CISOïŒChief Information Security OfficerïŒãšã¯ãäŒæ¥ã®ããŒã¿ãä¿è·ããããã«äœ¿çšãããµã€ããŒã»ãã¥ãªãã£æŠç¥ãèšèšããçµç¹å šäœã®ãªã¹ã¯ãè©äŸ¡ããŠããµã€ããŒé²åŸ¡ãæ¹åãã責任ããã€ãæé«æ å ±ã»ãã¥ãªãã£è²¬ä»»è ã®ããšã§ããCISOã¯ãã»ãã¥ãªãã£ããã°ã©ã ã®èšèšããã£ã¶ã¹ã¿ãªã«ããªèšç»ã®äœæããŠãŒã¶ãŒãçµå¶è ã嵿¥è ã管çè ãžã®ãµã€ããŒã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«é¢ããæè²ãè¡ããŸãã
CISOã®åœ¹å²
CIOïŒæé«æ å ±è²¬ä»»è ïŒãã·ã¹ãã 管çè ããŒã ãææ®ããããã«ãCISOã¯ã»ãã¥ãªãã£å°éå®¶ããŒã ãç£ç£ããŸãããã¹ãŠã®äŒæ¥ãå€§èŠæš¡ãªã»ãã¥ãªãã£ããŒã ãæãŠãããã§ã¯ãªãã®ã§ãCISOã¯éåžžãå€§äŒæ¥ã«ååšããŸããäžå°äŒæ¥ã§ã¯ãCISOãšå¥çŽããããŒãã£ã«CISOãå©çšããŠã»ãã¥ãªãã£ããã°ã©ã ã®æ§ç¯ãæ¯æŽããããšãã§ããŸãã
CISO ã¯çµç¹å ã®ãªãŒããŒã§ããããããµã€ããŒã»ãã¥ãªãã£ã®ç¶æ³ãåžžã«ç£èŠããããŒã¿ãä¿è·ããããã®æ¬¡åã®çãã»ãã¥ãªãã£ããŒã ã«æç€ºããããšãã§ããŸããCISO ã¯ãææ°ã®ãµã€ããŒã»ãã¥ãªãã£ç ç©¶ã«åºã¥ããã€ã³ãã©ã®ã¢ããã°ã¬ãŒãããæ°ããªè åšã黿¢ããããã®æ°ããã»ãã¥ãªãã£ããŒã«ã®èšç»ã«ã€ããŠæèšããŸãã
ãµã€ããŒã€ã³ã·ãã³ããçºçããå ŽåãCISOã¯ãã£ã¶ã¹ã¿ãªã«ããªãéå§ããã»ãã¥ãªãã£ããŒã ã«ãã®æ¹æ³ãæç€ºããæš©éãæã€äººç©ã«ãªããããããŸãããCISOã¯ãŸããã€ã³ã·ãã³ã察å¿ã«æå¹ã§ãããŠã³ã¿ã€ã ãå¶éããééçæå€±ãšæå®³ãæå°éã«æãããã£ã¶ã¹ã¿ãªã«ããªèšç»ã®èšèšãšå®æœã«é¢äžããŸãã
CISOãšCIO
ã»ãã¥ãªãã£ããŒã ãçµç¹ã®ã»ãã¥ãªãã£ãè©äŸ¡ãããªãŒããŒãããªãå Žåãããªãã®ããžãã¹ã¯ããã«ãŒãè åšã¢ã¯ã¿ãŒãªã©ã®ã¿ãŒã²ããã«ãªããŸããçµç¹ã¯ãç¹ã«ã·ã¹ãã ã䟵害ããããã«èšèšãããŠããªãã©ã³ãã ãªã¹ã¯ãªããæ»æã«å¯ŸããŠããããã«è匱ã«ãªããŸããã¹ã¯ãªããã¯ããŠã§ããµã€ãäžã§ã€ã³ã¿ãŒãããå šäœã®ã¹ãã£ã³ãå®è¡ããäžè¬çãªè匱æ§ãèŠã€ããå€ãã®å Žåãèªåçã«ãããæªçšããŸããCISOã¯ãã€ã³ã¿ãŒãããäžã®èªåçãªèåŒ±æ§æ»æã§ãããèªç€Ÿãæšçãšããé«åºŠãªæ»æã§ãããããã黿¢ããæ¹æ³ãèŠåºãããšãã§ããŸãã
