ç®æ¬¡
SSPMïŒSaaS Security Posture ManagementïŒãšã¯SaaSã»ãã¥ãªãã£äœå¶ç®¡çãæãããµãŒãããŒãã£ã®SaaSã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®å°çšã®ã»ãã¥ãªãã£ã·ã¹ãã ã§ããã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšç¶æ³ãèšå®ãã¢ã¯ã»ã¹å¶åŸ¡ãããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ã®ã£ãããç¶ç¶çã«è©äŸ¡ããŸããè·å Žå šäœã§åºã䜿çšãããŠããSaaSã¯ãå€ãã®è匱æ§ãã»ãã¥ãªãã£ç®¡çã®åé¡ãåŒãèµ·ãããŸãããäœã³ã¹ããŸãã¯ç¡æã®SaaSã¢ããªã±ãŒã·ã§ã³ã®å°é ã¯ãããžãã¹ãŠãããããŠãŒã¶ãŒã«åãäžããŸããããã»ãã¥ãªãã£ããŒã ãæ··ä¹±ãããŸããããšããã«ãŒããã€ã³ãã®è£œåãšãã¹ããŒãã§ãããã·ã¥ãŒã»ã¬ãŒãã£ããŒã¯ãŸãšããŠããŸãã
SSPMã¯ãã»ãã¥ãªãã£ããŒã ãå¹ççã«çºèŠã»ç®¡çã§ããªãè åšã軜æžããããã«ãSaaSã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ã¯æ€åºãèªååããŸããSSPMããŒã¹ã®ã»ãã¥ãªãã£æŠç¥ã¯ãäŒæ¢ã¢ã«ãŠã³ãã誀èšå®ãéå°ãªæš©éãäžæ£ãªçµ±åãããã³Microsoft 365ãSalesforceãOktaãGitHubãªã©ã®ããŒã«ã«ããããã®ä»ã®å€ãã®é²åºãç¹å®ããããšã§ãã¢ã¿ãã¯ãµãŒãã§ã¹ãåæžããŸãã
SSPMã¯ã忣ããããŒã ãéã»ãã¥ãªãã£æ åœè ãé垞管çããSaaSã¢ããªã±ãŒã·ã§ã³ã察象ãšããŠããŸããããã¯ãããŒã¿ããªã·ãŒã管çããCASBïŒã¯ã©ãŠã ã¢ã¯ã»ã¹ ã»ãã¥ãªã㣠ãããŒã«ãŒïŒããIaaSãã©ãããã©ãŒã ãä¿è·ããCSPMïŒã¯ã©ãŠãã»ãã¥ãªã㣠äœå¶ç®¡çïŒãªã©ã®ããŒã«ãšé£æºããŠæ©èœããŸããCSPMãå®å šã§ãªãã¯ã©ãŠãã¹ãã¬ãŒãžãªã©ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ¬ é¥ãç¹å®ããã®ã«å¯ŸããSSPMã¯ãGoogle Workspaceã§ã®ç£èŠãããŠããªããã¡ã€ã«å ±ææš©éãMFAã«ãã¬ããžã®ã®ã£ãããM365ã§ã®æªå¯©æ»ã®ãµãŒãããŒãã£ã¢ããªæ¥ç¶ãªã©ãã¢ããªã±ãŒã·ã§ã³ããã³IDäžå¿ã®ãªã¹ã¯ã«å¯ŸåŠããŸãã
SSPMã®éèŠæ§
çµç¹ã¯çŸåšãæ°çŸããããã¯æ°åãã®SaaSã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠããããã®å€ãã¯ITéšéã®ç£èŠãååã«è¡ãå±ããŠããŸãããæåã«ããã»ãã¥ãªãã£ã¬ãã¥ãŒã§ã¯ãé »ç¹ãªæ©èœã¢ããããŒããã·ã£ããŒITã®æ¡å€§ã«è¿œãã€ãããšãã§ããŸããããããã®ã¢ããªã«ãããèšå®ãã¹ã¯ãã¯ã©ãŠã䟵害ã®å€§éšåãå ããŠããŸãããæªçšããããŸã§æ€åºãããªãããšããããããŸããSSPMã¯ãCISãISO 270001ãªã©ã®èŠæ Œã«æºæ ããããªã·ãŒã匷å¶ãããšåæã«ãSaaSã¢ããªã®èšå®ãã¹ãã·ã£ããŒSaaSãããã³IDäžå¿ã®é²åºãç¹å®ããŸããäŒæ¥ã«ãšã£ãŠãããã¯æ å ±æŒæŽ©ã®æžå°ãã»ãã¥ãªã㣠ã€ã³ã·ãã³ãã®åœ±é¿ã®äœæžãã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ã®ç°¡çŽ åãããã³éçšå¹çã®åäžãæå³ããŸãã
