BISã³ãã¯ãããããŒã¯ã«èŠåãšã¯ïŒ SBOM察å¿ãšãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³éææ§ã®æ°èŠä»¶
èŠçŽ
äžåœãŸãã¯ãã·ã¢ç±æ¥ã®ãœãããŠã§ã¢ã®äœ¿çšãçŠæ¢ããç±³åœååçç£æ¥å®å šä¿éå±ïŒBISïŒã®ã³ãã¯ãããããŒã¯ã«èŠåã«ãããèªåè»OEMã¯è»äž¡ã«æèŒããããã¹ãŠã®ãœãããŠã§ã¢ã³ã³ããŒãã³ãã®ç±æ¥ã蚌æããããšãæ±ããããŠããŸãã2027å¹Žã®æœè¡æéãè¿«ãäžããã®èŠåãžã®å¯Ÿå¿ã«ã¯ãSoftware Bill of MaterialsïŒSBOMïŒã®å¯èŠåãšèªååããããµãã©ã€ãã§ãŒã³åæãäžå¯æ¬ ãšãªã£ãŠããŸããPlaxidityXã¯ãSoftware Supply Chain SecurityïŒSSCSïŒãœãªã¥ãŒã·ã§ã³ãæäŸããŠãããèŠå¶å¯Ÿè±¡ãšãªãã³ã³ããŒãã³ããç¹å®ããã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ã«å¿ èŠãªèšŒè·¡ãå¹ççã«çæã§ããããèªåè»ã¡ãŒã«ãŒãæ¯æŽããŠããŸããããã«ãããç±³åœãã¯ãããšããååœã§é²åããèŠå¶èŠä»¶ã«å¯Ÿããèªåè»ã¡ãŒã«ãŒã察å¿ã§ãããããµããŒãããŸãã
æ¥å¹Žåé ãããäžåœãŸãã¯ãã·ã¢ã«é¢é£ãããœãããŠã§ã¢ãæèŒããã³ãã¯ãããããŒã¯ã«ã®è²©å£²ã»èŒžå ¥ããç±³åœåžå Žã«ãããŠçŠæ¢ãããŸãããã®èŠå¶ã®èæ¯ã«ã¯ããã倧ããªå°æ¿åŠçãªå¯Ÿç«ããããŸããããã®åœ±é¿ã¯ãã§ã«èªåè»ã¡ãŒã«ãŒã®éçºã»è£œé çŸå Žã«åã³å§ããŠããŸãã
2025幎3æ17æ¥ã«æœè¡ãããç±³åœååçç£æ¥å®å šä¿éå±ïŒBISïŒã®ã³ãã¯ãããããŒã¯ã«æçµèŠåã«ããããœãããŠã§ã¢ã®ãçç£åœïŒCountry of OriginïŒãã¯ããœãããŠã§ã¢èªäœã®åè³ªãæ©èœãšåããããéèŠãªèŠçŽ ãšãªããŸãããå®å šèŠå¶ããµã€ããŒã»ãã¥ãªãã£èŠå¶ãžã®å¯Ÿå¿ã«è¿œãããèªåè»ã¡ãŒã«ãŒãTier 1ãµãã©ã€ã€ãŒã«ãšã£ãŠãããã®ãœãããŠã§ã¢ã¯å®å šããã ãã§ã¯ãªããããã®ãœãããŠã§ã¢ã¯ã©ãã§éçºãããã©ã®ãããªçµè·¯ã§äŸçµŠãããã®ããã蚌æããããšãæ±ããããããã«ãªããŸãã
ãã®èŠåã®æœè¡ã«ãããèªåè»ã¡ãŒã«ãŒã«ãããµãã©ã€ãã§ãŒã³ã®ç®¡çã»ç£æ»ã®ããæ¹ã¯å€§ããå€ããå¯èœæ§ããããŸãã
BISã³ãã¯ãããããŒã¯ã«èŠåãšã¯
