
æã¯éãªã
éèŠãªãµãŒããŒãããŒã¿ããŒã¹ãã¢ããªã±ãŒã·ã§ã³ã¯èšããŸã§ããªããã¢ã¯ãã£ããªä¿è·ããŒã«ã ãããåä¿¡ããã€ãã³ããã°ãå€æ°ãããŸãã ãããã®ãã°ã䜿çšããŠãäžæ£ã¢ã¯ã»ã¹ã®è©Šã¿ããããã¯ãŒã¯æ»æãããžãã¹ç¶ç¶æ§ã®äžæã«ã€ãªããç°åžžããŸãã¯ã»ãã¥ãªãã£ããªã·ãŒãç¹å®ã§ããŸãã ã€ãã³ããã°ãéãã«ã¯ãæéã®ãããäžé£ã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸããã¢ããªã±ãŒã·ã§ã³ãèµ·åããã³ã³ãœãŒã«ã«æ¥ç¶ããã€ãã³ãã®ãªã¹ãã衚瀺ããŠç¢ºèªããŸãã 1人ã®åŸæ¥å¡ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®ç£èŠïŒéäžç®¡çã³ã³ãœãŒã«ããããšä»®å®ïŒãæŽæ°ããã°ã©ã ãšIPSã®ã€ã³ã¹ããŒã«ïŒ2ã4å以äžãšä»®å®ïŒããããã®ãœãŒã¹ããã®ã€ãã³ãã®è¡šç€ºãããã³æçµæ¥ã«ã¯çŽ1æéããããŸãã 人çèŠå ã«æ³šæããŠãã ããïŒåœ¹å¡ã¯ä»ã®ã¿ã¹ã¯ã§éè² è·ã«ãªã£ãããç æ°ãäŒæäžã ã£ãããä»äºããæ°ãæ£ã£ããããããã©ãŒãã®ããã«ãããå®è¡ãããããå ŽåããããŸãã éèŠãªè³ç£ã®ã€ãã³ããã°ãå°ãªããšã1æ¥ã«1ååæããããã«å¿ èŠãªå·¥æ°ãæ°ããŸããïŒ ãããã®ã€ãã³ããã°ã§è åšãç¹å®ã§ããè³æ Œã®ããåŸæ¥å¡ã®è³éãèšç®ã§èæ ®ããé ãéä¿¡ãã£ãã«ãä»ããŠãã©ã³ãã®SZIã«æ¥ç¶ããã®ã«å¿ èŠãªæéãèæ ®ããŠãã ããã é«äŸ¡ïŒ ã¯ããããã¯ã©ãŠã³ããµã ã§ãããçµå¶é£ã«é»è©±ãããšããªãã£ã¹ããé²åºãããå¯èœæ§ãé«ããªããŸãã
ããã§ãããªãã¯ã»ãã¥ãªãã£æ©èœãã€ã³ã¹ããŒã«ããããããèšå®ãããããã¯æ©èœããŸã-ä»ã«äœãå¿ èŠã§ããïŒ SIEMã¯12人以äžã®äººã ã亀代ãããè¿ éã«åããæ絊ãèŠæ±ããŸããã
ããžãã¹ä¿è·
