幎ã å¢å ãããµãã©ã€ãã§ãŒã³ã«å¯Ÿãããµã€ããŒæ»æ
SecurityScorecardã¯ã2023幎åããããã¹ã§éå¬ãããäžççµæžãã©ãŒã©ã ïŒThe World Economic ForumïŒã®å¹Žæ¬¡ç·äŒã§ããµã€ããŒã¬ãžãªãšã³ã¹ãšéèŠã€ã³ãã©ã«é¢ããã¬ããŒããçºè¡šããŸããã
ãã®ã¬ããŒãã«ããã瀟äŒã«ãããŠãµã€ããŒã»ãã¥ãªãã£ãžã®é¢å¿ã¯10幎以äžã«ãããé«ãŸã£ãŠããã«ããããããããµã€ããŒã¬ãžãªãšã³ã¹ã¯æ¹åããã©ãããæªåããŠããããšãæããã«ãªããŸããã
2023幎ã®äžççµæžãã©ãŒã©ã ã§çºè¡šããããææ°ã®å¹Žæ¬¡ãµã€ããŒã¬ããŒãïŒGlobal Cybersecurity Outlook 2023ïŒã«ãããšãããžãã¹ãªãŒããŒããµã€ããŒãªãŒããŒã®90ïŒ ãããµãŒãããŒãã£ã®ãµã€ããŒã¬ãžãªãšã³ã¹ã«æžå¿µãæ±ããŠããããšã瀺ãããŠããŸãã
å®éã54ïŒ ã®çµç¹ããµãŒãããŒãã£ãä»ãã䟵害ãçµéšããŠãããšå ±åããŠããããšãèãããšãããããæžå¿µã¯æ£åœã§ããããšãæããã§ãã
å€§èŠæš¡ãªãµã€ããŒæ»æã§é«ãŸãæ¿åºã®ãµãã©ã€ ãã§ãŒã³ãªã¹ã¯ãžã®é¢å¿
åæ§ã«ãäžçååœã®æ¿åºããµãã©ã€ãã§ãŒã³ã®ãªã¹ã¯ãæžå¿µããŠããŸãã
2020幎3æãã12æãŸã§ã®9ã«æéã«ããããæ»æè ãæ°Žé¢äžã§äŸµæ»ãç¶ããã¢ã¡ãªã«ã®äž»ãªæ¿åºæ©é¢ã«ãäŸµå ¥ããŠããSolarWindsäºä»¶ã¯ããµãã©ã€ãã§ãŒã³ãªã¹ã¯ã«å¯Ÿããæ¿åºã®é¢å¿ãåèµ·ããŸããã
ããã«ã2023幎3æã«çºçãããã³ãã¥ãã±ãŒã·ã§ã³ãœãããŠã§ã¢ãææãããããã¹ã®3CX瀟ã®è£œåãæ¹ããããããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³æ»æã¯ããªã¹ã¯ãããã«æ·±å»ã§å€æ§ã§ãããã瀟äŒã«åŒ·ãèªèãããŸããã
ãã€ãã³æ¿æš©ãåœå®¶ãµã€ããŒã»ãã¥ãªãã£æŠç¥ïŒNational Cybersecurity StrategyïŒãçºè¡šããããšã§ãè€æ°ã®åéã®ãªã¹ã¯ç®¡çæ©é¢ã¯ãã§ã«ããµãã©ã€ãã§ãŒã³ãªã¹ã¯ã®æž¬å®ãå ±åã管çãè¡ãããã®æ°ããªèŠä»¶ãå ¬åžãå§ããŠããŸãã
欧å·ã§ã¯ããµã€ããŒã»ãã¥ãªãã£ã¬ãžãªãšã³ã¹æ³æ¡ïŒCybersecurity Resilience ActïŒãžã®æ°èŠä»¶ãšããŠã補åã®è匱æ§ãææžåããæ°ããªèŠä»¶ããããã€ããŒã«èª²ãããšã«ãªããŸããç¹ã«ããã©ã³ã¹ã§ã¯ãæ°ãµã€ããŒã¹ã³ã¢æ³ïŒnew cyberscore lawïŒãå¶å®ãããã€ã³ã¿ãŒãããã«æ¥ç¶ãããã©ãããã©ãŒã äŒæ¥ã«å¯Ÿããã·ã¹ãã ãããã»ã¹ã®ç¬¬äžè ç£æ»ã«åºã¥ããµã€ããŒã¬ãžãªãšã³ã¹ã«é¢ãããã¬ããŒãã«ãŒããã®é瀺ã矩åä»ããããäºå®ã§ãã
ãã®ããã«ãè¿å¹Žã®å€§èŠæš¡ãªãµã€ããŒæ»æãäžçäžã®æ¿åºã®ãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãžã®é¢å¿ãé«ãããã£ããã«ãªã£ãŠããŸãã
ãµã€ã㌠ã¬ãžãªãšã³ã¹ãæ§ç¯ããããã«
ããããèŠæš¡ãããããæ¥çš®ã®çµç¹ãä¿¡é Œãç²åŸãããµã€ããŒã¬ãžãªãšã³ã¹ãæ§ç¯ããã«ã¯ããµãã©ã€ãã§ãŒã³ã«å«ãŸããããŒãããŒãè«è² æ¥è ããµãŒãããŒãã£ããµãŒãããŒãã£ã®ãã³ããŒãå«ããäžçäžã®ããããçµç¹ããµã€ããŒãªã¹ã¯ã枬å®ããå®éåããããšãæ±ããããŠããŸãã
以äžããµã€ã㌠ã¬ãžãªãšã³ã¹ãæ§ç¯ããããã«å¿ èŠãªããšã説æããŸãã
ãµã€ããŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ããšã¯
ãµãã©ã€ãã§ãŒã³ã¯ã補åãæ¶è²»è ã«å±ããŸã§ã®ã©ã®æ®µéã«ãããŠãå±éºã«ãããããå¯èœæ§ããããŸãããã®ããããµãã©ã€ãã§ãŒã³ãããžã¡ã³ãã¯ã補åã®è£œé ãšæµéã®ã¿ã ãã察象ãšããã®ã§ã¯ãªããèšèšãéçºãæµéãå±éãååŸãä¿å®ãç Žæ£ãšãã£ã補åã®ã©ã€ããµã€ã¯ã«ã远跡ã»ç®¡çããå¿ èŠããããŸãã
ãã®æŠå¿µããµã€ããŒé åã«åœãŠã¯ãããšãããšããµã€ããŒé åã«ããããµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ãã¯ã補åããµãŒãã¹ã®ãµãã©ã€ãã§ãŒã³ã«é¢é£ãããªã¹ã¯ãç¹å®ãè©äŸ¡ã軜æžããããšã«ããããµãã©ã€ãã§ãŒã³ã®å®å šæ§ã確ä¿ããããã»ã¹ãšãªããŸãã
ãµã€ããŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ããéèŠãªçç±
ç±³åœç«æšæºæè¡ç ç©¶æïŒNational Institute of Standards and TechnologyïŒã«ãããšãäœã³ã¹ããçžäºéçšæ§ãè¿ éãªæè¡é©æ°ãå¯èœã«ããŠããèŠå ã¯ãåæã«ããµã€ããŒãµãã©ã€ãã§ãŒã³ã«å¯Ÿãã䟵害ã®ãªã¹ã¯ãé«ããå¯èœæ§ãããããšãæããã«ãªã£ãŠããŸãã