ãBIS Rule â Securing the Information and Communications Technology and Services Supply Chain: Connected VehiclesïŒICTSãµãã©ã€ãã§ãŒã³ä¿è·ã«é¢ããã³ãã¯ãããããŒã¯ã«èŠåïŒãã¯ãã³ãã¯ãããããŒã¯ã«ããã³ãã®ãµãã©ã€ãã§ãŒã³ã«é¢é£ããåœå®¶å®å šä¿éäžã®ãªã¹ã¯ã軜æžããããšãç®çãšããŠçå®ãããèŠå¶ã§ããç¹ã«ãæµå¯Ÿåœã«ããããŒã¿ã®äžæ£ååŸïŒããŒã¿æµåºïŒããè»äž¡ã®é éæäœãšãã£ãè åšãžã®å¯Ÿçãäž»ãªå¯Ÿè±¡ãšããŠããŸãã
ãã®æçµèŠåã§ã¯ãäžåœãŸãã¯ãã·ã¢ã®äŒæ¥ã«ãã£ãŠèšèšã»éçºã»äŸçµŠãããããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ã¯ãä¹çšè»ã®Vehicle Connectivity SystemsïŒVCSïŒè»äž¡éä¿¡ã·ã¹ãã ïŒããã³Automated Driving SystemsïŒADSïŒèªåé転ã·ã¹ãã ïŒæèŒããããšãçŠæ¢ããŠããŸãããŸãããœãããŠã§ã¢ã«é¢ããŠã¯ã2026幎3æ17æ¥ä»¥éã«èšèšãŸãã¯è£œé ããããœãããŠã§ã¢ãµãã³ã³ããŒãã³ãã«ãé©çšãããŸãã
èŠå¶ãžã®é©åã蚌æãããããèªåè»ã¡ãŒã«ãŒããµãã©ã€ã€ãŒã«ã¯ããµãã©ã€ãã§ãŒã³ã«å¯Ÿãã調æ»ã»æ€èšŒæŽ»åã®å®æœãé©åå®£èšæžïŒDeclaration of ConformityïŒã®æåºãããã«ã³ã³ãã©ã€ã¢ã³ã¹é¢é£ææžã®æé·10幎éã®ä¿ç®¡ãæ±ããããŸãã
èªåè»ã¡ãŒã«ãŒãçŽé¢ããã³ã³ãã©ã€ã¢ã³ã¹äžã®èª²é¡ â 2027幎ã«åããæéãšã®æŠã
ãœãããŠã§ã¢ã«é¢ããçŠæ¢æªçœ®ã¯2027幎ã¢ãã«ã€ã€ãŒã®è»äž¡ããé©çšãããããŒããŠã§ã¢ã«é¢ããçŠæ¢æªçœ®ã¯2030幎ã¢ãã«ã€ã€ãŒããé©çšãããŸããããããå€ãã®2027幎ã¢ãã«è»äž¡ã¯ãã§ã«èšè𿮵éãçµããŠããããããµãã©ã€ãã§ãŒã³ã®ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ã«çæããæéã¯æ®ãããŠããŸããã察å¿ã¯ä»ããå§ããå¿ èŠããããŸãã
åè¿°ã®ãšããããã®èŠåã§ã¯ã¡ãŒã«ãŒã«å¯Ÿããé©åå®£èšæžã®æåºã«å ããVCSããã³ADSã«å«ãŸãããœãããŠã§ã¢ã®ãµãã³ã³ããŒãã³ãããäžåœãŸãã¯ãã·ã¢ã«ç±æ¥ããªãããšã蚌æãããšããã³ã¹ã®æç€ºãæ±ããŠããŸããã§ã¯ãèªåè»ã¡ãŒã«ãŒã¯ã©ã®ããã«ããŠãã®èšŒæ ãåéã»æç€ºããã°ããã®ã§ããããã
