ã¢ã€ãã³ãã£ãã£ã»ãã¥ãªãã£ã®ç¶æ³ã¯å€§ããå€ãããããŸããµã€ããŒæ»æè ã«ãšã£ãŠãã¢ã€ãã³ãã£ãã£ãçªãæ»æææ³ã¯ãæåããããããã®ã«ãªã£ãŠããŸããŸãããããã¯åœŒãã以åããè³¢ããªã£ãããã§ã¯ãªã (ãã¡ããé«åºŠãªæå£ãæã€è ãããŸãã)ãç§ãã¡èªèº«ããæåã«ã€ãªãããéµããæž¡ããŠããŸã£ãããã§ãã
ã¢ã€ãã³ãã£ãã£ã®ç®¡çãè¡ãå±ããªãããšã§ãçµç¹ã«ãããŠæã䟡å€ã®ããè³ç£ãã€ãŸããã¢ã€ãã³ãã£ãã£ããžã®ã¢ã¯ã»ã¹ãããµã€ããŒç¯çœªè ã«å¯ŸããŽãŒã«ãã³ãã±ããã®ããã«äžããããŠããŸã£ãŠããã®ã§ãã
å°ãåãŸã§ã¯ããããŸã§ç¶æ³ã¯æ··ä¹±ããŠããŸããã§ãããåŸæ¥å¡ã¯ãã£ãäžã€ã®ãã°ã€ã³æ å ±ãšãéãããæš©éããããã°æ¥åãéè¡ã§ããŠããŸããããããä»ã§ã¯ããã¢ã€ãã³ãã£ãã£ããæã£ãŠããã®ã¯æ£èŠã®åŸæ¥å¡ã ãã§ã¯ãããŸããã
å¥çŽç€Ÿå¡ããµãŒãã¹ã¢ã«ãŠã³ããããã«ã¯ IoT ããã€ã¹ãŸã§ã¢ã€ãã³ãã£ãã£ãä»äžãããŠããŸããããã«ãã¢ã€ãã³ãã£ãã£ã¯Microsoft Active DirectoryãEntra IDãOktaãšãã£ãè€æ°ã®IDãããã€ã㌠(IDP)ãã¯ã©ãŠããã©ãããã©ãŒã ãSaaSã¢ããªããªã¢ãŒãããŒã«ãªã©ã«ãŸãããè€éã«çµ¡ã¿åã£ãŠããŸããæ¥ç¶ãäžã€å¢ãããã³ã«ãè€éæ§ãå¢ããŸããæš©éãäžã€å¢ãããã³ã«ããªã¹ã¯ãçãŸããŸãããããŠãæ»æè ãã¡ã¯ãããçç¥ããŠããŸãã
ãããŠãç¡çããçµç¹ã«äŸµå ¥ãããããæ£èŠã®èªèšŒæ å ±ã§ãçé¢ãããå ¥ãã»ããç°¡åã§ãããã«ãŠã§ã¢ãä»èŸŒãããããã£ãã·ã³ã°ã¡ãŒã«äžéã§æ°ã¥ãããã«äŸµå ¥ã§ããã®ã§ãã
ã¢ã€ãã³ãã£ãã£ã¯æãæè»œãªäŸµå ¥å£
ããŸãèªèšŒæ å ±ã®çªåãšæš©éã®ææ Œã¯ããµã€ããŒæ»æã®åå°ãšãªã£ãŠããŸããæ»æè ã¯ããã£ãã·ã³ã°ãçªåãããèªèšŒæ å ±ãåå©çšããããã¹ã¯ãŒããšãã£ãææ®µã§çµç¹ã«äŸµå ¥ãããšãã·ã¹ãã ãæšªæçã«ç§»åããªããæš©éãæ¡å€§ããæ»æç¯å²ãåºããŠãããŸããããããåãã¯éåžžã®ãŠãŒã¶ãŒè¡åãšåºå¥ãã€ãã«ãããããæ€ç¥ãéåžžã«å°é£ã§ãã
