PCI DSSå¾¹åºè§£èª¬
ã¯ããã«
PCI DSSã¨ã¯ï¼
ã¯ã¬ã¸ããã«ã¼ãã®ä¼å¡æ å ±ä¿è·ãç®çã¨ãã¦çå®ãããã«ã¼ãæ å ±ã»ãã¥ãªãã£ã®å½éçµ±ä¸åºæºã§ãã
ã¯ã¬ã¸ããã«ã¼ãã®ã·ã¹ãã 以å¤ã«ã¯é¢ä¿ç¡ãã®ï¼
ISMSãPãã¼ã¯ãªã©ã®è¦æ ¼ã§æ±ãããã¦ãã管ççãããã¯ããã«å
·ä½çã§ãããã¨ãããå人æ
å ±ä¿è·ãå¶æ¥ç§å¯ä¿è·ã®ããã®ãã¼ã¹ã©ã¤ã³ã¨ãã¦åèã«ãªãã¾ãã
ããã«ãä¸ã®ä¸ã®æµãã«è¿½å¾ãã¦æ¹è¨ãããé¢é£åºæºã»åèæ
å ±ã追å ããã¦ãã¦ãã¾ãã®ã§
- èå¼±æ§ã¹ãã£ã³ãèå¼±æ§è¨ºæããããã¬ã¼ã·ã§ã³ãã¹ãã®å®æ½è¦³ç¹ãé »åº¦
- äºè¦ç´ èªè¨¼ãå¤è¦ç´ èªè¨¼ãæ±ãããããã¤ã³ã
- ã¯ã©ã¦ãå©ç¨æã«ããã¦èæ ®ãã¹ãã»ãã¥ãªãã£ã責任åçç¹
- SaaSã¨ãã¦æä¾ãããã½ããã¦ã§ã¢ã®ã»ãã¥ãªãã£
- ã¹ãã¼ããã©ã³ãã¿ãã¬ããã®ã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£
- æ©å¯æ å ±ãæ©å¾®æ å ±ã®ç¡ä¾¡å¤å
- ãµãã©ã¤ãã§ã¼ã³ã«ãããã»ãã¥ãªãã£ç®¡ç
ãªã©ãèæ ®ããããã§ããPCI DSSãä»ã®é¢é£åºæºãããã³ãããã®è¿½å æ å ±ãåèã¨ãããã¨ã¯ã¨ã¦ãæå¹ã§ãã
ãPCI DSSå¾¹åºè§£èª¬ãã®ç®çã¯ï¼
ããå®å ¨ãªã«ã¼ã社ä¼ã®å®ç¾ãç®æããPCI DSSããã³ãã®é¢é£åºæºã追å æ å ±ã解説ãã¦ãã¾ããã¯ã¬ã¸ããã«ã¼ãæ å ±ã®ä¿è·ã«ã¨ã©ã¾ãããã»ãã¥ãªãã£å¯¾çãèæ ®ããããã§ãåèã¨ãã¦ããã ããã°å¹¸ãã§ãã
2024å¹´
ECäºæ¥è ãã¯ã¬ã¸ããã«ã¼ãã»ã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³5.0çããã³SAQï¼èªå·±å診ï¼ã§æ±ããããã»ãã¥ãªãã£å¯¾çã¨ã¯ãï½SAQ Aã¨SAQ A-EPã®éãã¨ä¸»ãªè¦ä»¶ï½
2023å¹´
PCI DSS Version 4.0ã«ãããå¤æ´ç¹ã®ãã¤ã³ãã第äºåãï½ æªæ¥æ¥ä»ã®æ°è¦è¦ä»¶ã«ã¤ãã¦ï½
2022å¹´
ãPCI DSS Version 4.0ã«ãããå¤æ´ç¹ã®ãã¤ã³ãã第ä¸åãï½ç§»è¡ã¹ã±ã¸ã¥ã¼ã«ã¨ä¸»ãªå¤æ´ç¹ã®æ¦è¦ï½
2020å¹´
PCI ã®æ°ããªã½ããã¦ã§ã¢ã»ãã¥ãªãã£åºæº Software Security Framework - ãã®5ï¼SSFã®èªå®ããã°ã©ã ã¨ã¾ã¨ã
PCI ã®æ°ããªã½ããã¦ã§ã¢ã»ãã¥ãªãã£åºæº Software Security Framework - ãã®4ï¼Secure Software Lifecycle Standardã®æ¦è¦
PCI ã®æ°ããªã½ããã¦ã§ã¢ã»ãã¥ãªãã£åºæº Software Security Framework - ãã®3ï¼Secure Software Standardã®ã³ã³ããã¼ã«ç®æ¨