ããã«ããã®èŠåã«å¯Ÿå¿ããããã§æå€§ã®èª²é¡ããããŸããäžè¬çãªãœãããŠã§ã¢ã»ããã¡ã€ã³ãã»ããŒã¯ã«ïŒSDVïŒã«ã¯50ã100åçšåºŠã®ECUïŒé»åå¶åŸ¡ãŠãããïŒãæèŒãããŠãããããããã®ECUã«ã¯å€æ°ã®ãµãã©ã€ã€ãŒããæäŸãããæ°åçš®é¡ãã®ãœãããŠã§ã¢ã©ã€ãã©ãªãå«ãŸããŠããŸããèªåè»æ¥çã®ãµãã©ã€ãã§ãŒã³ã¯éåžžã«è€éã§ãããããèªåè»ã¡ãŒã«ãŒãTier 1ãµãã©ã€ã€ãŒã§ãã£ãŠããäžäœãµãã©ã€ã€ãŒããæäŸãããã³ã³ããŒãã³ãã®å éšã«ã©ã®ãããªãœãããŠã§ã¢ãå«ãŸããŠããã®ããå®å šã«ææ¡ã§ããŠããªãã±ãŒã¹ãå°ãªããããŸãããããã«ã仿¥ã®SDVã¯æ°åè¡èŠæš¡ã®ã³ãŒãã§æ§æãããé«åºŠãªãœãããŠã§ã¢ã·ã¹ãã ãæèŒããŠããã人æã«ããç£æ»ã§ãœãããŠã§ã¢ã®åºæã远跡ããããšã¯çŸå®çã§ã¯ãããŸããã
å®éã«ã¯ãèŠå¶å¯Ÿè±¡ãšãªããœãããŠã§ã¢ã¯ãµãã©ã€ãã§ãŒã³ã®æ·±ãéå±€ã«åãããŠããå¯èœæ§ããããŸãããã®ããèªåè»ã¡ãŒã«ãŒã«ã¯ãUN R155ã§çŸ©åä»ããããŠããè匱æ§ã¹ãã£ã³ãšåæ§ã«ãçŠæ¢å¯Ÿè±¡ãšãªãçµç¹ã«ãã£ãŠéçºããããœãããŠã§ã¢ãç¹å®ã§ããé«åºŠãªè§£æããŒã«ãå¿ èŠã«ãªããŸããåé¡ã®ããã³ã³ããŒãã³ããç¹å®ããã¬ããŒããšããŠå¯èŠåã§ããã°ãèªåè»ã¡ãŒã«ãŒã¯è©²åœãµãã©ã€ã€ãŒã«å¯ŸããŠä¿®æ£çãžã®æŽæ°ã代æ¿ã³ã³ããŒãã³ããžã®çœ®ãæããèŠæ±ããããšãå¯èœã«ãªããŸããã€ãŸããã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ãå®çŸããããã«ã¯ããµãã©ã€ãã§ãŒã³å šäœã«ããããœãããŠã§ã¢æ§æã®å¯èŠåãšç¶ç¶çãªç£æ»äœå¶ã®æ§ç¯ãäžå¯æ¬ ãªã®ã§ãã
PlaxidityX SSCSãã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ã®èª²é¡ã解決
PlaxidityXã®Software Supply Chain SecurityïŒSSCSïŒã¯ããœãããŠã§ã¢éçºããåžå Žæå ¥åŸã®è»äž¡éçšãŸã§ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³å šäœã察象ãšããè匱æ§ç®¡çãå®çŸãããœãªã¥ãŒã·ã§ã³ã§ããé«åºŠãªãœãŒã¹ã³ãŒãè§£æãšãã€ããªè§£æãåäžã®ãã©ãããã©ãŒã äžã§çµ±åããèªåè»ã¡ãŒã«ãŒãTier 1ãµãã©ã€ã€ãŒãè匱æ§ãè¿ éãã€å¹æçã«ç¹å®ã»ç®¡çã§ããããæ¯æŽããŸãããã®æ©èœã¯ãUN R155ãISO/SAE 21434ãããã«ã¯EU Cyber Resilience ActïŒCRAïŒãšãã£ããµã€ããŒã»ãã¥ãªãã£èŠå¶ã»æšæºãžã®å¯Ÿå¿ãé²ããããã§éèŠãªåœ¹å²ãæãããŸãã
