EU CRA察å¿ã¬ã€ãïŒèªåè»ã¡ãŒã«ãŒãæŒãããã¹ãå¿ é èŠä»¶ãšå¯Ÿç
èŠçŽ
欧å·é£åïŒEUïŒã§èªåè»ã販売ããã¡ãŒã«ãŒã«ãšã£ãŠããµã€ããŒã»ãã¥ãªãã£èŠå¶ã¯å€§ããªè»¢æç¹ãè¿ããŠããŸããEUã§æ¡æããããCyber Resilience ActïŒCRAïŒãã«ããããããŸã§ã®èªäž»çãªã¬ã€ãã©ã€ã³äžå¿ã®èãæ¹ãããâProducts with Digital ElementsïŒPDEïŒããžã¿ã«èŠçŽ ãæã€è£œåïŒâã«å¯Ÿããæ³çææåã®ãããµã€ããŒã»ãã¥ãªãã£èŠä»¶ãžãšç§»è¡ããŸããããã®æ³èŠå¶ã¯ãEUåžå Žãžã®åå ¥æ¡ä»¶ãã®ãã®ã倧ããå€ãããã®ã§ããCRAã®é©çšå¯Ÿè±¡ãšãªãè»äž¡ãã³ã³ããŒãã³ãã¯ãCRAãžã®é©åã確èªã§ããªããã°ãEUå çåœã§è²©å£²ããããšãã§ããŸããã
æ¬èšäºã§ã¯ãèªåè»OEMããã³Tier1ã»Tier2ãµãã©ã€ã€ãŒã察象ã«ãCRAã®èŠæ±äºé ããã®é©çšéå§ææããããŠã©ã®äŒæ¥ã»è£œåã察象ãšãªãã®ããåããããã解説ããŸããããã«ãCRAã«æºæ ããªãå Žåã«æ³å®ããã財åçã»äºæ¥çãªãªã¹ã¯ã«ã€ããŠãåãäžããã»ããã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ã«äŒŽãæè¡ç課é¡ãžã®å¯ŸçãšããŠæ³šç®ãããæ°ããªãœãªã¥ãŒã·ã§ã³ã«ã€ããŠã玹ä»ããŸããå ·äœçã«ã¯ããUnified Vehicle Detection & ResponseïŒVDRãçµ±ååè»äž¡æ€ç¥ã»å¯Ÿå¿ãœãªã¥ãŒã·ã§ã³ïŒãããAutomated Security DesignïŒã»ãã¥ãªãã£èšèšã®èªååïŒ ããšãã£ãæè¡ããèªåè»ã¡ãŒã«ãŒããµãã©ã€ã€ãŒã®CRA察å¿ãã©ã®ããã«æ¯æŽã§ããã®ãã«ã€ããŠè§£èª¬ããŠãããŸãã
CRAãèªåè»æ¥çã«äžãã圱é¿
CRAã¯ãããŒããŠã§ã¢ããã³ãœãããŠã§ã¢è£œåã®ã©ã€ããµã€ã¯ã«å šäœã«ããã£ãŠããµã€ããŒã»ãã¥ãªãã£èŠä»¶ã矩ååããåã®EUå šåèŠå¶ã§ãããã®é©çšç¯å²ã¯éåžžã«åºãããããã¯ãŒã¯ãŸãã¯ä»ã®ããã€ã¹ã«æ¥ç¶å¯èœãªãããžã¿ã«èŠçŽ ãæã€è£œåãå šè¬ã察象ãšãªããŸãã
ãã ããèªåè»æ¥çã«ãããCRAã®é©çšã¯äžåŸã§ã¯ãªããè»äž¡ã«ããŽãªãŒãæ¢åèŠå¶ã®é©çšç¶æ³ã«ãã£ãŠæ±ããç°ãªããŸãã
UNR155é©çšè»äž¡ã¯ååãšããŠCRAé©çšé€å€
éèŠãªãã€ã³ããšããŠãUNR155ïŒãµã€ããŒã»ãã¥ãªãã£ãããžã¡ã³ãã·ã¹ãã ïŒã®ååŒèªèšŒèŠä»¶ããã§ã«é©çšãããŠããè»äž¡ã«ã€ããŠã¯ãååãšããŠCRAã®é©çšå¯Ÿè±¡å€ãšãªããŸããããã«ã¯äž»ã«ä»¥äžã®è»äž¡ã«ããŽãªãŒãå«ãŸããŸãã
- Category MïŒä¹çšè»
