ç®æ¬¡
ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã¯ãã¯ã©ãŠããžã®ç§»è¡ãšã¢ãã€ã«ã¯ãŒã«ãŒãåºçŸ©ã«æããèšèã§ãæ°ããã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹äžã®ãªã¹ã¯ãçã¿åºããŸãããã¯ã©ãŠãã¢ã«ãŠã³ãã®ä¹ã£åããéå°ã«å ±æãããŠããããŒã¿ãèªèšŒãããŠããªãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšãªã©ã¯ãã»ãã¥ãªãã£éšéã«å€§ããªèª²é¡ãçªãã€ããŠããŸããã¯ã©ãŠãã»ãã¥ãªãã£ã«ãšã£ãŠã¯ãITéšéãèš±å¯ããã¢ããªã±ãŒã·ã§ã³ã®å¯èŠåãšå¶åŸ¡ãéèŠã§ããäŒæ¥ã®å€ãã¯ãMicrosoft Office 365ã»Google G suiteã»Boxã»Dropboxã»ã»ãŒã«ã¹ãã©ãŒã¹ã»Slackã»AWSã»ServiceNowãªã©ãå®å šã«å©çšããããšèããŠããŸãã
ãµã€ããŒã»ãã¥ãªãã£æè²ãšãã¬ãŒãã³ã°ãå§ããŸããã
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ãšã¯?
ã¯ã©ãŠãã»ãã¥ãªãã£ãšã¯ãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãã©ãããã©ãŒã äžã®äººã ãããŒã¿ãã€ã³ãã©ã¹ãã©ã¯ãã£ããµã€ããŒæ»æãã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯ããä¿è·ããããã«äœ¿çšãããæè¡ãã¢ããªã±ãŒã·ã§ã³ãã³ã³ãããŒã«ãããã³ããªã·ãŒã®ã»ãããæããŸããã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãå€éšããã³å éšã®ã»ãã¥ãªãã£è åšã«å¯ŸåŠããããã«èšèšãããäžé£ã®ã»ãã¥ãªãã£å¯Ÿçã«äŸåããã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ããã³ããŒã¿ã¹ãã¬ãŒãžã®ã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ããã®ä»ã®äœ¿çšãªã¹ã¯ã管çããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãããŒã¿ãè³ç£ãä¿è·ããããšã§ãã¯ã©ãŠãããŒã¹ã®ãœãªã¥ãŒã·ã§ã³ã«äŸåããçµç¹ã«éèŠãªã»ãŒããã£ããããæäŸã§ããŸããçµæãæ å ±ã®ä¿¡é Œæ§ãšå¯çšæ§ãåäžããããŒã¿ä¿è·ã«é¢é£ããåæè²»çšãšç¶ç¶çãªã³ã¹ããåæžãããã¹ã±ãŒã©ããªãã£ã容æã«ãªããè€éãªæ»æãã人ãã·ã¹ãã ããã广çã«ä¿è·ããããšãã§ããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®èŠçŽ ã®äžã€ã«ãCASBïŒCloud Access Security Brokerãããã¯Cloud App Security Brokerã®ç¥ïŒããããŸããCASBã¯ããªã³ãã¬ãã¹ãã¯ã©ãŠãã«å°å ¥ã§ããã¯ã©ãŠããµãŒãã¹ãšã¯ã©ãŠããµãŒãã¹å©çšè ãšã®äžéã«å°å ¥ãããŸããã¯ã©ãŠãã§ã®ã¢ã¯ãã£ããã£ãç£èŠããæ»æããããã¯ããŠã»ãã¥ãªãã£ããªã·ãŒã匷åããŸã[1]ã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®ä»çµã¿
ã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãæè¡çããã³æç¶ãçãªå¯Ÿçã®çµã¿åãããå©çšããŠãã¯ã©ãŠãããŒã¹ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãã¢ããªã±ãŒã·ã§ã³ãããã³ããŒã¿ãæç¶çãªãµã€ããŒè åšããä¿è·ããŸããã¯ã©ãŠãã»ãã¥ãªãã£ã®åºæ¬ã¯ããŠãŒã¶ãŒãšããã€ã¹ã®èªèšŒãããŒã¿ãšãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãããã³ããŒã¿ãã©ã€ãã·ãŒã®ä¿è·ã確ä¿ããããšã§ãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã¯ã以äžãå®è·µããããšã«ãããã¯ã©ãŠãããŒã¹ã®è åšãã瀟å ã®å©çšè ãä¿è·ããŸãã
- å©çšè ãã¢ã¯ã»ã¹ã§ããã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãã©ãããã©ãŒã ãããã¯ãµãŒãã¹ãæããã«ãã
- æ»æãæ€ç¥ããããã«ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã®ã¢ã¯ãã£ããã£ãšæå³ããäŒæ¥ãå±éºã«ããããŠãããŠãŒã¶ãŒè¡åãç£èŠãã
- ãµã€ããŒæ»æè ãå©çšæš©éã®ãªã人ç©ãæ©å¯ããŒã¿ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãé²ã
- ã¯ã©ãŠãããŒã¹ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããä¹ã£åãããããšã黿¢ãã
- ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ ããªã·ãŒã匷åãã
åŸæ¥ã®ãµã€ããŒã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãåšå²ããã³ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã«çŠç¹ãåœãŠãã®ãšã¯ç°ãªããã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãèªèšŒããã»ã¹ãããŒã¿æå·åãå€èŠçŽ èªèšŒãªã©ã掻çšããŠäžæ£ã¢ã¯ã»ã¹ã鲿¢ããããŒã¿äžå¿ã®ã¢ãããŒããæ¡çšããŠããŸãã
CIAãã©ã€ã¢ããšããŠç¥ãããæ å ±ã»ãã¥ãªãã£ã¢ãã«ã®äžéšãšããŠãã¯ã©ãŠãã»ãã¥ãªãã£ã¯ããŒã¿ã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§ãç¶æãããããªãã¯ããã©ã€ããŒãããã€ããªããã¯ã©ãŠããµãŒãã¹ã®3ã€ã®äž»èŠãªã¯ã©ãŠãç°å¢ã§éçšãããŸããé©åãªç°å¢ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ãå©çšããå人ãŸãã¯çµç¹ã®çš®é¡ãããžãã¹ã®æ§è³ªãããã³ããŒã¿ã®ããŒãºã«äŸåããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®éèŠæ§
äŒæ¥ã¯ãååãææºäŒæ¥ãšãã¡ã€ã«ãªã©ã®ããŒã¿ãå ±æããããã«ãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãšãã¯ã©ãŠãããŒã¹ã®ã³ã©ãã¬ãŒã·ã§ã³ããŒã«ãã¡ãã»ãŒãžããŒã«ãå©çšããŠããŸããåæã«ãã¯ã©ãŠãäžã§ã®å ±æã¯ãèŠå¶ã®å¯Ÿè±¡ããŒã¿ãäŒæ¥ç§å¯ãæè¡èšèšãªã©ã®ç¥ç財ç£ãããã®ã»ãã®æ¥µç§äŒæ¥ããŒã¿ãå±éºã«ãããå¯èœæ§ããããŸãã
ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã€ã³ãã©ã¯ããµã€ããŒè åšããã®ä¿è·ãå¿ èŠã§ããã¯ã©ãŠãã»ãã¥ãªãã£ã¯ããã®ã¿ã¹ã¯ã«å°å¿µãããµã€ããŒã»ãã¥ãªãã£ã®äžåéã§ããã¯ã©ãŠãã»ãã¥ãªãã£ã¯ããŒã¿ä¿è·ã®ããã ãã§ãªããæ¥çãçµç¹ãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºãããè©å€äœäžãé²ããç Žå£çãªã€ãã³ããçºçããå Žåã®äºæ¥ç¶ç¶ã確ç«ããé«åºŠã«ã¯ã©ãŠãããŒã¹ã®ç°å¢ã§ç«¶äºåªäœæ§ãæäŸããã®ã«ã圹ç«ã¡ãŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãçµç¹ãç¹å®ã®è匱æ§ãè åšã«å¯ŸåŠããã®ã«äžå¯æ¬ ã§ãã瀟å¡ã®é倱ããã¬ãŒãã³ã°äžè¶³ã¯ã誰ã§ãã¢ã¯ã»ã¹ã§ããå ¬éãªã³ã¯ãä»ããŠãã¡ã€ã«ãéå°ã«å ±æãããªã©ã®ã¯ã©ãŠãã»ãã¥ãªãã£è åšãåŒãèµ·ããå¯èœæ§ããããŸããã€ã³ãµã€ããŒã«ããããŒã¿çªçãäžè¬çã§ããäŸãã°ãäŒç€Ÿãéè·ããå¶æ¥æ åœè ãã¯ã©ãŠãCRMãµãŒãã¹ããããŒã¿ãçãããšãèããããŸãã
ã·ã£ããŒITãšã¯ãITéšéããæ£åŒã«èš±å¯ãåŸãŠããªãã¯ã©ãŠãã¢ããªãã¯ã©ãŠããµãŒãã¹ãå©çšããããšããããŸããäžè¬çã«ãæ¿èªãããŠããªãSaaSã¢ããªã±ãŒã·ã§ã³ããã¡ã€ã«å ±æãSNSãã³ã©ãã¬ãŒã·ã§ã³ãWebäŒè°ãªã©ã«çšããŸããç€Ÿå æªæ¿èªã®ã¢ããªã«äŒæ¥ããŒã¿ãã¢ããããŒããããšãããŒã¿ãã©ã€ãã·ãŒãå± äœå°ã®èŠåã«éåããå¯èœæ§ããããŸãã
å¥ã®èª²é¡ãšããŠãOAuthã®èš±å¯ããããµãŒãããŒãã£ã®ã¢ããªãããã°ã©ã ããããŸããOAuthã«æ¥ç¶æžã¿ã®ãµãŒãããŒãã£ã¢ããªã¯ãMicrosoft 365ãGoogle Workspaceã®ãããªITæ¿èªãããã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããŸããæ°çŸã«ãåã¶ã¢ããªã瀟å ã®ã¯ã©ãŠãç°å¢ã§èŠã€ããããšã¯ããããããšã§ããåºç¯å²ã«ããŒã¿ã®å©çšèš±å¯ãäžããŠããŸãèšèšã®çãã®ããã«ããã®ãããªã¯ã©ãŠãã¢ããªã¯ãªã¹ã¯ããããŸãããŸããç°¡åã«æªçšã§ããããŒã¿ããããŸããããã«ãOAuthã®å±éºæ§ã¯ã1床ããã€ã¹ã§èªèšŒããŠããŸããšãç¡å¹ã«èšå®ãçŽããªãéããäŒæ¥ããŒã¿ã«ã¢ã¯ã»ã¹ããããšãã§ããç¶ç¶çã«ã¢ããªã±ãŒã·ã§ã³ã䜿çšã§ããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®èª²é¡
çŸä»£ã®ã¯ã©ãŠãã»ãã¥ãªãã£ã«ãããææ°ã®é²æ©ã«ããããããããããã®ã·ã¹ãã ã¯äŸç¶ãšããŠããã€ãã®ãªã¹ã¯ã課é¡ãããã³å¶éã«çŽé¢ããŠããŸããæãäžè¬çãªèª²é¡ã«ã¯ä»¥äžãå«ãŸããŸãã