SaaSã®å°å ¥ãæ¡å€§ããã«ã€ããSSPMã¯ããžãã¹ã®åªå äºé ãæé·ã劚ããããšãªãã忣ããã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã«å¿ èŠãªäžå 管çãæäŸããŸããSSPMã¯åŸæ¥ã®ã»ãã¥ãªãã£ã¢ãã«ã«ãã£ãŠæ®ãããã®ã£ãããåããé²åããè åšã®æä»£ã«ãããŠãäŒæ¥ãå®å šã«æ¡åŒµããèªä¿¡ãæã£ãŠã¯ã©ãŠããæŽ»çšã§ããããã«ããŸãã
ãµã€ããŒã»ãã¥ãªãã£æè²ãšãã¬ãŒãã³ã°ãå§ããŸããã
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
SSPMã®ä»çµã¿
SSPMã¯ãã¢ããªã±ãŒã·ã§ã³ã®èšå®ãã¹ãã·ã£ããŒSaaSãIDã®é²åºãªã©ã®ã»ãã¥ãªãã£ã®ã£ãããæ€åºããããã«ãSaaSã¢ããªã±ãŒã·ã§ã³ã®èªååãããç¶ç¶çãªç£èŠãéããŠåäœããŸããSaaSã¢ããªã®èšå®ãã¹ãã£ã³ããèšå®ãCISãISO 270001ãªã©ã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãèŠå¶èŠæ Œã«æºæ ããŠããããšã確èªããŸããIDã»ãã¥ãªãã£ã«ã€ããŠã¯ãSSPMã¯äŒæ¢ã¢ã«ãŠã³ããéå°ãªæš©éãæã€ã¢ã«ãŠã³ããããã³MFAã®æ¬ åŠãç¹å®ããæå°æš©éã®ååãé©çšããŠé²åºãæå°éã«æããŸãã
æ°ãããªã¹ã¯ãããªãããæ€åºããããšãSSPMã¯ãããã«ãã©ã°ãç«ãŠãŠåªå é äœãä»ããæªçšãããåã«ãªã¹ã¯ã«å¯ŸåŠã§ãããããæš©éã®èª¿æŽãã¢ããªãžã®ã¢ã¯ã»ã¹æš©ã®åãæ¶ããªã©ã®ä¿®åŸ©ã容æã«ããŸããSSPMã®ãšãŒãžã§ã³ãã¬ã¹ãªã¢ãããŒãã«ããããšã³ããã€ã³ãã«ãœãããŠã§ã¢ ã€ã³ã¹ããŒã«ãå¿ èŠãšããã«åºç¯ãªã«ãã¬ããžãå¯èœã«ãªãã倿§ãªSaaSãšã³ã·ã¹ãã å šäœã§ã®å°å ¥ãå¹çåãããŸããã¡ãŒã«ãDLPãCASBããŸãã¯IAMïŒIDãšã¢ã¯ã»ã¹ç®¡çïŒããŒã«ãªã©ã®æ¢åã®ã»ãã¥ãªãã£ã·ã¹ãã ãšçµ±åããããšã§ãSSPMã¯å¯èŠæ§ãšä¿®åŸ©ãäžå åããæåã®ç£èŠããã¥ãŒãã³ãšã©ãŒãžã®äŸåãæžãããŸãã
SSPMã®å©ç¹
SaaSã®å°å ¥ãæ¥å¢ããäžãSSPMãœãªã¥ãŒã·ã§ã³ã¯åæ£åã¯ã©ãŠãç°å¢ã«ãããé倧ãªè匱æ§ã«å¯ŸåŠããŸãããã«ãŒããã€ã³ãã®ããŒã¿ã«ãããšã2024幎ã«ç£èŠå¯Ÿè±¡ãšãªã£ãçµç¹ã®99%ããSaaSã¢ããªã±ãŒã·ã§ã³ã«çŽçµããSSOã¢ã«ãŠã³ãã®ä¹ã£åãã®è©Šã¿ãçµéšããŸãããSSPMã¯çµç¹ã«ä»¥äžã®ãããªäžå¯æ¬ ãªå©ç¹ããããããŸãã
- ç¶ç¶çãªäœå¶ã®æ€åºãšä¿®åŸ©ïŒèšå®ãã¹ãé²åºãèªåçã«æ€åºããå¹ççãªä¿®åŸ©ãå¯èœã«ããŸããSSPMã¯ãæªçšãããåã«é²åºã«å¯ŸåŠããããšã§ã䟵害ã®ãªã¹ã¯ã軜æžããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ã®ä¿èšŒïŒèšå®ãšã¢ã¯ã»ã¹å¶åŸ¡ãç£èŠããããšã§ãGDPRãHIPAAãžã®æºæ ã確å®ã«ããŸãã
