![](https://habrastorage.org/storage2/280/063/2cf/2800632cf8ca58309400e36aaa782a66.jpg)
Windows Server 2012ã«é¢é£ããè³æã®ç¿»èš³ãšå ¬éãããã³Microsoftã®ãã€ãã£ãç£æ»ã·ã¹ãã ã®æŽæ°ãåŒãç¶ãè¡ã£ãŠããŸãã èå³ã®ããèªè ã«ã¯ãWindows ServerããŒã ã®åŸæ¥å¡ãDynamic Access Controlã®æ°æ©èœã«ã€ããŠè©±ããããšãç解ããŠãã ããã
ããã«ã¡ã¯ãç§ã®ååã¯Nir Ben-Zviã§ããWindowsServerããŒã ã§åããŠããŸãã æ¬æ¥ãWindows Server 2012ã§å©çšå¯èœãªDynamic Access Controlã®æ°ããæ©èœã»ããã玹ä»ã§ããããšãå¬ããæããŸãã
ãŸããèšç»ããã»ã¹ã«ã€ããŠç°¡åã«èª¬æãã次ã«ãæ°ããäžå€®ã¢ã¯ã»ã¹ããªã·ãŒã¢ãã«ãèŠãŠãWindows Server 2012ã§æ§ç¯ãããœãªã¥ãŒã·ã§ã³ã§ããFile Serverã®æ°æ©èœã«ã€ããŠèª¬æããŸãããã®æ©èœã䜿çšããå¿ èŠãããå Žåã¯ãç°å¢å šäœãWindows Server 2012ã«ç§»åããå¿ èŠããããŸããã æåŸã«ãããŒãããŒã®ã©ã®ãããªæ±ºå®ããœãªã¥ãŒã·ã§ã³ã®ææ¡æ©èœã®æ¡åŒµã«åœ¹ç«ã€ãã«é¢ããåé¡ãæ€èšããŸãã
ã¯ããã«
ææ°ã®ïŒèªã¿åãïŒè€éãªïŒITã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ãåæ£ã·ã¹ãã ã§ããŒã¿äœæãé©ç°çãªé床ã§è¡ãããŸãã åæã«ããã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ã¯å€æ°ã®ããã€ã¹ããå®è¡ãããŸãã æ å ±ã»ãã¥ãªãã£æšæºãžã®æºæ ãšæ©å¯æ å ±ãæŒæŽ©ããä¿è·ããå¿ èŠæ§ã¯ãããžãã¹ããã³ITã«ãšã£ãŠæãéèŠãªåé¡ã®äžéšã§ãã ãããã®åé¡ã解決ããã«ã¯ãç¹å®ã®æ å ±ã«èª°ãã¢ã¯ã»ã¹ããããå¶åŸ¡ããå¿ èŠããããŸãããã®ãããªå¶åŸ¡ãå®è£ ãããšãã¯ãã¢ã¯ã»ã¹æ å ±ãã§ããã ãæ確ã«æ瀺ããããšãæãŸããã§ãã
æ°å¹ŽåãWindows Server 2012ãã©ã®ãããªãã®ã«ãªãããèšç»ãããšãã«ãããžãã¹ãšITãçŽé¢ãããããã®åé¡ãèªèããŠããŸããã
â¢ããžãã¹ãªã¯ãšã¹ããšèŠå¶èŠä»¶ãæºããç®çã®äž¡æ¹ã«åºã¥ããæ å ±ãžã®ã¢ã¯ã»ã¹ã®äžå 管ç
â¢æ å ±ãžã®ã¢ã¯ã»ã¹ã®ç£æ»ã¯ãåæãšISæšæºã®èŠä»¶ãžã®æºæ ãç®çãšããŠå®æœããå¿ èŠããããŸãã
â¢æ©å¯æ å ±ãä¿è·ããå¿ èŠããããŸãã
â¢ã³ã³ãã³ãææè ã¯èªåã®æ å ±ã«è²¬ä»»ãæã€å¿ èŠããããŸã-管çè ã¯ä»äºä»¥å€ã«åŸäºãã¹ãã§ã¯ãããŸãã
â¢éèŠãªåŽé¢ã¯ãæ å ±å°é家ã®çç£æ§ãç¶æããããšã§ã
