Explanation information generation device and explanation information generation method

The explanation information generation device addresses the challenge of adjusting security measure explanations by determining an explanation level and generating tailored validity explanations, enhancing efficiency and appropriateness for compliance targets and recipients.

WO2025203724A1PCT designated stage Publication Date: 2025-10-02HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/028308
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2024-08-07
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing methods for explaining the appropriateness of security measures in industrial control systems fail to adjust explanations based on the compliance target and explanation recipient, requiring significant manual effort and expert time due to diverse information and expression methods.

Method used

An explanation information generation device that determines an explanation level based on compliance target and recipient information, generating validity explanations using a processor and memory to output appropriate explanations efficiently.

Benefits of technology

Enables flexible and efficient generation of tailored validity explanations for security measures, reducing manual effort and ensuring appropriate content based on the compliance target and explanation recipient.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024028308_02102025_PF_FP_ABST
    Figure JP2024028308_02102025_PF_FP_ABST
Patent Text Reader

Abstract

This explanation information generation device: holds compliance target information, which indicates a rule which is a compliance target of a security measure with respect to a system, and / or explanation partner information, which indicates an explanation partner which is a partner that receives an explanation; determines, on the basis of the compliance target information and / or the explanation partner information, an explanation level which indicates the degree of specificity of a validity explanation which is a description about the validity of the security measure with respect to the system; generates a validity explanation on the basis of the determined explanation level; and generates data for outputting the generated validity explanation.
Need to check novelty before this filing date? Find Prior Art

Description

Explanation information generating device and explanation information generating method Incorporation by Reference

[0001] This application claims priority from Japanese Patent Application No. 2024-52179, filed on March 27, 2024, the contents of which are incorporated herein by reference.

[0002] The present invention relates to an explanatory information generating device and an explanatory information generating method.

[0003] While digital transformation (DX) is being promoted not only in general information systems but also in operational technology (OT) systems / industrial control systems that support social infrastructure such as industry, medical care, railways, automobiles, and electricity, the threat of cyber attacks is increasing.

[0004] Therefore, to realize safe and secure industrial control systems, security measures against cyber attacks are required. In addition, legislation is being formulated to make the implementation of such security measures mandatory, such as the European Cyber ​​Resilience Act and Japan's Economic Security Promotion Act, and standardization of security measures for industrial control systems, such as ISO / IEC 62443, is also underway, with the formulation of guidelines that provide more specific guidelines for security measures.

[0005] Background art in this technical field is WO 2023 / 105629 (Patent Document 1), which states, "We provide a security countermeasure planning system that contributes to selecting countermeasures based on changes over time in security risks inherent in a system. The security countermeasure planning system includes a functional unit that calculates a risk value for one or more assets included in a system to be diagnosed, a risk change estimation unit that estimates future risk values ​​for the asset risk values ​​calculated by the functional unit, and a countermeasure decision unit that selects countermeasures based on the future risk values ​​estimated by the risk change estimation unit" (see abstract).

[0006] International Publication No. 2023 / 105629

[0007] In the future, once security measures have been implemented in compliance with the laws, regulations, and standards mentioned above, an explanation will be required as to whether the implementation of those security measures is appropriate, i.e., an "explanation of the appropriateness of security measures." This explanation will be necessary when compliance with laws, regulations, and standards is required for procurement, or when fulfilling accountability to relevant stakeholders in the unlikely event of a security incident caused by a cyber attack. Therefore, a method for explaining the appropriateness of future security measures will be required.

[0008] The technology described in Patent Document 1 determines security measures for assets that make up a system based on a time-varying risk value, and this risk value is used to explain the validity of the determined security measures using the technology described in Patent Document 1.

[0009] However, when explaining appropriate security measures that comply with legal regulations, standards, etc., it is necessary to adjust the content of the explanation depending on the situation of the explanation and the needs or desires of the person giving the explanation or the person being explained to. Therefore, if the risk values ​​of the technology described in Patent Document 1 are used solely to explain the appropriateness of security measures, there is a risk that the content of the explanation will not be adjusted appropriately.

[0010] Furthermore, because the amount of information (e.g., grounds and evidence) that can be used to explain the validity of security measures is enormous and the ways of expressing the explanations themselves are diverse, creating a necessary and sufficient explanation requires the time (man-hours) of an expert with knowledge of systems, security, compliance targets, etc. Therefore, one aspect of the present invention provides an appropriate explanation of the validity of security measures with a low number of man-hours.

[0011] In order to solve the above problem, one aspect of the present invention employs the following configuration: An explanation information generation device includes a processor and a memory, the memory holds at least one of compliance target information indicating rules to which security measures for a system are to be complied with and explanation recipient information indicating an explanation recipient who is to receive the explanation, the processor determines an explanation level indicating a degree of specificity of a validity explanation that is an explanation of the validity of the security measures for the system based on the at least one of the compliance target information and information, generates the validity explanation based on the determined explanation level, and generates data for outputting the generated validity explanation.

[0012] According to one aspect of the present invention, an appropriate explanation of the validity of security measures can be obtained with a small number of steps.

[0013] Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments.

[0014] 1 is a block diagram showing an example of a functional configuration of an explanatory information generating device in Example 1. FIG. 2 is a block diagram showing an example of a hardware configuration of an explanatory information generating device in Example 1. FIG. 3 is a diagram showing an example of a screen configuration of an explanatory adjustment information input screen in Example 1. FIG. 4 is a diagram showing an example of a screen configuration of a system information / measure input screen in Example 1. FIG. 5 is a diagram showing an example of a data configuration of an explanatory level table in Example 1. FIG. 6 is a diagram showing an example of a data configuration of a related information table in Example 1. FIG. 7 is a diagram showing an example of a data configuration of an explanatory template table in Example 1. FIG. 8 is a flowchart showing an example of explanatory information generation processing in Example 1. FIG. 9 is a diagram showing an example of a screen configuration of a validity explanatory information output screen in Example 1. FIG. 10 is a block diagram showing an example of a functional configuration of an explanatory information generating device in Example 2. FIG. 11 is a flowchart showing an example of an explanatory information generation review processing in Example 2. FIG. 12 is a diagram showing an example of a screen configuration of an additional information input screen in Example 2. FIG. 13 is a block diagram showing an example of a functional configuration of an explanatory information generating device in Example 3. FIG. 14 is a diagram showing an example of a data configuration of an explanation template table in Example 3. FIG. 15 is a diagram showing an example of a screen configuration of a validity explanatory information output screen in Example 3.

