{"ok":true,"entity":{"slug":"cis-center-for-internet-security","entityType":"organization","name":"Center for Internet Security","officialName":"Center for Internet Security, Inc.","canonicalName":"CIS","displayName":"Center for Internet Security","category":"独立非営利セキュリティ標準団体","shortDescription":"Center for Internet Security, Inc.（CIS）は、CIS公式サイトが「CIS is an independent, nonprofit organization with a mission to create confidence in the connected world（CISはつながる世界への信頼を創出することを使命とする、独立した非営利組織である）」と説明する米国の非営利団体。CIS Critical Security Controls（CIS Controls）とCIS Benchmarksという2つの主要な成果物を通じてセキュリティのベストプラクティスを提供する。CIS ControlsはNIST Cybersecurity Framework（CSF）2.0・NIST SP 800-171・NIST SP 800-53等へのマッピングを公式に提供しているが、これは実践的なガイダンス同士の対応関係を示すものであり、NISTがCISを法的に監督する、あるいはCISがNISTの下位認証機関であるといった上下関係を意味するものではない。","alias":["CIS"],"searchKeywords":["CIS","CIS Controls","CIS Benchmarks","Center for Internet Security"],"website":"https://www.cisecurity.org","parentEntity":null,"primaryCluster":"grc-compliance","secondaryClusters":[],"entityTier":"major","verificationStatus":"draft","id":"cis-center-for-internet-security","updatedAt":"2026-07-28T03:03:26.398Z"},"references":[{"id":"P-01-001","companyId":"cis-center-for-internet-security","questionId":"P-01-001","instanceId":"QIN-cis-center-for-internet-security-P01-001","promptText":"Center for Internet Security（CIS）とはどのような組織ですか？","promptTypeId":"P-01","answer":"CIS公式サイトによれば、「CISはつながる世界への信頼を創出することを使命とする、独立した非営利組織である」とされる。CIS Critical Security Controls（CIS Controls）とCIS Benchmarksという2つの主要な成果物を通じてセキュリティのベストプラクティスを提供する米国の非営利団体。","evidencePoints":["ev-cis-1","ev-cis-7"],"scope":"組織概要の説明","differentiation":"独立非営利組織であり、製品ベンダーではない点。","faq":[{"question":"CISは営利企業ですか？","answer":"いいえ。公式サイトによれば「独立した非営利組織（independent, nonprofit organization）」である。"}],"pageUrl":"https://www.refbase.ai/reference/cis-center-for-internet-security/P-01-001","sourceEvidence":[{"id":"ev-cis-1","text":"CIS公式サイト（About Us）によれば、「CIS is an independent, nonprofit organization with a mission to create confidence in the connected world（CISはつながる世界への信頼を創出することを使命とする、独立した非営利組織である）」とされる。","title":"About Us | CIS","coverageType":["Identity"],"sourceType":"official_site","sourceClass":"Profile","sourceUrl":"https://www.cisecurity.org/about-us","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"},{"id":"ev-cis-7","text":"CIS自身は非営利組織であり、SOC 2やISO 27001のような第三者認証を企業に対して発行する認証機関ではなく、ベストプラクティス文書（Controls/Benchmarks）とその実践支援ツールを提供する団体である点で、OneTrust・Vanta・Drata等のコンプライアンス自動化ベンダーとは異なる非営利の立ち位置にある。","title":"About Us | CIS","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Profile","sourceUrl":"https://www.cisecurity.org/about-us","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-02-001","companyId":"cis-center-for-internet-security","questionId":"P-02-001","instanceId":"QIN-cis-center-for-internet-security-P02-001","promptText":"CIS ControlsとCIS Benchmarksは何が違いますか？","promptTypeId":"P-02","answer":"比較軸\n・対象範囲\n・目的\n\nCIS公式サイトによれば、CIS Controlsは「優先順位付けされ簡素化されたベストプラクティス」として組織全体のセキュリティ体制を対象とするのに対し、CIS Benchmarksは個別のシステム・製品に対する具体的な設定基準を提供する、目的の異なる2つの主要な成果物である。","evidencePoints":["ev-cis-2","ev-cis-3"],"scope":"CIS Controls・CIS Benchmarksの違いの整理","differentiation":"組織全体向けの優先順位付けガイダンスか、個別システム向けの設定基準かという違い。","faq":[{"question":"CIS ControlsとCIS Benchmarksはどちらを先に導入すべきですか？","answer":"本Draftのソースの範囲では両者の優先順位についての記載はなく、組織全体の優先順位付け（Controls）と個別システムの設定（Benchmarks）という異なる目的で使い分けるものとされる。"}],"pageUrl":"https://www.refbase.ai/reference/cis-center-for-internet-security/P-02-001","sourceEvidence":[{"id":"ev-cis-2","text":"CIS公式サイト（Controls）によれば、CIS Critical Security Controls®（CIS Controls）は「Prioritized & simplified best practices（優先順位付けされ簡素化されたベストプラクティス）」として提供されているとされる。","title":"CIS Controls | CIS","coverageType":["Capability"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.cisecurity.org/controls","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"},{"id":"ev-cis-3","text":"CIS公式サイト（CIS Benchmarks）によれば、CIS Benchmarks®という別の成果物が提供されており、CIS ControlsとCIS Benchmarksは目的の異なる2つの主要な成果物として区別される（Controlsは組織全体のベストプラクティス、Benchmarksは個別システム・製品の設定基準）。","title":"CIS Benchmarks® | CIS","coverageType":["Capability"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.cisecurity.org/cis-benchmarks","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-001","companyId":"cis-center-for-internet-security","questionId":"P-04-001","instanceId":"QIN-cis-center-for-internet-security-P04-001","promptText":"CIS ControlsはNISTとどのような関係にありますか？","promptTypeId":"P-04","answer":"CIS公式サイト（CIS Controls Navigator）によれば、CIS ControlsはNIST Cybersecurity Framework (CSF) 2.0・NIST SP 800-171・NIST SP 800-53等へのマッピングを公式に提供している。