NIST SP 1800-41 Draft ― OTでは「防ぐ」だけでなくResponse / Recoveryを設計する
Executive Summary
NIST NCCoEは2026年5月21日、製造業のICS / OT環境におけるCyber IncidentへのResponseとRecoveryを扱うSP 1800-41 Initial Public Draftを公開しました。11のIndustry CollaboratorとReference ArchitectureやAttack Scenarioを構築し、Cyber Attack後にOperationsを安全に復旧するための実践的な方法を示しています。1
重要なのは、Defense-in-depthでもCyber Riskをゼロにはできないと明示し、「侵入を防ぐ」Controlと同じレベルで、Response・Restore・Operational Recoveryを設計することです。
なぜ今なのか
OT / ICSではSystem停止がProduction、Safety、Quality、Supply Chainへ直接影響します。一方、Patchや復旧をITと同じ手順で行えない設備も多くあります。
そのためIncident Response Planは、Forensicsだけでなく「どの順で設備を戻すか」「安全確認をどう行うか」「代替運転が可能か」を含む必要があります。
実務上の論点
- Cyber IncidentがPhysical Processへ与えるImpactの把握
- IT / OT間のIncident Coordination
- Known-good Configuration / Backupの確保
- Restoration順序とDependencyの把握
- Recovery時のSafety Validation
- Vendor / Integratorを含むResponse Exercise
経営インパクト
| 観点 | 影響 |
|---|---|
| Production | Recovery時間が直接売上・Supply Chainへ影響 |
| Safety | 復旧を急ぐこと自体がPhysical Safety Riskになり得る |
| Vendor | Equipment Vendor / Integratorの支援可否がRecoveryを左右 |
| BCP | IT Disaster RecoveryだけではOT復旧をカバーできない |
日本企業への示唆
製造現場のBackupを「取っている」だけで安心せず、実際にPLC / HMI / Engineering Station / Historian等をどの順序で戻せるかを確認する必要があります。Cyber Exerciseへ工場運用・設備保全・Safety担当を含めることが重要です。
推奨アクション
- Critical OT AssetとDependencyを可視化する
- Known-good Backup / ConfigurationのRestore Testを行う
- IT / OT共同Incident Response Planを作る
- Recovery順序とSafety Checkpointを定義する
- Vendor / Integratorを含めた復旧Exerciseを実施する
- RTOだけでなくManual Operation / Production Lossも評価する
用語解説
Operational Resilience
Cyber Incidentや障害が起きても、重要なBusiness / Physical Operationを継続または許容時間内に復旧できる能力。