- èšå®ãã¹: ã¯ã©ãŠãã»ãã¥ãªãã£ã®è匱æ§ã®äžã§æãäžè¬çãªãã®ã®1ã€ã§ããèšå®ãã¹ã¯ãã¯ã©ãŠããªãœãŒã¹ãé©åã«æ§æãããŠããªãå Žåã«çºçããŸããããã«ãããã¯ã©ãŠãã»ãã¥ãªãã£ã·ã¹ãã ã«é倧ãªã®ã£ãããçããæªæã®ããæ»æè ããã¹ã¯ãŒããäœçœ®æ å ±ããã®ä»ã®æ©å¯æ å ±ãçãããšãå¯èœã«ããŸãã
- äžæ£ã¢ã¯ã»ã¹: é床ã«èš±å®¹ãããã¯ã©ãŠãã¢ã¯ã»ã¹ãå¶éã®ãªãããŒããããã³ç§å¯ããŒã¿ç®¡çã®å€±æïŒäŸ: äžååã«ä¿è·ããããã¹ã¯ãŒããæå·éµãAPIããŒã管çè èªèšŒæ å ±ïŒã«ãããæªæã®ããæ»æè ãã¯ã©ãŠãããŒã¹ã®ãªãœãŒã¹ã«äŸµå ¥ã§ããããã«ãªããŸãã
- ããŒã¿æŒæŽ©: ããã¯ãçµç¹ã®èš±å¯ãèªèãªãã«æ©å¯æ å ±ãæœåºãããå Žåã«çºçããäžè¬çãªã¯ã©ãŠãã»ãã¥ãªãã£ãªã¹ã¯ã§ããèšå®ãã¹ãã©ã³ã¿ã€ã ä¿è·ã®æ¬ åŠã«ãããããŒã¿ãçãŸãããããªããçµæžçæå€±ãè©å€äœäžãæ³ç責任ãçºçããå¯èœæ§ããããŸãã
- å®å šã§ãªãã€ã³ã¿ãŒãã§ãŒã¹: ã€ã³ã¿ãŒãã§ãŒã¹ãAPIãé©åã«ä¿è·ããªããšãè åšã¢ã¯ã¿ãŒãã¯ã©ãŠãã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããéèæ å ±ããã¹ã¯ãŒããå¥åº·èšé²ãªã©ã®æ©å¯ããŒã¿ãçãããã®å ¥å£ãæäŸããŠããŸããŸãã
- ã¢ã«ãŠã³ãã®ä¹ã£åã: ãµã€ããŒæ»æè ã¯ãã¹ã¯ãŒãã¯ã©ãã¯æè¡ãå©çšããŠãã°ã€ã³èªèšŒæ å ±ãæšæž¬ãŸãã¯çã¿ãã¯ã©ãŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã䟵害ããŸããããã«ãããçµæžçæå€±ãæ å ±ã®æŒæŽ©ãè©å€äœäžãåŒãèµ·ããããããšããããŸãã
- 管çãããŠããªãã¢ã¿ãã¯ãµãŒãã§ã¹: çµç¹ãããŒã¿ã®ä¿è·æ¹æ³ãçè§£ããã«ã¯ã©ãŠãã«ç§»è¡ããå Žåãæ©å¯æ å ±ããªãœãŒã¹ãæ»æè ã«ãã£ãŠæªçšããããªã¹ã¯ã«ãããããå€ãã®åé¡ãçºçããŸãã
- 人çãšã©ãŒ: 匱ããã¹ã¯ãŒãã®äœ¿çšãããã£ãã·ã³ã°è©æ¬ºè¢«å®³ãŸã§ã人çãšã©ãŒã¯ã¯ã©ãŠãã»ãã¥ãªãã£ã·ã¹ãã ãå±éºã«ãããäžè¬çãªåé¡ã§ããçµ±èšã«ãããšãã¯ã©ãŠãããŒã¹ã®ããŒã¿æŒæŽ©ã®88%ã¯äººçãšã©ãŒã«èµ·å ããŠããŸãã
- äžååãªå€æŽç®¡ç: 倿Žç®¡çããã³å¶åŸ¡ãããã³ã«ãäžååãŸãã¯ç¡èŠããããšãèšå®ãã¹ãèŠéããããäžæ£ã¢ã¯ã»ã¹ãããŒã¿æŒæŽ©ãããŒã¿æµåºãçºçããå¯èœæ§ããããŸãã
çµç¹ããµã€ããŒã»ãã¥ãªãã£ããŒã ã¯ãã¯ã©ãŠããµãŒãã¹ãããã€ããŒã®è²¬ä»»ãã©ãã§çµãããèªç€Ÿã®è²¬ä»»ãã©ãããå§ãŸãã®ããæç¢ºã«ããéã«ã課é¡ã«çŽé¢ããŸãããããã®ã®ã£ããã¯è匱æ§ã«ã€ãªããå¯èœæ§ããããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£å¯Ÿç
仿¥ãçµç¹ã¯ããŒã¿ãä¿è·ããããã«è€æ°ã®çš®é¡ã®ã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã掻çšããŠããŸãããããã®ãœãªã¥ãŒã·ã§ã³ã¯ãç·åçãã€å¹æçãªã¯ã©ãŠãã»ãã¥ãªãã£å¯Ÿçã確ç«ããããã«äžç·ã«äœ¿çšããããšãã§ããŸãã
IAMïŒIdentity and Access ManagementïŒ
IAMã¯ãŠãŒã¶ãŒã®ã¢ã€ãã³ãã£ãã£ãšã¯ã©ãŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã管çããŸããé©åãªèªèšŒãèªå¯ãããã³ãŠãŒã¶ãŒç®¡çã確ä¿ããæš©éã®ãªãã¢ã¯ã»ã¹ã鲿¢ãããšåæã«ãç¹å®ã®ã¯ã©ãŠããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ãã人ãšããã®äººãå®è¡ã§ããã¢ã¯ã·ã§ã³ã«å¯Ÿãã现ããå¶åŸ¡ãæäŸããŸãã
ãããã¯ãŒã¯ãšããã€ã¹ã®ã»ãã¥ãªãã£
ãããã¯ãŒã¯ãšããã€ã¹ã®ã»ãã¥ãªãã£ã¯ãã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãšããã€ã¹ããããã¯ãŒã¯ã¬ãã«ã®æ»æãé²åŸ¡ããé©åãªæ§æã確ä¿ããŸãããã®ã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã«ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãIdPïŒIDãããã€ããŒïŒãVPNãå«ãŸããDDoSæ»æããã«ãŠã§ã¢ãããã³ãã®ä»ã®å€éšè åšããä¿è·ããŸãããšã³ããã€ã³ãä¿è·ããã³ã¢ãã€ã«ããã€ã¹ç®¡çããã¯ã©ãŠããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã«äœ¿çšãããããã€ã¹ã®ã»ãã¥ãªãã£ã確ä¿ããã®ã«åœ¹ç«ã¡ãŸãã
ã»ãã¥ãªãã£ç£èŠãšã¢ã©ãŒã