- ã¢ã¿ãã¯ãµãŒãã§ã¹ã®åæžïŒäŒæ¢ã¢ã«ãŠã³ããéå°ãªæš©éãMFAã®æ¬ åŠãããã³ã·ã£ããŒITãç¹å®ããæªçšå¯èœãªè匱æ§ãããŒã¿æŒæŽ©ã®åå ãæžãããŸãã
- éçšå¹çïŒèšå®ãã¹ã®ç£æ»ãªã©ã®ã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååããããŒã ãããæŠç¥çãªåªå äºé ã«éäžã§ããããã«ããŸãã
- ã³ã¹ãåæžïŒããã¢ã¯ãã£ããªãªã¹ã¯ç®¡çã«ãããSaaSã®èšå®ãã¹ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã®ã£ããã«é¢é£ããããŒã¿äŸµå®³ãé²ããŸãããŸããã»ãã¥ãªãã£ç®¡çã®å¹çãåäžãããŸãã
- ãµãã©ã€ãã§ãŒã³ã®ä¿è·ïŒå®å šã§ãªããµãŒãããŒãã£ã®çµ±åãè匱ãªSaaSã¢ããªãæ€åºããŸããããã«ãããæ»æè ãä¿¡é Œã§ããããŒãããŒãäŸµå ¥å£ãšããŠæªçšããã®ãé²ããŸãã
- ã³ã©ãã¬ãŒã·ã§ã³ã®åŒ·åïŒäžå åãããå¯èŠæ§ãæäŸããããšã§ãã»ãã¥ãªãã£ããŒã ãããžãã¹ãŠãããããšã³ããŠãŒã¶ãŒéã®ã®ã£ãããåããçç£æ§ãæãªãããšãªãçµ±åããããªã¹ã¯ç®¡çãå¯èœã«ããŸãã
ãããã®é åã«å¯ŸåŠããããšã§ãSSPMã¯ãµã€ããŒãªã¹ã¯ã®å¢å€§ããåå ãšããŠã®SaaSã¢ããªãæé€ããŸãã
SaaSã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãäŸ
泚ç®ãéããé倧ãªäŸµå®³ã¯ãSaaSç¹æã®é²åºã«å¯ŸåŠããããã®SSPMã®äžå¯æ¬ ãªå¿ èŠæ§ã匷調ããŠããŸãã以äžã¯ãå®å šæ§ã®äœãSaaSãšã³ã·ã¹ãã ãããããçµæ«ã瀺ãæè¿ã®ã€ã³ã·ãã³ãã§ãã
ããããã€ãã»ããªã¶ãŒãã«ãã Microsoft 365 ã®äŸµå®³
ãã·ã¢æ¿åºã®æ¯æŽãåããè åšã¢ã¯ã¿ãŒã¯ãéå°ãªæš©éãæã€ã¬ã¬ã·ãŒãªOAuthã¢ããªã±ãŒã·ã§ã³ãæªçšããŠMicrosoftã®ã³ãŒãã¬ãŒã ã¡ãŒã« ã·ã¹ãã ã«äŸµå ¥ããçµå¶é£ã®æ©å¯æ§ã®é«ãéä¿¡ãæµåºãããŸããããã®æ»æã¯ãèšå®ãã¹ã®ããSaaSã¢ããªã®çµ±åãæšçã«ããããšã§åŸæ¥ã®é²åŸ¡ããã€ãã¹ããŸãããããããSSPMããµãŒãããŒãã£ã®ã¢ã¯ã»ã¹ãšæš©éã¬ãã«ãç¶ç¶çã«ç£èŠããŠããã°ããã©ã°ãç«ãŠãŠä¿®åŸ©ã§ããã¯ãã§ãã
ã¯ã©ãŠããã¬ã¢ã®ã¢ãã©ã·ã¢ã³ã§ã®ãµãŒãããŒã㣠ããŒã¯ã³äŸµå®³
æ»æè ã¯ã以åã®Oktaã®äŸµå®³ã§çãŸããOAuthããŒã¯ã³ãå©çšããŠã¯ã©ãŠããã¬ã¢ã®ã¢ãã©ã·ã¢ã³ç°å¢ã«ã¢ã¯ã»ã¹ãããœãŒã¹ã³ãŒããå éšããã¥ã¡ã³ãã䟵害ããŸãããSSPMã®ããªã·ãŒé©çšã«ããããµãŒãããŒã㣠ã¢ããªã±ãŒã·ã§ã³ã®æš©éãå¶éããäŒæ¢ç¶æ ã®ãµãŒãã¹ã¢ã«ãŠã³ããç¹å®ããããšã§ãå€ãèªèšŒæ å ±ã«ããã©ãã©ã«ã ãŒãã¡ã³ããé²ãããšãã§ããã¯ãã§ãã
ãã©ãŒãã£ãããã® SharePoint ããŒã¿æŒæŽ©
èšå®ãã¹ã®ãã Microsoft SharePoint ã€ã³ã¹ã¿ã³ã¹ã«ããã顧客ã®èªèšŒæ å ±ã財åèšé²ãå«ã 440GB ã®ãã©ãŒãã£ãããå éšããŒã¿ã®çé£ãçºçããŸãããSSPM ã®èªååãããèšå®ãã§ãã¯ãããã°ãäžé©åãªå ±æèšå®ãæ€åºããæ©å¯ãã¡ã€ã«ãžã®æå°æš©éã¢ã¯ã»ã¹ã匷å¶ã§ããŠããã¯ãã§ãã