æ å ±ã»ãã¥ãªãã£ã®äž»ãªç®çã¯ãããžãã¹ã®ä¿è·ãšããžãã¹ããã»ã¹ã®ç¶ç¶æ§ã確ä¿ããããšã§ãã ããã«ã¯äœãå¿ èŠã§ããïŒ ããžãã¹ããã»ã¹ã®èª¬æãè³ç£ã®æ±ºå®ãç£æ»ã®å®è¡ïŒã¹ãã£ã³ãšãã³ãã¹ããå«ãïŒãäŸµå ¥è ã®ã¢ãã«ã®ã³ã³ãã€ã«ããªã¹ã¯ã®èª¿æ»ãããã³ããããæå°åããèšç»ã®çå®ãè¡ããŸãã ãªã¹ã¯ãæå°éã«æããããã«ã©ã®ãããªå¯ŸçãåãããŠããŸããïŒ ããªã·ãŒãäœæããããŠãŒã¶ãŒãã¬ãŒãã³ã°ãå®æœãããæ å ±ä¿è·ããŒã«ãã€ã³ã¹ããŒã«ãããæ§æãå€æŽãããæŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ãããŸãã 次ã®PDCAãµã€ã¯ã«ãŸã§ïŒ
ãã«ã¹ã«æã眮ããŠãã ãã
IBã®ãèšå®ããŠå¿ããããšããååã¯é©çšãããŸããã 絶察çãªä¿è·ã¯ãããŸããããããŠãæãããããããªããªã¹ã¯ã¯ãããžãã¹ã®åæ¢ãšå€§ããªééçæ倱ã䌎ããŸãã ãœãããŠã§ã¢ããã³ããŒããŠã§ã¢ã¯åäœãåæ¢ããããæ£ããæ§æãããŠããªãå¯èœæ§ããããè åšãã¹ãããããŸãã çŸä»£ã®èªç©ºæ©ã®ã³ã³ãããŒã«ããã«ãèŠãŸãããïŒ ãã¹ãŠã®éèŠãªææšã¯ã人éå·¥åŠãšåªå é äœã«åŸã£ãŠãŸãšããããŠããŸãã ãã€ããããšåœŒã®ã¢ã·ã¹ã¿ã³ãã¯ãé倧ãªã€ã³ãžã±ãŒã¿ãŒã®éåãèŠãã«ã¯ããããŸããã ãã®ãããSIEMã§ã¯ãããŒã¹ã©ã€ã³ãŸãã¯ããªã·ãŒïŒèªç©ºæ©ã®ã³ãŒã¹ïŒããéžè±ããå ŽåããŸãã¯æ éãè åšïŒèšåã®æ éïŒã«ããè³ç£ã®æ éãçºçããå Žåããã€ããããªãã¬ãŒã¿ãŒã«çŽã¡ã«éç¥ãããŸãã
ãªãããã«ã1æéåŸã«äœãèµ·ããã®ã§ããããïŒ ãŠã€ã«ã¹ã¯æ°ç§ã§åºãããæ»æè ã¯è匱æ§ãåæããŠæªçšããããã®èªåã·ã¹ãã ã䜿çšããŠããŸãã ããŒã¿ã®äžéšïŒãŸãã¯ãã¹ãŠïŒã倱ããããããåæ¥éçšäžã®ã·ã¹ãã ã§RAID RAIDã¢ã¬ã€ãçºçããå Žåãææ¥ã¯èå³ããããŸããã éç¥ãè¿ éã«è¡ãããã»ã©ã察çãè¿ éã«è¬ããããšãã§ããããžãã¹ãåããçµæžçæ倱ãå°ãªããªããŸãã ã€ã³ã·ãã³ããçµæããããããªãã£ãå Žåã¯è¯ãããšã§ãïŒé£è¡æ©ã«æ»ããŸãïŒããããã«ãŠã³ãã¢ããïŒæšæ¥1ã€ã®ãšã³ãžã³ã§ããªããã¢ã¹ã¯ã¯ã«é£ã³ãŸããïŒãïŒã
äºé²çä¿è·ãååšããªã
äžå åããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããå Žåããã¹ãŠã®å Žæã«ã€ã³ã¹ããŒã«ãããæ£ããæ§æãããçŸåšã®ããŒã¿ããŒã¹ã§åäœããããšã確èªããå¿ èŠããããŸãã ã©ããã£ãŠïŒ ã€ãã³ããã°ã䜿çšããŸãã