[0015] Hereinafter, examples of modes for carrying out the present invention (hereinafter referred to as "embodiments") will be described with reference to the accompanying drawings. In this specification and the accompanying drawings, identical components or components having substantially the same functions are designated by the same reference numerals, and redundant description will be omitted.

[0016] 1 is a block diagram showing an example of the functional configuration of an explanatory information generating device. The explanatory information generating device 100 generates an explanation about the appropriateness of a security measure (a security measure for a system) to be implemented (or has been implemented) in a system (for example, an explanation about whether it is appropriate that the security measure is to be implemented in the system or has been implemented (including, for example, whether the security measure is appropriately compliant with the compliance target)).

[0017] Note that the system in this embodiment may include not only the system itself but also components (devices, equipment, etc.) that make up the system. The system in this embodiment may include multiple components, or may be composed of a single component. The explanation information generating device 100 generates an explanation of validity using, for example, information on a compliance target that indicates rules that a security measure complies with or aims to comply with, and information on a person to be explained.

[0018] The explanation information generating device 100 is connected to an explanation adjustment information input unit 110, a system information / measure input unit 120, and an explanation output unit 170. The explanation information generating device 100 also includes, for example, an explanation level setting unit 130, a related information generating unit 140, an explanation selecting unit 150, and an explanation information generating unit 160, which are all functional units. The explanation information generating device 100 holds an explanation DB (DataBase) 180, an explanation level DB 185, and a related information DB 190.

[0019] The explanation adjustment information input unit 110 inputs into the explanation information generating device 100 compliance target information indicating the security laws, regulations, standards, or guidelines that the security measures comply with or aim to comply with, and information about the person to whom the explanation regarding validity will be given (for example, a person in charge such as a national auditing agency, certification agency, industry auditing agency, or customer).

[0020] The compliance target may include any rules related to security, such as national laws, international laws, national regulations, international regulations, industry regulations, company regulations, national standards, international standards, industry standards, company standards, etc. Hereinafter, security measures may also be simply referred to as measures.

[0021] The system information / measures input unit 120 inputs information about the system that is the target of security measures and information about the details of the security measures to the explanation information generation device 100. Details of the information input by the explanation adjustment information input unit 110 and the system information / measures input unit 120 will be described later using Figures 3A and 3B.

[0022] The explanation adjustment information input unit 110 and the system information / measures input unit 120 can be configured by, for example, an input device of a communication terminal such as a PC (Personal Computer), or a communication device that communicates with an external device.

[0023] 1, the explanation adjustment information input unit 110 and the system information / measures input unit 120 are provided outside the explanation information generation device 100, but may also be built into the explanation information generation device 100. The explanation adjustment information input unit 110 and the system information / measures input unit 120 may be configured by an input / output I / F (interface) 23, which will be described later.

[0024] The explanation level setting unit 130 sets an explanation level using the reference target information and explanation partner information input from the explanation adjustment information input unit 110 and the explanation level table 400 of the explanation level DB 185, and outputs the set explanation level to the explanation selection unit 150. Details of setting the explanation level will be described later with reference to FIG.

[0025] The related information generation unit 140 generates related information based on the information input from the system information / measure input unit 120 and outputs the generated related information to the related information DB 190. The related information indicates candidates for information to be used to generate an explanation. Specifically, for example, the related information indicates candidates for information (e.g., character strings) to be embedded in the explanation (assigned to variables included in the explanation template).

[0026] The related information generation unit 140 generates related information by, for example, performing natural language processing using AI (Artificial Intelligence) or the like on the information input from the system information / countermeasure input unit 120. Furthermore, for example, the related information generation unit 140 may generate related information by using external information obtained from a website on the Internet or the like (for example, a text indicating the correspondence between countermeasures and their vulnerabilities).

[0027] The related information DB 190 stores a related information table 500, which will be described later with reference to Fig. 5. The related information table 500 indicates, for example, the content of the related information itself and the type of the related information.

[0028] The explanation selection unit 150 selects explanation template information that matches the explanation level input from the explanation level setting unit 130 from an explanation template table 600 (described later) stored in the explanation DB 180 .

[0029] The explanation information generation unit 160 sets the information to be assigned to the variables included in the explanation template information selected by the explanation selection unit 150 based on the content of the related information itself stored in the related information table 500 of the related information DB 190 and the type of the related information.

[0030] The explanation information generation unit 160 outputs the validity explanation information generated by assigning information to the variables of the explanation template information to the explanation output unit 170 connected to the explanation information generating device 100. In addition, the explanation information generation unit 160 outputs the compliance target information input from the explanation adjustment information input unit 110 to the explanation output unit 170.

[0031] The explanation output unit 170 outputs the validity explanation information and the reference target information output from the explanation information generation unit 160 to the display screens of terminal devices 26a and 26b (described later with reference to FIG. 2 ) connected to the explanation information generation device 100. In the example of FIG. 1 , the explanation output unit 170 is provided outside the explanation information generation device 100, but may also be built into the explanation information generation device 100.

[0032] 2 is a block diagram showing an example of the hardware configuration of the explanatory information generating device 100. The explanatory information generating device 100 is configured by, for example, an information processing device 20 and an auxiliary storage device 24. Note that the information processing device 20 may have the auxiliary storage device 24 built-in.

[0033] The information processing device 20 is, for example, a computer including a processing unit 21, a memory 22, and an input / output I / F 23, which are all connected to a bus. The processing unit 21, the memory 22, and the input / output I / F 23 are hardware used in the computer.

[0034] The processing unit 21 executes the programs stored in the memory 22 to realize the functions of the above-mentioned functional units (explanation level setting unit 130, related information generating unit 140, explanation selecting unit 150, and explanation information generating unit 160). The processing unit 21 includes a processor and is configured, for example, by a CPU (Central Processing Unit) or the like. The processing unit 21 may be configured, instead of a CPU, by an MPU (Micro-Processing Unit) or the like.

[0035] The memory 22 includes, for example, a read-only memory (ROM) and a random access memory (RAM). The ROM stores immutable programs (for example, a basic input / output system (BIOS)). The RAM is a high-speed, volatile storage element such as a dynamic random access memory (DRAM), and temporarily stores programs executed by the processing unit 21 and data used when the processing unit 21 executes the programs (variables, parameters, etc. generated during processing).

[0036] A large-capacity nonvolatile storage device is used as the auxiliary storage device 24. Examples of the auxiliary storage device 24 include a hard disk drive (HDD), a solid state drive (SSD), and a non-volatile random access memory (NVRAM).

