PCI DSS対çã«ããããã³ã¼ã«ã»ã³ã¿ã¼ã«å¯¾ããèãæ¹ã¨ã¯
ãã¯ã¬ã¸ããã«ã¼ãåå¼ã«ãããã»ãã¥ãªãã£å¯¾çã®å¼·åã«åããå®è¡è¨ç»ï¼ï¼ï¼ï¼ï¼ï¼ãå
¬è¡¨çããâ»1ã2018å¹´3æã«å
¬éãããé»è©±ããã¬ãã§æ³¨æãåããMOTOï¼Mail-Order/Telephone-Orderï¼é販ã®éä¿ææ¹çãå
·ä½åããã¾ãããMOTOé販ã§ä½¿ããã¦ããã³ã¼ã«ã»ã³ã¿ã¼ã·ã¹ãã ããã«ã¼ãæ
å ±ã®éä¿æåãã«è©²å½ããªãå ´åãåºæ¬çã«PCI DSSæºæ ãå¿
è¦ã§ãããPCI DSSã®è¦³ç¹ããMOTOã¯ECã¨ã¯ä½ãéããï¼ã³ã¼ã«ã»ã³ã¿ã¼ã·ã¹ãã ã§æµããé³å£°ãã¼ã¿ã¯ã©ã®ããã«æ±ãã¹ããï¼ãæ´çããå¿
è¦ãããã¾ãã
人ç©A
å
¥ç¤¾3å¹´ç®ã§ãããã»ãã¥ãªãã£è«çç¥èã¯ããç¨åº¦æã£ã¦ããããå®åçµé¨ã¯ãã¾ããªãã
人ç©B
QSAï¼PCI DSSèªå®å¯©æ»æ©é¢ï¼ è³æ ¼åå¾è
ãé·å¹´ã®ã³ã¼ã«ã»ã³ã¿ã¼è¨è¨ãæ§ç¯çµé¨ãæã£ã¦ããã
ãå®è¡è¨ç»2018ãã§MOTOã¨ããåèªãåºã¦ãããã©ãPCI DSSã®ä¸çã§ã¯ãã¾ã馴æã¿ããªãã§ããï¼
ãï½ï½é¦´æã¾ãªãã£ã¦ã©ããããã¨ã§ããï¼
PCI DSSè¦ä»¶ã§MOTOã¨ããåèªãè¦ããã¨ãªããããã
PCI DSSè¦ä»¶ã«ã¯MOTOã¨ã¯ã£ããè¨è¼ããã¦ããªãã§ãããAOCã¨å¼ã°ããPCI DSSæºæ 証ææ¸ã®å çåºæ¥å説ææ¬ã«ã¯è¨è¼ããã¦ãã¾ãã
å çåºæ¥å説ææ¬ããã®æç²
審æ»ã§å¯¾è±¡ã¨ããåå¼ãã£ãã«ï¼
- MOTO(Mail-Order/Telephone-Order)
- EC
- 対é¢
MOTOãECã¨åãã¬ãã«ã®ããã«æ¸ããã¦ãããã©æ¬å½ã§ããï¼
ECã¨åãã¬ãã«ã£ã¦ã©ããããã¨ã§ããï¼
ECã§ã¯ãã«ã¼ãæ
å ±ãã¼ã¿ãå
Œ
±ãããã¯ã¼ã¯ã§æµãã¦ããã®ã§ã»ãã¥ã¢ã«æ±ãã¹ãã¨èãããã©ãMOTOã¯ä¸»ã«é»è©±ã§åå¼ããã®ã§å
Œ
±ãããã¯ã¼ã¯ã«æ¯ã¹ãã¨ãªãã¨ãªãå®å
¨ãªæ°ããã¾ããã
ãå®å
¨ãªæ°ããããã ãã§ãããå®ã¯å
¨ç¶å®å
¨ã§ãªãã®ã§ãã
ãããªã®ã§ããï¼ECã¨åãã¬ãã«ã§æ±ãã¹ãã§ããã°ãPCI SSCãããã¡ãã£ã¨MOTOã«å¯¾ãã¦æ確ã«è¨åãã¦ã»ããã§ããï¼
