æè¡è©è«ç¤¾ã®ã»ãã¥ãªãã£å¯¾çæé©åã»ããã¼ã®ããã«ãã£ã¹ã«ãã·ã§ã³
仿¥ããæ¼éãã¾ã§ã¯ç¿æ³³ç¤¾ããã®MarkeZine Day 2009ãè¦ã«è¡ã£ã¦ãåå¾ããã¯åå·ã®ã³ã¯ã¨ãã¼ã«ã§éå¬ãããæè¡è©è«ç¤¾ããã®ã»ãã¥ãªãã£å¯¾çæé©åã»ããã¼ã«åå ãã¦ãã¾ããã
ãç®å½ã¦ã¯è±ªè¯ã¡ã³ãã¼ã®ããã«ãã£ã¹ã«ãã·ã§ã³ã§ãã
ãã¼ãã¼ã½ã³ãèªãï¼ ä¼æ¥ã»ãã¥ãªãã£å¯¾çã®ãããã
セキュリティ対策最適化セミナー … 技術評論社
ã¢ãã¬ã¼ã¿ï¼
ãä¸è¼ª ä¿¡é æ°ï¼S&Jã³ã³ãµã«ãã£ã³ã°æ ªå¼ä¼ç¤¾ï¼
ããã©ã¼ï¼
ãæ°äº äº¨ æ°ï¼å³ã®ç´ ã·ã¹ãã ãã¯ãæ ªå¼ä¼ç¤¾ å°ä»»èª²é·ï¼ï¼
ãæ°äº æ æ°ï¼æ ªå¼ä¼ç¤¾ã©ã㯠ãµã¤ãã¼ãªã¹ã¯ç·åç ç©¶æ æé·ï¼ï¼
ãæºå¡© å°å² æ°ï¼æ ªå¼ä¼ç¤¾ã¤ãã¼ãã£ãªä»£è¡¨åç· å½¹ï¼ç°å¢çCIOè£ä½å®ï¼ï¼
ãæä»£ 忣 æ°ï¼ä¸è¬ç¤¾å£æ³äºº JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ 代表çäºï¼
ã¢ãã¬ã¼ã¿ã¼ã¯è¨ããã¨ç¥ãããã»ãã¥ãªãã£æè¡æ¦éæ´¾ã®ä¸è¼ªããã§ãã
ããã©ã¼ã«ã¯ãç°å¢çCIOè£ä½å®ãå¤ããæºå¡©æ°ãã¦ã¼ã¶ã¼ä»£è¡¨ã¨ãã¦å³ã®ç´ ã·ã¹ãã ãã¯ãã®æ°äºæ°ãã»ãã¥ãªãã£çã®ä¸é«å¹´ããªã¼ã¿ã¼ã¨åä¹ãJPCERT/CCã®æä»£ãããä¸å®¶ã«ä¸å°ã©ãã¯ã®æ°äºæ ããã§ãã
ããã¼ãããé
ç½®ã ã
以ä¸ããããããã£ã話é¡ãããã¤ãããã¯ã¢ããã
- ã¤ã³ã·ãã³ãã£ã¦å
¬è¡¨ããã¦ãã以å¤ã®è¦ããªãæ°åãããã®ã§ã¯ï¼
- ï¼æä»£æ°ï¼å±åºè ã®æèãå¤ãã£ã¦ãã¦ããã¼ãã¹ãã£ã³ã¨ããã£ããããã§ã¯å±åºãªããªã£ã¦ããã
- ã¢ã³ãã¦ã¤ã«ã¹ã½ããã£ã¦ãããã¯æ¢ãã¦ãããªãã®ï¼
- ï¼æä»£æ°ï¼ã¢ã³ãã¦ã¤ã«ã¹ã½ããã¯æ»æè ãå ¥æã§ãããã¨ãããã¨ã¯ãåé¿ã§ããããã«ä½ãã®ãå½ããåãããªãã§ãããããããã³ãã¼ã対å¿ãããã³ã«äºç¨®ã¨ãä½ãã¯ãã
- ï¼ä¸è¼ªæ°ï¼ããããä½ã£ã¦ãã人ã¯ãã¸ãã¹ã§ãã£ã¦ããã®ã§ãçå£ãããããå®ãå´ã®ãå®ãããã®æèãåé§ãã¦ããã
- ä¼ç¤¾ã®ä¸ã«ãããã£ã¦åå¨ããã®ï¼
- ï¼æ°äºæ æ°ï¼æè¿ã¯ã¾ã伿¥å ãçãããããã«ãªã£ã¦ããã以åãç¡åã§ããããè¦ã¤ãããã£ã³ãã¼ã³ããã£ãã¨ãããããªãã®æ°ã®ã客ããã§ããããè¦ã¤ãã£ãã