[0037] The auxiliary storage device 24 may store, in addition to an OS (Operating System) and various parameters, programs for operating the information processing device 20. That is, the programs are read from the auxiliary storage device 24, loaded into the memory 22, and executed by the processing unit 21.

[0038] For example, the processor included in the processing unit 21 functions as the explanation level setting unit 130 by operating in accordance with the level setting unit program loaded into the memory 22, and functions as the related information generating unit 140 by operating in accordance with the related information generating program loaded into the memory 22. The same relationship between the programs and the functional units applies to the other functional units included in the explanation information generating device 100.

[0039] A part or all of the programs executed by the processing unit 21 may be provided to the information processing device 20 via a network from removable media, which are non-transitory storage media (flexible disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, non-volatile memory cards, etc.), or from an external computer equipped with a non-transitory storage device, and may be stored in a non-volatile storage device, which is a non-transitory storage medium, possessed by the information processing device 20. For this reason, the information processing device 20 may preferably have an interface for reading data from removable media.

[0040] The explanation DB 180, explanation level DB 185, and related information DB 190 are realized by part of the storage area of ​​the auxiliary storage device 24. The explanation DB 180 stores, for example, an explanation template table 600. The explanation level DB 185 stores, for example, an explanation level table 400. The related information DB 190 stores, for example, a related information table 500. Note that some or all of the information stored in the auxiliary storage device 24 in FIG. 2 may be stored in the memory 22.

[0041] In this embodiment, the information used by the explanation information generation device 100 does not depend on the data structure and may be expressed in any data structure. For example, the information can be stored in a data structure appropriately selected from a table, a list, a database, or a queue.

[0042] The input / output I / F 23 is a device that controls the input and output of data between the information processing device 20 and other devices. The input / output I / F 23 includes, for example, a network interface device that controls communication with other devices in accordance with a predetermined protocol.

[0043] The input / output I / F 23 may include an interface device to which a keyboard, a mouse, or the like is connected and which receives input from an operator. The input / output I / F 23 may also include an interface device to which a display, a printer, or the like is connected and which outputs the results of program execution in a format that can be viewed by the operator. The input / output I / F 23 may also include a serial interface such as a USB (Universal Serial Bus).

[0044] In this embodiment, for example, the auxiliary storage device 24, the terminal device 26 a, and the terminal device 26 b are connected to the input / output I / F 23. Note that the explanation adjustment information input unit 110, the system information / measures input unit 120, and the explanation output unit 170 may be configured by the input / output I / F 23.

[0045] The explanatory information generating device 100 is a computer system configured on a single physical computer or on multiple logically or physically configured computers, and may operate on separate threads on the same computer, or on a virtual computer constructed on multiple physical computer resources.

[0046] The terminal device 26a communicates with the information processing device 20 by using a closed circuit network such as a dedicated line. The terminal device 26a is used in an on-premise system. An engineer, a manager, or the like operates an input device such as a keyboard connected to the terminal device 26a to input information on the compliance target, information on the person to be explained, information on the system, and information on countermeasures, and this information is transmitted to the information processing device 20 that constitutes the explanation information generation device 100.

[0047] The terminal device 26b communicates with the information processing device 20 via the network 25. As with the terminal device 26a, an engineer, a manager, or the like operates an input device such as a keyboard connected to the terminal device 26b to input information on the compliance target, information on the person to be explained, information on the system, and information on countermeasures, and this information is transmitted to the information processing device 20 that constitutes the explanation information generation device 100.

[0048] The explanation information generation device 100 may be connected to only one of the terminal device 26a or the terminal device 26b. Also, the types of information input to the terminal device 26a and the terminal device 26b may be different, for example, by inputting information on the compliance target and information on the explanation recipient into one of the terminal device 26a and the terminal device 26b (i.e., the function of the explanation adjustment information input unit 110 is realized by the one device), and inputting system information and countermeasure information into the other (i.e., the function of the system information / countermeasure input unit 120 is realized by the other device).

[0049] The network 25 may be, for example, a wireless network or a wired local area network (LAN) that provides multiple topologies.

[0050] The Internet 27 is an example of a public line network. The information processing device 20 constituting the explanation information generation device 100 communicates with communication devices such as a cloud or an external factory via the Internet 27. The public line network may be a wireless communication infrastructure (wireless network) provided by a line carrier.

[0051] Each of the terminal devices 26a and 26b also includes a processing unit (processor), memory, an input / output I / F, and a storage device (non-volatile storage), and functions are realized by the processing unit executing a program stored in the memory. Each of the terminal devices 26a and 26b includes a display device (not shown) that displays information such as the status of the target system, and an input device (not shown) that generates an input signal according to the content of an input by a system administrator or the like.

[0052] [Example of explanation adjustment information input screen] Fig. 3A is a diagram showing an example of the screen configuration of the explanation adjustment information input screen. The explanation adjustment information input screen 300 is realized by the explanation adjustment information input unit 110. The explanation adjustment information input screen 300 includes, for example, a reference target information input area 310 and an explanation partner information input area 320.

[0053] The compliance target information input area 310 is an area for inputting information on the compliance target, i.e., information indicating the rules to which the measures implemented in the system conform. The compliance target information input area 310 includes, for example, a pull-down input area 311, a file reading area 312, and a text input area 313. The pull-down input area 311 is an area for selecting a compliance target from a plurality of predetermined compliance target candidates in a pull-down manner and accepting input.

[0054] The file reading area 312 is an area for specifying and reading an electronic file in which information to be referenced is described or an electronic file in which information for extracting or inferring the information to be referenced is described. The text input area 313 is an area for accepting input of information to be referenced by text input from the user.

[0055] In the example of Figure 3A, the checkbox located next to the text input area 313 is checked, so the "National Standard for the Electric Power Sector" entered in the text input area 313 is determined to be the object of compliance.

[0056] In addition, the explanation adjustment information input unit 110 may input the information determined in the compliance target information input area 310 itself to the explanation information generating device 100 as compliance target information, or may input information obtained by analyzing the relationship between the determined information and text such as laws and regulations, standards, and guidelines using machine learning or deep learning, etc., to the explanation information generating device 100 as compliance target information.

[0057] In addition, in the compliance information input area 310, information indicating the rule to be complied with (e.g., the name of a law or standard, etc.) may be input, or information indicating the content of the rule to be complied with (e.g., a specific legal sentence contained in a law or a specific sentence contained in a standard, etc.) may be input.

