NISTã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ã¨ã¯ ï½ç¬¬1åãSP800-37 Rev2ã¨ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ï½
ã¯ããã«
2018å¹´12æã«NISTï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼ãããªã¹ã¯ããã¸ã¡ã³ãã®ãã¬ã¼ã ã¯ã¼ã¯ãå®ããææ¸SP800-37 Revision 2ãå
¬éããã¾ããã
å½ææ¸ã¯ã2014å¹´ã«å
¬éãããSP800-37 Revision1ã®ä¿®æ£çã§ããã4å¹´ã¶ãã®æ¹è¨ã¨ãªãã¾ãã
æ¬ã³ã©ã ã§ã¯ããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã¨ã¯ä½ãã Revision 2ã¸ã®æ¹è¨ã§ä½ãå¤ãã£ãã®ããè¦ã¦ããããã¨æãã¾ãã
1.SP800-37 Rev2ã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ã¨ã¯
ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼Risk Management Frameworkï¼ã¨ã¯ãçµç¹ãæ å ±ã·ã¹ãã ã«ãããæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ï¼ãã©ã¤ãã·ã¼ãªã¹ã¯ãå«ãï¼ã®ç®¡çæ¹æ³ã示ãããã®ã§ãã
SP800-37 Revision 2ï¼ä»¥ä¸ãRev2ï¼ã®ææ¸ã¿ã¤ãã«ã¯
ãRisk Management Framework for Information Systems and Organizations A System Life Cycle Approach for Security and Privacy ãï¼æ
å ±ã·ã¹ãã ããã³çµç¹ã®ããã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ãï¼ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®ããã®ã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ã¢ããã¼ãï¼
ã¨ãªã£ã¦ãã¾ãã
ãã®ãããå½ææ¸ã¯ãæ
å ±ã·ã¹ãã ã®ã©ã¤ããµã¤ã¯ã«ã«åããããªã¹ã¯ããã¸ã¡ã³ãã®ãã¬ã¼ã ã¯ã¼ã¯ã¨ãªã£ã¦ãã¾ãã
å½ææ¸ã§ã¯ããªã¹ã¯ããã¸ã¡ã³ãã¨ã¯ã
ãçµç¹ã®æ´»åï¼ããã·ã§ã³ãæ©è½ãã¤ã¡ã¼ã¸ãè©å¤ãå«ãï¼ãçµç¹ã®è³ç£ãå人ãä»ã®çµç¹ãããã³å½å®¶ã«å¯¾ãããªã¹ã¯ã管çããããã°ã©ã ã¨ãµãã¼ãããã»ã¹ã§ã次ã®ãã®ãå«ãã
ãªã¹ã¯é¢é£æ´»åã®ã³ã³ããã¹ãï¼*1ï¼ã®ç¢ºç«ã
ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã
ä¸åº¦æ±ºå®ããããªã¹ã¯ã¸ã®å¯¾å¿ã
é·æã«ããããªã¹ã¯ã®ç£è¦ãã
ã¨å®ç¾©ããã¦ãã¾ãã
ãã®ãããã»ãã¥ãªãã£ãªã¹ã¯ã®ã¢ã»ã¹ã¡ã³ãã ãã§ãªãããã®å¾ã®ãªã¹ã¯å¯¾çã®å°å
¥ããªã¹ã¯å¯¾çã®ã¢ãã¿ãªã³ã°ãå«ãã å
容ã¨ãªã£ã¦ãã¾ãã
*1ãã³ã³ããã¹ããã¨ã¯ããã®å ´åãèæ¯ã«ããåæããå
±éçãªèãæ¹ã®ãã¨ã
2.Rev2ã¨Rev1ã¨ã®éãï¼å¤æ´ç¹ï¼
Revision 1ï¼ä»¥ä¸ãRev 1ï¼ã®ææ¸ã¿ã¤ãã«ã¯ããã¨ãã¨ä»¥ä¸ã®ããã«ãªã£ã¦ãã¾ããã
ï¼ã»ãã¥ãªãã£ã©ã¤ããµã¤ã¯ã«ã«ããã¢ããã¼ãã
Rev 1ã¯ãç±³å½é£é¦æ¿åºã®æ å ±ã·ã¹ãã ã対象ã¨ãããã®ã§ãã·ã¹ãã éçºãéç¨ä¿å®ã®ããã»ã¹ã«ãããã»ãã¥ãªãã£ãªã¹ã¯ã®ã¢ã»ã¹ã¡ã³ãã対çã®å®è£ ã»ã¢ãã¿ãªã³ã°ãè¡ãæ¹æ³ã«ã¤ãã¦ã®ã¬ã¤ãã©ã¤ã³ã§ããã
