ãªã³ã©ã€ã³æ±ºæžã貿æããã³ãµãŒãã¹äŒæ¥ã®ãã£ãã·ã¥ã¬ã¹æ±ºæžããªã³ã©ã€ã³ãã³ãã³ã°ã·ã¹ãã ã§ã®éè¡å£åº§ã®æäœãããã³ãµãŒãã¹ãããã€ããŒããã®ä»ã®æ±ºæžã¢ããªã±ãŒã·ã§ã³ïŒãã©ã¹ããã¯ã«ãŒãã䜿çšããæäœã®æ°ã¯æ¥éã«å¢å ããŠããŸãã ãããã£ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯æ¡å€§ããŠãããã«ãŒãææè ãšéèŠãªèªèšŒããŒã¿ã«é¢ããæ å ±ãæµéããŠããŸãã ãã®æ å ±ãŸãã¯ãã®äžéšãæ»æè ã®æã«æž¡ããšãçºè¡éè¡ãšãšã³ããŠãŒã¶ãŒã®äž¡æ¹ãééçæ倱ã被ããŸãã
æ¯æãã«ãŒãã®ææè ã«é¢ããããŒã¿èŠçŽ ãåŠçããã·ã¹ãã ã®èŠæš¡ãæ¡å€§ããã«ã€ããŠãè©æ¬ºã®åéãå¢å ããŠããŸãã ãã®åé¡ã«é¢é£ããŠããŠãŒã¶ãŒãçã£ãæãäžè¬çãªæ»æã¯ãäŸç¶ãšããŠæªæã®ãããœãããŠã§ã¢ã䜿çšããããŒã¿ã®çé£ãšããã³ããŒäŒæ¥ã®åœã®WebãªãœãŒã¹ã䜿çšããæ å ±ã®çé£ïŒãã£ãã·ã³ã°ïŒã§ãã ã»ãšãã©ã®å Žåããã³ããŒèªäœã«åããããæ»æã¯ã圱é¿ãåããäŒæ¥ã®åŸæ¥å¡ïŒã€ã³ãµã€ããŒïŒã«ãã£ãŠå®è¡ãããŸãã ãããŠãäŸµå ¥è ã®æåã®ã±ãŒã¹ã§ã¯ããŠãŒã¶æ å ±ã®ã¬ãã«ã§å¶åŸ¡ããé©åãªã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããããšãã§ããå ŽåãåŸè ã®å Žåã«ã¯ãæã ã¯ãããŒã¿èŠçŽ ã®ã«ãŒããä¿åãåŠçããŠéä¿¡ããã·ã¹ãã ããã»ã¹ã®ä¿è·ã«é©åãªçµç¹ãšæè¡çãªã¢ãããŒããå¿ èŠãšããŠããŸãã
å®å šåºæºã¯ã¬ãžããã«ãŒãæ¥çïŒã¯ã¬ãžããã«ãŒãæ¥çã®ã»ãã¥ãªãã£åºæºå¯©è°äŒãè©è°äŒPCI SSCïŒ[ 1]ãäž»èŠãªåœé決æžã·ã¹ãã ïŒãã¶ããã¹ã¿ãŒã«ãŒããã¢ã¡ãªã«ã³ãšã¯ã¹ãã¬ã¹ãã«ãã£ãŠèšç«ãããçºèŠãJCBïŒãã»ãã¥ãªãã£ã®ã«ãŒã«ãå«ãããã¥ã¡ã³ãã®ã»ãããéçºããŸãããã«ãŒãäŒå¡ããŒã¿- æ¯æãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£æšæºïŒPCI DSS ïŒã
PCI DSSèŠæ Œã¯ãæ¯æãã«ãŒãæ å ±ãéä¿¡ãåŠçããŸãã¯ä¿åãããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã³ã³ããŒãã³ãã®ã»ãã¥ãªãã£ã«ããªãå³ããèŠä»¶ã課ããŠããŸãã ãããã®èŠä»¶ã®éµå®ã®ããã®æ¯æãã€ã³ãã©ãã§ãã¯ã¯å€§å¹ ã«ã»ãã¥ãªãã£ã®ã¬ãã«ãäžããåå ãç¹å®ããããšãã§ããŸãã ããã«ãé©åã«æ§æãããç£æ»æé ã«ãããé©åæ§è©äŸ¡æŽ»åäžã«åãåã£ãæ å ±ãæ§é åããåªå é äœã«åŸã£ãŠæ å ±ã»ãã¥ãªãã£ãæ¹åããããã®æšå¥šäºé ãäœæã§ããŸãã ãã®ããã«ãäŒç€Ÿã®åŠåã§ããªãŒããŒãµãŒãã¹ã¯ãæšæºã®éµå®ãè©äŸ¡ããçµæã ãã§ãªããåèŠæ±ã«é¢ããã³ã¡ã³ããå«ãæ£åŒãªå ±åæžã®åœ¢ã§æ±ºæžã€ã³ãã©ã®ä¿è·ã®æãå®å šãªçµµã§ãããå®äºããªããã°ãªããªãåºæ¬çãªæé ã®ã»ããã§ããè¡åèšç»ãåé¡ãä¿®æ£ããŸãã Cã ãã§ãªããäŒæ¥ã®åœå åŸæ¥å¡ã®èŠç¹ããããã¹ãã®å¢çã®å€éšã«ããæ»æè ã®äœçœ®ãªã©ã®æ å ±è³ç£ã®ä¿è·ã®æ¬åœã®ã¬ãã«ã瀺ãããšãã§ãPCI DSSæšæºã§èŠå®å¿ é ã€ãã³ãã®ãªã¹ãã«å«ãŸããŠããäŸµå ¥ãã¹ããã
åœé決æžã·ã¹ãã ïŒ MPS ïŒã¯ããã¹ãŠã®éè¡ã貿æããã³ãµãŒãã¹äŒæ¥ïŒ TSP ïŒãããã»ããµãŒãããã³æ±ºæžã«ãŒãã®åéã§ããžãã¹ãè¡ããã®ä»ã®äŒæ¥ã«PCI DSSèŠæ Œã«æºæ ããããšã矩åä»ããŠããŸãã ééçãèŠæ Œã®èŠä»¶ã«éåããå Žåã®çœ°åããªãããšã¯ãTSPãšãµãŒãã¹ãããã€ããŒã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãšããžãã¹ããã»ã¹ã®é©å¿çã§ãã äžèšãããé©å蚌ææžãååŸããããã®æ£åŒãªæé ãšããŠã®ã¿PCI DSSã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒãµãŒãã¹ãå©çšããã¹ãã§ã¯ãªããšããäºå®ã«åŸãããšã«ãªããŸãã
PCI DSSã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒãµãŒãã¹ãæäŸããã³ã³ãµã«ã¿ã³ãäŒç€Ÿã¯ãæ€èšäžã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ãè©äŸ¡ãããã®æšæºãç£æ»ããããã®æ¹æ³è«ãèªç±ã«äœ¿çšã§ããå¿ èŠããããŸãã PCI DSSèŠä»¶ã®ã³ã³ããã¹ãã§ã¯ããã®æ¹æ³ã«ãããäžå®æéã調æ»äžã®ã·ã¹ãã ã®äž»èŠã³ã³ããŒãã³ãã匷調衚瀺ããããã«å¿ããŠçµæãæ§é åã§ããŸãã ãããã£ãŠãã³ã³ãµã«ã¿ã³ãã®ã¿ã¹ã¯ã¯ãã«ãŒãäŒå¡ããŒã¿ã®ã»ãã¥ãªãã£ã確ä¿ãããã®çµæã顧客ã®PCI DSSæšæºã®èŠä»¶ãæºããããšãæ¯æŽããããšã§ãã
å®çŸ©
ASVïŒæ¿èªæžã¿ã¹ãã£ã³ãã³ããŒïŒã¯ãã»ãã¥ãªãã£åºæºå¯©è°äŒïŒPCI SSCïŒã®å ¬åŒã¹ããŒã¿ã¹ãæã€ã¹ãã£ã³ãµãŒãã¹ãããã€ããŒã§ãã
