ãã®èšäºã§ã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ïŒISïŒã®èŠä»¶ãäœç³»åããŸãã èŠä»¶ã¯ãäž»ã«
NIST SP 800-82ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ïŒICSïŒã»ãã¥ãªãã£ã®ã¬ã€ããããã³
ISA / IEC 62443ã·ãªãŒãºãç£æ¥çšãªãŒãã¡ãŒã·ã§ã³ããã³å¶åŸ¡ã·ã¹ãã ã® ã»ãã¥ãªãã£ãã®æ°ããæ¹èšçãããçŸåšå©çšå¯èœãªæšæºããéžæãããŸãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã¯ãç©çäžçã®ãªããžã§ã¯ããšçžäºäœçšããäºæ
ãçœå®³ããã®ä¿è·ãæäŸããŸãã è±èªã®æç®ã§ã¯ãããã»ã¹å¶åŸ¡ã·ã¹ãã ã¯ç£æ¥å¶åŸ¡ã·ã¹ãã ïŒICSïŒãŸãã¯ç£æ¥ãªãŒãã¡ãŒã·ã§ã³ããã³å¶åŸ¡ã·ã¹ãã ïŒIACSïŒãšåŒã°ããŠããŸãã ITãã¯ãããžãŒã®äžçã§ã¯ããã³ã»ãããŒããšæ¯èŒããããšãã§ããŸãããã³ã»ãããŒãã¯ãé·ãå€åããäžçã«ãããŠãã·ã³ãã«ã§ãããªããããŸãæµè¡ããŠããªãååã«å¿ å®ã§ããã
ãããã£ãŠãæ©èœçå®å
šæ§ãšã®é¡äŒŒæ§ãåŒãåºãããäžé£ã®èŠä»¶ãæ€èšãããŸãããããã«ãããæ©èœçããã³æ
å ±çãªç£æ¥å¶åŸ¡ã·ã¹ãã ã®å®å
šæ§ã®äž¡åŽã確ä¿ãããŸãã
IoTãçµã¿èŸŒã¿å¶åŸ¡ã·ã¹ãã ãªã©ãä»ã®ãµã€ããŒç©çã·ã¹ãã ã§ãåæ§ã®åé¡ã«å¯ŸåŠããå¿
èŠããããŸãã
ããã»ã¹å¶åŸ¡ã·ã¹ãã ãšä»ã®æ
å ±ïŒITïŒã·ã¹ãã ã®éãã¯äœã§ããïŒ
æ
å ±ã»ãã¥ãªãã£ã®åé¡ãæ€èšããåã«ãICSã®ä¿è·ãšã»ãã¥ãªãã£ã®åé¡ãä»ã®ITã®å
šäžçãšã¯å¥ã«æ€èšããå¿
èŠãããããšãæåã«ç解ããŠãããšããã§ãããã
ãã®è³ªåã«çããåªããæ¯èŒåæã¯ãåè¿°ã®NIST SP 800-82ã«å«ãŸããŠããŸãã 以äžã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ãšæœè±¡çãªæ
å ±ã·ã¹ãã ïŒITã·ã¹ãã ïŒã®æ¯èŒç¹æ§ãåãããã®ææžã®äžéšã§ãã ããã€ãã®ç¹ã§è°è«ããããšãã§ããŸãããããŒãã«ã¯å¯èœãªå·®ç°ã«å¯èœãªéãéäžããããšããããšãèŠããŠããå¿
èŠããããŸãããããã¯ç¹å®ã®æ
å ±ã·ã¹ãã ã«åºæã§ã¯ãªãå¯èœæ§ããããŸãïŒããšãã°ãéè¡ã·ã¹ãã ã§ã¯ãå¯çšæ§ãšã¢ã¯ã»ã¹ã®é床ãéèŠã§ãïŒ ïŒ
æ
å ±ïŒITïŒã·ã¹ãã ãšç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ¯èŒåæ
ããã§ã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ã®åé¡ã¯äœã§ããïŒ
æ
å ±ã»ãã¥ãªãã£èªäœãåé¡ã§ãããšããäºå®ã«å ããŠãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®åéã®ç¶æ³ã«ã¯ãããã€ãã®èŠå ãååšãããããç¬èªã®ç¹æ§ããããŸãã
å€ãã®å ŽåãISã®ãã¹ãŠã®ã¡ã³ããã³ã¹ã¯ãIS管çã·ã¹ãã ïŒISMSïŒã®èæ
®ãŸã§åæžãããŸãããICSã®ISããããžã§ãã³ã°ã«ã¯ISMSãå¿
èŠã§ãããååãªæ¡ä»¶ã§ã¯ãããŸããã ããã«ãISèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®ç®¡çã§ã¯ã1ïŒäŒæ¥ã2ïŒäžé£ã®èªåå¶åŸ¡ã·ã¹ãã ã®éçºãšéçšã®ããã®ããã°ã©ã ã3ïŒåäžã®èªåå¶åŸ¡ã·ã¹ãã ã®3ã€ã®ã¬ãã«ãèæ
®ããå¿
