{"kind":"rule","id":"SEC-001","hash":"8e6c53174bef8ca55cea3f34e97f1aad0f6f0c55a15111ba9f2df8613d55fe55","record":{"id":"SEC-001","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"修正対象と稼働バージョンを照合する","en":"Reconcile advisories with deployed versions"},"summary":{"ja":"依存パッケージや自前運用の製品を使う環境。ソースのlockfileだけでなく、実際に配布・稼働するものが対象です。","en":"Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles."},"category":"known-vulnerability","surfaces":["dependencies","web-app"],"applicability":{"ja":"依存パッケージや自前運用の製品を使う環境。ソースのlockfileだけでなく、実際に配布・稼働するものが対象です。","en":"Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles."},"targets":[{"ja":"lockfile・パッケージ定義・SBOM","en":"Lockfiles, package manifests, SBOMs"},{"ja":"製品台帳・コンテナのダイジェスト・稼働バージョン","en":"Product inventory, image digests, running versions"}],"checks":[{"ja":"OSV・開発元の最新アドバイザリとバージョンを照合し、影響条件と根拠を記録する。","en":"Match versions against OSV and current vendor advisories; record affected conditions and evidence."},{"ja":"悪用が確認されたものと外部から到達可能なものを優先し、更新が本番に反映されたか確認する。","en":"Prioritize active exploitation and reachable assets; verify deployment of updates."}],"remediation":[{"ja":"互換性を確認して更新し、すぐ更新できない場合は開発元の回避策と公開範囲の制限を検討する。","en":"Test and update; if immediate updating is unavailable, assess vendor mitigations and exposure restrictions."}],"completionEvidence":[{"ja":"稼働バージョン・対象アドバイザリ・適用した更新・必要な動作確認の結果を残す。","en":"Record the running version, advisory, deployed fix, and relevant validation results."}],"limitations":[{"ja":"このDBにCVEがないことは安全の証拠になりません。閉じた製品の内部実装や実際の侵害は別途調査が必要です。","en":"Absence from this dataset is not evidence of safety. Closed-source internals and actual compromise require separate investigation."}],"incidentIds":["axios-npm-2026","digital-agency-gss-2026","equifax-2017","forticloud-sso-2026","gyazo-2026","kddi-isp-2026","metabase-2026","moveit-2023","nidek-website-2026","nishiyama-2026","openai-huggingface-eval-2026","postman-shai-hulud-2025","prontest-cloud-2026","react2shell-2025","rust-arrayref-2026","trivy-supply-chain-2026","voising-bi-2026"],"references":[{"title":"OSV API","url":"https://google.github.io/osv.dev/api/"},{"title":"CISA KEV","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-002","hash":"fcf58a1b53fff45725fbbe1f19fa49d638d0ea143a2444428247b31f3c62de1a","record":{"id":"SEC-002","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"MFAの方式と適用漏れを確認する","en":"Inspect MFA methods and coverage"},"summary":{"ja":"人がログインする管理画面・SSO・データ基盤。サービスアカウントは別の認証制御として扱います。","en":"Human access to administration, SSO, and data platforms. Inspect service identities separately."},"category":"credentials","surfaces":["identity"],"applicability":{"ja":"人がログインする管理画面・SSO・データ基盤。サービスアカウントは別の認証制御として扱います。","en":"Human access to administration, SSO, and data platforms. Inspect service identities separately."},"targets":[{"ja":"IdP・SaaSの認証ポリシーと委託先アカウント","en":"IdP/SaaS policies and contractor accounts"},{"ja":"回復手段・例外設定・管理者認証","en":"Recovery methods, exceptions, administrator authentication"}],"checks":[{"ja":"MFA必須の範囲を管理者・委託先・例外まで確認し、未登録を見落とさない。","en":"Check enforcement for administrators, contractors, exceptions, and unenrolled accounts."},{"ja":"プッシュ承認の連打やフィッシングに対する制御と、回復経路が認証を迂回しないか確認する。","en":"Inspect repeated-prompt and phishing controls, including recovery paths."}],"remediation":[{"ja":"対応可能な環境でフィッシング耐性のある認証を採用し、例外には期限と担当者を設定する。","en":"Adopt phishing-resistant authentication where supported; assign an owner and expiry to exceptions."}],"completionEvidence":[{"ja":"対象アカウントの適用率と、未認証の管理操作が拒否される検証を残す。","en":"Record coverage and evidence that administrative access without required authentication is rejected."}],"limitations":[{"ja":"MFAは端末侵害や認証後のセッション窃取を防ぐ保証ではありません。IdPにアクセスできなければ未確認です。","en":"MFA does not guarantee protection against compromised endpoints or stolen sessions. Missing IdP access means unverified."