CISOã®åœ¹å²ã¯ãå€ãã®å ŽåãITãšãªãã¬ãŒã·ã§ã³ãšãã倧ããªåã®äžã«äœçœ®ããŸããã»ãã¥ãªãã£ããŒã ã¯ãéçºè ãšãªãã¬ãŒã·ã§ã³ããŒã ã®äž¡æ¹ãšååããŠãããŒã¿ã»ãã¥ãªãã£ãæ¹åããããã®ããè¯ãæ¹æ³ãæ¢ããŸããCISOã¯ã»ãã¥ãªãã£ããŒã ãçããŸãããéçºè ã¯ã»ãã¥ãªãã£ããŒã ãšååããŠãäŒæ¥ã®ãœãããŠã§ã¢ã®è匱æ§ãçºèŠããå®å šãªã³ãŒãã®æžãæ¹ãæå°ããŸãããªãã¬ãŒã·ã§ã³ããŒã ã¯ãããŒã¿ãä¿è·ããã€ã³ãã©ãå°å ¥ããããšã§ãCISOãã»ãã¥ãªãã£ããŒã ããæ©æµãåããŸããã€ã³ãã©ã¯ãã¯ã©ãŠãã§ããªã³ãã¬ãã¹ã§ãæ§ããŸããã
éåžžãCIOãšCISOã飿ºããŠäŒæ¥ã€ã³ãã©ã®èšèšãè¡ããŸããCIOã¯ãããã¯ãŒã¯ã€ã³ãã©ã®èšèšãç£ç£ããCISOã¯CIOãšååããŠããã¡ã€ã¢ãŠã©ãŒã«ãããã管çãããã¯ã¢ãããããŒã¿ã¢ã¯ã»ã¹å¶åŸ¡ãç£èŠãäŸµå ¥æ€ç¥ãšé²æ¢ããŠãŒã¶ãŒID管çãã¯ãŒã¯ã¹ããŒã·ã§ã³ã»ã¢ã³ããŠã€ã«ã¹ãªã©ã®ã»ãã¥ãªãã£ã€ã³ãã©ãçµ±åããŸããCIOã®åœ¹å²ã¯ãŠãŒã¶ãŒã®çç£æ§ãé«ããããšã§ãããCISOã¯ãŠãŒã¶ãŒãæ£ããã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠäŒæ¥æ å ±ãä¿è·ããããšãä¿èšŒããå¿ èŠããããŸãã
CISOã®åœ¹è·ã«é©ãã人æ
CISOã¯ãªãŒããŒã§ãããããåªãã管çèœåãå¿ èŠã§ããCISOã¯ã人ãšäžæã«æ¥ããã ãã§ãªããäºç®ãèšç»ãç«ãŠãããšã«ãé·ããŠããªããã°ãªããŸãããCISOãè¡ãããšã¯ãã¹ãŠçµç¹ã®å©çã®ããã§ããã¹ãã§ããã®ããèšç»ãã»ãã¥ãªãã£ãã¬ãŒãã³ã°ã¯ããžãã¹ããŒãºã«ç¹åãããã®ã§ããã¹ãã§ãã
ã»ãã¥ãªãã£ã®ç®æšãšäŒæ¥ã®è²¡åããã³çç£æ§ã®ç®æšãäžèŽãããããšã¯ãCISOã®äž»èŠãªè²¬ä»»ã§ããåªããCISOã¯ããã¹ãŠã®å©å®³é¢ä¿è ãšååããŠãã»ãã¥ãªãã£ãåŸæ¥å¡ã®çç£æ§ã劚ããããã€åŸæ¥å¡ã誀ã£ãŠæ©å¯ããŒã¿ãæŒæŽ©ããªãããã«ããŸãã
åªããCISOã«ã¯ãåªãããªãŒããŒã·ãããšããµã€ããŒã»ãã¥ãªãã£ãšãããã³ã°ã«é¢ããæ·±ãç¥èãå¿ èŠã§ããCISOã®äžã«ã¯ããã¯ã€ãããããããã³ã°ã®ãããã¬ãŒã·ã§ã³ãã¹ããããŒã¯ãŠã§ãã®æŽ»åã®ç ç©¶ã«è²¢ç®ããææ°ã®è åšãéæŸãã®è匱æ§ã«é¢ããç¥èã身ã«ä»ããŠãã人ãããŸããCISOã¯äŒç»ãèšèšãæ åœãããããã»ãã¥ãªãã£ã®åäžãšãªã¹ã¯äœæžã®ããã«äœãå¿ èŠããæç¢ºã«äŒããèœåãæ±ããããŸãããŸãããã£ãã·ã³ã°ã¡ãŒã«ããã«ãŠã§ã¢ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãå®å šã§ãªãè¡çºãªã©ãåŸæ¥å¡ãèªèã§ãããããã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ããã°ã©ã ã®èšç»ãCISOãè¡ããŸãã
åªãããµã€ããŒã»ãã¥ãªãã£ã¯ãçµç¹å šäœã«ããããã®ã§ãããå šç€Ÿçãªåãçµã¿ã§ããå¿ èŠããããŸããçµç¹ã® CISO ã¯ããµã€ããŒã»ãã¥ãªãã£ã®æ¹éãæè²ãã宿œããããã®åãçµã¿ã調æŽããŸããã»ãã¥ãªãã£ããŒã ã¯ãé»åã¡ãŒã«ãåŸæ¥å¡ãã³ãããã¯ãã€ã³ãã©ããããµã€ãããŸãã¯ç€Ÿå ã³ãŒã¹ãéããŠããªã·ãŒãå ±æããŸãããµã€ããŒã»ãã¥ãªãã£ã®åãçµã¿ã調æŽããã®ã¯å€§å€ãªä»äºã§ãããã®ãããåªãã CISO ã¯ã广çãªããªã·ãŒãå±éããããã®äººæãšãªãœãŒã¹ã管çããèœåãæã£ãŠããŸãã
æ å ±ã»ãã¥ãªãã£ã®ä»ã®åéãšåæ§ãCISOã¯ãææ°ã®è åšãçè§£ããããã«ãåŠç¿ãç ç©¶ãæè²ãªãœãŒã¹ã®å©çšãæ¢ããããšã¯ãããŸãããæ°ããè åšã¯æ¯æ¥å±éãããŠãããè åšã«é¢ããç¥èãåŸãããšã¯CISOã®è²¬ä»»ã§ãããŸããæ°ããè匱æ§ãæ¥ã çºèŠãããŠãããããææ°ã®ã¬ããŒãããè匱æ§ã®ãããœãããŠã§ã¢ãç¹å®ããã€ã³ãã©ã«ããããé©çšããæ¹æ³ãè¿ éã«èŠã€ããããšãCISOã®è²¬åã§ãã
CISOã«å¿ èŠãªã¹ãã«
æ å ±ã»ãã¥ãªãã£ã®æŠç¥ã¯äŒæ¥ããšã«ç°ãªããåãçµã¿ããªãŒãããé©ä»»è ãç°ãªããŸããCISOã®åœ¹å²ã¯æç¢ºã«å®çŸ©ãããŠããŸãããCISO ã¯ããµã€ããŒã»ãã¥ãªãã£ã®åãçµã¿ãäž»å°ãã以å€ã«ãçµç¹æåã«é©åãããµã€ããŒã»ãã¥ãªãã£ã®å±éãšãªã¹ã¯ç®¡çã®ãã¹ããã©ã¯ãã£ã¹ãå®è·µã§ããå¿ èŠããããŸãã
ãµã€ããŒã»ãã¥ãªãã£ã«å¯Ÿããæ ç±ã¯ãçµç¹ã«ãšã£ãŠé·æçãªæè³ãšãªã人ç©ã®éèŠãªè奿æãšãªãããšããããããŸããCISO ã¯ãåŸæ¥å¡ãåºäžããŠããéçšã§å éšããæ¡çšãããããšããããŸãããåªãã CISO ã¯å€éšãããèŠã€ããããšãã§ããŸããCISOã¯ããªãŒããŒãšããŠã®åœ¹å²ã容æã«æããããããéåžžã®ããžãã¹æ £ç¿ã«ç²ŸéããŠããå¿ èŠããããCISOãITäºç®ãšãåªå é äœã決ããªããã€ã³ãã©ã«è³éãäŸçµŠããæ¹æ³ãçè§£ããŠããã°ãããžãã¹ã«ã圹ç«ã¡ãŸãã
