å ç¢ãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯ãšç¶æã«é¢ããå æ¬çãªã¬ã€ããäž»èŠãªæŠå¿µããã¹ããã©ã¯ãã£ã¹ãããã³ãªã³ã©ã€ã³è³ç£ãä¿è·ããããã®ã°ããŒãã«ãªèæ ®äºé ãç¶²çŸ ããŠããŸãã
ãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒå®å šãªå®è£
仿¥ã®çžäºæ¥ç¶ãããäžçã§ã¯ã匷åãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®éèŠæ§ã¯ããã匷調ããŠãããããããšã¯ãããŸãããäŒæ¥ãå人ãéä¿¡ãåååŒãæ å ±ã¢ã¯ã»ã¹ã«ãããŠã€ã³ã¿ãŒããããžã®äŸå床ãé«ããã«ã€ããŠããªã³ã©ã€ã³è³ç£ãæªæã®ããæ»æè ããä¿è·ããå¿ èŠæ§ã¯ãããŸã§ä»¥äžã«éèŠã«ãªã£ãŠããŸãããã®å æ¬çãªã¬ã€ãã§ã¯ãå ç¢ã§å¹æçãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ãå®è£ ããããã®äž»èŠãªã³ã³ããŒãã³ãããã¹ããã©ã¯ãã£ã¹ãããã³ã°ããŒãã«ãªèæ ®äºé ã«ã€ããŠæãäžããŠèª¬æããŸãã
è åšã®ç¶æ³ãçè§£ãã
å®è£ ã«å ¥ãåã«ãé²åããè åšã®ç¶æ³ãçè§£ããããšãéèŠã§ãããµã€ããŒè åšã¯åžžã«é²åããŠãããæ»æè ã¯è匱æ§ãæªçšããããã«é«åºŠãªæè¡ãéçºããŠããŸããäžè¬çãªè åšã«ã¯ã次ã®ãã®ããããŸãã
- ãã«ãŠã§ã¢ïŒããŒã¿ãæå·ãŸãã¯çãããã«èšèšãããæªæã®ãããœãããŠã§ã¢ãäŸãšããŠã¯ããŠã€ã«ã¹ãã¯ãŒã ãããã€ã®æšéЬãã©ã³ãµã ãŠã§ã¢ãªã©ããããŸãã
- ãã£ãã·ã³ã°ïŒé»åéä¿¡ã§ä¿¡é Œã§ãããšã³ãã£ãã£ãè£ ãããšã«ãã£ãŠããŠãŒã¶ãŒåããã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãã®è©³çްãªã©ã®æ©å¯æ å ±ãååŸããããã®æ¬ºççãªè©Šã¿ã
- ãµãŒãã¹æåŠïŒDoSïŒããã³åæ£åãµãŒãã¹æåŠïŒDDoSïŒæ»æïŒãã©ãã£ãã¯ã§ãµãŒããŒããµãŒãã¹ããŸãã¯ãããã¯ãŒã¯ãå§åããããšã«ããããµãŒããŒããµãŒãã¹ããŸãã¯ãããã¯ãŒã¯ãžã®éåžžã®ãã©ãã£ãã¯ãäžæããããšãã詊ã¿ã
- SQLã€ã³ãžã§ã¯ã·ã§ã³ïŒãŠã§ãã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæªçšããŠããŒã¿ããŒã¹ã¯ãšãªãæäœããããŒã¿äŸµå®³ã«ã€ãªããå¯èœæ§ã
- ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒïŒä»ã®ãŠãŒã¶ãŒãé²èЧãããŠã§ããµã€ãã«æªæã®ããã¹ã¯ãªãããæ¿å ¥ããããšã
- ã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªïŒCSRFïŒïŒæªæã®ãããŠã§ãèŠæ±ãåœé ããŠããŠãŒã¶ãŒã«ãŠã§ãã¢ããªã±ãŒã·ã§ã³ã§äžèŠãªã¢ã¯ã·ã§ã³ãå®è¡ãããããšã