èŠããããŸãã ããã¯åžžã«èšæ¶ãããŠããããã§ã¯ãããŸãããèªååãããããã»ã¹å¶åŸ¡ã·ã¹ãã ã®æè¡å¯Ÿè±¡ãšããŠãISMSã®ãã¹ãŠã®èŠä»¶ãæºããããšããŠæ©èœçããã³æè¡çç¹æ§ãèŠéãããšãããšãæŠå¿µã眮ãæããããŸãã
ãŸããæ
å ±ã»ãã¥ãªãã£ã¯ããã€ãã¯ã®èŠ³ç¹ããã®ã¿ãããã©ãã¯ãã€ãããŒã·ã§ã³ïŒStuxnetãBlackEnergyãªã©ïŒã®ã¹ããªãŒã ãšããŠèæ
®ãããããã«å¿ããŠããããããä¿è·ããããã®ç¹å®ã®å¯Ÿçã®ã»ãããšèŠãªãããããšããããŸãã
ããã«ãããããããçµç¹çããã³æè¡çæ段ãå«ãäœç³»çãªã¢ãããŒãïŒã人-ããã»ã¹-æè¡ãã®3ã€çµïŒã¯åççã§ãã
ãã1ã€ã®ãã€ã³ãã¯ãéå»5ã10幎ã«ãããéªåŽ©ã®å¢å ãæ
å ±ã»ãã¥ãªãã£ã®åéã«ãããæšæºã®æ°ã§ãã å€ãã®æšæºãç©æ¥µçã«æ¹è¯ããã³æ¡åŒµãããŠãããèŠä»¶ã«æ··ä¹±ãçããŠããŸãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã«é¢ããæšæºãæè¡ææžãããã³ããããåç
§ããæ
å ±æºãèæ
®ã«å
¥ããããšããŸããã 次ã®åºç¯ãªãªã¹ããååŸãããŸããã
-ISO / IEC 27000ã·ãªãŒãºãæ
å ±æè¡-ã»ãã¥ãªãã£æè¡-æ
å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ãã¯èª°ããããç¥ã£ãŠãããããã§äœåºŠãè°è«ãããŠããŸãããæšæºã¯ãã·ã¢èªã«ç¿»èš³ãã
ãGOST RãšããŠåãå
¥ããããŠããŸãã
-ISO / IEC 15408ã®3ã€ã®éšåãæ
å ±æè¡-ã»ãã¥ãªãã£æè¡-ITã»ãã¥ãªãã£ã®è©äŸ¡åºæºããŸãã¯ãããããå
±éåºæºãããã·ã¢èªã«ç¿»èš³ãã
ãGOST RãšããŠåãå
¥ããããŠããŸãã
-äžé£ã®èŠæ ŒISA / IEC 62443ãç£æ¥ãªãŒãã¡ãŒã·ã§ã³ããã³å¶åŸ¡ã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãããã®æšæºã¯æ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®ãçŸç§äºå
žãã§ãããããæã泚æãæãå¿
èŠããããŸãã åçã¯ã2000幎代ã«åœéèªåååäŒïŒISAïŒã«ãã£ãŠéçºããããã®åŸãåœéé»æ°æšæºäŒè°ïŒIECãè±èªã®IECïŒã«ãã£ãŠæšæºãšããŠæ¡çšãããŸããã ãã·ã¢é£éŠã§ã¯ã62433ã®äžéšã
GOST RãšããŠåãå
¥ããããŠããŸãã ISAã¯çŸåš62433ã®æ¬¡ã®ãšãã£ã·ã§ã³ãéçºããŠããŸãã éçºã¯äºå®ããé
ããŠããŸãããä»
èªãã§ããã¹ãããšããããŸãã äžã®å³ã¯ãèšç»ãããŠããISA / IEC 62443ã·ãªãŒãºã®æ§é ã瀺ããŠããŸãã
å³1. ISA / IEC 62443ã·ãªãŒãºã®æšæºã®æ§é ã
-æ
å ±ã»ãã¥ãªãã£ã®ãããã¯ã«é¢ããç±³åœåœç«æšæºæè¡ç 究æïŒNISTïŒã®åºçç©ã«ã¯ã
SP 500ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã
SP 800ã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªã㣠ã
SP 1800ãµã€ããŒã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ã¬ã€ãã® 3ã€ã®ã·ãªãŒãºãå«ãŸã
ãŸã ã NISTã¯ç¬èªã®ISMSïŒ
NIST SP 800-53ãé£éŠæ
å ±ã·ã¹ãã ããã³çµç¹åãã®ã»ãã¥ãªãã£ããã³ãã©ã€ãã·ãŒç®¡çã ïŒã
ããã³ ãµã€ããŒã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯ïŒSCFïŒãéçºããŸãã ã ããããç§ãã¡ã¯