å®ã¯PCI SSCãæããMOTOã®éè¦æ§ãç¥ã£ã¦ãã¦ã2011å¹´ã«ä»¥ä¸ã®é¡åã®ããã¥ã¡ã³ããåºãã¦ãã¾ããPCI DSSè¦ä»¶ã¸ã®è£è¶³æ
å ±ã¨ãã¦ã®æ±ãã§ããããã
- PCI Data Security Standard (PCI DSS) Information Supplement: Protecting Telephone-based Payment Card Dataâ»2
Information Supplement ? ã£ã¦ãªãã§ããï¼
æ°èãä¾ã§ããã¨ãå·å¤ãã®ãããªãã®ã§ããã
æ£ç¢ºã«è¨ãã¨ãè£è¶³æ
å ±ãã®æå³ã§ãPCI SSCãéè¦åº¦ãé«ãã¨å¤æãããè£è¶³æ
å ±ãç¹å¥ã«çºè¡¨ããæã«ä½¿ãç¨èªã§ãã
ãï½æ¬å½ã§ãããã°ã¼ã°ã«ã§ãããããã¾ãããä»ããããã¦ããã®ã¯2011å¹´çãªã®ã§ããªãå¤ãã§ããã
ä»å¹´ã®å¹´æ«ã«æ°ãããã¼ã¸ã§ã³ãåºãäºå®ã§ããã¨PCI SSCã¯äºåãåºãã¦ãã¾ãã
ä»å¹´ã®å¹´æ«ï¼ãå®è¡è¨ç»2018ãã§ã®MOTOã¨ãåãå¹´ã«ãªã£ã¦ãããã©ããªã«ãé¢ä¿ãããã§ãããï¼
å¤åãå¶ç¶ãã ã¨æãã¾ãããéå½ ãã§ããå¯è½æ§ãããã¾ãããããï¼æ±ï¼
PCI SSCãããããMOTOã«é¢ããããã¥ã¡ã³ããåºããèæ¯ã«ã¯ãªã«ããããã§ãããï¼
対é¢å çåºãECå çåºã®å¯¾çãé²ã¿ãããã«ã¼ã®æ»æ対象ã対çã®ãã¾ãé²ãã§ããªãMOTOã«ç§»ãå§ãããã¨ãåå ããããã¾ãããã¾ããã»ã¨ãã©ã®ã³ã¼ã«ã»ã³ã¿ã¼ã§ã¯ãæ³å¾ä¸ã®å¿
è¦æ§ãã¾ãã¯ãµã¼ãã¹åä¸ã®ããã«é話å
容ãé²é³ãã¦ããããã®æ
å ±ãæ»æ対象ã¨ãªãããã®ã大ããªè¦å ã ã¨æãã¾ããâ»2
é話é²é³ï¼ããªãã¡é»è©±ã§ã«ã¼ãæ
å ±ãåã£ãããããã¨ãé²é³ããã¦ãé²é³ãããé³å£°ãã¼ã¿ãããã«ã¼ã«çã¾ããã¨ãã«ã¼ãæ
å ±ãæ¼ãããããã¨ãããã¨ã§ããï¼æ¥æ¬èªãåããããã«ã¼ã¯ããªãå°ãªãã¨æããã©ãããï¼æ±ï¼
é³å£°ãã¼ã¿ãããã¹ãåãããã¼ã«ã¯ä¸ã®ä¸ã«å±±ç¨ããã®ã§ãã«ã¼ãæ
å ±ãå«ãé³å£°ãã¼ã¿ã¯çã®ã«ã¼ãæ
å ±ãã¼ã¿ã¨åãã¬ãã«ã§æ±ãã¹ãã§ãã
ããããã°ã³ã¼ã«ã»ã³ã¿ã¼ã«é»è©±ãã¦ãã«ã¼ãæ
