WithSecure(ãŠã£ãºã»ãã¥ã¢)ã¯ããã£ã³ã©ã³ãã»ãã«ã·ã³ãã«ãããŠãSphere 2023ãã5æ24æ¥ïœ25æ¥ã®2æ¥éã«ãããéå¬ãããæ¬çš¿ã§ã¯ãWithSecure CISO(Chief Information Security OfficerïŒæé«æ å ±ã»ãã¥ãªãã£è²¬ä»»è )ã®Christine Bejerasco(ã¯ãªã¹ãã£ã³ã»ããã©ã¹ã³)æ°ã®è©±ã玹ä»ããã
æ±ããããCISOã®åœ¹å²
åžäŒè ã«ç޹ä»ãããç»å£ããããã©ã¹ã³æ°ã¯ãããªãã®çµç¹ã§ã®åœ¹å²ã¯äœã§ããïŒåéãšããŠã®ãµã€ããŒã»ãã¥ãªãã£ã¯ãŸã æªçã§ãã£ãããããŸãåºãçè§£ãããŠããªãã£ãããCISOãããªãã£ããããã®ã§ãäœã§ãããã®ç¶æ ã§ãããã¡ããããã®ç«å Žã¯ããªãæ°ãããã®ã§ãããšãåé ã«è¿°ã¹ãã
-

WithSecure CISO(Chief Information Security Officer)ã®Christine Bejerasco(ã¯ãªã¹ãã£ã³ã»ããã©ã¹ã³)æ°
ããããäœã§ãããã®ç¶æ ã®èŠå ãšããŠã¯ãçµç¹ãæ±ããè åšã«å¯ŸããŠå©çšããŠãããœãªã¥ãŒã·ã§ã³ããµãŒãã¹ã¯ããšãããã°æè¡çãªããã£ãã©ãªãŒã䜿ãåŸåããããçµå¶é£ãé ãããŠããåãããããšåæ°ã¯èªã£ãŠããã
ãã®ãããåæ°ã¯ãç§ãã¡ãè¡ã£ãŠããããšãçè§£ããŠãããå¿ èŠãããã®ã§ããããããç¹ã«çµç¹ã®ãµã€ããŒã»ãã¥ãªãã£ã»ããã°ã©ã ããŸã æªæçã§ããå Žåã«ã¯ãCISOã®åœ¹ã«ã¯ç«ã¡ãŸããããšæèšããã
ãªããªããCISOã¯çµç¹ã®ããŸããŸãªå±€ãžã®çè§£ãæ·±ãããµã€ããŒã»ãã¥ãªãã£ã»ããã°ã©ã ãå®è¡ãããŠããããšã確èªããå¿ èŠããããããããŸããŸãªå±€ã«å¯Ÿå¿ããã¢ãã«ã®äœæããã€ã³ãã«ãªããšããã
ãSecurity Outcomes Canvasããšã¯
ããããç¶æ³ããµãŸããããã©ã¹ã³æ°ã¯ããããçµå¶è ãçè§£ã§ããèšèã圌ããæ±ããŠããæ å ±ããããŠå®è¡ã®ããã®åºçºç¹ã瀺ãããšãã§ããæ¹æ³ããããšããããã©ãã§ããããïŒããã§ãæåã®ããŒãžã§ã³ãšãªããSecurity Outcomes Canvas 1.0ã(ã»ãã¥ãªãã£ã»ã¢ãŠãã«ã ã»ãã£ã³ãã¹)ã玹ä»ããŸãããšè©±ããã
å瀟ã§ã¯åŸæ¥ãããã¢ãŠãã«ã ããŒã¹ã»ãã¥ãªãã£ããæå±ããŠãããããã¯å€§å±çãªèгç¹ã§ã»ãã¥ãªãã£ãæããçµç¹ã»äŒæ¥ãšããŠã©ã®ãããªç®æšãæã¡ãããžãã¹ãéæããã®ãããããŠãµã€ããŒã»ãã¥ãªãã£ãããžãã¹ã®ç®æšãéæããããã«ãããã«ãµããŒãã§ããããèããããšãšäœçœ®ä»ããŠããã
ã»ãã¥ãªãã£ã»ã¢ãŠãã«ã ã»ãã£ã³ãã¹ã¯ãã¢ãŠãã«ã ããŒã¹ã»ãã¥ãªãã£ãå®çŸããããã®ãã®ã§ãããããžãã¹ã¢ãã«ã»ãã£ã³ãã¹ãåèãšãã以äžã®7é ç®ã§ã®åãçµã¿ãæšå¥šããŠããã
1. ãBusiness Outcomesã(ããžãã¹ã®ææ)
