
*æ©å¯æ å ±ãæŒãã眪ã ããªãã®é»è©±ã¯ããªããèšãããšã ããèšããŸã... *
ååã ISãªã¹ã¯ç®¡çãã¬ãŒã ã¯ãŒã¯ã®éçºã«ç¹åããè³æã§ãã»ãŒ1幎åã«ç±³åœã§ISãä¿èšŒãããšããåé¡ãåãäžããŸããã ISãã¢ã¡ãªã«ã§ã©ã®ããã«æ§æãããŠãããã«ã€ããŠãããå°ã詳ãã話ããŸãã å°ãªããšãè«æã§ã¯ãå®å šã«è©å€ã®è¯ãçµç¹NISTãçºè¡ããŠããŸãã
çè«äžã®æ å ±ã»ãã¥ãªãã£ããããããã¹ããã©ã¯ãã£ã¹ã«ã€ããŠããã«è©³ãã説æããŸããããã¯ãã»ãšãã©ã®å®çšçãªã»ãã¥ãªãã£ã®å°é家ãç¥ã£ãŠããããã«ã人çã§ã¯ãã£ãã«ãããŸããã ãã ããããã¯ãå®éã®ISãµããŒãã·ã¹ãã ã®æ§ç¯ã«ãããéèŠæ§ãæãªããã®ã§ã¯ãããŸããã
èšäºã®ãã¹ãŠã®éšåãžã®ãªã³ã¯ïŒ
ã¢ã¡ãªã«åŒã®IBã ããŒã1. NIST 800-53ãšã¯äœã§ããïŒãŸããã»ãã¥ãªãã£ç®¡ççã¯ã©ã®ããã«èŠããŸããïŒ
ã¢ã¡ãªã«åŒã®IBã ããŒã2ããããŠãNIST 800-53ã«ã€ããŠè©³ãã説æããŠãã ããããªã¹ã¯ç®¡çã¯ã©ãã§è¡ããŸããïŒ
ã¢ã¡ãªã«åŒã®IBã ããŒã3.åºæ¬çãªã³ã³ãããŒã«ã»ãããšã¯äœã§ããïŒãŸããã·ã¹ãã ã®éèŠæ§ãå€æããæ¹æ³ã¯ïŒ
ã¢ã¡ãªã«åŒã®IBã ããŒã4.ãé©åããšãéè€ããç解ãããã®ã¬ãã¥ãŒãå®äºãã
ãªãã¢ã¡ãªã«
ç±³åœãå€ãã®åéã§ä»ã®å°åãããé²ãã§ããããšã¯ç§å¯ã§ã¯ãããŸããã ãã®å£°æã¯ããçšåºŠãæ å ±ã»ãã¥ãªãã£ã®åéã«é©çšãããŸãã
ãã®ãããæŽå²çã«ãã³ã³ãã¥ãŒã¿ãŒæè¡ã®ççºçãªæé·ãšæ®åãç±³åœã§çºçããŸããã ããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒã®æ®åãã€ã³ã¿ãŒãããã®åµé
æ¥çã®å é§è ã§ãããç¹å¥ãªãµãŒãã¹ãååã«çºéããŠããåœãšããŠãã¢ã¡ãªã«ã¯åžžã«ITã®åéã§ããããã£ãŠæ å ±ã»ãã¥ãªãã£ã®åéã§æ確ãªåªäœæ§ãæã£ãŠããŸãã ãããã£ãŠãããšãã°ãã³ã³ãã¥ãŒã¿ãŒã§åºã䜿çšãããããã«ãªã£ãå€æãã®æå·åã¢ã«ãŽãªãºã ã§ããïŒããšãã°ãDESæå·åã¢ã«ãŽãªãºã ã®ããŒã®é·ãã¯56ãããã§ããããå