- Category NïŒè²šç©è»äž¡
- Category LïŒäºèŒªã»äžèŒªè»ããã³ã¯ã¯ãã
- Category OïŒãã¬ãŒã©ãŒ
ãããã®è»äž¡ã¯ããã§ã«UNR155ã«ãããµã€ããŒã»ãã¥ãªãã£èŠæ±ãžã®å¯Ÿå¿ã矩ååãããŠãããããCRAãšã®éè€èŠå¶ãé¿ãã圢ãšãªã£ãŠããŸãã
CRAãé©çšå¯Ÿè±¡ã®è»äž¡ã«ããŽãªãŒïŒT/C/R/SïŒ
äžæ¹ã§ãUNR155ã®çŸ©åé©çšç¯å²å€ãšãªãè»äž¡ã«ããŽãªãŒã«ã€ããŠã¯ãCRAãçŽæ¥é©çšãããŸããå
·äœçã«ã¯ä»¥äžã®ã«ããŽãªãŒã該åœããŸãã
- Category TïŒãã€ãŒã«åŒãã©ã¯ã¿ãŒ
- Category CïŒã¯ããŒã©åŒãã©ã¯ã¿ãŒ
- Category RïŒèŸ²æ¥çšãã¬ãŒã©ãŒ
- Category SïŒäº€æåŒè¢«çœåŒæ©åš
ãããã®è»äž¡ã補é ããã¡ãŒã«ãŒã«ãšã£ãŠãCRAã¯æ°ããªãµã€ããŒã»ãã¥ãªãã£åºæºãšãªããŸãã
CRA察å¿ã®ã¿ã€ã ã©ã€ã³ã¯ç®åã«è¿«ã£ãŠãã
CRAãžã®å¯Ÿå¿ã¯æªæ¥ã®èª²é¡ã§ã¯ãããŸãããCRAã®å šé¢é©çšã¯ãæœè¡ãã36ãæåŸãšãªã2027幎åŸåãäºå®ãããŠããŸãããå®éã«ã¯ãã以åããéèŠãªå¯Ÿå¿çŸ©åãæ®µéçã«å§ãŸããŸããããšãã°2026幎9æä»¥éãã¡ãŒã«ãŒã«ã¯ãããžã¿ã«èŠçŽ ãæã€è£œåïŒPDEïŒã«åœ±é¿ãåãŒãé倧ã€ã³ã·ãã³ãããå®éã«æªçšãããŠããè匱æ§ã«ã€ããŠãEUåœå±ãã€ãŸãENISAïŒæ¬§å·é£åãµã€ããŒã»ãã¥ãªãã£æ©é¢ïŒããã³åœå®¶CSIRTïŒComputer Security Incident Response TeamïŒãžå ±åã§ããäœå¶ãæŽåããŠããããšãæ±ããããŸããç¹ã«éèŠãªã®ã¯ããã®å ±åæéãéåžžã«çãç¹ã§ããã±ãŒã¹ã«ãã£ãŠã¯ãã€ã³ã·ãã³ãæ€ç¥ãã24æé以å ã®å ±åãæ±ããããå ŽåããããŸãã
CRAéæºæ ã«ãã財åãªã¹ã¯
CRAã«ãã£ãŠããããããæã倧ããªå€åã®ã²ãšã€ã¯ããµã€ããŒã»ãã¥ãªãã£å¯Ÿå¿ããæšå¥šããããã¹ããã©ã¯ãã£ã¹ããããæ³çã»è²¡åç責任ããžãšå€ããç¹ã§ããCRAã§ã¯ãèŠå¶èŠä»¶ã«æºæ ããŠããªãäŒæ¥ã«å¯ŸããŠãç£ç£åœå±ãé«é¡ãªè¡æ¿å¶è£éãç§ãæš©éãæã¡ãŸããéåå 容ã«å¿ããŠäž»ã«ä»¥äžã®3段éã®çœ°åãå®ããããŠããŸãã
髿°Žæºã®å¶è£ïŒå¿ é èŠä»¶ãžã®éæºæ ïŒ
CRAã§å®ããããå¿ é ãµã€ããŒã»ãã¥ãªãã£èŠä»¶ãæºãããŠããªãå Žåãæå€§1,500äžãŠãŒããŸãã¯å šäžç幎é売äžé«ã®2.5%ã®ããããé«ãæ¹ãäžéãšããŠå¶è£éãç§ãããå¯èœæ§ããããŸãã
äžæ°Žæºã®å¶è£ïŒå ±å矩åéåïŒ
ã€ã³ã·ãã³ããè匱æ§ã«é¢ããå ±å矩åãæãããªãã£ãå Žåãæå€§1,000äžãŠãŒããŸãã¯å šäžç幎é売äžé«ã®2%ã®ããããé«ãæ¹ãäžéãšããŠçœ°åãé©çšãããŸãã