PCI ã®æ°ããªã½ããã¦ã§ã¢ã»ãã¥ãªãã£åºæº Software Security Framework - ãã®2ï¼Secure Software Standardã®æ¦è¦
æ°åã³ããã¦ã¤ã«ã¹ï¼COVID-19ï¼ã¨ PCI DSS ãªã¢ã¼ãè©ä¾¡
2019å¹´
ã¯ã©ã¦ããµã¼ãã¹å©ç¨æã®PCI DSSæºæ ã®ãã¤ã³ãâ¡ ï½PCI DSS Implementation Considerationsã®æ¦è¦ï½
ãéä¿æåã対å¿å¾ã®å çåºã«æ±ããããã»ãã¥ãªãã£å¯¾ç
PCI ã®æ°ããªã½ããã¦ã§ã¢ã»ãã¥ãªãã£åºæº Software Security Framework - ãã®1ï¼Framework ã®æ¦è¦
2018å¹´
å½ç¤¾ã翻訳ååãããPCI DSS v3.2.1 æ¥æ¬èªçããå ¬éããã¾ãã
ã¯ã©ã¦ããµã¼ãã¹å©ç¨æã®PCI DSSæºæ ã®ãã¤ã³ã ï½PCI DSS Responsibility Matrixã¨ã¯ï½
æ±ããããæ¥çã®é£æºæ å ±ã®éä¿æåã¨PCI DSSæºæ ãè¦ä»¶ã«
ããã«ä¼´ããå½é ã«ã¼ãã®ä½¿ç¨ãæ¬äººã«ãªããã¾ããã«ã¼ãã®ä¸æ£ä½¿ç¨ãå¾ã絶ããªãç¶æ³ã ãã»ãã¥ãªãã£äºæ¥é¨ ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°æ å½ æ å½èª²é· ã·ãã¢ã³ã³ãµã«ã¿ã³ãã®ç¾½çåäºç´ã¯â¦
ã«ã¼ãæ å ±éä¿æåã®ããã®ãPCI DSS Tokenization Guidelinesã
å®è¡è¨ç»ã§ã¯ãå çåºã«ãããã¯ã¬ã¸ããã«ã¼ãæ å ±ä¿è·ã®ããâ¦
2017å¹´
OWASP Top 10 2017 ã®ãªãªã¼ã¹ã¨PCI DSSè¦ä»¶ã®å½±é¿ã«ã¤ãã¦
OWASP Top 10ã¯ãPCI DSSè¦ä»¶ã®ä¸ã®ã¢ããªã±ã¼ã·ã§ã³éçºï¼è¦ä»¶6ï¼ããããã¬ã¼ã·ã§ã³ãã¹ãï¼è¦ä»¶11ï¼ãªã©ã§åç §ããã¦ãããã¨ãå¤ãâ¦
PCI DSSç¶ææ´»åã®ãã¤ã³ãï½ãBest Practices for Maintaining PCI DSS Complianceãã®æ¦è¦ï½
å½ç¤¾ã翻訳ååãããPCI DSS SAQ v3.2 Rev. 1.0æ¥æ¬èªçããå ¬éããã¾ãã
ãPCI DSS v3.2ãã¨åæ§ãJCDSCï¼æ¥æ¬ã«ã¼ãæ å ±ã»ãã¥ãªãã£åè°ä¼ï¼ã®QSAé¨ä¼æå¿ã«ããã¯ã¼ãã³ã°ã«ããã¦â¦
å½ç¤¾ã翻訳ååãããPCI DSS v3.2 æ¥æ¬èªçããå ¬éããã¾ãã
å½ç¤¾ã¯ã2016å¹´5æãããJCDSCï¼æ¥æ¬ã«ã¼ãæ å ±ã»ãã¥ãªãã£åè°ä¼ï¼ã®QSAé¨ä¼æå¿ã«ããã¯ã¼ãã³ã°ã«ããã¦ã翻訳å質åä¸ãç®çã«ã翻訳ãã¬ãã¥ã¼ãååã§è¡ããå ¬éã«åãã¦PCI SSCã¨ã®èª¿æ´ãé²ãã¦ãã¾ããâ¦
2020å¹´ãªãªã³ããã¯ã»ãã©ãªã³ããã¯æ±äº¬å¤§ä¼éå¬ã«åãã¦ã® SAQã«ããPCI DSSã¸ã®åçµã¿
2016å¹´
2020å¹´ãªãªã³ããã¯ã»ãã©ãªã³ããã¯æ±äº¬å¤§ä¼éå¬ã«åãã¦ã® ãPrioritized Approach for PCI DSSãæ´»ç¨ã®ããã
PCI DSS v3.2主ãªå¤æ´ç¹ã®è§£èª¬
