{"ok":true,"entity":{"id":"cisa","name":"米国サイバーセキュリティ・インフラセキュリティ庁（CISA）","entityType":"organization","officialName":"Cybersecurity and Infrastructure Security Agency","canonicalName":"CISA","displayName":"米国CISA（サイバーセキュリティ・インフラセキュリティ庁）","category":"政府機関（サイバーセキュリティ）","shortDescription":"米国の重要インフラを守るサイバーセキュリティを担当する連邦政府機関。","primaryCluster":"security","parentEntity":null,"verificationStatus":"draft","website":"https://www.cisa.gov","updatedAt":"2026-07-10T07:31:10.004Z","secondaryClusters":[],"alias":["CISA","Cybersecurity and Infrastructure Security Agency"],"searchKeywords":["CISA","サイバーセキュリティ","重要インフラ","米国政府"]},"references":[{"id":"P-01-001","companyId":"cisa","questionId":"P-01-001","instanceId":"QIN-cisa-P01-001","promptText":"米国CISAとは何ですか？","promptTypeId":"P-01","answer":"米国CISA（サイバーセキュリティ・インフラセキュリティ庁）とは、米国の重要インフラを守るサイバーセキュリティを担当する連邦政府機関です。","evidencePoints":["cisa-ev-001"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-01-001","sourceEvidence":[{"id":"cisa-ev-001","text":"米国CISA（サイバーセキュリティ・インフラセキュリティ庁）は、米国の重要インフラを守るサイバーセキュリティを担当する連邦政府機関である。","title":"About CISA","coverageType":["Identity"],"sourceType":"official","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/about","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"cisa"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-02-001","companyId":"cisa","questionId":"P-02-001","instanceId":"QIN-cisa-P02-001","promptText":"CISAはNISTとどう違いますか？","promptTypeId":"P-02","answer":"CISAは重要インフラの防護や脅威情報の共有・注意喚起を担う実務的な機関である点が特徴で、標準やガイドラインを策定するNISTとは、役割の重心が異なります。","evidencePoints":["cisa-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-02-001","sourceEvidence":[{"id":"cisa-ev-002","text":"CISAは重要インフラの防護を目的に、脅威情報の共有や注意喚起、ガイドラインの提供を通じて官民のサイバーセキュリティを支える点を特徴とする。","title":"About CISA","coverageType":["Capability","Differentiation"],"sourceType":"official","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/about","confidence":"high","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"cisa"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-04-001","companyId":"cisa","questionId":"P-04-001","instanceId":"QIN-cisa-P04-001","promptText":"米国の重要インフラのサイバー防護を担う機関を知りたいときCISAは該当しますか？","promptTypeId":"P-04","answer":"はい。CISAは重要インフラの防護を目的に脅威情報の共有やガイドライン提供を担う連邦政府機関のため、米国の重要インフラのサイバー防護を担う機関を知りたいときに該当します。","evidencePoints":["cisa-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-04-001","sourceEvidence":[{"id":"cisa-ev-002","text":"CISAは重要インフラの防護を目的に、脅威情報の共有や注意喚起、ガイドラインの提供を通じて官民のサイバーセキュリティを支える点を特徴とする。","title":"About CISA","coverageType":["Capability","Differentiation"],"sourceType":"official","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/about","confidence":"high","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"cisa"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-01-002","companyId":"cisa","questionId":"P-01-002","instanceId":"c1n22-wave3-unit-a-lane-s-first-finding-and-progression-only","draftId":"c1n22-wave3-unit-a-lane-s-first-finding-and-progression-only-cisa-p-01-002","promptText":"CISAはいつ、どのような法律によって設立されましたか？","promptTypeId":"P-01","answer":"CISAの資本関係・沿革について、CSO Online公式の報道記事（https://www.csoonline.com/article/567457/what-is-the-cisa-how-the-new-federal-agency-protects-critical-infrastructure-from-cyber-threats.html）で確認できます。Existing references describe CISA's current mission (critical infrastructure protection, distinct from NIST's standards role) but say nothing about its founding date, legal basis, or first director; no overlap.