[0058] The explanation recipient information input area 320 is an area for receiving input of information about the explanation recipient, i.e., the person who will receive an explanation about the validity of the security measures implemented in the system. The explanation recipient information input area 320 includes, for example, a pull-down input area 321, a file reading area 322, and a text input area 323. The pull-down input area 321 is an area for selecting an explanation recipient from a plurality of predetermined explanation recipient candidates using a pull-down menu and receiving input.

[0059] The file reading area 322 is an area for specifying and reading an electronic file that describes information about the person to be explained, or an electronic file that describes information for extracting or inferring information about the person to be explained. The text input area 323 is an area for accepting input of information about the person to be explained by text input from the user.

[0060] In the example of Figure 3A, the checkbox located next to the pull-down input area 321 is checked, so the "Electricity Inspection Agency Personnel" selected in the pull-down input area 321 is determined as the person to whom the explanation will be given.

[0061] In addition, the explanation adjustment information input unit 110 may input the information determined in the explanation partner information input area 320 itself to the explanation information generating device 100 as explanation partner information, or may input information obtained by analyzing the determined information using machine learning, deep learning, etc. to the explanation information generating device 100 as explanation partner information.

[0062] 3B is a diagram showing an example of the screen configuration of the system information / measure input screen. The system information / measure input screen 330 is realized by the system information / measure input unit 120. The system information / measure input screen 330 includes, for example, a target system information input area 340 and a measure information input area 350.

[0063] The target system information input area 340 is an area for inputting information about a system (target system) for which security measures have been implemented or are scheduled to be implemented. The target system information input area 340 includes, for example, a file reading area 341 and a pull-down input area 342.

[0064] The file reading area 341 is an area for specifying and reading an electronic file that describes information about the target system or an electronic file that describes information for extracting or inferring information about the target system. The pull-down input area 342 is an area for accepting input by selecting a target system from a plurality of predetermined candidate target systems using a pull-down method.

[0065] In the example of Figure 3B, the checkbox located next to the file reading area 341 is checked, so the system indicated by "C:\File\path\system.file" entered in the file reading area 341 is determined as the target system.

[0066] In addition, the system information / countermeasure input unit 120 may input the information determined in the target system information input area 340 itself to the explanation information generating device 100 as target system information, or may input information obtained by analyzing the determined information using machine learning, deep learning, etc. to the explanation information generating device 100 as target system information.

[0067] The countermeasure information input area 350 is an area for inputting information about the content of security countermeasures. The countermeasure information input area 350 includes, for example, a file reading area 351 and a text input area 352.

[0068] The file reading area 351 is an area for specifying and reading an electronic file that describes information on the countermeasure location and the countermeasure content for that countermeasure location, or an electronic file that describes information for extracting or inferring the information on the countermeasure content. Furthermore, the text input area 352 is an area for receiving text input from the user about the countermeasure location and the countermeasure content for that countermeasure location.

[0069] In the example of FIG. 3B , the checkbox located next to the text input area 352 is checked, and therefore the countermeasure entered in the text input area 352, “Countermeasure location: PC, Countermeasure content: Use of authentication function,” is determined as the countermeasure.

[0070] In addition, the system information / countermeasure input unit 120 may input the information determined in the countermeasure information input area 350 itself to the explanation information generating device 100 as countermeasure information, or may input information obtained by analyzing the determined information using machine learning, deep learning, etc. to the explanation information generating device 100 as countermeasure information.

[0071] 4 is a diagram showing an example of the data configuration of the explanation level table 400. The explanation level table 400 indicates, for example, an explanation level corresponding to a combination of an explanation partner and a reference target. The explanation level table 400 is created in advance according to input by, for example, an engineer or an administrator, and is stored in the auxiliary storage device 24.

[0072] The explanation recipients in the explanation level table 400 include, for example, "Country," "Certification Body," and "Auditor." The compliance targets 420 in the explanation level table 400 include, for example, "Overseas Regulations," "Domestic Standards," and "Domestic Guides." The explanation levels include "Level 1," "Level 2," "Level 3," and "Level 4."

[0073] In the example of Figure 4, when the person to be explained is a "country" and the compliance object is "overseas laws and regulations," the explanation level is "Level 1." When the person to be explained is a "country" and the compliance object is a "domestic standard," the explanation level is "Level 2." When the person to be explained is a "country" and the compliance object is a "domestic guide," the explanation level is "Level 3." For other combinations of the person to be explained and the compliance object, the explanation levels shown in Figure 4, for example, are also adopted.

[0074] The explanation level indicates, for example, the degree of specificity of the explanation. For example, the higher the explanation level, the more specific the explanation (i.e., the more concrete), and the lower the explanation level, the less specific the explanation (i.e., the more abstract). For example, the greater the number of variables included in the explanation template described below (if the same variable appears multiple times, it is counted multiple times), the more specific the explanation. In other words, the higher the explanation level, the greater the number of variables included in the explanation template corresponding to that explanation level.

[0075] Furthermore, for example, the wider the scope of application of the rules (laws, regulations, etc.) indicated by the compliance target (for example, domestic laws are applied throughout the country, while internal standards are applied only to a certain company, so domestic laws have a wider scope of application than internal standards), and it is desirable to set a lower explanation level. Also, for example, the wider the range of people who may provide explanations to the person being explained to (for example, a country may receive explanations from personnel in companies throughout the country, while an auditor may receive explanations only from personnel in a specific company, so the range of people who may provide explanations to a country is wider than the range of people who may provide explanations to an auditor), it is desirable to set a lower explanation level.

[0076] The explanation level setting unit 130 obtains from the explanation level table 400 the explanation level corresponding to the combination of the explanation partner and the reference target indicated by the explanation partner information and the reference target information input from the explanation adjustment information input unit 110, and outputs it to the explanation selection unit 150.

[0077] For example, in the example of Figure 3A, the "electricity audit agency official" entered in the explanation recipient information input area 320 is input to the explanation level setting unit 130 as explanation information, and the "electricity sector domestic standard" entered in the compliance target information input area 310 is input to the explanation level setting unit 130 as compliance target information.