å ±ãå£é ã§ä¼ããã«ãç´æ¥é»è©±ã®ãã¿ã³ã§çªå·ãå
¥åããæãããã¾ããï¼
ã¯ããããã¯IVRã¨ããã·ã¹ãã ãå¿çããæã§ãã
ãã®æã¯ãç´æ¥é»è©±ã«ã«ã¼ãæ
å ±ãå
¥åããã®ã§ãé²é³ãªãããããªããããªãã§ããï¼
DTMFãã¼ã³ã¨ãã¦é²é³ããã¾ããDTMFãã¼ã³ã¨ãã¦é²é³ãããé³å£°ãã¼ã¿ãããã«ã¼ã«çã¾ããå ´åã§ããã«ã¼ãæ
å ±æ¼ããã¨åããã¨ã«ãªãã¾ãã
D...T....ãªããçºé³ããããããããã
é»è©±æ¥çã§ã¯åºæ¬æ¦å¿µãªã®ã§ãèå³ããã°ã°ã°ã£ã¦ã¿ã¦ãã ããããããããããã®ãããªé³ãæãã¾ããåãããããä¾ã§è¨ãã¨ãæ ç»ãåæ¢åµã³ãã³ãã§é»è©±ã®ãã¿ã³ãæ¼ããã«ã声ã§é»è©±ããããæåãªã·ã¼ã³ãããã¾ããã
æ ç»ãåæ¢åµã³ãã³ãã§ããï¼ä»åº¦èª¿ã¹ã¦ã¿ã¾ããããã¯é¢ç½ããã§ããã
å話å¨ãå¤ããå¾ãé»è©±ã®ãã¿ã³ãæ¼ããªãã£ãã®ã§ãå話å¨ã«åãã£ã¦ãããããããã¨å£°ãåºãã¦é»è©±ãæããã·ã¼ã³ã§ãã
DTMFãã¼ã³ã¯äººã®å£°ã§ã容æã«æ¬ä¼¼å¯è½ã§ããï¼ããã¯åãã¦ç¥ãã¾ãããããè¨ãããã¨ãMOTOã対çãã¡ããã¨åããªãã¨ãããªãæ°ããã¾ãããã¨è¨ã£ã¦ãããã¼ã¿ã¨é³å£°ãå
Œ
±ãããã¯ã¼ã¯ã¨å
¬è¡é»è©±ç¶²ã¨ã§ã¯æ¬¡å
ãéãã®ã§ããããªãPCI DSSãMOTOã«é©ç¨ããã¨ãã¦ãéåæã¯ããªãããã¾ããã
å
Œ
±ãããã¯ã¼ã¯ã¨å
¬è¡é»è©±ç¶²ï¼ããã¨ããã«æ°ãã¤ãã¾ãããã
å
Œ
±ãããã¯ã¼ã¯ã¯ãªã¼ãã³ãªã¤ã¡ã¼ã¸ã ããå
¬è¡é»è©±ç¶²ã¯ããç¨åº¦ã¯ãã¼ãºããã¦ããã¤ã¡ã¼ã¸ãããã¾ãã
ã¾ãã«ãã£ãããéãã§ããä¾ãã°ãPCI DSSè¦ä»¶4ã¯ãå
Œ
±ãããã¯ã¼ã¯çµç±ã§æ©å¯æ§ã®é«ãã«ã¼ãä¼å¡ãã¼ã¿ãä¼éããå ´å対象ã«ãªãã¾ãããå
¬è¡é»è©±ç¶²ã使ã£ãé話ã®å ´åã«ã¯ãã«ã¼ãä¼å¡æ
å ±ãå«ãã§ãã¦ã対象å¤ã«ãªãã¾ããâ»2,3,4
ã¡ãªã¿ã«ãã³ã¼ã«ã»ã³ã¿ã¼ã®å ´åãå
¬è¡é»è©±ç¶²ã¨æ¥ç¶ããæ©å¨ã¯ä½ã«ãªãã¾ããï¼ã©ãããPCI DSSã¹ã³ã¼ãã«å
¥ããã§ããï¼
é常ã®ã³ã¼ã«ã»ã³ã¿ã¼ã®å ´åãå
¬è¡é»è©±ç¶²ã¯ã»ã¨ãã©PBXã¨ããæ©å¨ã«æ¥ç¶ãããã®é
