ã¯ã©ãŠãè²¬ä»»å ±æã¢ãã«ãè§£ãæããïŒIaaSãPaaSãSaaSã«ãããã¯ã©ãŠããããã€ããŒãšé¡§å®¢ã®ã»ãã¥ãªãã£è²¬ä»»ã«é¢ããã°ããŒãã«ã¬ã€ãã
ã¯ã©ãŠãã»ãã¥ãªãã£ïŒè²¬ä»»å ±æã¢ãã«ã®çè§£
ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã¯ãçµç¹ã®éå¶æ¹æ³ã«é©åœããããããã¹ã±ãŒã©ããªãã£ãæè»æ§ãã³ã¹ãå¹çãæäŸããŠããŸãããããããã®ãã©ãã€ã ã·ããã¯ãç¹æã®ã»ãã¥ãªãã£äžã®èª²é¡ããããããŸãããããã®èª²é¡ãä¹ãè¶ããããã®åºæ¬çãªæŠå¿µã¯ãè²¬ä»»å ±æã¢ãã«ã§ãããã®ã¢ãã«ã¯ãå®å šãªã¯ã©ãŠãç°å¢ã確ä¿ããããã«ãã¯ã©ãŠããããã€ããŒãšé¡§å®¢éã®ã»ãã¥ãªãã£è²¬ä»»ãæç¢ºã«ããŸãã
è²¬ä»»å ±æã¢ãã«ãšã¯
è²¬ä»»å ±æã¢ãã«ã¯ãã¯ã©ãŠããµãŒãã¹ãããã€ããŒïŒCSPïŒãšãã®ãµãŒãã¹ãå©çšãã顧客ã®ãæç¢ºãªã»ãã¥ãªãã£çŸ©åãå®çŸ©ããŸããããã¯ãäžèœããªãœãªã¥ãŒã·ã§ã³ã§ã¯ãªãããã®è©³çްã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒãã¹ïŒIaaSïŒããã©ãããã©ãŒã ãµãŒãã¹ïŒPaaSïŒããŸãã¯ãœãããŠã§ã¢ãµãŒãã¹ïŒSaaSïŒãªã©ããããã€ãããã¯ã©ãŠããµãŒãã¹ã®ã¿ã€ãã«ãã£ãŠç°ãªããŸãã
åºæ¬çã«ãCSPã¯ã¯ã©ãŠãã®ã»ãã¥ãªãã£ã«ã€ããŠè²¬ä»»ãè² ãã顧客ã¯ã¯ã©ãŠãå ã®ã»ãã¥ãªãã£ã«ã€ããŠè²¬ä»»ãè² ããŸãããã®åºå¥ã¯ã广çãªã¯ã©ãŠãã»ãã¥ãªãã£ç®¡çã®ããã«äžå¯æ¬ ã§ãã
ã¯ã©ãŠããµãŒãã¹ãããã€ããŒïŒCSPïŒã®è²¬ä»»
CSPã¯ãç©ççãªã€ã³ãã©ã¹ãã©ã¯ãã£ãšã¯ã©ãŠãç°å¢ã®åºç€ãšãªãã»ãã¥ãªãã£ãç¶æãã責任ããããŸããããã«ã¯ä»¥äžãå«ãŸããŸã:
- ç©ççã»ãã¥ãªãã£ïŒäžæ£ã¢ã¯ã»ã¹ãèªç¶çœå®³ãåé»ãªã©ãç©ççãªè åšããããŒã¿ã»ã³ã¿ãŒãããŒããŠã§ã¢ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããšãäŸãã°ãAWSãAzureãGCPã¯ãã¹ãŠãè€æ°ã®ç©ççä¿è·å±€ãåããé«åºŠã«ã»ãã¥ã¢ãªããŒã¿ã»ã³ã¿ãŒãç¶æããŠããŸãã
- ã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£ïŒãµãŒããŒãã¹ãã¬ãŒãžããããã¯ãŒãã³ã°æ©åšãªã©ãã¯ã©ãŠããµãŒãã¹ããµããŒãããåºç€ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããšãããã«ã¯ãè匱æ§ã®ãããé©çšããã¡ã€ã¢ãŠã©ãŒã«ã®å®è£ ãäŸµå ¥æ€ç¥ã·ã¹ãã ã®å°å ¥ãå«ãŸããŸãã
- ãããã¯ãŒã¯ã»ãã¥ãªãã£ïŒã¯ã©ãŠããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ãšæŽåæ§ã確ä¿ããããšãããã«ã¯ãDDoSæ»æããã®ä¿è·ããããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ããã©ãã£ãã¯ã®æå·åãå«ãŸããŸãã
