---
type: guideline
title: 参考文献
source: デジタル庁
ds_code: ds-202
category: security
updated: 2024-03-29
source_url: https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/b94907ca/20240329_resources_standard_guidelines_guideline.zip
---

# 参考文献

<table>
<colgroup>
<col style="width: 8%" />
<col style="width: 91%" />
</colgroup>
<thead>
<tr>
<th>[1]</th>
<th style="text-align: left;"><p>Department of Defense, "DoD Enterprise DevSecOps Reference Design,":</p>
<p><a href="https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf">https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf</a></p></th>
</tr>
</thead>
<tbody>
<tr>
<td>[2]</td>
<td style="text-align: left;"><p>JFrog, “What is a Software Artifact?,” JFrog:</p>
<p><a href="https://jfrog.com/devops-tools/article/what-is-a-software-artifact/">https://jfrog.com/devops-tools/article/what-is-a-software-artifact/</a></p></td>
</tr>
<tr>
<td>[3]</td>
<td style="text-align: left;"><p>Red Hat Software, “What is CI/CD?,”:</p>
<p><a href="https://www.redhat.com/en/topics/devops/what-is-ci-cd">https://www.redhat.com/en/topics/devops/what-is-ci-cd</a></p></td>
</tr>
<tr>
<td>[4]</td>
<td style="text-align: left;"><p>デジタル庁デジタル社会推進会議幹事会, “政府情報システムにおけるクラウドサービスの適切な利用に係る基本方針,”:</p>
<p><a href="https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/17ef852e/20221228_resources_standard_guidelines_guideline_01.pdf">https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/17ef852e/20221228_resources_standard_guidelines_guideline_01.pdf</a></p></td>
</tr>
<tr>
<td>[5]</td>
<td style="text-align: left;"><p>内閣サイバーセキュリティセンター, “政府機関等のサイバーセキュリティ対策のための統一基準群,”:</p>
<p><a href="https://www.nisc.go.jp/policy/group/general/kijun.html">https://www.nisc.go.jp/policy/group/general/kijun.html</a></p></td>
</tr>
<tr>
<td>[6]</td>
<td style="text-align: left;"><p>MDN Web Docs, “MDN Web Docs 用語集: ウェブ関連用語の定義,”:</p>
<p><a href="https://developer.mozilla.org/ja/docs/Glossary/SVN">https://developer.mozilla.org/ja/docs/Glossary/SVN</a></p></td>
</tr>
<tr>
<td>[7]</td>
<td style="text-align: left;">Trevor Rosen, SolarWinds, <em>Keynote: Project Trebuchet: How SolarWinds is Using Open Source to Secure Their Supply Chain,</em> KubeCon + CloudNative Con Europe 2022: <a href="https://www.youtube.com/watch?v=1-tMRxqMwTQ">https://www.youtube.com/watch?v=1-tMRxqMwTQ</a></td>
</tr>
<tr>
<td>[8]</td>
<td style="text-align: left;"><p>K. Zetter, “The Untold Story of the Boldest Supply-Chain Hack Ever,”:</p>
<p><a href="https://www.wired.com/story/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever/">https://www.wired.com/story/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever/</a></p></td>
</tr>
<tr>
<td>[9]</td>
<td style="text-align: left;"><p>“ゼロトラストアーキテクチャ適用方針,”:</p>
<p><a href="https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/5efa5c3b/20220630_resources_standard_guidelines_guidelines_04.pdf">https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/5efa5c3b/20220630_resources_standard_guidelines_guidelines_04.pdf</a></p></td>
</tr>
<tr>
<td>[10]</td>
