コンテンツにスキップ

NIST SP 1800-41 Draft ― OTでは「防ぐ」だけでなくResponse / Recoveryを設計する

Executive Summary

NIST NCCoEは2026年5月21日、製造業のICS / OT環境におけるCyber IncidentへのResponseとRecoveryを扱うSP 1800-41 Initial Public Draftを公開しました。11のIndustry CollaboratorとReference ArchitectureやAttack Scenarioを構築し、Cyber Attack後にOperationsを安全に復旧するための実践的な方法を示しています。1

重要なのは、Defense-in-depthでもCyber Riskをゼロにはできないと明示し、「侵入を防ぐ」Controlと同じレベルで、Response・Restore・Operational Recoveryを設計することです。

なぜ今なのか

OT / ICSではSystem停止がProduction、Safety、Quality、Supply Chainへ直接影響します。一方、Patchや復旧をITと同じ手順で行えない設備も多くあります。

そのためIncident Response Planは、Forensicsだけでなく「どの順で設備を戻すか」「安全確認をどう行うか」「代替運転が可能か」を含む必要があります。

実務上の論点

  • Cyber IncidentがPhysical Processへ与えるImpactの把握
  • IT / OT間のIncident Coordination
  • Known-good Configuration / Backupの確保
  • Restoration順序とDependencyの把握
  • Recovery時のSafety Validation
  • Vendor / Integratorを含むResponse Exercise

経営インパクト

観点 影響
Production Recovery時間が直接売上・Supply Chainへ影響
Safety 復旧を急ぐこと自体がPhysical Safety Riskになり得る
Vendor Equipment Vendor / Integratorの支援可否がRecoveryを左右
BCP IT Disaster RecoveryだけではOT復旧をカバーできない

日本企業への示唆

製造現場のBackupを「取っている」だけで安心せず、実際にPLC / HMI / Engineering Station / Historian等をどの順序で戻せるかを確認する必要があります。Cyber Exerciseへ工場運用・設備保全・Safety担当を含めることが重要です。

推奨アクション

  1. Critical OT AssetとDependencyを可視化する
  2. Known-good Backup / ConfigurationのRestore Testを行う
  3. IT / OT共同Incident Response Planを作る
  4. Recovery順序とSafety Checkpointを定義する
  5. Vendor / Integratorを含めた復旧Exerciseを実施する
  6. RTOだけでなくManual Operation / Production Lossも評価する

用語解説

Operational Resilience
Cyber Incidentや障害が起きても、重要なBusiness / Physical Operationを継続または許容時間内に復旧できる能力。

関連記事

参考情報