- ä»®æ³åã»ãã¥ãªãã£ïŒåäžã®ç©çãµãŒããŒäžã§è€æ°ã®ä»®æ³ãã·ã³ãå®è¡ã§ããä»®æ³åã¬ã€ã€ãŒãä¿è·ããããšãããã¯ãVMéã®æ»æãé²ããããã³ãéã®åé¢ãç¶æããããã«éèŠã§ãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãšèªèšŒïŒé¢é£ããæ¥çèŠå¶ãšã»ãã¥ãªãã£èªèšŒïŒISO 27001ãSOC 2ãPCI DSSãªã©ïŒãžã®æºæ ãç¶æããããšãããã«ãããCSPã確ç«ãããã»ãã¥ãªãã£åºæºãéµå®ããŠããããšãä¿èšŒãããŸãã
ã¯ã©ãŠã顧客ã®è²¬ä»»
顧客ã®ã»ãã¥ãªãã£è²¬ä»»ã¯ã䜿çšãããŠããã¯ã©ãŠããµãŒãã¹ã®ã¿ã€ãã«ãã£ãŠç°ãªããŸãã IaaSããPaaSãSaaSãžãšç§»è¡ããã«ã€ããŠãCSPãåºç€ãšãªãã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€§éšåã管çããããã顧客ã®è²¬ä»»ã¯å°ãªããªããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒãã¹ïŒIaaSïŒ
IaaSã§ã¯ãé¡§å®¢ã¯æãå€ãã®å¶åŸ¡ãè¡ããããæãå€ãã®è²¬ä»»ãè² ããŸãã圌ãã¯ä»¥äžã®è²¬ä»»ãè² ããŸã:
- ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã»ãã¥ãªãã£ïŒä»®æ³ãã·ã³äžã§å®è¡ãããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãžã®ãããé©çšãšåŒ·åãè匱æ§ã®ããããé©çšããªããšãã·ã¹ãã ãæ»æã«å¯ŸããŠéããããŸãŸã«ãªãå¯èœæ§ããããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ïŒã¯ã©ãŠãã«ãããã€ããã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããšãããã«ã¯ãã»ãã¥ã¢ãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ã®å®è£ ãè匱æ§è©äŸ¡ã®å®æœãWebã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒWAFïŒã®äœ¿çšãå«ãŸããŸãã
- ããŒã¿ã»ãã¥ãªãã£ïŒã¯ã©ãŠãã«ä¿åãããŠããããŒã¿ãä¿è·ããããšãããã«ã¯ãä¿åããŒã¿ãšè»¢éããŒã¿ã®æå·åãã¢ã¯ã»ã¹å¶åŸ¡ã®å®è£ ãããŒã¿ã®å®æçãªããã¯ã¢ãããå«ãŸããŸããããšãã°ãAWS EC2ã«ããŒã¿ããŒã¹ããããã€ããŠãã顧客ã¯ãæå·åãšã¢ã¯ã»ã¹ããªã·ãŒã®èšå®ãæ åœããŸãã
- ã¢ã€ãã³ãã£ãã£ãšã¢ã¯ã»ã¹ç®¡çïŒIAMïŒïŒã¯ã©ãŠããªãœãŒã¹ãžã®ãŠãŒã¶ãŒIDãšã¢ã¯ã»ã¹æš©éã管çããããšãããã«ã¯ãå€èŠçŽ èªèšŒïŒMFAïŒã®å®è£ ãããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒRBACïŒã®äœ¿çšããŠãŒã¶ãŒã¢ã¯ãã£ããã£ã®ç£èŠãå«ãŸããŸãã IAMã¯ãå€ãã®å Žåãæåã®é²åŸ¡ç·ã§ãããäžæ£ã¢ã¯ã»ã¹ãé²ãããã«äžå¯æ¬ ã§ãã