}],"incidentIds":["anthropic-cyber-evals-2026","askul-2025","awabank-test-environment-2026","digital-agency-gss-2026","forticloud-sso-2026","gainsight-oauth-2025","nishiyama-2026","openai-mixpanel-2025","prontest-cloud-2026","quick-2025","snowflake-unc5537-2024","uber-2022"],"references":[{"title":"Cloudflare: phishing attack blocked","url":"https://blog.cloudflare.com/2022-07-sms-phishing-attacks/"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-003","hash":"fa4a4a16010e066b0c6208029e5cf0d1e65b0a96a18bfd0463081b7681220a25","record":{"id":"SEC-003","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"端末とセッションの失効経路を確認する","en":"Inspect endpoints and session revocation"},"summary":{"ja":"従業員端末やサポート添付ファイルから、認証済みセッションが持ち出され得る環境。","en":"Environments where endpoints or support files can expose authenticated sessions."},"category":"endpoint","surfaces":["endpoint","identity","support"],"applicability":{"ja":"従業員端末やサポート添付ファイルから、認証済みセッションが持ち出され得る環境。","en":"Environments where endpoints or support files can expose authenticated sessions."},"targets":[{"ja":"端末管理・SSOセッション設定","en":"Endpoint management and SSO session policies"},{"ja":"HAR・サポート添付・ログアウト処理","en":"HAR/support attachments and logout handlers"}],"checks":[{"ja":"HAR等を送る前にCookie・Authorization・個人情報が除去される手順を確認する。実値は出力しない。","en":"Verify sanitization of cookies, Authorization headers, and personal data before sending HAR files; never output values."},{"ja":"失効・再認証・管理者セッションの制限を確認し、既存セッションで操作が続けられないか検証する。","en":"Inspect revocation, reauthentication, and administrator-session limits; verify old sessions cannot continue acting."}],"remediation":[{"ja":"管理端末とセッション制御を整え、漏洩疑いのセッションを担当者の承認範囲で失効する。","en":"Strengthen managed endpoints and session controls; revoke suspected sessions within granted authority."}],"completionEvidence":[{"ja":"合成したテストセッションが失効後に拒否される証拠と、添付ファイルの除去検査を残す。","en":"Record rejection of synthetic revoked sessions and attachment sanitization checks."}],"limitations":[{"ja":"リポジトリだけでは端末の状態を確認できません。HTTPOnly等のCookie属性だけで端末マルウェアへの耐性を判断しません。","en":"A repository cannot establish endpoint health. Cookie flags alone do not establish resistance to endpoint malware."}],"incidentIds":["askul-2025","axios-npm-2026","circleci-2023","okta-support-2023","openai-mixpanel-2025","quick-2025","rust-arrayref-2026","uber-2022"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-004","hash":"0bc3057e7502f695450d42cbdbb3bb9f0add66df1feb19fe0866e2ca0a8f41d6","record":{"id":"SEC-004","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"配布物と添付ファイルへの秘密情報の混入を確認する","en":"Inspect artifacts and attachments for secret inclusion"},"summary":{"ja":"コード・ビルド成果物・コンテナ・サポート資料を保存または配布する環境。","en":"Environments storing or distributing code, artifacts, containers, or support material."},"category":"credentials","surfaces":["repositories","containers","ci","support"],"applicability":{"ja":"コード・ビルド成果物・コンテナ・サポート資料を保存または配布する環境。","en":"Environments storing or distributing code, artifacts, containers, or support material."},"targets":[{"ja":"公開設定・Git履歴・配布用の成果物","en":"Visibility settings, Git history, distribution artifacts"},{"ja":"Dockerfile・中間レイヤー・CIログ・添付手順","en":"Dockerfiles, image layers, CI logs, attachment procedures"}],"checks":[{"ja":"許可されたスキャナーで確認し、ファイル・位置・種類だけを記録する。秘密の実値や環境変数全体を出力しない。","en":"Use authorized scanners; record only location and type, never secret values or whole environments."},{"ja":"最終ファイルを削除してもGit履歴やイメージのレイヤーに残らないか、配布対象全体を確認する。","en":"Check Git history and image layers as well as the final filesystem."}],"remediation":[{"ja":"ビルド時の秘密はsecret mount等に移し、ログと添付の除去処理を整備する。漏洩した鍵はSEC-005で失効を確認する。","en":"Use build-time secret mechanisms and sanitization. Verify revocation of leaked keys with SEC-005."}],"completionEvidence":[{"ja":"合成した秘密の検出テストと、成果物検査の対象範囲・結果を残す。","en":"Record synthetic-secret test results and the coverage of artifact inspection."}],"limitations":[{"ja":"秘密ファイルの読み取りは所有者の権限に従います。外部のコピーを全て消したことは証明できません。","en":"Secret-file access follows owner permissions. Deletion of all external copies cannot be established."}],"incidentIds":["anthropic-cyber-evals-2026","axios-npm-2026","campfire-2026","codecov-2021","okta-support-2023","openai-huggingface-eval-2026","postman-shai-hulud-2025","rust-arrayref-2026","sakura-billing-2026","toyota-github-2022","trivy-supply-chain-2026","unit42-ai-assisted-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-005","hash":"4b6c2d63dde3bd985a945c313d3ddbf204f4b2830230426efbd8029bb2cbe5c0","record":{"id":"SEC-005","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"更新対象の資格情報と旧鍵の失効を照合する","en":"Reconcile credential inventory and revocation"},"summary":{"ja":"資格情報の漏洩・侵害・供給元事故が疑われる環境。