LayerX Tech Advent Calendar 2024 ã®4æ¥ç®ã®è¨äºã§ãã
LayerX Fintechäºæ¥é¨ï¼ä¸äºç©ç£ãã¸ã¿ã«ã»ã¢ã»ããããã¸ã¡ã³ãï¼MDMï¼ã«åºåï¼ã§ãã»ãã¥ãªãã£ãã¤ã³ãã©ãæ ã·ã¹ããã«ããã¹ã¯ãã¬ããã³ã¹ã»ã³ã³ãã©ã¤ã¢ã³ã¹ã¨ã³ã¸ãã¢ãªã³ã°ãªã©ãæ å½ãã¦ãã @ken5scal ã§ãã
æ¥å¹´åº¦1æããç±³å½ å¤§çµ±é ã®æ°æ¿æ¨©ãå§ã¾ãã¾ããã
大統é ã®æã¤ç¹æ¨©ã®ä¸ã¤ã«ã大統é 令ãããã¾ãã
ããã¯ãæ³çãªææåãæã¡ãè°ä¼ã®æ¿èªãå¾ãã«å®æ½ãããã¨ãã§ãã
*1 権éã§ãã
対象ã¯æ§ã ãªåéã«åã³ãæ¨ä»?ã¯ãµã¤ãã¼ã»ãã¥ãªãã£ï¼Cybersecurityï¼ã«ãåã³ã¾ãã CSFãZero Trustã¢ã¼ããã¯ãã£ããµãã©ã¤ãã§ã¼ã³çããã¿ãããããã«ãè¯ããæªããæ¬é¦ã«ããããµã¤ãã¼ã»ãã¥ãªãã£ã¯ç±³å½ã®ãããã大ä½ãï¼ãï¼å¹´çµéãã¦ãããã£ããã¢ããããå¾åãããããã«è¦ãã¾ããå人ã®ææ³ã§ãã ããã§ãã®æ©ä¼ã«2010年以éã®ãµã¤ãã¼ã»ãã¥ãªãã£ã»æ å ±ã»ãã¥ãªãã£ç³»ã®å¤§çµ±é 令ããããããã¦ã¿ã¾ãããã â»æã£ãããå¤ãã¦æéæ¶è²»ããã°ãã£ãã®ã§ããªããæ¿æ¨©ã®2017ã¨ãã以éã«åå²ãã¾ãã
ãªããæ¿æ¨©æ
EO 13526: Classified National Security Information (2009)
å½å®¶å®å ¨ä¿éæ å ±ï¼Classified National Security Informationã以éCIï¼ã®åé¡ãä¿è·ãããã³æ©å¯è§£é¤ã管çããå½å®¶å®å ¨ä¿éï¼National Securityï¼ã¨éææ§ãä¿é²ãã¾ããç¹ã«ãæ å ±ããã¯ãä¿è·ãå¿ è¦ã¨ããªãå ´åã«æ©å¯è§£é¤ããããããå®æçãªåé¡ã¬ã¤ãã³ã¹ã®è¦ç´ãã義åä»ãã¦ãã¾ãã
ããèªä½ã¯EO 13292ï¼ããã·ã¥æ¿æ¨©, 2003ï¼ããEO 12958ï¼ã¯ãªã³ãã³æ¿æ¨©, 1995ï¼ãå»æ¢ããç¹ã«æ©å¯æ å ±ã®è§£é¤ããçµ±ä¸çãªæç¶ããè¦ç¨ãããã¨ãæ°ããã§ã
EO 13549: Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities(2010)
EO 13526ã§å®ç¾©ã¥ããããCIãå·ãå°æ¹ãé¨æãæ°éã»ã¯ã¿ã¼ã¨ãã£ãéé£é¦æ©é¢ã«ãæ¡å¤§ãã大統é 令ã§ãã
EO 13556: Controlled Unclassified Information(2010)
ããã¯ãæ¿åºå é¨ã®æ©å¯æ å ±ï¼CIï¼ã§ã¯ãªããä¸å®ã®ä¿è·ãå¿ è¦ã¨ããæ å ±ï¼Controlled Unclassified Informationï¼CUIï¼ï¼ãå®ç¾©ãããã®åãæ±ããæ¨æºåãããã¨ãç®æãããã®ã§ãã
ãªããããã«ä¼´ãCUIã管çããããã®ã¬ã¤ãã©ã¤ã³ã§ããSP800-171ãProtecting Controlled Unclassified Information in Nonfederal Systems and Organizationsãä½æããã¾ããã*2