NIST SP 800-82ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ïŒICSïŒã»ãã¥ãªãã£ã®ã¬ã€ããã«æãé¢å¿ãæã£ãŠããŸãã
-äž»ã«ãšãã«ã®ãŒã·ã¹ãã ã«é¢é£ããäžè¬ã¿ã€ãã«ãéèŠã€ã³ãã©ä¿è·ïŒSIPïŒãã®äžã®
åç±³é»æ°ä¿¡é Œæ§å
¬ç€ŸïŒNERCïŒã®åºçç©ã
-ãšãã«ã®ãŒçïŒDOEïŒãéçºãã
ãµã€ããŒã»ãã¥ãªãã£æ©èœæç床ã¢ãã«ïŒC2M2 ïŒã
-åœåå®å
šä¿éçDHSã®äžéšã§ãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ãµã€ããŒç·æ¥å¯Ÿå¿ããŒã ïŒICS-CERTïŒãéçºããæšå¥šãã©ã¯ãã£ã¹ ã
-åœéå°é家åäŒISACAã«ãã£ãŠéçºããã
æ
å ±ããã³é¢é£æè¡ã®ãã¬ãŒã ã¯ãŒã¯
å¶åŸ¡ç®æšïŒCOBITïŒ ã
-Center for Internet Securityãéçºãã
å¹æçãªãµã€ããŒé²åŸ¡ã®ããã®éèŠãªã»ãã¥ãªãã£ã³ã³ãããŒã«ïŒCIS CSCïŒãã¬ãŒã ã¯ãŒã¯ã
-åã
ã®ç£æ¥éšéåãã«éçºãããæšæºãããšãã°ãAmerican Gas AssociationïŒAGAïŒã®AGA 12ã·ãªãŒãºãAmerican Petroleum InstituteïŒAPIïŒã®APIã¬ã€ã1164ãåååçºé»æã§äœ¿çšãããIEC 62645æšæºãNuclear power plant-Instrumentation and controlãããªã¹ãã§ããŸãã·ã¹ãã -ãµã€ããŒã»ãã¥ãªãã£èŠä»¶ããªã©
ãããã£ãŠãå€ãã®æšæºãããããããã¯ãã¹ãŠæ
å ±ã»ãã¥ãªãã£ã®äž»é¡ãè¡šããåãããšã«ã€ããŠè©±ããŸããããã°ãã°ç°ãªãèšèã§è©±ããŸãã èŠä»¶ã調æŽããã¿ã¹ã¯ã¯ã次ã®ã»ã¯ã·ã§ã³ã§è§£æ±ºããŸãã ç¶æ³ãããããæããããè¯ããã¥ãŒã¹ã1ã€ãããŸãã æ
å ±ã»ãã¥ãªãã£ã®åéãç¹ã«æ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®åéã®ã»ãŒãã¹ãŠã®æšæºããã³æè¡ææžã¯ãç解ããããæè¡èšèªã§æžãããŠããŸãã ãã®ç¹ã§ããããã¯ãããšãã°
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ©èœå®å
šæ§ã®ç¹ã§ãä»ã®æšæºãšæ¯èŒããŠæå©
ã§ã ã
ããã§ãã1ã€ã®çåãæ®ããŸããæ
å ±ã»ãã¥ãªãã£ã®èŠä»¶ãš
æ©èœã»ãã¥ãªãã£ïŒFBïŒã®èŠä»¶ãã©ã®ããã«çµã¿åããããã åŸè
ã¯ãããã»ã¹å¶åŸ¡ã·ã¹ãã ãæœåšçã«å±éºãªç©çãªããžã§ã¯ãã管çãããšããç¹ã§éèŠã§ããããããäž»ãªãªã¹ã¯ã®ããå Žæã§ãã
æ
å ±ã»ãã¥ãªãã£ã®å°é家ãICSã®è©³çŽ°ãååã«ç解ããŠããªãå ŽåããããŸããã€ãŸããã·ã¹ãã ãæ»æãããªããã°ãåé¡ã¯ãããŸããã ããããè
åšãšãªã¹ã¯ã¯äŸµå
¥è
ããã ãã§ãªããç¡èœãªäººå¡ãæ©åšã®æ
éãç°å¢ã®åœ±é¿ãããçºçããŸãã ãããŠããããã®åé¡ã¯ãä¿¡é Œæ§ã確ä¿ããã©ã€ããµã€ã¯ã«ããã»ã¹ã管çããæ¹æ³ãé©çšããããšã«ãããFBã®æ çµã¿å
ã§é·ãé解決ãããŠããŸããã
ãŸãããä¿¡é Œã§ããã人ãã»ãã¥ãªãã£ã«æççã§ããããµã€ããŒè
åšã«ç¹å¥ãªåé¡ã¯èŠãããªãããšãäºå®ã§ãã ã»ãã¥ãªãã£ã·ã¹ãã ïŒç·æ¥ä¿è·ãPAZïŒã¯ãã©ã€ã»ã³ã¹ãšèªèšŒã«å€å€§ãªã³ã¹ããå¿
èŠãšãããããéåžžã«ä¿å®çã§ãã ããšãã°ãåååçºé»æã®å Žåãã©ã€ã»ã³ã¹è²»çšã¯ãããžã§ã¯ãè²»çšã®æ倧10ïŒ
ã«ãªããŸãã