Snowflake ã®ã¯ã¬ãã³ã·ã£ã«æªçšãã£ã³ããŒã³
ããã«ãŒã¯ãçãŸããèªèšŒæ å ±ãšMFAããŒã¹ã®èªèšŒã®æ¬ åŠãå©çšã㊠Snowflake ã®é¡§å®¢ã¢ã«ãŠã³ãã䟵害ãã165 ã®çµç¹ã«è¢«å®³ãäžãã5å9,000äžä»¶ã®ã¬ã³ãŒããé²åºãããŸãããSSPM ã®IDäžå¿ã®å¶åŸ¡ãããã°ãMFA ã®ã®ã£ãããçºèŠããIDããŒã¹ã®æ»æã軜æžã§ããã¯ãã§ãã
SSPMã®äž»èŠãªæ§æèŠçŽ
SSPMã¯ãããã¢ã¯ãã£ã ã»ãã¥ãªãã£å¯Ÿçãšèªååãããã¬ããã³ã¹ãçµã¿åãããŠãSaaSç¹æã®äœå¶ã«å¯ŸåŠããŸãããã®äžæ žãšãªãèŠçŽ ã¯ãéçšã®ä¿ææ§ãç¶æããªãããé²åããè åšã«å¯Ÿããç¶ç¶çãªä¿è·ã確å®ã«ããŸãã
ç¶ç¶çãªç£èŠ
SSPMããŒã«ã¯ãMicrosoft 365ãSalesforceãªã©ã®SaaSã¢ããªã±ãŒã·ã§ã³ãç¶ç¶çã«ã¹ãã£ã³ããèšå®ãã¹ãã·ã£ããŒSaaSãããã³IDã®é²åºãæ€åºããŸãããã®çµ¶ãéãªãç£èŠã«ãããå ¬éãã¡ã€ã«å ±æèšå®ãäŒæ¢ã¢ã«ãŠã³ãããã¹ã¯ãŒãéåãªã©ã®åé¡ãã䟵害ãžãšçºå±ããåã«ç¹å®ããŸãã
ãªã¹ã¯è©äŸ¡
SSPMã¯ãCISã³ã³ãããŒã«ãªã©ã®ãã³ãããŒã¯ãMITRE ATT&CKãªã©ã®æ¥çèŠæ Œã«ç §ãããŠèšå®ãè©äŸ¡ããããšã§ãæ·±å»åºŠãšããžãã¹ãžã®åœ±é¿ã«åºã¥ããŠãªã¹ã¯ã«åªå é äœãä»ããŸããSalesforceã®éå°ãªæš©éãæã€ãŠãŒã¶ãŒããMicrosoft 365ã«ãããäžé©åãªOAuthçµ±åã«ãã©ã°ãç«ãŠãŸããããã«ãããã¿ãŒã²ãããçµã£ãä¿®åŸ©äœæ¥ãå¯èœã«ãªããŸãã
ããªã·ãŒã®é©çš
SSPMã¯ãSaaSã¢ããªå šäœã§ã»ãã¥ãªãã£ããªã·ãŒãèªååããèšå®ãçµç¹ã®ããªã·ãŒã«é©åããããã«ããŸããã¢ããªã®èšå®ãã¹ãã·ã£ããŒSaaSãããã³IDã®é²åºãçºèŠããŠä¿®åŸ©ããŸãããããã®ã¢ã¯ã·ã§ã³ã¯ãé«åºŠã«åæ£åãããITç°å¢ã«ããããã¥ãŒãã³ãšã©ãŒã®åœ±é¿ã軜æžããŸãã
修埩
èšå®ãã¹ãã·ã£ããŒITããŸãã¯IDã®é²åºãªã©ã®ãªã¹ã¯ãæ€åºããããšãSSPMã¯ãªã¹ã¯ã«åºã¥ããåªå é äœä»ããšãITããŒã åãã®ã¹ããããã€ã¹ãããã®ã¬ã€ãã³ã¹ãæäŸããŸããæªäœ¿çšã®ã¢ã¯ã»ã¹ã®åãæ¶ãããŠãŒã¶ãŒæš©éã®èª¿æŽãè¡ãããšã§ãçµç¹ã®ã¢ã¿ãã¯ãµãŒãã§ã¹ãæå°éã«æããŸãã
ã¬ããŒããšåæ
ã«ã¹ã¿ãã€ãºå¯èœãªããã·ã¥ããŒãã¯ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã¹ããŒã¿ã¹ãé²åºã®åŸåãããã³ä¿®åŸ©ã®é²æç¶æ³ã远跡ããŸããSSPMã¯ãCISãISO 270001ãªã©ã®èŠæ Œåãã®ã¬ããŒããçæããŸãã
ãSaaSã»ãã¥ãªãã£ã«ã¯ãäžå åãããã»ãã¥ãªãã£ããŒã ãåéšéããšã³ããŠãŒã¶ãŒéã®é£æºãå¿ èŠã§ããSSPMãœãªã¥ãŒã·ã§ã³ã¯ãããä¿é²ããŸãããšãã¬ãŒãã£ããŒã¯åŒ·èª¿ããŸãããããã®æ§æèŠçŽ ã¯çžä¹çã«æ©èœããæçåãããSaaSãšã³ã·ã¹ãã ããå®å šã«ç®¡çãããè³ç£ãžãšå€è²ãããŸããSSPMã¯ãçç£æ§ãšå ç¢ãªãªã¹ã¯äœæžã®ãã©ã³ã¹ãç¶æããŸãã
