2æ25æ¥ïœ27æ¥ããªã³ã©ã€ã³ã«ãŠéå¬ããããTECH+ ãã©ãŒã©ã - ã»ãã¥ãªã㣠2025 Feb. ä»ã»ãã¥ãªãã£æ åœè ã¯äœããã¹ããããæ¬çš¿ã§ã¯ãã®ç¹å¥è¬æŒããã倧éªå€§åŠ D3ã»ã³ã¿ãŒ ææ/CISOã®çªä¿£æŠå€«æ°ã«ãããã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ã«ããã5W1Hãšã¯ - ååãéµãæ¡ã -ãã®å 容ã玹ä»ãããåæ°ã¯ã€ã³ã·ãã³ãçºçæã«ãããååã®éèŠæ§ã説ãããã®ã«ã®ã¯ã5W1Hãã«ãããšããã
ãµã€ããŒæ»æã¯ãä»äººäºããšæãããèªåäºããšèããã¹ã
倧åŠã§ã®è¬çŸ©ãç ç©¶ã»æå°ã®åãã倧éªã»é¢è¥¿äžåã®ã»ãã¥ãªãã£ã«é¢ããéå¶ã«ãæºãã£ãŠãããšããçªä¿£æ°ã¯ãŸãã2æ1æ¥ãã3æ18æ¥ãŸã§ãããµã€ããŒã»ãã¥ãªãã£æé2025ãã§ããããšã瀺ããããã§ããå é£ãµã€ããŒã»ãã¥ãªãã£ã»ã³ã¿ãŒïŒNISCïŒãå ¬éããŠããã€ã³ã¿ãŒãããã®å®å šã»å®å¿ãã³ãããã¯ã«ç®ãéããŠã»ããããšåŒã³ãããã
åæ°ãåšç±ãã倧éªå€§åŠã¯2017å¹Žã«æ å ±æŒããäºæ ãšå ¥è©Šã§ã®ãã¹ãšãã倧ããªäºæ¡ãèµ·ãããŠããããäºæ 察å¿ã®èŠç¹ããèŠããšã倧ããªãã¹ãç¯ããããšèŠã ããæ¯ãè¿ã£ãã
ããããããªãŒããŒã·ããããšããçµç¹äžäžžã§äºæ¡å¯Ÿå¿ã«åãçµãŸãªããšãããŸãããïŒçªä¿£æ°ïŒ
ãšããããæ®æ®µãµã€ããŒã»ãã¥ãªãã£äºæ¡ãç®ã«ããæ©äŒãå€ãã«ããããããããèªåã®çµç¹ã§äºæ ãèµ·ããªããšãã©ãããŠãä»äººäºã«ãªã£ãŠããŸããã¡ãïŒçªä¿£æ°ïŒã«ãªã£ãŠããŸã人ãå€ãã
ã仿ã®äºæ¡ããèªåäºã®ããã«æ±ã£ãŠèããŠããããšãéåžžã«å€§äºã§ããïŒçªä¿£æ°ïŒ
ããã«çªä¿£æ°ã¯ããµã€ããŒæ»æãšèšããšãæ å ±æŒãããã©ã³ãµã ãŠã§ã¢ã«ç®ãè¡ããã¡ã ãããå®ã¯DDoSïŒDistributed Denial of ServiceïŒãäŸç¶ãšããŠå€ãããšè©±ããå®éãèªç©ºäŒç€Ÿãã¡ã¬ãã³ã¯ãªã©ã®ã·ã¹ãã ãDDoSãšæãããæ»æã«ãã忢ããäºæ ã床ã çºçããŠããããã身代éç®çã§ã¯ãªããããçš®ã®ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ãªã®ã§ã¯ãªããããšåæ°ã¯æšæž¬ããã
çã«å®ãã¹ãã¯ãè³ç£ãã§ã¯ãªããç¶ç¶æ§ã
æ å ±ã¯è³ç£ã§ãããéããã°éããã»ã©èªãã®äŸ¡å€ãé«ãŸããšã®èãæ¹ãäžè¬çã ãããããæ å ±ãå¢ããã«ã€ãæ»æè ã«çãããå±éºæ§ãé«ãŸããããããªã¹ã¯ã倧ãããªãããšçªä¿£æ°ã¯èªãã
