NIST SP 1800-45 ― OT Remote Accessを「例外VPN」からReference Architectureへ
Executive Summary
NIST NCCoEは2026年6月24日、SP 1800-45「Cybersecurity for the Water and Wastewater Sector: Build Architecture」を最終公開しました。水道・下水Sectorを対象に、商用Technologyを用いた複数のSecure Remote Access Reference DesignをLabで構築・実証しています。1
重要なのは水道業界固有の話に閉じず、OT Remote AccessをVendor作業の例外経路ではなく、Authentication・Authorization・Monitoringを備えた正式Architectureとして設計することです。
なぜ今なのか
設備VendorのRemote Maintenanceは事業継続に有効ですが、常設VPN、Shared Account、Flat Network、監視不足が残ると重要Infrastructureへの強力な侵入経路になります。Digital TransformationでInternet-connected SensorやAnalyticsが増えるほどBoundaryも複雑になります。
何が起きているのか
SP 1800-45はSmallからLarge Utilityを想定したReference Designを示し、Remote AccessをOperational Needに応じて安全に実装する具体例を提供しています。Controlの中心はAccess Authorization、Authentication、Secure Communication、Monitoringであり、「VPNを使う」だけではありません。
経営インパクト
| 観点 | 影響 |
|---|---|
| Third-party Access | Vendor Account / Remote Maintenanceを正式なIdentity Control対象にする |
| OT Segmentation | Remote Accessの到達範囲を限定する |
| Monitoring | 誰がいつ何へ接続したか追跡できる必要 |
| Availability | 緊急保守を阻害せずSecurityを成立させる設計が必要 |
日本企業への示唆
日本の製造・重要インフラでも、Vendor Remote Accessを契約・現場運用・Network設計の3者で統合管理することが重要です。PAM、MFA、Jump Host、Session Recording、Time-bound Accessなどを、現場の保守要件に合わせて組み合わせるべきです。
推奨アクション
- OT Remote Access経路を全て棚卸しする
- Shared Accountを個別Identityへ移行する
- MFA / PAM / Time-bound Accessを適用する
- Vendorごとに到達可能Assetを限定する
- Session Logging / Recordingを実装する
- 緊急保守時のBreak-glass手順を演習する
用語解説
Remote Access Architecture
外部・遠隔利用者がOTへ接続するためのIdentity、Network、Control Point、Monitoringを含む設計。
Jump Host
管理対象Systemへの接続を中継し、Access Controlと監査を集中させるHost。