SaaSã¢ããªã®ã»ãã¥ãªãã£èª²é¡
SaaSã¢ããªã±ãŒã·ã§ã³ã¯ã忣åã®ç®¡çãšåçãªèšå®ã«ãããç¹æã®ãªã¹ã¯ããããããŸãã2024幎ã®SaaSã»ãã¥ãªãã£èª¿æ»ã§ã¯ãçŽ3å²ã®çµç¹ãéå»12ã¶æä»¥å ã«SaaSã®ããŒã¿æŒæŽ©ã«ééããããšãæããã«ãªããŸãããSSPMã¯ãSaaSã¢ããªã±ãŒã·ã§ã³å šäœã®å¯èŠåãå¶åŸ¡ã修埩ãèªååããããšã§ããããã®èª²é¡ã«å¯ŸåŠããŸãã
- SaaSã¢ããªã®èšå®ãã¹ïŒå ¬éãã¡ã€ã«å ±æèšå®ããã¹ã¯ãŒãããªã·ãŒéåãMFAã«ãã¬ããžã®ã®ã£ãããªã©ã®èª€ã£ãèšå®ã¯ãæ©å¯ããŒã¿ãé²åºãããŸããSSPMã¯ãSaaSé¢é£ã®äŸµå®³ã®åå ãšãªãããšãå€ããããã®ã®ã£ãããæ€åºãã修埩ããŸãã
- éå°ãªæš©éã«ããã¢ã¯ã»ã¹ïŒäžèŠãªæš©éãæã€ãŠãŒã¶ãŒã¯ã䟵害ã®ãªã¹ã¯ãé«ããŸããSSPMã¯æå°æš©éã®ååãé©çšããæ»æè ã«ããæš©éææ Œãã©ãã©ã«ã ãŒãã¡ã³ãã®æ©äŒãæžå°ãããŸãã
- ã·ã£ããŒITïŒæªæ¿èªã®SaaSã¢ããªã®äœ¿çšãæ¥å¢ããŠãããããŒã¿æŒæŽ©ãã³ã³ãã©ã€ã¢ã³ã¹éåãèå»¶ããæ»è§ãçã¿åºããŠããŸããSSPMã¯ããããã®æªå ¬èªSaaSã¢ããªãçºèŠã»è©äŸ¡ãããªã¹ã¯ã«åºã¥ããæææ±ºå®ãå¯èœã«ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹éåïŒSaaSã¢ããªã®èšå®ã¯ãã¹ã³ãŒãå€ã®èšå®ãç£æ»ã®ã®ã£ããã«ãããGDPRãHIPAAãPCI-DSSãªã©ã®èŠå¶ã«ãããã³ã³ãã©ã€ã¢ã³ã¹ã®åŒ±ç¹ãé²åãããããšããããããŸããSSPMã¯ãèšå®ãèŠå¶ãã³ãããŒã¯ã«é©åãããŸãã
- å®å šã§ãªãçµ±åïŒã»ãã¥ãªãã£ãäžååãªããããã¯äžé©åã«ç®¡çãããçµ±åã¯ãæ»æè ã«ããããŒã¿æŒæŽ©ãã¢ããªæ©èœã®æäœãèš±ããŠããŸããŸããSSPMã¯ãµãŒãããŒãã£ã®æ¥ç¶ãç£æ»ããæœåšçã«ãªã¹ã¯ã®ããçµ±åãæ€ç¥ããŸãã
- å éšè åšïŒåŸæ¥å¡ããSaaSã¢ããªã®äœ¿çšãèšå®ãã¹ãéããŠã誀ã£ãŠããããã¯æå³çã«ããŒã¿ãé²åºãããå¯èœæ§ããããŸããSSPMã¯ããããã®ãªã¹ã¯ãçºèŠãã修埩ããŸãã
ãGoogle ãã©ã€ãã®URLãžã®ãªã³ã¯ãä»ãã Google ããã¥ã¡ã³ãã®ãã£ãã·ã³ã°ããã«ãŠã§ã¢é ä¿¡ãé »ç¹ã«èгå¯ããŠããŸãããšããã«ãŒããã€ã³ãã®SaaSè åšæ€åºã®ãªãŒãç ç©¶è ã§ããããªãŒã«ã»ãã³ã¯è¿°ã¹ãŠããŸãããSaaSãã©ãããã©ãŒã ã¯ãè åšã¢ã¯ã¿ãŒã«ãšã£ãŠãé²åŸ¡åŽã«ãšã£ãŠããç¡æ³å°åž¯ãã®ãŸãŸã§ããGoogle Apps Script ã®ãããªæ°ããããŒã«ãæ¥éã«æ©èœã远å ããäžæ¹ã§ãè åšã¢ã¯ã¿ãŒã¯ãããã®ãã©ãããã©ãŒã ãæªçšããæ°ããæ¹æ³ãæ¢ããŠããŸãããšåœŒã¯ä»ãå ããŸãã
ãããã®è匱æ§ã«çŠç¹ãåœãŠãããšã§ãSSPMã¯SaaSç°å¢ãã»ãã¥ãªãã£äžã®è² åµãããå埩åã®ããç£æ»å¯Ÿå¿å¯èœãªããžãã¹è³ç£ãžãšå€è²ãããŸãã
SSPMã»CSPMã»CASBã®éã
ãããã®ã¯ã©ãŠãã»ãã¥ãªã㣠ã¢ãã«ãçè§£ããããšã§ãçŸä»£ã®äŒæ¥ãä¿è·ããäžã§ã®ããããã®åœ¹å²ãæç¢ºã«ãªããŸãã