- ãããã¯ãŒã¯æ§æïŒä»®æ³ãããã¯ãŒã¯ãä¿è·ããããã«ããããã¯ãŒã¯ã»ãã¥ãªãã£ã°ã«ãŒãããã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒãã£ã³ã°ã«ãŒã«ãæ§æããããšããããã¯ãŒã¯ã«ãŒã«ãæ£ããæ§æãããŠããªããšãã·ã¹ãã ãã€ã³ã¿ãŒãããã«å ¬éãããå¯èœæ§ããããŸãã
äŸïŒAWS EC2ã§ç¬èªã®eã³ããŒã¹Webãµã€ãããã¹ãããŠããçµç¹ã圌ãã¯ãWebãµãŒããŒã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ããããé©çšããã¢ããªã±ãŒã·ã§ã³ã³ãŒããä¿è·ãã顧客ããŒã¿ãæå·åããAWSç°å¢ãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã管çãã責任ããããŸãã
ãã©ãããã©ãŒã ãµãŒãã¹ïŒPaaSïŒ
PaaSã§ã¯ãCSPããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã©ã³ã¿ã€ã ç°å¢ãå«ãåºç€ã€ã³ãã©ã¹ãã©ã¯ãã£ã管çããŸãã顧客ã¯äž»ã«ä»¥äžã®è²¬ä»»ãè² ããŸã:
- ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ïŒãã©ãããã©ãŒã äžã§éçºããã³ãããã€ããã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããšãããã«ã¯ãã»ãã¥ã¢ãªã³ãŒãã®èšè¿°ãã»ãã¥ãªãã£ãã¹ãã®å®æœãã¢ããªã±ãŒã·ã§ã³ã®äŸåé¢ä¿ã«ãããè匱æ§ãžã®ãããé©çšãå«ãŸããŸãã
- ããŒã¿ã»ãã¥ãªãã£ïŒã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠä¿åããã³åŠçãããããŒã¿ãä¿è·ããããšãããã«ã¯ãããŒã¿ã®æå·åãã¢ã¯ã»ã¹å¶åŸ¡ã®å®è£ ãããŒã¿ãã©ã€ãã·ãŒèŠå¶ã®éµå®ãå«ãŸããŸãã
- PaaSãµãŒãã¹ã®æ§æïŒäœ¿çšãããŠããPaaSãµãŒãã¹ãå®å šã«æ§æããããšãããã«ã¯ãé©åãªã¢ã¯ã»ã¹å¶åŸ¡ã®èšå®ãšããã©ãããã©ãŒã ãæäŸããã»ãã¥ãªãã£æ©èœã®æå¹åãå«ãŸããŸãã
- ã¢ã€ãã³ãã£ãã£ãšã¢ã¯ã»ã¹ç®¡çïŒIAMïŒïŒPaaSãã©ãããã©ãŒã ãšã¢ããªã±ãŒã·ã§ã³ãžã®ãŠãŒã¶ãŒIDãšã¢ã¯ã»ã¹æš©éã管çããããšã
äŸïŒAzure App Serviceã䜿çšããŠWebã¢ããªã±ãŒã·ã§ã³ããã¹ãããŠããäŒæ¥ã圌ãã¯ãã¢ããªã±ãŒã·ã§ã³ã³ãŒããä¿è·ããã¢ããªã±ãŒã·ã§ã³ããŒã¿ããŒã¹ã«ä¿åãããŠããæ©å¯ããŒã¿ãæå·åããã¢ããªã±ãŒã·ã§ã³ãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã管çãã責任ããããŸãã
ãœãããŠã§ã¢ãµãŒãã¹ïŒSaaSïŒ
SaaSã§ã¯ãCSPãã¢ããªã±ãŒã·ã§ã³ãã€ã³ãã©ã¹ãã©ã¯ãã£ãããŒã¿ã¹ãã¬ãŒãžãªã©ãã»ãŒãã¹ãŠã®ãã®ã管çããŸãã顧客ã®è²¬ä»»ã¯éåžžã以äžã«éå®ãããŸã:
- ããŒã¿ã»ãã¥ãªãã£ïŒã¢ããªã±ãŒã·ã§ã³å ïŒïŒçµç¹ã®ããªã·ãŒã«åŸã£ãŠãSaaSã¢ããªã±ãŒã·ã§ã³å ã®ããŒã¿ã管çããããšãããã«ã¯ãã¢ããªã±ãŒã·ã§ã³å ã§æäŸãããããŒã¿åé¡ãä¿æããªã·ãŒãã¢ã¯ã»ã¹å¶åŸ¡ãå«ãŸããå ŽåããããŸãã