ãªã³ãµã€ãç£æ» -ç£æ»ã¯ã©ã€ã¢ã³ãã€ã³ãã©ã¹ãã©ã¯ãã£ãå®éã®æ©èœã³ã³ããŒãã³ãã«çŽæ¥ç£æ»äººã«ãã£ãŠè¡ãããŸãã
QSAïŒQualified Security AssessorïŒã¯ãåŸæ¥å¡ãã»ãã¥ãªãã£åºæºå¯©è°äŒïŒPCI SSCïŒãå®æœãããã¬ãŒãã³ã°ãšè©Šéšã«åå¥ã«åæ ŒããäŒç€Ÿã§ãã
ç£æ»äººïŒã³ã³ãµã«ã¿ã³ãïŒ -PCI DSSã®ç£æ»ïŒèŠæ Œã®èŠä»¶ãžã®æºæ ã®æ€èšŒïŒããã³PCI DSSèŠæ Œã®èŠä»¶ãžã®æºæ ã®è©äŸ¡ã«é¢é£ããã³ã³ãµã«ãã£ã³ã°æŽ»åã«æºãã人ã
顧客 - PCI DSSã®èŠä»¶ã®éµå®ã®ããã®ããã©ãŒããŒæ€æ»ãµãŒãã¹ã®ããã©ãŒãã³ã¹ã«èå³ãæã£ãŠæ³ç人ã
ååŸè ã¯ãéè¡ã«ãŒãçºè¡è åäŒã®ã¡ã³ããŒã§ãããæ¯æãã«ãŒããåãå ¥ãã貿æããã³ãµãŒãã¹ãããã¯ãŒã¯ã®äŒæ¥ãšã®çžäºäœçšã確ç«ããã³ç¶æããŸãã [2]
PCI DSSæšæº
PCI DSSã®æŠèŠ
ãã€ã¡ã³ãã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£æšæºã¯ã貿æããã³ãµãŒãã¹äŒæ¥ããµãŒãã¹ãããã€ããŒããã®ä»ã®çµç¹ã®æ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã§éä¿¡ãä¿åãåŠçããããã€ã¡ã³ãã«ãŒãææè ã®ããŒã¿ã®ã»ãã¥ãªãã£ã確ä¿ããããã®12ã®è©³çŽ°ãªèŠä»¶ã®ã»ããã§ãã èŠæ Œã®èŠæ±äºé ã®éµå®ã確ä¿ããããã«é©åãªæªçœ®ããšãããšã¯ãã€ã¡ã³ãã«ãŒãããŒã¿ã®æ å ±ã»ãã¥ãªãã£ãžã®ç·åçãªã¢ãããŒããæå³ããŸãã
æ§æ[3]ããã³PCI DSSæšæºã®å ¬åŒãµããŒãææžã®èª¬æïŒ
1ïŒæ¯æãã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£æšæºã ã»ãã¥ãªãã£ç£æ»ã®èŠä»¶ãšæé ã ããŒãžã§ã³2.0ïŒPayment Card Industry Data Security StandardãèŠä»¶ããã³ã»ãã¥ãªãã£è©äŸ¡æé v2.0ïŒã
ãã®ããã¥ã¡ã³ãã§ã¯ãæšæºã®12ã®èŠä»¶ããã®é©çšç¯å²ãæšæºèŠä»¶ãžã®æºæ ã®ç£æ»ã®æºåãšç£æ»ã®å®æœã«é¢ããåºæ¬æ å ±ãããã³å ±åè³æã®äœæã«é¢ããæ å ±ã«ã€ããŠè©³ãã説æããŠããŸãã ãã®ææžã¯ãäž»ã«ãèŠæ Œã®èŠä»¶ã«æºæ ããããã«ãªã³ãµã€ãç£æ»ãå®æœããç£æ»å¡ã䜿çšããããã«éçºãããŸããã
2ïŒçšèªéã ããŒãžã§ã³2.0ïŒçšèªév2.0ïŒã
PCI DSSèŠå¶ææžã§äœ¿çšãããçšèªãšç¥èªã®ãªã¹ãã ä»ã®ãµããŒãææžã§äœ¿çšãããŠããçšèªãç解ããããšãç®çãšããŠãããããã¬ãã¥ãŒã®ããã«ã客æ§ã«æšå¥šãããŸãã
3ïŒ PCI DSSã®æ¹åã ããŒãžã§ã³2.0ïŒPCI DSSã®ããã²ãŒããããŒãžã§ã³2.0ïŒã
貿æããã³ãµãŒãã¹ãããã¯ãŒã¯ã®äŒæ¥ããµãŒãã¹ãããã€ããŒããã®ä»ã®éèæ©é¢ã«ããæšæºèŠä»¶ã®ç解ãåäžãããããã«ãæšæºã®12ã®èŠä»¶ãšãã®æå³ã®èª¬æãèšèŒããããã¥ã¡ã³ãã
4ïŒ PCI DSSã³ã³ãã©ã€ã¢ã³ã¹ãéæããããã®åªå ã¢ãããŒãã ããŒãžã§ã³1.2ïŒPCI DSS v1.2ã®åªå ã¢ãããŒãïŒã
掻åã®åæ段éã§ãªã¹ã¯ã軜æžããæšæºãžã®æºæ ãéæããããã®äœæ¥èŠåã åªå ã¢ãããŒãã¯6段éã§æ§æãããŠãããåªå é äœã«åŸã£ãŠãã³ã³ãã©ã€ã¢ã³ã¹ãéæããããã®åªåãåæ£ããå®è¡äžã«æ¯æãã«ãŒãã®ããŒã¿ã䟵害ããããªã¹ã¯ã軜æžããŸãã ãã®ã¢ãããŒãã¯ãPCI DSS v2.0æšæºã®èŠä»¶ã眮ãæãããã®ã§ã¯ãããŸããã
5ïŒèªå®ã»ãã¥ãªãã£å°é家ã®èŠä»¶ïŒèªå®ã»ãã¥ãªãã£è©äŸ¡è ã®PCI DSSæ€èšŒèŠä»¶ïŒã
è³æ Œã®ããã»ãã¥ãªãã£å°é家ïŒQSAïŒã®ã¹ããŒã¿ã¹ãååŸæžã¿ãŸãã¯æ¢ã«æã£ãŠããã»ãã¥ãªãã£å°é家åãã®ãPayment Card Security Standards Boardã®èŠä»¶ãå«ãã¢ããªã±ãŒã·ã§ã³ã
6ïŒã¹ãã£ã³ãµãŒãã¹ãããã€ããŒã®èŠä»¶ïŒæ¿èªæžã¿ã¹ãã£ã³ãã³ããŒã®PCI DSSæ€èšŒèŠä»¶ïŒã
ã¹ãã£ã³ãµãŒãã¹ãããã€ããŒïŒASVïŒãåãåã£ãŠããããæ¢ã«æã£ãŠããã»ãã¥ãªãã£å°é家åãã®ãPayment Card Security Standards Boardã®èŠä»¶ãå«ãã¢ããªã±ãŒã·ã§ã³ã
7ïŒèªå°å¿ã®ã·ãŒãã ããŒãžã§ã³2.0ïŒPCI DSS Self-Assessment Questionnaire v2.0ïŒã
èªå·±è©äŸ¡ã·ãŒãã¯ã貿æããã³ãµãŒãã¹äŒæ¥ããã³ãµãŒãã¹ãããã€ããŒã«ããæšæºãžã®æºæ ã®èªå·±è©äŸ¡ãæŽçããããšãç®çãšããŠããããPayment Card Industry Data Security Standardã ã»ãã¥ãªãã£ç£æ»ã®èŠä»¶ãšæé ã ããŒãžã§ã³2.0 "ïŒ"ãã€ã¡ã³ãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£æšæºãèŠä»¶ãšã»ãã¥ãªãã£è©äŸ¡æé v2.0 "ïŒã ç¹å®ã®ã±ãŒã¹ã§äœ¿çšãããèªå·±è©äŸ¡ã·ãŒãã«ã¯ããã€ãã®ãªãã·ã§ã³ããããŸãã