通常点検では実値を含まない台帳と失効手順を確認します。","en":"Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures."},"category":"credentials","surfaces":["identity","ci","cloud","data-store"],"applicability":{"ja":"資格情報の漏洩・侵害・供給元事故が疑われる環境。通常点検では実値を含まない台帳と失効手順を確認します。","en":"Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures."},"targets":[{"ja":"鍵・トークン・サービスアカウントのメタデータ台帳","en":"Metadata inventory of keys, tokens, service identities"},{"ja":"旧鍵の失効結果・利用先・失効後の監査ログ","en":"Revocation results, consumers, post-revocation audit logs"},{"ja":"OAuthの有効期限・更新トークンの再利用・未使用連携の失効記録","en":"OAuth expiry, refresh-token reuse, and revocation of unused integrations"}],"checks":[{"ja":"使用中と誤認されたものだけでなく、全対象のID・所有者・利用先・失効方法を照合する。","en":"Reconcile all affected IDs, owners, consumers, and revocation methods, including identities believed unused."},{"ja":"新しい鍵の発行と旧鍵の失効を分けて確認し、未知の追加アカウントや永続化も調査対象へ渡す。","en":"Verify issuance and revocation separately; escalate unknown accounts and persistence for investigation."},{"ja":"長期間有効な連携トークンと更新トークンを棚卸しし、有効期限・再利用制御・失効後の拒否をメタデータと承認済みの試験証拠で確認する。","en":"Inventory long-lived integration and refresh tokens; verify expiry, reuse controls, and rejection after revocation through metadata and authorized test evidence."}],"remediation":[{"ja":"利用先への切替と旧鍵の失効を段階的に行う計画を作る。本番の失効・権限変更は既存の承認範囲で実施する。","en":"Prepare staged consumer migration and revocation; production revocation and permission changes require existing authority."}],"completionEvidence":[{"ja":"台帳の全対象に失効結果が対応し、旧鍵が拒否される検証または供給元の失効記録を残す。","en":"Record revocation for every affected identity and rejection tests or provider revocation evidence."}],"limitations":[{"ja":"新しい鍵を作っただけでは完了ではありません。漏洩した鍵をAIへ渡さず、権限不足なら未確認とします。","en":"Issuing a new key alone is not completion. Never provide leaked keys to an AI; missing access means unverified."}],"incidentIds":["anthropic-claude-code-abuse-2025","anthropic-cyber-evals-2026","askul-2025","awabank-test-environment-2026","axios-npm-2026","campfire-2026","circleci-2023","cloudflare-thanksgiving-2023","codecov-2021","digital-agency-gss-2026","forticloud-sso-2026","gainsight-oauth-2025","gyazo-2026","kddi-isp-2026","metabase-2026","nishiyama-2026","okta-support-2023","openai-huggingface-eval-2026","openai-mixpanel-2025","postman-shai-hulud-2025","prontest-cloud-2026","quick-2025","react2shell-2025","rust-arrayref-2026","sakura-billing-2026","sakura-hosting-2026","temairazu-2026","times-car-2026","toyota-github-2022","trivy-supply-chain-2026","unit42-ai-assisted-2026","voising-bi-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-006","hash":"ef322bf44c1b8241baf2b84ce08f6422b46075b59a85e88eb927713bbef64e8a","record":{"id":"SEC-006","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"稼働環境の公開範囲を確認する","en":"Inspect deployed exposure boundaries"},"summary":{"ja":"クラウド・データ基盤・管理画面・ファイル転送を持つ環境。委託先が管理する資産も対象です。","en":"Cloud, data platforms, administration, and file transfer, including delegated assets."},"category":"configuration","surfaces":["cloud","data-store","web-app"],"applicability":{"ja":"クラウド・データ基盤・管理画面・ファイル転送を持つ環境。委託先が管理する資産も対象です。","en":"Cloud, data platforms, administration, and file transfer, including delegated assets."},"targets":[{"ja":"IaC・実環境の公開設定・ネットワークポリシー","en":"IaC, deployed visibility, network policies"},{"ja":"管理画面・データ保存先・委託先の資産一覧","en":"Admin interfaces, data storage, delegated asset inventory"}],"checks":[{"ja":"意図した公開先と実際の設定を照合し、匿名アクセスや広い接続元許可を確認する。","en":"Compare intended exposure with deployed settings; inspect anonymous access and broad network permissions."},{"ja":"許可された資産だけで、データを取得せずに拒否を確認する。実環境へアクセスできなければ未確認とする。","en":"Test rejection only on authorized assets without retrieving data. Without live access, mark deployed state unverified."}],"remediation":[{"ja":"公開が不要な経路を制限し、設定変更を検知する監査と責任者を用意する。","en":"Restrict unnecessary exposure; establish drift detection and ownership."