ãããRev 2ã§ã¯ä»¥ä¸ã®ããã«å¤ãã£ã¦ãã¾ãã
ï¼ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®ããã®ã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ã¢ããã¼ãã
対象ãç±³å½é£é¦æ¿åºã®æ å ±ã·ã¹ãã ã«éå®ãããããã¹ã¦ã®çµç¹ã対象ã¨ãããã®ã«ãªãã¨å ±ã«ããã©ã¤ãã·ã¼ãªã¹ã¯ãæ示çã«åãæ±ããã®ã¨ãªãã¾ããã
Rev 2ã¸ã®æ¹è¨ã«ãã主ãªå¤æ´ã¯ä»¥ä¸ã®éãã§ãã
- â RMFã¸ã®æºåã¹ãããã®è¿½å
- RMFã®å¹æçã»å¹ççãè²»ç¨å¯¾å¹æã®é«ãå®è¡ã®ä¿é²ã®ããããªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼ã追å ããã¾ããããããä»åã®æ¹è¨ã§æã大ããªå¤æ´ã«ãªãã¾ãã
- â¡ãã©ã¤ãã·ã¼ãªã¹ã¯ã®RMFã¸ã®çµã¿è¾¼ã¿
- ãã©ã¤ãã·ã¼ä¿è·ãã¼ãºã¸ã®å¯¾å¿ã®ãããRMFã«ãã©ã¤ãã·ã¼ãªã¹ã¯ãå«ããã¨ãæ示çã«ç¤ºããã¾ããã
- â¢ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼SCRMï¼ã¨ã®çµ±å
- ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ã¸ã®å¯¾å¦ã®ãããRMFã«SCRMãå«ããã¨ã¨ãªãã¾ããã
- â£RMFã¨ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ã¨ã®é¢é£ä»ã
- CSFï¼ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ï¼ã¨æ´åãåããRMFã®åã¿ã¹ã¯ã«å¯¾å¿ããCSFã®ã»ãã¥ãªãã£å¯¾çï¼ã«ãã´ãªããµãã«ãã´ãªçï¼ãæè¨ããã¾ããã
- â¤å½ææ¸ã®ä½¿ç¨å¯¾è±¡ãç±³å½é£é¦æ¿åºã«éå®ããªã
- RMFã¯æ°éçµç¹çã«ã使ç¨ãæ¨å¥¨ãããææ¸ã¨ä½ç½®ã¥ããããããã«ãªãã¾ããã
ãªããä¸è¨ãå«ãã¦RFMã®åã¿ã¹ã¯ã«è¿½å å¤æ´ãå ¥ã£ã¦ãã¾ãã詳細ã¯ä»¥ä¸ã®ãªã³ã¯ãã確èªã§ãã¾ãã
ãRMFãRev1 ã¨Rev2ã®å¯¾æ¯.xlsx3.ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã¨ã¯
Rev2ã«ããããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼ä»¥ä¸ãRMFï¼ã¯ãå³1ã®ããã« ãªã¹ã¯ããã¸ã¡ã³ãã®æºå→æ å ±ã·ã¹ãã ã®åé¡→ã»ãã¥ãªãã£ç®¡ççã®é¸æ→ã»ãã¥ãªãã£ç®¡ççã®å®è£ →æ å ±ã·ã¹ãã ã®éç¨èªå¯→ã»ãã¥ãªãã£ç®¡ççã®ç£è¦ ã®7ã¤ã®ã¹ãããã§æ§æããã¦ãã¾ãã
å³1ããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼SP800-37 Rev2ï¼
RMFã®7ã¹ãããã§å®æ½ãããã¨ã¯ä»¥ä¸ã®éãã§ãã
ã¹ããã1 ãªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼
çµç¹ã®ãªã¹ã¯ããã¸ã¡ã³ãæ¦ç¥ãçå®ãã¦çµç¹å
¨ä½ã®ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãï¼ãªã¹ã¯è©ä¾¡ï¼ãè¡ããå
±é管ççï¼è¤æ°ã®ã·ã¹ãã ããµãã¼ãå¯è½ãªå
±éçãªã»ãã¥ãªãã£å¯¾çï¼ãç¹å®ãã¾ãã
ã¾ãã対象ã·ã¹ãã ã®ã·ã¹ãã å¢çãæããã«ãããã®ã·ã¹ãã ã®ãªã¹ã¯ã¢ã»ã¹ã¡ã³ããè¡ããã»ãã¥ãªãã£è¦ä»¶ãç¹å®ãã¾ãã
ã¹ããã2 æ å ±ã·ã¹ãã ã®åé¡ï¼CATEGORIZEï¼
対象ã·ã¹ãã ã®ç¹æ§ãæããã«ããã·ã¹ãã ãæ å ±ã®ã¿ã¤ããç¹å®ãããã¨ã«ãããå½è©²ã·ã¹ãã ã«æ±ããããã»ãã¥ãªãã£åé¡ãæ©å¯æ§ãå®å ¨æ§ãå¯ç¨æ§ã®è¦³ç¹ã§ããããé«ãä¸ãä½ã«æ±ºå®ãã¾ãã