ããã¯é²è¡çã調éåºæºã¨ãã¦2019å¹´ã«åèã«ãããã¨ããå½å ã§ããã話é¡ã«ãªãã¾ãã
EO 13587: Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information(2011)
2010å¹´ã®Wikileaksã«å¯¾ããæ©å¯æ å ±ï¼CIï¼æµåºã«å¿ãã¦ãCIã«å¯¾ããå é¨ä¸æ£å¯¾çå¼·åã®ç®çã§åºããã大統é 令ã§ãã Senior Information Sharing and Safeguarding Steering Committee (SISS SC)ãè¨ç«ããã¤ã³ãµã¤ãã¼ã»ã¹ã¬ããã»ã¿ã¹ã¯ã»ãã©ã¼ã¹ãåµè¨ãã¾ããã
EO 13636: Improving Critical Infrastructure Cybersecurity(2013)
ã¤ãã«ãCybersecurityãã¨ããåèªãç»å ´ãã¾ãã æ¥æ¬ã®ã»ãã¥ãªãã£çéã§ãæåãªå¤§çµ±é 令ã§ã¯ãªãã§ããããã ãã®å¤§çµ±é 令ã§ã¯éè¦ã¤ã³ãã©ã®ãµã¤ãã¼ã»ãã¥ãªãã£ãåä¸ããããã¨ãç®çã¨ãã次ã®ãã¨ãå½ãããã¾ãã
- NISTãæè¡ä¸ç«ãªãThe Cybersecurity Frameworkããéçºããã
- ãµã¤ãã¼ã»ãã¥ãªãã£ã®å®è·µã®æ¡ç¨ãä¿é²ããã¤ã³ã»ã³ãã£ããæä¾ããã
- ãµã¤ãã¼ã»ãã¥ãªãã£è å¨æ å ±ã®å ±æã®éãã¿ã¤ã ãªãã¹ãå質ãå¢ãã
- ãã©ã¤ãã·ã¼ã¨å¸æ°çèªç±ã®ä¿è·ãã ã¯ãªãã£ã«ã«ãªã¤ã³ãã©ã¹ãã©ã¯ãã£ã¼ã®ã»ãã¥ãªãã£ç¢ºä¿ãç®çã¨ããå ¨ã¤ãã·ã¢ããã«çµã¿è¾¼ã
- ç¾è¡ã®è¦å¶ãå©ç¨ãã¦ãµã¤ãã¼ã»ãã¥ãªãã£ãä¿é²ãã
ããã¦ä¸ç¹ç®ã«ãããä»æ¥v2ã«ãªã£ã¦ããCSF*3ã«ã¤ãªããã¾ããã
ããã¦æ¹ãã¦æ°ã¥ãã¾ããããCyber Securityãã§ã¯ãªããCybersecurityããªã®ã§ãããã¾ãããInformation Securityãã¯CISOãFederal Chief Information Securityã¨ãã£ãåè©ã®ä¸é¨ã§ã¯ã§ã¦ãã¾ããããCybersecurityãã®ããã«å¤§çµ±é 令ã®ã¿ã¤ãã«ãã®ãã«ã§ã¦ãããã¨ãããã¾ããã
EO13681: Improving the Security of Consumer Financial Transactions (2014)
Identity Theftã«ç«¯ãçºããä¸æ£ã«ã¼ãå©ç¨ãªã©ã®èæ¯ãããéèæ©é¢ã®ãã¼ã¿ã»ãã¥ãªãã£æ¨æºã®åä¸ãæ¯æãæè¡ã®åä¸ãããããã®å¤§çµ±é 令ã§ãããã®å¤§çµ±é 令ã®å é²çãªç¹ã¨ãã¦ã¯ãä»ã®å¤è¦ç´ èªè¨¼ãæãã§ããããmultiple factors of authenticationãåã³èº«å 確èªï¼identity proofingï¼ãå¸æ°ã®å人ãã¼ã¿ã«ã¢ã¯ã»ã¹ããéã«å¿ é åããããå½ãã¦ãããã¨ã§ãã
ããã¯NIST SP800-63ãDigital Identity Guidelinesã*4ã§ãè¨åããã¦ãã¾ãã