ãªãã§ïŒ äŒæ¥ã®ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ãšããŒã¿ããŒã¹ã®æŽæ°ãèªååãããšæ³åããŠãã ããã 2ã3æ¥ããšã«ã€ãã³ããã°ãç£æ»ããŸãããé害ãçºçãããµãŒãã¹ã¯ãŠã§ã¢ããŠã¹å ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®OSã§éå§ãããããããã¯ãŒã¯å šäœã«åºãããŠã€ã«ã¹ã«ææããŠããŸãã ããšãã°ããã¹ãŠã®ãµãŒããŒã§èªåå®è¡ãçŠæ¢ãããŠããŠããã¹ãŠã®ããããã€ã³ã¹ããŒã«ãããŠãããšããããšã¯çµ¶å¯Ÿã«ãããŸãããå®éã«ã¯ãããã¯ã»ãšãã©èµ·ãããŸããã èªåå®è¡ããã³ãããã¯ãŒã¯çµç±ã§ã®é åžã䌎ãè匱æ§ã䜿çšããŠèªåçã«é 眮ãããããã€ã®æšéŠ¬ããŸãã¯ãããã¯ãŒã¯å ±æäžã®åœé ãããã·ã§ãŒãã«ããã¯ãäŒç€Ÿå šäœã®åŽ©å£ã«ã€ãªãããŸãã ç·æ¥ã¢ãŒãã§äœãèµ·ãã£ãã®ããåæããéãããžãã¹ã¯ã»ãšãã©ã¢ã€ãã«ç¶æ ã«ãªããåœå±ã¯ç·åŒµããŠinããŸãã äŒæ¥ã®ããŠã³ã¿ã€ã ã«ããæ倱ã®è²¡åè©äŸ¡ã¯ãããã»ã©é£ãããªãã®ã§ãèªåã§ç°¡åã«è¡ãããšãã§ããŸãã ããã«ããã®ãããªå€±æã¯ããŒãã¹ãšçµŠäžã«æªåœ±é¿ãäžããåŸåããããŸãã
å¶åŸ¡ãããè åšãåãå ¥ãããããªã¹ã¯
å®éã«ã¯ãã»ãã¥ãªãã£ãããžãã¹ã«åããå ŽåããããŸãã æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããŠè匱æ§ã解決ã§ããªãå ŽåïŒèªèšŒãäžå®å®æ§ãããã¹ããããŠããªãããä»ã®ãœãããŠã§ã¢ãšã®ç«¶åãªã©ãå€ãã®çç±ããããŸãïŒããŸãã¯ãããšãã°ãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãæ©èœããªããªããããRPCãçŠæ¢ã§ããªãå ŽåããããŸãã è åšãæé€ããããã®ã³ã¹ãã¯æœåšçãªæ倱ãè¶ ããå¯èœæ§ãããããããªã¹ã¯ã¯ãåãå ¥ããããŸããã ãã ããSIEMã䜿çšããŠãã®ãããªãªã¹ã¯ãå¶åŸ¡ããã€ã³ã·ãã³ãã«å¯Ÿå¿ãã幎æ«ã«éçšãªã¹ã¯ãã«ããŒããããã«å²ãåœãŠãããè³éãäºç®ã«æ»ãããšãã§ããŸãã åœç¶ããã®å Žåããªã¹ã¯ã管çããæ¹æ³ãšããŠã€ã³ã·ãã³ããèªåçã«åæããã³èšé²ããããšãªãããªãã¬ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ã衚瀺ããããšã«çåã®äœå°ã¯ãããŸããã