- ããŒã¿äŸµå®³ïŒæ©å¯ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ãå€ãã®å Žåãé倧ãªçµæžçããã³è©å€äžã®æå®³ããããããŸãã
ãããã®æ»æã®é »åºŠãšå·§åŠãã¯äžçäžã§å¢å ããŠããŸãããããã®è åšãçè§£ããããšãã广çã«è»œæžã§ããã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ãèšèšããäžã§ã®æåã®ã¹ãããã§ãã
ãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®äž»èŠã³ã³ããŒãã³ã
å ç¢ãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããŠã§ãã¢ããªã±ãŒã·ã§ã³ãšããŒã¿ãä¿è·ããããã«é£æºããããã€ãã®äž»èŠãªã³ã³ããŒãã³ãã§æ§æãããŠããŸãããããã®ã³ã³ããŒãã³ãã¯ãå€å±€é²åŸ¡ãæäŸããéå±€åãããã¢ãããŒãã§å®è£ ããå¿ èŠããããŸãã
1. å®å šãªéçºãã©ã¯ãã£ã¹
ã»ãã¥ãªãã£ã¯ãæåããéçºã©ã€ããµã€ã¯ã«ã«çµ±åããå¿ èŠããããŸããããã«ã¯ä»¥äžãå«ãŸããŸãã
- å®å šãªã³ãŒãã£ã³ã°æšæºïŒäžè¬çãªè匱æ§ãé²ãããã«ãå®å šãªã³ãŒãã£ã³ã°ã¬ã€ãã©ã€ã³ãšãã¹ããã©ã¯ãã£ã¹ãéµå®ããŸããããšãã°ããã©ã¡ãŒã¿åãããã¯ãšãªã䜿çšããŠSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãé²ããŸãã
- 宿çãªã³ãŒãã¬ãã¥ãŒïŒã»ãã¥ãªãã£ã®å°éå®¶ã«è匱æ§ãæœåšçãªã»ãã¥ãªãã£äžã®æ¬ é¥ã«ã€ããŠã³ãŒããã¬ãã¥ãŒããŠããããŸãã
- ã»ãã¥ãªãã£ãã¹ãïŒéçããã³åçåæãäŸµå ¥ãã¹ããè匱æ§ã¹ãã£ã³ãªã©ã®åŸ¹åºçãªã»ãã¥ãªãã£ãã¹ãã宿œããŠã匱ç¹ãç¹å®ããŠä¿®æ£ããŸãã
- å®å šãªãã¬ãŒã ã¯ãŒã¯ãšã©ã€ãã©ãªã®äœ¿çšïŒç¢ºç«ãããååã«æ€èšŒãããã»ãã¥ãªãã£ã©ã€ãã©ãªãšãã¬ãŒã ã¯ãŒã¯ã掻çšããŸãããããã¯ãã»ãã¥ãªãã£ã念é ã«çœ®ããŠä¿å®ããã³æŽæ°ãããããšãå€ãããã§ãã
äŸïŒå ¥åæ€èšŒã®å®è£ ã«ã€ããŠèããŠã¿ãŸããå ¥åæ€èšŒã«ããããŠãŒã¶ãŒãæäŸãããã¹ãŠã®ããŒã¿ããã¢ããªã±ãŒã·ã§ã³ã§åŠçãããåã«ã圢åŒãã¿ã€ããé·ããããã³å€ã«ã€ããŠãã§ãã¯ãããŸããããã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ãXSSãªã©ã®æ»æãé²ãäžã§éåžžã«éèŠã§ãã
2. ãŠã§ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒWAFïŒ
WAFã¯ã·ãŒã«ããšããŠæ©èœããæªæã®ãããã©ãã£ãã¯ããŠã§ãã¢ããªã±ãŒã·ã§ã³ã«å°éããåã«ãã£ã«ã¿ãªã³ã°ããŸããHTTPãªã¯ãšã¹ããåæããSQLã€ã³ãžã§ã¯ã·ã§ã³ãXSSããã®ä»ã®äžè¬çãªãŠã§ãã¢ããªã±ãŒã·ã§ã³æ»æãªã©ã®è åšããããã¯ãŸãã¯è»œæžããŸããäž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- ãªã¢ã«ã¿ã€ã ã®ç£èŠãšãããã¯ïŒãã©ãã£ãã¯ãç£èŠããæªæã®ãããªã¯ãšã¹ãããªã¢ã«ã¿ã€ã ã§ãããã¯ããŸãã
- ã«ã¹ã¿ãã€ãºå¯èœãªã«ãŒã«ïŒç¹å®ã®è匱æ§ãŸãã¯è åšã«å¯ŸåŠããããã®ã«ã¹ã¿ã ã«ãŒã«ãäœæã§ããŸãã
- è¡ååæïŒçãããè¡åãã¿ãŒã³ãæ€åºããŠãããã¯ããŸãã
- ã»ãã¥ãªãã£æ å ±ããã³ã€ãã³ã管çïŒSIEMïŒã·ã¹ãã ãšã®çµ±åïŒéäžãã°èšé²ãšåæã®ããã
äŸïŒWAFã¯ããOR 1=1--ããªã©ã®æ¢ç¥ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ãã€ããŒããå«ããªã¯ãšã¹ãããããã¯ããããã«æ§æã§ããŸãããŸããåäžã®IPã¢ãã¬ã¹ããã®ãªã¯ãšã¹ããã¬ãŒãå¶éããŠããã«ãŒããã©ãŒã¹æ»æãé²ãããšãã§ããŸãã
3. äŸµå ¥æ€ç¥ããã³é²æ¢ã·ã¹ãã ïŒIDS/IPSïŒ
IDS/IPSã·ã¹ãã ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ãç£èŠããŠçãããã¢ã¯ãã£ããã£ããªãã確èªããé©åãªã¢ã¯ã·ã§ã³ãå®è¡ããŸããIDSã¯çãããã¢ã¯ãã£ããã£ãæ€åºããã»ãã¥ãªãã£æ åœè ã«èŠåããŸããIPSã¯ãæªæã®ãããã©ãã£ãã¯ãç©æ¥µçã«ãããã¯ããããšã«ãããããã«äžæ©é²ãã§ããŸããéèŠãªèæ ®äºé ã¯æ¬¡ã®ãšããã§ãã
- ãããã¯ãŒã¯ããŒã¹ã®IDS/IPSïŒãããã¯ãŒã¯ãã©ãã£ãã¯ãç£èŠããŠãæªæã®ããã¢ã¯ãã£ããã£ããªãã確èªããŸãã
- ãã¹ãããŒã¹ã®IDS/IPSïŒåã ã®ãµãŒããŒããã³ãšã³ããã€ã³ãã§ã®ã¢ã¯ãã£ããã£ãç£èŠããŸãã
- ã·ã°ããã£ããŒã¹ã®æ€åºïŒäºåå®çŸ©ãããã·ã°ããã£ã«åºã¥ããŠæ¢ç¥ã®è åšãæ€åºããŸãã
- ç°åžžããŒã¹ã®æ€åºïŒè åšã瀺ãå¯èœæ§ã®ããç°åžžãªè¡åãã¿ãŒã³ãèå¥ããŸãã
äŸïŒIPSã¯ãDDoSæ»æã®å åã瀺ããŠããIPã¢ãã¬ã¹ããã®ãã©ãã£ãã¯ãèªåçã«ãããã¯ã§ããŸãã
4. Secure Socket Layer/Transport Layer SecurityïŒSSL/TLSïŒ
SSL/TLSãããã³ã«ã¯ããŠã§ããã©ãŠã¶ãšãµãŒããŒéã®éä¿¡ãæå·åããããã«éèŠã§ããããã«ããããã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãæ å ±ãå人æ å ±ãªã©ã®æ©å¯ããŒã¿ãååããä¿è·ãããŸããéèŠãªåŽé¢ã¯æ¬¡ã®ãšããã§ãã
- èšŒææžç®¡çïŒä¿¡é Œã§ããèªèšŒå±ïŒCAïŒããSSL/TLSèšŒææžã宿çã«ååŸããŠæŽæ°ããŸãã
- 匷åãªæå·ã¹ã€ãŒãïŒåŒ·åã§ææ°ã®æå·ã¹ã€ãŒãã䜿çšããŠãå ç¢ãªæå·åãä¿èšŒããŸãã
- HTTPSã®åŒ·å¶ïŒãã¹ãŠã®ãã©ãã£ãã¯ãHTTPSã«ãªãã€ã¬ã¯ããããããã«ããŸãã
