ç®æ¬¡
å®çŸ©
äŒæ¥ã®ã€ã³ãã©ãããŒã¿ã»ã³ã¿ãŒã«å容ãããŠããå Žåããã®ç¬¬äžè æ ç¹ã®ç©ççã»ä»®æ³çãªå®å šæ§ã確ä¿ããããšãäžå¯æ¬ ã§ããããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã«ã¯ãäŒæ¥ããŒã¿ãæ»æè ããå®ãããã®ç©ççããã³ä»®æ³çãªãµã€ããŒã»ãã¥ãªãã£ãå«ãŸããŸããã»ãšãã©ã®ããŒã¿ã»ã³ã¿ãŒã«ã¯ã倿°ã®äŒæ¥ã®æ©å¯ããŒã¿ãä¿ç®¡ãããŠããããããã£ã1ã€ã®è匱æ§ãæ°åã®äŒæ¥ã®æ å ±æŒããã«ã€ãªããå¯èœæ§ããããŸããããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã¯ãããŒã¿æŒãããé²ãã ãã§ãªããäŒæ¥ã®ã€ã³ãã©ãã¯ã©ãŠãäžã«ãªãããŒãããããµãŒãã¹ã®çšŒåæéãšå®å šæ§ã確ä¿ããŸãã
ç¡æãã©ã€ã¢ã«
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
ããŒã¿ã»ã³ã¿ãŒã®å®å šæ§ã確ä¿ããæ¹æ³
å€ãã®äŒæ¥ã«ãããŠãããŒã¿ã«å¯Ÿããæå€§ã®è åšã¯ããœãããŠã§ã¢ããããã¯ãŒã¯ã€ã³ãã©ã®è匱æ§ãèŠã€ãåºããµã€ããŒæ»æè ã§ããããŒã¿ã»ã³ã¿ãŒã§ã¯ãåãçš®é¡ã®è åšããä¿è·ããã ãã§ãªããã€ã³ãã©ãç©ççã«ä¿è·ãããšãã圹ç®ãæãããªããã°ãªããŸããããããã€ããŒã¯ãèªèšŒãç¶æããããã«åŸããªããã°ãªããªãç¬èªã®ã³ã³ãã©ã€ã¢ã³ã¹åºæºããããŸãããããããããã®åºæºã¯ãæé ãé«åºŠãªãµã€ããŒã»ãã¥ãªãã£ã®å®è£ ãæ£ããè¡ããŠãããã©ããã確èªããããã«ç£æ»ãããŠããŸãã
ç©ççã»ãã¥ãªãã£
ããŒã¿ã»ã³ã¿ãŒã¯ã倧éœåžããé¢ããåççãªå Žæã«å»ºèšãããŸããããã¯ãç©ççãªã»ãã¥ãªãã£ã®ããã§ããããŸãããå°åã®äœå® ãäŒæ¥ã«åœ±é¿ãäžããã«ããŒã¿ã»ã³ã¿ãŒãéå¶ããããã§ããããŸããé éå°ã«ãããããç©ççãªè åšã¯ã»ãšãã©ãããŸããããããŒã¿ã»ã³ã¿ãŒãæšçãšããŠæ»æè ãæœèšå ã«å ¥ã£ãŠããå¯èœæ§ããããŸããæ»æè ãæœèšå ã«äŸµå ¥ããå ŽåãUSBãªã©ã®ç©çããã€ã¹ã䜿ã£ãŠãµãŒããŒããããŒã¿ãåãåºãå¯èœæ§ããããŸãã
第äžã®é²åŸ¡ã¯ãåšå²ã«èšçœ®ãããã«ã¡ã©ãšèŠåå¡ã§ããããŒã¿ã»ã³ã¿ãŒã§ã¯ãå ¥å£ã«ã«ã¡ã©ãé 眮ããŠããŸããããŒã¿ã»ã³ã¿ãŒã«ã¯ã¬ã©ã¹çªããªãã®ã§åé¡ã«ã¯ãªããŸããããã©ããªãã¢ã§ãç©ççã»ãã¥ãªãã£ã®ãªã¹ã¯ã«ãªããŸããã«ã¡ã©ãé åãèŠåå¡ããã®ã¬ãã«ã®æ»æããå®ã£ãŠãããŸãã