ç¶ç¶çãªç£èŠãæ€åºãããã³ã¢ã©ãŒãã¯ãIdPãSIEMã·ã¹ãã ãªã©ã®ããŒã«ã䜿çšããŠã¯ã©ãŠããªãœãŒã¹ã®ãªã¢ã«ã¿ã€ã ç£èŠãæäŸããçµç¹ãã»ãã¥ãªãã£è åšã«è¿ éã«å¯Ÿå¿ã§ããããæ¯æŽããŸããã»ãã¥ãªãã£ç£èŠãœãªã¥ãŒã·ã§ã³ã¯ãããŸããŸãªãœãŒã¹ããããŒã¿ãåéããã³åæããæœåšçãªã»ãã¥ãªãã£ã€ã³ã·ãã³ããç¹å®ããŠã¢ã©ãŒããçæããŸãã
CASBïŒCloud Access Security BrokerïŒ
CASBã¯ãçµç¹ã®ãªã³ãã¬ãã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãšã¯ã©ãŠãã®éã®ã²ãŒãããŒããŒãšããŠæ©èœããã¯ã©ãŠãã»ãã¥ãªãã£ã·ã¹ãã ã®äžçš®ã§ããCASBã¯ããã¹ãŠã®ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹å šäœã§ã»ãã¥ãªãã£ããªã·ãŒã广çã«ç£èŠããã³æœè¡ããããšãã§ããçµç¹ãã¯ã©ãŠãã®äœ¿çšç¶æ³ãææ¡ããèŠå¶èŠä»¶ã®éµå®ã匷å¶ããããšãå¯èœã«ããŸãã
ããŒã¿ã»ãã¥ãªãã£
ããŒã¿ã»ãã¥ãªãã£ã¯ãæå·åãããŒã¿ãã¹ãã³ã°ãã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšããŠããŒã¿ãäžæ£ã¢ã¯ã»ã¹ãæ¹ãããæå€±ããä¿è·ããŸããããã«ã¯ãä¿åäžã転éäžã䜿çšäžã®ããŒã¿ã®ä¿è·ãå«ãŸããŸããããŒã¿æŒæŽ©å¯ŸçïŒDLPïŒãœãªã¥ãŒã·ã§ã³ãã¢ã¯ã»ã¹å¶åŸ¡ãœãªã¥ãŒã·ã§ã³ãããã³æå·åãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãã¯ã©ãŠãå ã®æ©å¯ããŒã¿ãä¿è·ã§ããŸãã
ãã£ã¶ã¹ã¿ãªã«ããªãšäºæ¥ç¶ç¶ãã©ã³
ãã®éèŠãªãœãªã¥ãŒã·ã§ã³ã¯ãçœå®³æã«ã¯ã©ãŠããµãŒãã¹ã埩å ããããŠã³ã¿ã€ã ãæå°éã«æããããã®æŠç¥ãèšç»ããããšãå«ã¿ãŸãããã£ã¶ã¹ã¿ãªã«ããªã«ã¯ãéèŠãªããŒã¿ãšã¢ããªã±ãŒã·ã§ã³ãç¹å®ããç®æšåŸ©æ§æéïŒRTOïŒããã³ç®æšåŸ©æ§æç¹ïŒRPOïŒã確ç«ããŠãããŒã¿ãšã¢ããªã±ãŒã·ã§ã³ã蚱容æéå ã«åŸ©å ã§ããããã«ããããšãå«ãŸããŸãã
æ³çã³ã³ãã©ã€ã¢ã³ã¹
æ³çã³ã³ãã©ã€ã¢ã³ã¹ã¯ãããŒã¿ãã©ã€ãã·ãŒãšä¿è·ãå«ãæ³çããã³èŠå¶èŠä»¶ã«ã¯ã©ãŠããµãŒãã¹ãæºæ ããããšãä¿èšŒããŸããHIPAAãGDPRãããã³CCPAãªã©ã®èŠå¶ã«æºæ ããããšã¯ãæ©å¯ããŒã¿ãåãæ±ãçµç¹ã«ãšã£ãŠéèŠã§ããæ³çã³ã³ãã©ã€ã¢ã³ã¹ã«ã¯ãããŒã¿ãã©ã€ãã·ãŒãä¿è·ããããã®é©åãªã³ã³ãããŒã«ã®å®è£ ãšãã¯ã©ãŠããµãŒãã¹ãèŠå¶èŠä»¶ãæºãããŠããããšã®ç¢ºèªãå«ãŸããŸãã
ã¬ããã³ã¹
ã¬ããã³ã¹ã¯ãã¯ã©ãŠããµãŒãã¹ã®äœ¿çšã管çããé©åãªãªã¹ã¯ç®¡çãšã³ã³ãã©ã€ã¢ã³ã¹å ±åã確ä¿ããããã®ããªã·ãŒãšæé ã確ç«ããŸããã¯ã©ãŠããµãŒãã¹ãæ¥çã®èŠå¶ããã³åºæºã«æºæ ããããšãä¿èšŒããŸããã¬ããã³ã¹ã«ã¯ãã¯ã©ãŠããµãŒãã¹ã«é¢é£ãããªã¹ã¯ãç¹å®ããã³ç®¡çãããããã軜æžããããã®é©åãªã³ã³ãããŒã«ã確ç«ããããšãå«ãŸããŸãããŸããããŒã¿åé¡ãã¢ã¯ã»ã¹å¶åŸ¡ãããã³ã€ã³ã·ãã³ã察å¿ã®ããã®ããªã·ãŒãšæé ã確ç«ããããšãå«ãŸããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã·ã¹ãã ã®äœ¿çšã¯æ¬è³ªçã«å®å šã§ããããã«æãããããããŸãããããã®èª€è§£ã¯çå®ããããé¢ããŠããŸããå人ããã³çµç¹ã¯ãæ»æãããŒã¿æŒæŽ©ããè³ç£ãä¿è·ããããã«ã¯ã©ãŠãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãæ¡çšããã¹ãã§ãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®ãªãœãŒã¹ããåŸããããã¹ããã©ã¯ãã£ã¹ã«ã¯ä»¥äžãå«ãŸããŸãã
- 匷åãªãã¹ã¯ãŒãããªã·ãŒãšå€èŠçŽ èªèšŒãå®è£ ãã
- ããŒã¿ã転éäžããã³ä¿åäžã«æå·åãã
- 宿çã«ããŒã¿ãããã¯ã¢ãããããªã«ããªããã»ã¹ããã¹ããã
- è åšãæ€åºã察å¿ããããã®ã»ãã¥ãªãã£ç£èŠãšãã°èšé²ãå®è£ ãã
- ã·ã¹ãã ãšãœãããŠã§ã¢ãææ°ã®ããããšã¢ããããŒãã§åžžã«æŽæ°ãã
- æ©å¯ããŒã¿ããã³ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãèªå¯ããã人å¡ã®ã¿ã«å¶éãã
- 宿çã«ã»ãã¥ãªãã£ç£æ»ãšãªã¹ã¯è©äŸ¡ã宿œãã
- æç¢ºãªã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿èšç»ã確ç«ãã
- åŸæ¥å¡ã«ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãæè²ããæœåšçãªè åšã«ã€ããŠèªèããã
- ã»ãã¥ãªãã£ã®å®çžŸãè¯å¥œãªä¿¡é Œã§ããã¯ã©ãŠããµãŒãã¹ãããã€ããŒãéžæãã