PCI DSS v3.2ã®å ¬éã¨å¤æ´ç¹ä¸è¦§
PCI DSS v3.2 ã¾ããªããªãªã¼ã¹
PCI SSCã¯2015å¹´12æã«å ¬éãããSSLããã³åæã®TLSããã®ç§»è¡æéã®å»¶é·ã«é¢ããéç¥[2][3]ã§ã2016å¹´ã«PCI DSS v3.1ãæ´æ°ãããäºå®ã§ããã¨ãã¦ãã¾ãããâ¦
SSL/TLS 1.0 ã¯ãã¤ã¾ã§ã«ç¡å¹åããªããã°ãªããªããï¼
2015å¹´
èå¼±ãªSSLããã³TLSããã®ç§»è¡æéã®å¤æ´ã«ã¤ãã¦
PCI SSC ã¯ã2015å¹´4æã«å ¬éãã PCI DSS 3.1 ã§ã移è¡æéã2016å¹´6æ30æ¥ã¨ãã¦ãã¾ãããããã®å¾ããã¸ãã¹çå¶ç´ããã³æè¡çå¶ç´ã«é¢ãããã£ã¼ãããã¯ãåãâ¦
PCI DSS v3.1ã®å ¬éã¨å¤æ´ç¹ã®æ¦è¦
対é¢ï¼POSå çåºãèæ ®ãã¹ãï¼ã¤ã®ãã¤ã³ãï¼å¾ç·¨ï¼
対é¢ï¼POSå çåºãèæ ®ãã¹ãï¼ã¤ã®ãã¤ã³ãï¼åç·¨ï¼
SSL v3.0 ã®èå¼±æ§ã¨PCI DSSããã³PA-DSSã®æ¹è¨ã«ã¤ãã¦
ï½2014å¹´
第01åãPCI DSSã®æ¦è¦ãï¼èµ·æºã¨ãã®å¿ è¦æ§ï¼
第02åãPCI DSSã®æ¦è¦ãï¼PCI DSSã®12è¦ä»¶ãèªã¿è§£ãï¼
å ¨ã¦ã®ææ¸ã¯ãPCI SSCã®ãµã¤ããããã¦ã³ãã¼ããããã¨ãã§ãã¾ãâ¦
第03åããããã¯ã¼ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³ã«ããã¢ããã¼ã
https://www.pcisecuritystandards.org/pci_security/
PCI DSSãã¼ã¸ã§ã³1.2ã§ã¯ãæ§ã ãªé ç®ã«ã¤ãã¦æ確åã説æã®ä»ä¸ãªã©ãè¡ãããããåããããããå¿ è¦ã«å¿ãã¦æè»ã«ãªã£ã¦ãã¾ãâ¦
第04åãPrioritized Approachã®æ´»ç¨
第05åãã«ã¼ãä¼å¡ãã¼ã¿ãæ¢ã
第06åãç¡ç·ç°å¢ã«ãããã»ãã¥ãªãã£å¯¾ç
第07åãåºæºã®ã©ã¤ããµã¤ã¯ã«å¤æ´ã§ã©ããªããï¼
ä»åã¯ãã©ã¤ããµã¤ã¯ã«ãå¤æ´ããã3ã¤ã®åºæºã®ãã¡ãPCI DSSã¨PA-DSSã«ã¤ãã¦ãã©ã¤ããµã¤ã¯ã«ã®ä¸»ãªå¤æ´ç¹ã¨ä»å¾ã®å±éã説æãããã¨æãã¾ãã
第08åãPCI DSS v2.0å ¬é
ç¾å¨PCI SSCããã¯ãè±èªçã®ã¿å ¬éããã¦ãããæ¥æ¬èªçã®æ£å¼å ¬éã¯å¾ã«ãªãäºå®ã§ãã
æ¥æ¬å½å ã§ã¯PCI DSS対å¿ä¼æ¥ãå¢ãã¦ãããä¸æ¥ã§ãæ©ãæ¥æ¬èªã§ã®æ å ±å±éãæå¾ ããã¦ãããã¨ãããå¼ç¤¾ã§ã¯ãæ ªå¼ä¼ç¤¾æ¥ç«ã½ãªã¥ã¼ã·ã§ã³ãºã¨å ±åã§"PCI DSSãã¼ã¸ã§ã³2.0 翻訳ç"ãä½æãå ¬éãããã¾ãâ¦
第09åãASVã®å½¹å²ã¨å®æçãªãã¹ã
第10åãä»®æ³ç°å¢ã«å¯¾ããPCI DSSã®è¦ç¹â¦Part.1
第11åãä»®æ³ç°å¢ã«å¯¾ããPCI DSSã®è¦ç¹â¦Part.2
ååã§ã¯ãã¾ã使ç¨ãããè¨èãæ¦å¿µã®å®ç¾©ãè¡ã£ã¦ãããPCI DSSã«ãã¾ãä¾åããªãå½¢ã§â¦