}],"completionEvidence":[{"ja":"実環境の設定証拠と、想定外の接続元を拒否する確認結果を残す。","en":"Record deployed configuration and rejection of unintended access sources."}],"limitations":[{"ja":"IaCだけの確認では実環境の手動変更を見つけられません。公開サイトの存在自体を欠陥とは判断しません。","en":"IaC alone misses manual drift. A deliberately public service is not inherently a defect."}],"incidentIds":["anthropic-cyber-evals-2026","awabank-test-environment-2026","campfire-2026","digital-agency-gss-2026","forticloud-sso-2026","gyazo-2026","kddi-isp-2026","metabase-2026","moveit-2023","nidek-website-2026","nishiyama-2026","openai-huggingface-eval-2026","prontest-cloud-2026","react2shell-2025","sakura-billing-2026","sakura-hosting-2026","snowflake-unc5537-2024","temairazu-2026","times-car-2026","toyota-cloud-2023","unit42-ai-assisted-2026","voising-bi-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-007","hash":"24d16b0e16072cef37450fa3ea774f8f84c2301d0ac79c38c3d367205633d4a5","record":{"id":"SEC-007","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"CIで実行する外部コードと権限を確認する","en":"Inspect external CI code and permissions"},"summary":{"ja":"外部Action・Orb・スクリプト・ビルドツールを実行するCI。","en":"CI executing external actions, orbs, scripts, or build tools."},"category":"supply-chain","surfaces":["ci"],"applicability":{"ja":"外部Action・Orb・スクリプト・ビルドツールを実行するCI。","en":"CI executing external actions, orbs, scripts, or build tools."},"targets":[{"ja":"CIワークフロー・取得URL・Actionの参照","en":"CI workflows, download URLs, action references"},{"ja":"ジョブの権限・渡す秘密の種類・信頼境界","en":"Job permissions, secret types, trust boundaries"},{"ja":"依存パッケージのlockfile・固定インストール・公開用ジョブ","en":"Dependency lockfiles, frozen installation, and publishing jobs"}],"checks":[{"ja":"変更可能なタグやリモートスクリプトの直接実行を確認し、固定・署名・信頼できる検証手段を調べる。","en":"Inspect mutable references and direct remote-script execution; assess pinning, signatures, and trusted verification."},{"ja":"外部コードを動かすステップに不要な秘密や書込み権限が渡らないか確認する。","en":"Check whether external-code steps receive unnecessary secrets or write permissions."},{"ja":"lockfileが保存され、CIが固定インストールを使うか確認する。依存パッケージのインストール中に、別のパッケージの公開用トークンを取得できないか点検する。","en":"Check committed lockfiles and frozen installs, and whether dependency installation can access tokens that publish other packages."}],"remediation":[{"ja":"検証した参照を固定し、更新はレビューする。秘密が必要な処理と不要な処理を分離する。","en":"Pin reviewed references and review updates; separate jobs by secret requirements."}],"completionEvidence":[{"ja":"固定した参照と検証根拠、権限を絞ったCIの成功結果を残す。","en":"Record pinned references, verification evidence, and successful execution under narrowed permissions."}],"limitations":[{"ja":"固定だけでは固定先が安全だと証明できません。同じ侵害元から取ったチェックサムだけに依存しません。","en":"Pinning does not prove code is safe. A checksum from the same compromised source is insufficient."}],"incidentIds":["anthropic-cyber-evals-2026","axios-npm-2026","codecov-2021","postman-shai-hulud-2025","rust-arrayref-2026","trivy-supply-chain-2026","unit42-ai-assisted-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-008","hash":"f2471e2ab224669a418afa7fb130562e051bccc70c7a79cd70cb39641c967464","record":{"id":"SEC-008","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"侵害後に広がる管理権限を確認する","en":"Inspect privileges enabling lateral access"},"summary":{"ja":"管理者・サービスアカウント・CIが本番や別のデータ基盤へアクセスする環境。","en":"Environments where administrators, services, or CI can access production or separate data stores."},"category":"credentials","surfaces":["identity","cloud","data-store","ci"],"applicability":{"ja":"管理者・サービスアカウント・CIが本番や別のデータ基盤へアクセスする環境。","en":"Environments where administrators, services, or CI can access production or separate data stores."},"targets":[{"ja":"IAM・ロール・サービスアカウント","en":"IAM, roles, service identities"},{"ja":"本番トークン発行経路・環境間の接続","en":"Production token issuance, cross-environment access"}],"checks":[{"ja":"通常業務に必要な権限と、鍵の発行・データ一括取得・権限追加が可能な範囲を比較する。","en":"Compare job needs with credential issuance, bulk-export, and privilege-grant capabilities."},{"ja":"一つのセッションや鍵の侵害で他の環境へ到達できる経路を記録する。","en":"Document cross-environment paths available to a single compromised identity."}],"remediation":[{"ja":"権限の縮小と環境の分離を提案し、必要な業務への影響を検証する。","en":"Propose narrower roles and environment boundaries; test impact on required workflows."