ãµã€ããŒã»ãã¥ãªãã£å¯Ÿçãšãããšæè¡çãªèª²é¡ã«ãã©ãŒã«ã¹ããã¡ã ãããçµç¹é¢ã§ã®èª²é¡ããªããããã«ããŠã¯ãããªãããšå±ããã®ã¯å·å£èšèšã®ä»£è¡šåç· åœ¹ å·å£æŽæ°ã ã
åæ°ã¯å€§æã»ãã¥ãªãã£äŒæ¥ã§ã®æ¥åãçµãŠãå é£ãµã€ããŒã»ãã¥ãªãã£ã»ã³ã¿ãŒïŒNISCïŒã«åºåã宿°ãããã®ç«å ŽãçµéšããçŸåšã¯èªèº«ãç«ã¡äžããå·å£èšèšã§äŒæ¥åãã®ã»ãã¥ãªãã£æŒç¿ãªã©ãæäŸããŠããã
1æ22æ¥ïœ25æ¥ã«éå¬ããããTECH+åãããæ¹é© EXPO 2024 Jan. åãããã®ããäŒæ¥ã«ãªãããã«ä»ãã¹ãããšãã«å·å£æ°ãç»å£ãããµã€ããŒã»ãã¥ãªãã£ã®çæ³ãšçŸå®ïŒå¹æçãªã€ã³ã·ãã³ã察å¿ã®ããã®æŠç¥ããšé¡ããŠãããèŠãããçµç¹ã®åé¡ãæèµ·ãããšãšãã«ãæè¡ç課é¡ã«ã€ããŠããã«å®æœã§ãã察çã玹ä»ããã
ãµã€ããŒã»ãã¥ãªãã£ã®çæ³ãšçŸå®ãçšé ãçŸç¶
äŒæ¥ãçµç¹ã®ãµã€ããŒã»ãã¥ãªãã£ãé·å¹Žæ¯æŽããŠããå·å£æ°ã¯ãäŒæ¥ã®ãµã€ããŒã»ãã¥ãªãã£ã«ãããçæ³ã®å§¿ã«ã€ããŠæ¬¡ã®ããã«èª¬æããã
ãçµå¶è ã®ãªãŒããŒã·ããããããµãã©ã€ãã§ãŒã³å šäœã«ããã察çãžã®ç®é ãããã瀟å å€é¢ä¿è ãšã®ã³ãã¥ãã±ãŒã·ã§ã³ãã®3ååã®äžã§ãçµå¶è ã®çè§£ããããCISOïŒChief Information Security OfficerïŒãªã©ã®ã»ãã¥ãªãã£æ åœå¹¹éšããã®äžã«CSIRTïŒComputer Security Incident Response TeamïŒãªã©ã®æ åœè ãããçµç¹æ§é ããããããã§PDCAãåããæ å ±ã·ã¹ãã éšéãšæ¥åéšéã飿ºããªãããæ¥ã ã®ã»ãã¥ãªãã£ã®åé¡ã«å¯ŸåŠããã
ãããããçŸå®ã¯éããšãããšãããå€ãããšå·å£æ°ã¯è©±ããçµå¶è ã¯ã»ãã¥ãªãã£ã«èå³ãæãããCISOãCSIRTã¯èšçœ®ãä»»åœã¯ãããŠããŠãè·åã«å³ããè¡åãããŸãã§ããŠãããã人äºç°åãããããããè€æ°ã®åé¡ç¹ãæããåæ°ã¯ãç¹ã«ãäºæ¥éšéããæ å ±ã·ã¹ãã éšéã«äžžæãããããšãã諞æªã®æ ¹æºã«ãªã£ãŠããããã ããšåæããã
ãããžãã¹ã®äžå¿ãæ ãäºæ¥éšéã®æ¹ã ããæ å ±ã·ã¹ãã éšéã«ãã»ãã¥ãªãã£ã¯æ ã·ã¹ããã£ãŠãããã ããããšäžžæãããŠããŸã£ãŠããçµç¹ãå€ããããŸããäºæ ãèµ·ããŠããçµç¹ã«éã£ãŠããã®ãããªåŸåãå€ããšæããŸããïŒå·å£æ°ïŒ
çµç¹ãšæè¡ãããããã®èª²é¡ãšã¯
çæ³ãšçŸå®ã®ã®ã£ããã®äžã§ã€ã³ã·ãã³ããèµ·ããŠããããã ããã€ã³ã·ãã³ãçºçæã®èª²é¡ã¯ããçµç¹ç課é¡ãšæè¡ç課é¡ã®2ã€ã«åé¡ã§ããããšå·å£æ°ã¯èšãã
ããã§åæ°ãææããã®ããè³ç£ç®¡çãæ§æç®¡çããã¹ã¯ãŒã管çããããã¯æ»æææ³ãšãã£ãæè¡ç課é¡ã¯ã»ãããŒãªã©ã§ããèªãããããçµç¹æ§é ãæ¥çç¹æ§ãæ³åŸãããã»ã¢ãã»ã«ããªã©çµç¹ç課é¡ãžã®é¢å¿ãé«ããªããšããç¹ã ã
