ECEç»é²ãï½ãã®4ï½
CISSPã®è³æ ¼ã§ç»é²
ECEãã¤ã³ãã§ãCertification Examination Related to IT Securityãã¨ããã«ãã´ãªãããã40ãã¤ã³ãè²°ãã¾ãã
ITã»ãã¥ãªãã£ã«é¢é£ããè³æ ¼ããã©ãã¾ã§èªå®ãããã®ãåããã¾ãããæ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã§èªå®ãã¦ããããã ãããï¼
ãEC-Council ECE Examinationsãã¨ããå¥ã«ãã´ãªããã£ã¦ããã¡ãã¯EC-Councilã®å¥ã®è©¦é¨ã«åæ ¼ããã°120ãã¤ã³ãè²°ããããã§ãã
ãã以å¤ã®ITã»ãã¥ãªãã£ã«é¢é£ããè³æ ¼ã¨ãã¦ãä»åã¯CISSPã§ç»é²ãã¦ã¿ã¾ããã
ç»é²æ¹æ³ã¯ãåæ ¼è¨¼ã®ã³ãã¼ããã®ã¾ã¾ã¢ãããã¼ãã
è¨è¼äºé ã¯ä»¥ä¸ã®éãã
Event Name | CISSP Certiticae |
Event Date | 2023-03-2X |
Event Submission Date | 03-2X-2023 |
Event Description | I passed CISSP Certificate held by ISC2. I was awarded March. 2X, 2023 and certification is valid from next month. |
Event Location | Japan |
Â
ãã¤ã2-3æ¥ã§æ¿èªãããã®ã§ãããä»åã¯2é±éãã£ã¦ãPendingç¶æ ã
æéãããéãã ã¨æããåãåãããã©ã¼ã ããåãåãããããããã«è¿ä¿¡ããã¦ããã®3æ¥å¾ã«ã¯ç¡äºæ¿èªããã40ãã¤ã³ãåå¾ã
ããã«ããã3å¹´éã§å¿ è¦ãªãã¤ã³ãæ°ã§ãã120ã«å°éï¼
ECE管çç»é¢ã®ä¸ã«ä»¥ä¸ã®ã¡ãã»ã¼ã¸ã表示ãããã
次åæ´æ°ããã¨ãæ°ããèªå®æ¸ããã¦ã³ãã¼ãã§ãããã¨ãããã¨ã®ããã§ãã
ãã®2å¹´å¼±ã§åå¾ããECEãã¤ã³ãã¯åè¨ã§131ãã¤ã³ãã§ããããã®å 訳ã¯ä»¥ä¸ã®éãã
Certification Examination Related to IT Security | 40 |
EC-Council Exam Survey | 20 |
Education Course | 16 |
Education Seminar/Conference/Event | 55 |
ããããã¯ãCISSPã®ãã¤ã³ãã稼ãã§ãããªãã¨ãããªããCISSPã§ãã£ããã¨ãCEHã§ãèªå®ãããã¨æ¥½ãªã®ã§ããã©ã¤ãã¦ã¿ã¾ãã
Â
Â
Â
Â
Â
Â
Â
Â
Â
CISSP èªå®ã®éã®ã
å æ¥ãCISSPã®è©¦é¨ã«åæ ¼ãã¾ããã
åå¼·æéã¨ãã¦ã¯2ãæã»ã©ãå ¬å¼ãã¬ã¼ãã³ã°ã¯åãã¦ãã¾ããã
ããããªæ¹ãæ¸ããã¦ããããã°ãåèã«ããã¦é ããæ°è¦ã®æ å ±ã¯å°ãªãã§ããã
ä»å¾ãCISSPã®åå¾ãç®æãæ¹ã«åèã«ãªãã°å¹¸ãã§ãã
