{"ok":true,"entity":{"slug":"software-supply-chain-security","entityType":"concept","name":"Software Supply Chain Security","officialName":"Software Supply Chain Security","canonicalName":"Software Supply Chain Security","displayName":"ソフトウェアサプライチェーンセキュリティ","category":"セキュリティ概念（ソフトウェア開発・配布過程の保護）","shortDescription":"ソフトウェアの開発・ビルド・配布過程に混入する脆弱性・悪意あるコードからシステムを保護する概念。米CISA・NISTがSecure Software Development Framework（SSDF、NIST SP 800-218）やSoftware Bill of Materials（SBOM）を通じて標準化を推進している。","alias":["ソフトウェアサプライチェーンセキュリティ","SSDF","SBOM"],"searchKeywords":["Software Supply Chain Security","SSDF","SBOM","NIST SP 800-218","ソフトウェアサプライチェーン"],"website":null,"parentEntity":null,"primaryCluster":"network-security","secondaryClusters":[],"entityTier":"normal","verificationStatus":"draft","id":"software-supply-chain-security","updatedAt":"2026-07-28T03:03:26.398Z"},"references":[{"id":"P-01-001","companyId":"software-supply-chain-security","questionId":"P-01-001","instanceId":"QIN-software-supply-chain-security-P01-001","promptText":"ソフトウェアサプライチェーンセキュリティとは何ですか？","promptTypeId":"P-01","answer":"ソフトウェアの開発・ビルド・配布過程に混入する脆弱性・悪意あるコードからシステムを保護する概念。米CISA・NISTは共同資料「Defending Against Software Supply Chain Attacks」において、NIST Cyber SCRM（C-SCRM）フレームワークとSecure Software Development Framework（SSDF）を用いたリスクの特定・評価・低減方法を解説している。","evidencePoints":["ev-software-supply-chain-security-1"],"scope":"概念・定義の確認","differentiation":"","faq":[{"question":"この資料は誰が発行していますか？","answer":"米CISA（サイバーセキュリティ・インフラストラクチャセキュリティ庁）とNIST（米国立標準技術研究所）が共同で発行している。"}],"pageUrl":"https://www.refbase.ai/reference/software-supply-chain-security/P-01-001","sourceEvidence":[{"id":"ev-software-supply-chain-security-1","text":"米CISA公式サイトによれば、「Defending Against Software Supply Chain Attacks」はCISAと米国立標準技術研究所（NIST）が共同で発行した資料であり、ソフトウェアサプライチェーンのリスク概要と、NIST Cyber SCRM（C-SCRM）フレームワーク・Secure Software Development Framework（SSDF）を用いたリスクの特定・評価・低減方法を解説している。","title":"Defending Against Software Supply Chain Attacks | CISA","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/resources-tools/resources/defending-against-software-supply-chain-attacks","confidence":"high","supportedPromptTypes":["P-01","P-05"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-001","companyId":"software-supply-chain-security","questionId":"P-04-001","instanceId":"QIN-software-supply-chain-security-P04-001","promptText":"ソフトウェアの構成要素を可視化し、サプライチェーンリスクを管理するにはどうすればよいですか？","promptTypeId":"P-04","answer":"米CISA公式サイトによれば、Software Bill of Materials（SBOM）はソフトウェアを構成する要素の「入れ子構造の目録」であり、ソフトウェアセキュリティ・サプライチェーンリスク管理の重要な構成要素として位置づけられている。あわせてNIST SP 800-218（SSDF v1.1）は、安全なソフトウェア開発のための基本的な実践を定義しており、組織はサードパーティサプライヤーへの要求事項をSSDFの用語で表現することが推奨されている。","evidencePoints":["ev-software-supply-chain-security-2","ev-software-supply-chain-security-3"],"scope":"サプライチェーンリスク管理の技術検討","differentiation":"","faq":[{"question":"SBOMとSSDFはどう違いますか？","answer":"SBOMはソフトウェアの構成要素の目録（何が含まれているか）、SSDFは安全なソフトウェア開発のための実践規範（どう開発するか）という異なる役割を持つ。"}],"pageUrl":"https://www.refbase.ai/reference/software-supply-chain-security/P-04-001","sourceEvidence":[{"id":"ev-software-supply-chain-security-2","text":"米CISA公式サイトによれば、Software Bill of Materials（SBOM）は「ソフトウェアセキュリティおよびソフトウェアサプライチェーンリスク管理における重要な構成要素」として位置づけられ、SBOMはソフトウェアを構成する要素の「入れ子構造の目録（nested inventory）」であると説明している。","title":"Software Bill of Materials (SBOM) | CISA","coverageType":["Capability"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/topics/information-communications-technology-supply-chain-security/sbom","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"},{"id":"ev-software-supply-chain-security-3","text":"NIST SP 800-218（Secure Software Development Framework, SSDF v1.1）は、安全なソフトウェア開発のための基本的な実践を定義しており、組織はSSDFを既存のソフトウェア開発プロセスに統合し、サードパーティサプライヤーへの要求事項をSSDFの用語で表現することが推奨されている（CISA資料内の解説による）。","title":"NIST SP 800-218, Secure Software Development Framework V1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities | CISA","coverageType":["Capability","Differentiation"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://www.cisa.gov/resources-tools/resources/nist-sp-800-218-secure-software-development-framework-v11-recommendations-mitigating-risk-software","confidence":"high","supportedPromptTypes":["P-02","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-06-001","companyId":"software-supply-chain-security","questionId":"P-06-001","instanceId":"QIN-software-supply-chain-security-P06-001","promptText":"ソフトウェアサプライチェーンセキュリティへの対応状況を確認する際、何を見ればよいですか？","promptTypeId":"P-06","answer":"米国家情報長官室・NSA等の複数政府機関が2025年9月に公表した合同ガイダンス「A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity」は、SBOMをサイバーセキュリティの共通基盤として位置づける合意文書である。