Êƹñ¹ñËɾʤ¬¿ä¿Ê¤¹¤ëCMMC2.0¤Ë½àµò¡ªJaSRO¡ßKompleye¡Ö¾ðÊ󥻥¥å¥ê¥Æ¥£Âкö¤Î»Ù±ç¥µ¡¼¥Ó¥¹¡×
°ìÈ̼ÒÃÄË¡¿ÍÆüËÜ¥»¥¥å¥ê¥Æ¥£³ÊÉÕµ¡¹½(ά¾Î¡§JaSRO)¤Ï¡¢Kompleye¤È¶È̳Äó·È¤·¡¢CMMC2.0¤Ë½àµò¤·¤¿¾ðÊ󥻥¥å¥ê¥Æ¥£Âкö¤Î»Ù±ç¥µ¡¼¥Ó¥¹¤ò2023ǯ11·î¤«¤é³«»Ï¤·¤Þ¤¹¡£
JaSRO ¾ðÊ󥻥¥å¥ê¥Æ¥£Âкö¤Î»Ù±ç¥µ¡¼¥Ó¥¹
Êƹñ¹ñËÉÁí¾Ê(Department of Defense)¤Ï¡¢¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤ÎÀ®½ÏÅÙ¥â¥Ç¥ëǧÄê(Cybersecurity Maturity Model Certification¡¢°Ê²¼¡¢CMMC)¤òÍѤ¤¤¿Ä´Ã£¤ò·×²è¤·¤Æ¤ª¤ê¡¢¤½¤Î´ð½à¤È¤Ê¤ëCMMC¤ÎÂè2ÈÇ(°Ê²¼¡¢CMMC2.0)¤¬2021ǯ12·î¤Ëȯɽ¤µ¤ì¤Þ¤·¤¿¡£
CMMC2.0¤Ï´ÉÍýºö¤ÎÃæ³Ë¤È¤·¤Æ´û¸¤ÎÊƹñ´ð½à(NIST SP800-171)¤òÍѤ¤¤Æ¤¤¤Þ¤¹¡£
ÆüËÜ´ë¶È¤«¤é¤ÎËɱÒÉʤÎĴã¤âÂоݤȤʤäƤª¤ê¡¢ËܳÊŪ¤Ë´ð½à¤ÎŬÍѳ«»Ï¤¬¸«¹þ¤Þ¤ì¤Æ¤¤¤ë2025ǯ¤òÌÜÅӤˡ¢ÆüËÜ´ë¶È¤âĴã¤Ëµá¤á¤é¤ì¤ë¥»¥¥å¥ê¥Æ¥£¿å½à¤Ë±þ¤¸¤Æ¼«¸Êǧ¾Ú¤äÂè»°¼Ôǧ¾Ú¤ò¹Ô¤¦É¬ÍפËÇ÷¤é¤ì¤Æ¤¤¤Þ¤¹¡£
¤½¤³¤Ç¡¢JaSRO¤ÏNIST SP800-171¤òÍѤ¤¤¿¾ðÊ󥻥¥å¥ê¥Æ¥£³ÊÉÕ¤±¤Î¼ÂÀӵڤӥΥ¦¥Ï¥¦¤òÍѤ¤¤ÆCMMC2.0¤Ø¤ÎÂбþ¤Î»Ù±ç¤ò³«»Ï¤·¤Þ¤¹¡£
¤µ¤é¤Ë¡¢Êƹñ¤Î´Æººµ¡´Ø¤Ç¤¢¤ëKompleye¤È¶È̳Äó·È¤·¡¢½¼¼Â¤·¤¿»Ù±çÂÎÀ©¤Ç¥µ¡¼¥Ó¥¹¤òÄ󶡤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ê¤Þ¤·¤¿¡£
Kompleye¤Ï¡¢CMMC¤ÎC3PAO(¸øǧÂè»°¼Ô¿³ººµ¡´Ø)¤È¤·¤Æ¤Î¸ø¼°Ç§Äê¤ò¼õ¤±¤Æ¤ª¤ê¡¢CMMC-AB(Cybersecurity Maturity Model Certification Accreditation Body)¤ÈÀѶËŪ¤Ë¶¨ÎϤ·CMMC2.0¤ÎÉáµÚ¡¢¿ä¿Ê¤Ë¿ÔÎϤ·¤Æ¤¤¤Þ¤¹¡£