ã ãããåªåãšç¥èã®åŠéçãªçµ±å以å€ã«æ¹æ³ã¯ãããŸããã æ
å ±ã»ãã¥ãªãã£ãšè²¡åã»ãã¥ãªãã£ã®èŠä»¶ã®èª¿åã«ã€ããŠããæ¬æžã®åŸåã§èª¬æããŸãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£èŠä»¶ã®å
šäœå
èãããããªã¹ã¯ã«é¢é£ããæè¡ã·ã¹ãã ãæ€èšããå Žåããã®èŠä»¶ãçæããã¢ã«ãŽãªãºã ã¯æ¬¡ã®ãšããã§ãã
-ãªã¹ã¯ã¬ãã«ãã©ã³ã¯ä»ãããã·ã¹ãã ã®æ©èœã«ãªã¹ã¯ãé¢é£ä»ããŸãããããã£ãŠãã·ã¹ãã ã»ãã¥ãªãã£ã®å¿
èŠãªã¬ãã«ãã©ã³ã¯ä»ãããŸãã
-å¿
èŠãªãªã¹ã¯ã¬ãã«ã®éæãç®çãšãã察çãç¹å®ããã 倧ããªãããã¯ã§ã¯ããã®ãããªå¯Ÿçã¯æ¬¡ã®ãšããã§ãã管çã·ã¹ãã ãã©ã€ããµã€ã¯ã«ããã»ã¹ãé害ããã³/ãŸãã¯å€éšã®åœ±é¿ã«ããå¥åº·ã®æ··ä¹±ããä¿è·ããããã®æè¡ç察çã
ãã®ããšãèãããšãããã®ããã«å
šäœåãçŸããŸããã
å³2.æ
å ±ã»ãã¥ãªãã£ã®æŠå¿µ
æåç·ã«ã¯ãªã¹ã¯ç®¡çããããŸãã ISã®ã³ã³ããã¹ãã«ã¯ãè
åšãè匱æ§ããªã¹ã¯ã®è©äŸ¡ãšããªã¹ã¯ã軜æžããããã®å¯Ÿçãé©çšããçžäºæ¥ç¶ããã»ã¹ãå«ãŸããŸãã 蚱容å¯èœãªã¬ãã«ã®ãªã¹ã¯ã確ä¿ããããã®äœæ¥ã®çµç¹ã¯ãã人ãããããã»ã¹ãããæè¡ãã®ã«ããŽãªã«ãã£ãŠæ±ºå®ãããŸãã
å³3.æ
å ±ã»ãã¥ãªãã£ã®ç¢ºä¿ãšè©äŸ¡ã®ã³ã³ããã¹ãïŒåºå
žïŒISA / IEC 62443ïŒ
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®èª¬æã®ç¹åŸŽãšISã¡ã³ããã³ã¹ã®æŠå¿µã«ã€ããŠãããã«è©³ãã説æããå¿
èŠããããŸãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®èª¬æ
æ©èœã説æããããã«ãæ
å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ããèæ
®ãããããšãææ¡ãããŠãã3çš®é¡ã®ACS TPã¢ãã«ãæ±ããŸãã
ãŸããããã¯5ã€ã®ã¬ãã«ãå®çŸ©ããèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®åç
§ã¢ãã«ã§ãã
-ã¬ãã«4ïŒãšã³ã¿ãŒãã©ã€ãºç®¡çã
-ã¬ãã«3ïŒéçšçç£ç®¡çã
-ã¬ãã«2ïŒç©çããã»ã¹ã®ç®¡çãšç£èŠïŒSCADAïŒã
-ã¬ãã«1ïŒä¿è·ããã³å®å
šæ©èœãå«ãããŒã«ã«ããã»ã¹ããã³æ©åšå¶åŸ¡ïŒå¶åŸ¡ã·ã¹ãã ïŒã
-ã¬ãã«0ïŒç©ççãªããã»ã¹ãšæ©åšïŒã»ã³ãµãŒãšã¢ã¯ãã¥ãšãŒã¿ãŒïŒã
éåžžãACS TPãæå³ãããã®ã¯ãå®éã«ã¯ã¬ãã«0ã1ãããã³2ãåããŸãã
å³4.ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®åç
§ã¢ãã«ïŒãœãŒã¹ïŒISA / IEC 62443ïŒ
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ç©çã¢ãŒããã¯ãã£ã®ã¢ãã«ãæãäžè¬çã§ãã ãããã¯ãŒã¯ãä»ããŠçžäºæ¥ç¶ãããç©çã³ã³ããŒãã³ãã«ã€ããŠèª¬æããŸãã
å³5.ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ç©çã¢ãŒããã¯ãã£ã®ã¢ãã«ïŒãœãŒã¹ïŒISA / IEC 62443ïŒ
èªååãããããã»ã¹å¶åŸ¡ã·ã¹ãã ã®ãŸãŒãã³ã°ã¢ãã«ã¯ãISã»ãã¥ãªãã£ã®ã¬ãã«ãæ©èœç®çãããã³å®è£
ãããISããªã·ãŒã®èŠä»¶ã«å¿ããŠã°ã«ãŒãã«åå²ããããšã«ããã以åã®ã¢ãã«ããååŸã§ããŸãã ãã®ã¢ãã«ã¯ãè