èŠä»¶ã«é©ããäžé£ã®ãã¯ãããžãšãœãªã¥ãŒã·ã§ã³ãæ瀺ããããã«ãçµç¹å ã®åã ã®ããžã·ã§ã³ãšãããžãã¹ããã³èŠå¶æ©é¢ããã®èŠæ±ãæºããããã»ã¹ã§ã®ãããã®çžäºäœçšã調ã¹ãŸããã
ãããã£ãŠãç¹å®ãããåé¡ã®è§£æ±ºã«é¢äžããæçš¿ã®ãªã¹ãã¯ãããžãã¹ã®èŠ³ç¹ããããŒãºãå®çŸ©ããèŠå¶èŠä»¶ãæºããCSO / CIOã§å§ãŸããŸãã ãã®åŸã«ãã·ã¹ãã ã管çããIT管çè ãšå®éã®æ å ±ãç£èŠããã³ã³ãã³ãææè ãç¶ããŸãã æ å ±ãçŽæ¥æäœãã人ã«é¢ããŠã¯ãé©çšããããœãªã¥ãŒã·ã§ã³ã®æ å ±ãžã®åœ±é¿ã¯æå°éã«æããå¿ èŠããããŸãïŒçæ³çã«ã¯ããŸã£ãã圱é¿ããªãããã«ããå¿ èŠããããŸãïŒã
![ç»å](https://habrastorage.org/getpro/habr/post_images/19e/3cb/87f/19e3cb87ff628975e883dedf13566507.jpg)
çµç¹ãèŠå¶èŠä»¶ãæºãããããžãã¹ã¿ã¹ã¯ã解決ã§ããããã«ãæçµçã«æ¬¡ã®åéã«çŠç¹ãåœãŠãŸããã
â¢ç®æšãéæããããã«ç®¡çããå¿ èŠãããæ å ±ã®å®çŸ©
â¢æ å ±ã¢ã¯ã»ã¹ããªã·ãŒã®é©çš
â¢æ å ±ãžã®ã¢ã¯ã»ã¹ã®ç£æ»
â¢æ å ±ã®æå·å
ãããã®ã¿ã¹ã¯ã¯ãWindowsããã³ããŒãããŒãœãªã¥ãŒã·ã§ã³ã§ããŒã¿ä¿è·ãå¯èœã«ããäžé£ã®Windowsæ©èœã«å€æãããŠããŸãã
â¢Active Directoryã§äžå€®ã¢ã¯ã»ã¹ããã³ç£æ»ããªã·ãŒãæ§æããæ©èœãè¿œå ãããŸããã ãããã®ããªã·ãŒã¯æ¡ä»¶ä»ãèŠä»¶ã«åºã¥ããŠããŸãïŒä»¥äžãåç §ïŒã ãã ããã¢ã¯ã»ã¹å¶åŸ¡çšã®ã»ãã¥ãªãã£ã°ã«ãŒãã®æ°ã¯å€§å¹ ã«åæžã§ããŸãã
oãŠãŒã¶ãŒã¯èª°ã§ãã
o圌ã䜿çšããŠããããã€ã¹
oã¢ã¯ã»ã¹ãããããŒã¿
â¢ã¯ã¬ãŒã ã¯WindowsèªèšŒïŒKerberosïŒã«çµ±åãããŠããããããŠãŒã¶ãŒãšããã€ã¹ã¯ãã¡ã³ããŒã§ããã»ãã¥ãªãã£ã°ã«ãŒãã ãã§ãªããã¯ã¬ãŒã ã«ãã£ãŠã説æã§ããŸããããšãã°ãã財åéšã®ãŠãŒã¶ãŒãããã«ããŽãªãŒãé«ãã»ãã¥ãªãã£ã¯ãªã¢ã©ã³ã¹ãã
â¢æ¹åããããã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ãã³ã³ãã³ã管çè ãšãŠãŒã¶ãŒãããŒã¿ãèå¥ïŒã¿ã°ä»ãïŒã§ãããããIT管çè ã¯ãããã®ã¿ã°ã«åºã¥ããŠã¿ãŒã²ããããªã·ãŒãäœæã§ããŸãã ãã®æ©èœã¯ããã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ©èœãšãšãã«æ©èœãããã¡ã€ã«ã®å 容ããã®ä»ã®ç¹æ§ã«åºã¥ããŠãã¡ã€ã«ãèªåçã«åé¡ããŸãã
â¢ãµãŒããŒäžã®æ©å¯æ å ±ãèªåçã«ä¿è·ïŒæå·åïŒããçµ±åRights ManagementãµãŒãã¹ãããã«ããããµãŒããŒãé¢ããå Žåã§ãä¿è·ãããŸãã