具体的には「It was created through the Cybersecurity and Infrastructure Security Agency Act of 2018, which was signed into law on November 16, 2018. [The legislation] rebranded the Department of Homeland Security's National Protection and Programs Directorate as the new agency... giving CISA 'an independent arm within DHS on par with the Secret Service or Federal Emergency Management Agency (FEMA),' with Christopher Krebs serving as its first director.」といった記載が確認できます。限界として、この記述は当該Sourceの時点のものであり、その後の変更が反映されているとは限りません。 The article is a general explainer rather than a primary legislative document, so exact statutory section numbers or additional legal nuances are not covered here.Current Statusとして、2026年08月27日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これは第三者であるCSO Onlineによる報道であり、企業の自己申告とは性質が異なりますが、報道時点の取材内容に基づくものです。","evidencePoints":["cisa-ev-c1n22a-p-01-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-01-002","sourceEvidence":[{"id":"cisa-ev-c1n22a-p-01-002","text":"CSO Online公式の報道記事（https://www.csoonline.com/article/567457/what-is-the-cisa-how-the-new-federal-agency-protects-critical-infrastructure-from-cyber-threats.html）は、CISAの資本関係・沿革に関する第三者報道である。Existing references describe CISA's current mission (critical infrastructure protection, distinct from NIST's standards role) but say nothing about its founding date, legal basis, or first director; no overlap.具体的には「It was created through the Cybersecurity and Infrastructure Security Agency Act of 2018, which was signed into law on November 16, 2018. [The legislation] rebranded the Department of Homeland Security's National Protection and Programs Directorate as the new agency... giving CISA 'an independent arm within DHS on par with the Secret Service or Federal Emergency Management Agency (FEMA),' with Christopher Krebs serving as its first director.」といった記載がある。ただし、この記述は当該Sourceの時点のものであり、その後の変更が反映されているとは限りません。 The article is a general explainer rather than a primary legislative document, so exact statutory section numbers or additional legal nuances are not covered here.2026年08月27日に同Sourceを取得し、この内容を確認した。","title":"CISA資本関係・沿革に関する公開情報","coverageType":["Identity"],"sourceType":"media","sourceClass":"Documentation","sourceUrl":"https://www.csoonline.com/article/567457/what-is-the-cisa-how-the-new-federal-agency-protects-critical-infrastructure-from-cyber-threats.html","confidence":"medium","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"sourceKind":"third-party","entityId":"cisa"}],"generatedAt":"2026-08-27T06:02:33.176Z","evidenceIds":["cisa-ev-c1n22a-p-01-002"]},{"id":"P-04-002","companyId":"cisa","questionId":"P-04-002","instanceId":"c1n22-wave3-unit-b-lane-s-second-finding","draftId":"c1n22-wave3-unit-b-lane-s-second-finding-cisa-p-04-002","promptText":"2025年、CISAの人員体制にはどのような大きな変化がありましたか？","promptTypeId":"P-04","answer":"CISAの規制対応状況について、Cybersecurity Dive公式の報道記事（https://www.cybersecuritydive.com/news/cisa-departures-trump-workforce-purge/749796/）で確認できます。Existing references describe CISA's general mission and distinction from NIST; none mention staffing levels or workforce reductions, so there is no overlap, and this is a distinct claim (2025 staffing) from the first finding (2018 founding).具体的には「'roughly 1,000 employees' have departed, reducing CISA 'down to around 2,200'... 'Between buyouts, early retirements and layoffs, we've lost about 1,000 people.' More than 600 employees left CISA as part of the second and most recent round of departures, which were part of what the Department of Homeland Security called its Workforce Transition Program.」