äœæ°Žæºã®å¶è£ïŒäžæ£ç¢ºãªæ å ±æäŸïŒ
åžå Žç£èŠåœå±ã«å¯ŸããŠãäžæ£ç¢ºãŸãã¯èª€è§£ãæãæ å ±ãæäŸããå Žåã«ã¯ãæå€§500äžãŠãŒããŸãã¯å šäžç幎é売äžé«ã®1%ã®ããããé«ãæ¹ãäžéãšããå¶è£éãç§ãããå¯èœæ§ããããŸãã
æè¡çãªèª²é¡ïŒCRAã®å¿ é èŠä»¶ãã©ã®ããã«æºããã
ããããå¶è£ãªã¹ã¯ãåé¿ããããã«ã¯ãã¡ãŒã«ãŒãèªç€Ÿè£œåã«ã€ããŠãCRAã®Annex IïŒé屿žIïŒã§å®çŸ©ããããå¿ é ãµã€ããŒã»ãã¥ãªãã£èŠä»¶ããæºãããŠããããšã蚌æããå¿ èŠããããŸãããããã®èŠæ±äºé ã¯ã倧ãã3ã€ã®éèŠãªæ±ã«åé¡ãããŸãã
- ãµã€ããŒã»ãã¥ãªãã£ãªã¹ã¯è©äŸ¡
ã¡ãŒã«ãŒã¯ã補åãåžå Žæå ¥ããåã«ãå æ¬çãªãµã€ããŒã»ãã¥ãªãã£ãªã¹ã¯è©äŸ¡ã宿œãããã®å å®¹ãææžåããå¿ èŠããããŸãããã®ãªã¹ã¯è©äŸ¡ãåºç€ãšããŠãä¿è·ãã¹ãéèŠè³ç£ãç¹å®ããæ³å®ãããè åšããªã¹ã¯ãåæããäžã§ãå¿ èŠãªã»ãã¥ãªãã£å¯Ÿçãå®çŸ©ããŠãããŸããèªåè»æ¥çã«ãããŠã¯ãããã¯TARAïŒè åšåæãšãªã¹ã¯è©äŸ¡ïŒãã·ã¹ãã ã¬ãã«ã®è åšåæããã»ã¹ãšã坿¥ã«é¢ä¿ããŠããŸãã
- ã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ïŒèšè𿮵éããã®ã»ãã¥ãªãã£ç¢ºä¿ïŒ
CRAã§ã¯ãã»ãã¥ãªãã£ãéçºåŸã«è¿œå ããã®ã§ã¯ãªããèšè𿮵éããçµã¿èŸŒããã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ãã®èãæ¹ãæ±ããããŸãã補åã¯ãªã¹ã¯è©äŸ¡çµæã«åºã¥ããŠèšèšãããå¿ èŠãããããã»ãã¥ã¢ã»ãã€ã»ããã©ã«ãïŒåæèšå®ç¶æ ããå®å šïŒããªç¶æ ã§æäŸãããããšãæ¢ç¥ã®æªçšå¯èœãªè匱æ§ãå«ãŸãªãããšãããã«æ»æå¯Ÿè±¡é åãæå°åããŠããããšãæ±ããããŸããããã¯ãè»èŒECUããœãããŠã§ã¢ã¢ãŒããã¯ãã£ã®åæèšè𿮵éãããã»ãã¥ãªãã£èšèšãçµ±åããŠããå¿ èŠãããããšãæå³ããŸãã
- è匱æ§ç®¡çãšSBOM察å¿
CRAã§ã¯ã補åãªãªãŒã¹åŸã®è匱æ§å¯Ÿå¿äœå¶ã«ã€ããŠã峿 ŒãªèŠä»¶ãå®ããããŠããŸããã¡ãŒã«ãŒã¯ãå調çè匱æ§é瀺ïŒCoordinated Vulnerability DisclosureïŒCVDïŒã®ããã®ããªã·ãŒãæŽåããªããã°ãªããŸããããã®äžã§ãç¹ã«éèŠãšãªãã®ããSBOMã®ç®¡çã§ããã¡ãŒã«ãŒã«ã¯ãèªç€ŸéçºãœãããŠã§ã¢ã«å ãããµãŒãããŒãã£è£œã³ã³ããŒãã³ãããªãŒãã³ãœãŒã¹ã©ã€ãã©ãªãå«ããã¹ãŠã®ãœãããŠã§ã¢ã³ã³ããŒãã³ããç¶ç¶çã«ææ¡ã»ç®¡çããããšãæ±ããããŸããããã«ãããè匱æ§ãçºèŠãããéã«ã圱é¿ç¯å²ãè¿ éã«ç¹å®ããå¿ èŠãªä¿®æ£å¯Ÿå¿ãè¡ããäœå¶ãç¶æããå¿ èŠããããŸãããªãCRAã§ã¯ã補åãµããŒãæéäžãæäœ5幎éã«ãããç¶ç¶çãªè匱æ§å¯Ÿå¿ãæ±ããããŠããŸãã