8ïŒ PCI DSSé©åæ§è©äŸ¡-æ¥çå£äœã ããŒãžã§ã³2.0ïŒPCI DSSæºæ 蚌ææž-ããŒãã£ã³ãv2.0ïŒã
QSAãŸãã¯ååŒçµç¹ïŒååŒçµç¹ãå éšç£æ»ãå®æœããå ŽåïŒã«ãã£ãŠå ¥åãããããã¥ã¡ã³ããã³ãã¬ãŒãããã®çµæããã®çµç¹ãPCI DSSèŠæ Œã«æºæ ããŠããããšã«é¢ããå ¬åŒããã¥ã¡ã³ãã§ãã
9ïŒ PCI DSSé©åæ§è©äŸ¡-ãµãŒãã¹ãããã€ããŒã ããŒãžã§ã³2.0ïŒPCI DSSæºæ 蚌ææž-ãµãŒãã¹ãããã€ããŒv2.0ïŒã
QSAãšãµãŒãã¹ãããã€ããŒãPCI DSSèŠæ Œãžã®ãã®ãµãŒãã¹ãããã€ããŒã®ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ããå ¬åŒææžãšããŠèšå ¥ããªããã°ãªããªãããã¥ã¡ã³ããã³ãã¬ãŒãã
è¿œå ã®ããã¥ã¡ã³ãïŒ
1ïŒè¿œå ææž-ASVïŒè¿œå ææž-ASVïŒã
ã¹ãã£ã³ãµãŒãã¹ãããã€ããŒïŒASVïŒããã¥ã¡ã³ããããïŒASVããã°ã©ã ã¬ã€ããASVèŠä»¶ãªã¹ããASVã³ã³ãã©ã€ã¢ã³ã¹ãã§ãã¯ã
2ïŒè¿œå ããã¥ã¡ã³ã-QSAïŒè¿œå ããã¥ã¡ã³ã-QSAïŒã
èªå®ã»ãã¥ãªãã£ãšãã¹ããŒãïŒQSAïŒã®ããã¥ã¡ã³ãïŒQSAãQSAèŠä»¶ã®ãªã¹ãã
3ïŒè¿œå ææž-PFIïŒè¿œå ææž-PFIïŒã
ãã€ã¡ã³ãã«ãŒãæ¥çïŒPFIïŒã®ãã©ã¬ã³ãžãã¯å°é家åãã®äžé£ã®ããã¥ã¡ã³ãïŒPFIããã°ã©ã ã¬ã€ããPFIèŠä»¶ã®ãªã¹ããPFIã¹ããŒã¿ã¹ãžã®æºæ ã®æ€èšŒã æ¯æãæ¥çã®æ³å»åŠã®å°é家ã®å°äœã¯ãPCI SSCè©è°äŒã«ãã£ãŠPCI DSSæšæºã®2çªç®ã®ããŒãžã§ã³ãšãšãã«å°å ¥ãããŸããã
4ïŒèŠä»¶11.3äŸµå ¥ãã¹ãã
äŸµå ¥ãã¹ãã®ããã®PCI DSSæšæº11.3ã®è©³çŽ°ãªèª¬æã
5ïŒèŠä»¶6.6ã¢ããªã±ãŒã·ã§ã³ã¬ãã¥ãŒãšWebã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãæ確åãããŸããã
Webã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®PCI DSSæšæº6.6ã®æ確åã
6ïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ã¬ã€ãã ããŒãžã§ã³1.2ïŒã¯ã€ã€ã¬ã¹ã¬ã€ãã©ã€ã³v1.2ïŒ
ãã®ããã¥ã¡ã³ãã«ã¯ãPCI DSSèŠä»¶ã®ã³ã³ããã¹ãã§ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãå±éããã³ãã¹ãããããã®ææ¡ãšæšå¥šäºé ãå«ãŸããŠããŸãã
æšæºã®éçºè ã¯ãããã¥ã¡ã³ãããŒã¹ãæ§ç¯ããæé ã«æ³šæãæããŸããã ã³ã³ãµã«ã¿ã³ãã¯ãç£æ»ã®æ¹æ³è«çåºç€ãéçºããããã«ãå ¬åŒææžã®é¢ä¿ã決å®ããå¿ èŠããããŸãã å³1ã«ã¯ãå ¬åŒã®PCI DSSææžã®åŸå±æ§ã瀺ãå³ãå«ãŸããŠããŸãã
å³1 -PCI DSSèŠæ Œã®å ¬åŒææžã®åŸå±
äž»èŠãªããŒã¿ä¿è·èŠä»¶
ãã€ã¡ã³ãã«ãŒãææè ã®ããŒã¿ä¿è·ãçµç¹ããããã®éèŠãªèŠä»¶ã¯ãããã¥ã¡ã³ãããã€ã¡ã³ãã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£åºæºã ã»ãã¥ãªãã£ç£æ»ã®èŠä»¶ãšæé ã ããŒãžã§ã³2.0ãïŒãæ¯æãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£æšæºãèŠä»¶ããã³ã»ãã¥ãªãã£è©äŸ¡æé v2.0ãïŒããã³ã»ãã¥ãªãã£ç£æ»ã®ããã»ã¹ãç°¡çŽ åãããããªæ¹æ³ã§ã°ã«ãŒãåãããŠããŸãã 以äžã¯ãPCI DSSæšæºã®äžå¿ã§ãããç£æ»æé ã®çš®é¡ãšãã®ç°¡åãªåæã«ãã£ãŠã°ã«ãŒãåããã12ã®èŠä»¶ã®ãªã¹ãã§ãã
1ïŒèŠä»¶1.ãã«ãŒãäŒå¡ããŒã¿ãä¿è·ããããã«ãã¡ã€ã¢ãŠã©ãŒã«ãã€ã³ã¹ããŒã«ããæ©èœã確èªããŸããã
2ïŒèŠä»¶2ããããã©ã«ãã§ã¯ãã¡ãŒã«ãŒãèšå®ãããã¹ã¯ãŒãããã®ä»ã®ã·ã¹ãã ãã©ã¡ãŒã¿ã䜿çšããªãã§ãã ãããã
æåã®ã°ã«ãŒãã¯ãå®å šãªãããã¯ãŒã¯ã®æ§ç¯ãšç¶æããšåŒã°ããŸã ïŒèŠä»¶1ããã³2ïŒã æåã®èŠä»¶ãããã¿ãŒã²ããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ã°ã¡ã³ããŒã·ã§ã³ããã»ã¹ãã©ãã»ã©éèŠã§ããããã®ããã»ã¹ãã©ã®ãããªåºç€ã§æ§ç¯ãããŠããããæããã«ãªããŸãã ãã¡ã€ã¢ãŠã©ãŒã« -ã»ãã¥ãªãã£ã®åºç€ã 埪ç°ãã©ãã£ãã¯ãé©åã«èšèšãããšãã€ã³ãã©ã¹ãã©ã¯ãã£å šäœãæŽé ãããŸãã ããã«ãããããããæšæºã®ææ°ããŒãžã§ã³ã§ã¯ãæåã®èŠä»¶ã®è¡šçŸãå€å°ç·©åãããŠããããã¡ã€ã¢ãŠã©ãŒã«ã ãã§ãªããã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããã³ãããã¯ãããšããäºå®ãæ瀺ããŠããŸãã