ãçµç¹ç課é¡ãåå ã«ãªã£ãŠæè¡ç課é¡ãçãŸããŠããããšãå€ãã®ã«ãæè¡ç課é¡ã«çµå§ããŠãè¶ãæ¿ããŠããã±ãŒã¹ãå€ãèŠåããããŸããããããã®çµç¹ç課é¡ã«æãã€ããããŠããªãããšã«ãç§ã¯èª²é¡æãèŠããŠããŸããïŒå·å£æ°ïŒ
äŸãã°ãé«åºŠãªãã«ãŠãšã¢ã«ãã£ãŠäŸµå ¥ãããã€ã³ã·ãã³ãããã£ããšããããã®æè¡ç課é¡ã«å¯ŸããŠãé«åºŠãªæ€ç¥æ©èœãæã€Endpoint Detection and Response ïŒEDRïŒãå°å ¥ããŠã察å¿ãå®äºããããšèããããã¡ã ããããå·å£æ°ã¯ãæ°ããã·ã¹ãã ãå ¥ããããæ ¹æ¬çãªçµç¹ã®åé¡ã解決ãããŠããªãããã«ãåçºããŠããŸãã被害ãåºããããšãããããšèšãã
çµç¹ç課é¡ã¯çŸå Žã§ã¯ãªããçµå¶è ã®è²¬ä»»
ã§ã¯ãçµç¹ç課é¡ã«ã¯ãªãã¡ã¹ãå ¥ãã«ããã®ãããã®çç±ã¯ããŸããŸã ããã
äŒæ¥ãçµç¹ïŒåœäºè ïŒã¯ãããã»ã¢ãã»ã«ããç°¡åã«åãããªããäŸãã°ã人æã¯ç°¡åã«å¢ãããªãã人äºç°åããããšã»ãã¥ãªãã£é¢ä¿è ã管çè·ãå ¥ãæ¿ãããéå»ã«èµ·ãã£ãäºæ ã颚åããŠããŸãããšãããããŸããæè¡ç察çã ããªãå€éšã®ITãã³ããŒã«äžžæãããã°è¯ããšããèãæ¹ãã¯ã³ãã£ãŠããããã ã
ãã®ãããªçµç¹åŽã®ç¶æ³ã«å¯Ÿããå€éšã®ãã³ããŒã¯èªç€Ÿè£œåã売ãããšãæå€§ã®èå³ã«ãªã£ãŠããã±ãŒã¹ãå°ãªããªããããç©æ¥µçãªèª²é¡è§£æ±ºã«ã€ãªããã¥ãããšåæ°ã¯èª¬æããããŸããçµç¹ã®å€éšããèŠãç®ç·ã®ãããçµå¶çãªåé¡ãææ¡ãã«ããã
ãã®ãããªç¶æ³äžã§ãçµç¹ç課é¡ã«æãã€ããŠããªãã®ã¯ãæçµçã«ã¯çµå¶è ã®è²¬ä»»ããããå€éšããäŒããªããã°ãªããªãããšå·å£æ°ã¯æèšããã
ãã€ã³ã·ãã³ããèµ·ããæãããçµç¹çãªèª²é¡ã«æãã€ãããã£ã³ã¹ã§ãããããããªäºæ ããã£ãŠãããã®ç¶æ³ãçãã§ãã責任ã¯çµå¶è ã«ããã®ã ãšæããŸãããããèšããªãã£ãã®ããïŒåœäºè ãå€éšã®é¢ä¿è ã®ïŒãããŸã§ã®æŽ»åã®äžã§è¶³ããªãã£ãããšãªã®ã§ã¯ãªãã§ãããããïŒå·å£æ°ïŒ
ãŸããçµç¹ã®èª²é¡ã«åãçµããšãªããšãçµå¶è ããããããŸã§ãã»ãã¥ãªãã£ã®äºç®ã¯å¢ãããŠããããšããæèŠãããããã ããããã«ã€ããŠã¯ãå€éšãã³ããŒã«äžžæãããããã«æã£ãŠããéé¡ãå¢ããŠããã ãã§ã¯ãªãããèªåãã¡ã®çµç¹ã匷ãããããšã«ã€ãªãã£ãŠããªããšããã課é¡ãã ãšè¿°ã¹ãã
æè¡ç課é¡ã¯åºæ¬ãèŠçŽãããšã§æ¹åã§ãã
çµç¹çãªèª²é¡ã«ç®ãåããäžæ¹ãèªç€Ÿã®çµç¹ã匷ãããããã«ã¯æè¡ç課é¡ã®è§£æ±ºã«åããã¢ãããŒããæ¬ ãããªãã