- 宿çãªç£æ»ïŒSSL/TLSæ§æã宿çã«ãã¹ãããŸãã
äŸïŒéèååŒãåŠçãããŠã§ããµã€ãã¯ãéä¿¡äžã®ãŠãŒã¶ãŒããŒã¿ã®æ©å¯æ§ãšæŽåæ§ãä¿è·ããããã«ãåžžã«HTTPSã䜿çšããå¿ èŠããããŸããããã¯ããŠãŒã¶ãŒãšã®ä¿¡é Œãç¯ãäžã§éåžžã«éèŠã§ãããçŸåšã§ã¯å€ãã®æ€çŽ¢ãšã³ãžã³ã®ã©ã³ãã³ã°ã·ã°ãã«ãšãªã£ãŠããŸãã
5. èªèšŒãšèªå¯
ãŠã§ãã¢ããªã±ãŒã·ã§ã³ãšããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããã«ã¯ãå ç¢ãªèªèšŒããã³èªå¯ã¡ã«ããºã ãå®è£ ããããšãäžå¯æ¬ ã§ããããã«ã¯ä»¥äžãå«ãŸããŸãã
- 匷åãªãã¹ã¯ãŒãããªã·ãŒïŒæå°ã®é·ããè€éããããã³å®æçãªãã¹ã¯ãŒãã®å€æŽãªã©ã匷åãªãã¹ã¯ãŒãèŠä»¶ãé©çšããŸãã
- å€èŠçŽ èªèšŒïŒMFAïŒïŒãŠãŒã¶ãŒãã»ãã¥ãªãã£ã匷åããããã«ããã¹ã¯ãŒããã¢ãã€ã«ããã€ã¹ããã®ã¯ã³ã¿ã€ã ã³ãŒããªã©ãè€æ°ã®åœ¢åŒã®èªèšŒãæäŸããããšãèŠæ±ããŸãã
- ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒRBACïŒïŒãŠãŒã¶ãŒã«ãèªåã®åœ¹å²ã«å¿ èŠãªãªãœãŒã¹ãšæ©èœã®ã¿ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
- ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®å®æçãªç£æ»ïŒãŠãŒã¶ãŒã¢ã«ãŠã³ããšã¢ã¯ã»ã¹æš©éã宿çã«ç¢ºèªããŠãäžèŠãŸãã¯äžæ£ãªã¢ã¯ã»ã¹ãç¹å®ããŠåé€ããŸãã
äŸïŒéè¡ã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããžã®äžæ£ã¢ã¯ã»ã¹ãé²ãããã«MFAãå®è£ ããå¿ èŠããããŸããããšãã°ããã¹ã¯ãŒããšæºåž¯é»è©±ã«éä¿¡ãããã³ãŒãã®äž¡æ¹ã䜿çšããããšãäžè¬çãªå®è£ ã§ãã
6. ããŒã¿æå€±é²æ¢ïŒDLPïŒ
DLPã·ã¹ãã ã¯ãæ©å¯ããŒã¿ãçµç¹ã®ç®¡çå€ã«ãªãã®ãç£èŠããã³é²æ¢ããŸããããã¯ã顧客ããŒã¿ã財åèšé²ãç¥ç財ç£ãªã©ã®æ©å¯æ å ±ãä¿è·ããããã«ç¹ã«éèŠã§ããDLPã«ã¯ä»¥äžãå«ãŸããŸãã
- ããŒã¿åé¡ïŒæ©å¯ããŒã¿ãèå¥ããŠåé¡ããŸãã
- ããªã·ãŒã®é©çšïŒæ©å¯ããŒã¿ã®äœ¿ç𿹿³ãšå ±ææ¹æ³ãå¶åŸ¡ããããã®ããªã·ãŒãå®çŸ©ããŠé©çšããŸãã
- ç£èŠãšã¬ããŒãïŒããŒã¿ã®äœ¿çšç¶æ³ãç£èŠããæœåšçãªããŒã¿æå€±ã€ã³ã·ãã³ãã«é¢ããã¬ããŒããçæããŸãã
- ããŒã¿æå·åïŒä¿åæããã³è»¢éäžã®æ©å¯ããŒã¿ãæå·åããŸãã
äŸïŒäŒæ¥ã¯DLPã·ã¹ãã ã䜿çšããŠãåŸæ¥å¡ãæ©å¯é¡§å®¢ããŒã¿ãçµç¹å€ã«ã¡ãŒã«ã§éä¿¡ããããšãé²ãå ŽåããããŸãã
7. è匱æ§ç®¡ç