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒ
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã¯ãçµç¹ããµãŒããŒã§äœ¿çšããä¿éºãšæ¯èŒã§ããŸãã ãããã®ããªã·ãŒã¯ãæ å ±ã«é©çšãããããŒã«ã«ã¢ã¯ã»ã¹ããªã·ãŒïŒããšãã°ãä»»æACLïŒãæ¹åããŸãïŒçœ®ãæããŸããïŒã ããšãã°ããã¡ã€ã«ã®ããŒã«ã«DACLãç¹å®ã®ãŠãŒã¶ãŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŠããããäžå€®ããªã·ãŒãåããŠãŒã¶ãŒãžã®ã¢ã¯ã»ã¹ãçŠæ¢ããŠããå Žåããã®ãŠãŒã¶ãŒã¯ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸããïŒéãåæ§ïŒã
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒãå®è£ ããã³åŒ·åããã€ãã·ã¢ããã¯ãããŸããŸãªçç±ããã³çµç¹ã®ããŸããŸãªã¬ãã«ããæé·ããŸãã
â¢èŠå¶èŠä»¶ã®éµå®ã«é¢é£ããããªã·ãŒïŒãã®ããªã·ãŒã¯ãèŠå¶ããã³ããžãã¹èŠä»¶ãšæŽåæ§ãããã管çãããŠããæ å ±ãžã®æ£ããïŒååã«ç¢ºç«ãããïŒã¢ã¯ã»ã¹ãä¿è·ããããšãç®çãšããŠããŸãã ããšãã°ãUS-EUã»ãŒãããŒããŒèŠå¶ææžã«è©²åœããæ å ±ãžã®ã¢ã¯ã»ã¹ãç¹å®ã®ãŠãŒã¶ãŒã°ã«ãŒãã®ã¿ã«èš±å¯ããå Žåã
â¢éšéã¬ãã«ã®èš±å¯ããªã·ãŒïŒçµç¹å ã®åéšéã«ã¯ãä¿è·ïŒåŒ·åïŒããããŒã¿ãæ±ãããã®ç¹å®ã®èŠä»¶ããããŸãã ãã®ç¶æ³ã¯ã倧èŠæš¡ãªçµç¹æ§é ãæã€çµç¹ã§ããèŠãããŸãã ããšãã°ã財åéšéã¯ã財åæ å ±ãžã®ã¢ã¯ã»ã¹ã財ååŸæ¥å¡ã®ã¿ã«å¶éããããšèããŠããŸãã
â¢ç¥ãå¿ èŠãããããªã·ãŒïŒãã®ããªã·ãŒã¯ããç¥ãå¿ èŠãããã人ã ãã«ã¢ã¯ã»ã¹ãèš±å¯ãããããã«ããŸãã äŸïŒ
oãã³ããŒã¯æ å ±ã«ã¢ã¯ã»ã¹ããäœæ¥äžã®ãããžã§ã¯ãã«é¢é£ãããã¡ã€ã«ã®ã¿ãç·šéããå¿ èŠããããŸãã
oéèæ©é¢ã§ã¯ãæ å ±éã®ãå£ããéèŠã§ããããšãã°ãã¢ããªã¹ãã¯èšŒåžæ å ±ã«ã¢ã¯ã»ã¹ã§ããããããŒã«ãŒã¯åææ å ±ã«ã¢ã¯ã»ã¹ã§ããŸããã
äžå€®ç£æ»ããªã·ãŒ
äžå€®ç£æ»ããªã·ãŒã¯ãçµç¹ã®ã»ãã¥ãªãã£ãç¶æã§ãã匷åãªããŒã«ã§ãã ã»ãã¥ãªãã£ç£æ»ã®äž»ãªç®çã®1ã€ã¯ãæ å ±ã»ãã¥ãªãã£èŠå¶ãéµå®ããããšã§ãã SOXãHIPPAãPCIãªã©ã®æ¥çæšæºã§ã¯ãçµç¹ã¯æ å ±ã»ãã¥ãªãã£ãšããŒã¿ãã©ã€ãã·ãŒã«é¢é£ããååã«ç¢ºç«ãããäžé£ã®ã«ãŒã«ã«åŸãå¿ èŠããããŸãã