---
type: guideline
title: セキュリティ統制のカタログ化の例
source: デジタル庁
ds_code: ds-231
category: security
updated: 2023-03-31
source_url: https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/8089144a/20230411_resources_standard_guidelines_guideline_08.zip
---

# セキュリティ統制のカタログ化の例

本章では、セキュリティ統制のカタログ化のステップとしてセキュリティ管理策のカタログの例とその機械可読化の例を示す。具体的にはISMAP及びNIST SP800-53の管理策のカタログ並びに機械可読化の取組みであるNIST OSCALについて紹介する。

## ISMAP管理基準の例

政府情報システムのためのセキュリティ評価制度（ISMAP）管理基準（以下、「ISMAP管理基準」。）は、クラウドサービス事業者がISMAPクラウドサービスリスト若しくはISMAP-LIUクラウドサービスリストへの登録申請を行う上で実施すべきセキュリティ対策の一覧、及びその活用方法を示すことを目的としており、ISMAPの情報セキュリティ監査基準等に従って監査を行う場合、原則として監査人が監査の前提として用いる基準となっている。

ISMAP管理基準は、国際規格に基づいた規格（JIS Q 27001:2014、JIS Q 27002:2014、JIS Q 27017:2016）に準拠して編成された「クラウド情報セキュリティ管理基準(平成28年度版)」を基礎としつつ、「政府機関等の情報セキュリティ対策のための統一基準群（平成30年度版」）、及び「SP800-53 rev.4」を参照して作成されている。

1.  情報、情報に関連するその他の資産及び情報処理施設を特定する。また、これらの資産の目録を、作成し、維持する。

2.  目録の中で維持される資産は、管理する。

3.  情報の利用の許容範囲、並びに情報及び情報処理施設と関連する資産の利用の許容範囲に関する規則は、明確にし、文書化し、実施する。

4.  全ての従業員及び外部の利用者は、雇用、契約又は合意の終了時に、自らが所持する組織の資産の全てを返却する。

5.  P クラウドサービス事業者の領域上にあるクラウドサービス利用者の資産は、クラウドサービス利用の合意の終了時に、時期を失せずに返却または除去する。

ISMAP管理基準において、クラウドサービス事業者が、リスクに対応するために達成するべき統制目標を、管理基準のうち（X.X.X）という３桁の番号で表現している。以下に、ISMAP管理基準における統制目標の例を記載する。

## NIST SP800-53のセキュリティ管理策のカタログについて

NIST SP800-53（組織と情報システムのためのセキュリティおよびプライバシー管理策）(以下、「SP800-53」という。) は、米国連邦政府の内部セキュリティ基準を示すガイドラインの一つである。セキュリティポリシーの構成要素は、20のセキュリティ管理策ファミリーで、322のセキュリティ管理策から構成されている。またセキュリティ管理策の一部は、拡張管理策で構成されている。SP800-53におけるセキュリティ管理策の一例を[表 3](#_Ref127898689)に記載し、セキュリティ管理策一覧について別紙１に示す。

<table>
<caption><p>表 3　SP800-53 管理策の例：「識別および認証」ファミリー</p></caption>
<colgroup>
<col style="width: 20%" />
<col style="width: 79%" />
</colgroup>
<thead>
<tr>
<th style="text-align: center;">管理策番号</th>
<th style="text-align: center;">管理策名</th>
</tr>
</thead>
<tbody>
<tr>
<td><blockquote>
<p>IA-1</p>
</blockquote></td>
<td>ポリシーおよび手順</td>
</tr>
<tr>
<td><blockquote>
<p>IA-2</p>
</blockquote></td>
<td>識別および認証（組織のユーザー）</td>
</tr>
<tr>
<td><blockquote>
<p>IA-3</p>
</blockquote></td>
<td>デバイスの識別および認証</td>
</tr>
<tr>
<td><blockquote>
<p>IA-4</p>
</blockquote></td>
<td>識別子管理</td>
</tr>
<tr>
<td><blockquote>
<p>IA-5</p>
</blockquote></td>
<td>オーセンティケータ管理</td>
</tr>
<tr>
<td><blockquote>
<p>IA-6</p>
</blockquote></td>
<td>認証フィードバック</td>
</tr>
<tr>
<td><blockquote>
<p>IA-7</p>
</blockquote></td>
<td>暗号モジュール認証</td>
</tr>
<tr>
<td><blockquote>
<p>IA-8</p>
</blockquote></td>
<td>識別および認証（非組織のユーザー）</td>
</tr>
<tr>
<td><blockquote>
<p>IA-9</p>
</blockquote></td>
<td>サービスの識別および認証</td>
</tr>
<tr>
<td><blockquote>
<p>IA-10</p>
</blockquote></td>
<td>リスクベース認証</td>
</tr>
<tr>
<td><blockquote>
<p>IA-11</p>
</blockquote></td>
<td>再認証</td>
</tr>
<tr>
<td><blockquote>
<p>IA-12</p>
</blockquote></td>
<td>アイデンティティ証明</td>
</tr>
</tbody>
</table>