çç±ãªã-誰ãã責任ããã
ãããããã€ã³ã·ãã³ãã解決ããããã®ããŒã¿ããªãå Žåã«ééããã§ããããæ£ç¢ºãªçºçæå»ãšçºçå ŽæïŒãŠãŒã¶ãŒããã®åŒã³åºãã¯ã«ãŠã³ãããŸããïŒãã€ã³ã·ãã³ãã®åã®æ å ±ã¯ãããŸããã ãããŠãç§ãã¡ã¯äž»ãªè³ªåã«çããããšãã§ããŸãã-äºä»¶ãçºçããçç±ãšèª°ã責任ãè² ãã¹ããã ããããããã¯å 害è ã眰ããããã«å¿ èŠã§ã¯ãããŸããïŒãã ãããããå¿ èŠãªå ŽåããããŸãïŒã ã€ã³ã·ãã³ãã«åºã¥ããŠæ確ã«ããå¿ èŠãããäž»ãªããšã¯ãã€ã³ã·ãã³ãã®åçºãé²ãããã«äœããã¹ããã§ãã ããã«ãOSïŒWindowsã€ãã³ããã°ãŸãã¯syslogïŒã«ãã°ã€ã³ããã ãã§ã¯äžååãªå ŽåããããŸãã
ç§ã¯ç¥ã§ã¯ãªããç§ã¯ãã ã®ã·ã¹ãã 管çè ã§ã
æçããåå²ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ã管çè æš©éã¯ããªãåºãç¯å²ã®åŸæ¥å¡ã«å§ä»»ãããŸãã åœç¶ãããããã¹ãŠã®åŸæ¥å¡ã¯ã»ãã¥ãªãã£ãã§ãã¯ãåããç§ãã¡ã¯ããããä¿¡é ŒããŠããŸãã ããããå®éã«ã¯ã人éã®å¿çåŠã¯ãã°ãã°åœ±é¿ãåãŒããŸãïŒããŒã¿ããŒã¹ãã¯ã©ãã·ã¥ãããåŸæ¥å¡RAIDã¯ãå人ã®ãã©ãã·ã¥ãã©ã€ãã«ãŠã€ã«ã¹ãæã¡èŸŒã¿ãŸãããã€ãã³ãã ãããã®éèªãæééãã«åéãããªãå Žåãããžãã¹ã¯çµæžçæ倱ãšè©å€ã®äœäžãšãã圢ã§æ害ãäžããããŸãã æééãã«åéããããªããžããªã«çµ±åãããã€ãã³ããã°ã¯ãã€ã³ã·ãã³ãã®çµæã«ã€ããŠæ£ããå€æãäžãã®ã«åœ¹ç«ã¡ãŸãã SIEMããããŒã¿ïŒã€ãã³ããšã€ã³ã·ãã³ãïŒãæ éã«åé€ããããšã¯ã§ããŸãããã¬ã³ãŒãã¯ã·ã¹ãã ãã°ã«æ®ããæŽåæ§ã®ç£èŠãå®è¡ãããŸãã SIEMã·ã¹ãã ã®ã€ãã³ããã°ã®åœ¢ã§ã®èšŒæ ã¯ãããªãã®çµç¹ãè£å€æã®åé¡ã解決ããã®ã«åœ¹ç«ã¡ãŸãã
ãã®ã¹ã¯ãªãããäœã§ããã誰ãç¥ã£ãŠããŸããïŒ..