æ»æè ããã¢ãééã§ããã°ã次ã®ç©ççã»ãã¥ãªãã£ã¯ãã¡ã©ããŒã±ãŒãžïŒå°äœã«å²ãŸãã空éïŒã§ããé©åãªéµããªããã°ãæ»æè ã¯ãã¡ã©ããŒã±ãŒãžãééããããšãã§ããŸãããéµã«ã¯ãç©ççãªããŒãã»ãã¥ãªãã£ããã€ã¹ã«å ¥åãããããŒã³ãŒããã¹ãã£ããä»ããŠã¹ã©ã€ãããã«ãŒãããŸãã¯çäœèªèšŒã·ã¹ãã ããããŸããçäœèªèšŒã·ã¹ãã ã¯æãå®å šã§ãããæãã³ã¹ããããããŸãããã£ã¢4ã¬ãã«ã®ããŒã¿ã»ã³ã¿ãŒã§ã¯ãã»ãã¥ãªãã£ã¬ã€ã€ãŒãšããŠå¿ ãçäœèªèšŒãæ¡çšããŠããŸãã
ããŒã¿ã»ã³ã¿ãŒã§ã¯ãæ·å°å ãæ©ã人ãã»ãšãã©ããªãããã蚪åè ã¯æ³šææ·±ãç£èŠãããŸããæ¥èšªè ãããå Žåã¯ãæ©åšãžã®ã¢ã¯ã»ã¹ãå¶éãããåŸæ¥å¡ã®ãšã¹ã³ãŒããå¿ èŠãšãªããŸããæ¥èšªè ã«ã¯æ¥èšªè ã§ããããšã瀺ããããžãæž¡ãããæ¥èšªè ãæ·å°å ã«å°çãããšããšéåºãããšãã«ã¯ãã°ãèšé²ãããŸãã
ä»®æ³çã»ãã¥ãªãã£
ããŒã¿ã»ã³ã¿ãŒããµã€ããŒæ»æè ããå®ãããã«ã¯ãããã€ãã®æŠç¥ãçšããããŸãããªã³ãã¬ãã¹ã®ã€ã³ãã©ãæã€äŒæ¥ã¯ãããŒã¿ã»ã³ã¿ãŒã§äœ¿çšãããŠããæŠç¥ã®å€ããå©çšããããšãã§ããŸããäžè¬çãªãã«ãŠã§ã¢ãä»®æ³æ»æã®å€ããåé¿ããããã«ãããŒã¿ã»ã³ã¿ãŒã¯å³æ Œãªç£èŠãç£æ»ã«ãŒã«ãéµå®ããŠããŸãã
ããŒã¿ã»ã³ã¿ãŒã®ãªãœãŒã¹ãå©çšãããã¹ãŠã®ãŠãŒã¶ãŒã¯ãä»ã®ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ãæ å ±ã«ã¢ã¯ã»ã¹ã§ããªãããã«ããå¿ èŠããããŸããããŒã¿ã»ã³ã¿ãŒã§ã¯ããã¹ãŠã®è³ç£ãšãã©ãã£ãã¯ã®æŽ»åã360åºŠææ¡ã§ããSIEM (Security Information and Event Management) ããŒã«ã䜿çšããã®ãäžè¬çã§ãããããã®ããŒã«ã¯ããªã¹ã¯ç®¡çãè åšæ€ç¥ã¢ãã¿ãªã³ã°ãšçµã¿åãããŠãçãããã¢ã¯ãã£ããã£ãç¹å®ããŸãã
ãããã¯ãŒã¯æŽ»åã¯ãŸãŒã³ããšã«åºåããããŠããŸãããã®ãµã€ããŒã»ãã¥ãªãã£ææ³ã¯ãäŒæ¥ã®ãããã¯ãŒã¯èšå®ãšå€§å·®ãããŸããããã¯ããã«å³ããã顧客ã®ãã©ãã£ãã¯ãä»ã®é¡§å®¢ããŒã¿ãšçžäºäœçšããããé²åºãããããŠã¯ãããŸããããããã¯ãŒã¯æ§æã¯ã顧客ãä»®æ³ç°å¢äžã§ç¬èªã®ãœãããŠã§ã¢ãèªç±ã«å®è¡ã§ããããã«ããäžæ¹ã§ã顧客ã®ãœãããŠã§ã¢å ã®è匱æ§ããä»ã®é¡§å®¢ãããŒã¿ã»ã³ã¿ãŒãä¿è·ããå¿ èŠããããŸãã
