NPO Institute of Digital Forensics. NPOæ³äºº ãã¸ã¿ã«ã»ãã©ã¬ã³ã¸ãã¯ç ç©¶ä¼ ã141-0031 æ±äº¬é½åå·åºè¥¿äºåç°7-15-4 第ä¸è±ç°ãã«4F TELï¼FAXï¼03-6431-8200 Emailï¼info@digitalforensic.jp
ãã¸ã¿ã«ã»ãã©ã¬ã³ã¸ãã¯ç 究ä¼ï¼IDFï¼ã§ã¯ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãè¡ã£ã¦ããå£ä½ä¼å¡ä¼æ¥ã«ã¤ãã¦ã®ç´¹ä»ããã®ãã¼ã ãã¼ã¸ãéãã¦è¡ãã¾ãã ããã§ãç´¹ä»ããä¼æ¥ã¯ãæ¢ã«IDFã®ãã¼ã ãã¼ã¸ã§å ¬éãã¦ããã¾ããå£ä½ä¼å¡ãªã³ã¯ãããå£ä½ä¼å¡ã製åã»ãµã¼ãã¹åºåãªã¹ãããã«æ²è¼ãã¦ããæ å ±ã«å ãããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãå®æ½ãã¦ãããæ²è¼ãå¸æããä¼æ¥ã§ãã çæ§ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãä¾é ¼ãããã¨ããéã«ä¼æ¥é¸å®ã®ãå½¹ã«ç«ã¦ã°å¹¸ãã§ãã ãªããæ²è¼å£ä½ä¼å¡ä¼æ¥ã¯ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åã«é¢ããå½è©²ç¤¾ã®å ¬éæ å ±çã«åºã¥ããæ²è¼æç¹ã§ä¸é©åãªç¤¾ä¼çäºæ¡ãäºæ å ±åçãå ¬çæ©é¢ã«ãããªããã¦ããªãå£ä½ä¼å¡ä¼æ¥ã¨ãã¦ããã¾ãããIDFãå½è©²ä¼æ¥ã®å®åå 容ã«è²¬ä»»ãè² ããã®ã§ã¯ãªãä¸é©åãªç¤¾ä¼çäºæ¡ãäºæ å ±åçããã£ãå ´åã«ã¯ãæ²è¼ãåãæ¶ããã¨ãããã¾ãã â»æ²è¼é ã¯ãæ²è¼ã
Forkwell Library 第48åç®ã¯ã詳解 ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ããåãä¸ãã¾ããã¤ã³ã·ãã³ã対å¿ã«ã¯ãæ§ã ãªå°éåéã®ç¥èãå¿ è¦ã¨ããæ§ã ãªåéã®ãã¬ã¼ãã³ã°ãç¶ç¶çã«åããå¿ è¦ãããã¾ããæ¬æ¸ã¯ã»ãã¥ãªãã£ä¾µå®³ã試ã¿ãæ»æè ã®æ´»åã«å¯¾ããæ¥å¸¸çã«äºé²ã»æ¤ç¥ã»å¯¾å¿ãè¡ãå®å家ã«ãã£ã¦æ¸ãããå®å家ã®ããã®æ¸ç±ã§ã2022å¹´1æã«çºå£²ããã¾ãããä»åã¯è¨³è ã®ç³å· æä¹ æ°ãæããæ¬æ¸ã®æ¦èª¬ãå®è·µçãªæè¡ã®å¦ã³æ¹ãæ¬æ¸ã«é¢é£ããæè¡ã®å¦ã³æ¹ãªã©ã解説ããã ãã¾ãã
Being a digital forensics and incident response consultant is largely about unanswered questions. When we engage with a client, they know something bad happened or is happening, but they are uncertain of the âhow, when, where, and why.â A significant component of our job is to tease out the âknown knowns,â the âknown unknowns,â and effectively and efficiently help the client answer the following:
Home Getting Started On-Call Being On-Call Who's On-Call? Alerting Principles Before an Incident What is an Incident? Severity Levels Different Roles Call Etiquette Complex Incidents During an Incident During an Incident External Communication Guidelines Security Incident After an Incident After an Incident Postmortem Process Postmortem Template Overview What Happened Contributing Factors Resoluti