ãµãã©ã€ãã§ãŒã³ã®ãªã¹ã¯ã«ã¯ãäžæ£çç£ãªã©ã®ç©ççãªè åšãããã¯ã©ãŠãã»ãã¹ãã£ã³ã°ã»ãããã€ããŒã®ãµãŒã䟵害ãªã©ã®ããžã¿ã«çãªãã®ãŸã§ããããããã®ãå«ãŸããŸããããã¯é¡§å®¢ã«å¯Ÿãããªã¹ã¯ããçµç¹ã®ããŒã¿æŒæŽ©ãæå³ãã倧ããªã³ã¹ãã®ãããåé¡ã§ãããããããããµã€ããŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ããããžã¿ã«ã»ãµãŒãããŒãã£ã«äŸåããçµç¹ã«ãšã£ãŠéåžžã«éèŠã§ããçç±ã§ãã
ããžã¿ã«ã»ãµãã©ã€ãã§ãŒã³ã«å¯Ÿããè åšã®è»œæžã¯ãç¹å®ã®å人ãéšçœ²ãäžã€ã®ããšã ããæ åœãããããªããµã€ãåãããçµç¹ã§è¡ãããšã¯ã§ããŸããããµã€ããŒãªã¹ã¯ã®è»œæžã¯å æ¬çã«è¡ãå¿ èŠãããã®ã§ãã
ãµãŒãããŒãã£ã®ãªã¹ã¯ç®¡ç
ã§ã¯ãå®éã«ã©ã®ãããªæé ã§ãµã€ããŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ããè¡ãã¹ããªã®ã§ãããããæé ã®äŸã¯ä»¥äžã®éãã§ãã
ïŒ1ïŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ãããã°ã©ã ãæ§ç¯ããããã«ããµãŒãããŒãã£ãã³ããŒã管çããããžãã¹ãŽãŒã«ãšç®çãç¹å®ãã
ïŒ2ïŒãã¹ããã©ã¯ãã£ã¹ã«åºã¥ãããªã·ãŒãšæé ãçå®ãŸãã¯åè©äŸ¡ãã
ïŒ3ïŒèªç€Ÿãç¹ã«ã°ããŒãã«ã§äºæ¥å±éããŠããäŒæ¥ã«ãããŠã¯ãå
šãµãŒãããŒãã£ãã³ããŒã®ç¹å®ãšãªã¹ãã®äœæãåãã³ããŒã®åœ¹å²ãææ¡ãã
ïŒ4ïŒç®¡çåºæºã«åºã¥ãããµãŒãããŒãã£ãåé¡ãã
ïŒ5ïŒãã³ããŒãããŒãããŒã®ãªã¹ã¯è©äŸ¡ã«åœ¹ç«ã€ã¢ã³ã±ãŒãã®åçãéåä¿¡ããããã®ããã»ã¹ãã»ãã¥ãªãã£è©äŸ¡ãã©ãããã©ãŒã ãéžå®ãããã«å ããŠã第3è
ã®å®¢èгçãªè©äŸ¡ãå«ãããªã¹ã¯è©äŸ¡ã宿œãã
ïŒ6ïŒå
éšåã³ãµãŒãããŒãã£ã®åé¢ä¿è
ãžã®å¹æçã»å¹ççãªã³ã©ãã¬ãŒã·ã§ã³æ¹æ³ã確ç«ãã
ïŒ7ïŒè©äŸ¡çµæãšãŽãŒã«ã®ã®ã£ããã確èªããæ¹åãã©ã³ãäœæãå®è¡ã«ç§»ã
ïŒ8ïŒãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ãããã°ã©ã ã®äŸ¡å€ã瀺ããæšé²åãç¶æããããã«ãããžãã¹ãªãŒããŒã«äœãã©ã®ããã«å ±åãã¹ãããçè§£ãã
ïŒ9ïŒãµãã©ã€ãã§ãŒã³ã®ãµã€ããŒã¬ãžãªãšã³ã¹ãé«ããããŒã«ã掻çšãã
ãµãã©ã€ãã§ãŒã³ãªã¹ã¯ãããžã¡ã³ãã®åãçµã¿ãæçããã«ã€ããã¢ãã¿ãªã³ã°ã®èªååãšç¶ç¶ã瀟å å€ã®ãªã¹ã¯æ å¢ã®æž¬å®ãšå ±åã«ãçæãããšè¯ãã§ãããã