}],"completionEvidence":[{"ja":"許可した操作が成功し、許可していない操作が拒否されるテストを残す。","en":"Record positive tests for allowed operations and negative tests for denied operations."}],"limitations":[{"ja":"権限の広さだけで侵害を断定しません。本番ロールの変更は所有者の承認範囲に従います。","en":"Broad privileges do not establish compromise. Production role changes follow owner authorization."}],"incidentIds":["aflac-japan-2026","anthropic-claude-code-abuse-2025","anthropic-cyber-evals-2026","askul-2025","campfire-2026","circleci-2023","cloudflare-thanksgiving-2023","digital-agency-gss-2026","discord-support-vendor-2025","forticloud-sso-2026","gainsight-oauth-2025","gyazo-2026","kddi-isp-2026","metabase-2026","openai-huggingface-eval-2026","openai-mixpanel-2025","postman-shai-hulud-2025","quick-2025","react2shell-2025","sakura-billing-2026","sakura-hosting-2026","snowflake-unc5537-2024","temairazu-2026","times-car-2026","trivy-supply-chain-2026","unit42-ai-assisted-2026","voising-bi-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-009","hash":"ee5ca8e3ff31cae2c3818e2446db3453376e07ac498d71a4b9bd54aa2678f745","record":{"id":"SEC-009","version":"1.2.0","updatedAt":"2026-10-02","title":{"ja":"取得・管理操作のログが揃っているか確認する","en":"Inspect coverage of access and administration logs"},"summary":{"ja":"ファイル取得・データ一括出力・鍵発行・管理操作を提供する環境。","en":"Environments supporting file access, bulk exports, credential issuance, or administrative actions."},"category":"credentials","surfaces":["identity","data-store","support"],"applicability":{"ja":"ファイル取得・データ一括出力・鍵発行・管理操作を提供する環境。","en":"Environments supporting file access, bulk exports, credential issuance, or administrative actions."},"targets":[{"ja":"監査ログの種類・保管・検索クエリ","en":"Audit event types, retention, query coverage"},{"ja":"ファイル直接取得・鍵発行・不審な認証の通知","en":"Direct file access, credential creation, anomalous login alerts"}],"checks":[{"ja":"画面経由と直接API経由の操作が両方記録され、取得漏れがないか合成イベントで確認する。","en":"Use synthetic events to verify that UI and direct API paths are both logged."},{"ja":"大量取得や想定外の管理操作に通知が届くか確認し、秘密や個人情報はログへ出さない。","en":"Verify alerts for bulk access and unexpected administration without logging secrets or personal data."}],"remediation":[{"ja":"不足するイベントの記録と通知を整え、保存期間と調査担当者を決める。","en":"Add missing event coverage and alerts; define retention and investigation ownership."}],"completionEvidence":[{"ja":"合成イベントの操作から記録・検索・通知までの一連の証拠を残す。","en":"Record synthetic event execution, collection, query, and alert delivery."}],"limitations":[{"ja":"ログがないことは侵害がない証拠ではありません。ログを取得できなければ未確認とします。","en":"Missing logs do not establish absence of compromise. Unavailable logs mean unverified."}],"incidentIds":["aflac-japan-2026","anthropic-claude-code-abuse-2025","anthropic-cyber-evals-2026","askul-2025","awabank-test-environment-2026","axios-npm-2026","campfire-2026","cloudflare-thanksgiving-2023","digital-agency-gss-2026","discord-support-vendor-2025","forticloud-sso-2026","gainsight-oauth-2025","gyazo-2026","kddi-isp-2026","keio-ransomware-2026","metabase-2026","nidek-website-2026","nishiyama-2026","okta-support-2023","openai-huggingface-eval-2026","openai-mixpanel-2025","postman-shai-hulud-2025","prontest-cloud-2026","quick-2025","react2shell-2025","rust-arrayref-2026","sakura-billing-2026","sakura-hosting-2026","snowflake-unc5537-2024","temairazu-2026","times-car-2026","trivy-supply-chain-2026","unit42-ai-assisted-2026","voising-bi-2026"],"references":[],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-010","hash":"057e3ecf2e5f444da0fa1a37d2696bce79690ae193150a0ea534ec07542be6ff","record":{"id":"SEC-010","version":"1.1.0","updatedAt":"2026-10-02","title":{"ja":"外部入力とSQLの組み立てを確認する","en":"Inspect external input and SQL construction"},"summary":{"ja":"自社でSQLを実行するコードを持つ環境。閉じた製品は内部実装を推測せず、SEC-001の製品点検へ渡します。","en":"Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation."},"category":"implementation","surfaces":["web-app","data-store"],"applicability":{"ja":"自社でSQLを実行するコードを持つ環境。閉じた製品は内部実装を推測せず、SEC-001の製品点検へ渡します。","en":"Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation."},"targets":[{"ja":"API入力・検索条件・データアクセス層","en":"API inputs, query parameters, data access layer"},{"ja":"raw SQL・文字列連結・動的識別子","en":"Raw SQL, string concatenation, dynamic identifiers"}],"checks":[{"ja":"入力が値としてバインドされるか、SQLの構文へ直接連結されないか追跡する。","en":"Trace whether input is bound as data rather than concatenated into SQL syntax."},{"ja":"動的な列名やソート指定は許可リストで扱い、代表・境界・不正入力を合成データで検証する。","en":"Allow-list dynamic identifiers and sort options; test representative, boundary, and malformed inputs using synthetic data."}],"remediation":[{"ja":"値はパラメータ化し、識別子には許可リストを使う。必要な検索動作を保つ回帰テストを追加する。","en":"Parameterize values, allow-list identifiers, and add regression tests preserving required queries."}],"completionEvidence":[{"ja":"不正入力がSQL構造を変えず、許可された操作だけが成立するテストを残す。","en":"Record tests showing hostile input cannot alter query structure and only allowed operations succeed."}],"limitations":[{"ja":"MOVEitは製品側の欠陥の事例です。このルールはそこから導いた一般点検であり、同じ実装原因を自社コードへ断定しません。","en":"MOVEit is a vendor-defect example. This editorial rule does not claim the same implementation flaw exists in your code."}],"incidentIds":["anthropic-cyber-evals-2026","gyazo-2026","metabase-2026","moveit-2023"],"references":[{"title":"OWASP SQL Injection Prevention Cheat Sheet","url":"https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-011","hash":"c825b2408ad9c74579cd404c68b6cb9daa00d14601a42ba32b6b60fac4afcbf0","record":{"id":"SEC-011","version":"1.1.0","updatedAt":"2026-10-02","title":{"ja":"AIエージェントの接続先と実行権限を確認する","en":"Inspect AI-agent destinations and execution privileges"},"summary":{"ja":"コード実行やツール接続を行うAIエージェント・評価環境がある場合に適用します。","en":"Applies to agents and evaluation environments with code execution or tool connectivity."},"category":"configuration","surfaces":["ai-agent"],"applicability":{"ja":"コード実行やツール接続を行うAIエージェント・評価環境がある場合に適用します。","en":"Applies to agents and evaluation environments with code execution or tool connectivity."},"targets":[{"ja":"エージェントのネットワーク設定、パッケージプロキシ、MCP等のツール接続、サービスアカウント。","en":"Agent network settings, package proxies, tool connections such as MCP, and service accounts."},{"ja":"評価環境・CI・本番の境界と、接続・権限変更の記録。","en":"Boundaries among evaluation, CI, and production, plus connection and privilege-change records."}],"checks":[{"ja":"プロンプトの禁止事項と実際のネットワーク制御を照合する。例外のプロキシ経由で外部や本番に到達できないか、設定と既存の試験記録で確認する。","en":"Compare prompt restrictions with actual controls; inspect settings and existing tests for proxy routes to external or production systems."},{"ja":"ツールごとの取得・書き込み・公開の権限を確認し、未承認の接続、共用鍵、過大な権限を探す。秘密の値は取得しない。","en":"Inspect per-tool read, write, and publish authority for unapproved connections, shared keys, or excessive privileges without retrieving secret values."},{"ja":"人の承認が必要な操作と、実行ログ・停止手段を確認する。モデルの自己申告を合格の証拠にしない。","en":"Verify human approval requirements, execution logs, and stop mechanisms; do not accept model self-reports as evidence."}],"remediation":[{"ja":"用途ごとにサービスアカウントを分け、必要な接続先と操作に限定する。通信制御をモデルの外で実装する。","en":"Separate service accounts by purpose and restrict destinations and operations; enforce networking outside the model."},{"ja":"評価環境の本番接続と公開権限を分離し、例外を承認・記録する。疑わしい実行では承認範囲内で停止・鍵の失効を提案する。","en":"Separate production connectivity and publishing authority from evaluation; approve and record exceptions and propose authorized containment and revocation."}],"completionEvidence":[{"ja":"対象環境のリビジョンに対応した接続先・権限の一覧と、設定の確認記録。","en":"Destination and privilege inventory and configuration review tied to the environment revision."},{"ja":"許可された境界試験の記録、操作の承認履歴、実行ログと停止手段の確認結果。","en":"Authorized boundary-test records, approval history, execution logs, and verified stop mechanisms."}],"limitations":[{"ja":"設定を読むだけでは通信境界の有効性を保証できません。試験記録や実環境へのアクセスがない項目は未確認にします。","en":"Settings alone do not establish effective isolation; missing tests or runtime access remain unverified."},{"ja":"このDBを使うこと自体は、外部への通信、鍵の失効、権限変更の許可になりません。","en":"Using this catalog does not authorize external communication, credential revocation, or privilege changes."