ã¢ã€ãã³ãã£ãã£ãæªçšããæ»æã¯ä»¥äžã®ãããªç¹æ§ããã£ãŠãããããæ»æè ã«å¥œãŸããŸãã
æç¶æ§ïŒæ»æè ã¯äžåºŠã¢ã€ãã³ãã£ãã£ãææ¡ããã°ãæ°é±éããæ°ã«æã«ããããæ°ã¥ãããã«æœäŒã§ããŸãã
ã¹ãã«ã¹æ§ïŒæ£èŠã®èªèšŒæ å ±ãçšãããããã»ãã¥ãªãã£ã®ç®ãããããããŸãã
æš©éææ ŒïŒæš©éã®äœãã¢ã«ãŠã³ãã¯ãå€ãã®å Žåã«ãããŠãæåã®ãããã«ãããŸããã
誀ã£ãå®å¿æãšã¢ã€ãã³ãã£ãã£ã®æ¡å€§ãæããªã¹ã¯
å€ãã®çµç¹ã¯ãèªç€Ÿã®IdPïŒIdentity ProviderïŒãã¢ã€ãã³ãã£ãã£ã»ãã¥ãªãã£ãæ ã£ãŠãããšèª€è§£ããŠããŸãããã®èª€è§£ã«ã¯å€§ããªå±éºã䌎ããŸããIdP ã¯ãããŸã§ãèªèšŒããšãã¢ã¯ã»ã¹ç®¡çãã®ããã®ãã®ã§ããããäžæ£ãªèªèšŒã®æ€åºãããã¬ããã³ã¹ãããä¿®æ£ãã®æ©èœãåããŠããããã§ã¯ãããŸããã
æ°ããããŒã«ãã¯ã©ãŠããããã€ããŒãå°å ¥ãããã³ã«ãã¢ã€ãã³ãã£ãã£ãæš©éããããŠæœåšçãªããã¯ãã¢ãå¢ããŠãããŸãããã®çµæã誰ãã©ãã«ã¢ã¯ã»ã¹ã§ããã®ãããããŠãããæ£åœãªã®ãã誰ã«ãææ¡ã§ããªããäžéæã§æ¡æ£ããã¢ã€ãã³ãã£ãã£ç°å¢ãåºæ¥äžãã£ãŠããŸãã®ã§ãã
å¿ããŠã¯ãªããªãã®ã¯ãçŸåšäž»æµã®å€ãã®IdPãã¯ãããžãŒã¯ãçŸä»£ã®äŒæ¥ç°å¢ã«åãããŠèšèšããããã®ã§ã¯ãªããšããããšã§ããActive Directory ã®ãªãªãŒã¹ã¯1999幎ã§ããEntra ID ã¯ã¯ã©ãŠãæä»£ã«å¯Ÿå¿ããèšèšã§ã¯ãããã®ã®ãå¯èŠæ§ãååã«ç¢ºä¿ããã«ã¯è€æ°ã®ããŒã«ãéããŠå©çšããå¿ èŠããããŸããããã«ãµãŒãããŒãã£ã®SaaSã¢ããªããªã¢ãŒãã¯ãŒã¯ããªã·ãŒãæªç®¡çã®ãµãŒãã¹ã¢ã«ãŠã³ããªã©ãå å³ãããšãããããã¹ãŠã管çããããšã¯è³é£ã®æ¥ã§ãã
ãµã€ããŒç¯çœªè ã¯AIãæŽ»çšãé²åããŠãã
æ»æè ãã¡ã¯ããã äŸµå ¥ãç¹°ãè¿ããŠããã ãã§ãªããé²åããŠããŸããAI ãæŽ»çšããŠã¯ã¬ãã³ã·ã£ã«ã¹ã¿ããã£ã³ã°ãèªååããæš©éãææ ŒãããBloodHoundã®ãããªããŒã«ã§ã¢ã€ãã³ãã£ãã£ã®é¢ä¿æ§ãå€§èŠæš¡ã«ãããã³ã°ããŠããŸãã