šäžçã®ã¢ã«ãŽãªãºã ã®ãšã¯ã¹ããŒãããŒãžã§ã³ã¯40ãããã«å¶éãããããŒãæã£ãŠãããããæããã«NSAã®å©çãäžååã§ããïŒ ã åãããšãåœå ã®æ å ±ã»ãã¥ãªãã£ããã»ã¹ã«ãåœãŠã¯ãŸããŸãã ç±³åœã§ã¯ãæ å ±ä¿è·ã«é¢ããéåžžã«æ·±å»ãªèŠä»¶ããããæ å ±ã»ãã¥ãªãã£ã«é¢ããå€ãã®èå³æ·±ãææžãéçºãããŠããŸãã
ãã¡ãããçµç¹èªäœãæ å ±ã»ãã¥ãªãã£ããŒã«ã®å°å ¥ã«æ©ãã§ãããšæ³å®ããããšãã§ããŸãããç«æ³ãå«ãåºæ¿ã¯ãèªåèªèº«ãšãã®å人ããŒã¿ãä¿è·ããããšããåœæ°ããã®å§åã«å ããŠãç¹å¥ãªãµãŒãã¹ãèŠå¶æ©é¢ããããããããŠããããã«æããŸãã
ãšããã§ã次ã®ç¹ã«æ³šæãæãããšã¯èå³æ·±ãã§ãïŒã¢ã¡ãªã«ã®å°é家ã«ãã£ãŠäœæãããæ å ±ã»ãã¥ãªãã£ææžã§ã¯ãçšèªãåœå®¶ãã¯å®åŒåã§å®æçã«äœ¿çšãããŠããŸãã åœå®¶ã ææžã¯ãç±³åœã®å©çãèæ ®ããŠæžãããŠããŸãã ããã¯ãå人ãçµç¹ãå·ã®å©çã«è¿œå ãããŸãã äžåºŠããã·ã¢ã®äººã ã®å©çã«é¢ããå ¬åŒææžã®èšåãã©ãã«ããã®ãèŠããŠããŸããã ããã«ã¡ã³ã¿ãªãã£ã«ã€ããŠã®ãããªå°ããªçºèšããããŸãã

* ITãã€ãŠã§ã€ã«ä¹ãåã«ãªã¹ã¯ã«ã€ããŠèããŠãã ããïŒ*
ç¹å¥åºçã³ãŒã53ã
次ã«ãç±³åœã®æ³åŸãçŸå®ãšã¯ç°ãªãæ¡ä»¶ã§ããããæãé©åãªææžã®1ã€ã«ã€ããŠã話ããŸãã
NIST-åœç«æšæºæè¡ç 究æã ããŸããŸãªãããã¯ã«é¢ããä¿¡ããããªãã»ã©ã®æ°ã®åºçç©ããããšããçç±ã§ãçå£ãªçµç¹ã NISTã®æ å ±ã»ãã¥ãªãã£ã«é¢ããåºçç©ã«ã€ããŠã¯ã800ãšããçªå·ã§ç¹å¥ãªã·ãªãŒãºãå²ãåœãŠãããŸããããã®ã·ãªãŒãºã§ã¯ãããŸããŸãªæ¹åã®å€ãã®ããã¥ã¡ã³ãããã§ã«æ瀺ãããŠããŸãã ããããããããã¹ãŠã®äžã§ãç§ã¯æãèå³æ·±ãããããŠç§ã®æèŠã§ã¯ãçŸå®ã®åºçç©NIST Special Publication 800-53ãé£éŠæ å ±ã·ã¹ãã ãšçµç¹ã®ããã®ã»ãã¥ãªãã£ãšãã©ã€ãã·ãŒç®¡çããžã®è¿äŒŒã匷調ããŸããã éèªçã«ç¿»èš³ãããšããé£éŠæ¿åºã®æ å ±ã·ã¹ãã ããã³çµç¹ã®ã»ãã¥ãªãã£ãšãã©ã€ãã·ãŒã®å¶åŸ¡ããåŸãããŸãã ãã®ããã¥ã¡ã³ãã¯ãã§ã«3ã€ã®æ¹èšçãä¹ãè¶ããŠãããçŸåš4ã€ã®ããŒãžã§ã³ã§æäŸãããŠããŸãã