ã·ã¹ãã ã®äž»èŠãªã³ã³ããŒãã³ãã®ãããã¯ããã³ãã£ã«ã¿ãªã³ã°ãããã¯ãŒã¯ãã©ãã£ãã¯ã®å®è£ ã«å ããŠã第äžã®èŠä»¶ã¯ïŒãŠãŒã¶ããã©ã¡ãŒã¿ãå€æŽããããšã¯ã§ããŸããé©åã«æ§æãããåŸæ¥å¡ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³äžã§ããŒãœãã«ãã¡ã€ã¢ãŠã©ãŒã«ãæå³ç¯1.4ãå«ã¿ãïŒæ¯æææžã®æèã«ããããã¹ããããã¯ãŒã¯å ã®ãµãŒãæ段ïŒãã¡ã€ã¢ãŠã©ãŒã«ã®æ©èœïŒ-ããã¯ãçµç¹ã®ç®¡çè ãæé ãå¶åŸ¡ããã®ãæãå°é£ã§ãã 2çªç®ã®èŠä»¶ã¯ãã¡ãŒã«ãŒãããã©ã«ãã§èšå®ããã·ã¹ãã ãã©ã¡ãŒã¿ã®å¿ é å€æŽããããã¯ãŒã¯ç®¡çè ã«æãåºãããŸãã
3ïŒèŠä»¶3.ãã«ãŒãææè ãžã®ããŒã¿ã®å®å šãªä¿åã確ä¿ãããã
4ïŒèŠä»¶4.ãã«ãŒãææè ããããªãã¯ãããã¯ãŒã¯çµç±ã§éä¿¡ãããå Žåãã«ãŒãææè ã®ããŒã¿ã®æå·åã確ä¿ãããã
èŠä»¶ãã«ãŒãææè ã®ããŒã¿ä¿è·ã ïŒèŠä»¶3ããã³4ïŒã®ã°ã«ãŒãã¯ãããŒã¿ä¿è·ã®éèŠãªæ¹æ³ïŒæå·åãã»ãã¥ãªãã£ããŒããªã·ãŒãªã©ïŒãšãã®ç¯å²ãèæ ®ããŸãããä»ã®èŠä»¶ã§èª¬æãããæ å ±ä¿è·ã®ä»ã®æ¹æ³äŸµå®³ã®ãªã¹ã¯ãæžããæ段ãšããŠäœçœ®ä»ããããŠããŸãã ãã®äžé£ã®èŠä»¶ã§ã¯ãã»ãã¥ãªãã£ããŒããªã·ãŒãšã©ã€ããµã€ã¯ã«ã«ã€ããŠèª¬æããŸãã æå·åããã圢åŒã§ãã©ã¹ããã¯ã«ãŒãã®ææè ã«ããŒã¿ãä¿åããããšã«ãããæ»æè ã«ããäžæ£äœ¿çšã®äºå®ãæé€ããããšããäºå®ã«ããïŒåœŒãäœããã®æ¹æ³ã§ä»ã®ä¿è·ã©ã€ã³ãå æããå ŽåïŒããã®ã°ã«ãŒãã®ãã€ã³ãã¯éåžžã«å³å¯ã«è¡šçŸããããªããžã§ã¯ãã«ãã£ãŠæ確ã«è§£éãããããã³ç£æ»ã®å¯Ÿè±¡ã å人ããŒã¿ïŒç¹å®ã®å人ã«é¢é£ããæ å ±ïŒã«é¢é£ãããã©ã¹ããã¯ã«ãŒãã®ææè ã«ããŒã¿ãä¿åããããã®äŸ¿å©ãªææ³ã¯ãããããŒãœãã©ã€ãŒãŒã·ã§ã³ãã§ããææè ãäžæã«èå¥ã§ããªããããã®ããŒã¿ã®æçãåé€ãŸãã¯ç¬ç«ããŠä¿åããæé ã§ãã
5ïŒèŠä»¶5.ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã䜿çšããå®æçã«æŽæ°ãããã
6ïŒèŠä»¶6.ãå®å šãªã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³ãéçºããã³ç¶æãããã
èŠä»¶5ãš6ãçµã¿åãããã°ã«ãŒãã¯ã è匱æ§ç®¡çãšåŒã°ããŸã ã è匱æ§ç®¡çãšã¯ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãå«ãææ°ã®æŽæ°ããã°ã©ã ã®ã¿ã€ã ãªãŒãªã€ã³ã¹ããŒã«ãWebããŒã¹ã®ãã®ãå«ãå®å šãªã¢ããªã±ãŒã·ã§ã³ã®éçºãä¿å®ãããã³äœ¿çšãæããŸãã
7ïŒèŠä»¶7.ãå ¬åŒã®å¿ èŠæ§ã«å¿ããŠãã«ãŒãææè ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶éãããã
8ïŒèŠä»¶8.ãæ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¢ã¯ã»ã¹ã§ããå人ã«äžæã®èå¥åãå²ãåœãŠãŸããã
9ïŒèŠä»¶9.ãã«ãŒãäŒå¡ããŒã¿ãžã®ç©ççã¢ã¯ã»ã¹ãå¶éãããã
èŠä»¶7ã8ã9ã¯ã ãå³æ Œãªã¢ã¯ã»ã¹å¶åŸ¡æ段ã®å®è£ ãã°ã«ãŒãã«ã°ã«ãŒãåãããçµç¹ã®ã»ãã¥ãªãã£æ段ãšç©ççã¢ã¯ã»ã¹ããã³ç£èŠã¡ã«ããºã ã®äž¡æ¹ã䜿çšããŠæ å ±ã®ä¿è·ã確ä¿ããããã®çµç¹çããã³æè¡çãªæ§è³ªã§ãã
10ïŒèŠä»¶10.ãã«ãŒãææè ã®ãããã¯ãŒã¯ãªãœãŒã¹ããã³ããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããã³ç£èŠãããã
11ïŒèŠä»¶11.ãã»ãã¥ãªãã£ã·ã¹ãã ãšããã»ã¹ã®å®æçãªãã¹ããå®æœãããã
ç£æ»äººã«ãšã£ãŠæ³šç®ãã¹ãã¯ã ããããã¯ãŒã¯ã®å®æçãªç£èŠãšãã¹ãããšããèŠä»¶ã®ã°ã«ãŒãã§ãïŒèŠä»¶10ã11ïŒã å¿ ããããã¹ãŠã®è²¿æãšãµãŒãã¹äŒç€Ÿã¯ã瀟å ã»ãã¥ãªãã£ã®ãµãŒãã¹å 容ãè²·ãäœè£ãã§ãããã®åã¯ãå®æçã«äºé²äŸµå ¥ãã¹ãããã³ã»ãã¥ãªãã£ããã»ã¹ã®ç£èŠãè¡ã£ãŠããŸãã ãããã®äœç³»çãªæé ãå®è£ ããå¿ èŠããããããæ å ±ã»ãã¥ãªãã£åžå Žã§ã¯ãå éšããã³å€éšã®äŸµå ¥ãã¹ãã®åœ¢ã§ããŸããŸãªãµãŒãã¹ãçºçããå®å šã«ç°ãªããµãã©ã€ã€ãŒããã®è匱æ§ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãã¹ãã£ã³ããŸãã PCI DSSèŠä»¶ã®éµå®ãè©äŸ¡ããäžã§ç£æ»äººã¯ã浞éããã³ASV-ã¹ãã£ã³ã®æåŸã®ã¡ã³ããã³ã¹ãã¹ãã®çµæïŒãµã11.2ãã®è匱æ§ã®ããã«ååæããšã«ã¹ãã£ã³ããš11.3ãæ¯å¹Žã®ãããã¬ãŒã·ã§ã³ãã¹ããïŒã«ç²ŸéããŠãããšããã¹ãŠã®èå¥ãããè匱æ§ãæé€ããããšã確èªããå¿ èŠããããŸãã ãããã®çµæã¯ã第äžè æ©é¢ãæäŸããäŸµå ¥ãã¹ãããã³è匱æ§ã¹ãã£ã³ãµãŒãã¹ã®çµæãšããŠååŸã§ãããšããäºå®ãããã³ãã®çµæãç£æ»äººã®çµè«ã¯ã第äžè ã«ãããã®ãµãŒãã¹ã®æäŸäžã«ååŸããããŒã¿ã®ä¿¡é Œã«åºã¥ããŠããŸãã
12ïŒèŠä»¶12.ãæ å ±ã»ãã¥ãªãã£ããªã·ãŒãäœæããã³ç¶æãããã