çµç¹ãå éšã§å®æœããè¡åã«å ããŠãCASBã®ãµããŒããå©çšããããšã¯ãã¯ã©ãŠãä¿è·ã匷åããããã®éåžžã«äŸ¡å€ã®ããæè³ãšãªããŸãã
CASBãµãŒãã¹ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ã·ã¹ãã 管çã®4ã€ã®äž»èŠãªã¿ã€ããæäŸããŸãã
- å¯èŠæ§: ããã¯ãçµç¹ã®ã¯ã©ãŠããµãŒãã¹ã®å šäœåãçµ±åãããã¥ãŒã§ãããããã€ã¹ãå Žæã«é¢ä¿ãªãã¯ã©ãŠããµãŒãã¹ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã«é¢ãã詳现ãå«ã¿ãŸãã
- ããŒã¿ã»ãã¥ãªãã£: äžéšã®CASBã¯ãæãŸãããªã掻åãé²ãããã®ããŒã¿ã»ãã¥ãªãã£ããªã·ãŒã匷å¶ããæ©èœãæäŸããŸãããããã®ããªã·ãŒã¯ãç£æ»ãã¢ã©ãŒãããããã¯ãéé¢ãåé€ã衚瀺ã®ã¿ãªã©ã®ããŒã¿æŒæŽ©å¯ŸçïŒDLPïŒã³ã³ãããŒã«ãéããŠé©çšãããŸãã
- è åšé²æ¢: CASBã¯ãäžèŠãªããã€ã¹ããŠãŒã¶ãŒãããã³ç¹å®ã®ããŒãžã§ã³ã®ã¢ããªãã¯ã©ãŠããµãŒãã¹ã«ã¢ã¯ã»ã¹ããã®ãé²ãããã®é©å¿åã¢ã¯ã»ã¹å¶åŸ¡ãæäŸããŸããã¯ã©ãŠãã¢ããªã®ã¢ã¯ã»ã¹ã¯ããã°ã€ã³äžããã³ãã°ã€ã³åŸã«èгå¯ãããä¿¡å·ã«åºã¥ããŠå€æŽã§ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹: CASBã¯ãã¯ã©ãŠããµãŒãã¹ã®äœ¿çšã管çããŠããããšãçµç¹ã蚌æããã®ããµããŒãããŸããCASBã¯ãããŒã¿ã®æåšãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶[2]ãžã®æºæ ã®åªåãæ¯æŽããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£ã®è匱æ§
ãµã€ããŒç¯çœªè ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ã®è匱æ§ã匱ç¹ãæªçšããŠã貎éãªããŒã¿ãè³ç£ã«ã¢ã¯ã»ã¹ããããšããŸããäžåºŠæ»æè ãã¯ã©ãŠãã¢ã«ãŠã³ãã®èªèšŒæ å ±ãæã«å ¥ãããšãæ£èŠã®ãŠãŒã¶ãŒã«ãªãããŸããŠäººã ãéšããè³éãééãããããäŒæ¥ããŒã¿ãè§£æŸããããããŸãããŸããã¡ãŒã«ã¢ã«ãŠã³ããä¹ã£åã£ãŠã¹ãã ããã£ãã·ã³ã°ã¡ãŒã«ãé ä¿¡ããããšããããŸãã
1,000以äžã®ã¯ã©ãŠããµãŒãã¹ããã³ããš2,000äžä»¥äžã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã察象ãšãã調æ»ã§ã¯ã2019幎äžåæã ãã§1,500äžå以äžã®äžæ£ãã°ã€ã³è©Šè¡ããããŸããããã®ãã¡40äžå以äžãæåããŸããã調æ»å¯Ÿè±¡ã®ããã³ãã®çŽ85ïŒ ããµã€ããŒæ»æã®æšçãšãªãã45ïŒ ãå°ãªããšã1ã€ã®ã¢ã«ãŠã³ãã䟵害ãããŠããŸããã[3]
ãµã€ããŒç¯çœªè ã¯ãMicrosoft Office 365ãGoogle G Suiteãªã©ã®äººæ°ã®ããSaaSã¢ããªã±ãŒã·ã§ã³ãã¿ãŒã²ããã«ããåŸåããããŸãããããã®ã¢ããªã±ãŒã·ã§ã³ã¯ãäŒæ¥ã®ã³ãã¥ãã±ãŒã·ã§ã³ãéèŠãªããŒã¿ãžã®ã¢ã¯ã»ã¹ããŒãä¿æããŠãããã»ãŒãã¹ãŠã®åŸæ¥å¡ã䜿çšããŠããŸããæ»æè ã¯ãã¯ã©ãŠãã¢ã«ãŠã³ãã®èªèšŒæ å ±ã䟵害ããè匱ãªãŠãŒã¶ãŒãæªçšããããã«ãããŸããŸãªææ³ãšè€æ°ã®è匱æ§ãå©çšããŸããããã«ã¯ä»¥äžãå«ãŸããŸãã
- ç·åœããæ»æ: ç·åœããæ»æïŒãã«ãŒããã©ãŒã¹ã¢ã¿ãã¯ïŒã¯ãæ»æè ãå€ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®çµã¿åããã詊è¡ããŠæå¹ãªçµã¿åãããèŠã€ãã詊è¡é¯èª€ã®ææ³ã§ããèªååããŒã«ã䜿çšããŠå€§éã®èªèšŒæ å ±ãã³ãããè€æ°ã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®çµã¿åãããé²åºãããããšãç·åœããæ»æãã€ã³ããªãžã§ã³ãã«ããŠããŸãã
- é«åºŠãªãã£ãã·ã³ã°ãã£ã³ããŒã³: èªèšŒæ å ±ãã£ãã·ã³ã°ãšãåŒã°ãããããã®ã¿ãŒã²ãããçµã£ãå·§åŠãªãã£ã³ããŒã³ã¯ãããŸããŸãªåœ¢ã§äººã ãéšããŠèªèšŒæ å ±ãæããããŸããæ»æè ã¯éåžžããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ãçšããã¡ãŒã«ã§ãã£ãã·ã³ã°ãå®è¡ããŸãã
- ãã¹ã¯ãŒãã®äœ¿ããŸãã: ãã®äžè¬çãªã¯ã©ãŠãã»ãã¥ãªãã£ã®è åšã¯ãè€æ°ã®ã¢ã«ãŠã³ãã§åããã¹ã¯ãŒãã䜿çšããããšã«ãã£ãŠç¹åŸŽä»ããããŸããæ»æè ãç¡é¢ä¿ãªããŒã¿æŒæŽ©ããã¢ã«ãŠã³ãã®èªèšŒæ å ±ãæã«å ¥ãããšããã¹ã¯ãŒãã®äœ¿ããŸãããå©çšããŠä»ã®æ©å¯ã¢ã«ãŠã³ããããŒã¿ã«äŸµå ¥ããããšãã§ããŸãã