ãã¡ããããèªå·±èšè¿°ãã·ããªãªã§ãã°ç®¡çãšäœããã®ã€ãã³ã管çãæ§ç¯ã§ããŸãã syslogãŸãã¯ãªãŒãã³ãœãŒã¹ãœãããŠã§ã¢ãä»ããŠãã°ãåéããŸãã PowerShellãããããã¡ã€ã«ãshã¹ã¯ãªãããããã³ã¬ããŒãã€ã³ã·ãã³ãã«é¢ãããã¹ãŠãé»åã¡ãŒã«ã§æŽçã§ããŸãã ãªããŠäŸ¿å©ã§å®ãïŒ
ã¯ããããã¯äžå°äŒæ¥ã«åãå ¥ããããŸãã é£è¡æ©ã®äŸã«æ»ããŸãã ããã·ã¥ããŒããããã¹ãŠã®ã€ã³ãžã±ãŒã¿ãŒãã¡ã³ã¿ã«çã«åé€ïŒãŸãã¯ååãæ¶å»ïŒãããšã©ãŒã¡ãã»ãŒãžãSMSãšé»åã¡ãŒã«ã§ãã€ãããã«éä¿¡ããŸãããã€ãããã¯ããã±ããã«æºåž¯é»è©±ãçªã£èŸŒãã§ãçä¿¡æåãæŽçããã®ã«ã©ãã»ã©æ©ãç²ããŸããïŒ
SIEMã·ã¹ãã ã«ã¯ãã³ã³ããŒãã³ãã®åäœãèªå·±èšºæããã³ç£èŠããæ©èœããããŸãã ãããã¯ãã¡ãã¡ã«æ£ãã°ããããããã¡ã€ã«ãã§ã¯ãªãããã®æŽåæ§ãšããã©ãŒãã³ã¹ãå¶åŸ¡ããã®ã¯éåžžã«å°é£ã§ãã ç°ãªãã·ããªãªã䜿çšããå Žåãã³ã³ãã³ãã®ãªãããŸããæå·åãããŠããªã圢åŒã®ç®¡çã¢ã«ãŠã³ãã®è¡šç€ºãã身ãå®ãããšã¯äºå®äžäžå¯èœã§ãã SIEMãšã¯ç°ãªããã€ãã³ãã®ç¶ç¶çãªåéãã³ã³ããŒãã³ãã®åäœã®å€±æãã·ã¹ãã æ©èœãžã®ã¢ã¯ã»ã¹ãªã©ã«ã€ããŠå ±åããå æ¬çãªã·ã¹ãã ã§ãã
éèŠãªè³ç£ã ãã§ãªãä¿è·
ããšãã°ãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãããŒã¿ããŒã¹ãªã©ãéèŠãªïŒããªãã®æèŠã§ã¯ïŒè³ç£ãä¿è·ããŠãããšããŸãã ãã¹ãŠãããŸããããç§ãã¡ã®èœåãæ倧éã«æŽ»çšããŠãéãè²»ããããã¯ãŒââã¯ã¹ããŒã·ã§ã³çšã®SISãšã¢ãã€ã«ãŠãŒã¶ãŒçšã®2èŠçŽ èªèšŒã®æ¬ åŠãç¯çŽããŸããã ãŠãŒã¶ãŒã¯ã°ã«ãŒãããªã·ãŒã«ãã£ãŠããã³ãããããŸãã 圌ãã¯ãã ããã£ãŒã«ãã®çãäžã«ããã¯ãç«ã£ãŠãããã¢ã絶察ã«ç¡å¹ã§ããããšãèæ ®ããŸããã§ããã æ»æè ã¯ãä¿è·ãããŠããªãã¯ãŒã¯ã¹ããŒã·ã§ã³ãŸãã¯ã¢ãã€ã«ããã€ã¹ãããŠãŒã¶ãŒããã³ç®¡çã¢ã«ãŠã³ããååŸããã¹ãŒããŒä¿è·ãããããŒã¿ããŒã¹ãžã®å®å šã«æ£åœãªãªã¯ãšã¹ãã«ãããå¯èœãªãã¹ãŠããåŒãåºãããŸãã ç Žå£çãªè¡åã¯æããæ代é ãã§ããã ãã¥ãŒã¹ããã®æ å ±æŒæŽ©ã«ã€ããŠåŠã³ãŸããé©ããããšã«ããã¹ãŠã®ãµãŒããŒã確å®ã«ä¿è·ãããŸããã ããã¯å žåçãªAPTæ»æã®äŸã§ãã å®è¡äžã®ããã»ã¹ãOSã®æ°ããã©ã€ãã©ãªãæ°ãããµãŒãã¹ãéããŠããããŒããšæ¥ç¶ãç¹æš©ã®ææ Œ-ãããã¯ãã¹ãŠãããªãã®æèŠã§ã¯éèŠãªè³ç£ã§ã¯ãªãã£ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ã€ãã³ããã°ã§ç¢ºèªã§ããŸã...