æ å ±ã¯ã2023å¹´2ææç¹ã§ã®ãã®ã§ãã
Â
Â
Â
Â
Â
éæ
ããåå¼·ãããç´ããã¨ããããæ¸ç±ã¯ä»¥ä¸ã®ã¿ã§ååããã
ã»æ¥æ¬èªåé¡é
ã»è±èªããã¹ã
ãã ãä¸è¨ã丸æè¨ãã¦ãCISSPã®åæ ¼ã¯é£ããããã«æãã¾ããã
ããã¹ãã«åºã¦ããªããã¨ãåé¡ã§åããããããªæ°ããã¾ãã
èªåã¯ITé¢ä¿ã®ä»äºã20年以ä¸ãã£ã¦ããããã®çµé¨ããã£ãã®ã§ãæ£è§£ã§ããã®ãã¨ãæãã¾ãã
ããããåé¨ãããã¨ããæ¹ã«ãã¾ãåèã«ãªããªãããããã¾ãããã
CISSPã®ç¥èä½ç³»ããç¾å®ã®ä¸çã§ãã©ããã風ã«ä½¿ãããã®ãã
ã¨ãããã¨ã¾ã§èãã¦åãçµãå¿ è¦ãããã®ããããã¾ããã
ãããã風ã«èããããè³æ ¼è©¦é¨ã ã¨æãã¾ããã
CISSPã®ã¨ã³ãã¼ã¹ã¡ã³ã
ã¨ã³ãã¼ã¹ã¡ã³ãã®æé
試é¨åæ ¼å¾ãç¿æ¥ã«ã¯ã¨ã³ãã¼ã¹ã¡ã³ãã®æ¡å ã¡ã¼ã«ãå±ãã
以ä¸ãåèã«ããã¦ããã ãã¾ããã
è±æã®å¨è·è¨¼ææ¸ãç¨æãã¦ãæ¨è¦ã¯(ISC)²ã«ãé¡ããã¦ãJob Descriptionã«è¨è¼ãã¹ãè±æ2-3è¡ãï¼ãã¡ã¤ã³åç¨æãã¦ãç³è«ãã¾ãããä¸è¨ãµã¤ãã®ã¾ãã¾ã§ããã
ç³è«å¾ã«ãå度Online Endorsement Applicationã«è¨ªåããã¨ç³è«ç¶æ³ãè¦ãã¾ãã
ï¼ç³è«ç´å¾ï¼
èªåã®å ´åãããã4é±éã»ã©ç¶ãã¾ããã
ããæ¥ã以ä¸ã®è¡¨ç¤ºã«ä»£ããã¾ããã
ï¼å¯©æ»ä¸ï¼
ãããã審æ»ããç£æ»ã«å¼ã£æãããªãã§æ¬²ãããªãã¨ãããããèãã¦ããããããã«ãNext Step for Approved Applicationãã¨ããã¡ã¼ã«ãå±ãã審æ»å®äºã
ãã®å¾ãå¹´ä¼è²»ãæ¯æã£ã¦ããä¸è¨è¡¨ç¤ºãç¶ç¶ãã¦ããã
Â
2023å¹´3æç¾å¨ã(ISC)² Japan (isc2.org)ã«ã¢ã¯ã»ã¹ããã¨ãå½å¥ã®CISSPã®ä¿æè ã®äººæ°ãææ¡ã§ãã¾ãã
以åã¯ä»¥ä¸ã®URLããå ¨ä¸çã®å½å¥ã®CISSPã®ä¿æè ã®äººæ°ãææ¡ã§ãã¾ããã
https://www.isc2.org/About/Member-Counts
ç¾å¨ã¯ããã°ã¤ã³ããªãã¨è¦ããªããµã¤ãã«é£ã°ããããããã«ã¦ã³ããå½ãã¨ã§ã¯ãªããªã£ã¦ãã¾ã£ãã
ä¸çã®CISSPè³æ ¼ä¿æè ã¯ã2023å¹´3ææç¹ã§ã159,679人ã§ã2022å¹´7æããç´3600人å¢ããããã§ãã
æ¥æ¬ã®è³æ ¼ä¿æè ã¯ä»¥ä¸ã®æãã§å¢ãã¦ããããã§ãã
ãã¼ã¿å ï¼Wayback Machine (archive.org)ã§æ¾ãã¾ããã
æ¥æ¬ã§ããã人ããä¿æãã¦ããªããã¨ããã®ãä¸ã¤ã®ã¹ãã¤ã¿ã¹ã ã£ãã®ã§ã(ISC)² Japan (isc2.org)ã§æ¥æ¬äººã®ä¿æè æ°ãæ²è¼ãã¦æ¬²ãããã®ã§ãã