ããŒã¿ã»ã³ã¿ãŒã®ã€ã³ãã©ã«ã¢ããªã±ãŒã·ã§ã³ãé åããåã«ã培åºçã«äŸµå ¥ãã¹ããè¡ããè匱æ§ããªããã³ãŒãã確èªããŸããããŒã¿ã»ã³ã¿ãŒã®ç°å¢ã«ãã«ãŠã§ã¢ãäŸµå ¥ãããšãããŒã¿ã»ã³ã¿ãŒã ãã§ãªããããŒã¿ã»ã³ã¿ãŒãå©çšãããã¹ãŠã®é¡§å®¢ã®ã»ãã¥ãªãã£ã«æªåœ±é¿ãåãŒãå¯èœæ§ããããŸãã
ã¯ã©ãŠã ã»ãã¥ãªãã£
人ãšããŒã¿ãä¿è·ãã
ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã¬ãã«ïŒãã£ã¢è©äŸ¡ïŒ
ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã¬ãã«ã¯ãã£ã¢è©äŸ¡ã§èª¬æãããŸãããã®è©äŸ¡åºæºã§ãããã£ã¢ã¬ãã«ã¯ãç¹å®ã®ãããã€ããŒã«ããŒã¿ãé ããäŒæ¥ã«ãšã£ãŠéèŠã§ããã¯ã©ãŠããããã€ããŒãæ¢ãéãäŒæ¥ã¯ãèªç€Ÿã®èŠå¶åºæºã«åŸã£ãŠãããã©ããã確èªããããã«ãç¹å®ã®ãã£ã¢ã¬ãã«ã®ããŒã¿ã»ã³ã¿ãŒãèŠã€ããªããã°ãªããŸãããããŒã¿ã»ã³ã¿ãŒã®ãã£ã¢ã¬ãã«ãé«ãã»ã©ãããé«åºŠãªãµã€ããŒã»ãã¥ãªãã£ãåããå€§èŠæš¡ãªæœèšã§ããããšã瀺ããŠããŸããããŒã¿ã»ã³ã¿ãŒã®ãã£ã¢ã¬ãã«ã¯ã皌åæéã®ä¿èšŒã決å®ããããã«ã䜿çšãããŸãã
- ãã£ã¢1ïŒ ãã£ã¢1ã¯ãããŒã¿ã»ã³ã¿ãŒã®äžã§ãæäžäœã®éå±€ã§ãããæãåºæ¬çãªããŒã¿ã»ã³ã¿ãŒã§ããäž»ã«ã極ããŠæ©å¯æ§ã®é«ãæ å ±ãä¿åãããç¬èªã®ã€ã³ãã©ã®åé·æ§ãæã€äžå°äŒæ¥ãå©çšããŸããããŒã¿ã»ã³ã¿ãŒã¯99.671%ã®çšŒåæéãä¿èšŒããŠããããã®ãµãŒãã¹ã¬ãã«å¥çŽã§ã¯å¹Žé28.8æéã®ããŠã³ã¿ã€ã ã蚱容ããŠããããšã«ãªããŸãã
- ãã£ã¢2ïŒ ãã£ã¢2ã¯ãäž»ã«ã³ãã±ãŒã·ã§ã³ãµãŒãã¹ãå¿ èŠãšããäŒæ¥ãå©çšããŸããäŒæ¥ã¯èªç€Ÿã®ã€ã³ãã©ã®å€ããä¿æããŠããŸãããããŒã¿ã»ã³ã¿ãŒã®ã€ã³ãã©ã®ã¿ã«äŸåããããšãªãããã§ã€ã«ãªãŒããŒãããŒã¿ã»ã³ã¿ãŒãžã®ãªãœãŒã¹ã®åé ãè¡ãå¿ èŠããããŸãããã£ã¢1ãšãã£ã¢2ã®ããŒã¿ã»ã³ã¿ãŒã§ã¯ã黿ºãšå·åŽæ°Žã®äŸçµŠæºã1ã€ã§ããããããããã®ãªãœãŒã¹ã«é害ãçºçããå ŽåãããŒã¿ã»ã³ã¿ãŒå šäœãšãã®é¡§å®¢ã«ããŠã³ã¿ã€ã ãçºçããããšã«ãªããŸããTier 2ã¯ã99.741%ã®çšŒåæéãä¿èšŒãã幎é22æéã®ããŠã³ã¿ã€ã ã蚱容ããããšã«ãªããŸãã