- ï¼æ°äºæ°ï¼å³ã®ç´ ã大ä¸å¤«ã¨ã¯è¨ãåããªããå½å å¤ã«ãããã¯ã¼ã¯ããããæ¬ä¸¸ãå®ã£ã¦ããã©ããã«ç©´ãããã¯ãã¨å¸¸ã«èãã¦ãããç¤¾å æè²ã¯è¡ãå±ãã¦ããã¨æãããæ¼ä¼ã¿ã®ãã©ã¦ã¸ã³ã°ã¨ãç§ç©ã®USBã¡ã¢ãªæã¡è¾¼ã¿ã¨ããã©ãã¾ã§è¦å¶ã§ãããã¯ä½ã¨ãè¨ããªãã
- æ¿åºã¯ã©ããã¦ããã®ãï¼
- ï¼æºå¡©æ°ï¼ä»¥åã¯æ¿åºã®ã·ã¹ãã ã¯æ¥è ã«ä¸¸æãã ã£ãããããç´ãã¹ãåãã¦ãããéå»ã®éç¨å®ç¸¾ãªã©ã確ãããåé¡ãææ¡ããªããã°ãªããªããå½å®¶å ¬åå¡ã¯2å¹´ã§ä»£ãã£ã¦ãã¾ãã®ã§ãæã ã®ãããªå¤é¨ã®ã¢ããã¤ã¶ã¼ãéããããªãã¨ãå»å¹´ãããããè¡ã£ã¦ããããã£ã¨ä»ãITããã¸ã¡ã³ããã¾ã¨ãã«ããå§ããã¨ãããã§ã¼ãºã
- éã¶é¢ã¯ã©ã¦ãã£ã¦ä½ï¼
- ï¼æºå¡©æ°ï¼å®æ ã¯ç§ãããããããªãããã ãæ¿åºã¨æ°éã®éãã¨ããã¨ãã¦ã¯ãæµ·å¤ã®ã·ã¹ãã ãç°¡åã«ä½¿ãããã«ã¯ãããªããæ³å¾ãé©ç¨ã§ããã®ãã©ããã¨ãã£ãåé¡ããããããããã«ã¼ã«æ´åã¯ã§ãã¦ããªãã
- ï¼ä¸è¼ªæ°ï¼ç§ã¯æ¥æ¬ã«ç½®ãã®ãæ£ããã¨æãã
- æ
å ±æ¼ããäºä»¶ã®åçºé²æ¢çã«ã¤ãã¦ãäºä»¶ãèµ·ããç¬éã¯ããããªè©±é¡ã«ãªããã ã£ãããå
ã«ãã£ã¦ããã°ããã®ã«
- ï¼æ°äºæ æ°ï¼èº«ãèããªã話ã ããã»ãã¥ãªãã£ãä¿ã¤åªåãæ ãã¨ãã£ã¨ããã¾ã«ããããããããªã«å¤ãããã§ã¯ãªããã忥åºããã客ãããããã
- ï¼ä¸è¼ªæ°ï¼CISOã®äººã¯åä¼ç¤¾ã®ç¤¾é·ã«ãªã£ãããã»ãã¥ãªãã£ä½ã¨ãå§å¡ä¼ã¯ãã¤ã®éã«ããªããªã£ãããã¦ããã以åã«äºä»¶ãèµ·ãããããä¼ç¤¾ã¯ãæ°å¹´çµã£ã¦ãä»ã§ãæ°äººã«ãã®äºä»¶ã®æè¨ãæè²ãã¦ããããããããã¨ã¯ç¶ããªããã°ãªããªãã
- WAFï¼Web Application Firewallï¼ã¯æè¡ã§é²ããã対çã ã¨æããç©´ã ããã®ã½ãããå®ãã«ã¯WAFã¯ä»ã®ã¨ãããã鏿è¢ã
- ï¼æä»£æ°ï¼éçºè ã®ã¿ããªãã¤ããã¼ã§ã¯ãªããæ°äºæ ã¯ã¿ããªæ¬²ãããã©ããªããWebãå®ãã«ã¯WAFã¯ãã鏿è¢ãå®ç§ã§ã¯ãªããã©ãããªãé²ããããªãããå ¨ç¶ãã·ã
ä»ã«ããããããåçãããã¾ããããããã¯ç¾å ´ã«ããäººã®æ¥½ãã¿ã¨ãããã¨ã§ã