èªå®æéã¯ãä¼è²»æ¯æãã®ç¿æ1æ¥ããã¹ã¿ã¼ãããããããCPE creditsã®åå¾ããã以éãããªãã¨ã«ã¦ã³ããããªããããã
CEHã¯ã»ãã¥ãªãã£é¢ä¿ã®è³æ ¼åå¾ã§ECE30ãã¤ã³ãè²°ããã®ã§ãä»åã®CISSPãç³è«ãã¦ãï¼å¹´ã§120ãã¤ã³ãã«å°éã§ããã
ãããCISSPã®ECEã«ã¯è³æ ¼åå¾ã®ã«ãã´ãªããªãã®ã§ããã¤ã³ãã貯ããã®ã大å¤ã ã
CISSPã®åé¨ã«ã¤ãã¦
åé¨ç³è¾¼
æ¥æ¬ã§CISSPãåé¨ã§ããå ´æã¯æ±äº¬ï¼2ãæï¼ã¨å¤§éªï¼1ãæï¼ã®ãã¢ã½ã³ã®ã¿ã
ãã¡ãã§ã¢ã«ã¦ã³ããä½æãã¦ãåé¨äºç´ãããã
åé¨è³æ ¼ã¯ç¹ã«ãªãã®ã§ãã¹ã±ã¸ã¥ã¼ã«ã空ãã¦ããã°äºç´ã§ããã
ããããªããã空ãããªããªãè¦ã¤ãããªããç´è¿1é±éã2ãæ以ä¸å ã¨ããããªç¶æ³ããããã8æéå§ãã¨ããã¹ã±ã¸ã¥ã¼ã«ãã»ã¨ãã©ã§ã試é¨éå§ã®30ååã«åä»ãå¿ è¦ã¨ããç¶æ³ã§ãåæ³ãåæã¨ããæãã
ä½åº¦ããã°ã¤ã³ãã¦ã空ãç¶æ³ãè¦ã¦ããã¨ãä¸å®æã«ç©ºããå¢ãããã¦ãããã¨ãããããæ±äº¬ã§2ãæã»ã©å ã®äºç´ãå ¥ãã¦ãããã«ã確ä¿ããã
ãã®å¾ãããã³ãã³äºç´ã確èªãã¦ãã©ããªæãã§ç©ºããå¢ãããè¦ã¦ããã®ã§ããããã¾ãè¯ãåãããªãã£ãã
ããæ¥äºç´ã確èªãããã大éªã§10:15ã¹ã¿ã¼ãã®æ ã空ãã¦ããã試é¨ãï¼é±éæ©ã¾ãããåæ³ä¸è¦ã§ã交éè²»ãç¯ç´ã§ãããã¨ããã55ãã«ãæ¯æã£ã¦äºç´ãå¤æ´ããã
åæ³ã¯ä¸è¦ãªãããå½æ¥ãéªãªã©ã®å½±é¿ã§ãã©ãçããªãã£ããããã£ã³ã»ã«æ±ãã«ãªãåé¨æãç¡é§ã«ãªãã®ãå¿é ããªãããåé¨ä¼å ´ã¸ã
ããåé¨
å½æ¥ã5åã»ã©æ©ãåä»ã«å°çããã¨ã2-3äººå¾ ã£ã¦ãã人ããã¦ãé 次æç¶ããè¡ã£ã¦ãã£ãã
身å証ææ¸ãåºãã¦ãããã«ã¼ã«ã«ãã³ãå ¥ãã¦ãåçãæ®ã£ã¦ãéèèªè¨¼ãç»é²ãã¦ãç³è«æ¸ã«ãµã¤ã³ãã¦ããã±ããã空ã«ãã¦etc.
ãããä¸éãæ¸ãã°ã試é¨ã«ã¼ã ã«ç§»åãã¦ã5å以å ã«NDAã«æ¿è«¾ãã¦ã250åã®ãã¹ãéå§ããã¹ãã¯äºå®ã®10:15ãããåã«ã¹ã¿ã¼ããã¦ããã¨æãã
ä¼æ©ãããå ´åã¯æãä¸ããã°ãä¿ã®äººãæ¥ã¦ããã¦ç»é¢ãããã¯ãã¦ãããã
åä»ã§é£ã¹ããã»é£²ãã ãã§ããããã¤ã¬ã¯ãã«ã®å ±æã®ãã¤ã¬ã使ç¨ããã
ãã®æã«äººãä»ãã¦ããã®ãã¨æã£ãããããã§ããªãã£ãã
ãã¤ã¬ã«ååè ãæ½ã¾ãã¦ãããã¹ãã¨ã確èªã§ãã¡ããããããªãï¼ã¨æã£ããããããã©ãCISSPã®ãã¹ãã¯ãä¸åº¦åçããåé¡ã¯ããã¨ããä¿®æ£ã§ããªãã®ã§ããããªåªåãç¡é§ã«çµãããããææ¢ã³ã³ããã¼ã«ã ãã¨ãæã£ãã