å®è£ ã®ç¯å²ã«é¢ããèŠä»¶12ã¯ã顧客ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®é©å¿ã«é¢ããŠæãé£ãããã®ã®1ã€ã§ãã æ¡é 12.1.1ã§ã¯ããã¹ãŠã®PCI DSSèŠä»¶ãèæ ®ããããªã·ãŒã®äœæãå¿ èŠã§ãã 貿æãšèªå®ããããµãŒãã¹ã®äŒæ¥ããµãŒãã¹ãããã€ãã¯ããã®ã»ãã¥ãªãã£ããªã·ãŒãçå®ãæšæºã®èŠä»¶ã«å¿ããé»æµã確èªããŠãã ããã
Visaããã³MasterCardã»ãã¥ãªãã£ããã°ã©ã
PCI DSSèŠæ Œã¯ãäž»èŠãªåœé決æžã·ã¹ãã ã«ãã£ãŠéçºãããŠãããVisaãšMasterCardã»ãã¥ãªãã£ããã°ã©ã ã®èŠä»¶ãçµã¿åãããŠããŸãã
ãã¶AISããã°ã©ã
Visaã¢ã«ãŠã³ãæ å ±ã»ãã¥ãªãã£ïŒAISïŒããã°ã©ã ã¯ãVisa for EuropeïŒç±³åœã®åæ§ã®Visaããã°ã©ã -ã«ãŒãææè æ å ±ã»ãã¥ãªãã£ããã°ã©ã ïŒã«ãã£ãŠéçºãããå çåºããã³ãµãŒãã¹ãããã€ããVisaæ¯æãã«ãŒãææè ã®ã»ãã¥ãªãã£å¯Ÿçãæ¹åããã®ãæ¯æŽããŸãããã©ã³ã¶ã¯ã·ã§ã³æ å ±ã
çµç¹ãæºããå¿ èŠã®ããVisa AISããã°ã©ã ã®èŠä»¶ã¯ãçµç¹ãæ¯å¹Žä¿åãåŠçãéä¿¡ããVisaè³æ Œæ å ±ã®æ°ã«ãã£ãŠç°ãªãããããã®ããŒã¿ã«åŸã£ãŠãååŸè ã¯ç¹å®ã®ã¬ãã«ãå人ã«å²ãåœãŠãŸãã 以äžã¯ã販売è ãšãµãŒãã¹ãããã€ããŒã®ããã°ã©ã èŠä»¶ã®ãªã¹ãã§ãã
貿æãšãµãŒãã¹äŒç€ŸïŒå人ïŒã®èŠä»¶ïŒ
1ïŒPCI DSSèŠä»¶ã®éµå®ã«é¢ãã幎次ç£æ»ïŒå¹Žé600äžä»¶ä»¥äžã®Visaãã©ã³ã¶ã¯ã·ã§ã³ãåŠçããTSPããŸãã¯å¥ã®å°åãŸãã¯åœã§1ã€ã®Visaã¬ãã«ãå²ãåœãŠãããåœéTSPïŒã
2ïŒã¢ã³ã±ãŒãïŒSAQïŒã®å¹Žéèªå·±å®äºïŒãã¹ãŠã®æ¯æããã£ãã«ã§å¹Žé100äžãã600äžã®Visaãã©ã³ã¶ã¯ã·ã§ã³ãåŠçããTSPããŸãã¯å¹Žé20,000ãã100äžã®ãã¶eã³ããŒã¹ãã©ã³ã¶ã¯ã·ã§ã³ãåŠçããTSPïŒ ;
3ïŒã¹ãã£ã³ãµãŒãã¹ãããã€ããŒïŒASVïŒã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
4ïŒé©å蚌ææžã®ååšïŒTSPã®ãã¹ãŠã®ã¬ãã«ïŒ;
5ïŒã¢ã¯ã¯ã€ã¢ã©ã«ãã£ãŠå®è¡ãããã³ã³ãã©ã€ã¢ã³ã¹ãã§ãã¯ïŒå¹Žé20,000æªæºã®Visa eã³ããŒã¹ãã©ã³ã¶ã¯ã·ã§ã³ãåŠçããTSPããŸãã¯å¹Žéæ倧100äžä»¶ã®ãã©ã³ã¶ã¯ã·ã§ã³ãåŠçããä»ã®ãã¹ãŠã®TSPïŒã
ãµãŒãã¹ãããã€ããŒã®ãã¶èŠä»¶ïŒ
1ïŒPCI DSSèŠä»¶ã®éµå®ã«é¢ãã幎次ç£æ»ã
2ïŒSAQïŒå¹Žé300,000æªæºã®Visaãã©ã³ã¶ã¯ã·ã§ã³ãåŠçãããµãŒãã¹ãããã€ããŒïŒã®å¹Žéå®äºã
3ïŒPCI DSSèŠæ Œã«æºæ ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
4ïŒé©å蚌ææžã®ååšã
MasterCard SDPããã°ã©ã
MasterCardãæ¿èªããMasterCard Site Data ProtectionïŒSDPïŒã¯ãPCI DSSèŠæ Œã«åŸã£ãŠãMasterCardã¢ã«ãŠã³ãããŒã¿ã®TSPããã³ãµãŒãã¹ãããã€ããŒãå®å šã«ä¿åããããã«èšèšãããŠããŸãã 以äžã¯ã販売è ãšãµãŒãã¹ãããã€ããŒã®ããã°ã©ã èŠä»¶ã®ãªã¹ãã§ãã
販売è åãã®MasterCardã®èŠä»¶ïŒ
AïŒTSPã¬ãã«1ïŒãã¹ã¿ãŒã«ãŒãããã³å¯ããšã¹ãããããã®ããã«ãæ¯å¹Ž600äžä»¶ã®ä»¥äžã®ååŒã®å¹Žé売äžé«ãæã€ãã¹ãŠã®TSPã;ãã¹ãŠã®TSPã¯ã匷çãããŒã¿ã®æŒæŽ©ã«ã€ãªãã£ãæ»æã®åœ±é¿ãåããã®è£éã§ãã¬ãã«1ã«å²ãåœãŠãããŠãããã¹ãŠã®TSP MasterCardïŒã¯ã次ã®èŠä»¶ã«æºæ ããå¿ èŠããããŸãã
1ïŒQSAãå®æœãã幎次ç£æ»ã
2ïŒASVã«ãã£ãŠå®è¡ãããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
3ïŒå¿ é ã®ã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒæé ã
BïŒTSPã¬ãã«2ïŒã®å£²äžé«ãæã€ãã¹ãŠã®TSP 100äžäººä»¥äžãã以äžãã¹ã¿ãŒãšããšã¹ããã®ããã«æ¯å¹Ž600äžãã©ã³ã¶ã¯ã·ã§ã³ã«çããããã¹ãŠã®TSPã¯ã次ã®èŠä»¶ãæºãããªããã°ãªããªãïŒå¥ã®æ¯æãã·ã¹ãã ã®ã¬ãã«2ã«å¯Ÿå¿ããŸãã
1ïŒQSAãå®æœãã幎次ç£æ»ã
2ïŒSAQã¢ã³ã±ãŒãã®å¹Žæ¬¡èšå ¥ïŒ2010幎12æ31æ¥ãŸã§ïŒã
3ïŒASVã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
4ïŒåæã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒæé ã®å®è£ ïŒ2010幎12æ31æ¥ãŸã§ïŒã
CïŒTSPã¬ãã«3ïŒãã¹ãŠã®TSPããã¹ã¿ãŒãšããšã¹ããã«é»ååååŒã®æ°ã¯å¹Žé20 000ãè¶ ãããããã¹ã¿ãŒãšããšã¹ããäžã®eã³ããŒã¹ãã©ã³ã¶ã¯ã·ã§ã³ã®åèšæ°ã100äžãè¶ ããŠããªããä»ã®æ¯æãã·ã¹ãã ã®ã¬ãã«3ã«å¯Ÿå¿ããå šãŠã®TSPïŒãåŸããªããã°ãªããŸãã以äžã®èŠä»¶ïŒ
1ïŒSAQã¢ã³ã±ãŒãã®å¹Žæ¬¡èšå ¥ã