CRA察å¿ã«æ±ããããæ¬¡äžä»£ã®ã»ãã¥ãªãã£ã¢ãããŒã
CRAã®å³æ ŒãªèŠä»¶ã«å¯Ÿå¿ããããã«ã¯ãåå¥ã®ã»ãã¥ãªãã£ããŒã«ãå°å ¥ããã ãã§ã¯äžååã§ããæ±ããããã®ã¯ã補åã©ã€ããµã€ã¯ã«å šäœãéããŠãµã€ããŒã»ãã¥ãªãã£ãçµã¿èŸŒãã ãå æ¬çãã€çµ±ååã®ã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã§ããCRAæºæ ãå®çŸãããããèªåè»ã¡ãŒã«ãŒã«ã¯ãéçºåææ®µéããéçšãã§ãŒãºãŸã§äžè²«ããŠãµã€ããŒã»ãã¥ãªãã£ãçµã¿èŸŒãé«åºŠãªã¢ãããŒããæ±ããããŠããŸãã
1. ã€ã³ããªãžã§ã³ããªãšããžåŠçãšæ€ç¥ã«ããé«ç²ŸåºŠãªå ±å察å¿
CRAã§ã¯ãã€ã³ã·ãã³ãå ±åã«é¢ããŠå³æ ŒãªçŸ©åã課ãããŸããã¡ãŒã«ãŒã¯ã24æé以å ãšããçæéã§ã€ã³ã·ãã³ããå ±åããªããã°ãªããªãäžæ¹ã§ãäžæ£ç¢ºãªå ±åïŒäŸãã°èª€æ€ç¥ïŒã«ã€ããŠã眰å察象ãšãªãå¯èœæ§ããããŸãã
ãã®èª²é¡ã«å¯ŸããŠæå¹ãªã®ããã€ã³ããªãžã§ã³ããªVehicle Detection & ResponseïŒVDRïŒãã©ãããã©ãŒã ã§ããç¹ã«ä»¥äžã®æ©èœãéèŠãšãªããŸãã
ãã€ãºæå¶:
倧éã®ã¢ã©ãŒããã€ãºããã£ã«ã¿ãªã³ã°ããè»äž¡åŽïŒãšããžïŒã§æ€ç¥ããžãã¯ãå®è¡ããããšã§ãä¿¡é Œæ§ã®é«ãã€ã³ã·ãã³ãã®ã¿ãå ±å察象ãšããŠæœåºããŸããããã«ãããäžèŠãªèª€æ€ç¥ãæããªãããè¿ éãªå ±å矩åãžã®å¯Ÿå¿ãå¯èœã«ãªããŸãã
ãšã³ãããŒãšã³ãã®å¯èŠå:
CANãEthernetãHostãªã©è€æ°ã¬ã€ã€ãŒã®ããŒã¿ãçµ±åã»çžé¢åæããã»ãã¥ãªãã£ã€ã³ã·ãã³ããåäžã®ãã¥ãŒã§å¯èŠåããŸããããã«ãããè»äž¡å šäœã暪æããè åšåæãšè¿ éãªç¶æ³ææ¡ãå¯èœã«ãªããŸãã
ãã©ã¬ã³ãžãã¯å¯Ÿå¿:
èŠå¶åœå±ãžã®èª¬æãæ ¹æ¬åå åæã«å¿ èŠãšãªãé«ç²ŸåºŠãªèšŒè·¡ããŒã¿ïŒäŸïŒpcapãã°ïŒããªã³ããã³ãã§ååŸã§ããäœå¶ãéèŠã§ãã
2. Secure by Designãšãªã¹ã¯è©äŸ¡ã®èªåå
CRAã§ã¯ã補åãéçºåææ®µéããå®å šã«èšèšãããSecure by DesignããåŒ·ãæ±ããããŸãããã®ãã·ããã»ã¬ããã»ã»ãã¥ãªãã£ãã¢ãããŒãã§ã¯ãéçºã®æ©ã段éããã»ãã¥ãªãã£å¯Ÿçãšèªååããã»ã¹ãçµã¿èŸŒãå¿ èŠããããŸãã