è匱æ§ç®¡çã¯ãã»ãã¥ãªãã£ã®è匱æ§ãç¹å®ãè©äŸ¡ãããã³ä¿®æ£ããç¶ç¶çãªããã»ã¹ã§ããããã«ã¯ä»¥äžãå«ãŸããŸãã
- è匱æ§ã¹ãã£ã³ïŒæ¢ç¥ã®è匱æ§ã«ã€ããŠã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³ã宿çã«ã¹ãã£ã³ããŸãã
- è匱æ§è©äŸ¡ïŒè匱æ§ã¹ãã£ã³ã®çµæãåæããŠãè匱æ§ã®åªå é äœãä»ããŠå¯ŸåŠããŸãã
- ããã管çïŒã»ãã¥ãªãã£ããããšã¢ããããŒããè¿ éã«é©çšããŠãè匱æ§ã«å¯ŸåŠããŸãã
- äŸµå ¥ãã¹ãïŒå®éã®æ»æãã·ãã¥ã¬ãŒãããŠãè匱æ§ãç¹å®ããã»ãã¥ãªãã£å¶åŸ¡ã®å¹æãè©äŸ¡ããŸãã
äŸïŒãŠã§ããµãŒããŒã®è匱æ§ã宿çã«ã¹ãã£ã³ãããã³ããŒãæšå¥šããå¿ èŠãªããããé©çšããŸããããã¯ãã¹ã±ãžã¥ãŒã«ãçµãã§å®æçã«å®è¡ããå¿ èŠãããç¶ç¶çãªããã»ã¹ã§ãã
8. ã»ãã¥ãªãã£æ å ±ããã³ã€ãã³ã管çïŒSIEMïŒ
SIEMã·ã¹ãã ã¯ããã°ããããã¯ãŒã¯ããã€ã¹ãã»ãã¥ãªãã£ããŒã«ãªã©ãããŸããŸãªãœãŒã¹ããã®ã»ãã¥ãªãã£é¢é£ããŒã¿ãåéããŠåæããŸããããã«ãããã»ãã¥ãªãã£ã€ãã³ãã®äžå çãªãã¥ãŒãæäŸãããçµç¹ã¯æ¬¡ã®ããšãå¯èœã«ãªããŸãã
- ãªã¢ã«ã¿ã€ã ç£èŠïŒã»ãã¥ãªãã£ã€ãã³ãããªã¢ã«ã¿ã€ã ã§ç£èŠããŸãã
- è åšã®æ€åºïŒæœåšçãªè åšãç¹å®ããŠå¯Ÿå¿ããŸãã
- ã€ã³ã·ãã³ã察å¿ïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ãã調æ»ããŠä¿®æ£ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒãïŒèŠå¶ã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºããã¬ããŒããçæããŸãã
äŸïŒSIEMã·ã¹ãã ã¯ãè€æ°ã®ãã°ã€ã³è©Šè¡ã®å€±æãç°åžžãªãããã¯ãŒã¯ãã©ãã£ãã¯ãã¿ãŒã³ãªã©ãçãããã¢ã¯ãã£ããã£ãæ€åºãããå Žåã«ã»ãã¥ãªãã£æ åœè ã«èŠåããããã«æ§æã§ããŸãã
å®è£ æé ïŒæ®µéçã¢ãããŒã
å æ¬çãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®è£ ã¯ã1åéãã®ãããžã§ã¯ãã§ã¯ãªããç¶ç¶çãªããã»ã¹ã§ããçµç¹ã®ç¹å®ã®ããŒãºãšãªãœãŒã¹ãèæ ®ããæ®µéçãªã¢ãããŒãããå§ãããŸããããã¯äžè¬çãªãã¬ãŒã ã¯ãŒã¯ã§ãããåã±ãŒã¹ã§é©å¿ãå¿ èŠã«ãªããŸãã
ãã§ãŒãº1ïŒè©äŸ¡ãšèšç»
- ãªã¹ã¯è©äŸ¡ïŒæœåšçãªè åšãšè匱æ§ãç¹å®ããŠè©äŸ¡ããŸãã
- ã»ãã¥ãªãã£ããªã·ãŒã®éçºïŒã»ãã¥ãªãã£ããªã·ãŒãšæé ãéçºããŠææžåããŸãã
- ãã¯ãããžãŒã®éžæïŒãªã¹ã¯è©äŸ¡ãšã»ãã¥ãªãã£ããªã·ãŒã«åºã¥ããŠé©åãªã»ãã¥ãªãã£ãã¯ãããžãŒãéžæããŸãã