èªåã¯ã50å解ããæç¹ã§1åä¼æ©ãå度150å解ããæç¹ã§2åç®ã®ä¼æ©ãã¦ãæå¾ã¾ã§åé¡ã解ãã¾ããã
ãã¢ã½ã³ã®ä¿ã®äººéã¯ãã¨ã¦ãã¦ãã±ãã¨ãã¾ãä¸å¯§ã«å¯¾å¿ãã¦ãããã®ã§ãæ°æã¡ããåé¨ãããã¨ãã§ãã¾ããããããã¨ããããã¾ããã
ãã¹ãåé¡ã¯ãè±èªãä½µè¨ã¨èãã¦ããã®ã§ãããå®éã¯ããã¿ã³ãæ¼ãã¨è±èªã®åé¡ããããã¢ããããå½¢å¼ã§ãå ã®æ¥æ¬èªã®åé¡ãè¦ããªããªã£ã¦ãã¾ãã確èªã«æéããããã¾ããã
çµæçºè¡¨
æçµçã«5æé以ä¸è²»ããã¦ããã¹ãä¸ã¯ããã2度ã¨åé¨ããããªããããã§åæ ¼ããªãã£ãããã©ããã£ã¦åå¼·ãããããããã£ã±ãåãããªããã¨æããªãããã£ã¦ãã¾ãããããããªäººãææãã¦ãã¾ãããåé¡ããµããµããã¦ãã¦ãåçã«å ¨ç¶èªä¿¡ãæã¦ãªãã
ãªãã¨ã250åãå®äºãã¦ãåä»ã§çµæã¬ãã¼ããåãåãã¾ãã
ããã°ã§ä½åº¦ãè¦ããããã§ã¨ããããã¾ãï¼ãã®æåãã
ãã ãåçã«èªä¿¡ããªããå¾ç¹ããããããããåã£ãæããªããç²ãããã§ç¡åå¿ã§ããããã
Â
Â
CISSPã®åå¼·æ¹æ³
åå¼·æ¹é
ã¨ãããããåé¨æ¥ã¯æ±ºããã«ãæ¸ç±ãè³¼å ¥ãã¦æ å ±åéã
ããç¨åº¦ãç¥èãç¿å¾ãã¦ãèªä¿¡ãæã¦ãããåé¨ããããã¨ããæãã§ã¹ã¿ã¼ããã¾ããã
å ¬å¼ãè¦ããæ¸ç±ã®ä¸è¦§ã¯ä»¥ä¸ã«æ²è¼ããã¦ããã
ã¢ããªã»ãã©ãã·ã¥ã«ã¼ãã¯ç¡æã§ä½¿ç¨ã§ããããã§ããã使ãã¾ããã§ããã
ãã ãCISSPã®ç¥èä½ç³»ã¯2021å¹´ã«æ´æ°ããã¦ãã¦ãæ¥æ¬èªã®ããã¹ãã¯2018å¹´ãåé¡éã¯2019å¹´åºçã§ãããããã«ãã¼ãã¦ããªãã®ã§ã¯ï¼ã¨æã£ãã
è²ããªæ¹ã®ããã°ãè¦ãã¨ãæ¥æ¬èªã®å ¬å¼åé¡éã¯å¿ é ãã¨ã®ãã¨ã§ããã
è±èªæ¸ç±ã«ã¤ãã¦
ã»EXAMCRAM
CISSPã®åé¨ä¼å ´ãéå¶ãããã¢ã½ã³ãåºçãã¦ããã®ã§ãä½ã御å©çãããã®ãã¨è³¼å ¥ãå 容ã¯è¦ç¹ãã³ã³ãã¯ãã«ã¾ã¨ãããã¦ããå°è±¡ã
åãã¡ã¤ã³ã®è¦ç¹ãã¾ã¨ãããã¼ãã·ã¼ãã¨ç¨èªéããã¦ã³ãã¼ãã§ããã
WEBä¸ã§åé¡æ¼ç¿ãã§ããããã«ãªã£ã¦ããã
åãã£ãã¿ã¼ã®åé¡ã¯æ¸ç±ã¨åãå 容ã§20åã¥ã¤ã
試é¨åé¡ã¯80åã§ãæ¸ç±ã«æ²è¼ããã¦ãããã®ã¯60åã2ååã§ãå 容ãç°ãªãã
å®è¡ããçµæã¯ä¿åãããééããåé¡ã確èªã§ããããã«ãªã£ã¦ããã
ãã ãåçããåé¡ã確èªããUIã®ä½¿ãåæãã¤ãã¤ãã ã£ãã
Â
ã»Official Study guide & Practice Test
Â