2. ãPrimary Risksã(ãªã¹ã¯)
3. ãSecurity Outcomesã(ã»ãã¥ãªãã£ã®ææ)
4. ãMajor Opportunitiesã(æ©äŒ)
5. ãKey Initiativesã(ã€ãã·ã¢ãã£ããåªå äºé )
6. ãKey Resourcesã(ãªãœãŒã¹)
7. ãCostã(ã³ã¹ã)
ã§ã¯ã7é ç®ã«ã€ããŠå ·äœçã«ã¿ãŠãããããŸãã(1)ã«ãããŠããžãã¹ã®ææãå®ãããããžãã¹ã®ææã¯çµç¹ãã®ãã®ãäœãéæããããšããŠããã®ããšããããšã§ãããæŠç¥ã«ã€ããŠçµå¶å¹¹éšãã¹ããŒã¯ãã«ããŒã«ç¹°ãè¿ã説æããçµç¹ãæ¬åœã«éæããããšããŠããããšãçè§£ããŠãããã
ãã®åŸã(2)ãªã¹ã¯ã«ç§»è¡ãããCISOã¯ãããžãã¹ã»ã¢ãŠãã«ã ã«åœ±é¿ãäžããŠããäžäœ3ïœ5åã®ãªã¹ã¯ã«ãã©ãŒã«ã¹ãäžäŸãšããŠã¯ã顧客ãžã®ãµãã©ã€ãã§ãŒã³æ»æãæ å ±æŒãããã€ã³ãã©å¶åŸ¡ã®åªå€±ããµãŒãã¹åæ¢ãªã©ã ã
ãããã®ãªã¹ã¯ã軜æžããããžãã¹ã®ææãããé«ã確çã§éæããããã«å¿ èŠãªã»ãã¥ãªãã£äžã®ææãšã¯äœããçµç¹ãå®ãããã«ã¯ããã³ããŒããµãã©ã€ã€ãŒããµãã©ã€ãã§ãŒã³ã«ãããããŸããŸãªçµç¹ã®äººãã¡ãããµã€ããŒã»ãã¥ãªãã£ã«å¯Ÿããèãæ¹ãé«ããŠããå¿ èŠãããããããã®ãªã¹ã¯ã¯ãããžãã¹ã®ææã®æåçãäœäžããããã®ã ããã ã
ãªã¹ã¯ãç¹å®ã§ãããæ¬¡ã«(3)ã»ãã¥ãªãã£ã®ææã«ç§»ããããã©ã¹ã³æ°ã¯ãã»ãã¥ãªãã£ã®ææãšã¯ãããžãã¹ã®ææã«å¯Ÿãããªã¹ã¯ãäœæžããããšã«åœ¹ç«ã¡ãŸããçµç¹ãå¿ èŠãšããåºæ¬çãªã»ãã¥ãªãã£ææã¯äœããçµç¹ãæãé¢é£ããããžãã¹ææããµããŒãããããã«ãã©ã®ãããªã»ãã¥ãªãã£ææãå¿ èŠãªã®ããèããŸããããã«ãããçµç¹å ã®ããããå Žæã§ãµã€ããŒã»ãã¥ãªãã£ã®ãã€ã³ãã·ã§ã¢ãé«ãããã«ãã€ã³ããããµã€ããŒã»ãã¥ãªãã£ã®ç¶æ ãä¿ã¡ãŸãããšèª¬ãã
ãããŠãç¶ããŠã¯(4)ã®æ©äŒã ãçµç¹ã§ã»ãã¥ãªãã£ã®ææããµããŒãããã©ã®ãããªæ©äŒãããããèããã»ãã¥ãªãã£äžã®ææãéæããã®ã«åœ¹ç«ã€å¯èœæ§ã®ããäž»èŠãªæ©äŒãç¹å®ãããããã¯ãITã®ã¯ã©ãŠãåã財åããã»ã¹ã®å·æ°ãªã©ã該åœããã
ãã£ã³ãã¹ã®(1)ïœ(4)ã§ããŒã¹ã©ã€ã³ãæŽããããæ¬¡ã¯(5)ïœ(7)ã§èä»ããããŠããã(5)ã®ã€ãã·ã¢ãã£ãã§ã¯çµç¹å ã§ããžãã¹äžã®åãçµã¿ãç¹å®ãããããããžãã¹ãšããŠéæãã¹ãåãçµã¿ã§ããããšãçµç¹å ã®å¹¹éšãšåæããã
ã»ãã¥ãªãã£ã®ææã®ããã«æ¢åã®åãçµã¿ãšæ°ãã«å¿ èŠãªåãçµã¿ãæããã«ããæ¢åã®åãçµã¿ã§ã¯ãå€éšç£æ»ãã€ã³ã·ãã³ãã¬ããã³ã¹ãæ°ããªåãçµã¿ãšããŠã¯éçºãéçšãµã€ã¯ã«ãè¿ éãã€ç¶ç¶çã«è¡ãDevOpsã«ãã»ãã¥ãªãã£ãçµã¿èŸŒãã ãœãããŠã§ã¢éçºææ³ã§ããDevSecOpsã®å®è£ ãã¢ããªã±ãŒã·ã§ã³ã®SaaS(Software as a Service)åãªã©ãæããŠããã