ååã®è¨äºã§ãã»ãã¥ãªãã£ããã¼ã¸ã£ã¨ãã¦ãã½ããã¹ãã«ãã³ã³ããã³ã·ãæ§è³ªããéè¦ã¨æ¸ãã¾ããã ãã½ããã¹ãã«ãã³ã³ããã³ã·ãã¨ã¯ã課é¡ã®ææ¡åã解決ã¾ã§ã®æ¹åæ§ã®æ±ºãæ¹ã段åãåãã³ãã¥ãã±ã¼ã·ã§ã³åããã¬ã¼ã³åãªã©æ§ã ã§ãã ãæ§è³ªãã¨ã¯ãç¶ç¶çã«åå¼·ã§ããããç´ ç´ãã¨ãããããããã¾ã両ç«ã§ããããä»é¨éã¨æããæã®æ¼ãå¼ãã«å¼·ãããä½ãæãéããããªãã£ãæã«ã¸ããããªãããããã¨ããæã«äººåã§ææ®ãããã¨ã好ãããã¿ãããªæ確ã«å®ç¾©ã§ããªãã¡ã³ã¿ã«é¢ã®é¨åãå¤ãã«ããã¾ãã ä¸è¨ã®ãã¡ç ä¿®ãæ¸ç±ã§ãã¦ãã¼ãç´¹ä»ããã¦ãããã¼ããå¤ã ããã¾ããããä»é¨éã¨æããæã®æ¼ãå¼ãã«å¼·ãããã¯ãã¾ãè¦ããã¨ãªãããã¨æããèªåã®çµé¨ã¨æããå解ãã¦ã¿ã¾ããã ãã®è¨äºã¯ãããæå³ã§ã¯è ¹ã®é»ãã¨ãããè¦ãããããªãèªã¿æã«ã¨ã£ã¦ã¯å«æªæãæã¤å 容ããããã¾ããã ããã§ããããããæ å ±ã
ã¯ããã« å æ¥ãJPCERT/CCãäºåå±ã¨ãã¦åå ãããå°éçµç¹å士ã®æ å ±å ±ææ´»åã®æ´»æ§åã«åããããµã¤ãã¼æ»æã«ãã被害ã«é¢ããæ å ±å ±æã®ä¿é²ã«åããæ¤è¨ä¼ãã®å ±åæ¸ãå ¬éãããé¢é£ææç©ã®ãããªãã¯ã³ã¡ã³ããå§ã¾ãã¾ããã çµæ¸ç£æ¥çããµã¤ãã¼æ»æã«ãã被害ã«é¢ããæ å ±å ±æã®ä¿é²ã«åããæ¤è¨ä¼ https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/cyber_attack/index.html JPCERT/CCã¯ããã¾ã§ã«ä¸è¨ã®åãçµã¿ãéãã¦ãæ å ±å ±ææ´»åã®ä¿é²ã«åããã«ã¼ã«æ´åã«åãçµãã§ãã¾ããã 令åï¼å¹´åº¦ç·åçããµã¤ãã¼æ»æã®è¢«å®³ã«é¢ããæ å ±ã®æã¾ããå¤é¨ã¸ã®æä¾ã®ããæ¹ã«ä¿ã調æ»ã»æ¤è¨ã®è«è² ãã®èª¿æ»å ±åï¼2021å¹´7æå ¬éï¼[1] ããµã¤ãã¼æ»æ被害ã«ä¿ãæ å ±ã®å ±æã»å ¬è¡¨ã¬ã¤ãã³ã¹ãï¼2023å¹´3
å é£å®æ¿å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NISCï¼ã¯ããµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã«ããã¦åç §ãã¹ãé¢ä¿æ³ä»¤ãQ&Aå½¢å¼ã§è§£èª¬ããããµã¤ãã¼ã»ãã¥ãªãã£é¢ä¿æ³ä»¤Q&Aãã³ãããã¯ãï¼ä»¥ä¸ãæ¬ãã³ãããã¯ãã¨ããã¾ããï¼ãä½æãã¦ãã¾ãã ä¼æ¥ã«ãããå¹³æã®ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çåã³ã¤ã³ã·ãã³ãçºçæã®å¯¾å¿ã«é¢ããæ³ä»¤ä¸ã®äºé ã«å ããæ å ±ã®åæ±ãã«é¢ããæ³ä»¤ãæ å¢ã®å¤åçã«ä¼´ãçããæ³ç課é¡çãå¯è½ãªéãå¹³æãªè¡¨è¨ã§è¨è¿°ãã¦ãã¾ãã ä¼æ¥å®åã®åèã¨ãã¦ãå¹ççã»å¹æçãªãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã»æ³ä»¤éµå®ã®ä¿é²ã¸ã®ä¸å©ã¨ãªãã°å¹¸ãã§ãã â»Ver2.0ã¯ã令å5å¹´9æã«ããµã¤ãã¼ã»ãã¥ãªãã£ãåãå·»ãç°å¢å¤åãé¢ä¿æ³ä»¤ã»ã¬ã¤ãã©ã¤ã³çã®æç«ã»æ¹æ£ãè¸ã¾ããé ç®ç«ã¦ã»å 容ã®å å®ãæ´æ°ãè¡ãæ¹è¨ããããã®ã§ãã Qï¼Aã§åãä¸ãã¦ãã主ãªãããã¯ã¹ã«ã¤ã㦠ãµã¤ãã¼ã»ãã¥ãªãã£åºæ¬æ³é¢é£ ä¼ç¤¾æ³