ãã¡ãããWEBä¸ã§åé¡æ¼ç¿ãåºæ¥ãããã«ãªã£ã¦ããã
ãã ãæ¸ç±ã¯Official Study guideã9th editionãPractice Testã3rd editionã ããWEBã§ã®åé¡ã¯editionãä¸ã¤ã¥ã¤å¤ãã£ããçµå±ã2nd editionã¯2018å¹´ã«åºã¦ããã®ã§ãæ¥æ¬èªåé¡éã¨åããã®ãã¨ãããã¨ãï¼
åºæ¬çã«ã¯ããã¹ãã¨åãå 容ã®åé¡ãªã®ã ããå¾®å¦ã«éãç¹ããã£ãã
Study guideã¯ãããã¹ãã¨åãå 容ã®åé¡ãåç« æ¯ï¼å ¨21ç« ï¼ã«20åã¥ã¤ãããããã¨ã¯å¥ã«150åã®ãã¹ãã6ååãããä»ã«ãFlashã«ã¼ãã¨ããå½¢å¼ã®åé¡ã741åããã
Practice Testã¯ãåãã¡ã¤ã³100ååå¾ã®åé¡ã¨122åã®åé¡ãï¼ã¤ã123åã®åé¡ãï¼ã¤ç¨æããã¦ããã
ééããåé¡ã¯è¨é²ãããèªåã§ãã©ã°ãä»ä¸ãããã¨ãåºæ¥ãããã«ãªã£ã¦ããã
ãã¡ããå¦ç¿ã®ãã°ã確èªã§ããééããåé¡ã®å¾©ç¿ãã§ããã
å®éã®åå¼·ã®æ¹æ³
ã¾ããåãã¡ã¤ã³ã§
- æ¥æ¬èªã®ããã¹ããããã£ã¨èªã
- è±èªåé¡éãã¨ãããããã£ã¦ã¿ã
ã¨ãããã¨ã2é±éãããããã¦ããã¾ããããã®æç¹ã§5-6å²ç¨åº¦ã¯æ£è§£ã§ããæãã§ããã
次ã«ãã¼ãä½ãã
ç¥ããªãã£ãäºãåé¡ã§åããã¦åçã§ããªãã£ãç¥èãªã©ãã¾ã¨ãã¦ããã¾ããã
å人çã«ã¯ãã¤ã³ããããã§ã¾ã¨ããã®ã好ããªã®ã§ã以ä¸ã®æãã§åãã¡ã¤ã³æ¯ã«ã¾ã¨ãã¾ããã
Â
ãã¨ã¯ãã²ããã
- ãã¤ã³ããããã§ç¥èãå©ããã
- åé¡ã解ã
- ä¸è¶³äºé ãããã¹ãããããã§èª¿ã¹ã¦ãã¤ã³ããããã«è¿½è¨
ãç¹°ãè¿ãã¾ããã
Â
ãã¤ã³ããããä½æã®éã«ã¯ããã¡ãã«ãä¸è©±ã«ãªãã¾ããã
Â
ä½è«ã§ãããèªåã®èªç¥ç¹æ§ã¯ãã«ã¡ã©ãã§ç»åè¨æ¶ã¿ã¤ãããªã®ã§ãã¤ã³ãããããåãã¦ããã®ããããã¾ããã
è±èªã«ã¤ãã¦
åé¨å¾ã«æ°ã¥ããã®ã§ãããå ¬å¼ã«ãããªè³æãããã¾ããã
CISSPè±æ¥å¯¾è¨³é (ç¨èªWGææç©)
CEHãè±èªã§åå¼·ãã¦ãããã¨ããããæ¯è¼çæµæãªãå¦ç¿ãç¶ç¶ã§ããã
CEHã§å¦ãã ç¥èã2-3å²ã¯è¢«ãé¨åãããããã«æãããã¾ããWEBä¸ã§åé¡æ¼ç¿ãã§ããã®ã§ãæ¸ç±ãéãããããWEBç»é¢ã«åããæéãå¤ãã£ãã
è±èªã®æ¸ç±ãç²¾èªãããããªãã¨ãªããWEBä¸ã®åé¡æ¼ç¿ãä¸å¿ã§ããã®ããã«ãéãæã£ã¦ãããããªãã®ã ã£ãã
WEBã§ã¯ãGoogle翻訳ãé§ä½¿ããªãããåºæ¥ãã®ããããããã£ããééããåé¡ãè¨æ¶ããããããã©ã°ãä»ãããã®ã対象ã«åé¡ãæ§æã§ããã®ã§ãå¹ççã ã£ãã
å ¨ä½ã®åé¡ã2åããã解ãã¦ããã¨ã¯ééããåé¡ãªã©ãç¹°ãè¿ã解ãã¦ããã