ãã®ããã¥ã¡ã³ãã®æ¬è³ªã¯ãã»ãã¥ãªãã£ã³ã³ãããŒã«ãšãããããè³¢ã䜿çšããæ¹æ³ã«é¢ããæ瀺ã説æããããšã§ãã ããã¥ã¡ã³ãã¯éåžžã«èšå€§ã§ãããã³ã³ãããŒã«ã®èª¬æã«ã¯çŽ250ããŒãžãããããã®åèšæ°ã¯æ°çŸã§ããããšã«æ³šæããŠãã ããïŒã³ã³ãããŒã«ã®åŒ·åãèæ ®ããŸãããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãïŒ
åãISO 27001ãšæ¯èŒããŠãISOã¯ç¹å®ã®è£åæ段ã§ã¯ãªããIS管çã«ããéç¹ã眮ããŠãããããã»ãã¥ãªãã£ç®¡çã¯ã¯ããã«è©³çŽ°ãªè£åæ段ã§ãã

*å®å šãªçµã¿åãããããªãã§ã*
ã³ã³ãããŒã«ã®æŠèŠ
ããã¥ã¡ã³ãã¯éåžžã«ããæ§é åãããŠãããå€ãã®å®äŸãäœæ¥ãç°¡çŽ åãã䟿å©ãªããŒãã«ãªã©ããããŸãã ãã®ãã¹ãŠã¯ã1幎åãAndrei Prozorovã圌ã®ããã°ã§ FSTECãšNISTã®ææžãæ¯èŒããŠæžããŠããŸãã
åœç¶ãæšæºã®ãã¹ãŠã®ã³ã³ãããŒã«ã¯ãæ å ±ã»ãã¥ãªãã£ã®ããŸããŸãªé åã«å¯Ÿå¿ãããã¡ããªã«åå²ãããŸãã ãããã£ãŠãNISTã¯æ¬¡ã®ã³ã³ãããŒã«ãã¡ããªã§åäœããŸãïŒç¿»èš³ã¯ç§èªèº«ã®ãã®ã§ãããããç§ã責ããªãã§ãã ãããäžå¿ èŠãªæ··ä¹±ãåãé¿ããããã«ãå ã®ååã䜿çšããããšã奜ã¿ãŸãïŒã
Abbr | ã³ã³ãããŒã«ãã¡ããªãŒ | é©å¿ç¿»èš³ |
---|---|---|
AT | æèãšãã¬ãŒãã³ã° | æèãšãã¬ãŒãã³ã° |
Au | ç£æ»ãšèª¬æ責任 | ç£æ»ãšå ±å |
CA | ã»ãã¥ãªãã£ã®è©äŸ¡ãšæ¿èª | æ¿èªãšã»ãã¥ãªãã£è©äŸ¡ |
CM | æ§æ管ç | æ§æ管ç |
CP | ç·æ¥æèšç» | äºæ¥ç¶ç¶èšç» |
IA | èå¥ãšèªèšŒ | èªèšŒãšèªèšŒ |
IR | ã€ã³ã·ãã³ãå¯Ÿå¿ | ã€ã³ã·ãã³ãå¯Ÿå¿ |
MA | ã¡ã³ããã³ã¹ | ãµãŒãã¹/æè¡ãµããŒã |
MP | ã¡ãã£ã¢ä¿è· | ã¡ãã£ã¢ä¿è· |
