NIST SP 1800-39 Draft ― Zero Trust・PQC・Secure AIの前に「Dataを見つけて分類する」
Executive Summary
NISTは2026年2月12日、Data Classification Practicesを扱うSP 1800-39 Draftを公開しました。1
Guidanceは、File Repository、Email、Data Lake等に散在するSensitive Unstructured DataをDiscover・Identify・Labelする実装を示し、Data ClassificationをZero Trust Architecture、Quantum-safe Cryptography、Secure AI Model Trainingへ進むための初期Stepとして位置づけています。
なぜ今なのか
AI、PQC、Zero Trustはいずれも「何を守るか」が分からなければ適切に適用できません。Data Inventoryが曖昧なままでは、Encryption Migration、AI Training Data Control、Access PolicyのScopeを決められません。
Data Classificationの位置づけ
Discover Data
↓
Identify Sensitive Data
↓
Classify / Label
↓
Zero Trust
PQC / Encryption
Secure AI
経営インパクト
| 観点 | 影響 |
|---|---|
| Data Governance | Security Programの基礎としてData Inventoryが必要 |
| AI | Training / RAGへ投入してよいDataを判断しやすくなる |
| PQC | 長期保護が必要なDataをMigration Priorityへつなげる |
| ZTA | Sensitivityに応じたAccess Controlが可能になる |
日本企業への示唆
DLP Tool導入をGoalにせず、Classification LabelをAccess、Retention、Encryption、AI Use Policyへ接続することが重要です。
推奨アクション
- Unstructured Dataの主要RepositoryをInventory化する
- Classification Schemeを3〜5段階程度へ簡素化する
- LabelとAccess / Retention Ruleを紐づける
- AI Training / RAG利用可否をLabelから判断できるようにする
- Long-lived Sensitive DataをPQC Migration対象として識別する
- Classification Accuracyを継続測定する
用語解説
Unstructured Data
Document、Email、PDF、Chat、File等、Database Tableのように固定Schemaを持たないData。