ãããå®éã«ã¯ãèªåè»ã¡ãŒã«ãŒãè匱æ§ç®¡çã«å¿ èŠãªæ å ±ïŒSBOMãªã©ïŒãžã¢ã¯ã»ã¹ã§ããªãã±ãŒã¹ãå°ãªããããŸããããŸãããµãã©ã€ã€ãŒã«ã¯ãå®å šãªããœãããŠã§ã¢ãæäŸããæ³ç矩åããªãå ŽåããããŸãããã®çµæãè€æ°ã®ãµãã©ã€ã€ãŒã«ãã£ãŠéçºãããæ°å€ãã®ã³ã³ããŒãã³ãã«å«ãŸãããœãããŠã§ã¢ã®å®æ ãææ¡ããããšãé£ãããèªåè»ã¡ãŒã«ãŒãè»äž¡å šäœã®ãœãããŠã§ã¢ã»ãã¥ãªãã£ãä¿èšŒããããã§å€§ããªéå£ãšãªã£ãŠããŸããSSCSã¯ããã®èª²é¡ã解決ããããã«ããœãŒã¹ã³ãŒãåã³ã³ã³ãã€ã«æžã¿ãã€ããªããSBOMãçæããŸããAUTOSARãLinuxãAndroidãªã©å¹ åºããã©ãããã©ãŒã ã«å¯Ÿå¿ããŠããããµãŒãããŒãã£è£œãœãããŠã§ã¢ããã©ãã¯ããã¯ã¹åããããµãã©ã€ã€ãŒè£œã³ã³ããŒãã³ãã«å«ãŸãããªã¹ã¯ãå¯èŠåã§ããŸãã
ããã«ãBISã³ãã¯ãããããŒã¯ã«èŠåãžã®å¯Ÿå¿ãæ¯æŽãããããPlaxidityXã¯SSCSã«æ°ããªã³ã³ãã©ã€ã¢ã³ã¹æ©èœã远å ããŸããããã®æ©èœã§ã¯ãçæãããSBOMãç±³åœååçã®BIS Entity Listããã³Consolidated Screening ListïŒCSLïŒãšèªåç §åããèŠå¶å¯Ÿè±¡ãšãªãäŒæ¥ãå°åã«ç±æ¥ããã³ã³ããŒãã³ããè¿ éã«æ€åºããŸãããœãŒã¹ã³ãŒããšã³ã³ãã€ã«æžã¿ãã€ããªããSBOMãæœåºããèŠå¶å¯Ÿè±¡ã®ãœãããŠã§ã¢ã³ã³ããŒãã³ããå³åº§ã«ç¹å®ããå¯èŠåããããšãå¯èœã§ããããã¯åãªããµã€ããŒã»ãã¥ãªãã£å¯Ÿçã§ã¯ãããŸãããèªåè»ã¡ãŒã«ãŒãTier 1ãµãã©ã€ã€ãŒãç±³åœåžå Žãžã®åå ¥ã«å¿ èŠãªé©åå®£èšæžãäœæããããã®èšŒè·¡ãäœæããBISèŠåãžã®ã³ã³ãã©ã€ã¢ã³ã¹ãå¹ççã«å®çŸããããã®åºç€ãšãªããã®ã§ãã
ã°ããŒãã«ã«åºããèŠå¶ã®æµã â æ¬§å·ã®ãªã¹ã¯ããŒã¹ã¢ãããŒã
ç±³åœã®BISã³ãã¯ãããããŒã¯ã«èŠåã¯éåžžã«æç¢ºãªåœ¢ã§èŠå¶èŠä»¶ã瀺ããŠããŸãããæ¬§å·ã§ãåæ§ã®æ¹åæ§ãé²ãã§ããŸãããã ãããã®ã¢ãããŒãã¯ç¹å®ã®åœãäŒæ¥ãçŽæ¥æå®ããã®ã§ã¯ãªããããªã¹ã¯ããŒã¹ãã®èãæ¹ã«åºã¥ããŠããŸããããããåãã¯ãäž»ã«ä»¥äžã®èŠå¶ãæ¿çã«ãã£ãŠæšé²ãããŠããŸãã
EU Cyber Resilience ActïŒCRAïŒ
EU Cyber Resilience ActïŒCRAïŒã§ã¯ãSBOMã®æäŸãšè匱æ§å ±åãæ³ç矩åãšãªãããã»ãã¥ãªãã£ã»ãã€ã»ãã¶ã€ã³ãã®èãæ¹ãåŒ·ãæ±ããããŠããŸãã察象補åã¯ãåºè·æç¹ã§ãSecure by DefaultïŒå®å šãªåæèšå®ïŒããé©çšãããŠããããšãæ¢ç¥ã®æªçšå¯èœãªè匱æ§ãå«ãŸãªãããšãæ»æå¯Ÿè±¡é åãæå°éã«æããããšãå調çè匱æ§é瀺ïŒCoordinated Vulnerability DisclosureïŒCVDïŒã®ããã®æ¹éããã³ããã»ã¹ãæŽåããããšãæ±ããããŠããŸãã