PE | ç©ççããã³ç°å¢çä¿è· | çœå®³ä¿è·ãšç©ççã»ãã¥ãªã㣠|
PL | èšç»äž | èšç»äž |
PS | 人äºã»ãã¥ãªã㣠| ã¹ã¿ããã®å®å š |
RA | ãªã¹ã¯è©äŸ¡ | ãªã¹ã¯è©äŸ¡ |
SA | ã·ã¹ãã ããã³ãµãŒãã¹ã®ååŸ | ã·ã¹ãã ãšãµãŒãã¹ã®ååŸ |
SC | ã·ã¹ãã ãšéä¿¡ã®ä¿è· | ã·ã¹ãã ãšéä¿¡ã®ä¿è· |
SI | ã·ã¹ãã ãšæ å ±ã®æŽåæ§ | ã·ã¹ãã ãšæ å ±ã®æŽåæ§ |
ååŸ | ããã°ã©ã 管ç | æ å ±ã»ãã¥ãªãã£ç®¡ç |

*ã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã²ãŒã ããã¬ã€ããªãã§ãã ããïŒ*
ã»ãã¥ãªãã£å¶åŸ¡ãšã¯äœã§ããïŒ
ä»ãããã»ãã¥ãªãã£ã³ã³ãããŒã«ãšã¯äœãã«ã€ããŠè©±ãåããšãã§ãã 以äžã¯ãå¹³åãµã€ãºã®èª¬æãå«ãå žåçãªã³ã³ãããŒã«ã§ãã
AU-3ç£æ»èšé²ã®å 容
å¶åŸ¡ ïŒæ å ±ã·ã¹ãã ã¯ãçºçããã€ãã³ãã®ã¿ã€ããã€ãã³ãã®çºçææãã€ãã³ãã®çºçå Žæãã€ãã³ãã®ãœãŒã¹ãã€ãã³ãã®çµæãããã³é¢é£ããå人ãŸãã¯ãµããžã§ã¯ãã®IDã確ç«ããæ å ±ãå«ãç£æ»ã¬ã³ãŒããçæããŸãã€ãã³ãã
è£è¶³ã¬ã€ãã³ã¹ ïŒãã®å¶åŸ¡ã®èŠä»¶ãæºããããã«å¿ èŠãªç£æ»èšé²ã®å 容ã«ã¯ãããšãã°ãã¿ã€ã ã¹ã¿ã³ããéä¿¡å ããã³å®å ã¢ãã¬ã¹ããŠãŒã¶ãŒ/ããã»ã¹èå¥åãã€ãã³ãã®èª¬æãæå/倱æã®è¡šç€ºãé¢é£ãããã¡ã€ã«åãã¢ã¯ã»ã¹å¶åŸ¡ããŸãã¯åŒã³åºããããããŒå¶åŸ¡ã«ãŒã«ã ã€ãã³ãã®çµæã«ã¯ãã€ãã³ãã®æåãŸãã¯å€±æã®ã€ã³ãžã±ãŒã¿ãšã€ãã³ãåºæã®çµæïŒã€ãã³ãçºçåŸã®æ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ç¶æ ãªã©ïŒãå«ããããšãã§ããŸãã
é¢é£ã³ã³ãããŒã« ïŒAU-2ãAU-8ãAU-12ãSI-11ã
ã³ã³ãããŒã«ã®åŒ·å ïŒ
ïŒ1ïŒç£æ»èšé²ã®å 容| è¿œå ã®ç£æ»æ å ±
æ å ±ã·ã¹ãã ã¯ã次ã®è¿œå ãå«ãç£æ»ã¬ã³ãŒããçæããŸã
æ å ±ïŒ[å²ãåœãŠïŒçµç¹ãå®çŸ©ããè¿œå ã®è©³çŽ°æ å ±]ã