ã¹ããã3 ã»ãã¥ãªãã£ç®¡ççã®é¸æï¼SELECTï¼
対象ã·ã¹ãã ã®åé¡çµæã«åºã¥ããã»ãã¥ãªãã£ç®¡ççï¼ã»ãã¥ãªãã£å¯¾çããã©ã¤ãã·ã¼ä¿è·çï¼ãããã¼ã¹ã©ã¤ã³ã¨ãªãã»ãã¥ãªãã£ç®¡ççã®ä¸ããé¸æããå¿ è¦ãªå ´åã¯ãã®å 容ã調æ´ãã¾ãã
ã¹ããã4 ã»ãã¥ãªãã£ç®¡ççã®å®è£ ï¼IMPLEMENTï¼
対象ã·ã¹ãã ã®ã»ãã¥ãªãã£ç®¡ççãå®è£
ãã¾ããã¾ããã»ãã¥ãªãã£ç®¡ççã®å®è£
ç¶æ³ã«åºã¥ãã¦ãã»ãã¥ãªãã£ç®¡ççã®å¤æ´å
容ãã¢ã¦ããããçãææ¸åãã¾ãã
â»ãIMPLEMENTãããå®æ½ãã¨è¨³ããèãæ¹ãããã¾ãããããã§ã¯åããããããåå¾ã®æèãèæ
®ãããå®è£
ãã¨è¨³ãã¾ããã
ã¹ããã5 ã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ãï¼ASSESSï¼
対象ã·ã¹ãã ã®ã»ãã¥ãªãã£ç®¡ççããæ£ããå®è£
ãããæå³ããã¨ããã«æ©è½ããã»ãã¥ãªãã£ï¼ããã³ãã©ã¤ãã·ã¼ï¼ã®è¦ä»¶ãæºããã¦ãããã®æå¹æ§ãã¢ã»ã¹ã¡ã³ããã¾ãã
ã¢ã»ã¹ã¡ã³ãã®çµæãä¸åãããã°æ¯æ£æ´»åãè¡ããæ¯æ£å¾ã®ã»ãã¥ãªãã£ç®¡ççãå度ã¢ã»ã¹ã¡ã³ããã¾ãã
ã¹ããã6 æ å ±ã·ã¹ãã ã®éç¨èªå¯ï¼AUTHORIZEï¼
éç¨èªå¯è²¬ä»»è
ã«ã対象ã·ã¹ãã çã®éç¨èªå¯ãç³è«ãããªã¹ã¯ãå容å¯è½ã§ããã°éç¨ãèªå¯ããã¾ããå容ã§ããªããã°éç¨ã¯èªå¯ããã¾ããã
éç¨èªå¯è²¬ä»»è
ã¨ã¯ãçµç¹ã«ããã¦å¯¾è±¡ã·ã¹ãã ã®éç¨ã«ãã£ã¦çãããªã¹ã¯ãå容å¯è½ãªã¬ãã«ã«åãã責任ãè² ã責任è
ã§ãã
ã¹ããã7 ã»ãã¥ãªãã£ç®¡ççã®ç£è¦ï¼MONITORï¼
対象ã·ã¹ãã ã®ã»ãã¥ãªãã£ç®¡ççã®æå¹æ§ãç¶ç¶çã«ã¢ã»ã¹ã¡ã³ãããå¿ è¦ãªå ´åã¯ãªã¹ã¯å¯¾å¿ã®åãçµã¿ãå®æ½ãã¾ããéç¨èªå¯ã®ç³è«ã¨èªå¯ãç¶ç¶çã«è¡ããã¾ããã¾ãã対象ã·ã¹ãã ãå»æ¢ãã段éã§ã¯ãå»æ¢ã«å¿ è¦ãªä½æ¥ãè¡ãã¾ãã
åãã¦RMFã«åºã¥ãããªã¹ã¯ç®¡çãè¡ãå ´åã¯ãä¸è¨ã®é åºã§å®æ½ãããã¨ãæ¨å¥¨ããã¾ãããä¸åº¦ãã¹ã¦ã®ã¹ããããåãçµããå¾ã¯ãå¿
ãããå度åãé åºã«ããªãã¦ã¯ãªããªã訳ã§ã¯ãªããçµç¹ã®å¤æã§å®æ½ãã¹ãã¨èããã¹ããããå®è¡ãããã¨ãã§ãã¾ãã
ãªããæåã®ã¹ãããã§ãããªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼ã¯ãä»ã®6ã¤ã®ã¹ããããå®è¡ããããã®æºåã¨ããä½ç½®ã¥ãã®ãããã©ã®ã¹ãããã§ãæºåã¨ãã¦ãã®å¿
è¦æ§ã®æç¡ã確èªããã®ãæã¾ããã¨èãããã¾ãã
3. RMFã¨ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ï¼SDLCï¼
RMFã¯ãã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ï¼SDLCï¼System Development Life Cycleï¼ã¨é£æºãã¦ãããRMFã®åã¿ã¹ã¯ã¯çµç¹å
ã®SDLCããã»ã¹ã¨ä¸¦è¡ãã¦ãã¾ãã¯SDLCããã»ã¹ã®ä¸é¨ã¨ãã¦å®è¡ããã¾ãã
ãã®SDLCã¯ãSP 800-64 Rev.2ï¼æ
å ±ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ã«ãããã»ãã¥ãªãã£ã®èæ
®äºé
ï¼ã§ç¤ºããã¦ããã©ã¤ããµã¤ã¯ã«ã§ã
éå§ã→ éçºï¼èª¿é → å®è£
ï¼è©ä¾¡ → éç¨ããã³ä¿å® → å»æ¢