UN R155 / UN R156
UN R155ããã³UN R156ã¯ãèªåè»æ¥çã«ããããµãã©ã€ãã§ãŒã³ã®éææ§ç¢ºä¿ã®åœéèŠå¶ãšããŠããã§ã«å€ãã®èªåè»ã¡ãŒã«ãŒã«é©çšãããŠããŸãã
欧å·ãç®æããæŠç¥çèªåŸæ§ïŒStrategic AutonomyïŒã
è¿å¹Žã欧å·èŠå¶åœå±ã¯ãéæè¡çãªã¹ã¯èŠå ïŒNon-Technical Risk FactorsïŒããžã®é¢å¿ãé«ããŠããŸãããã®ã¢ãããŒãã¯ã欧å·ã®5Gã»ãã¥ãªãã£æ¿çã§ãããEU 5G Toolboxããšåæ§ã®èãæ¹ã«åºã¥ããŠãããå°æ¥çã«ã¯èªåè»æ¥çã«ãããŠããé«ãªã¹ã¯ãšå€æããããã³ããŒã®æ¡çšãå¶éãããå¯èœæ§ããããŸãããã®ç®çã¯ããµã€ããŒæ»æã ãã§ãªããããžã¿ã«ã€ã³ãã©ãéãã劚害è¡çºããµãã©ã€ãã§ãŒã³ãªã¹ã¯ãæªç¶ã«é²ãããšã«ãããŸãã
ãµãã©ã€ãã§ãŒã³ã®éææ§ãåžå Žåå ¥ã®éµã«ãªã
ç±³åœåžå Žã§ããæ¬§å·åžå Žã§ããããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã®éææ§ã¯æ¥éã«æ°ããªãäºæ¥ç¶ç¶ã®åææ¡ä»¶ãã«ãªãã€ã€ãããŸããããã¯ãèªåè»æ¥çãæ°ããªæä»£ãžç§»è¡ããŠããããšãæå³ããŠããŸããã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ãå®å šæ§ã®ç¢ºä¿ã«ã¯ããµãã©ã€ãã§ãŒã³ã®ææ·±éšã«ååšãããœãããŠã§ã¢ã³ã³ããŒãã³ããŸã§å«ããŠããã®æ§æãšç±æ¥ãææ¡ã§ããå¯èŠæ§ãäžå¯æ¬ ã«ãªã£ãã®ã§ãã
ããããèŠæ±ã«å¯Ÿå¿ããããã«ã¯ããã¯ã人æã«ããç£æ»ã ãã§ã¯ååã§ã¯ãããŸãããPlaxidityX SSCSã®ãããªèªååã»ã¹ã±ãŒã©ãã«ãªãœãªã¥ãŒã·ã§ã³ã掻çšããããšã§ãã¡ãŒã«ãŒã¯åŸæ¥ã®ã¹ãããçãªç£æ»ããè±åŽããç¶ç¶çãªãœãããŠã§ã¢åæãšèšŒè·¡ã«åºã¥ãã³ã³ãã©ã€ã¢ã³ã¹ç®¡çãžãšç§»è¡ã§ããŸããå°æ¿åŠçãªã¹ã¯ããµã€ããŒã»ãã¥ãªãã£æŠç¥ã«å€§ããªåœ±é¿ãäžããçŸåšãäŒæ¥ã«æ±ããããã®ã¯ããœãããŠã§ã¢ãå®å šã§ããããšãã ãã§ã¯ãããŸããããã©ã®ãããªãœãããŠã§ã¢ãå«ãŸããŠããã®ããããããã©ãããæ¥ãã®ããã蚌æã§ããããšããä»åŸã®åžå Žã¢ã¯ã»ã¹ãå·Šå³ããéèŠãªèŠä»¶ãšãªããŸãããããŠè¿ãå°æ¥ãèªç€Ÿã®è»äž¡ãã©ã®åœãå°åã§è²©å£²ã§ãããã¯ããœãããŠã§ã¢å éšã®æ§æãã©ãã ãæ£ç¢ºã«ææ¡ãã蚌æã§ãããã«ãã£ãŠæ±ºãŸãæä»£ã«ãªããããããŸããã
å·çïŒ2026幎06æ10æ¥