<td style="text-align: left;"><p>GitHub, “GitHub glossary,” GitHub,:</p>
<p><a href="https://docs.github.com/en/get-started/learning-about-github/github-glossary">https://docs.github.com/en/get-started/learning-about-github/github-glossary</a></p></td>
</tr>
<tr>
<td>[11]</td>
<td style="text-align: left;"><p>GitHub, Inc., “About authentication with SAML single sign-on,”:</p>
<p><a href="https://docs.github.com/en/enterprise-cloud@latest/authentication/authenticating-with-saml-single-sign-on/">https://docs.github.com/en/enterprise-cloud@latest/authentication/authenticating-with-saml-single-sign-on/</a></p></td>
</tr>
<tr>
<td>[12]</td>
<td style="text-align: left;"><p>National Security Agency, Cybersecurity and Infrastructure Security Agency, “Defending Continuous Integration/Continuous Delivery (CI/CD) Environments,”</p>
<p><a href="https://media.defense.gov/2023/Jun/28/2003249466/-1/-1/0/CSI_DEFENDING_CI_CD_ENVIRONMENTS.PDF">https://media.defense.gov/2023/Jun/28/2003249466/-1/-1/0/CSI_DEFENDING_CI_CD_ENVIRONMENTS.PDF</a></p></td>
</tr>
<tr>
<td>[13]</td>
<td style="text-align: left;"><p>National Institute of Standards and Technology, “NIST SP800-204D Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines,”:</p>
<p><a href="https://csrc.nist.gov/pubs/sp/800/204/d/final">https://csrc.nist.gov/pubs/sp/800/204/d/final</a></p></td>
</tr>
<tr>
<td>[14]</td>
<td style="text-align: left;"><p>Cybersecurity and Infrastructure Security Agency, “Securing The Software Supply Chain: Recommended Practices Guide for Developers,”:</p>
<p><a href="https://www.cisa.gov/sites/default/files/publications/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDF">https://www.cisa.gov/sites/default/files/publications/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDF</a></p></td>
</tr>
<tr>
<td>[15]</td>
<td style="text-align: left;"><p>SLSA, “Safeguarding artifact integrity across any software supply chain,”:</p>
<p><a href="https://slsa.dev/">https://slsa.dev/</a></p></td>
</tr>
<tr>
<td>[16]</td>
<td style="text-align: left;"><p>Cider Security Ltd., “Top 10 CI/CD Security Risks,”:</p>
<p><a href="https://www.cidersecurity.io/top-10-cicd-security-risks/">https://www.cidersecurity.io/top-10-cicd-security-risks/</a></p></td>
</tr>
<tr>
<td>[17]</td>
<td style="text-align: left;"><p>経済産業省 商務情報政策局　サイバーセキュリティ課, “OSS の利活⽤及びそのセキュリティ確保に向けた 管理⼿法に関する事例集,”</p>
<p><a href="https://www.meti.go.jp/policy/netsecurity/wg1/ossjirei_20220801.pdf">https://www.meti.go.jp/policy/netsecurity/wg1/ossjirei_20220801.pdf</a></p></td>
</tr>
</tbody>
</table>

[^1]: 尚、スマートフォンのアプリケーションの場合は、アプリ配信基盤へのアップロードとなる。アプリは利用者の手元の端末で実行される。

[^2]: ホスティングする環境については、オンプレミス、IaaS、PaaSなど様々な形態が考えられる

[^3]: 「ソースコードが⼀般に公開され、商⽤か⾮商⽤かを問わずソースコードの利⽤・修正・再配布が 可能」 \[18\]なソフトウェアを指す。

[^4]: GitHub、GitLab、BitBucket

[^5]: 従来端末などを必要としていた、コードを編集する環境そのものをWebブラウザ経由で提供するサービスも登場しつつある。

[^6]: 検知も重要である。本技術レポートでは、「３.３　ビルドフェーズの保護」にて言及している。

[^7]: SASTやDASTといったアプリケーションを一般的に対象とするスキャナに加え、IaCに対するスキャナも指している

[^8]: TyposquattingやDependency Confusionといった攻撃手法である

[^9]: ソフトウェア構成分析（SCA）、Software Bill of Material（SBOM）などが対象である