æè¡çåé¡ã«ã€ããŠã¯ãããæ°å¹Žã®ãŒããã©ã¹ããSecure Access Service EdgeïŒSASEïŒãEDRãªã©åžžã«æ°ããããŒã¯ãŒããåºãŠããŠããããå·å£æ°ã¯ãæ»æã«éã£ãŠããçµç¹ã¯ããã以åã®åé¡ã®ããšãå€ãããšææããããããŠãããã以åã®åé¡ããšããŠã3ã€ã®å ·äœäŸã瀺ãããã®åºæ¬çãªå¯Ÿçã玹ä»ããã
䜿ãåãããã管çè ãã¹ã¯ãŒã
ããããIDã®ãªã¹ãã¢ãããã§ããŠããã®ãããã¹ã¯ãŒãã®ç®¡çç¶æ³ã¯ã©ããªã£ãŠããã®ããªã©ãåºæ¬çãªå¯Ÿçãæ¡ããªããŠã¯ãããªãã
å·å£æ°ãèŠãŠããã±ãŒã¹ã§ãã管çè ãã¹ã¯ãŒãã®äœ¿ãåããåé¡ã«ãªã£ãããšããããšããããã®åå ãšããŠãå§èšå ãå€éšã«å¯ŸããŠãåããã¹ã¯ãŒãã«èšå®ããªãããã«äŒããŠããªããããããŠå§èšå ããäŸé ŒãããŠããªãããšãããããããªããç¶æ³ã«ãããšèªã£ãã
ãã®äŸã®å¯ŸçãšããŠå·å£æ°ã¯ã¢ã«ãŠã³ãã®æ£åžããšå ±éãã¹ã¯ãŒãã®æ²æ» ãæšå¥šããã
瀟å ã®ã©ãããã§ãæ¥ç¶ã§ããå éšãµãŒã
å·å£æ°ã¯ãæ¥åã¢ããªã±ãŒã·ã§ã³ã¯WebããŒã¹ã«ãªã£ãŠããŠããå®éã¯OSããããSecure Shell ïŒSSHïŒãšRemote Desktop Protocol ïŒRDPïŒã§ã¡ã³ããã³ã¹ããŠããç¶æ³ã®ããšãå€ãããšææããã
ãæ»æè ãåºç€éšåã«äžæ£ã¢ã¯ã»ã¹ããŠç®¡çè æš©éã«ãã°ã€ã³ããŠããŸãã°ãã©ããªã«é«åºŠãªã»ãã¥ãªãã£æ©èœããã£ãŠãæ¢ãããããªããã§ããSSHãRDPã§æ¥ç¶ããåºç€éšåãã瀟å ã®ã©ãããã§ãã€ãªããç¶æ ã«ãªã£ãŠããã®ã§ããã°ããã®éšåã¯ã¯ã©ãŠãã«ãä»»ãããŠããŸã£ãŠãè¯ããããããŸãããïŒå·å£æ°ïŒ
å ããŠåæ°ã¯ãæ¥ç¶å ã®å¶éãå³ããã«ãããŠã»ããããšè©±ããããæ»æãåããå Žåã§ããå¶éã匷ãããããšã«ãã£ãŠè¢«å®³ã®è»œæžã«ã€ãªãããšç¶ããã
æªæŽ»çšã®ã»ãã¥ãªãã£æ©åš
äŸãã°ããã¡ã€ã¢ãŠã©ãŒã«ãå°å ¥ããæãçµå¶è ãäºæ¥éšéãæ å ±ã·ã¹ãã éšéããã³ããŒã«å§èšããçµæããã³ããŒã¯ã«ãŒã«ãå ¥ããªãæå°éã®èšå®ã§é²ããããšã«ãªããçµæãšããŠå šå¡ã®æ¥åãå§è¿«ããªããã®ã®ãæ»æè ãç°¡åã«æ»æã§ããŠããŸããšããç¶æ³ãçãŸããã
ãã®ãããªèª²é¡ã«å¯Ÿããå·å£æ°ã¯ãæ°ãããã®ãè³Œå ¥ããã®ã§ã¯ãªããæ¢åã®æ©åšã補åããµãŒãã¹ã掻çšããã¹ããã ãšã¢ããã€ã¹ããã
ãä»ãããªãœãŒã¹ãæå€§é䜿ãã ãã§ããèªç€Ÿã®ã»ãã¥ãªãã£ãåäžããã䌞ã³ãããããã¯ãã§ããèªç€Ÿã®æã€ãªãœãŒã¹ã掻çšããªãããšã«ã¯ãæ°ããªã»ãã¥ãªãã£æŠå¿µãæå ¥ããŠãæå³ããããŸãããïŒå·å£æ°ïŒ
å·å£æ°ã¯è¬æŒãéããŠç¹°ãè¿ãããæè¡ç課é¡ãžã®å¯Ÿçãç®ã«ã€ãã®ã¯ãããããçµç¹ç課é¡ã«ç®ãåããŠã»ããããšåŒ·èª¿ããã
ãæè¡çãªå¯Ÿçããæéããããããçµç¹ã®çè«ãåé¢ä¿ãããã®ã§æãã€ãã«ãããã ããããããã²çµç¹çãªå¯Ÿçãå¿ããã«é²ããŠã»ããã®ã§ãããããªãã«ãåé¡ã¯çä»ããªãã®ã§ããïŒå·å£æ°ïŒ