2ïŒASVã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
3ïŒå¿ é ã®ã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒæé ã
dïŒã¬ãã«4ã®TSPïŒæåã®3ã€ã®ã¬ãã«ã«å±ããªããã¹ãŠã®TSPïŒã¯ã次ã®èŠä»¶ãæºãããŠããå¿ èŠããããŸãã
1ïŒSAQã¢ã³ã±ãŒãã®å¹Žæ¬¡èšå ¥ã
2ïŒASVã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
3ïŒã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒæé ã®æ¥ã«ååŸè ãšåè°ããã
MasterCardãµãŒãã¹ãããã€ããŒã®èŠä»¶ïŒ
aïŒã¬ãã«1ãµãŒãã¹ãããã€ããŒïŒãã¹ãŠã®ãµãŒãããŒãã£ããã»ããµã300,000ãè¶ ããMasterCardããã³Maestroãã©ã³ã¶ã¯ã·ã§ã³ãæ¯å¹Žä¿åã転éããŸãã¯åŠçãããã¹ãŠã®ããŒã¿ã¹ãã¬ãŒãžçµç¹ïŒã¯ã次ã®èŠä»¶ãæºããå¿ èŠããããŸãã
1ïŒQSAãå®æœãã幎次ç£æ»ã
2ïŒASVã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
bïŒã¬ãã«2ã®ãµãŒãã¹ãããã€ããŒïŒMasterCardããã³Maestroã®å¹Žé30äžä»¶æªæºã®ãã©ã³ã¶ã¯ã·ã§ã³ãä¿åã転éããŸãã¯åŠçãããã¹ãŠã®ããŒã¿ã¹ãã¬ãŒãžçµç¹ïŒã¯ã次ã®èŠä»¶ãæºããå¿ èŠããããŸãã
1ïŒSAQã¢ã³ã±ãŒãã®å¹Žæ¬¡èšå ¥ã
2ïŒASVã«ããååæããšã®ãããã¯ãŒã¯ã¹ãã£ã³ã
IPUã®èŠä»¶ãé å®ããªãã£ãå Žåã®è²¬ä»»
TSPã¬ãã«ã¯ãTSPãæ¥ç¶ãããŠããã¢ã¯ã¯ã€ã¢ã©ã«ãã£ãŠçŽæ¥æ±ºå®ãããŸãã ã¿ãŒã³ã§ã¯ãIPUã¯ã幎äºåTSPã¬ãã«1ã2ãPCI DSSèŠä»¶ã®3ã®å ±åã³ã³ãã©ã€ã¢ã³ã¹ãæäŸããããã«ãè²·åãå¿ èŠã§ãã ãããã£ãŠãè²·åè ã¯ã貿æããã³ãµãŒãã¹äŒæ¥ãšééçã®éã®ä»²ä»è ãšããŠæ©èœããŸãã 貿æããã³ãµãŒãã¹äŒæ¥ãééçã®èŠåã«éåããå Žåããã¶ã¯ãªã¹ã¯ã管çããããã®é©åãªæªçœ®ãè¬ããŸããããã«ãããååŸè ã«çœ°éã課ãããå¯èœæ§ããããŸã[5]ã
ã¬ãã«1ã®åºæºãæºãããµãŒãã¹ã»ãããã€ãã¯ãå¿ èŠãªã³ã³ãã©ã€ã¢ã³ã¹æç¶ã§ãããPCI DSSæºæ ã®ãµãŒãã¹ãããã€ãã®ãªã¹ãã«å«ãŸããŠããŸãã ãµãŒãã¹ãããã€ãã®ã¬ãã«2ã¯äžã«å«ãŸãããªã¹ãã®é¢é£ããè²·åãããŠïŒã³ã³ãããŒã«ãsamooprosnikaç£èŠçµæãè¡šããŠããïŒãå¶åŸ¡ãããŠããŸããã
å³2-ééçãšéèæ©é¢ã®çžäºäœçšã®ã¹ããŒã
PCI DSSèŠæ Œã«æºæ ããISç£æ»
PCI DSSå ã®ãµãŒãã¹
以äžã¯ãPCI DSSæšæºã§æäŸã§ãããµãŒãã¹ã®ç¯å²ã§ãã
1ïŒPCI DSSãžã®æºæ ã®ç£æ»
ã¹ããŒã¿ã¹QSAïŒèªå®ã»ãã¥ãªãã£è©äŸ¡æ©é¢ïŒãæããç£æ»äººãå®æœãã以äžã®äžè¬çãªæé ãå«ãŸããŸãã
aïŒPCI DSSèŠæ Œã«æºæ ããããã®ç£æ»ã®æºåãšèšç»ã«åãçµã¿ãŸãã
bïŒç£æ»æé ã«åŸã£ãŠæŽ»åãå®æœããã
cïŒçµæã®åæã
dïŒPCI DSSæšæºã«æºæ ããããã®ç£æ»ã¬ããŒãã®çæã
2ïŒPCI DSSãžã®æºæ ã®ç£æ»ãå®æœããããã®ã客æ§ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æºå
PCI DSSéµå®ã®ããã®èªèšŒã®æŽ»åãžã®é¡§å®¢ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãæºåããããã«è¡ãããèŠæ Œã«æºæ ããããã®äºåçãªç£æ»ã§ãã
3ïŒPCI DSSèŠæ Œã®èŠä»¶ã«åŸã£ãè匱æ§ã¹ãã£ã³
ããã¯ãASVïŒæ¿èªæžã¿ã¹ãã£ã³ãã³ããŒïŒã®ã¹ããŒã¿ã¹ãæã€äŒæ¥ã«ãã£ãŠå®è¡ãããPCI DSSèŠæ Œã®èŠä»¶11.3ã«åŸã£ãŠãå¿ é ã®æé ã§ãããå ¬åŒææžPCI DSSã»ãã¥ãªãã£ã¹ãã£ã³æé ã«è©³çŽ°ã«åæ ãããŠããŸãã
4ïŒPCI DSSã«æºæ ããäŸµå ¥ãã¹ã
äŸµå ¥ãã¹ãã¯ãå°ãªããšã幎ã«äžåºŠïŒ11.3 PCI DSSèŠä»¶ã®æšæºïŒãéå¬ããå«ãŸããŠããæšæºã«æºæ ãéæããããã«å¿ é ã§ãã
aïŒå€éšäŸµå ¥ãã¹ãã
BïŒå éšç£æ»ã
5ïŒé¡§å®¢çµç¹ã®æ å ±ã»ãã¥ãªãã£ã®åéã«ãããé«åºŠãªãã¬ãŒãã³ã°ã³ãŒã¹
ããã¯ãã客æ§ã®åŸæ¥å¡ã®æèãé«ããããã«è¡ããããªãã·ã§ã³ã§ä»¥äžãå«ã¿ãŸãïŒ
aïŒæ å ±ã»ãã¥ãªãã£ã®ããŸããŸãªåŽé¢ã«é¢ãããã¬ãŒãã³ã°ãšã»ãããŒã
bïŒããŒãå¥ãã¬ãŒã³ããŒã·ã§ã³ã®ãã¢ã³ã¹ãã¬ãŒã·ã§ã³;
dïŒãŠã§ãããŒã®å®æœã
PCI DSSèŠæ Œã¯ãVisaããã³MasterCardïŒVisa AISãMasterCard SDPïŒãéçºããæ å ±ä¿è·ããã°ã©ã ã®èŠä»¶ãçµã¿åããããã®ã§ããããã®æ¯æãã·ã¹ãã ã䜿çšãããã¹ãŠã®çµç¹ã«é©çšãããŸãã