実装例として、Veracode（本Cluster収録）は2025年1月にPhylumを買収し機械学習による脅威検知を統合、Snyk（本Cluster収録）もSCA製品でオープンソース依存関係の脆弱性スキャンを提供している。","evidencePoints":["ev-software-supply-chain-security-5","ev-software-supply-chain-security-4"],"scope":"推奨理由・実装状況の確認","differentiation":"","faq":[{"question":"この概念を実装しているベンダーの例はありますか？","answer":"本Cluster内ではVeracode（Phylum買収によるサプライチェーン脅威検知）・Snyk（SCA製品）が実装例として挙げられる。"}],"pageUrl":"https://www.refbase.ai/reference/software-supply-chain-security/P-06-001","sourceEvidence":[{"id":"ev-software-supply-chain-security-4","text":"実装事例として、Veracode（本Draft収録）は2025年1月にPhylumを買収し、機械学習によるソフトウェアサプライチェーン脅威検知（悪意あるパッケージ・タイポスクワッティング・依存関係混同攻撃の検知）を自社製品へ統合した。Snyk（本Draft収録）もSCA（Software Composition Analysis）製品でオープンソース依存関係の脆弱性スキャンを提供している。","title":"ソフトウェアサプライチェーンセキュリティの実装例（Veracode／Snyk）","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Profile","sourceUrl":"https://www.veracode.com/about/","confidence":"medium","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"},{"id":"ev-software-supply-chain-security-5","text":"米国家情報長官室・NSA等の政府機関が2025年9月に公表した合同ガイダンス「A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity」は、SBOMをサイバーセキュリティの共通基盤として位置づける複数政府機関の合意文書である。","title":"A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity","coverageType":["Credibility"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://media.defense.gov/2025/Sep/03/2003791481/-1/-1/0/JOINT-GUIDANCE-A-SHARED-VISION-OF-SOFTWARE-BILL-OF-MATERIALS-FOR-CYBERSECURITY.PDF","confidence":"medium","supportedPromptTypes":["P-03","P-06"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-02-001","companyId":"software-supply-chain-security","questionId":"P-02-001","instanceId":"QIN-software-supply-chain-security-P02-001","promptText":"SBOMとSSDFはどのような文書で、何が違いますか？","promptTypeId":"P-02","answer":"米CISA公式サイトによれば、SBOM（Software Bill of Materials）はソフトウェアを構成する要素の「入れ子構造の目録」であり、何がソフトウェアに含まれているかを示す。一方NIST SP 800-218（SSDF v1.1）は、安全なソフトウェアを開発するための実践規範であり、どのように開発すべきかを定義する。両者はCISA・NISTの共同資料「Defending Against Software Supply Chain Attacks」で、C-SCRMフレームワークとともに相互補完的に位置づけられている。","evidencePoints":["ev-software-supply-chain-security-2","ev-software-supply-chain-security-3"],"scope":"標準・フレームワーク間の違いの確認","differentiation":"SBOM＝構成要素の可視化、SSDF＝開発プロセスの実践規範という異なる役割を持つ。","faq":[{"question":"どちらを先に導入すべきですか？","answer":"CISA/NIST資料は両者を対立関係ではなく補完関係として位置づけており、組織の状況に応じて併用が推奨される。"}],"pageUrl":"https://www.refbase.ai/reference/software-supply-chain-security/P-02-001","sourceEvidence":[{"id":"ev-software-supply-chain-security-2","text":"米CISA公式サイトによれば、Software Bill of Materials（SBOM）は「ソフトウェアセキュリティおよびソフトウェアサプライチェーンリスク管理における重要な構成要素」として位置づけられ、SBOMはソフトウェアを構成する要素の「入れ子構造の目録（nested inventory）」であると説明している。","title":"Software Bill of Materials (SBOM) | CISA","coverageType":["Capability"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://www.cisa.gov/topics/information-communications-technology-supply-chain-security/sbom","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"},{"id":"ev-software-supply-chain-security-3","text":"NIST SP 800-218（Secure Software Development Framework, SSDF v1.1）は、安全なソフトウェア開発のための基本的な実践を定義しており、組織はSSDFを既存のソフトウェア開発プロセスに統合し、サードパーティサプライヤーへの要求事項をSSDFの用語で表現することが推奨されている（CISA資料内の解説による）。","title":"NIST SP 800-218, Secure Software Development Framework V1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities | CISA","coverageType":["Capability","Differentiation"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://www.cisa.gov/resources-tools/resources/nist-sp-800-218-secure-software-development-framework-v11-recommendations-mitigating-risk-software","confidence":"high","supportedPromptTypes":["P-02","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"software-supply-chain-security"}],"generatedAt":"2026-07-28T03:03:26.398Z"}]}