これらの構成要素であるセキュリティ管理策は、NIST SP800-53B（組織と情報システムのための管理策ベースライン）において、インパクトが「低」「中」「高」に対応した各セキュリティ管理策ベースラインで引用されている。インパクトが「低」の場合には、全ての管理策の中から131のセキュリティ管理策の実装を求めている。また「中」の場合には、177管理策と一部の110の拡張管理策の実装を求めている。「高」の場合には、「中」で求めた管理策と拡張管理策に加え、83の管理策・拡張管理策の実装を求めている。

## コラム：NIST OSCALでの機械可読形式による表現ついて

<table style="width:99%;">
<colgroup>
<col style="width: 99%" />
</colgroup>
<thead>
<tr>
<th><p>情報セキュリティ責任者は、情報セキュリティとプライバシーのリスクに対処するために、選択した統制（コントロール）の実装を検証し、効果的であることを示す必要がある。また、システムのセキュリティとプライバシーの姿勢を保証するために、システムの制御実装を正しく記述、評価、および承認する必要がある。これらのタスクはリソースを大量に消費し、問題の複雑さを考えると、予算の制約内で実行するのが困難になりがちである。</p>
<p>NIST OSCAL（Open Security Controls Assessment Language）は、セキュリティ対策を定義し、定義に基づいて評価するための標準化されたデータ中心の評価フレームワークである。情報セキュリティ責任者、ベンダー、および監査人などセキュリティ統制業務に携わる関係者の事務処理を減らすため、正確で機械可読な形式を使用して、セキュリティ制御カタログ、規制フレームワーク、およびシステム情報の表現を正規化し、組織間での制御実装情報の共有を可能にしている。また、システムセキュリティ評価の効率、適時性、正確性、および一貫性を向上させるため、複数の要件セットに対してシステムのセキュリティ制御の実装を同時に評価し、要件間のトレーサビリティを確保すると同時に、情報システム環境に関係なく、一貫した評価実行を可能としている。そして、システムのセキュリティ状態をより頻繁に、理想的には継続的に評価できるようにし、継続的な保証を推進するため、評価関連の労力を大幅に削減し、評価と承認の時間を短縮し、継続的な監視機能を使用して収集されたデータに基づいて、制御の実装の有効性の評価をサポートすることを目標として、開発・更新がなされている。</p>
<p>表記形式はJSON、XML、YAMLといったマークアップ言語が採用されており、各形式間での相互運用性、拡張性、機械可読形式を基本として記述されている。以下に機械可読形式での例を示す。NIST SP800-53 rev.5について、OSCALを用いて表したYAML形式によるサンプルを、以下の<a href="#_Ref126069919">図 4</a>～<a href="#_Ref126069929">図 7</a>に示す。</p></th>
</tr>
</thead>
<tbody>
</tbody>
</table>

catalog:

uuid: 2486041e-ea2a-48ad-ab1b-218f74aaeceb

metadata:

title: NIST Special Publication 800-53 Revision 5 HIGH IMPACT BASELINE

last-modified: 2022-11-02T14:21:44.749362Z

version: Final

oscal-version: 1.0.0

links:

\- href: NIST_SP-800-53_rev5_HIGH-baseline_profile.yaml

rel: resolution-source

roles:

\- id: creator

title: Document Creator

\- id: contact

title: Contact

parties:

\- uuid: c748c806-1d77-4695-bb40-e117b2afa82e

type: organization

name: Joint Task Force, Transformation Initiative

email-addresses:

\- sec-cert@nist.gov

addresses:

\- addr-lines:

\- National Institute of Standards and Technology

\- "Attn: Computer Security Division"

\- Information Technology Laboratory

\- 100 Bureau Drive (Mail Stop 8930)

city: Gaithersburg

state: MD

postal-code: 20899-8930

responsible-parties:

\- role-id: creator

party-uuids:

\- c748c806-1d77-4695-bb40-e117b2afa82e

\- role-id: contact

party-uuids:

\- c748c806-1d77-4695-bb40-e117b2afa82e

図 4　カタログ冒頭部分

groups:

\- id: ia

class: family

title: Identification and Authentication

controls:

（中略）

\- id: ia-3

class: SP800-53

title: Device Identification and Authentication

params:

\- id: ia-03_odp.01

label: devices and/or types of devices

guidelines:

\- prose: devices and/or types of devices to be uniquely identified

and authenticated before establishing a connection are defined;

\- id: ia-03_odp.02

select:

how-many: one-or-more

choice:

\- local

\- remote

\- network

props:

\- name: label

value: IA-3

\- name: label

value: IA-03

class: sp800-53a

\- name: sort-id

value: ia-03

links:

\- href: "#ac-17"

rel: related

\- href: "#ac-18"

rel: related

\- href: "#ac-19"

rel: related

\- href: "#au-6"

rel: related

\- href: "#ca-3"

rel: related

\- href: "#ca-9"

rel: related

\- href: "#ia-4"

rel: related

\- href: "#ia-5"

rel: related

\- href: "#ia-9"

rel: related

\- href: "#ia-11"

rel: related

\- href: "#si-4"

rel: related

（その２へ続く）

図 5　識別および認証に関する部分（その１）

parts:

\- id: ia-3_smt

name: statement

prose: "Uniquely identify and authenticate {{ insert: param, ia-03_odp.01\

\\ }} before establishing a {{ insert: param, ia-03_odp.02 }} connection."

\- id: ia-3_gdn

name: guidance

prose: Devices that require unique device-to-device identification and

authentication are defined by type, device, or a combination of type

and device. Organization-defined device types include devices that

are not owned by the organization. Systems use shared known information

(e.g., Media Access Control \[MAC\], Transmission Control Protocol/Internet

Protocol \[TCP/IP\] addresses) for device identification or organizational

authentication solutions (e.g., Institute of Electrical and Electronics

Engineers (IEEE) 802.1x and Extensible Authentication Protocol \[EAP\],

RADIUS server with EAP-Transport Layer Security \[TLS\] authentication,

Kerberos) to identify and authenticate devices on local and wide area

networks. Organizations determine the required strength of authentication

mechanisms based on the security categories of systems and mission

or business requirements. Because of the challenges of implementing

device authentication on a large scale, organizations can restrict

the application of the control to a limited number/type of devices

based on mission or business needs.

\- id: ia-3_obj

name: assessment-objective

props:

\- name: label

value: IA-03

class: sp800-53a

prose: " {{ insert: param, ia-03_odp.01 }} are uniquely identified and\

\\ authenticated before establishing a {{ insert: param, ia-03_odp.02\

\\ }} connection."

\- id: ia-3_asm-examine

name: assessment-method

props:

\- name: method

ns: http://csrc.nist.gov/ns/rmf

value: EXAMINE

\- name: label

value: IA-03-Examine

class: sp800-53a

\- id: ia-3_asm-examine

name: assessment-method

props:

\- name: method

ns: http://csrc.nist.gov/ns/rmf

value: EXAMINE

\- name: label

value: IA-03-Examine

class: sp800-53a

parts:

\- name: assessment-objects

prose: \>-

Identification and authentication policy

system security plan

procedures addressing device identification and authentication

system design documentation

list of devices requiring unique identification and authentication

device connection reports

system configuration settings and associated documentation

other relevant documents or records

（その３へ続く）

図 6 識別および認証に関する部分（その２）

\- id: ia-3_asm-interview

name: assessment-method

props:

\- name: method

ns: http://csrc.nist.gov/ns/rmf

value: INTERVIEW

\- name: label

value: IA-03-Interview

class: sp800-53a

parts:

\- name: assessment-objects

prose: \>-

Organizational personnel with operational responsibilities

for device identification and authentication

organizational personnel with information security responsibilities

system/network administrators

system developers

\- id: ia-3_asm-test

name: assessment-method

props:

\- name: method

ns: http://csrc.nist.gov/ns/rmf

value: TEST

\- name: label

value: IA-03-Test

class: sp800-53a

parts:

\- name: assessment-objects

prose: Mechanisms supporting and/or implementing device identification

and authentication capabilities

図 7 識別および認証に関する部分（その３）