¥µ¡¼¥Ó¥¹ÆâÍÆ
JaSRO¤Ï¡¢ÆüËÜ´ë¶È¤ÎCMMC½àÈ÷¤ò±ß³ê¤Ë¿Ê¤á¤ë¤¿¤á¤Î»Ù±ç¤ËÅؤᡢCMMC¤ÎÂè»°¼Ôǧ¾Ú¤ÏCMMC¤Î¸øǧC3PAO¤Ç¤¢¤ëKompleye¤¬¹Ô¤¦Í½Äê¤Ç¤¹¡£
²¼µ¤Î¡Ö¥µ¡¼¥Ó¥¹ÆâÍÆ¡×Åù¤è¤ê´õ˾¤Î¥µ¡¼¥Ó¥¹¤ò»ØÄꤷ¡¢¤ªµÒÍͤ¬Êú¤¨¤ë²ÝÂê¤Ë¹Ê¤ê¹þ¤ßÌäÂê¤Î²ò·è¤òŬÀڤ˸úΨ¤è¤¯¹Ô¤¦¤³¤È¤Ç¡¢CMMC¤ÎÂè»°¼Ôǧ¾Ú¤Î¼èÆÀÅù¤ò»Ù±ç¤·¤Þ¤¹¡£
¤Þ¤¿¡¢CMMC2.0¤Ç¤Ï¼è¤ê°·¤¦¾ðÊó¤Î¥ì¥Ù¥ë¤Ë¤è¤Ã¤Æɾ²ÁÊýË¡¤¬Äê¤á¤é¤ì¤Æ¤ª¤ê¡¢¥ì¥Ù¥ë1(Federal Contract Information¤ËÂбþ)¤Ç¤Ï¼«¸Êǧ¾Ú¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£
¥ì¥Ù¥ë2(Controlled Unclassified Information¤ËÂбþ)¤Ï¼è¤ê°·¤¦¾ðÊó¤Î¼ïÎà¤Ë¤è¤Ã¤Æ¡¢¼«¸Êǧ¾Ú¤â¤·¤¯¤ÏÂè»°¼Ôµ¡´Ø¤¬Ç§¾Ú¤ò¹Ô¤¦¤³¤È¤È¤Ê¤ê¤Þ¤·¤¿¡£
¤µ¤é¤Ë¡¢Í¥ÀèÅÙ¤ÎÄ㤤°ìÉô¤Î´ÉÍýºö¤Ë¤ª¤¤¤Æ¤Ï¹ÔÆ°·×²è¤È¥Þ¥¤¥ë¥¹¥È¥ó(POA¡õM¡§Plan of Action & Milestones ¤Îά¾Î)¤ÎÍøÍѤ¬Ç§¤á¤é¤ì¤Þ¤·¤¿¡£
»ö¶È¼Ô¤¬CMMC2.0¤Î°ìÉô¤ÎÍ×µá¤ËÂФ·¡¢180Æü°ÊÆâ¤ËÂкö¤ò¹Ö¤¸¤ëPOA¡õM¤òºîÀ®¤·¤ÆÂбþ¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ë¸«Ä̤·¤Ç¤¹¡£
JaSRO¤Ï°Ê¾å¤ÎCMMC¤ÎÍ×µá»ö¹à¤òƧ¤Þ¤¨¡¢Kompleye¤¬³«È¯¤·¤¿CMMC2.0¤Ë½àµò¤·¤¿¥ì¥Ù¥ë1¤ª¤è¤Ó¥ì¥Ù¥ë2¤Î¼«¸Êɾ²Á¥Ä¡¼¥ë(̵½þ)¤ò³èÍѤ·¡¢¼«¸Êǧ¾ÚµÚ¤ÓÂè»°¼Ôǧ¾Ú¤Ë´Ø¤¹¤ë¸ú²ÌŪ¤ÊCMMC¤Ø¤ÎÂбþ½àÈ÷¤Î»Ù±ç¤ò¹Ô¤¦Í½Äê¤Ç¤¹¡£
¥µ¡¼¥Ó¥¹ÆâÍÆ(ÂåɽÎã)