CSPM ïŒã¯ã©ãŠãã»ãã¥ãªãã£äœå¶ç®¡çïŒ
CSPMã¯ãAWSãAzureãGoogle Cloudãªã©ã®ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ã㣠ãµãŒãã¹ãä¿è·ããŸããæå·åãããŠããªãã¹ãã¬ãŒãž ãã±ãããå®å šã§ãªããããã¯ãŒã¯ ãããã³ã«ãªã©ãIaaS/PaaSç°å¢ã«ãããèšå®ãã¹ãç¹å®ããã³ã³ãã©ã€ã¢ã³ã¹ã®ãã¹ããã©ã¯ãã£ã¹ãé©çšããŸããCSPMããŒã«ã¯ãèšå®ã CIS Benchmarksãªã©ã®ãã¬ãŒã ã¯ãŒã¯ã«å¯Ÿå¿ãããŸãããSaaSã¢ããªã®èšå®ãã¹ãã·ã£ããŒSaaSãªã©ã®SaaSã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ã¯ã«å¯Ÿããå¯èŠæ§ãäžè¶³ããŠããŸãã
CASBïŒã¯ã©ãŠã ã¢ã¯ã»ã¹ ã»ãã¥ãªã㣠ãããŒã«ãŒïŒ
CASBã¯ããŠãŒã¶ãŒãšã¯ã©ãŠããµãŒãã¹éã®çºèŠããã³ããªã·ãŒé©çšã®ã¬ã€ã€ãŒãšããŠæ©èœããŸããããŒã¿ã¢ã¯ã»ã¹ã管çãã転éäžã®æ©å¯æ å ±ãæå·åãŸãã¯ãããã¯ãããã«ãŠã§ã¢ãªã©ã®è åšããããã¯ããŸããCASBã¯ãã·ã£ããŒITã«å¯Ÿããå¯èŠæ§ãæäŸããDLPãªã©ã®æ©èœãéããŠè»¢éäžã®ããŒã¿ãä¿è·ããŸããããããCASBã¯ãSSPMã察åŠãããããªSaaSç¹æã®èšå®ã®ããªããã詳现ãªIDãªã¹ã¯ã«ã¯å¯ŸåŠããŸããã
SSPM
SSPMã¯ãæ¥åã«äžå¯æ¬ ãªåºãæ¡çšãããŠããSaaSãã©ãããã©ãŒã ããITã»ãã¥ãªãã£ããŒã ã®é¢äžãèªèãªãã«äœ¿çšãããŠããã·ã£ããŒSaaSã®ä¿è·ã«éç¹ã眮ããŠããŸããèšå®ããŠãŒã¶ãŒæš©éãããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ã®ã£ããïŒéå°ãªæš©éãæã€ãŠãŒã¶ãŒãå éšãã¡ã€ã«ãžã®ãããªãã¯ã¢ã¯ã»ã¹ãMFAã«ãã¬ããžã®ã®ã£ãããªã©ïŒãç¶ç¶çã«ç£èŠããŸããSSPMã¯SaaSã®ãªã¹ã¯ã修埩ããCISãISO 270001ãªã©ã®èŠæ Œãžã®æºæ ã確å®ã«ããŸãã
æ©èœ
SSPM
CSPM
CASB
ãã©ãŒã«ã¹é å
SaaSã¢ããªã±ãŒã·ã§ã³ (äŸ: Microsoft 365, Salesforce, Okta)
ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ã㣠(äŸ: AWS, Azure, GCP)
ã¯ã©ãŠãã¢ã¯ã»ã¹ããã³ããŒã¿ãã㌠(äŸ: SaaS, IaaS, PaaS)
äž»ãªæ©èœ
ãªã¹ã¯ãçºèŠããããã®èšå®ãæš©éãããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ç¶ç¶çãªç£èŠ
ã€ã³ãã©ã¹ãã©ã¯ãã£èšå®ãã§ãã¯ã«ããIaaS/PaaSç°å¢ã®ä¿è·
ãŠãŒã¶ãŒãšã¯ã©ãŠããµãŒãã¹éã®ã»ãã¥ãªãã£ããªã·ãŒã®é©çš
ç¹åŸŽ
- äžå åãããå¯èŠæ§ãšã¯ãŒã¯ãããŒã®ä¿®åŸ©
- ã»ãã¥ãªãã£ãªã¹ã¯ã®IDäžå¿ã®ãã¥ãŒ
- ãªã¹ã¯ããªããã®åæ
- ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£èšå®ãã¹ã®æ€åº
- ãããã¯ãŒã¯ ã»ãã¥ãªãã£åæ
- IaaS/PaaSã®ã³ã³ãã©ã€ã¢ã³ã¹ ãããã³ã°