圌ãã¯è匱æ§ãåŸ ã€ããšãªããç§ãã¡ãé²åºããããéããçã£ãŠããã®ã§ãã
ãããã£ãŠãä»ããã«ã§ãããããç¶æ³ãå€ããªããã°ãªããŸããã
äºå察å¿åã®ã¢ã€ãã³ãã£ãã£æŠç¥ã¯ãã¯ãäžå¯æ¬
ä»ããããåã身ã®ã¢ã€ãã³ãã£ãã£ãã€ãžãŒã³ãããããã³ã³ããã¹ãïŒæèïŒãèæ ®ããããªã¹ã¯ããŒã¹ã®èœåçãªã»ãã¥ãªãã£ããžãšè»¢æããæã§ããå ·äœçã«ã¯ã以äžã®ãããªããšã宿œããå¿ èŠããããŸãã
ç²ç¹ã®æé€
ãªã³ãã¬ãã¹ãšã¯ã©ãŠãã®ã¢ã€ãã³ãã£ãã£ããŒã¿ãçµ±åããåäžã®å¯èŠåãã¥ãŒãå®çŸããŸããèŠããªããã®ã¯ä¿è·ã§ããŸããã
AIã«å¯Ÿæããããã®AI掻çš
æš©éãããã€ã¹ã®æåãèšå®ãã¹ãæš©éã¬ãã«ã«åºã¥ããŠã¢ã€ãã³ãã£ãã£ã®ãªã¹ã¯ãè©äŸ¡ããAIé§åã®åæãå°å ¥ããŸãã
ä¿®æ£ã®å®è¡å¯èœæ§ãé«ãã
å¯èŠåã¯ãè¡åã«ã€ãªãã£ãŠåããŠäŸ¡å€ãçãŸããŸããã»ãã¥ãªãã£ããŒã ãšIAMïŒIdentity and Access ManagementïŒããŒã ãå ±éèšèªã§äŒè©±ã§ããããã«ããã©ã®ãªã¹ã¯ãç·æ¥ã§ãã©ããåŸåãå¯èœãããããŠã©ã®ããã«ä¿®æ£ãã¹ãããæç¢ºã«ããå¿ èŠããããŸãã
IAMãIGAïŒIdentity Governance and AdministrationïŒãPAMïŒPrivileged Access ManagementïŒã ITDRïŒIdentity Threat Detection and ResponseïŒãšãã£ãç¥èªãç¥ã£ãŠããã ãã§ã¯ç§ãã¡ãå®ããŸãããããŒã«ã¯æçåããã¢ã¿ãã¯ãµãŒãã§ã¹ïŒæ»æå¯Ÿè±¡é åïŒã¯åºãããæ»æè ã¯æ¥ã é²åããŠããŸããã¢ã€ãã³ãã£ãã£ã¯æ°ããªå¢çç·ã§ãããããŸãŸãã«æ»æã®æšçãšãªã£ãŠããŸãã
çµç¹ãã¢ã€ãã³ãã£ãã£ãªã¹ã¯ãåªå ãã¹ãã»ãã¥ãªãã£è åšãšããŠæ±ããªãéãã䟵害ã¯ãããããéãã«ãå·§åŠã«ããããŠå€§èŠæš¡ã«é²è¡ãç¶ããã§ãããããµã€ããŒæ»æè ãã¡ã¯ãåšå²ã«æº¶ã蟌ãè¡ããç¿åŸããŠããŸããä»ãããå®ãåŽãå æãæã€ã¹ãæã§ãã
ãã¯ãããçããããã©ãããã§ã¯ãããŸããããæ°ã¥ãããã©ããããåãããŠããã®ã§ãã