åšãè匱æ§ããªã¹ã¯ãããã³å¯ŸçãåæããŠããªã¹ã¯ãå¿
èŠãªã¬ãã«ã«æžããããã®åºç€ãšãªããŸãã
å³6ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ãŸãŒãã³ã°ã¢ãã«ïŒåºå
žïŒISA / IEC 62443ïŒ
ããã«ãæ
å ±ã»ãã¥ãªãã£ãæäŸããããã»ã¹ã¯ãèªååãããããã»ã¹å¶åŸ¡ã·ã¹ãã ãã¿ãŒã²ãããµã€ãã§ã©ã®ããã«äœ¿çšããããã決å®ããããšã«äŸåããŸãã ãã®ãããªèª¬æã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
-å®è¡ãããæ©èœã
-é©çšå¯èœãªãœãããŠã§ã¢ãããŒããŠã§ã¢ãããã³ãããã¯ãŒã¯ã³ã³ããŒãã³ããšã€ã³ã¿ãŒãã§ã€ã¹ã
-ã¿ãŒã²ããããã»ã¹ã®å®è£
åºæºïŒå¹çãå®å
šæ§ãç°å¢ãžã®é
æ
®ãªã©ïŒã
-ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ç¯å²ã«å«ãŸããæ圢ããã³ç¡åœ¢è³ç£ïŒçç£èšåãç¥ç財ç£ãããžãã¹ã®è©å€ã補åã®å質ãå人ããã³ç°å¢ä¿è·æ©åšãªã©ïŒ;
-çµæžçæ害ã®å¯èœæ§ããªãã³ã«äººã®çåœãšå¥åº·ãç°å¢ãçç£ãæ©å¯æ
å ±ãå
Œ
±ã€ã¡ãŒãžãžã®æ害ãããªãæãŸãããªãçµæã®åæã
æ
å ±ã»ãã¥ãªãã£ã®æŠå¿µ
æ
å ±ã»ãã¥ãªãã£ã¬ãã«
ISãµããŒãã³ã³ã»ããã®åºç€ã¯ãèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ãISã¬ãã«ïŒã»ãã¥ãªãã£ã¬ãã«ãSLïŒã«åå²ããããšã§ãã ISã¬ãã«ã¯ãç¹åŸŽçãªè
åšãšè匱æ§ããªã¹ã¯ãICSã®éšåãšã³ã³ããŒãã³ãã®å¯Ÿè±¡æ©èœãããã³é¢é£ããã»ãã¥ãªãã£ããªã·ãŒã«å¿ããŠæ±ºå®ãããŸãã
ISã¬ãã«ã¯ã以åã«ææ¡ãããFBã®ACS TPã¬ãã«ã§äœ¿çšããã
å®å
šæ§æŽåæ§ã¬ãã«ïŒSILïŒãšãåŒã°ãããã®ããåçšãããŠãããšèããããŠããŸãã
æšæºã§ã¯ãã»ãã¥ãªãã£ã¬ãã«ã§ããã»ã¹å¶åŸ¡ã·ã¹ãã ãåé¢ããããã®ããã€ãã®ã¢ãããŒããèŠã€ããããšãã§ããŸãã åãISA / IEC 62443ã§ææ¡ãããŠãããŸãŒãã³ã°ã«çŠç¹ãåœãŠãŸãã
-ã»ãã¥ãªãã£ã¬ãã«0ïŒç¹å®ã®èŠä»¶ãã»ãã¥ãªãã£ä¿è·ã¯äžèŠïŒã ISãµããŒãããŸã£ããæŸæ£ã§ãããã©ããã¯æ確ã§ã¯ãªããããISãµããŒãæ段ãäžèŠãªã¬ãã«ã決å®ãããšãããããã®äžç¢ºå®æ§ãçããŸãã å®éã«ã¯ãç¹å®ã®ç¶æ³ã«å°ãããåççãªå
足ã®ååããé²ãããšãã§ããŸãã éåžžããŒãã¬ãã«ã¯äžè¬çãªãŸãŒã³ã§ã¯ãªããåã
ã®ã³ã³ããŒãã³ãã«èšå®ãããŸãããäœããã®çç±ã§æ¬¡ã®ã¬ãã«ã®ã»ãã¥ãªãã£ã¬ãã«1ã«ã¯éããŸããã
-ã»ãã¥ãªãã£ã¬ãã«1ïŒå¶çºçãŸãã¯å¶ç¶ã®éåã«å¯Ÿããä¿è·ïŒ; å¶çºçãŸãã¯å¶çºçãªISéåã«å¯Ÿããä¿è·ã¯ããŸãæç¶ãçãªæ段ã«ãã£ãŠæäŸãããŸãã
-ã»ãã¥ãªãã£ã¬ãã«2ïŒäœãªãœãŒã¹ãæ±çšã¹ãã«ãäœã¢ãããŒã·ã§ã³ã®åçŽãªæ段ã䜿çšããæå³çãªéåã«å¯Ÿããä¿è·ïŒ; 第2ã¬ãã«ããéå§ããŠãæªæã®ããéåã«å¯Ÿããä¿è·ãèæ
®ãããŸãã 第2ã¬ãã«ã§ã¯ããŠã€ã«ã¹ãæ¢ç¥ã®è匱æ§ã®äœ¿çšãªã©ãéåžžã®éå°éæ»æãæ±ããŸãã éåžžããã®ãããªæ»æã¯èªåçã«åæ ãããŸãã
-ã»ãã¥ãªãã£ã¬ãã«3ïŒäžçšåºŠã®ãªãœãŒã¹ãICSåºæã®ã¹ãã«ãããã³äžçšåºŠã®åæ©ãæã€æŽç·Žãããæ段ã䜿çšããæå³çãªéåã«å¯Ÿããä¿è·ïŒ; ãã®ã¬ãã«ã§ã¯ãæšçã·ã¹ãã ã«æ»æãä»æããã®ã«ååãªç¥èãšãªãœãŒã¹ãåãã䟵å