ã»ãã¥ãªãã£ã¢ãã«ï¼Bell-LaPadulaã¨Bibaï¼
ã»ãã¥ãªãã£ã¢ãã«
CISSPã®è©¦é¨ã«åºã¦ãããBell-LaPadulaãªã©ãæå³ãåãããªãããã¹ãã¨ãã¦å²ãåã£ã¦æè¨ããã°è¯ãã®ãããããªãããå°ãã¾ã¨ãã¦ã¿ãã
ãããããã»ãã¥ãªãã£ã¢ãã«ã®å¿ è¦æ§ã¯ã©ãã«ããã®ãï¼
ä¾ãã°ãã¦ã¼ã¶ã¼ããã¡ã¤ã«ã«ã¢ã¯ã»ã¹ããéããã®ãã¡ã¤ã«ã®ã¸ã®ã¢ã¯ã»ã¹ã®å¯å¦ãå¤æããå¿ è¦ãããã
ããããã«ååãã¤ãã¦ãã¦ã
ã»Subjectï¼ã¦ã¼ã¶ã¼ï¼
ã»Objectï¼ãã¡ã¤ã«ï¼
ã»Reference Monitorï¼å¯å¦ãå¤æããï¼
ã¨ãããã¨ã«ãªãã
å¯å¦ãå¤æããããã®æéãã»ãã¥ãªãã£ã¢ãã«ã«ãªãã
ãã®ã¢ãã«ããããããã£ã¦ããã®ä¸ã¤ãBell-LaPadulaã¢ãã«ã«ãªãã
Â
以ä¸ã®IPAã®è³æã¯2005å¹´ã«ä½æããããã®ã
https://www.ipa.go.jp/security/fy16/reports/access_control/documents/PolicyModelSurvey.pdf
詳ããã¨ãããã詳ãããã¦éã«æ··ä¹±ãã¾ãããã ãã»ãã¥ãªãã£ã¢ãã«ãæ°å¼ã§ç¤ºããã¨ãã§ãã¦ãããã«ããå®å ¨æ§ã証æãã¦ãããã¨ãããã¨ã¯ç解ã§ããã
ãã®è³æã§ã¯ã
- Confidentialï¼ç§å¿æ§ï¼
- Integtrityï¼å®å ¨æ§ï¼
- ä¸ç«å
ã¨ãã観ç¹ã§ããªã·ã¼ãåé¡ãã¦ããã
ä¸è¨è³æããå¼ç¨ï¼
Â
ãã以å¤ã«æ å ±ã®åºåãã«å¿ããåé¡ã¨ãã¦ã
- å¤å±¤çï¼ä¸ä¸ï¼ãããã·ã¼ã¯ã¬ããã»ã·ã¼ã¯ã¬ããã»æ©å¯ï¼
- å¤å çï¼å·¦å³ï¼å¶æ¥ã»ç·åã»ç®¡çï¼
ã¨ãã観ç¹ãããã
ãã®è¦³ç¹ã§ã®åé¡ã¯ã以ä¸ã®éãã
å¤å±¤ç
- Bell-LaPadula
- Biba
- LOMAC
å¤å ç
- Clark-Wilson
- Chinese Wallï¼Brewer-Nashï¼
- DTE
ãããã®ã»ãã¥ãªãã£ããªã·ã¼ã®å²ãå½ã¦æ¹æ³ã«ã¤ãã¦ãåé¡ãããã
- DACï¼ä»»æï¼ACLã使ç¨ï¼
- MACï¼å¼·å¶ï¼ã©ãã«ã¨ã¯ãªã¢ã©ã³ã¹ã使ç¨ï¼
- RBACï¼ãã¼ã«ãã¼ã¹
- ABACï¼å±æ§ãã¼ã¹
- Rule-Based Access controlï¼ã«ã¼ã«ãã¼ã¹
DACã¨RBACã¯WindowsãLinuxã§ä½¿ç¨ããã¦ããã
Lattice-Based  Access controlã¯MACã®ä¸ç¨®ã
DACã¯ã¦ã¼ã¶ã¼ããRBACã¯ç®¡çè ãã¢ã¯ã»ã¹æ¨©ã決ããã
ã¨ãå¨è¾ºç¥èã ãã§é ã®ä¸ãï¼ã§ä¸æ¯ã«ãªãã
Bell-LaPadulaã¢ãã«ã«ã¤ãã¦
1973å¹´ã«çºæãããã¢ãã«ãç§å¿æ§ãå¤å±¤çãDACã«è©²å½ã