ä¿è·ã¯å æ¬çãªãã®ã§ãªããã°ãªããŸããã ããã®èšŒæ ã¯Bit9ãšRSAã®äºä»¶ã§ãããäœããã®çç±ã§åœŒããéçºããä¿è·ãèªåã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«çœ®ããªãã£ãã
èŠèŽåæ°
ã»ãã¥ãªãã£ããŒã«ã¯éåžžã眲åããŒã¹ã§ããã€ãŸããæ¢ç¥ã®è åšïŒãŠã€ã«ã¹ããããã¯ãŒã¯æ»æãDLPã®èŸæžãªã©ïŒã®åæã«åºã¥ããŠäœæãããŸãã æ°çŸäžã®ã€ãã³ããšææšãããã³ããŒã¹ã©ã€ã³åæã«åºã¥ããŠãè€éãªçžé¢ã¢ã«ãŽãªãºã ïŒRBRçžé¢ã«ã€ããŠ- ããã°ã®èšäºãåç §ããŠãã ãã-ããã§ã®è³ªåã¯ãããŸããïŒã䜿çšããã ãã§ãæ°ããè åšãèå¥ã§ããŸãã 人éã®è³ã¯ããã®ãããªå€§éã®ããŒã¿ãåžžã«å æ¬çã«åæã§ãããšã¯éããŸããã ãã ããSIEMã·ã¹ãã ã§ã®è¡šçŸã®æœè±¡åã¯ããªãã¬ãŒã¿ãŒã«ããè åšã®ã¿ã€ã ãªãŒãªæ€åºã«è²¢ç®ããŸãã ã·ã¹ãã ã¯ãã¹ãŠã®äºåèšç®ãè¡ããã€ã³ãžã±ãŒã¿ã衚瀺ããŸãã ããšãã°ãããŒã¹ã©ã€ã³ã®åæã«åºã¥ããŠãã·ã¹ãã ã¯æ°ããDynDNSãã©ãã£ãã¯ãå°ãªããšãå ±åãããã¡ã€ã³ç®¡çè ã«ä»£ãã£ãŠããŸããŸãªè³ç£ããã®ãã°ã€ã³è©Šè¡ã10å倱æããããšã瀺ããŸãã éåžžãã·ã¹ãã ã¯ããã€ã®æšéŠ¬ãŸãã¯ãã«ãŒããã©ãŒã¹ãå ±åã§ããŸãïŒçžé¢ã«ãŒã«ã®æ§æãšç¹å®ã®ã·ã¹ãã ã®æ©èœã«å¿ããŠïŒã ããè€éãªçžé¢ã¢ã«ãŽãªãºã ã䜿çšãããšãã€ã³ã·ãã³ãã®åå ãèŠã€ããããšãã§ããŸãïŒããšãã°ããŠãŒã¶ãŒã«æ¥ç¶ããŠããã¢ãã ãç¹å®ããããã€ã®æšéŠ¬ãšãã«ãŒããã©ãŒã¹ã«ææããïŒã äœçŸäžãã®ããã¹ãã€ãã³ãã«åºã¥ããŠããã®ãããªåæãç¬ç«ããŠå®è¡ããäœè£ã¯ãããŸããã èŠèŠåããã«ãæ§æããæ©èœã¯ãåã ã®åŸæ¥å¡ãšãSOCïŒã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒïŒã®éçšãããã³ITããã³æè¡ãµããŒãéšéã®äž¡æ¹ã«åœ¹ç«ã¡ãŸãã
ã³ã³ãã©ã€ã¢ã³ã¹