[0078] In this case, the "electricity audit organization official" indicated by the explanation partner information corresponds to the "certification organization" in the explanation level table 400, and the "electricity sector national standard" indicated by the compliance target information corresponds to the "national standard" in the explanation level table 400. For example, a table or algorithm for identifying which explanation partner in the explanation level table 400 the explanation partner information corresponds to, and a table or algorithm for identifying which compliance target in the explanation level table 400 the compliance target information corresponds to are predefined. The explanation level setting unit 130 uses these tables or algorithms as necessary to identify the explanation partner and compliance target (in the explanation level table 400) that correspond to the explanation partner information and the compliance target information. The explanation level setting unit 130 then obtains "Level 3" in the explanation level table 400 that corresponds to the combination of "certification organization" and "national standard" and outputs it to the explanation selection unit 150.

[0079] 4, the explanation level table 400 is information in which the explanation level is identified from a combination of an explanation partner and a reference target, but the information may be information in which the explanation level is identified from only the explanation partner, or information in which the explanation level is identified from only the reference target information. That is, the explanation level setting unit 130 may identify the explanation level from the explanation level table 400 using only the explanation partner indicated by the explanation partner information, or may identify the explanation level from the explanation level table 400 using only the reference target indicated by the reference target information.

[0080] [Related Information Table] Fig. 5 is a diagram showing an example of the data configuration of a related information table 500. The related information table 500 includes, for example, a related information column 510 and a type column 520. The related information column 510 indicates the content of the related information. The type column 520 indicates the type of related information. The types of related information include, for example, "threats" that the security measures address, "system requirements" for implementing the security measures, "device requirements" that make up the system, "implementation technologies" for realizing the security measures, and security "measures" that will be or have been implemented in the system.

[0081] An example of a method by which the related information generation unit 140 generates the related information table 500 will be described. For example, a plurality of types that can be stored in the type column 520 are predetermined. The related information generation unit 140 generates related information (values ​​to be stored in the related information column 510) corresponding to each of the plurality of types by analyzing and / or analysing the information (system information and countermeasure information) input from the system information / countermeasure input unit 120, for example.

[0082] Specifically, for example, the related information generation unit 140 extracts related information corresponding to each of the multiple types from the information input from the system information / countermeasure input unit 120 using natural language processing, AI (Artificial Intelligence), etc. Furthermore, for example, the related information generation unit 140 may perform analysis and / or analysis using external information (e.g., text indicating the relationship between countermeasures and threat information) obtained from a website on the Internet, based on the information input from the system information / countermeasure input unit 120.

[0083] In the above example, the related information table 500 is generated by the related information generation unit 140, but it may also be created in advance according to input from, for example, an engineer or administrator, and stored in the auxiliary storage device 24.

[0084] 6 is a diagram showing an example of the data configuration of an explanation template table 600. The explanation template table 600 includes, for example, an explanation template column 610 and an explanation level column 620.

[0085] The explanation template column 610 stores explanation templates that are models of validity explanation information output by the explanation information generating device 100. The parts in brackets “[ ]” in the explanation template are variables.

[0086] The explanation information generation unit 160 obtains related information corresponding to the type written inside "[ ]" from the related information table 500 and assigns it to each variable in the explanation template. However, the variable "[Compliance target]" is assigned the compliance target information input by the explanation adjustment information input unit 110, rather than related information. Note that a variable marked with "*" indicates that multiple values ​​(related information) can be assigned to the variable.

[0087] As described above, the higher the explanation level, the more specific the explanation template. Specifically, for example, the higher the explanation level, the greater the number of variables (the same variables are counted multiple times) in the explanation template corresponding to that explanation level. In the example of FIG. 6 , the explanation template corresponding to explanation level “Level 1” includes five variables (“[Compliance Target]”, “[Countermeasure]”, “[Implementation Technology]”, “[Implementation Technology]”, and “[System Requirements]”), while the explanation template corresponding to explanation level “Level 3” includes eight variables (“[Compliance Target]”, “[Countermeasure]”, “[Implementation Technology]”, “[Implementation Technology]”, “[Device Requirements]”, “[Implementation Technology*]”, “[Threat]”, and “[Implementation Technology]”).

[0088] In the above example, the explanation level setting unit 130 set the explanation level to "Level 3." The explanation selection unit 150 selects an explanation template corresponding to "Level 3" from the explanation template table 600 in FIG. 6 , which reads, "The [Countermeasure] that complies with the [Compliance Target] is realized by the [Implementation Technology]. The reason for using the [Implementation Technology] is that the device that constitutes the system is the [Device Requirement], and the [Implementation Technology*] was a candidate for the realization technology, and the [Implementation Technology] was selected in consideration of the [Threat]." and outputs this to the explanation information generation unit 160.

[0089] In this embodiment, the explanation template table 600 is pre-stored in the explanation DB 180, but when the explanation information generating device 100 is used, information equivalent to the explanation template table 600 or information to be sent to the explanation information generating unit 160 may be created using generation AI or the like.

[0090] 7 is a flowchart showing an example of explanation information generation processing by the explanation information generation unit 160. The explanation information generation unit 160 acquires reference target information from the explanation adjustment information input unit 110, acquires an explanation template from the explanation selection unit 150, and acquires the related information table 500 from the related information DB 190 (S701).

[0091] The explanation information generation unit 160 assigns compliance target information to the variable "[Compliance target]" in the explanation template obtained in step S701, and obtains related information of the type corresponding to the variable from the related information table 500 and assigns it to other variables in the explanation template (S702).

[0092] The explanation information generating unit 160 determines whether information has been assigned to all variables in the acquired explanation template (S703). For example, if the related information table 500 does not contain related information of a type corresponding to the variables in the explanation template, or if no reference information is input to the explanation information generating unit 160, information will not be assigned to at least one variable in the explanation template.

[0093] If the explanation information generating unit 160 determines that information has been assigned to all variables (S703: YES), it transmits the explanation template to which information has been assigned as appropriate explanation information to the explanation output unit 170 (S704), and ends the explanation information generation process. Note that if the explanation template does not include the variable "[reference target]", in step S704, the explanation information generating unit 160 also transmits the reference target information to the explanation output unit 170.

[0094] If the explanation information generation unit 160 determines that information has not been assigned to at least one variable (S703: NO), it sends a notification to the explanation output unit 170 indicating that the generation of validity explanation information has failed (S704) and terminates the explanation information generation process.

[0095] Note that multiple explanation templates may be defined for one explanation level in the explanation template table 600. In this case, for example, the explanation selection unit 150 may input multiple explanation templates corresponding to the explanation level to the explanation information generation unit 160. In this case, the explanation information generation unit 160 executes the process of step S702 for each of the multiple explanation templates, executes the process of step S704 when information has been assigned to all variables for at least one template, and executes the process of step S705 when information has not been assigned to at least one variable for all templates.