ãã®æšæºã¯ãPCI DSSæšæºãå¿ é ã§ããCEMEAå°åïŒäžå€®ããã³æ±ãšãŒããããäžæ±ãã¢ããªã«ïŒã«å¿ èŠã§ãããããã£ãŠããã®å°åã®ãã¹ãŠã®TSPããã³ãµãŒãã¹ãããã€ããŒã¯ãã³ã³ãã©ã€ã¢ã³ã¹æé ãå®è¡ããå¿ èŠããããŸãã ãããã£ãŠãäžèšã®MEAãšã®ã³ã©ãã¬ãŒã·ã§ã³ãã·ã¢ã®éèæ©é¢ã¯ãæšæºçãªè©äŸ¡æé ã®PCI DSSã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãåããªããã°ãªããŸããã
ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ãå®æœããããã®äžè¬çãªã¢ãããŒã
PCI DSSæšæºã®äžã§æäŸã§ãããµãŒãã¹ã®äžè¬çãªãªã¹ãã®äžã§ã顧客ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ã®å šäœåãååŸããã³ã³ãã©ã€ã¢ã³ã¹èšŒææžãçºè¡ãããšãQSAã¹ããŒã¿ã¹ãååŸããäŒæ¥ã«ãã£ãŠå®è¡ãããèŠä»¶ãžã®ã³ã³ãã©ã€ã¢ã³ã¹ã®ç£æ»ãµãŒãã¹ãæäŸã§ããŸãã
ISç£æ»ãå®æœããã¢ãããŒãã«ã¯ãæ ¹æ¬çã«ç°ãªã2ã€ã®æ¹æ³ããããŸãã
1ïŒäŸµå ¥ãã¹ãã
2ïŒæ å ±ã»ãã¥ãªãã£ã®æè¡ç£æ»ã
é©åæ§ãã§ãã¯æé ã®æåã®æ®µéã§ãç£æ»äººã¯ç£æ»é åãç¹å®ããŸããã³ã³ããŒãã³ãã®ã»ããã¯ã圌ã®æèŠã§ã¯ãæ¯æãã«ãŒãããŒã¿ã®ã»ãã¥ãªãã£ã®çšåºŠã«é¢ããå®å šãªæ å ±ãååŸããã®ã«ååã§ãã
PCI DSSæšæºèŠä»¶ãžã®æºæ ã«é¢ããç£æ»ãèŠä»¶ã®åæãããã³å ¬åŒææžãPayment Card Industry Data Security Standardãã«èšèŒãããŠããé©åãªå¯Ÿçã®æ¡çšããã»ã¹ã èŠä»¶ãšã»ãã¥ãªãã£è©äŸ¡æé ãïŒããã€ã¡ã³ãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£åºæºãèŠä»¶ãšã»ãã¥ãªãã£è©äŸ¡æé ãïŒã ç£æ»é åãšãµã³ãã«ã®æ±ºå®çµæã¯ãç£æ»äººã«ãã£ãŠç¢ºèªãããã¬ããŒãã«èšé²ãããŸãã ããã«ãç£æ»å¡ã¯ã³ã³ããŒãã³ãïŒäŒç€Ÿã®ãªãã£ã¹ãTSPãäŒç€Ÿã®ãã£ã©ã¯ã¿ãŒãªã©ïŒã®ç·æ°ã決å®ããŸã[6]ã åŸãããããŒã¿ã¯ãé©åæ§è©äŸ¡ã®æ®µéã§å ¥åãšããŠäœ¿çšãããŸãã
é©åæ§è©äŸ¡ãå®æœããããã«éçºãããæ¹æ³è«ã«åŸã£ãŠãç£æ»äººã¯åæããŒã¿ãåéãã段éã§åãåã£ãæ å ±ãåæããŸãã çµæã¯ãèŠä»¶ãéèšããŠããŸãã èŠä»¶ãæºããããŠããªãå Žåãè£åæªçœ®ã®ãªã¹ããäœæãããŸã[6]ãæºããããŠããªãèŠä»¶ããã®ãããªæªçœ®ãæå³ããå Žåã é©åæ§è©äŸ¡æé ã®æåŸã«ãç£æ»äººã¯ã¬ããŒãïŒAOCãé©å蚌ææžïŒã«èšå ¥ããŸãã
ç£æ»ã®äž»èŠãªæ®µé
以äžã®é ç®ã¯ããã·ã¢ã®äž»èŠã³ã³ãµã«ãã£ã³ã°äŒç€Ÿã®ç£æ»å®åãæ§ç¯ããããã«å¯ŸããŠãã€ã«ã¹ããŒã³ã®ã»ããã§ãã
1ïŒç¬¬äžæ®µéã åæãšäœç³»åã
èæ¯ïŒ
aïŒã¯ãã«ãŒãææè ã«é¢ããéèŠãªæ å ±ãä¿ç®¡ãŸãã¯åŠçããã顧客ã®ã·ã¹ãã ã®æ§æèŠçŽ ã«é¢ããæ å ±ãã
bïŒæ å ±ã»ãã¥ãªãã£ã«é¢é£ããã客æ§ã®èŠå¶ããã³ç®¡çææžïŒPCI DSSã®èŠä»¶ã«åŸã£ãŠå¿ èŠãªæ å ±ã»ãã¥ãªãã£ããªã·ãŒãèŠå¶ãæ瀺ãããã³ãã®ä»ã®ææžïŒã
cïŒããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®æ å ±è»¢éããããã¯ãŒã¯ããããžã®æ§æãšç¹æ§ã
dïŒæ å ±ã·ã¹ãã ã®å éšããã³å€éšéä¿¡ã®æ§è³ªãæ å ±ã·ã¹ãã ã§éèŠãªæ å ±ãåŠçããååã
äœæ¥ç¯å²ïŒ
aïŒãœãŒã¹ããŒã¿ã®åæã
bïŒãœãŒã¹ããŒã¿ã®åæã«åºã¥ããç£æ»é åã®éžæã
åºåããŒã¿ïŒ
aïŒããããžïŒæ å ±åŠçããã€ã¹ã®ãªã¹ããšç¹æ§ïŒç£æ»ãšãªã¢ã
bïŒäœæ¥ç¯å²ããã³å¿ èŠãªç£æ»ã®æè¡çæ段ã®æ±ºå®ã«é¢ããæ å ±ã
2ïŒã¹ããŒãž2ãæšæºã®èŠä»¶ãžã®æºæ ã®è©äŸ¡ã
å ¥åããŒã¿ïŒåã®ã¹ãããã§ååŸããåºåããŒã¿ã
äœæ¥ç¯å²ïŒé¡§å®¢ã®éžæãããèªèšŒé åã®æ©èœã«ãã£ãŠæ±ºå®ãããŸãïŒïŒ
aïŒäŒæ¥ãããã¯ãŒã¯ã®åæãšãã®ã»ãã¥ãªãã£ã®æ€èšŒã
bïŒç¡ç·ãããã¯ãŒã¯ã®åæãšã»ãã¥ãªãã£ã®æ€èšŒã
cïŒãã¡ã€ã¢ãŠã©ãŒã«ã®æ§æã®åæã
dïŒã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãã®åæã
eïŒãã¹ã¯ãŒãããªã·ãŒåæã
fïŒéèŠãªæ å ±åŠçæè¡ã®åæã
gïŒãããã¯ãŒã¯ç£èŠãœãããŠã§ã¢ã®å¯çšæ§ã確èªãããŠãŒã¶ãŒã®ã¢ã¯ã·ã§ã³ãèšé²ããŸãã
hïŒãœãããŠã§ã¢æŽæ°ããªã·ãŒïŒã»ãã¥ãªãã£ãœãããŠã§ã¢ãå«ãïŒã®ç¢ºèªã
åºåããŒã¿ïŒ
aïŒPCI DSSèŠæ Œã®èŠä»¶ãžã®é¡§å®¢ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ããæçµçµè«ã
bïŒé¡§å®¢ããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ãæ¢åã®è匱æ§ãã»ãã¥ãªãã£ããªã·ãŒã®èšèšã«ããããšã©ãŒã®åçãå ¥æããã
3ïŒã¹ããŒãž3ãã¬ããŒãçæã
å ¥åããŒã¿ïŒåã®ã¹ãããã§ååŸããåºåããŒã¿ã
äœæ¥ç¯å²ïŒèªèšŒå¯©æ»ã®çµæã«é¢ããå ±åæžã®äœæã