- ããŒã¿æå€±ãšç¥ç財ç£ã®çªç: éåžžã®æ¥åæ¥ã«ã¯ãã¯ã©ãŠãããŒã¹ã®ã³ã©ãã¬ãŒã·ã§ã³ãã¡ãã»ãŒãžã³ã°ããŒã«ãä»ããŠååãããŒãããŒãããã³ãã®ä»ã®äººã ãšæ å ±ãå ±æããŸããããããåŸæ¥å¡ã®ã¯ã©ãŠãã»ãã¥ãªãã£ã«é¢ãããã¬ãŒãã³ã°ã®æ¬ åŠãåŸæ¥å¡ã®æªæã«ãããæ©å¯ããŒã¿ãèŠãŠã¯ãããªã人ã«å ±æãããå¯èœæ§ããããŸãã
- æªæã®ãããã¡ã€ã«å ±æ: ãã£ãã·ã³ã°ãªã³ã¯ãèªèšŒæ å ±ã®çé£ããŒã«ãããŠã³ããŒããŒããããã®æ»æã«é垞䜿çšãããŸããè åšã¢ã¯ã¿ãŒã¯ãDropboxãªã©ã®ã¯ã©ãŠããµãŒãã¹ãéããŠãã«ãŠã§ã¢ãé åžããããšããããŸãã
- ããŒã¿æŒæŽ©: ã¯ã©ãŠãã»ãã¥ãªãã£ã«é¢é£ããæãé倧ãªãªã¹ã¯ã®1ã€ã¯ãããŒã¿æŒæŽ©ã®å¯èœæ§ã§ããããã«ãŒã¯ã¯ã©ãŠãããŒã¹ã®ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããŠãéèããŒã¿ãå人æ å ±ãç¥ç財ç£ãªã©ã®æ©å¯æ å ±ãçãããšãã§ããŸãã
- ã·ã£ããŒIT: äŒæ¥å ã®äººã ãéšéããITã»ãã¥ãªãã£ãããŒãžã£ãŒã®æ¿èªãèªèãªãã«æ°ããã¯ã©ãŠãã¢ããªããµãŒãã¹ãå°å ¥ããããšããããããŸãããããã®ãµãŒãã¹ã¯ãããŒã¿æå€±ãããŒã¿ã®éå°å ±æãã³ã³ãã©ã€ã¢ã³ã¹ã®åé¡ãªã©ãåŒãèµ·ããå¯èœæ§ããããŸãã
- å éšè åš: ã¯ã©ãŠãããŒã¹ã®ã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããåŸæ¥å¡ãå¥çŽè ããæå³çãŸãã¯æå³ããã«ããŒã¿æŒæŽ©ãåŒãèµ·ãããããããŒã¿ãçãã ããæ©å¯æ å ±ãæŒããããããããšããããŸãã
- 忣åãµãŒãã¹æåŠïŒDDoSïŒæ»æ: ã¯ã©ãŠãããŒã¹ã®ã·ã¹ãã ã¯ãã·ã¹ãã ãéè² è·ã«ããŠæ£åœãªãŠãŒã¶ãŒãã¯ã©ãŠããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããªãããDDoSæ»æã®æšçã«ãªãããšããããŸãã
- å®å šã§ãªãAPI: ã¯ã©ãŠãããŒã¹ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããã«äœ¿çšãããã¢ããªã±ãŒã·ã§ã³ããã°ã©ãã³ã°ã€ã³ã¿ãŒãã§ãŒã¹ïŒAPIïŒã¯ãæ³šå ¥æ»æãäžéè æ»æãªã©ã®æ»æã«å¯ŸããŠè匱ã§ããå¯èœæ§ããããŸãã
- å ±æã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§: ã¯ã©ãŠãããŒã¹ã®ã·ã¹ãã ã¯å ±æã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããããšãå€ãã1ã€ã®é¡§å®¢ã®ã·ã¹ãã ã«è匱æ§ããããšãåãã€ã³ãã©ã¹ãã©ã¯ãã£äžã®ãã¹ãŠã®é¡§å®¢ã®ããŒã¿ãé²åºããå¯èœæ§ããããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯: ã¯ã©ãŠãããŒã¹ã®ã·ã¹ãã ã¯ãHIPAAãPCI-DSSãGDPRãªã©ã®ããŸããŸãªèŠå¶ãæšæºã«æºæ ããå¿ èŠããããŸãããããã®èŠå¶ã«æºæ ããªããšãæ³çããã³è²¡æ¿çãªçœ°åãç§ãããå¯èœæ§ããããŸãã
äŒæ¥ã¯ãå€åãç¶ãããµã€ããŒã»ãã¥ãªãã£èŠå¶ã«çŽé¢ããŠãã¯ã©ãŠãã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯ã®å¢å€§ã«çŽé¢ããŠããŸããæ¿åºãæ¥çã®èŠå¶ã«ãããã¯ã©ãŠãå ã®ããŒã¿ã®æåšãšå ±ææ¹æ³ãææ¡ããããšãæ±ããããŠããŸããæ¬§å·é£åäžè¬ããŒã¿ä¿è·èŠåïŒGDPRïŒã¯ãæ°çŸäžã®çµç¹ã«åœ±é¿ãäžããŠããŸãããã®ãããæ°ããèŠåã«æºæ ããèšç»ãç«ãŠãããšããã¹ãŠã®çµç¹ã«ãšã£ãŠéèŠã§ãã
仿¥ã®æ»æã¯æè¡ã§ã¯ãªã人ãã¿ãŒã²ããã«ããŠããŸããããã¯ã¯ã©ãŠãã§ããªã³ãã¬ãã¹ã§ãåæ§ã§ããäŒæ¥ãã¡ãã»ãŒãžã³ã°ããã³ã³ã©ãã¬ãŒã·ã§ã³ãã©ãããã©ãŒã ãäŒæ¥ãããã¯ãŒã¯ããã¯ã©ãŠãã«ç§»è¡ããã«ã€ããŠãæ»æã«å¯ŸããŠè匱ã«ãªããŸãã
ãµã€ããŒã»ãã¥ãªãã£æŠç¥
幞ãã«ããã¯ã©ãŠãã»ãã¥ãªãã£ã匷åããããã«ãçµç¹ããµã€ããŒã»ãã¥ãªãã£ããŒã ãå©çšã§ããå€ãã®ã»ãã¥ãªãã£æŠç¥ããããŸããã¯ã©ãŠãããŒã¹ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããããšãããããŒã¿ã®æå·åãããã¯ã¢ãããŸã§ãã¯ã©ãŠãã»ãã¥ãªãã£ã®ããã®ããã€ãã®æŠç¥ã以äžã«ç€ºããŸãã
ã¯ã©ãŠãããŒã¹ã®ã»ãã¥ãªãã£è åšããä¿è·ãã
ç¹°ãè¿ãã«ãªããŸããããµã€ããŒç¯çœªè ã¯æè¡ã§ã¯ãªã人ã ãã¿ãŒã²ããã«ããåŸåããããMicrosoft Office 365ãGoogle G Suiteãªã©ã®äººæ°ã®ããã¯ã©ãŠãæäŸã®SaaSã¢ããªã±ãŒã·ã§ã³ãå©çšããŸããåºç¯ãªã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãåããCASBã¯ã仿¥ã®äººäžå¿ã®è åšã«å¯Ÿããæè¯ã®é²åŸ¡ãæäŸããŸãã