- ãŠãŒã¶ãŒç®¡çïŒSaaSã¢ããªã±ãŒã·ã§ã³å ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããšã¢ã¯ã»ã¹æš©éã管çããããšãããã«ã¯ããŠãŒã¶ãŒã®ããããžã§ãã³ã°ãšããããžã§ãã³ã°è§£é€ã匷åãªãã¹ã¯ãŒãã®èšå®ãå€èŠçŽ èªèšŒïŒMFAïŒã®æå¹åãå«ãŸããŸãã
- SaaSã¢ããªã±ãŒã·ã§ã³èšå®ã®æ§æïŒçµç¹ã®ã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠãSaaSã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£èšå®ãæ§æããããšãããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ãæäŸããã»ãã¥ãªãã£æ©èœã®æå¹åãšãããŒã¿å ±æèšå®ã®æ§æãå«ãŸããŸãã
- ããŒã¿ã¬ããã³ã¹ïŒSaaSã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšããé¢é£ããããŒã¿ãã©ã€ãã·ãŒèŠå¶ãšæ¥çæšæºïŒGDPRãHIPAAãªã©ïŒã«æºæ ããŠããããšã確èªããããšã
äŸïŒSalesforceãCRMãšããŠäœ¿çšããŠããããžãã¹ã圌ãã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ãã®ç®¡çã顧客ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©éã®èšå®ãSalesforceã®äœ¿çšãããŒã¿ãã©ã€ãã·ãŒèŠå¶ã«æºæ ããŠããããšã確èªãã責任ããããŸãã
è²¬ä»»å ±æã¢ãã«ã®å¯èŠå
è²¬ä»»å ±æã¢ãã«ã¯ãCSPãšé¡§å®¢ãç°ãªãã¬ã€ã€ãŒã®è²¬ä»»ãå ±æãããå±€ç¶ã®ã±ãŒããšããŠå¯èŠåã§ããŸããäžè¬çãªè¡šçŸã¯æ¬¡ã®ãšããã§ã:
IaaSïŒ
- CSPïŒç©çã€ã³ãã©ã¹ãã©ã¯ãã£ãä»®æ³åããããã¯ãŒãã³ã°ãã¹ãã¬ãŒãžããµãŒããŒ
- 顧客ïŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãããŒã¿ãã¢ã€ãã³ãã£ãã£ãšã¢ã¯ã»ã¹ç®¡ç
PaaSïŒ
- CSPïŒç©çã€ã³ãã©ã¹ãã©ã¯ãã£ãä»®æ³åããããã¯ãŒãã³ã°ãã¹ãã¬ãŒãžããµãŒããŒããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã©ã³ã¿ã€ã
- 顧客ïŒã¢ããªã±ãŒã·ã§ã³ãããŒã¿ãã¢ã€ãã³ãã£ãã£ãšã¢ã¯ã»ã¹ç®¡ç
SaaSïŒ
- CSPïŒç©çã€ã³ãã©ã¹ãã©ã¯ãã£ãä»®æ³åããããã¯ãŒãã³ã°ãã¹ãã¬ãŒãžããµãŒããŒããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã©ã³ã¿ã€ã ãã¢ããªã±ãŒã·ã§ã³
- 顧客ïŒããŒã¿ããŠãŒã¶ãŒç®¡çãæ§æ
è²¬ä»»å ±æã¢ãã«ãå®è£ ããããã®éèŠãªèæ ®äºé
è²¬ä»»å ±æã¢ãã«ãæ£åžžã«å®è£ ããã«ã¯ãæ éãªèšç»ãšå®è¡ãå¿ èŠã§ãã以äžã«ããã€ãã®éèŠãªèæ ®äºé ã瀺ããŸã:
- èªåã®è²¬ä»»ãçè§£ããïŒéžæããã¯ã©ãŠããµãŒãã¹ã®ç¹å®ã®ã»ãã¥ãªãã£è²¬ä»»ãçè§£ããããã«ãCSPã®ããã¥ã¡ã³ããšãµãŒãã¹å¥çŽãæ³šææ·±ã確èªããŠãã ããã AWSãAzureãGCPãªã©ã®å€ãã®ãããã€ããŒã¯ã詳现ãªããã¥ã¡ã³ããšè²¬ä»»ãããªãã¯ã¹ãæäŸããŠããŸãã