æ å ±ã»ãã¥ãªãã£ã®3倧èŠçŽ ãšããŠããCIAããšããèšèãæããããããšããããããã¯ãConfidentialityïŒæ©å¯æ§ïŒãIntegrityïŒå®å šæ§ïŒãAvailabilityïŒå¯çšæ§ïŒã®ããããã®é æåãåã£ããã®ã§ããããªãã§ãæ©å¯æ§ãæéèŠèŠãããŠããã
ãããçŸåšã§ã¯ããã®é åºãéã«ãããAICããããªãã¡å¯çšæ§ãéèŠãããŠãããããã¯ãBCPïŒäºæ¥ç¶ç¶æ§ïŒã«ãã€ãªããèãæ¹ã ããã®ããã«ã¯ååã倧åã§ããããã®ããŒã¯ãŒããšãªãã®ãã5W1Hãã ãšåæ°ã¯èª¬ããã
å¹³æããã5W1Hãã®èŠç¹ã§åé¡ç¹ã®æŽãåºãã
5W1Hãšã»ãã¥ãªãã£å¯Ÿçã®é¢ä¿æ§ã«è§Šããåã«ãçªä¿£æ°ã¯åŸæ¥ã®ã€ã³ã·ãã³ã察çã«ãããåé¡ç¹ãææããã
察å¿ããã¥ã¢ã«ã«ã¯åŸã ã«ããŠãã±ãŒãã«æç·ã«ãããããã¯ãŒã¯åæãã·ã¹ãã /ãµãŒãã¹ã®åæ¢ããã°è§£æãªã©ã®åå ç©¶æäœæ¥ãæããããããããåæ°ã¯ãèªåãã¡ã®ãµãŒãã¹ãæ¢ããããã客ãããæžã£ãŠããã®ã§ã¯ãªããããšçåãæãããã埩æ§èšç»ãäºåã«èããŠããå¿ èŠããããšããã
ãã€ã³ã·ãã³ããèµ·ããããããã®äºæ¥ç¶ç¶ãããã¡ããšèããªããã°ãããªãã®ã§ããïŒçªä¿£æ°)
äŸãã°é£çµ¡äœå¶ã«ã€ããŠãã·ã¹ãã ãæ¢ãŸããšãååŒå ã顧客ãªã©ãšã¡ãŒã«ã§ã¯é£çµ¡ã§ããªããªããåºå®é»è©±ãŸãã¯åŸæ¥å¡ã®æºåž¯é»è©±ã䜿ããããªããªãäºæ ãäºæ³ãããã
ã察çããã¥ã¢ã«ã«èŒã£ãŠãªãããšã®æ¹ã倧ããã®ã§ãå¹³æã«èããŠããå¿ èŠãããã®ã§ããïŒçªä¿£æ°ïŒ
ãã®ããã«ã¯ãäœãå¿ èŠãªã®ããåæ°ã¯ãŸããã·ã¹ãã ã®å å®¹ãææ¡ããŠããã¹ãã ãšèª¬ããäŒæ¥ã®ã·ã¹ãã ã§ã¯ãWebãµãŒããããŒã¿ããŒã¹ãåå®ç³»ãªã©ãå€ãã®ãœãããŠã§ã¢ãåäœããŠããã䜿çšããŠããã¢ãžã¥ãŒã«ãã©ã€ãã©ãªãå€å²ã«äºãããŸããã¡ãŒã«ãŒè£œåã«å ããŠOSSïŒãªãŒãã³ãœãŒã¹ã»ãœãããŠã§ã¢ïŒã䜿çšããŠããã±ãŒã¹ãå°ãªããªããçªä¿£æ°ã¯ãããããäŸãã°SBOMïŒSoftware Bill of MaterialsããœãããŠã§ã¢éšå衚ïŒã®ãããªä»çµã¿ãçšããŠå¹³çŽ ããææ¡ããŠããããšãããäºæ çºçåŸã®ååã«ãããååæºã«ãªãããšè©±ããã
ãŸãã»ãã¥ãªãã£å¯Ÿçã§ã¯ã察å¿ããã¥ã¢ã«ã®æŽåãæ å ±å ±æã®å Žã¥ãããSIRTïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ããŒã ïŒã®æ§ç¯ãšSOCïŒSecurity Operation CenterïŒã®éçšãã»ãã¥ãªãã£æè²ãç ä¿®ã®éèŠæ§ã説ãããããšãå€ãããåæ°ã¯ããããããã£ãæ°ã«ãããŠãããéæ³ã¿ãããªãã®ãã ãšæèšããã