(1) CMMC¼«¸Êǧ¾Ú¤ÎÂкö»Ù±ç(¥ì¥Ù¥ë1¡¢¥ì¥Ù¥ë2¤Î°ìÉô¤¬ÂоÝ,*1)
(2) CMMCÂè»°¼Ôǧ¾Ú¤ÎÂкö»Ù±ç(¥ì¥Ù¥ë2¤Î°ìÉô¤¬ÂоÝ,*1)
(3) POA¡õM(¹ÔÆ°·×²è¤È¥Þ¥¤¥ë¥¹¥È¥ó)¤ÎºîÀ®»Ù±ç
(4) CMMCƳÆþ¤Ë¸þ¤±¤¿¥Þ¥Ë¥å¥¢¥ëÎà¤Î²þÄê»Ù±ç
(5) CMMCƳÆþ¤Ë¸þ¤±¤¿ÆâÉô´Æºº¤Î»Ù±ç(´Æºº½àÈ÷¡¢´Æºº¼Â»ÜµÚ¤ÓÊó¹ð)
(6) CMMCƳÆþ¤Ë¸þ¤±¤¿¥Þ¥Í¥¸¥á¥ó¥È¥ì¥Ó¥å¡¼¤Î¼Â»Ü»Ù±ç
(7) CMMCÂè»°¼Ôǧ¾Ú¤Ë¤ª¤±¤ë¿³ººÇæÀÊ(ÇæÀʤΤ¦¤¨¡¢µÏ¿µÚ¤Ó¥¢¥É¥Ð¥¤¥¹¼Â»Ü)
(8) CMMCÂè»°¼Ôǧ¾Ú¤Î¤ª¤±¤ë»ØŦ»ö¹àÂбþ»Ù±ç(¿³ºº´°Î»¤Þ¤Ç¤Î¥Õ¥©¥í¡¼¥¢¥Ã¥×µÚ¤Ó»ØŦ»ö¹àÂбþ)
(9) ¤ªµÒÍͤγ°Éô°ÑÂ÷ÀèÅù¤ÎÂбþ»Ù±ç(Ä´ºº¡¢¥¢¥ó¥±¡¼¥ÈÂбþ¡¢CMMCÂбþ»Ù±çÅù)
¾åµ*1¤Ï¡¢Kompleye¤¬Ä󶡤¹¤ë¼«¸Êɾ²Á¥Ä¡¼¥ë¤ò³èÍѤ¹¤ëͽÄê¤Ç¤¹¡£
¥µ¡¼¥Ó¥¹²Á³Ê
(1) ¾åµ¡Ú¥µ¡¼¥Ó¥¹ÆâÍÆ(ÂåɽÎã)¡Û¤è¤ê¥µ¡¼¥Ó¥¹ÆâÍƤò»ØÄꤷ¤Æ²¼¤µ¤¤¡£
¸ÄÊ̤˸渫ÀѤòºîÀ®¤·¤Þ¤¹¡£
¤½¤Î¾´ØÏ¢¥µ¡¼¥Ó¥¹
JaSRO¤ÏÊƹñ´ð½à(NIST SP800-171)¤Î¾ðÊ󥻥¥å¥ê¥Æ¥£³ÊÉÕ¤±¤äÀ¯ÉܾðÊó¥·¥¹¥Æ¥à¤Î¤¿¤á¤Î¥»¥¥å¥ê¥Æ¥£É¾²ÁÀ©ÅÙ(ISMAP)¤Î»Ù±ç¥µ¡¼¥Ó¥¹¤âÄ󶡤·¤Æ¤¤¤Þ¤¹¡£
CMMC¤ËÂбþ¤¹¤ëºÝ¤Ë¡¢¤½¤ì¤é¤ÎÍ×·ï¤ÈÀ°¹çŪ¤ÊÂкö¤ò¹Ö¤¸¤ë¤³¤È¤òÍ×˾¤Î¾ì¹ç¤Ï¤½¤Î»Ý¤ò¤ªÃΤ餻¤¯¤À¤µ¤¤¡£
Í×˾¤Ë±þ¤¸¤¿Âбþ¤¬²Äǽ¤È¤Ê¤ë»Ù±ç¥Á¡¼¥à¤òÊÔÀ®¤·¤Þ¤¹¡£
(»²¹Í¥µ¡¼¥Ó¥¹»öÎã)
¡üÊƹñ´ð½à(NIST SP800-171/172 Åù)¤Î¾ðÊ󥻥¥å¥ê¥Æ¥£³ÊÉÕ¤±»öÎã
http://jasro.org/news/pdf/JaSRO_NewsRelease_20221228.pdf
https://www.nikkei.com/article/DGXZRSP646952_Y2A221C2000000/