åç §ã¢ã¯ã»ã¹ã¨æ´æ°ã¢ã¯ã»ã¹ãæ確ã«åºå¥ããã¨ãã«æ´æ°ã¢ã¯ã»ã¹ã«é¢ãã*-ç¹æ§ãå°å ¥ãããã¨ãæè¡çç¹å¾´ã¨ãªã£ã¦ããã
ã¾ãã¢ãã«ã®æ§è³ªãæ°å¦ç帰ç´æ³ã«ãã£ã¦è¨¼æå¯è½ã¨ããç¹ã大ããã
å¼ç¨ï¼https://www.ipa.go.jp/security/fy16/reports/access_control/documents/PolicyModelSurvey.pdf
Confidentialityãå®ãããã®ã¢ãã«ã
ãã¨ãã°ã
- Top Secret
- Secret
- Confidential
ã¨ããæ å ±ã®ã¬ãã«ããã£ã¦ãSecretã«ã¢ã¯ã»ã«ã§ãã権éãããå ´åãæ³å®ããã
1.Top Secretã¯èªã¿åãã§ããªããã©ãï¼.ï¼ï¼.ã¯èªããï¼ã·ã³ãã«ã»ãã¥ãªãã£å±æ§ï¼ã
ã¹ã¿ã¼å±æ§ï¼ï¼å±æ§ï¼ã¨ããç¶æ ã«ãªãã¨ã1.ã¯èªããªããã©æ¸ãè¾¼ã¿ã許å¯ããããåæ§ã«2.ã«ãæ¸ãè¾¼ã¿ãå¯è½ã ãã3.ã«ã¯æ¸ãè¾¼ããªãã
å¼·åã¹ã¿ã¼å±æ§ã§ã¯ã2.ã«å¯¾ãã¦ã®ã¿ãèªã¿åãã¨æ¸ãè¾¼ã¿ãå¯è½ã
ã¨ããç¶æ ãæããããã¨ã§æ å ±ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã¦ãä¸ä½ã®æ å ±ã¸ã®æ¸ãè¾¼ã¿ã許å¯ãããæ å ±ã®æ¼æ´©ãé²ãããã«ããã
ã¨ããçµè«ã«ãã©ãçãã®ã«éåã¨æéãããã£ãã
Bibaã¢ãã«ã«ã¤ãã¦
1977å¹´ã®ã¢ãã«ã§ãBell-LaPadulaã¨å¯¾ã«èªããããã¨ãå¤ãã
ãã¡ãã¯ãIntegtrityãç¶æããããã®ãã®ã
ãã¨ãã°ã
- é«ãæ£ç¢ºæ§
- ä¸ç¨åº¦ã®æ£ç¢ºæ§
- ä½ãæ£ç¢ºæ§
ã®æ å ±ããã£ãã¨ããã
2.ä¸ç¨åº¦ã®æ£ç¢ºæ§ã«ã¢ã¯ã»ã¹ã§ãã人ã¯ã1.ã«ã¢ã¯ã»ã¹ã§ãããã3.ã«ã¯ã¢ã¯ã»ã¹ã§ããªãï¼ã·ã³ãã«ã¤ã³ãã°ãªãã£å±æ§ï¼ãä½ãæ£ç¢ºæ§ã®æ å ±ã§æ±æããããã¨ãé²æ¢ãããã¨ã§å®å ¨æ§ãç¶æããã
éã«ãæ¸ãè¾¼ã¿ã«ã¤ãã¦1.ã«ã¯æ¸ãè¾¼ããªãããã«ãã¦ãé«ãæ£ç¢ºæ§ãæ±æãããã¨ãé²ãï¼ã¹ã¿ã¼å±æ§ï¼ã
ã¾ã¨ã
WindowsãLinuxã§ä½¿ç¨ããã¦ããDACã¨RBACã«æ £ãã¦ããã®ã§ããã¡ãã®æ¹ãæè»ã ããMACã§ããBell-LaPadulaã¯éå»ã®éºç©ãã¨æã£ã¦ãã¾ãããããCISSPã§åãããã®æå³ãåãããªãããã ãæè¿è¨ããã¦ãããã¼ããã©ã¹ãã¯MACã«è©²å½ãããã·ã¹ãã ã®å©ç¨å½¢æ ã«ãã£ã¦ãæ°ããã»ãã¥ãªãã£ã¢ãã«ãçã¾ããå¯è½æ§ãã¼ãã§ã¯ãªãã®ãããããªããããããæå³ã§ã¯ãBell-LaPadulaãå¦ã¶ãã¨ã¯ã温æ ç¥æ°ãªã®ã§ããããã
ã»ãã¥ãªãã£ã¼ã»ã¯ãªã¢ã©ã³ã¹å¶åº¦