å€ãã®å°åãåœéãåœå ãããã³æ¥çæšæºã«ã¯ããžã£ãŒãã«ã®ç®¡çãçµç¹åããããã®èŠä»¶ãââãããŸãã ãã¹ãŠã®SIEMã·ã¹ãã ã«ã¯ãåœéæšæºãæºãããã³ãã¬ãŒãããããç¬èªã®ãã³ãã¬ãŒããè¿œå ããŠãã€ãã³ãã®åéãšä¿åã«é¢ããã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒããçæããæ©èœããããŸãã èªå®¶è£œã®ã·ã¹ãã ã®å Žåãã¬ããŒããç£æ»äººåãã®ã€ã³ã¿ãŒãã§ãŒã¹ã®åœ¢åŒã§ãã®ãããªãã³ãã¬ãŒããäœæããã«ã¯ãããªãã®ãªãœãŒã¹ãè²»ããå¿ èŠããããŸãã
ã¢ã¯ã»ã³ã
ã€ã³ã·ãã³ãã«å¯Ÿããäžé©åãªå¯Ÿå¿ã¯ ãäžæ£ãªä¿¡å·æ©ã®åäœã«å¹æµããŸãã ISããã³ITéšéã¯ãããžãã¹ããã»ã¹ã確ä¿ãããšããäž»èŠãªã¿ã¹ã¯ã解決ã§ããŸããã SIEMã«ã¯ãã€ã³ã·ãã³ãç»é²ããã»ã¹ãç·šæããããã«æäœéå¿ èŠãªããŒã«ãããïŒãŸãã¯ãµããŒããµãŒãã¹ãšçµ±åããæ©èœããããŸãïŒãã€ã³ã·ãã³ã解決ã®å¶åŸ¡ãšãã¬ããžããŒã¹ã®èç©ã«åœ¹ç«ã¡ãŸãã SIEMã«ã¯ãããžãã¹ããã»ã¹ãè³ç£ã®äŸ¡å€ãè åšã®å±éºæ§ãžã®åœ±é¿ã«å¿ããŠãã€ã³ã·ãã³ããçµ±åããã³åªå é äœä»ãããæ©èœããããŸãã äžéšã®ã·ã¹ãã ã§ã¯ããªã¹ã¯ç®¡çã·ã¹ãã ãšã®çµ±åãå¯èœã§ãã
SIEMã¯ãISéšéã察å¿ããæéããªãã ãã®å€æ°ã®ã€ã³ã·ãã³ããçæãããšãã誀解ããããŸãã SIEMã¯ããã«äœ¿ãããœãªã¥ãŒã·ã§ã³ã§ã¯ãªããDLPã·ã¹ãã ã®å Žåã®ããã«ãé©åãªå®è£ ãã€ãã³ããœãŒã¹ãšã®çµ±åãã¢ã¯ãã£ããªã«ãŒã«ã»ãããšçžé¢ã¢ã«ãŽãªãºã ãžã®åå¥ã®ã¢ãããŒããå¿ èŠã§ããããšãç解ããå¿ èŠããããŸãã æè»ãªäŸå€ã·ã¹ãã ãšæ£ããSIEMæ§æã«ãããéèŠãªã€ãã³ãã«ã®ã¿éç¹ã眮ãããšãä¿èšŒãããŸã-ãã©ããã£ã³ã°ã¯ãããŸããã
ã€ãã³ããå ±æãã
SIEMã¯æ å ±ã»ãã¥ãªãã£ã®ããã ãã®ã·ã¹ãã ã§ã¯ãããŸããã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããããã¯ãŒã¯æ©åšããœãããŠã§ã¢ã®ãšã©ãŒãšé害-ITéšéã®ã¹ã¿ããã¯ããã¹ãŠã®æ å ±ãSIEMããååŸã§ããŸãã ITéšéã¯ããŠãŒã¶ãŒã®é»è©±ã§ã¯ãªããäºåã«ïŒç¹ã«ISã€ã³ã·ãã³ãã®ããã«ITã€ã³ã·ãã³ããé²æ¢ã§ããããïŒã€ã³ã·ãã³ãã«ã€ããŠãç¥ããããšèããŠããŸãã
