【テンプレあり】英語セキュリティ計画書の書き方|ITプロジェクトで使える日英フォーマット付き

※本サイトで紹介している商品・サービス等の外部リンクには、アフィリエイト広告が含まれる場合があります。

技術英語の実践術

グローバルITプロジェクトでセキュリティをどう管理するか、英語で文書化できているだろうか。

「セキュリティはインフラチームに任せている」という状況では、プロジェクト全体のセキュリティリスクが見えなくなる。英語圏のプロジェクトでは、セキュリティ計画書(Security Management Plan)がプロジェクト開始前に必須のドキュメントとして機能する。

この記事では、セキュリティ計画書に必要な4つのセクションを日英テンプレート付きで解説する。Word形式のテンプレートをダウンロードしてそのまま使えるので、初めて英語でセキュリティ計画書を作る人にも役立つ。


セキュリティ計画書に必要な4つの構成要素

英語のセキュリティ計画書は、次の4セクションで構成する。

  1. セキュリティ方針(Security Policy & Objectives):プロジェクトのセキュリティ目標と適用範囲を定義する
  2. リスクアセスメント(Risk Assessment):セキュリティリスクを識別・評価する
  3. セキュリティ統制(Security Controls):技術的・運用的・物理的な対策を定める
  4. モニタリングとインシデント対応(Monitoring & Incident Response):継続的な監視とインシデント対応手順を定める

各セクションを順番に埋めていけば、英語のセキュリティ計画書が完成する。


テンプレートをダウンロード(Word)

日本語版・英語版のWordテンプレートをそれぞれ用意した。ダウンロードしてプロジェクト情報を入力するだけで使える。


日本語版テンプレート(コピペOK)

基本情報

項目内容
プロジェクト名
作成者
作成日
バージョンv1.0
機密分類社外秘 / 機密

セクション1:セキュリティ方針と目標

目的(Purpose)

本セキュリティ計画書は、プロジェクト期間中の情報資産を保護し、機密性・完全性・可用性(CIA)を確保するための方針と対策を定めるものである。

適用範囲(Scope)

対象含む / 含まない
プロジェクトシステム含む
開発・テスト環境含む
本番環境含む
外部ベンダーシステム含む(契約に明記)
社内既存システム含まない

セキュリティ目標

目標KPI目標値
セキュリティインシデントの最小化重大インシデント件数0件/年
脆弱性の早期対応高リスク脆弱性の対応期間7日以内
アクセス管理の徹底不正アクセス検知率99%以上
コンプライアンス準拠監査指摘事項0件

準拠する規格・法令

  • ISO/IEC 27001
  • GDPR(個人データを扱う場合)
  • 個人情報保護法
  • その他(プロジェクト固有の規制):

セクション2:リスクアセスメント

情報資産一覧

#資産名機密分類資産オーナー保管場所
1顧客個人情報機密
2システム設計書社外秘
3ソースコード社外秘
4認証情報・APIキー機密
5プロジェクト契約書機密

セキュリティリスク評価

#リスク脅威脆弱性発生可能性影響度リスクレベル対応方針
1不正アクセス外部攻撃者弱いパスワード重大軽減
2データ漏洩内部不正アクセス権限過剰軽減
3マルウェア感染フィッシングセキュリティ教育不足軽減
4サービス停止DDoS攻撃冗長構成なし軽減
5設定ミス人的ミスレビュープロセス不足軽減

セクション3:セキュリティ統制

技術的統制

統制項目対策内容担当実施時期
アクセス管理MFA必須、最小権限の原則適用インフラプロジェクト開始前
暗号化通信はTLS1.2以上、保存データはAES-256インフラ設計フェーズ
脆弱性管理SAST/DAST、依存パッケージの定期スキャンDevSecOps開発フェーズ〜
ログ・監査全アクセスログを180日間保持・SIEM連携インフラ構築フェーズ
セキュリティテストペネトレーションテスト(リリース前)外部ベンダーテストフェーズ

運用的統制

統制項目対策内容担当頻度
セキュリティ教育年1回の必須受講PM年1回
アクセス権限レビュー四半期ごとに権限棚卸しセキュリティ担当四半期
パッチ管理重大パッチは7日以内に適用インフラ随時
サードパーティ評価ベンダーセキュリティ評価の実施調達契約時