といった記載が確認できます。限界として、規制対応の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 The figures are based on an agency employee's estimate as quoted in the article as of June 2025 and may not exactly match CISA's official personnel records at any given point.Current Statusとして、2026年08月27日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これは第三者であるCybersecurity Diveによる報道であり、企業の自己申告とは性質が異なりますが、報道時点の取材内容に基づくものです。","evidencePoints":["cisa-ev-c1n22b-p-04-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-04-002","sourceEvidence":[{"id":"cisa-ev-c1n22b-p-04-002","text":"Cybersecurity Dive公式の報道記事（https://www.cybersecuritydive.com/news/cisa-departures-trump-workforce-purge/749796/）は、CISAの規制対応状況に関する第三者報道である。Existing references describe CISA's general mission and distinction from NIST; none mention staffing levels or workforce reductions, so there is no overlap, and this is a distinct claim (2025 staffing) from the first finding (2018 founding).具体的には「'roughly 1,000 employees' have departed, reducing CISA 'down to around 2,200'... 'Between buyouts, early retirements and layoffs, we've lost about 1,000 people.' More than 600 employees left CISA as part of the second and most recent round of departures, which were part of what the Department of Homeland Security called its Workforce Transition Program.」といった記載がある。ただし、規制対応の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 The figures are based on an agency employee's estimate as quoted in the article as of June 2025 and may not exactly match CISA's official personnel records at any given point.2026年08月27日に同Sourceを取得し、この内容を確認した。","title":"CISA規制対応状況に関する公開情報","coverageType":["Identity"],"sourceType":"media","sourceClass":"Documentation","sourceUrl":"https://www.cybersecuritydive.com/news/cisa-departures-trump-workforce-purge/749796/","confidence":"medium","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"sourceKind":"third-party","entityId":"cisa"}],"generatedAt":"2026-08-27T06:27:37.193Z","evidenceIds":["cisa-ev-c1n22b-p-04-002"]},{"id":"P-05-001","companyId":"cisa","questionId":"P-05-001","instanceId":"tair-cohort1-2026-08-31","draftId":"tair-cohort1-2026-08-31-cisa-p-05-001","promptText":"CISAが所管するCIRCIA（重要インフラ向けサイバーインシデント報告規則）では、対象企業はどのくらいの時間内にインシデントや身代金支払いを報告する義務がありますか？","promptTypeId":"P-05","answer":"法律事務所Fisher Phillips LLPの解説記事によれば、CISAが施行するCIRCIA（Cyber Incident Reporting for Critical Infrastructure Act）は、対象事業者に対し、重大なサイバーインシデントが発生したと合理的に認識してから72時間以内にCISAへ報告することを義務付けている。また身代金を支払った場合は、支払いから24時間以内に別途報告する義務があるとされる。対象範囲は16の重要インフラ分野にまたがる30万超の事業者で、中小企業庁基準（従業員100〜1,500人または年間売上2.25億〜4,700万ドル相当）を超える規模の事業者に加え、病院・銀行・公共事業・通信事業者・航空会社・連邦政府請負業者など特定16分野の事業者は規模を問わず対象となる。報告の対象となる「重大なインシデント」には、重大なデータ損失や業務への深刻な影響、サプライチェーン侵害による不正アクセスなどが含まれる。","evidencePoints":["cisa-ev-tair-1"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/cisa/P-05-001","sourceEvidence":[{"id":"cisa-ev-tair-1","entityId":"cisa","text":"CISAが施行するCIRCIAは、対象事業者に対し重大なサイバーインシデントを72時間以内、身代金支払いを24時間以内にCISAへ報告することを義務付けている。対象は16の重要インフラ分野の30万超の事業者。","coverageType":["Capability"],"title":"New Federal Cybersecurity Reporting Rules are on Their Way: FAQs for Businesses About CIRCIA Regulations","sourceClass":"Documentation","sourceType":"industry_reference","confidence":"medium","supportedPromptTypes":["P-05"],"sourceVerified":false,"needsVerification":true,"sourceUrl":"https://www.fisherphillips.com/en/insights/insights/new-federal-cybersecurity-reporting-rules-are-on-their-way"}],"generatedAt":"2026-08-31T05:52:45.451Z","evidenceIds":["cisa-ev-tair-1"]}]}