ã®ä¸é¨ã¨ãªãï¼ã¨ãã¦2024å¹´ä¸ã«çºå¹ãå ±å義åãé¤ã2027å¹´ã«æ½è¡ããããã¨ãè¦è¾¼ã¾ãã¦ãã¾ãã
æ¥æ¬ã®IoT製åé©åæ§è©ä¾¡å¶åº¦ã¸ã®å¯¾å¿ã¯ä»»æã¨ããã¦ãã¾ããä¸æ¹ãCRAã¯ãæ³å¾ã¨ãã¦EUåå ã®å¸å ´ã§æµéããã»ã¼ãã¹ã¦ã®ãã¸ã¿ã«è£½åã«å¯¾ãã¦éµå®ã義åä»ãããã¦ãã¾ãããã®ãããEUå¸å ´ã§è²©å£²ããã¦ãããã¸ã¿ã«è£½åã«é¢ãã£ã¦ããæ¥æ¬ã®ä¼æ¥ãç¡é¢ä¿ã¨ã¯ããã¾ãããEUã§ãã¸ã¿ã«è£½åã販売ãã¦ããä¼æ¥ã¯ãCRAã«å¯¾ããåãçµã¿ãé²ãããã¦ãããã®ã¨æãã¾ãã
次ã®è¡¨1ã¯ãæ¥æ¬ã®IoT製åé©åæ§è©ä¾¡å¶åº¦ã¨CRAã®ç®çã対象製åãã»ãã¥ãªãã£è¦ä»¶ãé©åæ§è©ä¾¡ãé©åæ§è©ä¾¡ã®ä¸»ä½ã«ã¤ãã¦æ´çãããã®ã§ãã
以ä¸ã§ã¯ãããããã®é
ç®ã®å
±éç¹ã¨ç¸éç¹ã«ã¤ãã¦èª¬æãã¾ãã ãªããIoT製åé©åæ§è©ä¾¡å¶åº¦ã®å¶åº¦æ§ç¯æ¹éã®ãå¥æ·» â1ã»ãã¥ãªãã£è¦ä»¶ã»é©ååºæºãã®åèã§å¼ç¨ããã¦ããCRAã¯ã2022å¹´ã®ææ¡æã®å
容ãå
ã«ä½æããã¦ããã2024å¹´ã®æ¡ææã®å
容ã¨ã¯æ¡çªå·ãè¨è¼å
容ã«ç¸å½æ°ã®å¤æ´ãçºçãã¦ãã¾ããæ¬ã³ã©ã ã§ã¯ãæ¡ææã®å
容ã«åºã¥ãã¦è¨è¼ãã¦ãã¾ãã
é ç® | IoT製åé©åæ§è©ä¾¡å¶åº¦ | CRA |
---|---|---|
主ãªç®ç |
|
|
対象製å |
|
|
ã»ãã¥ãªãã£è¦ä»¶ |
è©ä¾¡åºæº
|
éå±æ¸I å¿ é è¦ä»¶
è©ä¾¡åºæº
|
é©åæ§è©ä¾¡ |
é©åè©ä¾¡ã¬ãã«ã«åºã¥ããã»ãã¥ãªãã£è¦ä»¶ãé©ååºæºãè©ä¾¡æé ãè©ä¾¡æ¹å¼ãè¨å® é©åæ§è©ä¾¡ã¬ãã«ã¨é©ååºæºã»è©ä¾¡æé
é©åæ§è©ä¾¡æ¹å¼
ãã®ä»
|
éå±æ¸Iã«è¦å®ããã¦ããå¿ é è¦ä»¶ãæºãããã¦ãããã©ããã®è©ä¾¡ é©åæ§è©ä¾¡æé CEãã¼ãã³ã°ã®ããã®4æé ãããã³æ¬§å·ãµã¤ãã¼ã»ãã¥ãªãã£èªè¨¼å¶åº¦
é©åæ§è©ä¾¡æ¹å¼
ãã®ä»
|
é©åæ§è©ä¾¡ã®ä¸»ä½ |
|
|
ç®ç
å ±éç¹
ç®çã®å ±éç¹ã¯ããããã¯ã¼ã¯ã«æ¥ç¶ããããã¸ã¿ã«è£½åï¼IoT製åãããã®ã©ã¤ããµã¤ã¯ã«ãéãã¦å®å ¨ãªç¶æ ã§ä½¿ç¨ããããã¨ã製é äºæ¥è ã«ä¿è¨¼ããããã¨ã§ããã¾ããã¦ã¼ã¶ã製åãé¸å®ããéã«ã製åã®ã»ãã¥ãªãã£ç¶æ ã«ã¤ãã¦ç¢ºèªã§ããããã«ãããã¨ãå ±éãã¦ããç¹ã¨ããã¾ãã
ç¸éç¹
åé ã§ã触ãã¾ããããCRAã¯ãEUåå ã§è²©å£²ããã対象ã¨ãªããã¸ã¿ã«è£½åã«å¯¾ãã¦èª²ãããã義åãã§ããã®ã«å¯¾ãã¦ãæ¥æ¬ã®IoT製åé©åæ§è©ä¾¡å¶åº¦ã¸ã®é©åã¯ãä»»æãã§ããã¨ããç¹ã«éããããã¾ããIoT製åé©åæ§è©ä¾¡å¶åº¦ã¯ãé©åãã製åã使ç¨ãããã¨ãæ¿åºæ©é¢çã§ã®èª¿éæã®æ¡ä»¶ã¨ãããã¨ã§ãIoT製åã®ã»ãã¥ãªãã£ã¬ãã«ãåä¸ããããã¨ãæå³ãã¦ãã¾ããæ¥æ¬ã§ã¯ãISMSã«æºæ ããçµç¹ãä»å½ã¨æ¯è¼ãã¦å¤ãã¨ããç¹å¾´ãããã¾ãããããã¯çµç¹ã®ã»ãã¥ãªãã£ã¬ãã«ã測ãææ¨ã¨ãã¦å ¥ææ¡ä»¶çã«ISMSèªè¨¼åå¾ãæ±ãããããã¨ãå¤ãã¨ãããã¨ãçç±ã®ä¸ã¤ã¨èãããã¾ãã調éæ¡ä»¶ã«ãããã¨ã§ä¾çµ¦ããã製åã®ã»ãã¥ãªãã£ã¬ãã«åä¸ãå³ãã¨ããæå³ã§ã¯ãIoT製åé©åæ§è©ä¾¡å¶åº¦ã¯ããISMSã®è£½åçãã®ãããªä½ç½®ä»ãã«ãããã¨ããæå³ãããã®ããããã¾ããã
対象製å
å ±éç¹
å¶åº¦å¶å®ã®èæ¯ã«ã¯ããããã¯ã¼ã¯ã«æ¥ç¶ããããã¸ã¿ã«è£½åï¼IoT製åãçµç±ããã»ãã¥ãªãã£ã¤ã³ã·ãã³ããæå¶ããã¨ãã観ç¹ãããã¾ãããã®ããã製åã®éè¦æ§ãå©ç¨ã·ã¼ã³ï¼æ¶è²»è åãããæ¿åºã»ä¼æ¥ã»ç£æ¥åããï¼ã«ããããããæ»æãã¯ãã«ï¼æ»æè ããããã¯ã¼ã¯ãã·ã¹ãã ã«ä¾µå ¥ããããã®æ¹æ³ï¼ã¨ãã¦å©ç¨ãããã製åã対象ã«ãã¦ããã¨ããç¹ã¯ãåæ¹ã«å ±éãã¦ãã¾ãã
ç¸éç¹
ä¸æ¹ã対象å¤ã¨ãªã製åã¨ãã¦ãCRAã§ã¯ãæ¢åã®ä»ã®è¦åï¼å»çæ©å¨è¦åãæ°éèªç©ºæ©è¦åãèªåè»ã®åå¼èªè¨¼è¦åçï¼ã®å¯¾è±¡è£½åãããã³å½å®¶å®å
¨ä¿éã«é¢ãããã¸ã¿ã«è£½åãè»äºç®çã»æ©å¯æ
å ±å¦çç®çã®è£½åã¯é©ç¨ããé¤å¤ããã¦ãã¾ãã
IoT製åé©åæ§è©ä¾¡å¶åº¦ã§ã¯ãã»ãã¥ãªãã£å¯¾çã追å ã§ããæ±ç¨çãªIT製åï¼ãã½ã³ã³ãã¿ãã¬ãã端æ«ãã¹ãã¼ããã©ã³çï¼ã¯å¯¾è±¡å¤ã¨ãã¦ãã¾ãã
ã¾ãã対象製åã®åé¡æ¹æ³ã«ã¤ãã¦ãCRAã§ã¯ããé常ã«éè¦ãªè£½åï¼critical productsï¼ãããéè¦ãªè£½åï¼important productsï¼ããããã³ãã以å¤ã®è£½åï¼æ¬ã³ã©ã ã§ã¯ãé常ã®è£½åãã¨è¨è¼ãã¾ãï¼ã®ããã«è£½åã®éè¦æ§ã«åºã¥ããåé¡ãè¡ããã¦ãã¾ãï¼éå±æ¸IIIãéå±æ¸IVï¼ãã¾ãããéè¦ãªè£½åãã¯ãã¯ã©ã¹Iãï¼ä½ãªã¹ã¯ï¼ã¨ãã¯ã©ã¹IIãï¼é«ãªã¹ã¯ï¼ã«è£½åãåé¡ãã¦ãã¾ããå¾ã«èª¬æããé©åæ§è©ä¾¡æç¶ãã¯ããã®éè¦æ§ã¨ãªã¹ã¯ã«åºã¥ã製ååé¡ã¨çµã³ã¤ãããã®ã¨ãªã£ã¦ãã¾ãã
ããã«å¯¾ãã¦IoT製åé©åæ§è©ä¾¡å¶åº¦ã§ã¯ãéä¿¡æ©å¨ãé²ç¯é¢é£æ©å¨ãã¹ãã¼ã家é»ãªã©ã®ããã«è£½åã®ç¹å¾´ã«å¿ãã製åé¡åãæ´çãããã¨ãæ¤è¨ããã¦ãã¾ããå¾ã«èª¬æããé©ååºæºã¯ããã®è£½åé¡åããã³é©åæ§è©ä¾¡ã¬ãã«ãã¨ã«è¨å®ããã¾ãã
ã»ãã¥ãªãã£è¦ä»¶
å ±éç¹
æ¥æ¬ã®IoT製åé©åæ§è©ä¾¡å¶åº¦ã¯ãæ¯è¼çé
ãã¦å¶åº¦æ§ç¯ãé²ãããããã¨ããããåå½ãé²ãã¦ããåæ§ã®å¶åº¦ã®ææãæ´»ç¨ããåãè¾¼ããã¨ãã§ãã¦ãã¾ãããã®çµæãCRAã®å¿
é è¦ä»¶ãã«ãã¼ããã»ãã¥ãªãã£è¦ä»¶ã¨ãªã£ã¦ãã¾ãã
ããããæ®å¿µãªãããæ¬ã³ã©ã å·çæç¹ã§ã¯è¦ä»¶å
¨ä½ãã«ãã¼ããé©åè©ä¾¡åºæºã¯ä½æããã¦ããªãã¨ããç¹ã¯å
±éãã¦ãã¾ãã