¡üÀ¯ÉܾðÊó¥·¥¹¥Æ¥à¤Î¤¿¤á¤Î¥»¥¥å¥ê¥Æ¥£É¾²ÁÀ©ÅÙ(ISMAP)¤Ø¤ÎÅÐÏ¿»Ù±ç
http://jasro.org/news/pdf/JaSRO_NewsRelease_20221026.pdf
Äó·ÈÀè¤Î¾Ò²ð
¡üKompleye Attestation LLC¤ÎCMMC¤Ë´Ø¤¹¤ë¥µ¡¼¥Ó¥¹ÆâÍƤϼ¡¤Î¥ê¥ó¥¯¤ò»²¾È¤¯¤À¤µ¤¤¡£
https://www.kompleye.com/cmmc/
Kompleye¤Ï¡¢Cyber-AB(CMMC¤Î¸ø¼°Ç§Ä굡´Ø)¤è¤êC3PAO(¸øǧÂè»°¼Ô¿³ººµ¡´Ø)¤È¤·¤Æ¸ø¼°Ç§Äê¤ò¼õ¤±¤Æ¤¤¤Þ¤¹¡£
Ìä¹ç¤»Àè
¸ÄÊ̤ÎÌä¹ç¤»¤ÏWeb²ñµÄ¥·¥¹¥Æ¥àÅù¤Ë¤Æ¿ï»þ¹Ô¤¤¤Þ¤¹¡£
¤´´õ˾¤ÎÊý¤ÏE-mail¤Ë¤Æ¡¢
info@jasro.org
°¸¤ËÏ¢Íí¤·¤Æ¤¯¤À¤µ¤¤¡£
Ì䤤¹ç¤ï¤»Àè
°ìÈ̼ÒÃÄË¡¿ÍÆüËÜ¥»¥¥å¥ê¥Æ¥£³ÊÉÕµ¡¹½¡¡´ë²èÉô
JaSRO(Japan Security Rating Organization)
E-mail¡§
info@jasro.org
URL¡¡ ¡§
http://www.jasro.org/
¡»JaSRO¤Ï¡¢À¤³¦½é¤Î¾ðÊ󥻥¥å¥ê¥Æ¥£³ÊÉÕ¤ò¹Ô¤¦Âè»°¼Ôɾ²Áµ¡´Ø¤Ç¤¹¡£
¡»¾ðÊó´ÉÍý¤ÎÂкö¿å½à¤ò¡Ö³ÊÉաפdzΤ«¤á¹ç¤¦¼Ò²ñ¥·¥¹¥Æ¥àºî¤ê¤Ë¼è¤êÁȤó¤Ç¤¤¤Þ¤¹¡£
¡»À¯ÉܾðÊó¥·¥¹¥Æ¥à¤Î¤¿¤á¤Î¥»¥¥å¥ê¥Æ¥£É¾²ÁÀ©ÅÙ(ISMAP)Âбþ¤Î¹½Ãۻٱ硦ÆâÉô´Æºº»Ù±ç¤ò¹Ô¤Ã¤Æ¤¤¤Þ¤¹¡£
¡»À¯ÉÜ¥¬¥¤¥É¥é¥¤¥ó¡¢NIST SP800-171/172 Åù¤Ø¤ÎÂбþ¤Î¹½Ãۻٱ硦ÆâÉô´Æºº»Ù±ç¤ò¹Ô¤Ã¤Æ¤¤¤Þ¤¹¡£
¡»ISO/IEC27001(ISMS)¤Î²þÄûÅù¤Ëȼ¤¦¡¢µ¬³Ê°Ü¹Ô(ŬÍÑÀë¸À¡¢¥Þ¥Ë¥å¥¢¥ë¡¢¶µ°é¸¦½¤Åù)¤Î»Ù±ç¤ò¹Ô¤Ã¤Æ¤¤¤Þ¤¹¡£
Copyright © 2023 Dtimes All Rights Reserved.
The post Êƹñ¹ñËɾʤ¬¿ä¿Ê¤¹¤ëCMMC2.0¤Ë½àµò¡ªJaSRO¡ßKompleye¡Ö¾ðÊ󥻥¥å¥ê¥Æ¥£Âкö¤Î»Ù±ç¥µ¡¼¥Ó¥¹¡× appeared first on Dtimes.