ç£æ»äººã®ä»äºã¯ããã®ãããªããªã·ãŒã®ååšïŒãŸãã¯äžåšïŒã確ç«ããããã«ãã£ãŠãããã®æšæºã®èŠä»¶ãžã®ã³ã³ãã©ã€ã¢ã³ã¹ïŒãŸãã¯ã³ã³ãã©ã€ã¢ã³ã¹éåïŒã蚌æããããšã§ãã ããã«ãã»ãã¥ãªãã£ç£æ»ã䜿çšãããšãç°åžžãªåäœãèšé²ããã»ãã¥ãªãã£ã·ã¹ãã ã®ç©Žã®åœ¢æãç¹å®ããŠåé¿ããäžæ£ãªåäœãå¶éã§ããŸããéèŠãªãŠãŒã¶ãŒã¢ã¯ãã£ããã£ã¯ãã¹ãŠèšé²ããããã®ãããªèšé²ã¯èª¿æ»äžã«äœ¿çšã§ããŸãã
Windows Server 2012ã§ã¯ã管çè ã¯ããŠãŒã¶ãŒãã¢ã¯ã»ã¹ããæ å ±ãšãŠãŒã¶ãŒãèæ ®ããåŒã䜿çšããŠç£æ»ããªã·ãŒãéçºã§ãããããçµç¹ã¯ã©ãã«ããŠãç¹å®ã®æ å ±ãžã®ã¢ã¯ã»ã¹ã®ã¿ãç£æ»ã§ããŸãããªãã£ãã ããã«ãããããã¿ãŒã²ãããçµã£ããåæã«äœ¿ããããç£æ»ããªã·ãŒãžã®éãéãããŸãã ããã§ããããŸã§å®è£ ãé£ããã£ãã·ããªãªãå®è£ ã§ããŸãã ããšãã°ã以äžã«ãªã¹ããããŠããç£æ»ããªã·ãŒãç°¡åã«éçºã§ããŸãã
â¢èš±å®¹åºŠã®é«ãã«ããŽãªãæã£ãŠããªãã«ããããããããéèŠãªãæ å ±ã«ã¢ã¯ã»ã¹ããããšããŠãããã¹ãŠã®äººã®ç£æ»
â¢äœæ¥ããŠããªããããžã§ã¯ãããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ããããšããŠãããã¹ãŠã®ãã³ããŒã®ç£æ»ã
ããã«ãããç£æ»ã€ãã³ãã®éã調æŽããããéèŠãªã€ãã³ãã®ã¿ã«å¶éããããšãã§ããŸããããã«ãããèšå€§ãªæ°ã®ã¬ã³ãŒããäœæããããšãªããããŸããŸãªãµãŒããŒäžã®æ å ±ãžã®ã¢ã¯ã»ã¹ã远跡ã§ããŸãã
ããã«ãæ å ±ã®ã¿ã°ä»ãã¯ç£æ»ã€ãã³ãã«èšé²ããããããã€ãã³ãåéã¡ã«ããºã ã䜿çšããŠãã³ã³ããã¹ãã¬ããŒããçæã§ããŸããããšãã°ãéå»3ãæéã«éèŠãªæ å ±ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã
ãã¡ã€ã«ãµãŒããŒãœãªã¥ãŒã·ã§ã³
ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«åºã¥ããŠãWindows Server 2012 Active DirectoryãWindows Server 2012 File Serverãããã³Windows 8ã¯ã©ã€ã¢ã³ãçšã®å®å šãªãœãªã¥ãŒã·ã§ã³ãéçºããŸããã ãã®ãœãªã¥ãŒã·ã§ã³ã«ããã次ã®ããšãå¯èœã«ãªããŸãã
â¢èªåããã³æåã®ãã¡ã€ã«åé¡ã䜿çšããŠããŒã¿ãèå¥ããŸãã
â¢äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã®ã»ãŒããã£ãããããªã·ãŒã䜿çšããŠããã¹ãŠã®ãµãŒããŒã«ããããã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸãã ããšãã°ãçµç¹å šäœã§ãããã¯ãŒã¯æ£åžžæ§æ å ±ãåä¿¡ãããŠãŒã¶ãŒãå¶åŸ¡ã§ããŸãã