匷åãªèªèšŒã¡ã«ããºã ã䜿çšãã
å€èŠçŽ èªèšŒïŒMFAïŒã¯ãã¯ã©ãŠããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã«è€æ°ã®åœ¢åŒã®èªèšŒããŠãŒã¶ãŒã«èŠæ±ããéèŠã§å®è£ ã容æãªã»ãã¥ãªãã£å¶åŸ¡ã§ããããã«ã¯ããã¹ã¯ãŒããPINãçäœæ å ±ãããŒã¯ã³ãã¹ããŒãã«ãŒããªã©ã®ãŠãŒã¶ãŒãæã£ãŠãããã®ãå«ãŸããŸããMFAã¯ããŠãŒã¶ãŒã®ãã¹ã¯ãŒããæŒæŽ©ããå Žåã§ããã¯ã©ãŠããªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ãå€§å¹ ã«è»œæžããŸãã
ã¯ã©ãŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éãã
ãã1ã€ã®éèŠãªæŠç¥ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ã«ãããŸããç¹ã«ãã¯ã©ãŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¿ èŠãšãããŠãŒã¶ãŒã«éå®ããããšãéèŠã§ããããã«ã¯ãçµç¹å ã§ã®åœ¹å²ã«åºã¥ããŠãŠãŒã¶ãŒã«æš©éãä»äžãã圹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ã®å®è£ ããç¹å®ã®ã¯ã©ãŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éãããããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ã®äœ¿çšãå«ãŸããŸãã
ããŒã¿ãããã¯ã¢ãããã
ããŒã¿ããã¯ã¢ããã¯ãããŒã¿æŒæŽ©ãã»ãã¥ãªãã£äŸµå®³ãçºçããå Žåã®ããŒã¿åŸ©æ§ã®ããã®ã¯ã©ãŠãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã§ããããã¯ã¢ããã¯å®æçã«å®è¡ããäž»ããŒã¿ã¹ãã¬ãŒãžãšã¯å¥ã®å®å šãªå Žæã«ä¿ç®¡ããå¿ èŠããããŸããããŒã¿æå€±ããã®åŸ©æ§ãå©ããã ãã§ãªããèŠå¶èŠä»¶ã®éµå®ãäºæ¥ç¶ç¶æ§ã®ç¢ºä¿ã«ã圹ç«ã¡ãŸãã
ã·ã¹ãã ãææ°ã®ç¶æ ã«ä¿ã€
ãœãããŠã§ã¢ãšã·ã¹ãã ãææ°ã®ç¶æ ã«ä¿ã€ããšã¯ãæ¢ç¥ã®è匱æ§ã®ãªã¹ã¯ã軜æžããããã®éèŠãªã»ãã¥ãªãã£å¯Ÿçã§ããããã«ã¯ãã»ãã¥ãªãã£ããããæŽæ°ãå©çšå¯èœã«ãªã£ããããã«é©çšããããšãããã³å®æçã«ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ããã®ä»ã®ã»ãã¥ãªãã£ãœãããŠã§ã¢ãæŽæ°ããããšãå«ãŸããŸãã
瀟å¡ãæè²ãã
ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã¯ãã©ã®ã»ãã¥ãªãã£ããã°ã©ã ã«ãæ¬ ãããªãèŠçŽ ã§ãã瀟å¡ã«ã¯ã©ãŠãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãæè²ããããšã§ãã»ãã¥ãªãã£ã®éèŠæ§ãšçµç¹ã®ããŒã¿ããã³ã·ã¹ãã ãä¿è·ããäžã§ã®åœ¹å²ãçè§£ãããããšãã§ããŸããããã«ã¯ããã¹ã¯ãŒã管çããã£ãã·ã³ã°ã®èªèããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æ€åºã«é¢ãããã¬ãŒãã³ã°ãå«ãŸããŸãã
ã¯ã©ãŠããªãœãŒã¹ã宿çã«ç£èŠãã
ç£èŠã¯ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããè¿ éã«æ€åºã察å¿ããããã®éèŠãªã»ãã¥ãªãã£å¯Ÿçã§ãããããã¯ãŒã¯ãã©ãã£ãã¯ãã·ã¹ãã ãã°ããŠãŒã¶ãŒã®æŽ»åãç£èŠããŠãäžå¯©ãªè¡åãæœåšçãªã»ãã¥ãªãã£è åšãç¹å®ããããšãå«ãŸããŸãã
ã³ã³ãã©ã€ã¢ã³ã¹ãç¶æãã
åŸæ¥å¡ãå¥çŽè ãããŒãããŒãã¯ã©ãŠãå ã§ããŒã¿ãå ±æããã«ã€ããŠãéåã®ãªã¹ã¯ãå¢å ããŸããããããéåãæ€åºã鲿¢ããããã«ã¯ããªã¹ã¯èªèåã®ã¯ã©ãŠãã»ãã¥ãªãã£ãå¿ èŠã§ããããã«ãæ¿åºèŠå¶ãæ¥çã®èŠä»¶ã«æºæ ããããšãäžå¯æ¬ ã§ããããã«ã¯ã瀟äŒä¿éçªå·ãçå¹Žææ¥ãªã©ã®å人ãç¹å®ã§ããæ å ±ïŒPIIïŒãã¯ã¬ãžããã«ãŒãæ å ±ïŒPCIïŒãä¿è·å¯Ÿè±¡ä¿å¥æ å ±ïŒPHIïŒãå«ãŸããŸãã
ç°å¢å ã®ã¯ã©ãŠãã¢ããªã管çãã
ã¯ã©ãŠãæäŸã®ã¢ããªã®å¢å ãèãããšããããã®ã¢ããªã®äœ¿çšã管çããããšãéèŠã§ããå¹³åçãªäŒæ¥ã«ã¯çŽ1,000ã®ã¯ã©ãŠãã¢ããªãããããã®äžã«ã¯æ·±å»ãªã¯ã©ãŠãã»ãã¥ãªãã£ã®ã®ã£ããããããã®ããããŸãããããã¯GDPRãªã©ã®ããŒã¿æåšèŠå¶ã«éåããå¯èœæ§ããããŸããããã«ãæ»æè ã¯ãµãŒãããŒãã£ã®ã¢ããªã³ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãå©çšããŠã人ã ã«æ¿èªæžã¿ã®SaaSã¢ããªãžã®åºç¯ãªã¢ã¯ã»ã¹ãèš±å¯ãããããšããããããŸãã
