8月12日、米国標準技術研究所(National Institute of Standards and Technology: NIST)は、人工知能(AI)を活用したサイバーセキュリティ脆弱性データベース整備に向けた情報の募集を開始した。近年、脆弱性に関する報告数が増加傾向にあり、AIを活用したツールを悪用するなどその手口も巧妙化していることから、サイバーセキュリティ上の欠陥(脆弱性)に関する中央リポジトリを拡充する。NISTが運営する国家脆弱性データベース(National Vulnerability Database: NVD)における拡張性、相互運用性、透明性、有用性の向上に向け、自動化に適したタスクや人間による評価範囲、リアルタイムなリスク評価などの課題に関する情報を募っており、意見提出の締め切りを10月13日までとした。脅威管理エコシステムをイノベーションする機会と位置付けるAI発展に向けた取り組みで、特定の行政命令や既存の共有枠組みとは別に実施するとし、寄せられた意見は技術設計やデータ運営管理方針の策定に活用される。
Federal Register “Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence” (08/12/26)
https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of
参照記事: NEXTGOV /FCW “NIST wants to outfit the National Vulnerability Database with AI” (08/13/26)
https://www.nextgov.com/cybersecurity/2026/08/nist-wants-outfit-national-vulnerability-database-ai/415371/?oref=ng-homepage-river