奥ä»ïŒã客æ§ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãPCI DSSæšæºã®èŠä»¶ã«æºæ ããŠããããšã«é¢ããèªèšŒç£æ»ã®çµæã«ã€ããŠå ±åããŸãã
æŠå Ž-ã»ã°ã¡ã³ã
PCI DSSã®ç¯å²ã§ããã°æ¥œèŠ³çãªèŠãŠãæ¬è³ªçãªèŠä»¶ã¯ãã«ãŒãçªå·ïŒPANïŒã®äžã«æäœããã·ã¹ãã ã«é©çšãããŸãããã ããå®éã®ãã·ã¹ãã ãã®æŠå¿µã¯éåžžã«æ¡åŒµå¯èœã§ãã·ã¹ãã ãå®çŸ©ããå€ãã®ã³ã³ããŒãã³ãã§ã«ãŒãçªå·ãåŠçã§ããŸããã¡ãªã¿ã«ãPANããã®ä»ã®æ å ±ãå«ãã«ãŒãäŒå¡ããŒã¿ã«å ããŠãéèŠãªèªèšŒããŒã¿ããããŸãããã®ããŒã¿ã®ä¿åã¯ãæå·åããã圢åŒã§ãåãå ¥ããããŸããã
å³3-ããŒã¿èŠçŽ ãšããã«å¯Ÿå¿ãã察ç
ã瀺ãè¡šãã©ã¹ããã¯ã«ãŒãã®ããŒã¿èŠçŽ ãšããã«å¯Ÿå¿ããä¿è·å¯Ÿçã瀺ãè¡šãèŠããšãCVV2ïŒã«ãŒãæ€èšŒå€2 -Visaæ¯æãã·ã¹ãã ã®ã«ãŒãã®èªèšŒã³ãŒãïŒãšCVC2ïŒMasterCardæ¯æãã·ã¹ãã ã®åãã³ãŒãïŒã¯éèŠãªèªèšŒããŒã¿ã§ãããããä¿åã§ããŸãããããã«ããããããããŠãŒã¶ãŒã®æ¥åã§ã¯ã顧客ã®ç掻ãç°¡çŽ åããããã«è²©å£²ããã³ãµãŒãã¹äŒç€ŸãWebãªãœãŒã¹ã«ãã®ã³ãŒããåå ¥åããå¿ èŠããªãå ŽåããããŸãããã®ãããªçµç¹ã¯ãCVC2ãšCVV2ããªã³ã©ã€ã³éèååŒãè¡ãéã®éèŠãªãªã³ã¯ã®1ã€ã§ãããããPCI DSS蚌ææžïŒããã³ãã®çµæãããžãã¹ããã»ã¹ã®ã»ãã¥ãªãã£ïŒãšãŠãŒã¶ãŒã«å¯Ÿããé床ã®ç䌌ã±ã¢ãéžæããå¿ èŠããããŸãã
ã¿ãŒã²ããã·ã¹ãã ã®æ§é ãæé©åãããã®åŸã«ãŒããã«ããŒã®ããŒã¿ãæäœããç°å¢ãéžæããããšã«ãããPCI DSSã®åœ±é¿ç¯å²ãçããç£æ»è ã®æ³šæãããå ·äœçãªãªããžã§ã¯ãã«éäžããããã®çµæãé©åæ§è©äŸ¡ã®ã³ã¹ããåæžã§ããŸãããã ããã»ã°ã¡ã³ããŒã·ã§ã³ããã»ã¹ã§ã¯ãåé¡ã®çµç¹ã®ããžãã¹ããã»ã¹ãç解ããå Žåã«ãã£ãŠã¯åæ§ç¯ããå¿ èŠããããŸããããã¯ãæé©åãããŠããªãç£æ»ãããã¯ããã«ã³ã¹ããé«ããªããŸãããã®å Žåããããã¯ãŒã¯å šäœãç£æ»ç¯å²ã«å«ãŸããŸããããã§ãåçµç¹ã¯ãçŸåšã®ããžãã¹æ £è¡ãä¿®æ£ãã¹ããããŸãã¯ãçŸç¶ã®ãŸãŸãã®ãã§ãã¯ãåãããããã©ãããèªã決å®ããå¿ èŠããããŸãã
ã©ã®ãããªæ¹æ³ã§ç¡ç·ãããã¯ãŒã¯ã¯ãã«ãŒãäŒå¡ã®ããŒã¿äŒéã®åªäœãšããŠäœ¿çšãããŠããå Žåã¯ããã®äºå®ã¯ééã£ãã»ã°ã¡ã³ããŒã·ã§ã³ãŸãã¯ãã®æ¬ åŠã®çµæã§ãããã®å Žåãåãžã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ããã®PCI DSSèŠä»¶ãæ¥ãããããïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£å°é家ã¯ããéè·¯ã«æšªããã£ãŠãããã®ããã«ïŒïŒçç±ã¯ãmeticulousnessãèŠä»¶ã®ïŒèšŒææžå©çšè ãŸãã¯ç£æ»ã®äžéšã®ããã®ããããã«è¯ãã§ã¯ãããŸããã
ãã¹ãã»ã°ã¡ã³ãã®ããäžã€ã®ãå¯çè«ã¯ããåŠçãµãŒãã¹ãã¹ãã¬ãŒãžããŸãã¯ã«ãŒãäŒå¡ããŒã¿ã®äŒéç·šæã®ç 究ãæäŸå çµç¹ã§ããå第äžè ã¯ãç£æ»å¡ã«PCI DSSã³ã³ãã©ã€ã¢ã³ã¹èšŒææžãæ瀺ããããé©åæ§è©äŸ¡æé ãå®è¡ããå¿ èŠããããŸãã
çµè«ãå°ããŸãïŒ
1ïŒé©åãªã»ã°ã¡ã³ããŒã·ã§ã³ã«ãããé©åæ§è©äŸ¡ãå®æœããæéãšãå Žåã«ãã£ãŠã¯ééçã³ã¹ããåæžã§ããŸãã
2ïŒææè ã®ããŒã¿ãåŠçããæ段ãšããŠã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ã·ã¹ãã å ã®ååš-誀ã£ãã»ã°ã¡ã³ããŒã·ã§ã³æé ãŸãã¯ãã®äžåšã®çµæã
3ïŒããžãã¹ããã»ã¹ãžã®ç¬¬äžè ã®é¢äžã«ã¯ãç£æ»äººã«ãããããã®åœäºè ã®æ€èšŒã®ããã®è¿œå ã®æéè²»çšã䌎ããŸãã
åèæç®
1.çšèªè§£èª¬ïŒããŒãžã§ã³2.0ïŒ - PCI SSCã2010 - 16 P
2. PCIã»ãã¥ãªãã£åºæºå¯©è°äŒ- PCI SSCã2010 - www.pcisecuritystandards.orgã
3. PCI DSSããã¥ã¡ã³ãã©ã€ãã©ãª-PCI SSCã2010-www.pcisecuritystandards.org/security_standards/documents.php?category = supporting
4.ããã¥ã¡ã³ããæ¯æãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£æšæºãèŠä»¶ãšã»ãã¥ãªãã£ç£æ»æç¶ãïŒããŒãžã§ã³2.0ïŒ - PCI SSCã2010 - ã84 P
5. PCI DSSã³ã³ãã©ã€ã¢ã³ã¹ç®¡ç- «INFOSECã2010幎- www.pcisecurity.ruã
6.ææžãPayment Card Industry Data Security Standardãã®ä»é²BãCãFãã»ãã¥ãªãã£ç£æ»ã®èŠä»¶ãšæé ãïŒããŒãžã§ã³2.0ïŒ-PCI SSCã2010-84ããŒãž
ãã®åæäœæ¥ã®äžéšã®è³æã¯ã2011幎1æã«HackerèªïŒïŒ144ïŒã«æ²èŒãããŸããã