- äºç®ç·šæïŒäºç®ãšãªãœãŒã¹ãå²ãåœãŠãŸãã
- ããŒã ã®çµæïŒã»ãã¥ãªãã£ããŒã ïŒå éšã®å ŽåïŒãç·šæããããå€éšããŒãããŒãç¹å®ããŸãã
ãã§ãŒãº2ïŒå®è£
- ã»ãã¥ãªãã£ã³ã³ãããŒã«ã®æ§æãšå±éïŒéžæããã»ãã¥ãªãã£ãã¯ãããžãŒïŒWAFãIDS/IPSãSSL/TLSãªã©ïŒãå®è£ ããŸãã
- æ¢åã®ã·ã¹ãã ãšã®çµ±åïŒã»ãã¥ãªãã£ããŒã«ãæ¢åã®ã€ã³ãã©ã¹ãã©ã¯ãã£ããã³ã·ã¹ãã ãšçµ±åããŸãã
- èªèšŒãšèªå¯ã®å®è£ ïŒåŒ·åãªèªèšŒããã³èªå¯ã¡ã«ããºã ãå®è£ ããŸãã
- å®å šãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ã®éçºïŒéçºè ããã¬ãŒãã³ã°ããå®å šãªã³ãŒãã£ã³ã°æšæºãå®è£ ããŸãã
- ããã¥ã¡ã³ãã®éå§ïŒã·ã¹ãã ãšå®è£ ããã»ã¹ãææžåããŸãã
ãã§ãŒãº3ïŒãã¹ããšæ€èšŒ
- äŸµå ¥ãã¹ãïŒäŸµå ¥ãã¹ãã宿œããŠè匱æ§ãç¹å®ããŸãã
- è匱æ§ã¹ãã£ã³ïŒã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³ã宿çã«ã¹ãã£ã³ããŠè匱æ§ã確èªããŸãã
- ã»ãã¥ãªãã£ç£æ»ïŒã»ãã¥ãªãã£ç£æ»ã宿œããŠãã»ãã¥ãªãã£ã³ã³ãããŒã«ã®å¹æãè©äŸ¡ããŸãã
- ã€ã³ã·ãã³ã察å¿èšç»ã®ãã¹ãïŒã€ã³ã·ãã³ã察å¿èšç»ããã¹ãããŠæ€èšŒããŸãã
ãã§ãŒãº4ïŒç£èŠãšã¡ã³ããã³ã¹
- ç¶ç¶çãªç£èŠïŒã»ãã¥ãªãã£ãã°ãšã€ãã³ããç¶ç¶çã«ç£èŠããŸãã
- 宿çãªãããé©çšïŒã»ãã¥ãªãã£ããããšã¢ããããŒããè¿ éã«é©çšããŸãã
- ã€ã³ã·ãã³ã察å¿ïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¯Ÿå¿ããŠä¿®æ£ããŸãã
- ç¶ç¶çãªãã¬ãŒãã³ã°ïŒåŸæ¥å¡ã«ç¶ç¶çãªã»ãã¥ãªãã£ãã¬ãŒãã³ã°ãæäŸããŸãã
- ç¶ç¶çãªæ¹åïŒã»ãã¥ãªãã£ã³ã³ãããŒã«ãç¶ç¶çã«è©äŸ¡ããŠæ¹åããŸãã
ã°ããŒãã«å®è£ ã®ãã¹ããã©ã¯ãã£ã¹
ã°ããŒãã«çµç¹å šäœã§ãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ãå®è£ ããã«ã¯ãããŸããŸãªèŠçŽ ãæ éã«æ€èšããå¿ èŠããããŸããããã€ãã®ãã¹ããã©ã¯ãã£ã¹ã«ã¯ã次ã®ãã®ããããŸãã
- ããŒã«ãªãŒãŒã·ã§ã³ïŒã»ãã¥ãªãã£å¯ŸçãçŸå°ã®æ³åŸãèŠå¶ãããã³æåçèŠç¯ã«é©åãããŸããEUã®GDPRãã«ãªãã©ã«ãã¢ïŒç±³åœïŒã®CCPAãªã©ã®æ³åŸã«ã¯ç¹å®ã®èŠä»¶ããããããã«æºæ ããå¿ èŠããããŸãã
- ããŒã¿ã¬ãžãã³ã·ãŒïŒããŒã¿ã¬ãžãã³ã·ãŒèŠä»¶ãéµå®ããŸããããã«ãããç¹å®ã®å°ççãªå Žæã«ããŒã¿ãä¿åããå¿ èŠãããå ŽåããããŸããããšãã°ãäžéšã®åœã§ã¯ãããŒã¿ã®ä¿åå Žæã«é¢ãã峿 ŒãªèŠå¶ããããŸãã