- 匷åãªã»ãã¥ãªãã£å¶åŸ¡ãå®è£ ããïŒã¯ã©ãŠãå ã®ããŒã¿ãšã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã«ãé©åãªã»ãã¥ãªãã£å¶åŸ¡ãå®è£ ããŸããããã«ã¯ãæå·åãã¢ã¯ã»ã¹å¶åŸ¡ãè匱æ§ç®¡çãã»ãã¥ãªãã£ç£èŠã®å®è£ ãå«ãŸããŸãã
- CSPã®ã»ãã¥ãªãã£ãµãŒãã¹ã䜿çšããïŒã»ãã¥ãªãã£äœå¶ã匷åããããã«ãCSPãæäŸããã»ãã¥ãªãã£ãµãŒãã¹ã掻çšããŸããããšãã°ãAWS Security HubãAzure Security CenterãGoogle Cloud Security Command Centerãªã©ããããŸãã
- ã»ãã¥ãªãã£ãèªååããïŒå¹çãåäžããã人çãã¹ã®ãªã¹ã¯ã軜æžããããã«ãå¯èœãªéãã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååããŸããããã«ã¯ãInfrastructure as CodeïŒIaCïŒããŒã«ãšã»ãã¥ãªãã£èªååãã©ãããã©ãŒã ã®äœ¿çšãå«ãŸããŸãã
- ç£èŠãšç£æ»ïŒã»ãã¥ãªãã£äžã®è åšãšè匱æ§ããªãããã¯ã©ãŠãç°å¢ãç¶ç¶çã«ç£èŠããŸããã»ãã¥ãªãã£å¶åŸ¡ãæå¹ã§ããããšã確èªããããã«ã宿çã«ç£æ»ããŸãã
- ããŒã ãèšç·ŽããïŒããŒã ã«ã»ãã¥ãªãã£ãã¬ãŒãã³ã°ãæäŸããŠã圌ããèªåã®è²¬ä»»ãšã¯ã©ãŠããµãŒãã¹ãå®å šã«äœ¿çšããæ¹æ³ãçè§£ããŠããããšã確èªããŸããããã¯ãéçºè ãã·ã¹ãã 管çè ãããã³ã»ãã¥ãªãã£å°éå®¶ã«ãšã£ãŠç¹ã«éèŠã§ãã
- ææ°ã®ç¶æ ãç¶æããïŒã¯ã©ãŠãã»ãã¥ãªãã£ã¯çµ¶ããé²åããŠããåéã§ããææ°ã®ã»ãã¥ãªãã£è åšãšãã¹ããã©ã¯ãã£ã¹ã«é¢ããææ°æ å ±ãå ¥æããããã«å¿ããŠã»ãã¥ãªãã£æŠç¥ã調æŽããŸãã
è²¬ä»»å ±æã¢ãã«ã®å®è·µã«ãããã°ããŒãã«ãªäŸ
è²¬ä»»å ±æã¢ãã«ã¯ã°ããŒãã«ã«é©çšãããŸããããã®å®è£ ã¯å°åèŠå¶ãæ¥çåºæã®èŠä»¶ã«ãã£ãŠç°ãªãå ŽåããããŸãã以äžã«ããã€ãã®äŸã瀺ããŸã:
- ãšãŒãããïŒGDPRïŒïŒãšãŒãããã§äºæ¥ãå±éããŠããçµç¹ã¯ãäžè¬ããŒã¿ä¿è·èŠåïŒGDPRïŒã«æºæ ããå¿ èŠããããŸããããã¯ãã¯ã©ãŠããããã€ããŒã®æåšå°ã«é¢ä¿ãªããã¯ã©ãŠãã«ä¿åãããŠããEUåžæ°ã®å人ããŒã¿ãä¿è·ãã責任ãããããšãæå³ããŸãã圌ãã¯ãCSPãGDPRã®èŠä»¶ã«æºæ ããããã«ååãªã»ãã¥ãªãã£å¯ŸçãæäŸããŠããããšã確èªããå¿ èŠããããŸãã
- ç±³åœïŒHIPAAïŒïŒç±³åœã®å»çæ©é¢ã¯ãå»çä¿éºã®çžäºéçšæ§ãšèª¬æè²¬ä»»ã«é¢ããæ³åŸïŒHIPAAïŒã«æºæ ããå¿ èŠããããŸããããã¯ãã¯ã©ãŠãã«ä¿åãããŠããä¿è·ãããå¥åº·æ å ±ïŒPHIïŒã®ãã©ã€ãã·ãŒãšã»ãã¥ãªãã£ãä¿è·ãã責任ãããããšãæå³ããŸãã圌ãã¯ãCSPãHIPAAã®èŠä»¶ã«æºæ ããŠããããšã確èªããããã«ãCSPãšäºæ¥ææºå¥çŽïŒBAAïŒãç· çµããå¿ èŠããããŸãã
