
åãæ¹æ¹é©ãæ°ããªçæ´»æ§å¼ãªã©ãæ±ããããä¸ã伿¥ã»çµç¹ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã«ãããæ°ããªèª²é¡ã«å¯¾ãã¦ãã¼ããã©ã¹ããã¢ãã«ã®ã»ãã¥ãªãã£å¯¾çãææ¡ãã¾ãã
ãµã¤ãã¼ã»ãã¥ãªãã£ã«ãããæ°ããªèª²é¡ä¾
- å®å
¨ãªãã¬ã¯ã¼ã¯ã®å®æ½
社å¤ã§ä½¿ç¨ãã端æ«ã社å¤ããã¢ã¯ã»ã¹ããæ©å¯æ å ±ãå®ãããã«å¿ è¦ãªå¯¾çãè¦ç´ãããã - ã¯ã©ã¦ããµã¼ãã¹ã®å®å
¨ãªå©ç¨
æ å ±ã·ã¹ãã é¨éãé¢ç¥ããªãä¸é©åãªã¯ã©ã¦ããµã¼ãã¹ã®å©ç¨(ã·ã£ãã¼IT)ãªã©ããçããæ å ±æ¼ãããªã¹ã¯ã«å¯¾å¿ãããã - VPNï¼Virtual Private Networkï¼è£
ç½®ããã®ç§»è¡
VPNè£ ç½®ã®IPã¢ãã¬ã¹ã¯å¤é¨ã«å ¬éããã¦ããããæ»æãåãããããã¨ãè£ ç½®èªä½ã®èå¼±æ§ã¨ãã£ãã»ãã¥ãªãã£ã®åé¡ãããã³éä¿¡ã®å®å®æ§ãã¹ã±ã¼ã©ããªãã£æ§ã¨ãã£ã課é¡ã«å¯¾å¿ãããã - æ¬ç¤¾ãæ¯ç¤¾ãæµ·å¤æ ç¹ãªã©ã®ã»ãã¥ãªãã£ããªã·ã¼ã®çµ±ä¸å
æ ç¹ãã¨ã«ç°ãªãã»ãã¥ãªãã£ã¬ãã«ãä¸å®ã¬ãã«ã«å¼ãä¸ãããããçµ±ä¸ããããªã·ã¼ãé©ç¨ãããã
ãã¼ããã©ã¹ããã¢ãã«ã¨ã¯
ã¼ããã©ã¹ãï¼Zero Trust Network, Zero Trust Architectureï¼ã¯ãè¨èã®éããä½ãä¿¡é ¼ããªãããã¨ãæå³ãã¦ããããããã¯ã¼ã¯ã®å é¨ã»å¤é¨ãåãã伿¥ãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãå ¨ã¦æ¤è¨¼ãã¦ãã許å¯ããã»ãã¥ãªãã£ã®èãæ¹ã§ãã徿¥ã®èªç¤¾ãããã¯ã¼ã¯ã¨ã¤ã³ã¿ã¼ãããï¼ç¤¾å¤ï¼ã®å¢çã§é²å¾¡ããã¢ãã«ã¨ã¯ç°ãªããããã¤ã§ãã©ãããã§ãå®å ¨ã«ãæ¥åãè¡ããã¨ãã§ãã¾ãã
ã¼ããã©ã¹ãã»ãã¥ãªãã£å®ç¾ã®ã¹ããã
ã¼ããã©ã¹ãã¢ãã«ããã¼ã¹ã«ããã»ãã¥ãªãã£å¯¾çãè¡ãã«ããããã客æ§ã®ã»ãã¥ãªãã£å¯¾çã«ãããç¾ç¶ã®èª²é¡ãæ´çãã解決ããããã«å¿ è¦ãªãµã¼ãã¹ã»è£½åã®ãææ¡ãå°å ¥ãå°å ¥å¾ã®éç¨ã¾ã§ãä¸è²«ãã¦æ¯æ´ãã¾ãã
課é¡ã®æ´ç
ãµã¼ãã¹é¸å®
PoC
æ¬æ ¼å°å ¥
éç¨ã»ç£è¦
ã¼ããã©ã¹ãã»ãã¥ãªãã£å¯¾å¿ã½ãªã¥ã¼ã·ã§ã³
ã¼ããã©ã¹ããå®ç¾ãã3ã¤ã®æè¡è¦ç´
ããã¤ã¹ãå©ç¨è ã®ãã±ã¼ã·ã§ã³ã«ä¾åããªãã»ãã¥ãªãã£ãæä¾ããä»çµã¿ãå®ç¾ããããã®æè¡è¦ç´ ãï¼ã¤ã®è¦³ç¹ã«åé¡ãã¦èãã¾ãã
3ã¤ã®æè¡è¦ç´ ã«å¯¾å¿ããã½ãªã¥ã¼ã·ã§ã³
ãªã½ã¼ã¹ããããã¯ã¼ã¯ãã¨ã³ããã¤ã³ãã®åæè¡è¦ç´ ã¨å¯¾å¿ã½ãªã¥ã¼ã·ã§ã³ããã客æ§ã®è¦ä»¶ã«å¿ãã¦çµã¿åããã¦é©ç¨ãã¾ãã
â»è£½åã®æè¡çãªé£æºå¯å¦ãæ¹æ³ãªã©ã¯åå¥ã«ãç¸è«ãã ããã