ãªã¹ã¯è©äŸ¡ã®èªåå:
CRA察å¿ã§ã¯ãTARAïŒè åšåæãšãªã¹ã¯è©äŸ¡ïŒã®èªååãéèŠãªèŠçŽ ãšãªããŸããèšè𿮵éã§ä¿è·å¯Ÿè±¡ãšãªãè³ç£ãæ³å®ãããæ»æçµè·¯ãç¹å®ããããšã§ã補åã«å¿ èŠãªã»ãã¥ãªãã£å¶åŸ¡ãæ©ã段éããçµã¿èŸŒãããšãå¯èœã«ãªããŸããããã«ãããéçºåŸåã§ã®ææ»ããæããªãããããå¹ççãã€äžè²«æ§ã®ããã»ãã¥ãªãã£èšèšãå®çŸã§ããŸãã
SW Supply Chain SecurityïŒSSCSïŒ:
CRAã§ã¯ããµãŒãããŒãã£è£œã³ã³ããŒãã³ããå«ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³å šäœã®è匱æ§ç®¡çãæ±ããããŸãããã®ããã¡ãŒã«ãŒã«ã¯ãSBOMãèªåçæã»ç¶ç¶ç£èŠã§ããä»çµã¿ãå¿ èŠã«ãªããŸããããã«ããããµãã³ã³ããŒãã³ãã§æ°ããªè匱æ§ãçºèŠãããå Žåã§ããã©ã®è»äž¡ããœãããŠã§ã¢ã«åœ±é¿ãåã¶ã®ããè¿ éã«ææ¡ããå¿ èŠãªå¯ŸçãžçŽ æ©ãã€ãªããããšãå¯èœã«ãªããŸãã
ä»ããè¡åãèµ·ããã¹ãæ
CRAã®æœè¡ã«ãããèªåè»ã¡ãŒã«ãŒããµãã©ã€ã€ãŒã«æ±ãããããµã€ããŒã»ãã¥ãªãã£å¯Ÿå¿ã®ç¯å²ã¯å€§ããæ¡å€§ããŠããŸãããµã€ããŒã»ãã¥ãªãã£ã¯ãã¯ãEUåžå Žã§è£œåã販売ããããã®åºæ¬èŠä»¶ãšãªãã€ã€ãããŸããç¹ã«ãUNR155ã®é©çšå¯Ÿè±¡å€ã§ãã蟲æ¥çšè»äž¡ãç¹æ®è»äž¡ïŒCategory TãCãRãSïŒã®ã¡ãŒã«ãŒã«ãšã£ãŠãCRAã¯æ¥µããŠå€§ããªå€åãæå³ããŸãã察å¿ãäžååãªå Žåã«ã¯ãå¶è£éã ãã§ãªããåžå Žæå ¥ã®é å»¶ãè²©å£²åæ¢ããã©ã³ãæ¯æãšãã£ãæ·±å»ãªäºæ¥ãªã¹ã¯ã«ã€ãªããå¯èœæ§ããããŸãã
ããããå€åã«å¯Ÿå¿ããããã«ã¯ãåŸæ¥ã®æäœæ¥äžå¿ã®ã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ããè±åŽããéçºããéçšãŸã§ãèŠæ®ããçµ±ååã®ã»ãã¥ãªãã£ã¢ãããŒããžç§»è¡ããããšãéèŠã§ããããšãã°ãVehicle Detection & ResponseïŒVDRïŒãã©ãããã©ãŒã ã«ããé«ç²ŸåºŠãªã€ã³ã·ãã³ãæ€ç¥ã»å ±åããSBOM管çãšè匱æ§å¯Ÿå¿ãå¹çåããèªååãããã»ãã¥ãªãã£èšèšã¯ãCRA察å¿ãé²ããäžã§æå¹ãªææ®µãšãªããŸãã
PlaxidityXã§ã¯ãã°ããŒãã«èªåè»ã¡ãŒã«ãŒãšã®åãçµã¿ãéããŠå¹ã£ãç¥èŠãããšã«ãCRAã®ãããªè€éãªèŠå¶èŠä»¶ãå®è·µçãªã»ãã¥ãªãã£æŠç¥ãžãšèœãšãèŸŒãæ¯æŽãè¡ã£ãŠããŸããCRA察å¿ããªã¹ã¯è©äŸ¡ãSecure by Designã®å®è·µã«ã€ããŠè©³ããç¥ãããæ¹ã¯ããã²ãæ°è»œã«ãåãåãããã ããã
å·çïŒ2026幎05æ06æ¥