ãã¹ããã©ã¯ãã£ã¹ãšããŠå®çŸ©ãããŠããã®ã¯ãNISTãšISOã®2ã€ã®äž»èŠãªãã¬ãŒã ã¯ãŒã¯ã§ããæ°ããCISOãããŒã ã«å ãããšãçŸåšã®ãã©ã¯ãã£ã¹ããã³ãããŒã¯ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãããã®ä»ã®ããžãã¹ããã»ã¹ã®ã¬ãã¥ãŒãè¡ãããŸãããã®ãããCISOã¯çŸåšã®ãã©ã¯ãã£ã¹ãæ€èšŒãããããæ¹åããèšç»ãæ§ç¯ããã¹ãã«ãå¿ èŠãšãªããŸãã
ã»ãšãã©ã®äŒæ¥ãåšå® å€åãåãå ¥ããŠãããããCISOã¯ã¯ã©ãŠããšã¯ã©ãŠãã€ã³ãã©ãåãå·»ããµã€ããŒã»ãã¥ãªãã£ã«ã€ããŠãçè§£ããŠããå¿ èŠããããŸãã仿¥ã®ã³ã³ãã¥ãŒãã£ã³ã°ç°å¢ã§ã¯ãã¯ã©ãŠãã®ç§»è¡ããªã³ãã¬ãã¹ã€ã³ãã©ãžã®çµ±åã¯äžè¬çãªããšã§ããCISOã¯ãåŸæ¥å¡ã®çç£æ§ãé«ããããã«ã¯ã©ãŠããæŽ»çšããæåã®æ¹æ³ã«ã€ããŠããªãã¬ãŒã·ã§ã³ããŒã ãéçºè ã«æç€ºã§ããªããã°ãªããŸããã
CISOã®å¿ èŠæ§
ç°å¢å ã®ãªã¹ã¯ã®æ°ãããããªããã°ãã©ã®ãããªãµã€ããŒã»ãã¥ãªãã£ã€ã³ãã©ãå¿ èŠãªã®ãããããŸãããCISOã¯ããããã¯ãŒã¯å šäœã®è匱æ§ã匱ç¹ãèŠã€ããããã«ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã宿œããŸããã»ãšãã©ã®å°èŠæš¡ãªçµç¹ã§ã¯ã誰ããªã¹ã¯ãæèããããšãªããããã€ãã®è匱æ§ãååšããŠããŸããCISOã¯ããªã¹ã¯ãç¹å®ãããããæ¯æ£ããããã®æŠç¥ãçå®ããŸãã
CISOãéãäž»ãªçç±ã¯ãCISOã®ç¥èãæŽ»çšãããªã¹ã¯ãäœæžããããã®èšç»ãäœæãããµã€ããŒã»ãã¥ãªãã£æŠç¥ãèšèšããããã§ããCISOãæçã§ãããã1ã€ã®çç±ã¯ãçµç¹ã«ã³ã³ãã©ã€ã¢ã³ã¹ããããããããšã§ããçµç¹ãç¹å®ã®ã³ã³ãã©ã€ã¢ã³ã¹ã»ã¬ã€ãã©ã€ã³ã«åŸããªããã°ãªããªãã®ã«ãç°å¢ãã³ã³ãã©ã€ã¢ã³ã¹ã«æºæ ããŠããªãå ŽåãããŒã¿äŸµå®³åŸã«äœååãã®ã³ã¹ããçºçããå¯èœæ§ããããŸãã
CISOãæ¡çšããäž»ãªçç±ã¯ãçµè²»ã®ç¯çŽãšãã©ã³ãã®è©å€ã®ç¶æã®2ã€ã§ããããŒã¿æŒæŽ©ã¯ã蚎èšããã©ã³ããžã®ãã¡ãŒãžãããŠã³ã¿ã€ã ãåçã®æå€±ã顧客ãã€ã€ãªãã£ãªã©ãäœååãã®æå€±ããããããŸããããŒã¿æŒæŽ©ã®é·æçãªåœ±é¿ã¯äœå¹Žãç¶ãããšããããå°èŠæš¡ãªäŒæ¥ã§ã¯åç£ããŠããŸãããšããããŸããCISOã¯ãåçã«åœ±é¿ãäžããããŒã¿æŒæŽ©ããçµç¹ãä¿è·ããèŠå¶èŠä»¶ã«æºæ ããçµç¹ãç¶æããŸãã