ä¸ã«é話é²é³è£
ç½®ãªã©ãããã¾ããããã³ã¼ã«ã»ã³ã¿ã¼ã§ã«ã¼ãæ
å ±ãåãæ±ãå ´åã«ã¯ãèªç¤¾ã§ä¿æããæ©å¨ã»ãããã¯ã¼ã¯ã«ããã¦ã«ã¼ãæ
å ±ã転éãå¦çãä¿ç®¡ãããã¨ã«ãªãã®ã§ãPBXæ©å¨ããPCI DSSã¹ã³ã¼ãã«å
¥ãã¨æãã¾ãã
PBXï¼ãªãã話ãã ãã ãããããããªãã¾ããã
é常ã®ã³ã¼ã«ã»ã³ã¿ã¼ã®æ§æã¯ä»¥ä¸ã«ãªã£ã¦ãã¾ãã
æ§æå³ããã¿ãã¨ã確ãã«ãã¹ã¦ã®ã³ã¼ã«ã¯PBXãçµç±ããã®ã§ãããããããã°ããã®åã©ããã§PCI DSSæºæ ããIVR決æ¸ãµã¼ãã¹ã®ã¿æä¾ããåºåãè¦ããã¨ããã¾ããããªãã¡ããã®æ§æå³ã§ããã¨ãIVRã第ä¸è
ãæä¾ãããã¨ã§ããï¼
ã¯ããããã§ããæ£ç¢ºã«è¨ãã¨ä»¥ä¸ã®ï¼ã¤ã®ãã¿ã¼ã³ãããã¾ãã
â PBXã«çä¿¡å¾ãå
¬è¡é»è©±ç¶²çµç±ã§ç¬¬ä¸è
ã®IVRã«é»è©±è»¢éãããã¿ã¼ã³
â¡ PBXã«çä¿¡å¾ãå çåºã®ãããã¯ã¼ã¯ï¼ä¾ï¼VPNãªã©ï¼çµç±ã§ç¬¬ä¸è
ã®IVRã§å¦çãããã¿ã¼ã³
PCI DSSã®è¦³ç¹ã§ã¿ãå ´åãä½ãéãã®ã§ããï¼
ãã¿ã¼ã³â ã®å ´åã¯ãPBXã«çä¿¡ããã³ã¼ã«ã第ä¸è
ã®IVR決æ¸ã·ã¹ãã ã«è»¢éããã¨å®å
¨ã«PBXã®å¶å¾¡ããé¢ããããªãã¡ãã«ã¼ãæ
å ±ã¯å çåºãä¿æããæ©å¨ã»ãããã¯ã¼ã¯ãçµç±ããªããã¨ã«ãªããPCI DSSã¹ã³ã¼ãããå¤ãããã¨ã«ãªãã¾ãããã¿ã¼ã³â¡ã®å ´åã¯ãPBXã«çä¿¡ããã³ã¼ã«ã¯ãPBXãçµç±ããã¾ã¾IVR決æ¸ã·ã¹ãã ã«è¡ãããªãã¡ãã«ã¼ãæ
å ±ã¯å çåºãä¿æããæ©å¨ã»ãããã¯ã¼ã¯ãçµç±ãããã¨ã«ãªããPBXã¯PCI DSSã¹ã³ã¼ãããå¤ãã¾ããã
ãPCI DSS対象ç¯å²ãã§ããã ã縮ãããã¨ããèãæ¹ã«åºã¥ãã¨ããã¿ã¼ã³â ãé¸ãã ã»ãã絶対ã«æ¥½ã§ããã
確ãã«ãPCI DSS対象ç¯å²ãã®è¦³ç¹ããã¿ãå ´åããã¿ã¼ã³â ã®ã»ããããã§ãããå®å
¨ã«PBXã®å¶å¾¡ããé¢ããã¨ããå¼±ç¹ãããã¾ããä¾ãã°ãã³ã¼ã«ã»ã³ã¿ã¼ã®ãªãã¬ã¼ã¿ã¼ã«çä¿¡ããã³ã¼ã«ã決æ¸ã®ããã«ç¬¬ä¸è
ã®IVR決æ¸ã·ã¹ãã ã«è»¢éãã¦ã決æ¸ãçµãã£ãå¾ãå¼ãç¶ãå