ã¯ããã« ç 究éçºç¬¬äºé¨ãªã¼ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ä¸ç¬ã§ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢å士ã®ä¼è©±ã§ã¯ãã"ã·ãµ"ãæè¿ã¾ãã¬ãã¼ãåºãã¦ãã¦â¦ãã¨ãã"ã¢ã¤ãã¼ã¨ã¼"ãã注æåèµ·åºã¦ãããã¨ãã£ããåå¦è ã«ã¯è¬ã®åèªãããããåºã¦ãã¾ããæ¬è¨äºã§ã¯ããããã£ãä¼è©±ã«åºã¦ããåèªã®ãã¡ãå½å å¤ã®ã»ãã¥ãªãã£é¢é£ã®ä¸»ãªçµç¹ã«ã¤ãã¦ã¾ã¨ãã¾ãããã»ãã¥ãªãã£ã«èå³ãããã°ãããã«æããçµç¹ã¨ããã®çµç¹ãé¢ããæ¿çãæ´»åã«ã¤ãã¦ãäºåã«æãã¦ããã¦æã¯ããã¾ãããããããã»ãã¥ãªãã£ãå¦ã¼ãã¨ããæ¹ã®åèã«ãªãã°å¹¸ãã§ãã ãªããè¨è¼ããæ å ±ã¯ãã¹ã¦å·çæç¹ (2023 å¹´ 6 æ) ã®ãã®ã§ãã ã2023/06/30 追è¨ãNISC ããã³ ENISA ã®æ¥æ¬èªå称ãä¿®æ£ãCISA ã®èªã¿æ¹ã«ã¤ãã¦ä¿®æ£ã»è¿½è¨ãNCSC ã«ã¤ãã¦è¿½è¨ãã¾ããã ã¯ããã« ä¸å¤®çåº å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿
J-CLICS æ»æçµè·¯å¯¾çç·¨ã§ã¯ãæ»æè ãä¾µå ¥ããéã«ä½¿ç¨ãããæããããå¶å¾¡ã·ã¹ãã ï¼ä»¥ä¸ããICSãã¨ãããï¼ã¨ã®æ¥ç¶ç¹ãæ»æçµè·¯ã¨å®ç¾©ããæ³å®ããã4ã¤ã®æ»æçµè·¯ãè¨å®ãã¦ãã¾ããè¨å®ããæ»æçµè·¯ãã¨ã«ä¾µå®³æé ã¨å®æ½ãã¹ãã»ãã¥ãªãã£å¯¾çãæ¤è¨ãã¦ããããã®å¯¾çã®å®æ½ç¶æ³ã確èªããããã§ãã¯ãªã¹ããããã³ãã®ãè¨åé ç®ã¬ã¤ããã§æ§æããã¦ãã¾ããããã«ãæ»æçµè·¯ãã¨ã«æ»æãæç«ããæ¡ä»¶ãæ´çããã対çãããããå ããè©ä¾¡ããéã®åèå³æ¸ã¨ãã¦ãã¾ãã J-CLICSã®å称ããã¤ICSã®èªå·±è©ä¾¡ãã¼ã«ã«ã¯ããJ-CLICS STEP1ï¼STEP2ãã¨ãJ-CLICS æ»æçµè·¯å¯¾çç·¨ãã®2種ãããã¾ããJ-CLICS STEP1ï¼STEP2ã¯ãããããICSã®ã»ãã¥ãªãã£å¯¾çã«åãçµãæ¹åãã§ããã¼ã¹ã©ã¤ã³ã¢ããã¼ãã¨ãã¦ç¾å¨ã®ICSã«ãããã»ãã¥ãªãã£å¯¾çç¶æ³ãå¯è¦åããéè¦åº¦ãé«ã
ã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第3.1ç (2023å¹´10æ) 2023å¹´10æ18æ¥ã«ç¬¬3.1çã®PDFã®ããã¹ããç»åã®ã³ãã¼ãã§ããããã«ä¿®æ£ãã¦åé å¸ãã¾ããããææ°ã§ããå¿ è¦ãªæ¹ã¯åãã¦ã³ãã¼ãããé¡ããã¾ãã 2023å¹´10æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第3.1çããå ¬éãã¾ãããä»é²ã¨ãªãããµã¼ãã¹ãã¼ããã©ãªãªã·ã¼ãããå ¬éãã¾ããããã²ãæ´»ç¨ãã ããã ãWG6ã ã»ãã¥ãªãã£ãªãã¬ã¼ã·ã§ã³é£æºWGã«ããã¦ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第2.1çãã®æ¹çã«åãã¦è°è«ãç¶ãã¦ãã¾ããã2021å¹´10æã«å ¬éãããITU-Tå§åX.1060ãX.1060ã®æ¥æ¬èªçã®æ¨æºã¨ãªãTTCæ¨æºJT-X1060ã«åãããå½¢ã§ã®å ¨é¢çãªæ¹çã¨ãªãã¾ãã 第3.1ç å·çé¢ä¿è (社åäºåé³é ) éå°» æ³°å¼ NECã½ãªã¥ã¼ã·ã§ã³ã¤ããã¼ã¿æ ªå¼ä¼ç¤¾ æ©å· æ¦å² NECã½ãªã¥ã¼ã·ã§ã³
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}