â»ã対å¿ã½ãªã¥ã¼ã·ã§ã³ãã¯ä¸ä¾ã§ããä¸è¨ä»¥å¤ã®è£½åã«ã¤ãã¦ã¯ããåãåãããã ããã
ããªã½ã¼ã¹ãèªè¨¼/èªå¯ï¼IDaaSï¼Identity as a Serviceï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Azure Active Directoryï¼Azure ADï¼
https://www.microsoft.com/ja-jp/ï¼Microsoft.comã«ç§»åï¼
ããããã¯ã¼ã¯ããã©ã¤ãã¼ãã¢ã¯ã»ã¹ï¼SDPï¼Software Defined Perimeterï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Zscaler Internet Accessï¼Zscaler Private Access
https://www.zscaler.jp/ï¼Zscalerãµã¤ãã«ã«ç§»åï¼
ããããã¯ã¼ã¯ãã¯ã©ã¦ãå¶å¾¡ï¼SWGï¼Secure Web Gatewayï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Zscaler Internet Accessï¼Zscaler Private Access
https://www.zscaler.jp/ï¼Zscalerãµã¤ãã«ã«ç§»åï¼
ããããã¯ã¼ã¯ãã·ã£ãã¼IT対çï¼CASB ï¼Cloud Access Security Brokerï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- McAfee MVISON Cloud
- Microsoft Cloud App Security
https://www.microsoft.com/ja-jp/ï¼Microsoft.comã«ç§»åï¼ - Zscaler Internet Accessï¼Zscaler Private Access
https://www.zscaler.jp/ï¼Zscalerãµã¤ãã«ã«ç§»åï¼
ãã¨ã³ããã¤ã³ããã¢ãã¤ã«ããã¤ã¹ã®ç®¡çï¼MDMï¼Mobile Device Managementï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Microsoft Intuneã
https://www.microsoft.com/ja-jp/ï¼Microsoft.comã«ç§»åï¼
ãã¨ã³ããã¤ã³ãããã¼ã¿ç®¡çï¼DLPï¼Data Loss Preventionï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- åå¥ã«ãç¸è«ãã ããã
ãã¨ã³ããã¤ã³ãã端æ«ã»ãã¥ãªãã£ï¼EDRï¼Endpoint Detection and Responseï¼
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Tanium Endpoint Management
https://www.intellilink.co.jp/business/security/tanium - ã¨ã³ããã¤ã³ãç£è¦ãµã¼ãã¹ with IntellilinkARGUS
â»ãTanium Endpoint Managementãã®24æé365æ¥ç£è¦ã»éç¨ãµã¼ãã¹ - Microsoft Defender ATP
https://www.microsoft.com/ja-jp/ï¼Microsoft.comã«ç§»åï¼ - Cybereason EDR
