åºæ
æ å ±ã»ãã¥ãªãã£ã®èšºæã«ã¯ãç£æ»ãè匱æ§è©äŸ¡ãäŸµå ¥ãã¹ãã®3ã€ã®ã¢ãããŒãããããšèããããŠããŸãã ç£æ»ãšè匱æ§è©äŸ¡ã«ã€ããŠè©±ããŸãããã ã«ããã®äžã§ãç£æ»ã®ãã¬ãŒã ã¯ãŒã¯å ã§å¯ŸåŠããå¿ èŠãããåé¡ãããã³æ©æ¢°åŠç¿ã«åºã¥ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®æ€åºãé²æ¢ã調æ»ïŒç£æ»è ã®è åšã®æ€åºã®å€æŽïŒãã€ã³ãã©ã¹ãã©ã¯ãã£ãªããžã§ã¯ãããã®ãã°ã®åéïŒInTrustïŒãããã³çŸåšã®ç£æ»ã®ããã®Quest SoftwareããŒã«ããããæ€èšããŸã1ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ïŒITã»ãã¥ãªãã£æ€çŽ¢ïŒã«ãªã¹ããããŠãããã¹ãŠã®ã·ã¹ãã ã®æ§æïŒEnterprise ReporterïŒããã³ç£æ»ããŒã¿ã®åºåã
ITã»ãã¥ãªãã£ç£æ»ã¯ãæ å ±ã·ã¹ãã ãšãã®ã¡ã³ããã³ã¹ã顧客ã®æåŸ ãšäŒç€Ÿã®åºæºãæºãããã©ãããå€æããŸãã ç§ãã¡ã®èŠ³ç¹ãããç£æ»ã·ã¹ãã ã«ã¯æ¬¡ã®æ©èœãå¿ èŠã§ãã
- éåžžããã³éå®åã®æŽ»åãèå¥ããã³èå¥ããŸãã
- ã¯ãšãªãæ§ç¯ããã€ãã³ãã®é åã§ããŒã¿ããã£ã«ã¿ãŒåŠçããŠãå¿ èŠãªæ å ±ãååŸããŸãã
- ã€ãã³ãã責任ã®ããã°ã«ãŒãã«ãšã¹ã«ã¬ãŒã·ã§ã³ããŸãã
- éå®åã¢ã¯ãã£ããã£ãèå¥ããããšãã§ããäºåèšå®ãããã¬ããŒãããããŸãã
ç§ãã¡ãããç®ã«ããã€ã³ãã©ããæ±ãããšã®ç¹åŸŽã¯ãæ®å·®ã®ååã«é¢ããç£æ»ã®å®æœã§ãã ã€ãŸããå€æŽã®ç£æ»ã¯éšéã«ãã£ãŠå®è¡ãããéšéã«ã¯ä»ã®ã¿ã¹ã¯ãããŒããããŸãã æåã®åé¡ã¯ããããçããŸã-
çµã¿èŸŒã¿ã®ç£æ»ããŒã«ã䜿çšãã
ä»ã®ãŠãŒã¶ãŒãæ€çŽ¢ããŠæ§æããã®ã«ååãªæéããããŸããã çµã¿èŸŒã¿ããŒã«ãšã¯ãããšãã°ãWindowsã¹ãããã€ã³ãŸãã¯Power Shellã®ç¹å¥ãªã¹ã¯ãªãããæå³ããŸãã ãã¡ããããã®ãããªããŒã«ã®å©ããåããŠãããªãã¯äºå®ã®åŸã®äºä»¶ã«ã€ããŠèŠã€ããããšãã§ããã ãã§ãã
çµç¹ãæé·ããã«ã€ããŠããŠãŒã¶ãŒãšå€æŽã®æ°ãå¢å ããŸãã ç¹å®ã®æ°åã§ãã®äž»é¡ã«é¢ããç 究ããããŸãããããããªããŠããããžã¿ã«äº€æãæ¯å¹Žäžåãã«å€åããŠããããšã¯æããã§ãã 2çªç®ã®ç£æ»èª²é¡ã¯
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å¢å ã«ããå€æŽã®å¢å
æé·ã¯ãã¹ã¿ãããŸãã¯é¡§å®¢æ°ã®å¢å ã«é¢é£ããå ŽåããããŸãããããã«é¢ä¿ãªããå€åã®éã¯æ¯äŸããŠå¢å ããŸãã
ç£æ»ã¯ãå éšèŠå ïŒãããã¯æåã®2ã€ã®åé¡ã§ãïŒã ãã§ãªããå€éšèŠå ïŒåœäœãŸãã¯äŒæ¥ããªã·ãŒã®èŠä»¶ïŒã«ãã£ãŠãæ·±å»ãªåœ±é¿ãåããŸãã ãããŠã3çªç®ã®ç£æ»åé¡ã«åãçµã¿ãŸã-
èŠä»¶ãæºããããã®é©åãªããŒã«ã®æ¬ åŠ
é©åãªããŒã«ããªãå Žåãã·ã¹ãã 管çè ã¯å¿ èŠãªå€æŽãå¶åŸ¡ããªããããŸãã¯å¶åŸ¡ããŸãããå³èã®æ段ã䜿çšããŸãïŒåé¡1ãåç §ïŒã
ãããŠä»ãç§ãã¡ã¯è³ªåãžã®çããå©ããããšãã§ããããŒã«ã®ã¬ãã¥ãŒã«é²ã¿ãŸãïŒã誰ããããããŸãããïŒãïŒå®éã圌ãã¯ä»ã®å€ãã®è³ªåãžã®çããå©ããã§ãããïŒã
æ å ±ã»ãã¥ãªãã£ã€ãã³ãã®éçšç£æ»
èšçœ®äŒè°ã®ããã«ããã€ãã®äŒç€Ÿã«è¡ããšãPower Shellã«åºã¥ãç£æ»ã·ã¹ãã ããããŸãã ã¹ã¯ãªããã¯éåžžãåäžã®Windows管çè ã«ãã£ãŠãµããŒããããŸãã ãã®åŸæ¥å¡ã解éããããŸã§ãããã¯æ·±å»ãªåé¡ã§ã¯ãããŸããã 圌ã®åºçºåŸãçåãçããŸãïŒèª°ããããæ¯æŽããçºå±ããç¶ããã§ããããã æ°ãã管çè ïŒååãªèœåãããå ŽåïŒã¯éåžžããããã®ã¹ã¯ãªãããå床äœæããŸãã ãããŠããããã¯å€ç«ããã±ãŒã¹ã§ã¯ãããŸããã
Change Auditorã¯ãMicrosoftç°å¢ããã³ãã£ã¹ã¯ã¢ã¬ã€ã®å€æŽããªã³ã©ã€ã³ã§ç£æ»ããããã®ããŒã«ã§ãããå人ã®ç¥èã¯å¿ èŠãããŸããã
ãµããŒããããç£æ»ïŒADãAzure ADãSQL ServerãExchangeãExchange OnlineãSharepointãSharepoint OnlineãWindows File ServerãOneDrive for BusinessãSkype for BusinessãVMwareãNetAppãEMCãFluidFS ãã€ããªããç°å¢ã«é©ããŠããŸãã GDPRãSOXãPCIãHIPAAãFISMAãGLBAèŠæ Œã«æºæ ããããã®äºåå®çŸ©ãããã¬ããŒãããããŸãã
ç£æ»ã«å ããŠãChange Auditorã¯å€æŽããããã¯ã§ããŸãã ããšãã°ãADã°ã«ãŒããžã®æ°ãããŠãŒã¶ãŒã®è¿œå ãçŠæ¢ãããããã¡ã€ã«/ãã©ã«ããŒã®å€æŽãçŠæ¢ãããããŸãã
Change Auditorã«ã¯ãè¿œå ã®åæã¢ãžã¥ãŒã«-è åšæ€åºããããŸãã
æ©æ¢°åŠç¿ïŒMLïŒãšãŠãŒã¶ãŒè¡ååæïŒUEBAïŒãæèŒã éå»30æ¥éã«Change Auditorããã€ãã³ããåä¿¡ããéåžžãšã¯ç°ãªããŠãŒã¶ãŒã®è¡åãæããã«ããŸãïŒç°åžžãªå ŽæãŸãã¯ç°åžžãªæéããã®å ¥åããã¡ã€ã³ã³ã³ãããŒã©ãŒã®é£ç¶ãããã¹ã¯ãŒãå ¥åã®å€±æãçŠæ¢ããããã¡ã€ã«ãªãœãŒã¹ã®å ¥åãªã©ã ãã®ã¢ãžã¥ãŒã«ã¯ãããã€ãã®ãã£ã¡ã³ã·ã§ã³ã§ã€ãã³ããåæããç°åžžãå ±åããŸãã
ç£æ»ã€ã³ãã©ã¹ãã©ã¯ãã£æ§æ
é·ãéWindowsã€ã³ãã©ã¹ãã©ã¯ãã£ãã¯ãªãŒã³ã¢ãããããããããã§ããŸã æã«å ¥ããªã人ã®ããã«ã ã¬ããŒãäœæããŒã«ã§ããEnterprise Reporterã¯ãADãAzure ADãSQL ServerãExchangeãExchange OnlineãWindows File ServerãOneDrive for BusinessãAzureãªãœãŒã¹ïŒä»®æ³ãã·ã³ããããã¯ãŒã¯ã»ãã¥ãªãã£ã°ã«ãŒãããã®ä»ã®ãªããžã§ã¯ãïŒãããªããžã§ã¯ãããŒã¿ãååŸããçŸããã¬ããŒããäœæããŸãã
補åã®äž»ãªäŸ¡å€ã¯ãæ¢åã®ã¬ããŒãã»ããã§ããããã«ãããã€ã³ã¹ããŒã«çŽåŸã«è匱æ§ã確èªã§ããŸãã ããšãã°ããã顧客ã§ããã¹ã¯ãŒãæå¹æéãªãã·ã§ã³ãç¡å¹ã«ãªã£ãŠãããã¡ã€ã³ç®¡çè ã°ã«ãŒãã®ãŠãŒã¶ãŒãèŠã€ããŸããã
æ¢è£œã®ã¬ããŒãããïŒ
- éå»30æ¥éãã°ã€ã³ããŠããªããŠãŒã¶ãŒ
- æéåãã®ãã¹ã¯ãŒããæã€ãŠãŒã¶ãŒã
- éå»30æ¥éãã°ã€ã³ããŠããªãç¹æš©ã°ã«ãŒããŠãŒã¶ãŒã
- ããŒã«ã«ã·ã¹ãã ã¢ã«ãŠã³ãã£ã³ã°ã§ã¯æ©èœããªãWindowsãµãŒãã¹ã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®åœ¹å²ãæã€ãµãŒããŒã«ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã
- ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããä¿®æ£ããã°ã©ã
- ãµãŒããŒã®ã»ãã¥ãªãã£èšå®
- ãã¹ããããã°ã«ãŒããšãã¹ããããã°ã«ãŒãã®ãŠãŒã¶ãŒ
- Active Directoryã®ã¢ã¯ã»ã¹èš±å¯
- ãã¡ã€ã«ã¹ãã¬ãŒãžãªã©ã®ãã©ã«ãã®æš©éã
ãªã¹ããããã¬ããŒãã®äŸã¯ã Quest Webãµã€ãã®PDFã¬ããŒãã«ãããŸãïŒãã¡ã€ã«ã¯ããã«éãã®ã§ãç»é²ã¯äžèŠã§ãïŒã GDPRãSOXãPCI-DSSãHIPAAãFISMAãGLBAãªã©ã«æºæ ããããã®äºåå®çŸ©ãããã¬ããŒãããããŸãã ãŸããäŒç€Ÿã«å ±åèŠä»¶ãããå ŽåããŸãã¯ããã¥ã¡ã³ãã®ãã©ã³ãåãåžæããå Žåã¯ãç¹å¥ãªãã¶ã€ããŒãããŸãã
ãã°ã®åéãšåæ
æ å ±ã»ãã¥ãªãã£ã€ãã³ãã«é¢ããå¥ã®ããŒã¿ãœãŒã¹ã¯ãã°ã§ãã ãããã§ã¯ããã¹ãŠã§ã¯ãªãã«ããŠããã»ãšãã©ãã¹ãŠãèŠã€ããããšãã§ããŸãã ããããåéããåŸãããããæ£èŠåããŠæ§é åããŠãããšãã°ADãšããã¹ããã°ãªã©ã®ã€ãã³ããçžäºã«é¢é£ä»ãããšäŸ¿å©ã§ãã
InTrustã¯ãç°çš®ãœãŒã¹ãããã°ãåéããã³åæããããã®ããŒã«ã§ãã ãããã¯ãŒã¯ããã€ã¹ããWindowsãã°ãããã¹ããã°ãããã³syslogãååŸã§ããŸãã åéåŸããã¹ãŠã®çµ±èšïŒã€ãã³ãïŒã¯ãã©ãŒã ã®ç¶æ ïŒã€ãã³ããçºçãããšããäœãèµ·ãã£ãã®ããã©ãã§èµ·ããã®ãã誰ãã¢ã¯ã·ã§ã³ãå®è¡ããã®ããã¢ã¯ã·ã§ã³ã®å®è¡å ïŒã«éå ãããŸãã
InTrustã¯ã10,000ã®ãœãŒã¹ããæ¯ç§æ倧60,000ã®ã€ãã³ããåŠçã§ããŸãã å€ãã®å ŽåãWindowsã€ãã³ããã°SysmonïŒã¬ãžã¹ããªå€ã®å€æŽã®è¿œè·¡ã誀ã£ãããã·ã¥ãªã©ã®æ°ããããã»ã¹ã®äœæïŒãPowerShellãã°ã®ã€ãã³ããç£èŠããããã«ãã³ã¬ã¯ã¿ãšãŒãžã§ã³ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ã€ã³ã¹ããŒã«ãããŸãã
çããŒã¿ã¯ã20ïŒ1ã®å§çž®çã§å èµã¹ãã¬ãŒãžã«ä¿åãããŸãã äžéšã®SIEMã·ã¹ãã ãšã®æ¢è£œã®çµ±åããããŸãã ãããã䜿çšããå ŽåãInTrustã¯ã©ã€ã»ã³ã¹ãç¯çŽãã䟿å©ãªæ¹æ³ã§ãã ã¹ãã¬ãŒãžã«çããŒã¿ãä¿åããã€ãã³ãã®ã¿ãSIEMã«éä¿¡ããŸãã
åã®äžã®ããŒã«
ã»ãã¥ãªãã£ã®æŠå¿µãå®å šã«ããã«ã¯ããã¹ãŠã®ãœãŒã¹ããã®ããŒã¿ãçµã¿åãããŠã1ã€ã®ãŠã£ã³ããŠã§äœãèµ·ãã£ãŠãããã芳å¯ããããšãæãŸããã§ãã ããã«ãæ ¹æ¬åå ã®è¶ é«éæ€åºã®ããã«ã€ãã³ããé¢é£ä»ããŸãã
ITã»ãã¥ãªãã£æ€çŽ¢-éçšç£æ»ãã€ã³ãã©ã¹ãã©ã¯ãã£æ§æã®ç£æ»ãããã³ãã°ããã®ããŒã¿ã«åºã¥ããGoogleã«ããã°ããŒãã«ãªå šææ€çŽ¢ã®ããã®ããŒã«ã ãã¹ãŠã®ããŒã¿ã¯ãæ¥ç¶ãããã·ã¹ãã ãããªã¢ã«ã¿ã€ã ã§ååŸãããŸãã
ãŠãŒã¶ãŒãã¯ãŒã¯ã¹ããŒã·ã§ã³ãã€ãã³ãã®ã¿ã€ãããŸãã¯ãã®ä»ã®ååãå ¥åããŠããã®å±æ§ã«é¢é£ããã€ãã³ããŸãã¯æ§æãèŠã€ããããšãã§ããŸãã ã¯ãšãªãçæãããšãã«ãè«çåŒã䜿çšã§ããŸãã ã¯ãšãªçµæããã¬ããŒããäœæããã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠé¢ä¿è ã«éä¿¡ãããšäŸ¿å©ã§ãã
ITã»ãã¥ãªãã£æ€çŽ¢ã€ã³ã¿ãŒãã§ãŒã¹ãããADãžã®å€æŽãããŒã«ããã¯ããããšãã§ããŸãã ã€ãŸããããšãã°ã誀ã£ãŠåé€ããããŠãŒã¶ãŒããã¹ãŠã®å±æ§ãšãšãã«åŸ©å ã§ããŸãã ããã¯ãå¥ã®Quest補åã§ããRecovery Manager for Active Directoryãšã®çµ±åã«ããå®çŸãããŸãã
ãã®èšäºã®äž»ãªç®çã¯ãå€æŽãç£æ»ããããã«Quest補åãã¡ããªãŒã玹ä»ããããšã§ãã çŸåšäœ¿çšããŠãããããã®ããŒã«ã¯ãç°ãªãæ©èœã»ãããæã£ãŠããå ŽåããããŸãïŒããå€ããããå°ãªãïŒã 察åŠããªããã°ãªããªãããšãã©ã®æ©èœãããªãã«ãšã£ãŠæçšã§ãã£ããããªãããªãã1ã€ãŸãã¯å¥ã®ãœãªã¥ãŒã·ã§ã³ãéžãã ããã³ã¡ã³ãã«æžããŠãã ããã çµéšã亀æããããšã¯èå³æ·±ãã§ãã