¥è
ã«å¯Ÿããä¿è·ãæäŸããå¿
èŠããããŸãã ãã®ãããªæ»æè
ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãç£æ¥çšãããã³ã«ã®ããŸãç¥ãããŠããªãè匱æ§ãããã³ç¹å¥ãªç¥èãå¿
èŠãšãããœãããŠã§ã¢ããŒã«ãæªçšããŸãã
-ã»ãã¥ãªãã£ã¬ãã«4ïŒæ¡åŒµãªãœãŒã¹ãICSåºæã®ã¹ãã«ãé«ãã¢ãããŒã·ã§ã³ãæã€æŽç·Žãããæ段ã䜿çšããæå³çãªéåã«å¯Ÿããä¿è·ïŒã ãã®ã¬ãã«ã¯ãæ»æè
ãããªãã®ãªãœãŒã¹ãåŒãä»ãããšããç¹ã§ä»¥åã®ã¬ãã«ãšç°ãªããŸããããšãã°ãçµç¹åãããã°ã«ãŒãã¯ãé«ãèšç®èœåãæã€ã³ã³ãã¥ãŒã¿ãŒã®ã¯ã©ã¹ã¿ãŒãé·æé䜿çšã§ããŸãã
åãæ©åšé
眮ãŸãŒã³ïŒèªåå¶åŸ¡ã·ã¹ãã ãŸãŒãã³ã°ã¢ãã«ãåç
§ïŒå
ã§ãåãISã¬ãã«ãæäŸããããšããå§ãããŸãããŸãŒã³éã§ã¯ãå¶åŸ¡ããããã£ãã«ãä»ããŠãã€ãŸãäžããäžãžãã€ãŸãã åãã¬ãã«ã®æ
å ±ã»ãã¥ãªãã£ããŸãã¯ããé«ãã»ãã¥ãªãã£ã¬ãã«ããããäœãã»ãã¥ãªãã£ã¬ãã«ãžã®ããããããŸãã¯ãã®éã§ã¯ãããŸããã
èªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®ISã¬ãã«ããšã«ãèŠä»¶ã®ããã€ãã®ã°ã«ãŒããå®çŸ©ãããŠããŸãã
-IDããã³èªèšŒç®¡çã
-ãªãœãŒã¹ã®äœ¿çšã®å¶åŸ¡ã
-çµ±åïŒå®å
šæ§ïŒã®ç¢ºä¿ã
-ããŒã¿ã®æ©å¯æ§ã確ä¿ããŸãã
-ãªãœãŒã¹ã®å¯çšæ§ã
-ããŒã¿ãããŒã®å¶åŸ¡ãšå¶éã
-ã€ãã³ãã«å¯Ÿããåå¿æéã
ãããã£ãŠãISMSãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ã©ã€ããµã€ã¯ã«ãããã³ä¿è·å¯Ÿçã«ã€ããŠã以äžã§èª¬æããèŠä»¶ã®ç¯å²ã¯ã確ç«ãããISã¬ãã«ã«äŸåããŸãã
æ
å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã
ISMSã®æŽçã®åé¡ã«ã€ããŠã¯ããã§ã«å€ãã®è³æãååšããŸãã ISMS管çã¯ã1ïŒäŒæ¥ã2ïŒäžé£ã®ããã»ã¹å¶åŸ¡ã·ã¹ãã ã®éçºãšéçšã®ããã®ããã°ã©ã ã3ïŒåäžã®ããã»ã¹å¶åŸ¡ã·ã¹ãã ãªã©ãããã€ãã®ã¬ãã«ã§ã€ã³ã¹ããŒã«ã§ããããšã«çæããããšãéèŠã§ãã
ãšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®ISMSã§ã¯ã管çã·ã¹ãã ãšåæ§ã«ãããã³ã°ãµã€ã¯ã«ãå®è£
ãããŸããèšç»-å®è¡-ãã§ãã¯-è¡çºã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®éçºãããžã§ã¯ãã®ãã¬ãŒã ã¯ãŒã¯ã§äœ¿çšãããISMSã«ã€ããŠã¯ãã©ã€ããµã€ã¯ã«ãå®è£
ãããŠããŸããããã«ã€ããŠã¯ä»¥äžã§èª¬æããŸãã
æ
å ±ã»ãã¥ãªãã£ã®ã©ã€ããµã€ã¯ã«
ACS TPã®å ŽåãVååã®ã©ã€ããµã€ã¯ã«ãå®è£
ãããŸããããã¯ãæ€èšŒããã³æ€èšŒæ段ïŒåéçºæ®µéåŸã®ã¬ãã¥ãŒãåæããŸãã¯ãã¹ãïŒã®å®è£
ã«ãã£ãŠç¹åŸŽä»ããããŸãã èªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®ãœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ã®äŸã以äžã«ç€ºããŸãã
å³7.èªåããã»ã¹å¶åŸ¡ãœãããŠã§ã¢ã®Vååããã»ã¹ã©ã€ããµã€ã¯ã«ïŒåºå
žïŒIEC 61508ïŒ
ãã®ã©ã€ããµã€ã¯ã«ã¯FBã®èŠä»¶ãå®è£
ãããããæ©èœå®å
šã©ã€ããµã€ã¯ã«ãšåŒã°ããŸãã ã»ãã¥ãªãã£ã©ã€ããµã€ã¯ã«ã«æºæ ããã«ã¯ãæ
å ±ã»ãã¥ãªãã£èŠä»¶ãä»æ§ã§æå®ããå¿
èŠããããŸãã æ
å ±ã»ãã¥ãªãã£ã®èŠä»¶ã«ã¯ãæ©å¯æ§ãçµ±åãšã¢ã¯ã»ã·ããªãã£ã®ç¢ºä¿ãèå¥ãšèªèšŒã®ç®¡çãªã©ã察çã®ãªã¹ã¯ãæžããããšãç®çãšãã察çã®å®è£
ãå«ããå¿
èŠããããŸãã ãããã®èŠä»¶ã¯ãã©ã€ããµã€ã¯ã«ã®ãã¹ãŠã®æ®µéã§å®è£
ããã³æ€èšŒãããŸãã
æ
å ±ã»ãã¥ãªãã£ã®éèŠãªæŠå¿µã¯å€å±€é²åŸ¡ã§ããããããæ
å ±ã»ãã¥ãªãã£ã®åéããæ¥ãŸããã ãå€å±€é²åŸ¡ãã¯ãå€å±€é²åŸ¡ã®å€å±€é²åŸ¡ã«äŒŒãŠããŸããæ»æè
ãé²åŸ¡ã¬ãã«ã®1ã€ã貫éããåŸãæ»æ察象ã®æ°ãããå Žåã«ãã£ãŠã¯æ ¹æ¬çã«ç°ãªãé²åŸ¡ã«åºäŒããŸãã
æ
å ±ã®äŒéãšæ©èœã»ãã¥ãªãã£
æ©èœå®å
šã®ãããã¯ã«é¢ããåºçç©ã§ã¯ãããŸããŸãªèŠä»¶ãããã€ãã®ã°ã«ãŒãã«æžããããšãã§ããŸããã
-æ©èœå®å
šç®¡ç;
-æ©èœå®å
šã©ã€ããµã€ã¯ã«ã®å®è£
ã
-ã·ã¹ãã ããã³ãœãããŠã§ã¢èšèšã®äœç³»çãªé害ã«å¯Ÿããä¿è·ïŒã·ã¹ãã ããã³ãœãããŠã§ã¢é害ã®åé¿ïŒã
-ã©ã³ãã ãªããŒããŠã§ã¢é害ã«å¯Ÿããä¿è·ïŒã©ã³ãã é害åé¿ïŒã
å³8.æ©èœå®å
šèŠä»¶ã®æŠå¿µ
æ
å ±ã»ãã¥ãªãã£ã®åéã§èŠä»¶ã®ãããã®ã°ã«ãŒããäºæž¬ããå Žåãå³ã¯ã»ãŒåãã«ãªããŸãã
第äžã«ãFBããã³ISãæäŸããèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®åœ¹å²ã«åºã¥ããŠãã·ã¹ãã ã®ã¬ãã«ãžã®ã°ã©ããŒã·ã§ã³ãšåé¢ãå®è¡ãããŸãã FBãä¿èšŒããã³è©äŸ¡ããããã«å®å
šæ§æŽåæ§ã¬ãã«ïŒSILïŒãå°å
¥ãããBFãä¿èšŒããã³è©äŸ¡ããããã«ã»ãã¥ãªãã£ã¬ãã«ïŒSLïŒãå°å
¥ãããŠããŸãã
次ã«ãISMSå
ã§æ
å ±ã»ãã¥ãªãã£ç®¡çãå®è£
ããå¿
èŠããããŸãã æ
å ±ã»ãã¥ãªãã£ãšéèã»ãã¥ãªãã£ã®ããã»ã¹ã®å€ãã«ã¯å
±éç¹ãããããããããã®éã®èª¿æŽãå®è¡ããå¿
èŠããããŸãã
第äžã«ãäžèšã«ç€ºããããã«ãFBãšISã®äž¡æ¹ãæäŸããããšãç®çãšããéçºãæ€èšŒãããã³æ€èšŒããã»ã¹ã¯ãåäžã®ã©ã€ããµã€ã¯ã«ïŒå®å
šæ§ãšã»ãã¥ãªãã£ã©ã€ããµã€ã¯ã«ïŒå
ã§å®è£
ã§ããŸãã
第4ã«ãFBãšISã®åéã§ã¯ãããŒããŠã§ã¢é害ã®å¯èœæ§ã«ãã£ãŠåŒãèµ·ããããäžè¬çãªãªã¹ã¯ããããŸãã ãã®ãããªé害ã«å¯Ÿããä¿è·ã®æ¹æ³ã¯ãããã¯ã¢ããã蚺æãå¹²æžããã³ãã®ä»ã®æ¥µç«¯ãªåœ±é¿ã«å¯Ÿããä¿è·ãªã©ã§ãã ãããã£ãŠãISãšFBã確ä¿ããããã«åã察çã䜿çšãããŸãã
第5ã«ããœãããŠã§ã¢èšèšãšã·ã¹ãã ã³ã³ããŒãã³ãã®äžåãåå ã§ãèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã§ãããã系統çé害ãçºçããŸãã åãæ¬ é¥ã¯ããµã€ããŒç¯çœªè
ã«ãã£ãŠæªçšãããå¯èœæ§ã®ããè匱æ§ã«ã€ãªãããŸãã
ISãšFBã®äž¡æ¹ãæäŸããããã«ãããã€ãã®å¯Ÿçã䜿çšã§ããŸãïŒããšãã°ãæ©åšãšæ
å ±ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒããããã£ãŠãISãšFBã確ä¿ããããšãç®çãšãã察çéã®èª¿æŽãå¿
èŠã§ãã
ãããŠæåŸã«ãISããã³FB管çã®ãã¬ãŒã ã¯ãŒã¯å
ã§ãããã2ã€ã®ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã確ä¿ããããã®å¯Ÿçãè©äŸ¡ããå¿
èŠããããŸãã
äžèšã®ãã¹ãŠãå³ã«ç€ºãããŠãããISãšFBã確ä¿ããããã®æŽ»åã調æŽããããã®åºç€ãšãªããŸãã
å³9.æ©èœããã³æ
å ±ã»ãã¥ãªãã£ã®èª¿åããèŠä»¶ã®æŠå¿µ
çµè«
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ã確ä¿ããç¹åŸŽã¯ããã®ãããªã·ã¹ãã ãç©ççãªäžçã®ããã»ã¹ãšçžäºäœçšãããã®äž»èŠãªç¹æ§ãæè¡çãªã¹ã¯ãã人ã
ãšç°å¢ãä¿è·ããããšã§ããè匱æ§ã¯ã人ãç°å¢ãããã³æ圢è³ç£ã«ããç©ççãªæ»æã«ã®ã¿äœ¿çšã§ãããããICSã®æ
å ±ã»ãã¥ãªãã£ã¯éèŠã§ãã
äžèšãèæ
®ããŠãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ãšæ©èœå®å
šã®æäŸãšè©äŸ¡ã¯ãåäžã®ã©ã€ããµã€ã¯ã«ïŒå®å
šãšã»ãã¥ãªãã£ã©ã€ããµã€ã¯ã«ïŒã®æ çµã¿å
ã§èª¿æŽããå¿
èŠããããŸãã
ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®æ
å ±ãšæ©èœå®å
šã®åé¡ã«å¯Ÿãã解決çã¯ãçµç¹ãšæè¡ã®äž¡æ¹ã®é åã«ãããŸãã
çµç¹ã®æ§æèŠçŽ ã¯ããããããåŸæ¥å¡ã®ç¶ç¶çãªãã¬ãŒãã³ã°ãšããããå¯èœãªæ¹æ³ã§ã®å®å
šæåã®éçºã§ãã
èªåããã»ã¹å¶åŸ¡ã·ã¹ãã ãä¿è·ããããã®æè¡ç察çã®äžã§ãæãå¹æçãªã®ã¯ãããŸããŸãªã¬ãã«ã®æ
å ±ã»ãã¥ãªãã£ïŒã»ãã¥ãªãã£ã¬ãã«ïŒã®é åã«æ©åšãšãœãããŠã§ã¢ãé
眮ããããšã§ãããã®äžã§ãç·æ¥ä¿è·ã·ã¹ãã ïŒPAZïŒã®ãããŸãŒã³ãæé«ã¬ãã«ã§ããå¥ã®å¹æçãªæè¡çæ段ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããããã¯ãŒã¯ãããã³ã«ãªã©ã®ç¹æ®ãªïŒç¬èªã®ïŒãœãããŠã§ã¢ã®äœ¿çšã§ãã
æ»æããµã€ããŒã€ã³ã·ãã³ãããä¿è·ããã«ã¯ãã©ã³ãã ïŒæ©åšã®ã©ã³ãã ãªé害ã«èµ·å ããè匱æ§ïŒãšã·ã¹ãã ïŒèšèšäžã®æ¬ é¥ã«èµ·å ããè匱æ§ïŒã³ã³ããŒãã³ããåºå¥ããå¿
èŠããããŸãã
æåã®ã¿ã€ãã®è匱æ§ãå¹æçã«æé€ããã«ã¯ãããŒã¿ãšé»æºã®ããã¯ã¢ããã蚺æãç©ççä¿è·ãæ©åšãšå¶åŸ¡ãªããžã§ã¯ããå®å
šãªç¶æ
ã«ç§»è¡ãããªã©ãæ©èœå®å
šã確ä¿ããæ¹æ³ã§è£å®ããããå€ãè¯ãä¿¡é Œæ§çè«ãåŒã³åºãå¿
èŠããããŸãã
ä»ã®è匱æ§ã¯ãæ¥çã§æ¢ã«åŸãããŠããçµéšã®æ çµã¿å
ã§ã培åºçãªé²åŸ¡ã®æ§ç¯ïŒDefense in DepthïŒã®æŠå¿µã«åºã¥ããŠæé€ã§ããŸãããã ããããã«ãŒæ»æã®ã¡ã«ããºã ãéçºãããããããŒããªã¹ã¯ã¯ããåŸãŸããã
ASU TPã®ç®æšã¯ãæè¡çãªã¹ã¯ããä¿è·ããããšã«ãããåžžã«äººé¡ã«å¯Ÿããé«è²ŽãªãµãŒãã¹ã§ãããããããæ±ãããµã€ããŒæ»æã®çµæãšããŠãITã®äžçã®ãã®éšåã¯ããµã€ããŒå
µåšã®é¢šè»ã«å¯Ÿæããæºåãã§ããŠããæ§ãšèšãã°ãçŸä»£ã®çŸå®ã«å¯ŸããŠãŸã£ããæºåãã§ããŠããŸããã§ããã
æããã«ãéäºã®æ¹æ³ã¯é©åã§ãªããã°ãªããããµã€ããŒæŠäºã§ã¯ãICSã¯æããã«æåããéåœã«ãããŸãããããã£ãŠããã³ãããŒãïŒACS TPãç¹ã«ç·æ¥ä¿è·ïŒã¯æè¡ããã»ã¹ã®åé¡ãšæŠããªããã°ãªããããã®æŠå Žã¯ä»ã®ãµã€ããŒã¹ããŒã¹ããåé¢ãããä¿è·ãããªããã°ãªããŸããã