ç¸éç¹
CRAã«ããã¦ãã¸ã¿ã«è£½åãå¸å ´ã«æµéããããã«æ±ããããã»ãã¥ãªãã£è¦ä»¶ã¯ããéå±æ¸I å¿ é è¦ä»¶ãã§å®ãããã¦ãã¾ããéå±æ¸Iã¯ãããã¼ã1 ãã¸ã¿ã«è£½åã®ç¹æ§ã«é¢ãããµã¤ãã¼ã»ãã¥ãªãã£è¦ä»¶ãï¼å ¨14é ç®ï¼ããã³ããã¼ã2 èå¼±æ§ãã³ããªã³ã°è¦ä»¶ãï¼å ¨8é ç®ï¼ããæ§æããã¦ãã¾ãããã¼ã1ã¯ã対象ã¨ãªããã¸ã¿ã«è£½åã®è¨è¨ã»éçºã»è£½é ã«é¢ããè¦ä»¶ãããã³ãªã¹ã¯è©ä¾¡ã»ãªã¹ã¯å¯¾çã«é¢ããè¦ä»¶ã§æ§æããã¦ããããã¼ã2ã¯ã対象製åã«èå¼±æ§ãããã«ä¼´ãã¤ã³ã·ãã³ããçºè¦ãããéã«è£½é æ¥è ã«æ±ãããã対çã«é¢ããè¦ä»¶ã§æ§æããã¦ãã¾ãããªãããããã®å¿ é è¦ä»¶ã®é©åæ§è©ä¾¡åºæºã¯ãæ´åè¦æ ¼ï¼harmonised standardsï¼ã¨ãã¦æ´åããããã¨ã«ãªã£ã¦ãã¾ãããæ¬ã³ã©ã å·çæç¹ã§ã¯ã¾ã å ¬éããã¦ãã¾ããã
ä¸æ¹IoT製åé©åæ§è©ä¾¡å¶åº¦ã®ã»ãã¥ãªãã£è¦ä»¶æ¡ã¯ããã¹ã¦ã®æ°çç¨IoTæ©å¨ã«é©ç¨ãããåºæ¬çãªãµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ãã欧å·è¦æ ¼ã¨ãã¦ãã§ã«åºãå©ç¨ããã¦ããETSI EN 303 645ãããã³åæ§ã®å¶åº¦ãå°å ¥ã»éå§ããã¦ããã·ã³ã¬ãã¼ã«ã®Cybersecurity Labelling Schemeï¼CLSï¼ãåèã«ã18ã®ã«ãã´ãªã101ã®ã»ãã¥ãªãã£è¦ä»¶ã§æ§æããã¦æè¦å ¬åã«æãããã¦ãã¾ãï¼2024å¹´3æï¼ã次é ã§èª¬æãã¾ããããã¹ã¦ã®è£½åé¡åã«å ±éããåºæ¬çãªã¬ãã«ã¨ãã¦è©ä¾¡ãããâ1ã®è¦ä»¶ãé©åæ§è©ä¾¡é ç®ãããã25è¦ä»¶ã16é ç®ãå ¬éããã¦ãã¾ããâ2以ä¸ã«èª²ãããè¦ä»¶ãé©åæ§è©ä¾¡é ç®ã¯ãä»å¾å ¬éãããäºå®ã¨ãªã£ã¦ãã¾ãã
IoT製åé©åæ§è©ä¾¡å¶åº¦ã®è¦ä»¶ã¯CRAã®éå±æ¸Iã®å¿
é è¦ä»¶ã ãã§ã¯ãªããCRAã®ä»ã®éå±æ¸ãæ¡æã«è¨è¼ããã¦ããäºé
ããCRAã®æ¡æã¨ã¯ç´æ¥é¢é£ããªãäºé
ãå«ãã§ãã¾ããIoT製åé©åæ§è©ä¾¡å¶åº¦æè¦å
¬åæã®ã»ãã¥ãªãã£è¦ä»¶æ¡101ã®ãã¡ãCRAã«ç¸å½ããè¦ä»¶ã»æ¡æãããè¦ä»¶ã¯57è¦ä»¶ãæ®ãã®44è¦ä»¶ã¯CRAã«å«ã¾ãã¦ãã¾ããã
表2ã§ã¯ãIoT製åé©åæ§è©ä¾¡å¶åº¦ã®â1è©ä¾¡é
ç®ã¨å¯¾å¿ããã»ãã¥ãªãã£è¦ä»¶ãããã³IoT製åé©åæ§è©ä¾¡å¶åº¦ã®ã»ãã¥ãªãã£è¦ä»¶ã«é¢é£ããCRAè¦ä»¶ãä¸è¦§åãã¦ãã¾ãï¼CRAã®è¦ä»¶ã¯ãâ1ã®è©ä¾¡é
ç®ã¨æ£ç¢ºã«ä¸è´ãã¦ããå
容ã§ã¯ãªããã¨ã«æ³¨æãå¿
è¦ã§ãï¼ãâ1ã®è©ä¾¡é
ç®ã¯16ã§ããããã®ãã¡ãCRAã«é¢é£ããè¦ä»¶ã»æ¡æã®ããè©ä¾¡é
ç®ã¯12ã¨ãªãã¾ãã
â1è©ä¾¡é ç®çªå·ãé©ååºæºã®æ¦è¦ | ã»ãã¥ãªãã£è¦ä»¶ | CRA |
---|---|---|