 ã»ãã¥ãªãã£ã¼ã»ã¯ãªã¢ã©ã³ã¹å¶åº¦ã¨ã¯
æ°é人ãå«ãå½ã®æ©å¯æ å ±ã«æ¥ããç«å ´ã®äººã«é¢ããå¤é¨ã«æ¼æ´©ããæããªã©ã調ã¹ãå¶åº¦ã欧米ãªã©ã§ã¯å½ããåã«å®æ½ããã¦ããããæ¥æ¬ã§ã¯ãå¿ è¦æ§ã®èªèã¯ãããã®ã®ã人権侵害ã®æããããã¨ãããã¨ã§ãªããªãé²ã¾ãªãããã§ãã
Â
ãã¡ãã®è¨äºã®ææãèå³æ·±ãã
NVDï¼National Vulnerability Database)
ã«æ ¼ç´ããã¦ããæ å ±ã®ãã¡ãããããéçºãããã¾ã§ã®ãã¼ããã¤æ å ±ãã«éããã»ãã¥ãªãã£ã¼ã¯ãªã¢ã©ã³ã¹ä¿æè ã§ãªãã¨ã¢ã¯ã»ã¹ãããã¨ãã§ããªããã¨ã§ãã
ä¸è¨ãµã¤ãããå¼ç¨ã
èªç¤¾ã®è£½åã®èå¼±æ§æ å ±ãNVDã«ç»é²ããã¦ãã¦ããã»ãã¥ãªãã£ã¯ãªã¢ã©ã³ã¹ã§èªãããã¦ããªãã¨æ å ±ã«ã¢ã¯ã»ã¹ã§ããªããã¨ããæ å ±æ ¼å·®ãçãã§ããã
ã»ãã¥ãªãã£ã¯ãªã¢ã©ã³ã¹å¶åº¦ãæããå½å士ã§ã¯ãç¸äºèªè¨¼ãã¦ããã¨ããããããèªå½ã®ã»ãã¥ãªãã£æ å ±ãå ±æãããã¨ãå¯è½ã«ãªã£ã¦ããã
ã»ãã¥ãªãã£ã¯ãªã¢ã©ã³ã¹ãå¾ãããã«ã¯ãæ±ãæ å ±ã®ã¬ãã«ï¼Top Secret, Secret, confidentialï¼ã«å¿ãã¦ãå³ãã審æ»ãå¿ è¦ã«ãªãã
Â
ãã¡ãã®è³æã«ã¢ã¡ãªã«ã®è³æ ¼åå¾ã®è©³ç´°ãè¨ããã¦ããã
https://www.cistec.or.jp/jaist/event/kenkyuutaikai/kenkyu34/02-02arimoto.pdf
ããªã°ã©ãæ¤æ»ããããããã£ã¦ãªããªãã
æ¤æ»ã«ã¯1-2å¹´ããããããã§ãããã¢ã¡ãªã«ã§ã¯äººå£ã®ï¼ï¼ 以ä¸ãã¯ãªã¢ã©ã³ã¹ãå¾ã¦ããããã§ãã
ãã¨ãã¨ã¯ãå®å ¨ä¿éãä¸å¿ã¨ããæ©å¯æ å ±ï¼CIãClassified Informationï¼ã ãã対象ã§ããããç±³æ¿åºã¯ãã®ç¯å²ããæ¿åºãçæããCUIï¼Controlled Unclassified Informationï¼æ©å¯æ å ±ã§ã¯ãªãããã©ã管çãå¿ è¦ãªæ å ±ï¼ãæ°éãçæããæ å ±ãCUIæå®ãããããã«ãé©ç¨ç¯å²ãåºãã¤ã¤ããã¾ãããã©ã¯ã»ãªãã大統é ï¼å½æï¼ã2010å¹´ãç±³å½ã®ç£æ¥ç«¶äºåã«è³ããæ å ±ãCUIã¨ãã¦åçãæå®ãããã大統é 令ãçºä»¤ãã¾ããã
å¼ç¨ï¼https://business.nikkei.com/atcl/gen/19/00179/100600018/
ã¨ãããã¨ã§ãã¯ãªã¢ã©ã³ã¹ãæããªãã¨ã¢ã¯ã»ã¹ã§ããªãæ å ±ãå¢ãã¤ã¤ããã
å®å ¨ä¿éãåæã¨ããã»ãã¥ãªãã£ãæ°éã«ãåºãã£ã¦ããã®ã¯ãä»å¾ã®æµããªã®ã ãããã
Â
Â
Â