}],"incidentIds":["anthropic-claude-code-abuse-2025","anthropic-cyber-evals-2026","openai-huggingface-eval-2026","unit42-ai-assisted-2026"],"references":[{"title":"OpenAI evaluation incident","url":"https://openai.com/index/hugging-face-model-evaluation-security-incident/"},{"title":"Anthropic evaluation incidents","url":"https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"},{"title":"Unit 42 AI-assisted intrusion","url":"https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-012","hash":"a263b1e54e292b97464b5b6e1494a948a77571813c642c26eec1ed994473b833","record":{"id":"SEC-012","version":"1.1.0","updatedAt":"2026-10-02","title":{"ja":"非本番環境と保存データの廃止期限を確認する","en":"Inspect nonproduction and data retirement deadlines"},"summary":{"ja":"クラウドやDBに顧客データ、本人確認書類、初期認証情報、テスト用コピーを保存する環境に適用します。","en":"Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies."},"category":"configuration","surfaces":["cloud","data-store"],"applicability":{"ja":"クラウドやDBに顧客データ、本人確認書類、初期認証情報、テスト用コピーを保存する環境に適用します。","en":"Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies."},"targets":[{"ja":"開発・検証・BI・バックアップのデータコピー、退会者と登録未完了者の保存データ。","en":"Development, test, BI, and backup copies, including former-member and incomplete-applicant data."},{"ja":"環境とデータの責任者、用途、アクセス権、保持期限、廃止・消去の記録。","en":"Owners, purpose, privileges, retention deadlines, and retirement or deletion records."}],"checks":[{"ja":"資産一覧と実環境を照合し、用途を終えた環境と期限超過のデータを探す。","en":"Compare inventory and runtime assets for obsolete environments and overdue data."},{"ja":"本番データをテストへ持ち込む必要性と匿名化・最小化、外部公開と認証の設定を確認する。","en":"Inspect the need for production data in tests, anonymization and minimization, exposure, and authentication."},{"ja":"保持・消去の運用がDB本体だけでなく、コピー・復元・検索・バックアップにどう適用されるか確認する。","en":"Inspect how retention and deletion apply to copies, restoration, search, and backups as well as the live database."}],"remediation":[{"ja":"所有者と合意した保持方針に合わせて、不要な環境を廃止しデータを最小化する。削除は承認範囲と復旧要件に従う。","en":"Retire unnecessary environments and minimize data under an owner-approved retention policy; deletion follows authority and recovery requirements."},{"ja":"環境作成時に責任者・期限・アクセス制限を必須にし、期限超過を検知する。","en":"Require ownership, deadlines, and access restrictions at environment creation; detect overdue assets."}],"completionEvidence":[{"ja":"環境リビジョンに対応する資産・保持期限の一覧と、対象を明記した消去・匿名化の記録。","en":"Revision-linked asset and retention inventory with scoped deletion or anonymization records."},{"ja":"本番コピー、退会者、未完了申込者、バックアップへの適用を確認した結果。","en":"Evidence covering production copies, former members, incomplete applicants, and backups."}],"limitations":[{"ja":"法令や契約上の保持要件はこのDBで判断できません。必要なデータを独断で削除しません。","en":"This catalog does not determine legal or contractual retention requirements; do not delete required data without authority."},{"ja":"設定や期限の定義だけでは消去の実施を証明できません。実施記録がない範囲は未確認です。","en":"Defined settings or deadlines alone do not prove deletion; absent execution evidence remains unverified."}],"incidentIds":["aflac-japan-2026","awabank-test-environment-2026","discord-support-vendor-2025","gyazo-2026","nidek-website-2026","openai-mixpanel-2025","sakura-billing-2026","temairazu-2026","times-car-2026","voising-bi-2026"],"references":[{"title":"阿波銀行の調査結果","url":"https://www.awabank.co.jp/kojin/benri/awagin_app/news/2026/news20260603a/index.html"},{"title":"タイムズカー第3報","url":"https://share.timescar.jp/news/2026/0929/1816.html"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-013","hash":"0e16048f65f44638a3e7858bde158f737c2fa74751e5b12580da67ab0a3e7856","record":{"id":"SEC-013","version":"1.0.0","updatedAt":"2026-10-02","title":{"ja":"隔離手順とバックアップの復元を確認する","en":"Inspect containment and backup restoration"},"summary":{"ja":"共有システム、クラウド、データ保存先がある場合に、侵害時の被害拡大と復旧を点検します。","en":"Applies to shared systems, cloud, and data stores for containment and recovery inspection."},"category":"configuration","surfaces":["cloud","data-store"],"applicability":{"ja":"共有システム、クラウド、データ保存先がある場合に、侵害時の被害拡大と復旧を点検します。","en":"Applies to shared systems, cloud, and data stores for containment and recovery inspection."},"targets":[{"ja":"システム間の依存関係、ネットワーク隔離と実行の責任者、バックアップの保存先と削除権限。","en":"System dependencies, isolation procedures and owners, backup locations, and deletion privileges."}],"checks":[{"ja":"侵害された本番権限からバックアップを変更・削除できるかを権限情報で確認する。","en":"Use privilege metadata to check whether compromised production authority can alter or delete backups."