- éèãµãŒãã¹æ¥çïŒããŸããŸãªèŠå¶ïŒïŒäžçäžã®éèæ©é¢ã¯ãããŒã¿ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ãã峿 ŒãªèŠå¶ã®å¯Ÿè±¡ãšãªããŸãã圌ãã¯ãCSPãæäŸããã»ãã¥ãªãã£å¶åŸ¡ãæ³šææ·±ãè©äŸ¡ããèŠå¶èŠä»¶ãæºããããã«è¿œå ã®ã»ãã¥ãªãã£å¯Ÿçãå®è£ ããå¿ èŠããããŸããäŸãšããŠã¯ãã¯ã¬ãžããã«ãŒãããŒã¿ã®åãæ±ãã«é¢ããPCI DSSããããŸããŸãªåœå éè¡èŠå¶ããããŸãã
è²¬ä»»å ±æã¢ãã«ã®èª²é¡
ãã®éèŠæ§ã«ãããããããè²¬ä»»å ±æã¢ãã«ã¯ããã€ãã®èª²é¡ãæç€ºããå¯èœæ§ããããŸã:
- è€éãïŒCSPãšé¡§å®¢éã®è²¬ä»»åæ ãçè§£ããããšã¯ãç¹ã«ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãåããŠå©çšããçµç¹ã«ãšã£ãŠã¯è€éã«ãªãå¯èœæ§ããããŸãã
- æç¢ºãã®æ¬ åŠïŒCSPã®ããã¥ã¡ã³ãã¯ã顧客ã®ç¹å®ã®ã»ãã¥ãªãã£è²¬ä»»ã«ã€ããŠåžžã«æç¢ºã§ã¯ãããŸããã
- 誀ã£ãæ§æïŒé¡§å®¢ã¯ã¯ã©ãŠããªãœãŒã¹ã誀ã£ãŠæ§æããæ»æã«å¯ŸããŠè匱ã«ãªãå¯èœæ§ããããŸãã
- ã¹ãã«ã®ã£ããïŒçµç¹ã¯ãã¯ã©ãŠãç°å¢ã广çã«ä¿è·ããããã«å¿ èŠãªã¹ãã«ãšå°éç¥èãæ¬ ããŠããå¯èœæ§ããããŸãã
- å¯èŠæ§ïŒã¯ã©ãŠãç°å¢ãç¹ã«ãã«ãã¯ã©ãŠãç°å¢ã«ãããã»ãã¥ãªãã£äœå¶ã®å¯èŠæ§ãç¶æããããšã¯å°é£ãªå ŽåããããŸãã
è²¬ä»»å ±æã¢ãã«ã«ãããã¯ã©ãŠãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
ãããã®èª²é¡ãå æããå®å šãªã¯ã©ãŠãç°å¢ã確ä¿ããããã«ãçµç¹ã¯ä»¥äžã®ãã¹ããã©ã¯ãã£ã¹ãæ¡çšããå¿ èŠããããŸã:
- ãŒããã©ã¹ãã»ãã¥ãªãã£ã¢ãã«ãæ¡çšããïŒãŒããã©ã¹ãã»ãã¥ãªãã£ã¢ãã«ãå®è£ ããŸããããã¯ããããã¯ãŒã¯ã®å¢çã®å å€ã«é¢ä¿ãªããããã©ã«ãã§ã©ã®ãŠãŒã¶ãŒãŸãã¯ããã€ã¹ãä¿¡é Œããªããšä»®å®ããŸãã
- æå°æš©éã¢ã¯ã»ã¹ãå®è£ ããïŒãŠãŒã¶ãŒã«ã¯ãèªåã®è·åãéè¡ããããã«å¿ èŠãªæå°éã®ã¢ã¯ã»ã¹æš©éã®ã¿ãä»äžããŸãã
- å€èŠçŽ èªèšŒïŒMFAïŒã䜿çšããïŒäžæ£ã¢ã¯ã»ã¹ããä¿è·ããããã«ããã¹ãŠã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã§MFAãæå¹ã«ããŸãã
- ä¿åããŒã¿ãšè»¢éããŒã¿ãæå·åããïŒäžæ£ã¢ã¯ã»ã¹ããä¿è·ããããã«ãæ©å¯ããŒã¿ãä¿åæãšè»¢éæã«æå·åããŸãã
- ã»ãã¥ãªãã£ç£èŠãšãã®ã³ã°ãå®è£ ããïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€åºããŠå¯Ÿå¿ããããã«ãå ç¢ãªã»ãã¥ãªãã£ç£èŠãšãã®ã³ã°ãå®è£ ããŸãã
- 宿çãªè匱æ§è©äŸ¡ãšãããã¬ãŒã·ã§ã³ãã¹ãã宿œããïŒè匱æ§ããªããã¯ã©ãŠãç°å¢ã宿çã«è©äŸ¡ãã匱ç¹ãç¹å®ããããã«ãããã¬ãŒã·ã§ã³ãã¹ãã宿œããŸãã