ã¯ã©ãŠãã¢ããªã®ã¬ããã³ã¹æ©èœã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ã®è åšã«å¯ŸããéèŠãªå¯èŠæ§ãæäŸããŸãããŸãããšã³ããŠãŒã¶ãŒã«ã¢ã©ãŒããçºããæå°ããã¯ã©ãŠãã¢ã¯ã»ã¹ã®èªåå¿çïŒèš±å¯ãèªã¿åãå°çšããããã¯ãªã©ïŒãèšå®ããããã®éèŠãªã³ã³ãããŒã«ãæäŸããŸãã
ãããã®ãã³ãã«å ããŠã匷åãªæ€åºã修埩ããªã¹ã¯ããŒã¹ã®èªèšŒæ©èœãåããåºç¯ãªã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãæäŸããCASBã¯ããã«ãŒããã©ãŒã¹ã¢ã¿ãã¯ããã£ãã·ã³ã°æ»æãæªæã®ãããã¡ã€ã«å ±æãªã©ã仿¥ã®äººäžå¿ã®è åšã«å¯Ÿããæè¯ã®é²åŸ¡ãæäŸããŸãã
ã¯ã©ãŠãã»ãã¥ãªãã£æŠç¥ã®èŠçŽ
匷åãªã¯ã©ãŠãã»ãã¥ãªãã£æŠç¥ã«ã¯ãããã€ãã®éèŠãªèŠçŽ ãå«ãŸããŸãã以äžããã®èŠçŽ ã§ãã
- äžæ£ã¢ã¯ã»ã¹ã鲿¢ããããã®å€èŠçŽ èªèšŒïŒMFAïŒãšåœ¹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ãå«ã匷åãªãŠãŒã¶ãŒã»ãã¥ãªãã£ã·ã¹ãã
- ã¯ã©ãŠããµãŒãã¹ãããã€ããŒã®çµç¹å ã§ã®ããŒã¿åãæ±ãã倿Žç®¡çãããã³å éšã³ãã¥ãã±ãŒã·ã§ã³ã«é¢ããæç¢ºãªããªã·ãŒãšæé
- å°çšã®æå·éµãèšç®ãªãœãŒã¹ããããã¯ãŒã¯ãªã³ã¯ãããã³ã¹ãã¬ãŒãžã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããé«åºŠã«å®å šãªã¯ã©ãŠãä¿è·ãœãªã¥ãŒã·ã§ã³
- APIã«ãã£ãŠæäŸãããæ»æé¢ã®è¿œè·¡ãæ§æãããã³ç£èŠãå«ãå®å šãªAPI
- ã»ãã¥ãªãã£äŸµå®³ãçœå®³ãçºçããå Žåã®äºæ¥ç¶ç¶ã確ä¿ããããã®ãã£ã¶ã¹ã¿ãªã«ããªããã³åé·åæé
- éçããã³åçã»ãã¥ãªãã£ããªã·ãŒãæ¹åããããã®åçºããè匱æ§åæãå«ããªã¹ã¯è©äŸ¡ãã¬ãŒã ã¯ãŒã¯
- æ©ææ®µéã§ã®ã»ãã¥ãªãã£è匱æ§ã鲿¢ããããã®å®çŸ©ãããååããœãªã¥ãŒã·ã§ã³ãããã³ã¢ãŒããã¯ãã£ãå«ãã¯ã©ãŠãã«çµ±åããããµã€ããŒã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³
ãããã®èŠçŽ ã¯ãæ©å¯æ§ãå®å šæ§ãããã³å¯çšæ§ïŒCIAïŒãç¶æããããšãšå ±ã«ããµã€ããŒæ»æã鲿¢ããå¿ èŠãªãšãã«å¿ èŠãªå Žæã§ç確ãªå¯Ÿçãè¬ããããã®åŒ·åºãªã¯ã©ãŠãã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã確ç«ããããã®åºæ¬ãšãªããŸãã
Proofpointã®ã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³
Proofpointã¯ãã¡ãŒã«ãã¯ã©ãŠãã¢ããªãéããŠäººã ãçãé«åºŠãªè åšããä¿è·ããããã®ããŸããŸãªã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãæäŸããŠããŸããProofpointãæäŸããããŒã«ããã³ãã©ãããã©ãŒã ã«ã¯ä»¥äžãå«ãŸããŸãã
- è åšé²åŸ¡: æªæã®ãããã¡ã€ã«ãå®å šã§ãªãURLã䜿çšããæ¢ç¥ããã³æ°ããè åšãæ€åºãåæãããã³ãããã¯ããããã«èšèšãããŠããŸãã
- ãŠã§ãã»ãã¥ãªãã£: ãŠã§ãããŒã¹ã®è åšã«å¯Ÿããå¯èŠæ§ãæäŸãããªã¹ã¯ã®é«ããŠã§ããµã€ããã¯ã©ãŠããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ãããŠãŒã¶ãŒããªã³ã©ã€ã³äžã®ããŒã¿ãä¿è·ããŸãã
- ããŒã¿é²åŸ¡: è€æ°ã®è£œåãçµã¿åãããŠããŒã¿ãé²åŸ¡ããå éšãªã¹ã¯ã調æ»ããã¯ã©ãŠãè åšããããã¯ããŸãã
Proofpointã®ã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ãæ©å¯ããŒã¿ããã³ãªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã鲿¢ãããŠãŒã¶ãŒã®ã¯ã©ãŠãããŒã¹ã®ã¢ã«ãŠã³ãã®ä¹ã£åããä¿è·ããããšãç®çãšããŠããŸãã詳现ã«ã€ããŠã¯ãProofpointã«ãåãåãããã ããã
[1] Gartner Inc. âMagic Quadrant for Cloud Access Security Brokersâ
[2] Ibid.
[3] Proofpoint. âCloud Attacks Prove Effective Across Industries in the First Half of 2019â (ã2019幎äžåæã®åæïŒã¯ã©ãŠãæ»æãããŸããŸãªæ¥çã«å¯ŸããŠå¹æçã§ãã£ãããšã倿ã)