ã®ãªãã¬ã¼ã¿ã¼ã¨é話ãããã±ã¼ã¹ãè¦ã¦ã¿ã¾ãããããã¿ã¼ã³â ã®å ´åIVR決æ¸ã·ã¹ãã ã«è»¢éããæç¹ã§ãå®å
¨ã«PBXã®å¶å¾¡ããé¢ããããªãã¡ããªãã¬ã¼ã¿ã¼ã¨ã®é話æ
å ±ãææ¡ã§ããªããªãã®ã§ã決æ¸ãçµãã£ãå¾å
ã®ãªãã¬ã¼ã¿ã¼ã¨é話ã§ããªããªãã¾ããããã¯åãªãä¸ä¾ã§ããããããªãã¨ããã£ã¦ããã¿ã¼ã³â¡ã主æµã«ãªã£ã¦ããã¨æãã¾ãã
ãã¿ã¼ã³â¡ã®å ´åãPCI DSS対象ç¯å²ã縮ãããæ¹æ³ã¯ãªãã§ããï¼
æåã«ããã¹ã対çã¯ãããã¯ã¼ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³ã«ãªãã¾ããã詳細ã¯ã
ã«ã¼ãä¼å¡ãã¼ã¿ãæ¢ããã確èªãã¦ã¿ã¦ãã ããããã®è¨äºã§ã®ãã«ã¼ãä¼å¡ãã¼ã¿ãããã«ã¼ãæ
å ±ãå«ãé話ã¾ãã¯DTMFãã¼ã³ãã«èªã¿æ¿ãã¦ãããã¨ãPCI DSS対象ç¯å²ã®èãæ¹ã¯å
¨ãåãã§ããã¾ãããããã¯ã¼ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³ä»¥å¤ã®ç´°ãã対çã«ã¤ãã¦ã¯ãWhere to Start, Decision Process for Voice Recordings
â»2ãåèã«ãã¦ãã ããã
ã2018 FIFAã¯ã¼ã«ãã«ãããã®ä¸ç¶ãããããå§ã¾ãã®ã§ãä»æ¥ã®ä¼è©±ã¯ãããããã«ãã¾ããããï¼
åããã¾ããã次åWhere to Start, Decision Process for Voice Recordingsâ»2ã«é¢ãã¦è©³ããæãã¦ãã ããã
äºè§£ãã¾ãããã¡ãªã¿ã«ä»æ¥ã¯å¸°ã£ã¦ããæ ç»ãåæ¢åµã³ãã³ãã®ãã®æåãªã·ã¼ã³ãè¦ããã§ããï¼ï¼æ±ï¼
å¼ç¨å
Writer Profile
ã»ãã¥ãªãã£äºæ¥é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°æ
å½ ãã¼ãã³ã³ãµã«ã¿ã³ã
å´ ç³å Cui Bingnanï¼CISSPã AWS SAAï¼
ã³ã¼ã«ã»ã³ã¿ã¼ã·ã¹ãã ã®è¨è¨æ§ç¯ãç´8å¹´ãæµ·å¤è£½ATMæ©å¨ã®æ¥æ¬å½å
å±éã§ã³ã³ãµã«ã¿ã³ããç´2å¹´çµé¨ããç¾å¨ã¯ä¸»ã«PCI DSSãP2PEã®æºæ æ¯æ´ãªã©ã«å¾äºãæ¥ã»ä¸ã»éã»è± è¨èªã§ã³ãã¥ãã±ã¼ã·ã§ã³å¯è½ã