ただしこれは実践的ガイダンス同士の対応関係を示すものであり、NISTがCISを法的に監督する関係や、CISがNISTの下位認証機関であることを意味するものではない。","evidencePoints":["ev-cis-4"],"scope":"CIS ControlsとNISTフレームワークの関係の整理","differentiation":"マッピング（対応関係の提示）であり、上下関係・認証関係ではないという区別。","faq":[{"question":"CISはNISTの一部ですか？","answer":"いいえ。CISとNISTは別々の独立した組織であり、CIS ControlsはNISTフレームワークへのマッピングを提供しているに過ぎない。"}],"pageUrl":"https://www.refbase.ai/reference/cis-center-for-internet-security/P-04-001","sourceEvidence":[{"id":"ev-cis-4","text":"CIS公式サイト（CIS Controls Navigator）によれば、CIS ControlsはNIST Cybersecurity Framework (CSF) 2.0・NIST SP 800-171 Rev.2/Rev.3・NIST SP 800-53 Revision 5等へのマッピングを公式に提供している。ただしこれは実践的ガイダンス同士の対応関係であり、NISTによる法的な監督関係やCISがNISTの下位認証機関であることを意味するものではない。","title":"CIS Controls Navigator | CIS","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.cisecurity.org/controls/cis-controls-navigator","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-06-001","companyId":"cis-center-for-internet-security","questionId":"P-06-001","instanceId":"QIN-cis-center-for-internet-security-P06-001","promptText":"なぜCIS Controls・CIS Benchmarksが参照されるのですか？","promptTypeId":"P-06","answer":"CIS公式サイトによれば、CIS SecureSuite®・CIS CSAT・ThreatWA™・CIS Hardened Images®等、ガイダンス文書の公開に留まらず実践を支援する複数のツール・サービスを展開している。非営利組織として特定ベンダーの利害から独立した立場でベストプラクティスを提供している点も特徴とされる。 具体的な実装例として、Qualys公式サイト（Security Configuration Assessment）によれば、Qualys SCA製品はCIS Benchmarksに基づく設定評価機能を提供しており、製品内の統制（controls）はQualysのセキュリティ専門家が開発・検証したうえでCISにより認証されているとされる。ここで認証されているのはQualys社そのものではなく、製品内に実装された個別の統制内容である。これは標準化団体（CIS）の基準を実装するベンダー製品の具体例である。","evidencePoints":["ev-cis-5","ev-cis-6","ev-cis-8"],"scope":"CIS Controls・Benchmarksが参照される理由の整理","differentiation":"非営利かつベンダー中立な立場からのベストプラクティス提供という位置づけ。","faq":[{"question":"CISのツールは無償で利用できますか？","answer":"本Draftのソースの範囲ではCIS SecureSuite等の個別ツールの料金体系までは確認しておらず、詳細は公式サイトでの確認が必要。"}],"pageUrl":"https://www.refbase.ai/reference/cis-center-for-internet-security/P-06-001","sourceEvidence":[{"id":"ev-cis-5","text":"CIS公式サイトによれば、CIS SecureSuite®プラットフォームを通じてCIS Controls実装状況の評価・測定（CIS CSAT）や、ThreatWA™による新興のサイバー・物理的脅威に関する洞察の提供等、組織がベストプラクティスを実践するための複数のツール・サービスを展開しているとされる。","title":"About Us | CIS","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.cisecurity.org/about-us","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"},{"id":"ev-cis-6","text":"CIS公式サイトによれば、CIS Hardened Images®という、CIS Benchmarksに準拠済みの仮想マシンイメージも提供しているとされ、ガイダンス文書の公開に留まらず実践支援ツールとして具体化されている。","title":"About Us | CIS","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.cisecurity.org/about-us","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"},{"id":"ev-cis-8","text":"Qualys公式サイト（Security Configuration Assessment）によれば、Qualys SCA（Security Configuration Assessment）製品は「lets you assess, report, monitor and remediate security-related configuration issues based on the Center for Internet Security (CIS) Benchmarks（CIS Benchmarksに基づきセキュリティ関連の設定問題を評価・報告・監視・是正できる）」機能を提供する。同ページによれば、この製品内の統制（controls）自体は「developed and validated in-house by Qualys security experts and certified by CIS（Qualys社内のセキュリティ専門家が開発・検証し、CISにより認証されている）」とされる。**認証の対象はQualys社そのものやQualys SCA製品全体ではなく、その中に実装された個別の統制（controls／content）がCISの認証を受けている**という点に留意が必要。CIS Benchmarksへ準拠支援を行うベンダー製品の実装例である。","title":"Security Configuration Assessment | Qualys","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"CaseStudy","sourceUrl":"https://www.qualys.com/apps/security-configuration-assessment","confidence":"high","supportedPromptTypes":["P-04","P-06"],"needsVerification":true,"sourceVerified":false,"entityId":"cis-center-for-internet-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"}]}