物理的統制

統制項目対策内容
データセンターアクセス入退室管理システム・監視カメラ
端末管理MDM導入・フルディスク暗号化
廃棄記録媒体の安全な廃棄(証明書取得)

セクション4:モニタリングとインシデント対応

モニタリング計画

監視項目ツール担当頻度
ネットワーク異常インフラリアルタイム
ログ異常SIEMセキュリティリアルタイム
脆弱性スキャンDevSecOps週次
設定変更監視インフラリアルタイム

インシデント対応手順

フェーズアクション担当目標時間
検知アラート確認・初期トリアージSOC / インフラ15分以内
封じ込め影響システムの隔離インフラ1時間以内
根絶原因除去・パッチ適用開発・インフラ24時間以内
復旧サービス再開・動作確認開発・インフラ48時間以内
事後対応インシデントレポート作成・再発防止策実施PM・セキュリティ5営業日以内

英語版テンプレート(コピペOK)

Basic Information

ItemDetails
Project Name
Prepared By
Date
Versionv1.0
ClassificationConfidential / Internal Use Only

Section 1: Security Policy & Objectives

Purpose

This Security Management Plan defines the security policies, controls, and procedures to protect information assets throughout the project lifecycle and ensure Confidentiality, Integrity, and Availability (CIA).

Scope

TargetIncluded / Excluded
Project systemsIncluded
Development & test environmentsIncluded
Production environmentIncluded
Third-party vendor systemsIncluded (specified in contracts)
Existing internal systemsExcluded

Security Objectives

ObjectiveKPITarget
Minimize security incidentsCritical incidents0 per year
Rapid vulnerability remediationTime to resolve high-risk vulnerabilitiesWithin 7 days
Enforce access controlsUnauthorized access detection rate≥ 99%
Compliance adherenceAudit findings0

Applicable Standards & Regulations

  • ISO/IEC 27001
  • GDPR (where personal data is processed)
  • Applicable data protection laws
  • Other (project-specific regulations):

Section 2: Risk Assessment

Information Asset Register

#AssetClassificationAsset OwnerStorage Location
1Customer personal dataConfidential
2System design documentsInternal
3Source codeInternal
4Credentials & API keysConfidential
5Project contractsConfidential

Security Risk Assessment

#RiskThreatVulnerabilityLikelihoodImpactRisk LevelTreatment
1Unauthorized accessExternal attackerWeak passwordsHighHighCriticalMitigate
2Data breachInsider threatExcessive accessMediumHighHighMitigate
3Malware infectionPhishingInsufficient trainingMediumHighHighMitigate
4Service disruptionDDoS attackNo redundancyLowHighMediumMitigate
5MisconfigurationHuman errorNo review processMediumMediumMediumMitigate

Section 3: Security Controls

Technical Controls

ControlMeasureOwnerTiming
Access managementEnforce MFA; apply least privilegeInfrastructurePre-project
EncryptionTLS 1.2+ in transit; AES-256 at restInfrastructureDesign phase
Vulnerability managementSAST/DAST; dependency scanningDevSecOpsDev phase onward
Logging & auditRetain all access logs 180 days; SIEM integrationInfrastructureBuild phase
Security testingPenetration testing before releaseExternal vendorTest phase

Operational Controls

ControlMeasureOwnerFrequency
Security trainingMandatory annual trainingPMAnnually
Access reviewQuarterly access rights reviewSecurity leadQuarterly
Patch managementApply critical patches within 7 daysInfrastructureAs needed
Third-party assessmentVendor security assessmentProcurementAt contract

Physical Controls

ControlMeasure
Data center accessAccess control system & CCTV
Device managementMDM deployment; full-disk encryption
DisposalSecure media disposal with certificate

Section 4: Monitoring & Incident Response

Monitoring Plan

Monitor ItemToolOwnerFrequency
Network anomaliesInfrastructureReal-time
Log anomaliesSIEMSecurityReal-time
Vulnerability scansDevSecOpsWeekly
Configuration change monitoringInfrastructureReal-time