- ãã£ã¢3ïŒ ãã£ã¢3ããŒã¿ã»ã³ã¿ãŒã¯ããã£ã¢1ããã³ãã£ã¢2ãã倧ããã°ã¬ãŒãã¢ããããããŒã¿ã»ã³ã¿ãŒã§ããåã®2ã€ã®éå±€ãšã®äž»ãªéãã¯ã黿ºãšå·åŽã®ãªãœãŒã¹ã2éã«äœ¿çšãã皌åæéã«åé·æ§ãæãããŠããããšã§ããåé·åããããªãœãŒã¹ã¯ãã§ã€ã«ãªãŒããŒãå¯èœã«ããããã1ã€ã®ãªãœãŒã¹ãæ éããŠã顧客ã«ããŠã³ã¿ã€ã ãçºçããããšã¯ãããŸããããŸããã¡ã³ããã³ã¹æã«ãããŠã³ã¿ã€ã ã¯çºçããŸãããTier3ã§ã¯ã99.982%ã®çšŒåæéä¿èšŒããŸãã¯å¹Žé1.6æéã®ããŠã³ã¿ã€ã ãçºçããå¯èœæ§ããããŸãã
- ãã£ã¢4ïŒ ãã£ã¢4ããŒã¿ã»ã³ã¿ãŒã¯ã皌åæéã®ä¿èšŒãå¿ èŠãšããå€§äŒæ¥ã®ããã«ããã¹ãŠã®ãªãœãŒã¹ãåé·åããããŠã³ã¿ã€ã ã«å¯Ÿãããã©ãŒã«ããã¬ã©ã³ã¹ãæäŸããŸãããã£ã¢4ã§ã¯ã顧客ãããŠã³ã¿ã€ã ãçµéšããããšã¯ã»ãšãã©ãããŸããããã£ã¢4ããŒã¿ã»ã³ã¿ãŒã§ã¯ã99.995%ã®çšŒåæéããŸãã¯å¹Žéããã26.3åã®ããŠã³ã¿ã€ã ãå®çŸããŸãã
ãã£ã¢ãé«ãã»ã©ãããŒã¿ã»ã³ã¿ãŒã®ä¿¡é Œæ§ãšå®å šæ§ãé«ãããšãæå³ããŸãããããªãã¯ã¯ã©ãŠãåéã®å€§æãã³ããŒïŒAmazon Web ServicesãGoogle Cloud PlatformãMicrosoft Azureãªã©ïŒã¯ããããããã£ã¢4ã®ããŒã¿ã»ã³ã¿ãŒãæã£ãŠããŸããç©ççãªã¢ã¯ã»ã¹ã¯ãçäœèªèšŒã·ã¹ãã ãšããã¯ã¢ããã·ã¹ãã ã«ãã£ãŠä¿è·ãããããŒã¿ã®å®å šæ§ãšä¿¡é Œæ§ãå®ã£ãŠããŸãã
CASBã§ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ãä¿è·
Proofpoint Cloud App Security BrokerïŒProofpoint CASBïŒã¯ãMicrosoft Office 365ãªã©ã®ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ãä¿è·ããŸãã
ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£åºæº
ãã¹ãŠã®ããŒã¿ã»ã³ã¿ãŒã¯ããµã€ããŒã»ãã¥ãªãã£ã«ãããŠç¬èªã®åºæºã«åŸã£ãŠããŸãããã»ãšãã©ã®ããŒã¿ã»ã³ã¿ãŒãåŸã£ãŠããã°ããŒãã«ã¬ã€ãã©ã€ã³ããããŸããã¯ã©ãŠããããã€ããŒã¯ãç¬èªã®ããžã¿ã«ã³ã³ãã©ã€ã¢ã³ã¹åºæºã«åŸã£ãŠãããé©åãªãããã€ããŒãæ¢ããŠãã顧客ã¯ãã³ã³ãã©ã€ã¢ã³ã¹ã¬ã€ãã©ã€ã³ã«åŸã£ãŠããããŒã¿ã»ã³ã¿ãŒãæ¢ãå¿ èŠããããŸãã