è£è¶³ã¬ã€ãã³ã¹ ïŒçµç¹ãç£æ»ã§èæ ®ããå¯èœæ§ã®ãã詳现æ å ±
èšé²ã«ã¯ãããšãã°ãç¹æš©ã³ãã³ããŸãã¯å人ã®å šæèšé²ãå«ãŸããŸã
ã°ã«ãŒãã¢ã«ãŠã³ããŠãŒã¶ãŒã®IDã çµç¹ã¯è¿œå ç£æ»ã®å¶éãæ€èšãã
ç¹å®ã®ç£æ»èŠä»¶ã«æ瀺çã«å¿ èŠãªæ å ±ã®ã¿ãžã®æ å ±ã ãã
å¯èœæ§ã®ããæ å ±ãå«ããªãããšã«ãããç£æ»èšŒè·¡ãšç£æ»ãã°ã®äœ¿çšãä¿é²ããŸã
æœåšçã«èª€è§£ãæãå¯èœæ§ãããããé¢å¿ã®ããæ å ±ãèŠã€ããããšãããå°é£ã«ãªãå¯èœæ§ããããŸãã
ïŒ2ïŒç£æ»èšé²ã®å 容| èšç»ãããç£æ»èšé²ã³ã³ãã³ãã®éäžç®¡ç
æ å ±ã·ã¹ãã ã¯ãã³ã³ãã³ãã®éäžç®¡çãšæ§æãæäŸããŸã
[å²ãåœãŠïŒçµç¹å®çŸ©ã®æ å ±ã«ãã£ãŠçæãããç£æ»ã¬ã³ãŒãã«ãã£ããã£ããã
ã·ã¹ãã ã³ã³ããŒãã³ã]ã
è£è¶³ã¬ã€ãã³ã¹ ïŒãã®å¶åŸ¡ã®åŒ·åã§ã¯ãã³ã³ãã³ãããã£ããã£ããå¿ èŠããããŸã
ç£æ»ã¬ã³ãŒãã§ã¯ãäžå€®ã®å Žæããæ§æããå¿ èŠããããŸãïŒèªååãå¿ èŠã§ãïŒã çµç¹
å¿ èŠãªç£æ»ã³ã³ãã³ãã®éžæã調æŽããŠãéäžç®¡çããµããŒããã
æ å ±ã·ã¹ãã ã«ãã£ãŠæäŸãããæ§ææ©èœã
é¢é£ã³ã³ãããŒã« ïŒAU-6ãAU-7ã
åç § ïŒãªãã
åªå é äœãšããŒã¹ã©ã€ã³ã®å²ãåœãŠ ïŒ
P1 äœã AU-3 MOD AU-3ïŒ1ïŒ é«ã AU-3ïŒ1ïŒïŒ2ïŒ
ã³ã³ãããŒã«ã®èª¬æã¯æ¬¡ã®ãã¿ãŒã³ã«åŸããŸãã
ãŸã第äžã«ãå¶åŸ¡ãã¡ããªãŒã®ã³ãŒããšçªå·ããããŸã-AU-3ã ã»ãã¥ãªãã£ã³ã³ãããŒã«ã®ååã¯æ¬¡ã®ãšããã§ãããç£æ»ã¬ã³ãŒãã®å 容ãã
ããã«ç¶ãã»ã¯ã·ã§ã³ã¯æ¬¡ã®ãšããã§ãã
- å¶åŸ¡ çµç¹ãŸãã¯ISã«ãã£ãŠå®è¡ãããã»ãã¥ãªãã£ã«é¢é£ããç¹å®ã®ã¢ã¯ã·ã§ã³ãŸãã¯ã¢ã¯ãã£ããã£ã®èª¬æã äžéšã®ã³ã³ãããŒã«ã«ã¯ãæè»ãªæ§æãªãã·ã§ã³ãçšæãããŠãããçµç¹ã«ã³ã³ãããŒã«ã«é¢é£ããããã€ãã®ãã©ã¡ãŒã¿ãŒã決å®ããæ©èœãæäŸããŸãã ããšãã°ããã®ãããªãã©ã¡ãŒã¿ã¯ãç£æ»ã®é »åºŠããã°ã®ä¿åæéããŸãã¯ãŠãŒã¶ãŒã®èªèšŒã«å€±æããåæ°ã§ãã ãããã£ãŠãçµç¹ã®ããžãã¹ç®æšããã®ã»ãã¥ãªãã£èŠä»¶ããªã¹ã¯è©äŸ¡ãšãªã¹ã¯å容æ§ã®çµæãããã³æ³åŸãšèŠå¶åœå±ã®èŠä»¶ã«åºã¥ããŠãç¹å®ã®ããŒãºã«åãããŠã³ã³ãããŒã«ã調æŽããããšãã§ããŸãã