[0096] 8 is a diagram showing an example of the screen layout of a validity explanation information output screen 800. The validity explanation information output screen 800 is realized by the explanation output unit 170.

[0097] The validity explanation information output screen 800 includes, for example, a reference target information display area 810, an explanation generation success / failure information display area 811, a validity explanation display area 820, an explanation information file output format selection button 830, and a file output execution button 840. The reference target information display area 810 displays information indicating the reference target. The explanation generation success / failure information display area 811 displays information indicating the success / failure of explanation generation (for example, information indicating the determination result in step S703). The validity explanation display area 820 displays the validity explanation information output by the explanation information generation unit 160.

[0098] In the example of Fig. 8, "National Standard for the Electric Power Sector" is displayed in the compliance target information display area 810, and "Generation Successful" is displayed in the explanation generation success / failure information display area 811. Also, in the example of Fig. 8, the validity explanation display area 820 displays the following: "Network access control that complies with the national standard for the electric power sector is realized by introducing communication control equipment. The reason for using the introduction of communication control equipment is that the devices that make up the system are configured with an embedded OS, and the utilization of authentication functions and the introduction of communication control equipment were candidates as realization technologies, and the introduction of communication control equipment was chosen in consideration of the threat of unauthorized access from outside."

[0099] When the explanation information file output format selection button 830 is selected, it becomes possible to select a file format including, for example, a file type such as text, a file template previously registered by the user, etc. When the file output execution button 840 is selected, a file including the validity explanation information is output in accordance with the selected file format.

[0100] As described above, the explanatory information generating device 100 of this embodiment can flexibly change the explanation of the appropriateness of security measures that comply with laws, regulations, standards, etc. being implemented in a system or having been implemented in a system depending on the compliance target and the person to whom the explanation is given, i.e., generate an appropriate explanation. Furthermore, the explanatory information generating device 100 can obtain the explanation of the appropriateness with a small amount of work.

[0101] In this embodiment, the explanation information generating device 100 outputs a validity explanation in natural language because the part of the explanation template excluding the variables and the information assigned to the variables of the explanation template (the reference target indicated by the reference target information and the related information) are all written in natural language. In other words, the explanation information generating device 100 can output an explanation that is easy for the person to understand.

[0102] In this embodiment and other embodiments, examples are mainly described in which the system in which security measures are implemented or have been implemented is an industrial system such as a power generation system, but the explanation information generating device 100 can also be applied to any system in which security measures are implemented or have been implemented, such as an IT (Information Technology) system.

[0103] The explanation information generating device 100 of this embodiment supplements the missing information when information is insufficient in explanation generation. In this embodiment, differences from the first embodiment will be mainly described, and explanations of similarities with the first embodiment will be omitted as appropriate.

[0104] [Configuration Example of Explanation Information Generating Device] Fig. 9 is a block diagram showing an example of the functional configuration of the explanation information generating device 100. The explanation information generating device 100 of this embodiment differs from the explanation information generating device 100 of the first embodiment (Fig. 1) in that it includes an explanation information generation review unit 910, which is a functional unit, instead of the explanation information generating unit 160, and in that it includes an additional input review unit 920, which is also a functional unit. In this embodiment, the explanation information generation review unit 910 and the additional input review unit 920, which are both functional units, are included in the processing unit 21 of the information processing device 20 shown in Fig. 2.

[0105] The explanation information generation review unit 910 attempts to generate validity explanation information using the reference object, explanation template information, and related information. If the explanation information generation review unit 910 fails to generate the validity explanation information because, for example, related information corresponding to the type indicated by at least one variable included in the explanation template does not exist, the explanation information generation review unit 910 transmits to the additional input review unit 920 a notification indicating the generation failure and information indicating the variables to which information has not been assigned.

[0106] The additional input review unit 920 reviews an additional information input request to have the user input the missing information as additional information based on the information on the generation failure and unassigned variables from the explanation information generation review unit 910.

[0107] If the additional input review unit 920 determines that the missing information is information about the compliance target and / or the person being explained to (for example, if information corresponding to the variable "[compliance target]" is not obtained), it sends an additional information input request to the explanation adjustment information input unit 110, and if it determines that the missing related information is information about the system and / or countermeasures (for example, if information corresponding to the variable "[threat]", the variable "[system requirements]", the variable "[equipment requirements]", the variable "[implementation technology]", or the variable "[countermeasures]", etc. is not obtained), it sends an additional information input request to the system information / countermeasures input unit 120.

[0108] Upon receiving a request for inputting additional information, the explanation adjustment information input unit 110 and / or the system information / measures input unit 120 outputs an additional information input screen for accepting input of the missing information (additional information) indicated by the request for inputting additional information.

[0109] [Processing of Explanation Information Generation Review Unit] Fig. 10 is a flowchart showing an example of explanation information generation review processing by the explanation information generation review unit 910. The explanation information generation review processing of Fig. 10 is similar to the explanation information generation processing of Fig. 7 except that the processing of step S1000 is performed instead of the processing of step S704, and the processing of each step is executed by the explanation information generation review unit 910.

[0110] If the explanation information generation review unit 910 determines that information has not been assigned to at least one variable (S703: NO), it sends a notification indicating that the generation of validity explanation information has failed and information indicating the variables to which information has not been assigned to the additional input review unit 920 (S1000), and the explanation information generation review process ends.

[0111] 11 is a diagram showing an example of the screen configuration of an additional information input screen. The additional information input screen 1100 is realized by the explanation adjustment information input unit 110 and the system information / measures input unit 120. The additional information input screen 1100 includes an additional information input area 1110 for receiving input of additional information.

[0112] 11 , additional information is accepted in the case where the missing information is “threat” in the additional information input area 1110. Therefore, the example of the additional information input screen 1100 in FIG. 11 is realized by the system information / measure input unit 120.

[0113] The additional information input area 1110 includes, for example, a pull-down input area 1111, a file reading area 1112, a question display area 1113, and a user action instruction display area 1114. The pull-down input area 1111 is an area for selecting additional information (information about threats in the example of FIG. 11 ) from multiple candidates of additional information that have been predetermined (or obtained from external information such as the Internet) in a pull-down manner and accepting the input.

[0114] The file reading area 1112 is an area for specifying and reading an electronic file that contains additional information (information about threats in the example of Figure 11) or an electronic file that contains information for extracting or inferring the additional information.