1 é©åãªèªè¨¼ã«åºã¥ãã¢ã¯ã»ã¹å¶å¾¡ | 1-3, 5-5 | éå±æ¸I 1.(2)(d) |
2 容æã«æ¨æ¸¬å¯è½ãªããã©ã«ããã¹ã¯ã¼ãã®ç¦æ¢ | 1-1, 1-2 | - |
3 ãã¹ã¯ã¼ãçã®èªè¨¼å¤ã®å¤æ´æ©è½ | 1-4 | - |
4 ãããã¯ã¼ã¯çµç±ã®ã¦ã¼ã¶èªè¨¼ã«å¯¾ããç·å½ããæ»æããã®ä¿è· | 1-5 | éå±æ¸I 1.(2)(d) |
5 é£çµ¡å ã»æç¶ãçã®èå¼±æ§é示ããªã·ã¼ã®å ¬é | 2-1 | éå±æ¸I 2.(5)ãéå±æ¸I 2.(6)ãéå±æ¸II 1ãéå±æ¸II 2 |
6 ã½ããã¦ã§ã¢ã³ã³ãã¼ãã³ãã®ã¢ãããã¼ãæ©è½ | 3-1, 3-2 | éå±æ¸I 2.(8) |
7 容æãã¤åãããããã½ããã¦ã§ã¢ã¢ãããã¼ãæé | 3-3 | éå±æ¸I 2.(8) |
8 ã¢ãããã¼ãåã®ã½ããã¦ã§ã¢ã®å®å ¨æ§ã®ç¢ºèªæ©è½ | 3-2, 3-7, 3-10 | éå±æ¸I 1.(2)(f) |
9 ã»ãã¥ãªãã£ã¢ãããã¼ãã®åªå 度決å®æ¹éã®ææ¸å | 3-8 | éå±æ¸I 2.(2)ãéå±æ¸I 2.(7)ãéå±æ¸I 2.(8) |
10 ã¦ã¼ã¶ãåå¼çªå·ãèªèå¯è½ã¨ããè¨è¼ã»æ©è½ | 3-14 | éå±æ¸II 3 |
11 製åã«ä¿åãããå®ãã¹ãæ å ±ã®ä¿è· | 4-1 | - |
12 ãããã¯ã¼ã¯çµç±ã§ä¼éãããå®ãã¹ãæ å ±ã®ä¿è· | 5-1, 5-7 | éå±æ¸I 1.(2)(e) |
13 ä¸è¦ãã¤ãªã¹ã¯ã®é«ãã¤ã³ã¿ãã§ã¼ã¹ã®ç¡å¹å | 6-1 | éå±æ¸I 1.(2)(j) |
14 åé»ã»ãããã¯ã¼ã¯åæ¢çããã®å¾©æ§æã®èªè¨¼æ å ±ãã½ããã¦ã§ã¢è¨å®ã®ç¶æ | 9-1 | éå±æ¸I 1.(2)(h) |
15 製åå ã«ä¿åãããå®ãã¹ãæ å ±ã®åé¤æ©è½ | 11-1 | - |
16 ã¦ã¼ã¶ã¸ã®ã»ãã¥ã¢ãªå©ç¨ã»å»æ£æ¹æ³ã«é¢ããæ å ±æä¾ | 17-2, 17-3, 17-5, 17-8, 17-10 | éå±æ¸I 2.(4)ãéå±æ¸I 2.(8)ãéå±æ¸II 4ãéå±æ¸II 5ãéå±æ¸II 6ãéå±æ¸II 7ãéå±æ¸II 8ãéå±æ¸II 9 |
表2ã®CRAã®è¦ä»¶ã®ãã¡ã太åã¯éå±æ¸Iã«è¨è¼ã®è¦ä»¶ã§ãï¼éå±æ¸IIã¯ãã¦ã¼ã¶ã¸ã®æ
å ±ã¨èª¬æã¨ãã¦ããã¸ã¿ã«è£½åã«æ·»ä»ãã¹ãäºé
ãã¾ã¨ãããã¦ãã¾ãï¼ã
ãªããIoT製åé©åæ§è©ä¾¡å¶åº¦æè¦å
¬åæã®101ã®ã»ãã¥ãªãã£è¦ä»¶æ¡ã§ãCRAã®ä»ã®éå±æ¸ãæ¡æã«é¢é£ããé
ç®ã«ã¯ã以ä¸ãããã¾ãï¼ç¬¬13æ¡ è£½é æ¥è
ã®ç¾©åã第14æ¡ è£½é æ¥è
ã®å ±å義åã第28æ¡ EUé©å宣è¨ã第31æ¡ æè¡ææ¸ã第32æ¡ ãã¸ã¿ã«è£½åã®é©åæ§è©ä¾¡æé ãéå±æ¸II ã¦ã¼ã¶ã¸ã®æ
å ±ã¨æ示ãéå±æ¸V EUé©å宣è¨ãéå±æ¸VII
æè¡ææ¸ã®å
容ã