(6)ã§ã¯çµç¹å ã®ãã¯ãããžãŒãããã»ã¹ã人æãã¯ãããšãããªãœãŒã¹ããªã¹ãã¢ããããã»ãã¥ãªãã£ææã®ããã«æ¢åã®ãªãœãŒã¹ãšå¿ èŠãªãªãœãŒã¹ãç¹å®ããã
çµç¹å ã§ããã§ã«ãµããŒãããŠãããã¯ãããžãŒã掻çšãããŠããªããã¯ãããžãŒãã©ã®ãããªæ°ãããã¯ãããžãŒãå¿ èŠãã粟æ»ããã»ããããã»ã¹ã§ã¯æ¢åã®ããã»ã¹ãæ°ããããã»ã¹ã®æç¡ãã©ã®ãããªããã»ã¹ã倿Žããå¿ èŠãããããææ¡ã人æã¯æ¢åã®åãçµã¿ã«ã¯èª°ãåãçµã¿ãæ°ããåãçµã¿ã¯èª°ãæ åœããã®ããæ±ºããã
æåŸã«(7)ã³ã¹ãã ããããã®ã»ãã¥ãªãã£ææãéæããããã«å¿ èŠãªæãéèŠãªã³ã¹ãã¯äœããã©ã®åãçµã¿ãæãè²»çšããããã®ããèªèããã€ãã·ã¢ãã£ããšãªãœãŒã¹ã®ã³ã¹ãæ§é ãå®çŸ©ãããããã«ã¯ãå€éšã³ã³ãµã«ã¿ã³ãæãMDR(Managed Detection and Response)ãµãŒãã¹ããã¬ãŒãã³ã°ãã©ãããã©ãŒã ã®ãµãã¹ã¯ãªãã·ã§ã³ã³ã¹ããªã©ã該åœããã
ãµã€ããŒã»ãã¥ãªãã£ãåŸä»ãããã®ã§ã¯ãªãããããããçµã¿èŸŒã
ããã©ã¹ã³æ°ã¯ããµã€ããŒã»ãã¥ãªãã£ã¯èªåãã¡ã®ä»äºã®äžéšã§ãããçµç¹ãå®ãããµãã©ã€ãã§ãŒã³ãå®ããå®å šãªãœãããŠã§ã¢ã ããé¡§å®¢ã«æäŸãããšããããšãä¿èšŒããŠãããããã®ãšããèªèãæã€ããšã§ãããšèª¬ãã
åæ°ã«ãããšãäŸãã°æ³åæ åœè ããµã€ããŒã»ãã¥ãªãã£ãå¥çŽã«çµã¿èŸŒãæš©éãšèª¬æè²¬ä»»ãäžããããã°ãä¿¡é Œæ§ã確ä¿ããŠãåé¡ãèµ·ãããªããšããããžãã¹ææãéæããå¯èœæ§ãé«ããªãããã®ããããµã€ããŒã»ãã¥ãªãã£ãåŸä»ãããã®ã§ã¯ãªãããããããçµã¿èŸŒãŸããç¶æ ãæãŸãããšããã
ãã®ããã§ãåæ°ã¯ãç§ãã¡ã«ã¯é¡§å®¢ãããããµãã©ã€ã€ãŒãããŸããç§ãã¡ã¯çãçžäºæ¥ç¶ãããããžã¿ã«ã®äžã§ç掻ããŠãããèªåãã¡ã®ã³ãã¥ããã£ã®å®å šã確ä¿ããããšããŠããŸãããã»ãã¥ãªãã£ã¯ãŠã§ãå šäœã«åºãã£ãŠããŸãããšã®èªèã瀺ãã
ãããŠãããã©ã¹ã³æ°ã¯ãæ£çŽãªãšãããç§ãã¡ã«ã¯ããããããŒã«ãå¿ èŠã§ãããªããªãããµã€ããŒã»ãã¥ãªãã£ã®åéã¯æªçã§ããããã®ããšãã©ã®ããã«èª¬æããããšãã課é¡ãããããã§ããSecurity Outcomes Canvasãäœæããã°ãçµç¹ã®ããŸããŸãªå±€ãšã®äŒè©±ã«äœ¿çšå¯èœãªåäžãªã¢ãã«ãçšæã§ããå®éã«å¹æãçºæ®ã§ããŸããããããã°ãçè§£ã®äžèŽãåŸãããšãã§ããããã°ã©ã ãå®è¡ã«ç§»ãããšãå¯èœã«ãªãã®ã§ãããšç· ãããã¬ãŒã³ããŒã·ã§ã³ãçµããã