[0115] The question display area 1113 displays a question to the user regarding additional information (information about a threat in the example of Figure 11), and an answer to the question about the additional information is entered by selecting an answer box ("YES" or "NO") displayed next to the question display area 1113.

[0116] The user action instruction display area 1114 displays information indicating an action instruction that is an instruction to prompt the user to input additional information. In the example of Fig. 11, the user action instruction display area 1114 displays an instruction statement "Please enter any information related to the threat that comes to mind" as an action instruction to the user, and additional information is input by inputting a response statement corresponding to the instruction statement into a text box displayed below the user action instruction display area 1114 (by the user taking action in response to the action instruction).

[0117] 11 , the checkbox located next to the file reading area 1112 is checked, and therefore the threat indicated by "C:\File\path\threat.file" input into the file reading area 1112 is determined as additional information. The explanation adjustment information input unit 110 and / or the system information / measure input unit 120 (in the example of FIG. 11 , the system information / measure input unit 120) transmits the determined additional information to the explanation level setting unit 130 or the related information generation unit 140 (in the example of FIG. 11 , to the related information generation unit 140), and an attempt is made to generate explanation information using the determined additional information in the same manner as in the first embodiment.

[0118] In addition, the candidate information in the pull-down in the pull-down input area 1111, the question content in the question display area 1113, and the instruction content in the user action instruction display area 1114 may be generated by the additional input review unit 920 and included in the additional information input request, or the additional input review unit 920 may send only the information indicating the unassigned variables to the explanation adjustment information input unit 110 and / or the system information / measures input unit 120, and the explanation adjustment information input unit 110 and / or the system information / measures input unit 120 may generate the candidate information, the question content, and the instruction content.

[0119] The candidate information may be information inferred from registered related information. In addition, the question content and the instruction content may be generated using a predetermined algorithm such as AI, or may be generated using pre-stored information.

[0120] In this embodiment, when information is insufficient when generating an explanation, the explanation information generation device 100 presents the missing information to the user and prompts them to enter additional information, making it easier to successfully generate validity explanation information.

[0121] In this embodiment, if the explanation information generating device 100 fails to generate the validity explanation information, it will re-generate the validity explanation information. However, even if the generation of the validity explanation information is successful, it may re-generate the validity explanation information in accordance with the user's instructions.

[0122] Specifically, for example, the explanation information generating device 100 selects an explanation template based on the explanation level, but there may be cases where a user who reads the validity explanation information determines that the level of specificity of the validity explanation information is too high or too low.

[0123] To deal with such cases, after the explanation output unit 170 outputs the validity explanation information output screen 800, the explanation adjustment information input unit 110 may receive, as additional information, an instruction to reset the explanation level (for example, an instruction to raise the explanation level by one, an instruction to lower the explanation level by one, or an instruction to set the explanation level to a specific value) in accordance with an input from the user. In this case, the explanation adjustment information input unit 110 transmits the reset instruction to the explanation selection unit 150, and the explanation selection unit 150 reselects an explanation template in accordance with the explanation level indicated by the reset instruction.

[0124] Furthermore, to deal with the above-described case, the explanation adjustment information input unit 110 may receive, as additional information, an instruction to reset the explanation partner information in accordance with input from the user after the explanation output unit 170 outputs the validity explanation information output screen 800. In this case, the explanation adjustment information input unit 110 transmits the reset instruction to the explanation level setting unit 130, and the explanation level setting unit 130 reselects the explanation level in accordance with the explanation partner information indicated by the reset instruction.

[0125] Through the above-described processing, the explanation information generating device 100 can output validity explanation information having the explanation level desired by the user.

[0126] The explanation information generating device 100 of this embodiment receives evaluations of the output explanations from users such as system operators, administrators, or system designers, and reflects the evaluations in the generation of explanations. In this embodiment, differences from the first embodiment will be mainly described, and explanations of similarities to the first embodiment will be omitted as appropriate.

[0127] 12 is a block diagram showing an example of the functional configuration of the explanation information generating device 100. The explanation information generating device 100 of this embodiment differs from the explanation information generating device 100 of the first embodiment in that the explanation output unit 170 is connected to an explanation output / evaluation unit 1210, which is stored in the explanation DB 180.

[0128] The explanation output / evaluation unit 1210 outputs information indicating the validity explanation information output from the explanation information generation unit 160 and information indicating an evaluation of the validity explanation information to the display screen of the terminal device 26 a and / or the terminal device 26 b connected to the explanation information generation device 100. In addition, the explanation output / evaluation unit 1210 accepts input of an evaluation of the validity explanation information and stores the input evaluation in the explanation template table 600.

[0129] 12, the explanation output / evaluation unit 1210 is provided outside the explanation information generation device 100, but may be built into the explanation information generation device 100. The explanation output / evaluation unit 1210 may be configured by the input / output I / F 23.

[0130] 13 is a diagram showing an example of the data configuration of the explanation template table 600. The explanation template table 600 of this embodiment differs from the explanation template table 600 of the first embodiment in that it further includes an evaluation value column 1310.

[0131] Information indicating the evaluation value given by the user to each explanation template is stored in the evaluation value column 1310. Specifically, for example, the evaluation value column 1310 stores evaluation values ​​previously given by the user to the validity explanation information using each explanation template via the validity explanation information output screen 800 shown in FIG. 14 (to be described later).

[0132] For example, a user may select an evaluation value from a predetermined scale (e.g., five scales) for the validity explanation information, and the average value of the selected evaluation values ​​may be stored in the evaluation value column 1310 corresponding to the explanation template corresponding to the validity explanation information. Any form of quantitative (e.g., a predetermined type of statistical value) or qualitative evaluation value that can express the merits or demerits of each explanation template may be used. Note that the initial value of the evaluation value corresponding to each explanation template may be, for example, predetermined (for example, if the evaluation value is on a five-scale scale, the initial value may be the median value, such as "3").

[0133] In this embodiment, the explanation selection unit 150 uses the information stored in the explanation level column 620 and the evaluation value column 1310 of the explanation template table 600 to select an explanation template to be used for generating validity explanation information from the explanation template table 600. Specifically, for example, the explanation selection unit 150 selects from the explanation template table 600 the explanation template with the highest evaluation value (or a predetermined number of explanation templates in descending order of evaluation value) among the explanation templates corresponding to the explanation level input from the explanation level setting unit 130.