- èšèªãµããŒãïŒè€æ°ã®èšèªã§ã»ãã¥ãªãã£ããã¥ã¡ã³ããšãã¬ãŒãã³ã°è³æãæäŸããŸãã
- 24æé365æ¥ã®ã»ãã¥ãªãã£éçšïŒããŸããŸãªã¿ã€ã ãŸãŒã³ãšå¶æ¥æéãèæ ®ããŠã24æé365æ¥ã®ã»ãã¥ãªãã£éçšã確ç«ããã»ãã¥ãªãã£ã€ã³ã·ãã³ããç£èŠããŠå¯Ÿå¿ããŸãã
- ã¯ã©ãŠãã»ãã¥ãªãã£ïŒã¹ã±ãŒã©ããªãã£ãšã°ããŒãã«ãªãŒãã®ããã«ãã¯ã©ãŠãWAFãã¯ã©ãŠãããŒã¹ã®IDS/IPSãªã©ã®ã¯ã©ãŠãããŒã¹ã®ã»ãã¥ãªãã£ãµãŒãã¹ã掻çšããŸããAWSãAzureãGCPãªã©ã®ã¯ã©ãŠããµãŒãã¹ã¯ãçµ±åã§ãã倿°ã®ã»ãã¥ãªãã£ãµãŒãã¹ãæäŸããŠããŸãã
- ã€ã³ã·ãã³ã察å¿èšç»ïŒããŸããŸãªå°ççãªå Žæã§ã€ã³ã·ãã³ãã«å¯ŸåŠããã°ããŒãã«ã€ã³ã·ãã³ã察å¿èšç»ãçå®ããŸããããã«ã¯ãçŸå°ã®æ³å·è¡æ©é¢ããã³èŠå¶æ©é¢ãšã®é£æºãå«ãŸããå ŽåããããŸãã
- ãã³ããŒã®éžæïŒã°ããŒãã«ãµããŒããæäŸããåœéèŠæ Œã«æºæ ããã»ãã¥ãªãã£ãã³ããŒãæ éã«éžæããŸãã
- ãµã€ããŒã»ãã¥ãªãã£ä¿éºïŒããŒã¿äŸµå®³ãŸãã¯ãã®ä»ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®çµæžç圱é¿ã軜æžããããã«ããµã€ããŒã»ãã¥ãªãã£ä¿éºãæ€èšããŸãã
äŸïŒã°ããŒãã«eã³ããŒã¹äŒæ¥ã¯ãCDNïŒã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒã䜿çšããŠãã³ã³ãã³ããè€æ°ã®å°ççãªå Žæã«é ä¿¡ããããã©ãŒãã³ã¹ãšã»ãã¥ãªãã£ãåäžãããããšãã§ããŸãããŸããäºæ¥ãå±éãããã¹ãŠã®å°åã§ãGDPRãªã©ã®ããŒã¿ãã©ã€ãã·ãŒèŠå¶ã«ã»ãã¥ãªãã£ããªã·ãŒãšæ £è¡ãæºæ ããŠããããšã確èªããå¿ èŠããããŸãã
ã±ãŒã¹ã¹ã¿ãã£ïŒã°ããŒãã«eã³ããŒã¹ãã©ãããã©ãŒã ã®ã»ãã¥ãªãã£ã®å®è£
æ°ããåžå Žã«æ¡å€§ããä»®æ³ã®ã°ããŒãã«eã³ããŒã¹ãã©ãããã©ãŒã ã«ã€ããŠèããŠã¿ãŸããå ç¢ãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã確ä¿ããå¿ èŠããããŸããèããããã¢ãããŒããæ¬¡ã«ç€ºããŸãã
- ãã§ãŒãº1ïŒãªã¹ã¯è©äŸ¡ïŒããŸããŸãªå°åã®èŠå¶èŠä»¶ãšè åšã®ç¶æ³ãèæ ®ããŠãå æ¬çãªãªã¹ã¯è©äŸ¡ã宿œããŸãã
- ãã§ãŒãº2ïŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ããã¢ããïŒ
- äžè¬çãªãŠã§ãæ»æããä¿è·ããããã«WAFãå®è£ ããŸãã
- çµã¿èŸŒã¿ã®ã»ãã¥ãªãã£æ©èœãåããã°ããŒãã«CDNãå±éããŸãã
- DDoSä¿è·ãå®è£ ããŸãã
- ãã¹ãŠã®ãã©ãã£ãã¯ã«åŒ·åãªTLSæ§æã§HTTPSã䜿çšããŸãã
- 管çã¢ã«ãŠã³ããšãŠãŒã¶ãŒã¢ã«ãŠã³ãã«MFAãå®è£ ããŸãã