SIEMã¯éèªç®¡çããã»ã¹ã®éåžžã«åçŽãªãœãªã¥ãŒã·ã§ã³ã§ã¯ãããŸããããŸããäžå°äŒæ¥ã§ã®å®è£ ã¯éåžžã«é«äŸ¡ã§ãã ãã®éçšã«ã¯ãã€ãã³ãåéã®ç¶ç¶æ§ãå¶åŸ¡ããçžé¢ã«ãŒã«ã管çããæ°ããè åšã®åºçŸã«åãããŠã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã«å¿ããŠãããã調æŽããã³æŽæ°ããæè³æ Œã®åŸæ¥å¡ãå°ãªããšã1äººå¿ èŠã§ãã SIEMãããã©ãã¯ããã¯ã¹ããšããŠèšå®ããé©åãªç£èŠãšå¶åŸ¡ãè¡ããã«äºåå®çŸ©ããããã¹ãŠã®çžé¢ã«ãŒã«ãæå¹ã«ãããšãäºç®ãç¡é§ã«ãªããŸãã
å®è£ ãæåãããšã次ã®ãã®ãåãåããŸãã
- ITããã³æ å ±ã»ãã¥ãªãã£ã€ãã³ããšããã»ã¹ãããžãã¹ã«äžãã圱é¿ã®çžé¢ãšè©äŸ¡ã
- ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç¶æ³ããªã¢ã«ã¿ã€ã ã§åæããSOCã
- è åšãšç°åžžãæ€åºããããã»ã¹ã®èªååã
- ã€ã³ã·ãã³ãç»é²ããã³å¶åŸ¡ããã»ã¹ã®èªååã
- ã³ã³ãã©ã€ã¢ã³ã¹ã管çãå ±åã®ããªã·ãŒãšåºæºã®ç£æ»ã
- ããžãã¹ããã»ã¹ã«å¯Ÿããè åšã®åœ±é¿ã«å¿ããŠåªå é äœä»ããè¡ããæ°ããªISããã³ITã®è åšã«å¯Ÿããæ£ãã察å¿ãææžåããã
- ãã£ãšåã«çºçãããã®ãå«ãã€ã³ã·ãã³ããšç°åžžã調æ»ããå¯èœæ§ã
- 蚎èšã®èšŒæ ããŒã¹ã
- ã¬ããŒããšææšïŒKPIãROIãã€ãã³ã管çãè匱æ§ç®¡çïŒã
SIEMãããžãã¹ã®ç¶ç¶æ§ã®ç¢ºä¿ãå¹çã®åäžãåé¡ãã€ã³ã·ãã³ãã®è§£æ±ºã«ã©ã®ããã«åœ¹ç«ã€ãã«ã€ããŠãã»ãã®ããã€ãã®äŸãæããŸããã ããã§ããèªååãåå¿ïŒã·ããªãªïŒãã€ã³ã·ãã³ãã®é²æ¢ãããã³ãããã®èª¿æ»ã«ã€ããŠå€ããæžãããšãã§ããŸãã ããã«ã€ããŠã¯ã次ã®åºçç©ã§èª¬æããŸãã ãããšã¯å¥ã«ãSIEMã䜿çšããŠããžãã¹ãžã®ITããã³æ å ±ã»ãã¥ãªãã£ã€ãã³ãã®åœ±é¿ã远跡ããæ¹æ³ã®å€ããå¿é ããéåžžã«éèŠãªãã€ã³ããæ€èšããŸãã
ããããïŒ è³ªåãã³ã¡ã³ããåŸ ã£ãŠããŸãã
ããžãã£ããªãµãŒãã»ã³ã¿ãŒããªã¬ã·ã¢ã·ã§ã¬ã¹ãã