CISOã®ä»åŸ
ãµã€ããŒã»ãã¥ãªãã£ã®åéã«èº«ã眮ããšã誰ããå€åãé²åããç¶æ³ã«é©å¿ããå¿ èŠããããŸããæ°ããè åšã¯æ¥ã ç»å Žãããã®å€ããäŒæ¥ãæšçãšããŠããŸããCISOã¯æ°ããè åšã«å¯ŸåŠããŸãããããããã®CISOã¯ãææ°ã®ãã¯ãããžãŒãã©ã®ããã«ä¿è·ããããçè§£ããªããã°ãªããŸããã人工ç¥èœïŒAIïŒãã¡ã¿ããŒã¹ããœãŒã·ã£ã«ã¡ãã£ã¢ãéåã³ã³ãã¥ãŒãã£ã³ã°ããã®ä»å€ãã®æªæ¥æè¡ãªã©ãçè§£ããå¿ èŠããããŸãã
ã»ãšãã©ã®å Žåãæé«ã®ãµã€ããŒã»ãã¥ãªãã£ç°å¢ã¯ãŒããã©ã¹ãæŠç¥ã䜿çšããŠããããšã瀺åããŠããŸããCISO ã¯ããŒããã©ã¹ããçè§£ããã©ã®ãããªç°å¢ã§ãããã宿œããæ¹æ³ãç¥ã£ãŠããªããã°ãªããŸãããæ°ããæŠç¥ãæ¡çšããããšã¯ãå€ãæè¡ãæã€çµç¹ã«ãšã£ãŠã¯é£ãããããããŸããããããã£ãŠãCISOã¯ãã§ããã ãããŠã³ã¿ã€ã ãå°ãªãããŠãçµç¹ãæ°ãããã¬ãŒã ã¯ãŒã¯ã«å°ãããšãã§ããªããã°ãªããŸããã
ããŒãã£ã« CISO ã¯ãå°ä»»ã®è²¬ä»»è ãéããããªããããµã€ããŒã»ãã¥ãªãã£ã®ãªãŒããŒãå¿ èŠãªäŒæ¥ã«äººæ°ããããŸããããŒãã£ã« CISOïŒvCISOïŒã¯ãæšæºç㪠CISO ãšåãæ©èœããã¹ãŠå®è¡ããŸãããã»ãã¥ãªãã£ããŒã ããã«ã¿ã€ã ã§ç£ç£ããã®ã§ã¯ãªããçµç¹ãå©ããå¿ èŠãšããŠãããšãã«æ©èœããŸããCISOã¯é«äŸ¡ãªåŸæ¥å¡ã§ãããããvCISOã¯éåžžã®åžžå€åœ¹å¡ã眮ãäœè£ã®ãªãäžå°äŒæ¥ã«ãšã£ãŠãçµæžçãªéžæè¢ãšãªããŸãã
Proofpointã®CISOãã
Proofpointã¯ããµã€ããŒã»ãã¥ãªãã£ããŒããã©ã¹ããããã¯ãŒãã³ã°ãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã®èª²é¡ã«å¯ŸããŠCISOãæ¯æŽããããšãã§ãããªãœãŒã¹ãå«ãCISOãããæäŸããŠããŸãããŸããææ°ã®è åšããç£èŠãå°ã蟌ããæ²æ» ã«é¢é£ããææ°ã®æŠç¥ã«é¢ãã調æ»ã§ããCISOãæ¯æŽããŠããŸããCISOããã¯ããã®æå§ããšããŠæé©ãªå Žæã§ãã
ãã¯ã€ãããŒããŒãVoice of the CISO Reportãã§ã¯ãå幎ã®ãµã€ããŒã»ãã¥ãªãã£äºä»¶ãè åšãšæŠãããã®æ°ããªæŠç¥ãå€åãç¶ããCISOã®åœ¹å²ãšãã®èª²é¡ã«ã€ããŠã¬ãã¥ãŒããŠããŸãã®ã§ããã²ã芧ãã ããã
CISOã«é¢ããäžçã®èŠç¹ã¯ããCISO Perspectivesãã§ã芧ããã ããŸãã