- ãã§ãŒãº3ïŒãã¹ããšç£èŠïŒ
- è匱æ§ã宿çã«ã¹ãã£ã³ããŸãã
- äŸµå ¥ãã¹ããå®è¡ããŸãã
- ãªã¢ã«ã¿ã€ã ã®ç£èŠãšã€ã³ã·ãã³ã察å¿ã®ããã«SIEMãå®è£ ããŸãã
- ãã§ãŒãº4ïŒã³ã³ãã©ã€ã¢ã³ã¹ãšæé©åïŒ
- GDPRãCCPAãããã³ãã®ä»ã®é©çšãããããŒã¿ãã©ã€ãã·ãŒèŠå¶ãžã®æºæ ã確ä¿ããŸãã
- ããã©ãŒãã³ã¹ãšè åšã®ç¶æ³ã®å€åã«åºã¥ããŠãã»ãã¥ãªãã£ã³ã³ãããŒã«ãç¶ç¶çã«ç£èŠããŠæ¹åããŸãã
ãã¬ãŒãã³ã°ãšæèåäž
匷åãªã»ãã¥ãªãã£æåãæ§ç¯ããããšãéèŠã§ããã»ãã¥ãªãã£ã®è åšãšãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠåŸæ¥å¡ãæè²ããã«ã¯ã宿çãªãã¬ãŒãã³ã°ãšæèåäžããã°ã©ã ãäžå¯æ¬ ã§ãã察象ãšãªãåéã¯æ¬¡ã®ãšããã§ãã
- ãã£ãã·ã³ã°å¯ŸçïŒåŸæ¥å¡ããã£ãã·ã³ã°æ»æãç¹å®ããŠåé¿ããããã®ãã¬ãŒãã³ã°ã
- ãã¹ã¯ãŒãã»ãã¥ãªãã£ïŒåŸæ¥å¡ã«åŒ·åãªãã¹ã¯ãŒãã®äœæãšç®¡çã«ã€ããŠæè²ããŸãã
- å®å šãªããã€ã¹ã®äœ¿çšïŒäŒç€Ÿãçºè¡ããããã€ã¹ãšå人çšããã€ã¹ã®å®å šãªäœ¿çšã«é¢ããã¬ã€ãã³ã¹ãæäŸããŸãã
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ïŒåŸæ¥å¡ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æãèªèããŠåé¿ããããã®ãã¬ãŒãã³ã°ã
- ã€ã³ã·ãã³ãã¬ããŒãïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ããå ±åããããã®æç¢ºãªæé ã確ç«ããŸãã
äŸïŒå®æçãªã·ãã¥ã¬ãŒãããããã£ãã·ã³ã°ãã£ã³ããŒã³ã¯ãåŸæ¥å¡ããã£ãã·ã³ã°ã¡ãŒã«ãèªèããèœåãåŠã³ãåäžãããã®ã«åœ¹ç«ã¡ãŸãã
çµè«
å æ¬çãªãŠã§ãã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®è£ ã¯ãããã¢ã¯ãã£ãã§éå±€åãããã¢ãããŒããå¿ èŠãšããç¶ç¶çãªããã»ã¹ã§ãããã®ã¬ã€ãã§èª¬æããã³ã³ããŒãã³ããšãã¹ããã©ã¯ãã£ã¹ãå®è£ ããããšã«ãããçµç¹ã¯ãµã€ããŒæ»æã®ãªã¹ã¯ãå€§å¹ ã«è»œæžãã貎éãªãªã³ã©ã€ã³è³ç£ãä¿è·ã§ããŸããã»ãã¥ãªãã£ã¯æ±ºããŠç®çå°ã§ã¯ãªããè©äŸ¡ãå®è£ ãç£èŠãæ¹åã®ç¶ç¶çãªéã®ãã§ããããšãå¿ããªãã§ãã ãããè åšã®ç¶æ³ã¯åžžã«å€åããŠãããããã»ãã¥ãªãã£äœå¶ã宿çã«è©äŸ¡ããé²åããè åšã«é©å¿ããããšãéèŠã§ãããŸããå ±å責任ã§ããããŸãããããã®ã¬ã€ãã©ã€ã³ã«åŸãããšã§ãçµç¹ã¯å埩åãããå®å šãªãªã³ã©ã€ã³ãã¬ãŒã³ã¹ãæ§ç¯ããã°ããŒãã«ãªããžã¿ã«ç°å¢ã§èªä¿¡ãæã£ãŠéå¶ããããšãã§ããŸãã