â¢ãã¡ã€ã«ãµãŒããŒäžã®ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãç£æ»ããäžå€®ç£æ»ããªã·ãŒã䜿çšããŠæ å ±ã»ãã¥ãªãã£æšæºã«æºæ ãã調æ»ãå®æœããŸãã ããšãã°ãéå»3ãæéã«æ©å¯æ§ã®é«ãæ å ±ã«èª°ãã¢ã¯ã»ã¹ããããå€æã§ããŸãã
â¢æ©å¯ææžã®Rights Management ServicesïŒRMSïŒã®èªåæå·åã«ããããŒã¿æå·åã ããšãã°ãHIPAAã§ä¿è·ãããæ å ±ãå«ããã¹ãŠã®ããã¥ã¡ã³ããæå·åããããã«RMSãæ§æã§ããŸãã
![ç»å](https://habrastorage.org/getpro/habr/post_images/fee/e76/567/feee76567dc13448675bc1158060e329.jpg)
çµç¹å ã®è€æ°ã®ãã¡ã€ã«ãµãŒããŒã®å®è£ ããµããŒãããããã«ãè€æ°ã®ãµãŒããŒéã§ã¬ããŒããæ§æããã³çæã§ããData Classification ToolkitãæäŸããŠããŸãã
Data Classification Toolkitã®ããŒã¿çã¯ããããããŠã³ããŒãã§ããŸãã
段éçãªå®è£ ã³ã³ã»ãã
DACãéçºããããã®éèŠãªååã®1ã€ã¯ã段éçãªå®è£ ã§ãã ãã¡ã€ã«ãµãŒããŒã®ç£æ»ãšæ å ±ãžã®ã¢ã¯ã»ã¹ã«é¢ããŠãäŒç€ŸãçŽé¢ããŠããã¿ã¹ã¯ã解決ããå¿ èŠããããšããã«ããã®æ©èœã®äœ¿çšãéå§ã§ããŸãã
Windows Server 2012ãã¡ã€ã«ãµãŒããŒããã³æŽæ°ãããActive Directoryãã¡ã€ã³ã¹ããŒãã®ã»ãšãã©ã®ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡æ©èœã䜿çšã§ããŸãã æå°æ°ã®Windows Server 2012ãã¡ã€ã³ã³ã³ãããŒã©ãŒãè¿œå ãããšãã«ã¹ã¿ã èŠæ±ãªã©ãæå¹ã«ã§ããŸãã ã¢ããã°ã¬ãŒãããã·ã¹ãã ã®åéšåã«ã¯ãããå€ãã®ãªãã·ã§ã³ããããŸãããå®è£ ã®é床ãèšå®ããã®ã¯ããªã次第ã§ãã
![ç»å](https://habrastorage.org/getpro/habr/post_images/908/a27/f22/908a27f220aa3fc16c11faf6cc9847a4.jpg)
ããŒãããŒãœãªã¥ãŒã·ã§ã³
ããŒãããŒãœãªã¥ãŒã·ã§ã³ãšããŸããŸãªããžãã¹ã¢ããªã±ãŒã·ã§ã³ã«ãããWindowsã¢ã¯ã»ã¹ã®Dynamic Access Controlãžã®æè³ãæ¹åããActive Directoryã䜿çšããçµç¹ã«äŸ¡å€ãæäŸã§ããŸãã æšå¹Žã®äŒè°ã§çºè¡šãããããŒãããŒã·ãããœãªã¥ãŒã·ã§ã³ã®äŸã以äžã«ç€ºããŸãã
â¢ããŒã¿æŒæŽ©é²æ¢ã·ã¹ãã ãšèªåã³ã³ãã³ãåé¡ã·ã¹ãã ã®çµ±å
â¢éäžç£æ»ããŒã¿åæ
â¢äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã䜿çšããRights ManagementãµãŒãã¹ã®æ¿èª
â¢ä»ã®å€ãã®...
Technetçµç±