â1ã®è©ä¾¡é ç®ã¯ãCRAã®éå±æ¸Iã®è¦ä»¶ãç¶²ç¾ ãã¦ããããã§ã¯ããã¾ãããä¾ãã°ãCRAã®è¦ä»¶ã¨ãã¦ãã°ãã°è¨åãããSBOMï¼Software Bill of Materials, ã½ããã¦ã§ã¢é¨åæ§æ表ï¼ã®ä½æã¯ã©ãã§ãããããCRAã§ã¯ãéå±æ¸I 2.(1)ã§è¦æ±ããã¦ãããIoT製åé©åæ§è©ä¾¡å¶åº¦æè¦å ¬åæã®è¦ä»¶æ¡ã§ã¯3-15ã¨ãã¦æ¤è¨ããã¦ãã¾ããããããã¯è¡¨2ã«ã¯ç»å ´ãã¾ãããCRAéå±æ¸Iã®è¦ä»¶ããã¹ã¦æºããããã«ã¯ãIoT製åé©åæ§è©ä¾¡å¶åº¦ã®â2ãâ3ãªã©ã§è©ä¾¡ãããä»ã®è¦ä»¶ãæºããå¿ è¦ãããã¨ãããã¨ã«ãªãã¾ããIoT製åé©åæ§è©ä¾¡å¶åº¦ã¨CRAã®ç¸äºèªè¨¼ã«ã¤ãã¦æ¤è¨ããã¦ããå ´åã¯ããã®ç¹ã«ã注æãã¦ãããã¨ãå¿ è¦ããããã¾ããã
é©åæ§è©ä¾¡
å ±éç¹
èªå·±é©å宣è¨ãããã¯ç¬¬ä¸è èªè¨¼ã®ããããã«ãã£ã¦è¦ä»¶ã¸ã®é©åæ§ãå®è¨¼ãããã¨ãé©åãã¦ãã製åã¸ã®ã©ããªã³ã°ï¼CRAã§ã¯CEãã¼ãã³ã°ï¼ã«ãããã®é©åæ§ã示ããã¨ãã§ãããã¨ã¯åæ¹ã§å ±éãã¦ããã¨ããã¾ããã¾ããåå½ã§å°å ¥ãæºåãé²ãããã¦ããåæ§ã®é©åæ§è©ä¾¡å¶åº¦ã§è©ä¾¡ããã製åã®ç¸äºèªè¨¼ã«ã¤ãã¦æ¤è¨ãããã¦ããç¹ã«ã¤ãã¦ãå ±éãã¦ãã¾ããâ1ã®å¶åº¦éç¨ãéå§ãããæç¹ã§ããã§ã«å¶åº¦ãå°å ¥ããã¦ããã·ã³ã¬ãã¼ã«ã®CLSããã³ã¤ã®ãªã¹ã®Product Security and Telecommunication Infrastructure Actï¼PSTIæ³ï¼ã¨ã¯ç¸äºèªè¨¼ã®æ¹åæ§ãæ示ãããã¨ãäºå®ããã¦ãã¾ãã
ç¸éç¹
製åé¡åã製ååé¡ãã¨ã®è©ä¾¡æç¶ãã«ã¤ãã¦ã¯ãCRAã¨IoT製åé©åæ§è©ä¾¡å¶åº¦ã§å°ãéããããã¾ãã
表3ã¯ãCRAã«ããã製åã®åé¡ã¨é©åæ§è©ä¾¡æç¶ãã®é¢ä¿ã示ãããã®ã§ãã
CRAã®å ´åã製åã«é¢ãããå¿
é è¦ä»¶ã¯åãï¼éå±æ¸Iï¼ã§ãã製é æ¥è
ã¯ãéå±æ¸Iã®å¿
é è¦ä»¶ãæºããã¦ãããã¨ããä»å¾æ´åãããæ´åè¦æ ¼ãå©ç¨å¯è½ã«ãªã£ãéã«ããã®è¦æ ¼ã«å¾ã£ã¦ç¤ºããã¨ãã§ãã¾ãã
é©åç¶æ³ã示ãæç¶ãã¯ã製åã®éè¦æ§ã«å¿ããåé¡ãã¨ã«è£½é æ¥è
ãé¸æãããã¨ã«ãªãããã®é¸æã®å¹
ã¯è£½ååé¡ã«ãã£ã¦ç°ãªã£ã¦ãã¾ãããéè¦ãªè£½åãããé常ã«éè¦ãªè£½åãã¯ãèªå·±é©å宣è¨ã«ããé©åæ§ã®å®è¨¼ãæ¡ç¨ã§ãã¾ããã
CRAã«ãããé©åæ§è©ä¾¡æç¶ãã¯ãEUåå
ã§è²©å£²ããã製åã®å®å
¨æ§ã示ãCEãã¼ã¯ãè²¼ä»ããããã«ä½¿ç¨ããã¦ããé©åæ§è©ä¾¡æç¶ããã¢ã¸ã¥ã¼ã«Aãã¢ã¸ã¥ã¼ã«Bãã¢ã¸ã¥ã¼ã«Cãã¢ã¸ã¥ã¼ã«Hã®4種é¡ï¼éå±æ¸IVï¼ãæ¡ç¨ãã¦ãã¾ãã
å®è¨¼æ¹æ³ | æç¶ã | 製åã®éè¦æ§ | |||
---|---|---|---|---|---|
é常 | éè¦ | é常ã«éè¦ | |||
ã¯ã©ã¹I | ã¯ã©ã¹II | ||||
èªå·±é©åå®£è¨ | Module Aï¼å é¨çç£ç®¡çï¼ | ã | - | - | - |
第ä¸è èªè¨¼ | Module B&Cï¼EUåå¼è©¦é¨ããã³å é¨çç£ç®¡çã«åºã¥ãEUåå¼ã¸ã®é©åï¼ | ã | ã | ã | â³ |