- è£è¶³ã¬ã€ãã³ã¹ ã ç¹å®ã®ã³ã³ãããŒã«ã®è¿œå æ å ±ã ã³ã³ãããŒã«ã®å®è£ ãŸãã¯äœ¿çšãªã©ã«é¢ãã説ææ å ±ãå«ããããšãã§ããŸãã ä»ã®é¢é£ã³ã³ãããŒã«ãžã®ãªã³ã¯ãæäŸãããå ŽåããããŸãã
- ã³ã³ãããŒã«ã®æ©èœåŒ·å ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã³ã³ãããŒã«ã«æ©èœãè¿œå ããã匷åãããããŠãã³ã³ãããŒã«ããæ¹åãããå¯èœæ§ã瀺ããŸãã ã¡ã€ã³ãšçµã¿åãããŠã®ã¿äœ¿çšã§ããäžçš®ã®ã³ã³ãããŒã«ãå€æããŸãã ãã®äŸã§ã¯ãAU-3ïŒ1ïŒïŒ2ïŒã³ã³ãããŒã«ã¯å®éã«ç£æ»ã¬ã³ãŒããšãã®ãããªã¬ã³ãŒãã®åºæ¬æ§æãçæããå¿ èŠæ§ã決å®ããAU-3ã³ã³ãããŒã«èªäœã§æ§æããããå¢å¹ ãïŒ1ïŒèšé²ãããã€ãã³ããšãå¢å¹ ãã«é¢ããè¿œå æ å ±ã®ãªã¹ããä¿®æ£ããŸãïŒ2ïŒç£æ»èšé²ã®å 容ã®äžå 管çã®çµç¹ãèšè¿°ããã ã芧ã®ãšããããããã®æ¡åŒµæ©èœã¯ã³ã³ãããŒã«èªäœãªãã§ã¯å®è£ ã§ããŸããããããããåå¥ã®ã³ã³ãããŒã«ã«åããããšã¯åççã§ã¯ãããŸããã ãŸãããããã®æ¡åŒµæ©èœã¯ãããšãã°ãç£æ»ã¬ã³ãŒãã«å¿ èŠãªæ å ±ã®å®å šãªãªã¹ããå®çŸ©ããç£æ»ã¬ã³ãŒããäžå 管çããå¿ èŠãããIPã®ãªã¹ããå®çŸ©ããããšã«ãããçµç¹ã«æè»ãªæ§æãªãã·ã§ã³ãæäŸããããšã泚ç®ã«å€ããŸãã
- åç § ç«æ³ïŒåœç¶ã¢ã¡ãªã«ïŒãæšæºãèŠå¶èŠä»¶ãããŸããŸãªã¬ã€ãã©ã€ã³ãªã©ãžã®ãªã³ã¯ããããŸãã ç§ãã¡ã«ãšã£ãŠãããã¯ããå€ãã®èæ¯æ å ±ã§ãã