- ã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååããïŒãããé©çšãæ§æç®¡çãã»ãã¥ãªãã£ç£èŠãªã©ã®ã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååããŠãå¹çãåäžããã人çãã¹ã®ãªã¹ã¯ã軜æžããŸãã
- ã¯ã©ãŠãã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿èšç»ãçå®ããïŒã¯ã©ãŠãã§ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¯Ÿå¿ããããã®èšç»ãçå®ããŸãã
- 匷åãªã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ãæã€CSPãéžæããïŒã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã®å®çžŸã蚌æãããŠããCSPãéžæããŸãã ISO 27001ãSOC 2ãªã©ã®èªèšŒãæ¢ããŠãã ããã
è²¬ä»»å ±æã¢ãã«ã®æªæ¥
ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãæçãç¶ããã«ã€ããŠãè²¬ä»»å ±æã¢ãã«ãé²åããå¯èœæ§ããããŸããæ¬¡ã®ãããªããšãäºæ³ãããŸã:
- èªååã®åŒ·åïŒCSPã¯ãããå€ãã®ã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååãç¶ãã顧客ãã¯ã©ãŠãç°å¢ãä¿è·ããããããŸãã
- ããæŽç·Žãããã»ãã¥ãªãã£ãµãŒãã¹ïŒCSPã¯ãAIãæŽ»çšããè åšæ€åºãèªåã€ã³ã·ãã³ã察å¿ãªã©ãããæŽç·Žãããã»ãã¥ãªãã£ãµãŒãã¹ãæäŸããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ã®åŒ·åïŒã¯ã©ãŠãã»ãã¥ãªãã£ã«é¢ããèŠå¶èŠä»¶ã¯å³ãããªããçµç¹ã¯æ¥çæšæºãšèŠå¶ãžã®æºæ ãå®èšŒããå¿ èŠããããŸãã
- å ±æéåœã¢ãã«ïŒè²¬ä»»å ±æã¢ãã«ãè¶ ããæœåšçãªé²åãšããŠããããã€ããŒãšé¡§å®¢ãããã«é£æºããã»ãã¥ãªãã£çµæã«å¯Ÿããã€ã³ã»ã³ãã£ããæŽåããããå ±æéåœãã¢ãã«ããããŸãã
çµè«
è²¬ä»»å ±æã¢ãã«ã¯ãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã䜿çšãããã¹ãŠã®äººã«ãšã£ãŠéèŠãªæŠå¿µã§ãã CSPãšé¡§å®¢ã®äž¡æ¹ã®è²¬ä»»ãçè§£ããããšã«ãããçµç¹ã¯å®å šãªã¯ã©ãŠãç°å¢ã確ä¿ããäžæ£ã¢ã¯ã»ã¹ããããŒã¿ãä¿è·ã§ããŸãã ã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãç¶ç¶çãªèŠæãšååãå¿ èŠãšããå ±åã®åãçµã¿ã§ããããšãå¿ããªãã§ãã ããã
äžèšã«æŠèª¬ãããŠãããã¹ããã©ã¯ãã£ã¹ãæ³šææ·±ãéµå®ããããšã«ãããã客æ§ã®çµç¹ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ã®è€éããèªä¿¡ãæã£ãŠä¹ãè¶ããå ç¢ãªã»ãã¥ãªãã£äœå¶ãäžçèŠæš¡ã§ç¶æããªãããã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã®å¯èœæ§ãæå€§éã«åŒãåºãããšãã§ããŸãã