},{"ja":"復元試験の日時・対象リビジョン・成功結果を確認し、目標復旧時間とデータ損失の要件と照合する。","en":"Inspect restoration-test dates, revisions, and outcomes against recovery-time and data-loss requirements."},{"ja":"共有システムの隔離手順、業務影響、連絡・判断の担当を記録と照合する。","en":"Compare shared-system containment procedures, operational impact, and decision ownership with records."}],"remediation":[{"ja":"バックアップの権限と管理経路を本番から分け、保護・保持の方針を設定する。","en":"Separate backup privileges and administration from production and define protection and retention policies."},{"ja":"承認された環境で復元・隔離の試験を行い、結果に基づき手順を更新する。","en":"Conduct authorized restoration and containment tests and update procedures from outcomes."}],"completionEvidence":[{"ja":"バックアップの権限・保護設定と、対象リビジョンを明記した復元試験の記録。","en":"Backup privilege and protection settings, plus restoration-test records with scoped revisions."},{"ja":"隔離の判断者、手順、業務依存を確認した記録。","en":"Records verifying containment decision ownership, procedures, and operational dependencies."}],"limitations":[{"ja":"バックアップが存在することだけでは復元成功を証明できません。復元試験の証拠がなければ未確認です。","en":"Backup existence does not prove successful restoration; missing restoration evidence remains unverified."},{"ja":"本番通信の遮断や破壊的な復旧操作は、この点検ルールだけでは許可されません。","en":"This inspection rule does not authorize production isolation or destructive recovery."}],"incidentIds":["askul-2025","keio-ransomware-2026","nishiyama-2026","sakura-hosting-2026"],"references":[{"title":"アスクル調査結果","url":"https://www.askullogist.co.jp/pdf/20251212.pdf"},{"title":"京王電鉄の障害公表","url":"https://www.keio.co.jp/news/update/announce/nr260926v13404/"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}} {"kind":"rule","id":"SEC-014","hash":"40889eb24f568c0135a0c8abe83471c8d3cf585ac435d86a668dbc910a6fc471","record":{"id":"SEC-014","version":"1.0.0","updatedAt":"2026-10-02","title":{"ja":"照会APIの認可と取得量の制御を確認する","en":"Inspect query authorization and retrieval limits"},"summary":{"ja":"会員・顧客・組織の情報を照会、一覧表示、一括出力するWebアプリやAPI。","en":"Web apps and APIs that query, list, or export member, customer, or organization information."},"category":"implementation","surfaces":["web-app","identity","data-store"],"applicability":{"ja":"利用者のIDや所属組織に応じて取得可能なデータが変わる環境。大量照会の制御も対象です。","en":"Environments where user or organization identity determines accessible data, including bulk-query controls."},"targets":[{"ja":"APIルート・認可処理・組織IDによる絞り込み・DBへの照会","en":"API routes, authorization, tenant filtering, and database queries"},{"ja":"ページ送り・一括出力・取得量の上限・監視設定","en":"Pagination, exports, retrieval limits, and monitoring configuration"}],"checks":[{"ja":"画面の表示制限に加え、各APIが呼び出し元の権限とデータの所属を照合するか確認する。未認証・権限不足・別組織の試験データが拒否されるか、許可されたテスト環境の証拠で確認する。","en":"Inspect server-side caller and record authorization; use evidence from an authorized test environment for unauthenticated, insufficient-role, and cross-tenant denial."},{"ja":"通常形式のリクエストを繰り返した場合も、利用者・組織ごとの取得量を制限・検知できるか確認する。ページ送りや複数のAPIに分けた取得も試験計画に含める。","en":"Inspect per-user and per-tenant volume limits and detection, including repeated ordinary requests, pagination, and access spread across endpoints."}],"remediation":[{"ja":"認可をサーバー側で共通化し、業務に合う取得量の上限と通知を設ける。許可された操作の成功と、許可していない照会の拒否を試験データで確認する。","en":"Centralize server-side authorization and set appropriate limits and alerts; verify allowed and denied queries with synthetic data."}],"completionEvidence":[{"ja":"対象API、権限とデータ所属の組合せ、許可・拒否の試験結果、取得量の上限と通知の証拠を残す。未検査のAPIや一括出力は明記する。","en":"Record API coverage, role/ownership combinations, allow/deny results, retrieval limits, and alert evidence; identify untested endpoints and exports."}],"limitations":[{"ja":"取得量の制限だけでは認可の欠陥を直せません。本番での大量リクエストや実顧客データへの照会を点検のために実行せず、権限や試験証拠が不足すれば未確認とします。","en":"Limits do not repair authorization flaws. Do not exercise bulk requests or real customer queries in production; unavailable permissions or test evidence mean unverified."}],"incidentIds":["aflac-japan-2026"],"references":[{"title":"アフラック生命保険:調査結果と再発防止策","url":"https://www.aflac.co.jp/static/corp/profile/news/2026/2026073100.pdf"}],"execution":"read-only-by-default","provenance":"editorial-guidance"}}