Incident Response Procedure

PhaseActionOwnerTarget Time
DetectionAlert review & initial triageSOC / InfraWithin 15 min
ContainmentIsolate affected systemsInfrastructureWithin 1 hour
EradicationRemove root cause; apply patchesDev & InfraWithin 24 hours
RecoveryRestore service; verify operationsDev & InfraWithin 48 hours
Post-incidentWrite incident report; implement preventive measuresPM & SecurityWithin 5 business days

各セクションの書き方と例文

セクション1:セキュリティ方針の書き方

セキュリティ方針では「何を守るか」「なぜ守るか」を明示する。英語ではCIAトライアドを軸に記述するのが標準的。

方針を説明する英文例:

  • This plan establishes the minimum security requirements that all project members and vendors must comply with.

(本計画書は、すべてのプロジェクトメンバーおよびベンダーが準拠すべき最低限のセキュリティ要件を定める)

  • Security requirements will be incorporated into all phases of the project lifecycle, from design through decommissioning.

(セキュリティ要件は、設計から廃棄まで、プロジェクトライフサイクルの全フェーズに組み込まれる)

セクション2:リスクアセスメントの書き方

リスクレベルの算出方法を明示すると、評価の根拠が明確になる。

リスク評価の英文例:

  • Risk level is calculated as the product of Likelihood and Impact, rated on a 1–5 scale.

(リスクレベルは、発生可能性と影響度の積として算出し、1〜5のスケールで評価する)

  • Risks rated as Critical or High require immediate mitigation actions.

(重大または高リスクに評価されたリスクは、即座の軽減アクションが必要となる)

セクション3:セキュリティ統制の書き方

統制ごとに「誰が・いつ・何をするか」を明記すると、実施漏れを防げる。

統制を説明する英文例:

  • All privileged access must be granted on a need-to-know and least-privilege basis and reviewed quarterly.

(すべての特権アクセスはneed-to-knowおよび最小権限の原則に基づいて付与し、四半期ごとにレビューする)

  • All data transmitted between systems must be encrypted using TLS 1.2 or higher.

(システム間で送信されるすべてのデータは、TLS 1.2以上を使用して暗号化しなければならない)

セクション4:インシデント対応の書き方

インシデントの重大度区分を明示しておくと、対応優先度の判断がスムーズになる。

インシデント対応の英文例:

  • A P1 (Critical) incident must be escalated to the Security Lead within 15 minutes of detection.

(P1(重大)インシデントは、検知から15分以内にセキュリティリードにエスカレーションしなければならない)

  • All security incidents must be documented in the incident log, regardless of severity.

(すべてのセキュリティインシデントは、重大度にかかわらずインシデントログに記録しなければならない)


セキュリティ計画書でよく使う英語表現

英語のセキュリティ計画書で頻出する表現をまとめた。

シーン英語表現日本語訳
方針enforce security controlsセキュリティ統制を実施する
アクセス管理grant/revoke accessアクセスを付与/削除する
リスク対応mitigate / transfer / accept / avoid軽減/転嫁/受容/回避する
脆弱性remediate a vulnerability脆弱性を修正する
監査conduct a security auditセキュリティ監査を実施する
インシデントcontain the incidentインシデントを封じ込める
報告submit an incident reportインシデントレポートを提出する
準拠comply with regulations規制に準拠する

まとめ:英語セキュリティ計画書は4つのセクションで完成する

英語セキュリティ計画書の4セクションをおさらいする。

  1. セキュリティ方針(Security Policy & Objectives):目標・適用範囲・準拠規格を定義する
  2. リスクアセスメント(Risk Assessment):資産を識別しリスクを評価する
  3. セキュリティ統制(Security Controls):技術的・運用的・物理的対策を定める
  4. モニタリングとインシデント対応(Monitoring & Incident Response):継続監視と初動手順を定める

セキュリティ計画書で定めた方針は、セキュリティポリシーと整合している必要がある。英語セキュリティポリシーの書き方と合わせて整備することで、組織全体のセキュリティ方針とプロジェクト固有の統制がつながる。

また、インシデント発生時に備えたセキュリティインシデント対応書も不可欠だ。英語セキュリティインシデント対応の書き方と組み合わせることで、計画から対応までの一貫したセキュリティ管理体制が整う。

コメント

タイトルとURLをコピーしました