PCIãHIPAAã³ã³ãã©ã€ã¢ã³ã¹ã«æºæ ããããŒã¿ã»ã³ã¿ãŒã¯ãéèååŒãå»çååŒãéµå®ããªããã°ãªããªã顧客ã«å©çšãããŸãããããŒã¿ã»ã³ã¿ãŒã¯äž»ã«SOCïŒService Organization ControlïŒã«åºã¥ããŠçµ±äžãããæ¥åéè¡ã蚌æããç£æ»ã¬ã€ãã©ã€ã³ã«åŸã£ãŠããŸããSOCåºæºãšã¯ããªã¹ã¯ã®è©äŸ¡ãå ±åãæè¡ã®å®æçãªèŠçŽãããããã¬ã€ãã©ã€ã³ã§ããSOCã¯ãæé ã確èªããç£æ»äººãäœæã»é åžããç£æ»å ±åæžã§ããããšã«çæããå¿ èŠããããŸãã
以äžã®ãªã¹ãã¯ãSOC ã®ã¬ãã«ãšã³ã³ãã©ã€ã¢ã³ã¹ã«ã€ããŠã®ç°¡åãªèª¬æã§ãã
- SOC 1ïŒ SOC 1ã¯ãéèã¢ããªã±ãŒã·ã§ã³ããã¹ãããããã«äœ¿çšãããæé ã«çŠç¹ãåœãŠãŠããŸããããŒã¿ã»ã³ã¿ãŒã®ã€ã³ãã©ã«ãã¹ããããŠããã¢ããªã±ãŒã·ã§ã³ã§ã顧客ãäŒæ¥ã®è²¡åããŒã¿ãæ±ããã®ã¯ãã¹ãŠãã®ã¬ããŒãã«è©²åœããŸãã
- SOC 2ïŒ SOC 2ã¯ãããŒã¿ã»ã³ã¿ãŒã«é¡§å®¢æ å ±ãä¿ç®¡ããŠããSaaSäŒæ¥ã«é©çšãããæãäžè¬çãªç£æ»ã®1ã€ã§ããç£æ»äººã¯ããµã€ããŒã»ãã¥ãªãã£ã®æŠç¥ãšæé ãæ€èšŒããããŒã¿ã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§ã確ä¿ããŠãããã©ããã確èªããŸãã
- SOC 3ïŒ SOC 3ç£æ»ã¯ãSOC 2ã¬ããŒããšåãã§ãããäž»ãªéãã¯ããã®ã¬ããŒãããããŒã¿ã»ã³ã¿ãŒãSOC 2åºæºã«æºæ ããŠããããšã確èªããããã«ãäžè¬äººãã¬ãã¥ãŒããããã®ãã®ã§ããããšã§ãã
ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã®éèŠæ§
ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã®éèŠæ§ã¯ãã¯ã©ãŠãäºæ¥è ã ãã§ã¯ãªãã顧客ãã³ã³ãã©ã€ã¢ã³ã¹ã§å®ããããåºæºãæºãããäºæ¥è ãšé£æºããããšãäžå¯æ¬ ã§ããã¯ã©ãŠãã®é¡§å®¢ã¯ãããŒã¿ã»ã³ã¿ãŒã«æ©å¯ããŒã¿ãä¿ç®¡ããéã«ã¯ãSOC 3ã¬ããŒãã確èªããå¿ èŠããããŸãã顧客ã®ããã«ãµãŒãã¹ããã¹ãããããŒã¿ã»ã³ã¿ãŒæäŸäŒæ¥ã¯ãæäŸãããã¹ãŠã®ã»ãã¥ãªãã£ãããã³ã«ãæé ãããã³åé·æ§ãªãœãŒã¹ãããŠãŒã¶ãŒã«ãšã£ãŠãã¹ãã®å®å šæ§ãæã€ããšãä¿èšŒããªããã°ãªããŸããã