- DLP
- ã·ã£ããŒITã®çºèŠ
- è åšæ€åºïŒãã«ãŠã§ã¢ïŒ
掻çšäºäŸ
- SaaSèšå®ãã¹ã®çºèŠãšå¯ŸåŠ
- ã·ã£ããŒSaaSã®çºèŠãšä¿®åŸ©
- IDé²åºã®ä¿®åŸ©
- ã¯ã©ãŠã ã¹ãã¬ãŒãž ãã±ããã®ä¿è·
- æå·åãããã³ã«ã®æ€èšŒ
- IaaSã³ã³ãã©ã€ã¢ã³ã¹ã®ç£èŠ
- ããŒã¿ã¢ã¯ã»ã¹ã®å¶åŸ¡
- 転éäžã®æ©å¯ããŒã¿ã®æå·å
- æªæ¿èªã¯ã©ãŠãã¢ããªã®ãããã¯
ã³ã³ãã©ã€ã¢ã³ã¹
GDPR, HIPAA, SOC 2, CIS, ISO 270001, NIST-CSF
CIS Benchmarks, PCI-DSS, NIST
ISO 27001, GDPR, æ¥çåºæã®çŸ©å
çµ±åç¯å²
SaaSã¢ããªïŒå ¬èªãã·ã£ããŒITãããã³IDãããã€ããŒïŒ
IaaS/PaaSãã©ãããã©ãŒã ããã³ãµãŒããŒã¬ã¹ç°å¢
ãã¹ãŠã®ã¯ã©ãŠããµãŒãã¹ (SaaS, IaaS, PaaS)
å°å ¥
ãšãŒãžã§ã³ãã¬ã¹ãAPIé§å
APIããŒã¹ãŸãã¯ãšãŒãžã§ã³ãããŒã¹
ãããã·ãŸãã¯APIããŒã¹
ãªã¹ã¯ã®åªå é äœä»ã
SaaSç¹æã®è åšïŒäŸïŒãµãŒãããŒãã£çµ±åãMFAã®ã£ãããéå°ãªããŒã«ã«ã¢ã«ãŠã³ãïŒ
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§ïŒäŸïŒé²åºããã¹ãã¬ãŒãžãå®å šã§ãªãä»®æ³ãã·ã³ïŒ
ããŒã¿é²åºãªã¹ã¯ïŒäŸïŒäžæ£å ±æãèªèšŒæ å ±ã®çé£ïŒ
æ©èœ
ãã©ãŒã«ã¹é å
SSPM
SaaSã¢ããªã±ãŒã·ã§ã³ (äŸ: Microsoft 365, Salesforce, Okta)
CSPM
ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ã㣠(äŸ: AWS, Azure, GCP)
CASB
ã¯ã©ãŠãã¢ã¯ã»ã¹ããã³ããŒã¿ãã㌠(äŸ: SaaS, IaaS, PaaS)
æ©èœ
äž»ãªæ©èœ
SSPM
ãªã¹ã¯ãçºèŠããããã®èšå®ãæš©éãããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ç¶ç¶çãªç£èŠ
CSPM
ã€ã³ãã©ã¹ãã©ã¯ãã£èšå®ãã§ãã¯ã«ããIaaS/PaaSç°å¢ã®ä¿è·
CASB
ãŠãŒã¶ãŒãšã¯ã©ãŠããµãŒãã¹éã®ã»ãã¥ãªãã£ããªã·ãŒã®é©çš
æ©èœ
ç¹åŸŽ
SSPM
- äžå åãããå¯èŠæ§ãšã¯ãŒã¯ãããŒã®ä¿®åŸ©
- ã»ãã¥ãªãã£ãªã¹ã¯ã®IDäžå¿ã®ãã¥ãŒ
- ãªã¹ã¯ããªããã®åæ
CSPM
- ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£èšå®ãã¹ã®æ€åº
- ãããã¯ãŒã¯ ã»ãã¥ãªãã£åæ
- IaaS/PaaSã®ã³ã³ãã©ã€ã¢ã³ã¹ ãããã³ã°
CASB
- DLP
- ã·ã£ããŒITã®çºèŠ
- è åšæ€åºïŒãã«ãŠã§ã¢ïŒ
æ©èœ
掻çšäºäŸ
SSPM
- SaaSèšå®ãã¹ã®çºèŠãšå¯ŸåŠ
- ã·ã£ããŒSaaSã®çºèŠãšä¿®åŸ©
- IDé²åºã®ä¿®åŸ©
CSPM
- ã¯ã©ãŠã ã¹ãã¬ãŒãž ãã±ããã®ä¿è·
- æå·åãããã³ã«ã®æ€èšŒ
- IaaSã³ã³ãã©ã€ã¢ã³ã¹ã®ç£èŠ
CASB
- ããŒã¿ã¢ã¯ã»ã¹ã®å¶åŸ¡
- 転éäžã®æ©å¯ããŒã¿ã®æå·å
- æªæ¿èªã¯ã©ãŠãã¢ããªã®ãããã¯
æ©èœ
ã³ã³ãã©ã€ã¢ã³ã¹
SSPM