EO13691: Promoting Private Sector Cybersecurity Information Sharing(2015)
æ°éã»ã¯ã¿ã¼ã®ãµã¤ãã¼ã»ãã¥ãªãã£æ å ±å ±æãä¿é²ãããã¨ãç®çã¨ãããµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ã¨ã¤ã³ã·ãã³ãã«é¢ããæ å ±ãå ±æããããã®æ å ±å ±æããã³åæçµç¹ï¼Information Sharing and Analysis Organization, ISAOï¼ã®è¨ç½®ãæ¨å¥¨ãã¦ãã¾ããISACï¼Information Sharing and Analysis Centerï¼ã¨ã®éãã¯ç¹å®ã®ç£æ¥ã»ã¯ã¿ã¼ã«ç¦ç¹ãå½ã¦ãããå¦ãã§ãããã¾ãæ¥æ¬å½å ã§ISAOã¯æ®åãã¦ãªãããï¼
EO13718: Commission on Enhancing National Cybersecurity(2016)
æãç·æ¥åº¦ã®é«ããµã¤ãã¼ã»ãã¥ãªãã£ä¸ã®èª²é¡ãç¹å®ãããããã®èª²é¡ã«å¯¾å¦ããããã®æ¦ç¥ãææ¡ããã¢ã¦ã§ã¢ãã¹ã¨æè²ãæ¨é²ãããå½å®¶ãµã¤ãã¼ã»ãã¥ãªãã£å¼·åå§å¡ä¼ãè¨ç½®ãã大統é 令ã§ãã å§å¡ä¼ã¯ã大統é ãæå®ãããµã¤ãã¼ã»ãã¥ãªãã£ããã¸ã¿ã«çµæ¸ãæ³å·è¡ãIT æè¡çã«é¢ããç¥èã»çµé¨ãæ㤠12 åã®å§å¡ããæ§æããã¾ã*5ãå®éã®æ§æå¡ã®ãªã¹ãã¯ãã¡ãã§ãï¼Wikiã§æ縮ã§ãï¼ã
ãã®å§å¡ä¼ã®ä¸ã¤ã®ææç©ã¨ãã¦ãReport on Securing and Growing the Digital Economyããããã¾ãã ãã®ã¬ãã¼ãã¯æ¬¡ã®ï¼ã¤ã®èª²é¡ã«å¯¾ãã16ã®å§åã¨53ã®è¡åè¨ç»ãææ¡ãã¾ããã
- æ å ±ã¤ã³ãã©ã¹ãã©ã¯ãã£ã¼ã¨ãã¸ã¿ã«ãããã¯ã¼ã¯ã®ä¿è·ãé²è¡ãã»ãã¥ãªãã£å¼·å
- ãã¸ã¿ã«ãããã¯ã¼ã¯ã¨ãã¸ã¿ã«çµæ¸ã®ã»ãã¥ãªãã£ã¨æé·ã®ããã®æè³ã®é©æ°ã¨å é
- ã¨ã³ãã¦ã¼ã¶ã¼ããã¸ã¿ã«æ代ã«é©å¿ããã
- ãµã¤ãã¼ã»ãã¥ãªãã£ã¯ã¼ã¯ãã©ã¼ã¹ã®è½åãæ§ç¯ãã
- æ¿åºããã¸ã¿ã«æ代ã«å¹æçã«ãå®å ¨ã«æ©è½ããã
- ãªã¼ãã³ã§ãå ¬å¹³ã競äºçãå®å ¨ãªã°ãã¼ãã«ãã¸ã¿ã«çµæ¸ã確ä¿ãã
ä¸æ¦ãåç·¨ã¯ä»¥ä¸ã§ãã
ãã¾ã
ä¸ççã«ã¯Cybersecurity Frameworkã®åç §æ°ãå§åçã§ãããæ¥æ¬ã§ã¯NIST SP800-171ãå¤ãåç §ããã¦ãããã§ãã
*1:https://www.nikkei.com/topics/22A00417
*2:https://xtech.nikkei.com/atcl/nxt/column/18/00001/00311/
*3:https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
*4:https://openid-foundation-japan.github.io/800-63-4/sp800-63.ja.html
*5:https://dl.ndl.go.jp/view/download/digidepo_9929064_po_02670112.pdf?contentNo=1