- åªå é äœãšããŒã¹ã©ã€ã³ã®å²ãåœãŠ ã ã©ãã«ã¯ãã³ã³ãããŒã«ã®å®è£ ã«é¢ããææ決å®ããã»ã¹ïŒäžèšã®äŸã§ã¯P1ïŒã§ã®æ³šææã«æšå¥šãããåªå é äœã«é¢ããæ å ±ãšãããŸããŸãªéèŠåºŠã®ã·ã¹ãã ã®åºæ¬ã»ããéã§ã®ã³ã³ãããŒã«ã®åæååžããã³ãã®ãå¢å¹ ãïŒããã«å°ãïŒã«ã€ããŠã®æ å ±ãæäŸããŸãã å®è£ ã®åªå 床ã«ãããçµç¹ã¯äž»ã«åºæ¬çãªå¯Ÿçãå®è£ ããããšã«ãããããå¹ççãã€ã¿ã€ã ãªãŒã«å¶åŸ¡ãå®è£ ã§ããŸãã

*äžéšã®å°é家ã¯èªåã®ç§å¯ãæãããªãã
ã»ãã¥ãªãã£ç®¡çã®çš®é¡
æ§é çã¢ãããŒããåçåãã確å®ã«ããããã«ãããã¥ã¡ã³ãã®äœæè ã¯ãç®çã«å¿ããŠãã³ã³ãããŒã«ãç°ãªãã¿ã€ãã«åé¢ããããšãæäŸããŸããã
- å
±é ããŸããŸãªã·ã¹ãã ã«ç¶æ¿ã§ããåäžã®IPã®ç¯å²ãè¶
ããŠåœ±é¿ãäžããããšãã§ããäž»ãªã³ã³ãããŒã«ã ãã®ISã§ã»ãã¥ãªãã£æ©èœãå®è¡ããå Žåãã·ã¹ãã ã¯ã»ãã¥ãªãã£å¶åŸ¡ãç¶æ¿ããŸããããã®ISã®å€éšã§éçºãå®è£
ãè©äŸ¡ãæ¿èªãããŸããã
- ã·ã¹ãã åºæ ã å¶åŸ¡ã¯ãç¹å®ã®IPã®ææè
ã®è²¬ä»»ã§ãã
- ãã€ããªãã å¶åŸ¡ã®äžéšã¯äžè¬çãªå¶åŸ¡ãšããŠæ©èœããäžéšã¯ã·ã¹ãã å¶åŸ¡ãšããŠæ©èœããŸãã ããšãã°ãIR-1ç£èŠã§ã¯ãçµç¹å
šäœã§ã€ã³ã·ãã³ãå
šäœã®å¯Ÿå¿ããªã·ãŒãå®çŸ©ã§ããŸãããåã
ã®ã·ã¹ãã ã«å¯ŸããŠç¹å®ã®å¯Ÿå¿æé ãå®çŸ©ãããŠããŸãã
ç¹å®ã®ç¶æ³ã§ã¯å®è£ ããã³è©äŸ¡ããã»ã¹ã®ã³ã¹ããåæžããçµç¹å šäœã®ã¢ãããŒãã®æŽåæ§ã確ä¿ã§ãããããèè ã¯ã³ã³ãããŒã«ãäžè¬ãæ··åãããã³äœç³»ã«åé¢ããŸãã ãã®è«çãœãªã¥ãŒã·ã§ã³ã«ãããããšãã°ãç¹å®ã®ã³ã³ãããŒã«ã«å¯Ÿãã責任ã決å®ããããã»ã¹ãç°¡çŽ åããã³ã³ãããŒã«ãå¹æçã«äœæ¥ãå®è¡ããé åã決å®ã§ããŸãã
ãããŠä»ãNIST 800-53ãšISO 27001ã®ç°¡åãªæ¯èŒ
ISO 27001èŠæ Œã¯ãã·ã¢ã®åºå€§ãã§ã¯ããã«åºãç¥ãããŠãããããããã»ãŒèª°ããèããããšãããã§ãããããã®ä»äºã¯å€ããå°ãªããæ å ±ã»ãã¥ãªãã£ã«å¯æ¥ã«é¢é£ããŠããŸãã ãã®èŠæ Œã¯ãæ å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ã®èŠä»¶ã説æããŠããŸãã ISOèŠæ Œã®äººæ°ïŒãŸãã¯äººæ°ïŒã®ãããNISTã®åé¡ã®ææžãšç°¡åã«æ¯èŒããŠãèªè ã«ããå°ãæ確ã«æ瀺ããŸãã