GDPR, HIPAA, SOC 2, CIS, ISO 270001, NIST-CSF
CSPM
CIS Benchmarks, PCI-DSS, NIST
CASB
ISO 27001, GDPR, æ¥çåºæã®çŸ©å
æ©èœ
çµ±åç¯å²
SSPM
SaaSã¢ããªïŒå ¬èªãã·ã£ããŒITãããã³IDãããã€ããŒïŒ
CSPM
IaaS/PaaSãã©ãããã©ãŒã ããã³ãµãŒããŒã¬ã¹ç°å¢
CASB
ãã¹ãŠã®ã¯ã©ãŠããµãŒãã¹ (SaaS, IaaS, PaaS)
æ©èœ
å°å ¥
SSPM
ãšãŒãžã§ã³ãã¬ã¹ãAPIé§å
CSPM
APIããŒã¹ãŸãã¯ãšãŒãžã§ã³ãããŒã¹
CASB
ãããã·ãŸãã¯APIããŒã¹
æ©èœ
ãªã¹ã¯ã®åªå é äœä»ã
SSPM
SaaSç¹æã®è åšïŒäŸïŒãµãŒãããŒãã£çµ±åãMFAã®ã£ãããéå°ãªããŒã«ã«ã¢ã«ãŠã³ãïŒ
CSPM
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§ïŒäŸïŒé²åºããã¹ãã¬ãŒãžãå®å šã§ãªãä»®æ³ãã·ã³ïŒ
CASB
ããŒã¿é²åºãªã¹ã¯ïŒäŸïŒäžæ£å ±æãèªèšŒæ å ±ã®çé£ïŒ
SSPMãSaaSã¢ããªã®èšå®ãä¿è·ããCSPMãã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£ã匷åããCASBãããŒã¿ãããŒãæ€åºãå¶åŸ¡ããŸããããããçµã¿åãããããšã§ãé²åããã¯ã©ãŠãã®è åšã«å¯ŸããŠå€å±€çãªé²åŸ¡ãæäŸããŸãã
SSPMã®æŽ»çšäºäŸ
SSPMã¯ãSaaSç¹æã®ãªã¹ã¯ã«å¯ŸåŠããããšã§ãæ¥çå šäœã§ã»ãã¥ãªãã£ã®åäžãå®çŸããŸãã以äžã¯ãçµç¹ãSaaSã»ãã¥ãªãã£äœå¶ãæ¹åããã·ããªãªã§ãã
ã¡ãã£ã¢ 倧æã®SaaSã¹ãããŒã«è»œæž
ãã100åãã«èŠæš¡ã®ã¡ãã£ã¢äŒæ¥ã¯ãæ©å¯ã³ã³ãã³ããé²åºãããŠããã·ã£ããŒITããŒã«ãå«ãã1,200以äžã®SaaSã¢ããªã«èŠæ ®ããŠããŸãããSSPMã¯ãITéšéãåœåææ¡ããŠããããã250%å€ãã¢ããªãçºèŠããŸãããããã®å€ããéå°ãªæš©éãæã£ãŠããããæªå¯©æ»ã®çµ±åãè¡ãããŠãããããŸããããªã¹ã¯ã®åªå é äœä»ããšä¿®åŸ©ã¯ãŒã¯ãããŒãèªååããããšã§ããã®çµç¹ã¯2幎éã§ã»ãã¥ãªãã£äœå¶ã®ã¹ã³ã¢ã40%ãã85%ã«åäžãããæœåšçãªäŸµå®³ã³ã¹ã149äžãã«ã鲿¢ããŸããã
SSPMãœãªã¥ãŒã·ã§ã³
SaaSã®å°å ¥ãå éããã«ã€ãããããã®åçãªãšã³ã·ã¹ãã ãä¿è·ããããšã¯ãããŒã¿æŒæŽ©ãã©ã³ãµã ãŠã§ã¢ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã®ã£ãããªã©ã®ãªã¹ã¯ã軜æžããããã«äžå¯æ¬ ãšãªã£ãŠããŸããSSPMã·ã¹ãã ã®å¿ èŠæ§ã¯æããã§ãããSaaSã¢ããªãšããã«é¢é£ããè åšã®æ¡æ£ãšãšãã«é«ãŸãäžæ¹ã§ãããããã£ãŠãå ¬èªããã³æªå ¬èªã®SaaSã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãªã¹ã¯ããã»ãã¥ãªãã£ããŒã ã«ãšã£ãŠã®æ¬¡ã®ã»ãã¥ãªã㣠ã³ã³ãããŒã« ããã³ãã£ã¢ãšãªã£ãŠããããšã¯é©ãã¹ãããšã§ã¯ãããŸããã幞ããªããšã«ããã«ãŒããã€ã³ãã¯ãã®èª²é¡ã«å¯ŸåŠããã客æ§ãæ¯æŽããããšã«å°œåããŠããŸããã詳现ã«ã€ããŠã¯ããåãåãããã ããã