Module Hï¼ç·åå質ä¿è¨¼ã«åºã¥ãé©åï¼ | ã | ã | ã | â³ | |
ãµã¤ãã¼ã»ãã¥ãªãã£èªè¨¼å¶åº¦ï¼EUCCï¼ | ã | ã | ã | ã |
å¡ä¾ï¼ããé©ç¨å¯è½ããâ³ãä»ã®æç¶ããã¨ããã¨ãã§ããªãå ´åãé©ç¨å¯è½ã- é©ç¨å¯¾è±¡å¤
ã¾ããEUãµã¤ãã¼ã»ãã¥ãªãã£æ³ï¼Cybersecurity Act, Regulation (EU) 2019/881ï¼ã«åºã¥ã2024å¹´1æ31æ¥ã«æ¡æããããµã¤ãã¼ã»ãã¥ãªãã£èªè¨¼å¶åº¦ï¼European Cybersecurity Certification Schemes, EUCCï¼ã«åºã¥ãã¦çºè¡ããããå®è³ªçã以ä¸ã®ä¿è¨¼ã¬ãã«ã®EUãµã¤ãã¼ã»ãã¥ãªãã£è¨¼ææ¸ã«ããããé常ã®è£½åãããã³ãéè¦ãªè£½åãã«å¯¾ãã¦ãã¢ã¸ã¥ã¼ã«B&Cããã³ã¢ã¸ã¥ã¼ã«Hã«ãã第ä¸è
é©åæ§è©ä¾¡ãå®æ½ãã義åããªããªãã¾ãï¼ç¬¬27æ¡(9)ã§è¦å®ï¼ããªããEUãµã¤ãã¼ã»ãã¥ãªãã£è¨¼ææ¸ã§ç¤ºãããä¿è¨¼ã¬ãã«ã«ã¯ãåºæ¬çï¼basicï¼ãããå®è³ªçï¼substantialï¼ãããé«åº¦ï¼highï¼ããããã¾ãã
ãé常ã«éè¦ãªè£½åãã®å ´åãä¸è¨ã®EUãµã¤ãã¼ã»ãã¥ãªãã£èªè¨¼å¶åº¦ãéãã¦ããå®è³ªçã以ä¸ã®ä¿è¨¼ã¬ãã«ã®EUãµã¤ãã¼ã»ãã¥ãªãã£è¨¼ææ¸ãåå¾ããå¿
è¦ãããã¾ãï¼ç¬¬8æ¡(1)ã§è¦å®ï¼ã
表4ã¯ãIoT製åé©åæ§è©ä¾¡å¶åº¦ã«ããã製åé¡åã¨é©åæ§è©ä¾¡ã®å®è¨¼æ¹æ³ã«ã¤ãã¦ã®ã¤ã¡ã¼ã¸ã示ãã¦ãã¾ããIoT製åé©åæ§è©ä¾¡å¶åº¦ã®å ´åãâ1ã§ã¯è£½åé¡åã«é¢ãããå ±éã®è©ä¾¡é ç®ã§èªå·±é©å宣è¨ãè¡ããã¨ã«ãããé©åæ§ã示ãã¾ããâ2以ä¸ã§ã¯ã製åé¡åãã¨ã«å¯¾å¿ãæ±ããããè¦ä»¶ãé©ååºæºãè©ä¾¡æé ãæ´åãããâ2ã¯èªå·±é©å宣è¨ã§ãâ3以ä¸ã¯ç¬¬ä¸è èªè¨¼ã§é©åæ§ãå®è¨¼ãã¾ãããªããè©ä¾¡é ç®ã«ã¤ãã¦â1ã§ã¯ãã®æ¡ãå ¬éããã¦ãã¾ãããâ2以ä¸ã«ã¤ãã¦ã¯ä»å¾æ´åãå ¬éããããã¨ã«ãªã£ã¦ãã¾ãã
å®è¨¼æ¹æ³ | ã¬ãã« | 製åé¡å A | 製åé¡å B | 製åé¡å C |
---|---|---|---|---|
èªå·±é©åå®£è¨ | â1 | çµ±ä¸çé©ååºæº | ||
â2 | åå¥é©ååºæº | åå¥é©ååºæº | åå¥é©ååºæº | |
第ä¸è èªè¨¼ | â3 | åå¥é©ååºæº | åå¥é©ååºæº | - |
â4 | åå¥é©ååºæº | - | - |
ãªããã©ããªã³ã°ã«ããé©åæ§ã示ããã¨ãã§ãããã¨ã¯å ±éãã¦ããã®ã§ãããCRAã§ã¯CEãã¼ãã³ã°ãã¦ããªããã¸ã¿ã«è£½åã¯ãå¸å ´ã§è²©å£²ãããã¨ãã§ããªãã®ã«å¯¾ãã¦ãIoTé©åæ§è©ä¾¡å¶åº¦ã§ã¯ãã©ãã«ã®è¡¨ç¤ºç¾©åã¯è¨ãããã¦ãã¾ããã
é©åæ§è©ä¾¡ã®ä¸»ä½
å ±éç¹
製åã®é©åæ§è©ä¾¡ã«ããã¦ããã¸ã¿ã«è£½åï¼IoT製åã®è£½é æ¥è ãè©ä¾¡ããã³å®è¨¼ãè¡ãèªå·±é©å宣è¨ã¨è©ä¾¡æ©é¢ãè¡ã第ä¸è èªè¨¼ãããç¹ã¯ãIoT製åé©åæ§è©ä¾¡å¶åº¦ã¨CRAã§å ±éãã¦ãã¾ãã