ããã§çªä¿£æ°ãæ²ããã®ããåè¿°ã®5W1Hã ã
5W1Hãšã¯ãWhenïŒãã€ïŒãWhereïŒã©ãã§ïŒãWhoïŒèª°ãïŒã WhatïŒäœãïŒã WhyïŒãªãïŒãHowïŒã©ã®ããã«ïŒãšããè±èªã®ææ¥ãªã©ã§èª°ãããèãèŠãã®ããååã§ãããåæ°ã¯ãããã»ãã¥ãªãã£ã®ã³ãã¥ãã±ãŒã·ã§ã³ã«ãéèŠãªã®ã ãšæ°ä»ãããšããã
ã»ãã¥ãªãã£å¯Ÿçã§ã¯ã誰ãããäœããããã®ãããã¡ããšäŒããŠããå¿ èŠããããããããã»ãã¥ãªãã£ã®å å®¹ãææ¡ããŠããªããã°ãåœç¶ãªãããªã¹ã¯ãææ¡ããããšãã§ããªãããã®ããã«ã¯èª²é¡ã®æŽãåºããå¿ èŠã ã
åé¡ç¹ã®ææ¡ã«ã¯åå ã®åæãå¿ èŠã ãšèªãçªä¿£æ°ã¯ãããšã¿èªåè»ã®ã5W1Hæèãã玹ä»ãããããã¯ãäŸãã°å·¥äœæ©æ¢°ã忢ãããªã©æ£åžžã«åäœããªãå Žåã«ãçŽæ¥ã®åå ãèŠä»ããŠè§£æ±ºããã ãã§ã¯ãªããæ ¹æ¬ã®åå ã«ãŸã§æ·±æãããŠãããšããææ³ã ã
ããã®ãããªåé¡è§£æ±ºãèšç»ç«æ¡ãæ å ±äŒéããã»ãã¥ãªãã£å¯Ÿçã«ãéèŠãªã®ã§ããïŒçªä¿£æ°)
åæ°ã¯ããã«ããã®äºäŸãšããŠãèªãã調æ»å§å¡äŒã®ã¡ã³ããŒãšããŠæºãã£ããNTTè¥¿æ¥æ¬ã®ã°ã«ãŒãäŒç€Ÿã§çºçããæ å ±æŒããäºæ¡ãåãäžããã
ãã®äºæ¡ã®å ±åæžã§ã¯æè¡çãªç¹ããããWhyã®èŠç¹ããããªããã®äºè±¡ãèµ·ããã®ãããæ·±æããããšãããããã§æµ®ãã³äžãã£ãã®ã¯ãªãŒããŒã·ãããšãæ å ±å ±æã«ãããåé¡ç¹ã ã£ãã
ãªãŒããŒã·ããã«ã€ããŠã¯ãäžéœåãªæ å ±ãäžã«äŒãããšå±è²¬ããããããªç€Ÿå 颚åã ãšæ å ±ãäžããã«ãããªããäºæ ãæªåããŠãããæ å ±å ±æã§ã¯ãã©ããã£ãäºæ ã®å Žåã«äŒããã¹ããªã®ããæŽçãããŠããªãã£ãã®ã ããã®äºæ¡ã¯æŽŸé£äŒç€Ÿã®ã¡ã³ããŒãèµ·ããããã®ã ããã責任ã®å¢çãææ§ã«ãªã£ãŠããç¹ã«åé¡ããã£ãããšçªä¿£æ°ã¯è¿°ã¹ãã
ãããŸã§ååã®éèŠæ§ã説ããŠããåæ°ã¯æåŸã«ããçŸä»£ã¯ã»ãã¥ãªãã£äºæ¡ãä»äººäºã«ã§ããæä»£ã§ã¯ãªãããšããããã§ããèªç€Ÿã§ãèµ·ããã®ã§ã¯ãªãããšããæèãæã¡ããã®æºåã«äœãã§ãããäžæŠç«ã¡è¿ã£ãŠèããŠã»ããããšåŒã³ãããã
ããã®ããã«ã¯5W1Hã®èŠç¹ããã€ã»èª°ãã»ã©ãã§ã»äœãã»ãªãã»ã©ã®ããã«ãæŽãåºããšãã·ã³ãã«ã«çãããã³ããèŠã€ãã£ãŠããŸããïŒçªä¿£æ°ïŒ