https://www.cybereason.co.jp/ï¼Cybereasonãµã¤ãã«ç§»åï¼
ãã°åæ
â 対å¿ã½ãªã¥ã¼ã·ã§ã³
- Microsoft Azure Sentinel
https://www.microsoft.com/ja-jp/ï¼Microsoft.comã«ç§»åï¼ - ã¦ã¼ã¶ã¼ã»æ©å¨æ¯ãèãåæã½ãªã¥ã¼ã·ã§ã³Exabeam
https://www.intellilink.co.jp/business/security/exabeam - Threat Huntingãµã¼ãã¹
https://www.intellilink.co.jp/business/security/threat_hunting
â»Threat Huntingãµã¼ãã¹ã¯ããã°ãæä¾ããã ããå½ç¤¾ãèç©ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ãå ã«ãè å¨ãä¾µå ¥ããçè·¡ã®æç¡ã調æ»ã»åæãããµã¼ãã¹ã§ããã¹ãããã§èª¿æ»ã»åæã叿ãããå ´åãªã©ã«æ´»ç¨ãã ããã
é¢é£æ å ±
ã³ã©ã ï¼å¯ç¨¿
ãã³ã©ã ãã¯ã©ã¦ãåã»ãã¬ã¯ã¼ã¯å社ä¼ã«ãããã»ãã¥ãªãã£ã¢ãã«ãã¼ããã©ã¹ããï½(1) NIST SP800-207 2nd DRAFTã®æ¦è¦ï½
https://www.intellilink.co.jp/column/security/2020/052000
ãã³ã©ã ã3åã§åãããã¼ããã©ã¹ãããã£ãºãã¼æ ç»ãã¢ã©ã¸ã³ãã«ç½®ãæãã¦èãã¦ã¿ã
https://www.intellilink.co.jp/column/security/2020/100900
ããã¥ã¼ã¹ã¬ã¿ã¼ããã¼ããã©ã¹ãã»ãã¥ãªãã£ãã®å¼·åã§ãªã¢ã¼ãéçºãæ¬æ ¼å
https://www.intellilink.co.jp/topics/notification/2020/072000
ããã¤ãããã¥ã¼ã¹æ²è¼ããªãããã¾ã¼ããã©ã¹ããªã®ã
第1åãã¼ããã©ã¹ãã»ãã¥ãªãã£ã¨ã¯ã
https://news.mynavi.jp/article/zerotrust-1/
第2åãã¼ããã©ã¹ãã®æ¦è¦ã
https://news.mynavi.jp/article/zerotrust-2/
第3åãã¼ããã©ã¹ãã§æ±ããããã½ãªã¥ã¼ã·ã§ã³ - åç·¨ã
https://news.mynavi.jp/article/zerotrust-3/
第4åãã¼ããã©ã¹ãã§æ±ããããã½ãªã¥ã¼ã·ã§ã³ â å¾ç·¨ã
https://news.mynavi.jp/article/zerotrust-4/
第5åãã¼ããã©ã¹ãã¢ãã«ã®å°å
¥ã
https://news.mynavi.jp/article/zerotrust-5/
ã@ITæ²è¼ãç¹éï¼ã¯ã©ã¦ããç¨ãã¦ãSASEãã§çµ±åãã»ãã¥ãªãã£ã¨ãããã¯ã¼ã¯ï¼2ï¼
伿¥ã¯ã¼ããã©ã¹ãï¼SASEã¨ããçæ³ãã©ããããã©ãã¾ã§ç®æãã¹ããââNTTãã¼ã¿å
端æè¡ãä¸è¶³æ©ãå°å
¥ããçç±
https://www.atmarkit.co.jp/ait/articles/2103/09/news003.html
ç´¹ä»è³æ
åç»
ãè¬æ¼åç»ãã¼ããã©ã¹ãã»ãã¥ãªãã£ãèããï½éçºè
ã®å¨å®
å¤åçã90ï¼
ã«ããä¸ã§è¦ãããã¨ï½
https://www.youtube.com/watch?v=02UTm3Gnt6k