ãã ããå°é家ã®å ¬æ£ãªç°è°ãäºæ³ããŠãããã2ã€ã®æšæºãçŽæ¥æ¯èŒããããšããŠããããã§ã¯ãªãããšã«æ³šæããŠãã ãããããã§ã¯ãããŸããã ãããã¯ç°ãªãç®çã®ããã«æžãããŠããããããå察ã§ã¯ãªãäºãã«è£å®ããŠããŸãã ãã ããNISTã§æ瀺ããã詳现ã¯ç§°è³ã«å€ããŸãã
NIST SP 800-53ãšISO / IEC 27001ã®å®å šå¶åŸ¡ã®æ¯çãèŠèŠçã«æ¯èŒããããã«ããããã®èŠæ Œã®æºæ ã瀺ãè¡šã®2ã€ã®æçã以äžã«ç€ºããŸãã ïŒãã®è¡šã¯ææžNIST 800-53ããåãããŠããã2ã€ã®æšæºã®ã³ã³ãããŒã«ã®æ¯çã«ã€ããŠã®ç§ã®äž»èŠ³çãªå€æã®ååšãé€å€ããŠããŸãïŒã
è¡š1.å·ŠåŽãISO 27001ã³ã³ãããŒã«ãå³åŽãNIST 800-53ã®ã³ã³ãããŒã«ã§ã

è¡š2.éãããïŒ

ãããã®è¡šããæãããªããã«ãISOã³ã³ãããŒã«ã¯ããäžè¬çã§ãããNISTã®ããæ£ç¢ºã«å®åŒåãããã³ã³ãããŒã«ãããã€ãå«ãŸããŠããŸãã ãŸãã¯ããããå¥ã®æ¹æ³ã§å®åŒåãããšããã®è©³çŽ°ã®çµæãšããŠã1ã€ã®NISTã³ã³ãããŒã«ããé«ã¬ãã«ã®æ§è³ªã§ããããã€ãã®ISOã³ã³ãããŒã«ã§èª¬æãããŠããç®çãæããããšãã§ãããšçµè«ä»ããããšãã§ããŸãã ããŸãããã°ã説æããã®ã¯ããã»ã©é£ãããªãã ãããã®ãã¬ãŒãã®ã©ããç§ã«èªè ã«ä»»ããå察ã®çµè«ã§ããããšãã§ããããšããåé¡ã ãã®ãããªä»®å®ã¯ãã³ã³ãããŒã«ã®æšæºãšèª¬æããã£ãšèŠãŠãæ¶ããŠããŸãããã§ãã
ããã¯ãå žåçãªISO 27001ã»ãã¥ãªãã£ã³ã³ãããŒã«ã®å€èŠ³ã§ãããç¹ã«ãã³ã³ãããŒã«æ§é ã調æ»ãããµã³ãã«ãšããŠæäŸãããŠããAU-3ã³ã³ãããŒã«ãç£æ»èšé²ã®å 容ãã®ç¯å²ãã«ããŒããŠããŸãã ãã®èª¬æããäžèšã®NISTã³ã³ãããŒã«ã®ãã¹ãŠãšæ¯èŒããŠãã ããã

次ã¯äœã§ãã
次ã®èšäºã§ã¯ãNIST 800-53èŠæ Œã§æ瀺ãããŠããã»ãã¥ãªãã£å¶åŸ¡ãæäœããããã»ã¹ãç°¡åãªåœ¢åŒã§èª¬æããããšããŸãã
誰ãã圹ã«ç«ã€ããå°ãªããšãé¢çœããšæãããšãé¡ã£ãŠããŸãã