ç¸éç¹
CRAã®ç¬¬ä¸è
èªè¨¼ã§ã¯ãå çå½ã®èªå®æ©é¢ï¼notifying authorityï¼ã«èªå®ãããé©åæ§è©ä¾¡æ©é¢ï¼conformity assessment bodyï¼ã§ãã第ä¸è
è©ä¾¡æ©é¢ï¼notified bodyï¼ã«ãããã¢ã¸ã¥ã¼ã«Bããã³ã¢ã¸ã¥ã¼ã«Hã®æç¶ãã«åºã¥ãã¦è©ä¾¡ãè¡ããã¾ããEUé©å宣è¨ã®ä½æããã³CEãã¼ãã³ã°ã¯ãèªå·±é©å宣è¨ã®å ´åã第ä¸è
èªè¨¼ã®å ´åã製é äºæ¥è
ãè¡ããã¨ã«ãªãã¾ãããã¢ã¸ã¥ã¼ã«Hã®æç¶ãã«åºã¥ãã¦è©ä¾¡ãè¡ãããå ´åã¯ãCEãã¼ã¯ã«ç¬¬ä¸è
è©ä¾¡æ©é¢ã®è©ä¾¡æ©é¢çªå·ãä»è¨ããå¿
è¦ãããã¾ãã
ã¾ããEUCCã«ããé©åæ§ã示ãå ´åããEUCCã®é©åæ§è©ä¾¡æ©é¢ã«ããè©ä¾¡ãåãã証ææ¸ãåå¾ããå¿
è¦ãããã¾ãã
IoT製åé©åæ§è©ä¾¡å¶åº¦ã§ã¯ãæè³æ ¼è
ãè©ä¾¡ãè¡ãå ´åãæ
å ±å¦çå®å
¨ç¢ºä¿æ¯æ´å£«çã®æå®è³æ ¼ä¿æè
ãç ä¿®ãåè¬ã宣èªããä¸ã§è©ä¾¡åã¯è©ä¾¡çµæã®ç¢ºèªãå®æ½ãããã¨ãæ±ãããã¦ãã¾ããã¾ããç¬ç«è¡æ¿æ³äººè£½åè©ä¾¡æè¡åºç¤æ©æ§ï¼NITEï¼ã®è£½åè©ä¾¡æè¡åºç¤æ©æ§èªå®å¶åº¦ï¼ASNITEï¼ã®ä¸ã«ISO/IEC17025ã«åºã¥ãè©ä¾¡æ©é¢èªå®å¶åº¦ãè¨ããé©åãªè½åããã³ä½å¶ãæ´åããäºæ¥è
ãè©ä¾¡æ©é¢ã¨ãã¦èªå®ãããã¨ãæ¤è¨ããã¦ãã¾ãã
IoT製åé©åæ§è©ä¾¡å¶åº¦ã«ãããã©ãã«ã®ä»ä¸ã¯ãèªä¸»é©å宣è¨ã¨ç¬¬ä¸è
èªè¨¼ã®ããããIPAãè¡ãã¾ãã
æå¾ã«
æ¬ã³ã©ã ã¯ãæ¥æ¬ã¨EUã§å¶åº¦æºåãé²ãããã¦ããIoT製åããã³ãã¸ã¿ã«è£½åã®ã»ãã¥ãªãã£é©åè©ä¾¡å¶åº¦ã®å ±éç¹ãç¸éç¹ã«ã¤ãã¦æ¦è¦³ãã¦ãã¾ãããç¾å¨ã®ç¤¾ä¼ã»çµæ¸æ´»åã¯IoTãªãã«ã¯æãç«ã¡ã¾ããããã®ã»ãã¥ãªãã£å¯¾çãé²ããããã®ä¸å©ã«ãªãã°å¹¸ãã§ãã
åèæç®
- [1]IoT製åã«å¯¾ããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦æ§ç¯æ¹é
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/20240823.html - [2]IoT製åã«å¯¾ããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦æ§ç¯æ¹éï¼æ¬ç·¨ï¼
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240823_1.pdf - [3]å¥æ·» â1ã»ãã¥ãªãã£è¦ä»¶ã»é©ååºæº
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240823_2.pdf - [4]ç£æ¥ãµã¤ãã¼ã»ãã¥ãªãã£ç ç©¶ä¼ ã¯ã¼ãã³ã°ã°ã«ã¼ã3 IoT製åã«å¯¾ããã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦æ§ç¯ã«åããæ¤è¨ä¼ æçµã¨ãã¾ã¨ã