[0134] For example, when "Level 1" is input as the explanation level from the explanation level setting unit 130 to the explanation selection unit 150, the explanation selection unit 150 selects, for example, the explanation template in the explanation template table 600 that corresponds to "Level 1," which has the highest evaluation value of "30," namely, "[Countermeasure] that complies with [Compliant target] is realized by [Implementation technology]. The reason for using [Implementation technology] is because the threat to the target is [Threat]."

[0135] [Example of Screen Output of Explanation Output / Evaluation Input Process] FIG. 14 is a diagram showing an example of the screen layout of a validity explanation information output screen 800 output by the explanation output / evaluation unit 1210. As shown in FIG.

[0136] The validity explanation information output screen 800 of this embodiment differs from the validity explanation information output screen 800 of the first embodiment in that it further includes an evaluation value input area 1410 and an evaluation input execution button 1420. The evaluation value input area 1410 is an area for receiving input of an evaluation value for the explanation displayed in the validity explanation display area 820. In the example of Fig. 14 , "4" is input into the evaluation value input area 1410 as an evaluation value for the explanation displayed in the validity explanation display area 820.

[0137] When the evaluation input execution button 1420 is selected, the explanation output / evaluation unit 1210 reflects the evaluation value entered in the evaluation value input area 1410 in the evaluation value corresponding to the explanation template in the explanation template table 600 that corresponds to the validity explanation displayed in the validity explanation display area 820.

[0138] As described above, the explanation information generation device 100 of this embodiment accepts evaluations from users, such as system operators, administrators, or system designers, regarding the content of the output validity explanation information, and reflects the evaluations in the generation of explanations. This enables the explanation information generation device 100 to generate validity explanation information that reflects the requests and preferences of users.

[0139] The present invention is not limited to the above-described embodiments, and various other applications and modifications are possible without departing from the spirit of the present invention as defined in the claims. For example, the above-described embodiments have been described in detail and specifically to clearly explain the present invention, and are not necessarily limited to those including all of the components described. Furthermore, it is possible to replace part of the configuration of one embodiment with a component of another embodiment. It is also possible to add a component of another embodiment to the configuration of one embodiment. It is also possible to add, replace, or delete other components from part of the configuration of each embodiment.

[0140] For example, the functions of the explanation information generation device 100 in the above-described embodiment may not be located in the same device, but may be distributed across multiple devices, with the functions being realized as a single system by a group of related devices.

[0141] Furthermore, the above-described configurations, functions, processing units, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. Broadly defined processor devices such as FPGAs (Field Programmable Gate Arrays) and ASICs (Application Specific Integrated Circuits) may also be used as hardware. The above-described configurations, functions, etc. may also be implemented in software by a processor interpreting and executing programs that implement the respective functions. Information such as programs, tables, and files that implement the respective functions may be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.

[0142] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected.

Claims

1. An explanatory information generating device comprising a processor and a memory, wherein the memory holds at least one of compliance target information indicating rules to which security measures for a system are to be complied with and explanation recipient information indicating the person to whom the explanation is to be given, and wherein the processor determines an explanation level indicating the degree of specificity of a validity explanation, which is an explanation of the validity of the security measures for the system, based on at least one of the compliance target information and explanation recipient information, generates the validity explanation based on the determined explanation level, and generates data for outputting the generated validity explanation.

2. An explanation information generating device as described in claim 1, wherein the memory holds explanation level information indicating the correspondence between at least one of the reference subject and the explanation partner and the explanation level, and the processor, in determining the explanation level, obtains from the explanation level information the explanation level corresponding to at least one of the reference subject and the explanation partner indicated by at least one of the reference subject information and the explanation partner information.

3. An explanatory information generating device as described in claim 2, wherein the processor receives an instruction to reset the explanation level of the output validity explanation, regenerates the validity explanation based on the explanation level indicated by the reset instruction, and generates data for outputting the regenerated validity explanation.

4. An explanation information generation device as claimed in claim 2, wherein the memory holds explanation template information which is correspondence information between the explanation level, an explanation sentence including a variable, and an explanation template which indicates the type of the variable, and related information which indicates candidates for information to be assigned to the variable for each type of variable, and the processor obtains from the explanation template information an explanation template which corresponds to the determined explanation level, obtains from the related information the candidate which corresponds to the type of variable included in the obtained explanation template, and generates the validity explanation by assigning the obtained candidate to the variable of the obtained explanation template.

5. An explanation information generating device according to claim 4, wherein in the explanation template information, the higher the explanation level, the greater the number of variables included in the explanation template corresponding to that explanation level.

6. An explanatory information generating device according to claim 4, wherein the portion of the explanatory template excluding the variables and the candidates in the related information are written in natural language.

7. An explanatory information generating device as described in claim 4, wherein, when the processor determines that the candidate cannot be assigned to at least one variable of the acquired explanatory template, it generates information for outputting an additional information input screen that indicates the type of each of the at least one variable and prompts the user to input additional information to be assigned to the at least one variable.

8. An explanatory information generating device as described in claim 7, wherein the processor generates a question regarding the additional information and an instruction to act to prompt the user to input the additional information based on a predetermined algorithm, and includes the generated question and instruction to act in the information for outputting the additional information input screen.

9. An explanation information generating device according to claim 4, wherein the explanation template information indicates an evaluation value corresponding to the explanation template, and the processor obtains from the explanation template information the explanation template with the highest evaluation value among the explanation templates corresponding to the determined explanation level.

10. An explanation information generating device as described in claim 9, wherein the processor includes information for accepting input of the evaluation value for the generated validity explanation in data for outputting the generated validity explanation, accepts input of the evaluation value for the generated validity explanation, and updates the evaluation value of the acquired explanation template in the explanation template information based on the evaluation value input.

11. A method for generating explanatory information using an explanatory information generating device, wherein the explanatory information generating device has a processor and a memory, and the memory holds at least one of compliance target information indicating rules to which security measures for a system are to be complied with and explanation recipient information indicating the person receiving the explanation, and the explanatory information generating method comprises the steps of: the processor determines an explanation level indicating the degree of specificity of a validity explanation, which is an explanation of the validity of the security measures for the system, based on at least one of the information; the processor generates the validity explanation based on the determined explanation level; and the processor generates data for outputting the generated validity explanation.

Citation Information

Patent Citations

  • Injection method of projection material and injection system of projection material

    JP2024052179A

  • Security countermeasure planning system, security countermeasure planning method, and program

    WO2023105629A1

  • Image forming apparatus, attack tolerance evaluation program, and attack tolerance evaluation system

    JP2018022419A

  • Security management system and security management method

    JP2023096365A

  • Warning device, control method, and program

    WO2020194449A1