ã®5ã¤ã®ãã§ã¼ãºã§ç¤ºããã¦ãã¾ãã
æ°è¦ã·ã¹ãã ã¯ãSDLCã®éå§ï½å®è£
ï¼è©ä¾¡ã«ããã¦ãRMFã®ãªã¹ã¯ããã¸ã¡ã³ãã®æºåï½æ
å ±ã·ã¹ãã ã®éç¨èªå¯ã¾ã§ãå®è¡ããã¾ãã
éç¨ããã³ä¿å®ã«å
¥ãã¨ã»ãã¥ãªãã£ç®¡ççã®ç£è¦ãå®è¡ãããã®ã§ããããã以éã¯æ¢åã·ã¹ãã ã¨ãªããã·ã¹ãã å¤æ´çã®ã¤ãã³ããçºçããã¨RMFãæåããå®è¡ãããã¨ã«ãªãã¾ãã
ãªããRMFã®æåã®ã¹ãããã§ãããªã¹ã¯ããã¸ã¡ã³ãã®æºåã¯ãã·ã¹ãã ã¬ãã«ã®æºåã®ã¿SDLCã®éå§ãã§ã¼ãºã§å®æ½ãã¾ããçµç¹ã¬ãã«ã®æºåã¯ãSDLCã®å®è¡ä»¥åã«çµç¹ã¨ãã¦å®æ½ããã¹ããã®ã¨èãããã¾ãã
å³2ãã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ã¨RMFã®åã¹ããã
ã¾ã¨ã
ä»åã¯ãSP800-37 Rev2ã«åºã¥ãRMFã®å
¨ä½åã«ã¤ãã¦èª¬æãã¾ããã
RMFã¯ããªã¹ã¯ã¢ã»ã¹ã¡ã³ããè¡ããã»ãã¥ãªãã£å¯¾çãå°å
¥ããã ãã§ãªãããã®å¾ãç¶ç¶çã«å¯¾çã®æå¹æ§ã確èªããè¦ç´ãã»æ¹åãè¡ããã¨ãéè¦ã§ãããã¨ã示ãã¦ãã¾ãã
ã¾ããRMFã®ã¿ã¹ã¯ã¯ãã·ã¹ãã éçºæãã·ã¹ãã éç¨æã ãã«éå®ãã¦å®æ½ãããã®ã§ã¯ãªããã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ã®å
¨ãã§ã¼ãºã§å®æ½ãããã®ã§ãããã¨ã示ãã¦ãã¾ãã
次å以éã¯ãRMFã®7ã¤ã®ã¹ãããã«ã¤ãã¦å ·ä½çã«è¦ã¦ããããã¨æãã¾ãã
åèæç®
- IPAãSP 800-37 Rev.1ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ã«å¯¾ãããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯é©ç¨ã¬ã¤ãï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025329.pdf - NISTãSP 800-37 Rev.2ãæ
å ±ã·ã¹ãã ããã³çµç¹ã®ããã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf - IPAãSP 800-53 Rev.4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦æ¿åºã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡ççï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000056415.pdf - IPAãSP 800-64 Rev.2ãæ
å ±ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ã«ãããã»ãã¥ãªãã£ã®èæ
®äºé
ï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025343.pdf - IPAãFramework for Improving Critical Infrastructure Cybersecurity Ver1.1ãéè¦ã¤ã³ãã©ã®ãµã¤ãã¼ã»ãã¥ãªãã£ãæ¹åããããã®ãã¬ã¼ã ã¯ã¼ã¯ï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000071204.pdf - NISTãFISMA Implementation Projectã
https://csrc.nist.gov/projects/risk-management/risk-management-framework-(RMF)-Overview
Writer Profile
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨
ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½ èª²é·
æ¸ç° åä¹ï¼CISSPãCEHãCISAï¼
Tweet