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/20240315_report.html - [5]IoT 製åã«å¯¾ãã ã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦ æ§ç¯ã«åããæ¤è¨ä¼ æçµã¨ãã¾ã¨ã
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240315_1.pdf - [6]ãå¥æ·»1ãã»ãã¥ãªãã£è¦ä»¶ä¸è¦§
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240315_2.pdf - [7]ãå¥æ·»2ãâ1ã»ãã¥ãªãã£è¦ä»¶ã»é©ååºæº
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240315_3.pdf - [8]IoT製åã®ã»ãã¥ãªãã£é©åæ§è©ä¾¡å¶åº¦â1ãã§ãã¯ãªã¹ãï¼æ¡ï¼
https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/wg_cybersecurity/iot_security/pdf/20240315_4.pdf - [9]Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-34e9-11ed-9c68-01aa75ed71a1.0001.02/DOC_1&format=PDF - [10]ANNEXES to the PROPOSAL FOR A REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUCIL on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-34e9-11ed-9c68-01aa75ed71a1.0001.02/DOC_2&format=PDF - [11]Cyber Resilience Act
European Parliament legislative resolution of 12 March 2024 on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 (COM(2022)0454 â C9-0308/2022 â 2022/0272(COD))
https://www.europarl.europa.eu/doceo/document/TA-9-2024-0130_EN.pdf - [12]Cybersecurity Act
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32019R0881 - [13]COMMISSION IMPLEMENTING REGULATION (EU) â¦/... of 31.1.2024 laying down rules for the application of Regulation (EU) 2019/881 of the European Parliament and of the Council as regards the adoption of the European Common
Criteria-based cybersecurity certification scheme (EUCC)
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202400482
- â»æä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã