仿¥ã®æ¥éã«é²åããç¶æ³ã«ãããŠãå€ãã®çµç¹ãITã«å€§ããäŸåããæ¥åã®å¹çåãšç«¶äºåãç¶æããããšããŠããŸãããããã®ã·ã¹ãã ã®äžã«ã¯ãITéšéãã»ãã¥ãªãã£éšéã«ãã管çã»ä¿è·ãããŠãããã®ããããŸãããæ£åŒã«æ¿èªãããŠããªã圱ã®è³ç£ãã©ãã©ãå¢ããŠããŠããŸãããããã¯å€ãã®å Žåãã·ã£ããŒITãã·ã£ããŒã¯ã©ãŠããã·ã£ããŒVPNãã·ã£ã㌠ãã¹ã¯ãŒã ãããŒãžã£ãŒãªã©ãšåŒã°ããŸãã
ãã®ãã·ã£ããŒããªã¹ãã«ãã·ã£ããŒç®¡çè ïŒShadow AdminïŒãå¿ããŠã¯ãªããŸãããã·ã£ããŒç®¡çè ãšã¯ãç¹å®ã®ITã·ã¹ãã ã«ãããŠãæ£åŒã«æ¿èªãããããšãªãç®¡çæš©ãããã¯ç¹æš©ã®ãã圹å²ãæã€äººã®ããšã§ãããã®ããã°èšäºã§ã¯ãã·ã£ããŒç®¡çè ãå€å€§ãªãªã¹ã¯ãæã€çç±ãšããããã管çè ãžã®å¯Ÿçã«ã€ããŠèª¬æããŸãã
ã·ã£ããŒIT管çè ãšã¯
ã·ã£ããŒIT管çè ã¯äžè¬çã«ãæè¡çãŸãã¯æ©èœçãªå°éç¥èããã£ãŠããŸãããã®ãããç¹å®ã®ãµãŒãã¹ã®ã»ããã¢ãããæ§æã管çãè¡ãããšãã§ããŸãããããã管çè ã¯å€ãã®å Žåãç·æ¥ã®ããžãã¹ããŒãºã«å¯ŸåŠããããšããæãããè¡åããŠããŸããããããé·æçãªç®¡çã®èгç¹ããèŠããšãå€ãã®å Žåèšç»çãšã¯èšããŸããã倧æµã¯ãçµç¹ã®ã¬ããã³ã¹ããªã¹ã¯ãã³ã³ãã©ã€ã¢ã³ã¹ïŒGRCïŒã®èŠä»¶ãèæ ®ããŠããŸããããã®ããããããã管çè ã®è¡åã«ãã£ãŠãçµç¹ã«é倧ãªãªã¹ã¯ãããããå¯èœæ§ããããŸããã»ãã¥ãªã㣠ãã¹ããã©ã¯ãã£ã¹ãçµç¹ã®GRCããªã·ãŒãçç¥ããŠããªããã°ãªãããã§ããããã·ã£ããŒIT管çè ã管çããã·ã¹ãã ãæ©å¯ããŒã¿ã䜿çšããŠããããéèŠãªããžãã¹ããã»ã¹ããµããŒãããŠãããã©ãã§ããããïŒ
ã·ã£ããŒIT管çè ãçãŸããçç±
ITã®ååŸã管çã«ãããŠæ£åŒã®ããã»ã¹ãåªå äºé ã«äžæºãæããåŸæ¥å¡ãã·ã£ããŒIT管çè ã«ãªãããšããããŸããäžè¬çã«ã以äžã®ãããªåé¡ããããŸãã
- ITã®å¯Ÿå¿ãè¿ éã§ãªãïŒçµç¹å ã®åéšéã®ããŒã ã¯ãITãœãªã¥ãŒã·ã§ã³ãå¿ èŠãšããŠããããæ¿èªãå°å ¥ã«æéãããããããITéšéã¯ã¹ã ãŒãºã§ãªããšèããŠããå ŽåããããŸãã
- ãªãœãŒã¹äžè¶³ïŒITéšéã¯ããã¹ãŠã®èŠæ±ã«å¯ŸåŠã§ããäœè£ããªããåŸæ¥å¡ãéšéã¯åèªã§å¯ŸåŠãããããªãå ŽåããããŸãã
- ããŒãºã«åã£ãŠããªãïŒäºæ¥éšéãšããã«é¢é£ããã·ã£ããŒç®¡çè ã¯å€ãã®å Žåãæ¿èªãããããµããŒããããŠããã·ã¹ãã çµç±ã§ã¢ã¯ã»ã¹ã§ãããã®ããããããå¹ççã§ãããšèãããµãŒãã¹ãŸãã¯ã·ã¹ãã ãå°å ¥ããŠããŸãã
- ã€ãããŒã·ã§ã³ãã¢ãžãªãã£ïŒã·ã£ããŒIT管çè ã®äžã«ã¯ãã€ãããŒã·ã§ã³ã«é¢å¿ã®é«ãè ãããŸããæ°ããããŒã«ãŸãã¯ãã¯ãããžãŒãå°å ¥ããæ¥åãé²ããããšãã§ãããããããŸããããæ£åŒãªITæ§é ã«ã¯æ²¿ã£ãŠããŸããããããŠãããããè¡åã«ãããŠãã·ã£ããŒIT管çè ã¯æªæ¿èªã®ã·ã¹ãã ã®ç®¡çè ãšãªããŸãã
ã·ã£ããŒIT管çè ã®ãªã¹ã¯
ã·ã£ããŒIT管çè ã¯å€ãã®å Žåãè¯ãããšæã£ãŠè¡åããŠããã®ã§ãããæå³ããçµç¹ãããŸããŸãªãªã¹ã¯ã«ããããŠããŸãå¯èœæ§ããããŸãã æ»æè ãããããã¢ã«ãŠã³ããæªçšããã°ãããã¯ãã¢ã®äœæãã»ãã¥ãªãã£èšå®ã®å€æŽãæ©å¯ããŒã¿ã®æãåºã ãã·ã¹ãã ã®å šåæ¢ãªã©ãæš©éãå¿ èŠãªã¢ã¯ã·ã§ã³ãå®è¡ã§ããããã«ãªããŸããæ»æè ã¯ãŸãããããã®ã¢ã«ãŠã³ãã䜿çšããŠçè·¡ãé ãããšãã§ããŸããããããŠæ€ç¥ãåé¿ã§ããããã䟵害ããã·ã¹ãã ãã³ã³ãããŒã«ãç¶ããããšãã§ããŸãã
Active Directoryã«é¢é£ããã·ã£ããŒç®¡çè ãªã¹ã¯ããããŸããæ»æè ã¯ãActive Directoryã§ã·ã£ããŒç®¡çè ã¢ã«ãŠã³ãã䜿çšããŠãã£ã¬ã¯ããªãµãŒãã¹ã®æäœããã¹ã¯ãŒãã®ãªã»ãããæš©éææ Œãè¡ãããšãã§ããŸããããã«ããããã®ã¢ã«ãŠã³ããç¹å®ããããšã§ãæ»æè ã¯ã¢ã¯ã»ã¹ã¬ãã«ãäžããããšãã§ããŸããå€ãã®å Žåã¯ä»ã«äœã®ãšã¯ã¹ããã€ããå¿ èŠãããŸãããã·ã£ããŒç®¡çè ã¢ã«ãŠã³ããããã»ã©é倧ãªãªã¹ã¯ã§ããäžã€ã®çç±ã¯ãå€ãã®å ŽåãæªçšãããŠãããã°ããããŠãæ°ã¥ããªãããšã§ãã
ã·ã£ããŒITãã·ã£ããŒç®¡çè ã¢ã«ãŠã³ãã«é¢é£ãã䟵害ãšããŠãåºãç¥ãæž¡ã£ãŠããæè¿ã®äŸãšããŠã ãMidnight Blizzardã«ããMicrosoftãžã®æ»æãã®èšäºãã芧ãã ããã
ã·ã£ããŒç®¡çè ãçµç¹ã«ãªã¹ã¯ããããã6ã€ã®åŽé¢
ã·ã£ããŒç®¡çè ã圱é¿ãåãŒããšãªã¢ã¯6ã€ãããŸãã
1ïŒã»ãã¥ãªãã£ã®è匱æ§
ã·ã£ããŒIT管çè ã¯å€ãã®å ŽåãITéšéã«ãã£ãŠèšå®ããããéèŠãªã»ãã¥ãªã㣠ããã»ã¹ãåé¿ããŸããããã¯ã以äžã®ãããªããŸããŸãªé倧ãªã»ãã¥ãªã㣠ãªã¹ã¯ã«ã€ãªããå¯èœæ§ããããŸãã
- ã¢ã¯ã»ã¹å¶åŸ¡ã®åŒ±äœåïŒã·ã£ããŒIT管çè ã¯ãã¢ããªã±ãŒã·ã§ã³ãŸãã¯ããŒã¿ãžã®éåºŠãªæš©éãèªèº«ãŸãã¯ä»ã®äººã«ä»äžããå ŽåããããŸããããã«ãããéèŠãªã·ã¹ãã ãžã®èš±å¯ãããŠããªãã¢ã¯ã»ã¹ãããã¯ãã¢ãäœæãããå¯èœæ§ããããŸããããã¯ãé©åãªç£èŠãã§ããªãã°ããããæ»æè ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããã³ã³ãããŒã«ããããšã奜ããããåé¡ãšãªããŸãã
- ã·ã¹ãã ã®æ§æãã¹ïŒã·ã£ããŒIT管çè ããé©åãªã»ãã¥ãªãã£æ§æã䜿çšããŠããªããã°ãæ£ããæ§æãããŠããªãã·ã¹ãã ãæ§ç¯ããŠããŸããããããããŸããããããã°ãæ»æè ããã®ãããªã·ã¹ãã ãæªçšãããªã¹ã¯ã¯ããã«é«ãŸããŸãã
2ïŒããŒã¿ã®äŸµå®³ãšæå€±
å€ãã®ã·ã£ããŒITãµãŒãã¹ã«ã¯ãæ©å¯ããŒã¿ã®åŠçãé¢ãããŸããäŸãã°ã財åèšé²ãç¥ç財ç£ã顧客æ å ±ãªã©ã§ããã·ã£ããŒIT管çè ãé©åãªç£èŠãªããã®ããŒã¿ã管çããã°ã以äžã®ãããªãªã¹ã¯ãæãå¯èœæ§ãé«ãŸããŸãã
- æ å ±æŒããïŒã·ã£ããŒIT管çè ã«ãã£ãŠæ§æãããã·ã¹ãã ãŸãã¯ã¢ããªã±ãŒã·ã§ã³ã¯ãé©åã«æå·åãããŠããªããé©åãªã¢ã¯ã»ã¹å¶åŸ¡ãèšå®ãããŠããªãããŸãã¯ååã«ç£èŠãããŠããªãå¯èœæ§ããããŸããããã¯ãæ å ±æŒãã ããæ©å¯æ å ±ãèš±å¯ãããŠããªãæ¹æ³ã§å ±æããããšãã£ãåé¡ãæããŸãã
- ããŒã¿æå€±ïŒã·ã£ããŒIT管çè ãã·ã¹ãã ãé©åã«ããã¯ã¢ããããŠããªãããŸãã¯å人ã®ã¯ã©ãŠããµãŒãã¹ãªã©ãã»ãã¥ã¢ã§ãªãç°å¢ã§ããŒã¿ãä¿åããŠããå Žåãã·ã¹ãã é害ãçºçããããã©ã³ãµã ãŠã§ã¢ãªã©ã®ãµã€ããŒæ»æãåãããããã°ãçµç¹ã®éèŠãªããŒã¿ã倱ããããªã¹ã¯ãçããŸãã
3ïŒèŠå¶ã®ééµå®
GDPRïŒEUäžè¬ããŒã¿ä¿è·èŠåïŒãHIPAAïŒç±³åœ å»çä¿éºã®çžäºéçšæ§ãšèª¬æè²¬ä»»ã«é¢ããæ³åŸïŒãSOC 2ãšãã£ããèŠå¶äžã®èŠä»¶ãéµå®ããå¿ èŠãããçµç¹ã«ãšã£ãŠãã·ã£ããŒIT管çè ã¯ãé倧ãªã³ã³ãã©ã€ã¢ã³ã¹ ãªã¹ã¯ãããããå¯èœæ§ããããŸããã·ã£ããŒã·ã¹ãã ãã·ã£ããŒã¢ã«ãŠã³ãã¯å€ãã®å Žåãæ£åŒãªITã·ã¹ãã ãšåæ§ã®å³æ Œãªãã§ãã¯ãç£æ»ãè¡ãããªããããèŠå¶ã«å¯Ÿå¿ããããã«å¿ èŠãªã»ãã¥ãªãã£ãŸãã¯ãã©ã€ãã·ãŒèŠä»¶ã«é©åã§ããªãå¯èœæ§ããããŸããããã¯ã以äžãæããããããããŸãã
- æ³çåŠåã眰éïŒçµç¹ãèŠå¶ãéµå®ããŠããªãå Žåã眰éãæ³çåé¡ã颚è©è¢«å®³ãæãããšãäºæ³ãããŸãã
- ç£æ»èšŒè·¡ã®æ¬ åŠïŒã·ã£ããŒITã·ã¹ãã ã¯ãå¿ èŠãªãã®ã³ã°ãç£èŠãå°å ¥ããŠããªãå¯èœæ§ããããŸãããã®ãããããŒã¿ã®åãã倿Žã远跡ããããšã¯é£ãããç£æ»ããã©ã¬ã³ãžãã¯èª¿æ»ã®éã«åé¡ãšãªãããŸãã
4ïŒéå¹çãªãªãã¬ãŒã·ã§ã³
ã·ã£ããŒIT管çè ã¢ã«ãŠã³ãã¯ãåé¡ãå³åº§ã«è§£æ±ºã§ãããããããŸããããããããã®ãŸãŸæŸçœ®ãããŠããã°ãé·æçã«èŠãã°ãªãã¬ãŒã·ã§ã³ã®éå¹çãæããããããããŸãã
- ããŒã¿ã®ãµã€ãåïŒã·ã£ããŒIT管çè ã¯å€ãã®å Žåãäžå€®ã®ITã€ã³ãã©ãšããŸãçµ±åããŠããªãã·ã¹ãã ãå°å ¥ããŠããŸãããã®çµæãããŒã¿ã¹ãã¬ãŒãžã¯ããã©ã°ã¡ã³ãåãããŠãããããããŸããŸãªéšéã§ããŒã¿ã䜿çšããã®ãç°¡åã§ã¯ãããŸããã
- äžè²«æ§ã®ãªãããã»ã¹ïŒè€æ°ã®ããŒã ãããããç°ãªãããŒã«ãæ¿èªãããŠããªãããŒã«ã䜿çšããŠããã°ãå€ãã®å Žåã¯ãŒã¯ãããŒã«äžè²«æ§ããªããªããŸããçµç¹ã«ãšã£ãŠãããã»ã¹ãå¹çåããããæ¥åã«ã€ããŠçµ±äžããããã¥ãŒãåŸããããããšãé£ãããªããŸãã
5ïŒã€ã³ã·ãã³ã ã¬ã¹ãã³ã¹ãžã®åœ±é¿
ãµã€ããŒæ»æ ãŸãã¯ããŒã¿äŸµå®³ ãçºçããå Žåãã·ã£ããŒIT管çè ã®æ å ±ãå¿ èŠãªå ŽåãITéšéã«ããç¹å®ãšå¯Ÿå¿ã«ããªãã®æéããããå¯èœæ§ããããŸããã·ã£ããŒITãµãŒãã¹ãã·ã£ããŒITã¢ã«ãŠã³ãã¯äžè¬çã«ææžåãç£èŠãè¡ãããŠããªããããITããŒã ã¯ã圱é¿ãåããã·ã¹ãã ããã¹ãŠæ€ç¥ããããšãã§ããªãã£ããã察å¿ã«åå ããŠãããåŸæ¥å¡ãããããªãã£ããããå¯èœæ§ããããŸããããããå¯èŠæ§ã®æ¬ åŠã«ãããã€ã³ã·ãã³ã ã¬ã¹ãã³ã¹ãå°ã蟌ãã«é ããçããå¯èœæ§ããããŸãããã®çµæãã»ãã¥ãªã㣠ã€ã³ã·ãã³ãã«ãã被害ã倧ãããªããŸãã
6ïŒå¢ããITã®è² æ
ã·ã£ããŒITãããã«é¢é£ããã·ã£ããŒç®¡çè ã確èªãããã°ãITããŒã ã«ã¯ãæéã®ããããªã³ããŒãã£ã³ã° ããã»ã¹ãåŸ ã£ãŠããŸãããããã®ã·ã¹ãã ã®ç£æ»ãä¿è·ãè¡ããçµç¹ã®æ£åŒãªITã·ã¹ãã ãããã»ã¹ã«çµ±åããªããã°ãªããŸãããITããŒã ã«ãšã£ãŠã¯èšç»å€ã®è² æ ãã®ããããããšã«ãªããŸããããã«ãããéèŠãªãããžã§ã¯ããããªãœãŒã¹ãå²ãåœãŠãªããã°ãªããããªãã¬ãŒã·ã§ã³ ã³ã¹ããããã¿ãŸãã
ã·ã£ããŒç®¡çè ããã¶ãåºã
ã·ã£ããŒIT管çè ã®ãªã¹ã¯ã«å¯ŸåŠããã«ã¯ãITããŒã ãã»ãã¥ãªãã£ããŒã ã¯ãããã¢ã¯ãã£ããªæŠç¥ã䜿çšããå¿ èŠããããŸãã
- å¯èŠæ§ãšç£èŠã®åäžïŒSaaSã»ãã¥ãªãã£ïŒãã¹ãã£ç®¡çïŒSSPMïŒãæ å ±æŒãã察ç ïŒDLPïŒãã¢ã€ãã³ãã£ãã£è åšã®æ€ç¥ãšå¯Ÿå¿ïŒITDRïŒãªã©ã®ããŒã«ã䜿çšããŠãæªæ¿èªã®ãµãŒãã¹ãã·ã£ããŒç®¡çè ãå¯èŠåããŸãã
- ã¢ã¯ã»ã¹å¶åŸ¡ã®å®è¡ïŒç¹æš©ã¢ã¯ã»ã¹ç®¡çïŒPAMïŒã®ã»ãããã«ããã¡ã¯ã¿èªèšŒïŒMFAïŒãSSOïŒã¢ã€ãã³ãã£ã㣠ãããã€ã㌠ãµãŒãã¹ïŒãçšããäžå çãªèªèšŒãµãŒãã¹ã䜿çšããæ¿èªããã人ã®ã¿ãIT管çè ã«ãªããããã«ããŸãã
- æç¢ºãªITããªã·ãŒã®äœæïŒäœ¿çšãæ¿èªãããŠããITãµãŒãã¹ãITã·ã¹ãã ãå®ããæç¢ºãªããªã·ãŒãäœæããåšç¥ããŸãããã¹ãŠã®åŸæ¥å¡ãã·ã£ããŒITã®æœåšçãªãªã¹ã¯ãçè§£ã§ããããã«ããŸãããŸããéèŠãªITæ¥åã®åªå äºé ãåªå ã§ããæç¢ºãªæ¹æ³ãæäŸããåŸæ¥å¡ããã®å ã·ã£ããŒITã«é ŒããªããŠãããããã«ããŸãããšã¯ãããã·ã£ããŒITãé¢é£ããã·ã£ããŒç®¡çè ã®åé¡ã¯ãä»åŸãã°ããã®éè§£æ¶ãããå¯èœæ§ãäœããããçŸå®çãªèŠç¹ãæã£ãŠããããšãéèŠã§ãã
ãŸãšã
ã·ã£ããŒIT管çè ã¯ãèªèº«ã®è¡åãçµç¹ã«åªããå©çããããããã®ãšèããŠããŸãããã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ããªãã¬ãŒã·ã§ã³ãå±éºã«ããããããªé倧ãªãªã¹ã¯ãæããããããããŸããçµç¹ã¯ããããããªã¹ã¯ã管çããäœæžããããã®ããã¢ã¯ãã£ããªæé ãæ¡çšããããšã§ãèªèº«ãå±éºããå®ãããšãã§ããŸãã
ãã«ãŒããã€ã³ãã§ã¯ãçµç¹ããã·ã£ããŒITãã·ã£ããŒç®¡çè ãããžãã¹ã«æªåœ±é¿ãåãŒãåã«æ€ç¥ãã修埩ã§ãããããµããŒããã補åããµãŒãã¹ãžã®æè³ãç¶ç¶çã«è¡ã£ãŠããŸããããã§ã¯ãæ°ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ããç°¡åã«2ã€ã玹ä»ããŸãã
- Proofpoint Account Takeover ProtectionïŒã¢ã«ãŠã³ãä¹ã£åãã®æ€ç¥ãšå¯Ÿå¿ã®æ©èœã«ãããæªæ¿èªãŸãã¯æªæã®ãããµãŒãããŒã㣠ã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšã«ãã©ã°ãä»ãã修埩ããŸãã
- Proofpoint ITD (Identity Threat Defense) ïŒãã«ãŒããã€ã³ãã®ITDRãœãªã¥ãŒã·ã§ã³ã§ããå šäœçãªæ©èœãšããŠãActive DirectoryãããŸããŸãªã¯ã©ãŠã ã¢ã€ãã³ãã£ã㣠ãããã€ããŒã«ãããã·ã£ããŒç®¡çè ã¢ã«ãŠã³ããæ€ç¥ãã修埩ãã¬ã€ãããŸãã
ãã«ãŒããã€ã³ãã®ã¢ã€ãã³ãã£ã㣠ã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ã«ã€ããŠè©³ããã¯ããã¡ãã®WebããŒãžã«ã¢ã¯ã»ã¹ããŠãã ããã