NISTã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ã¨ã¯ ï½ç¬¬2åãæºå~åé¡~é¸æï½
第1åã§ã¯ãSP800-37 Revision 2ï¼ä»¥ä¸ãRev2ï¼ã«ãããRMFã®å
¨ä½åã«ã¤ãã¦è§£èª¬ãã¾ããã
第2åã§ã¯RFMã®ï¼ã¤ã®ã¹ãããã®ãã¡ãååã®ãªã¹ã¯ããã¸ã¡ã³ãã®æºåãæ
å ±ã·ã¹ãã ã®åé¡ãã»ãã¥ãªãã£ç®¡ççã®é¸æã®3ã¹ããããè¦ã¦ããããã¨æãã¾ãã
ããã3ã¹ãããã®å¤§ã¾ããªæµãã¯ããªã¹ã¯ããã¸ã¡ã³ãã®æºåã§ãªã¹ã¯ã¢ã»ã¹ã¡ã³ããè¡ã→ã·ã¹ãã ã®åé¡ã§ã·ã¹ãã ã®ã»ãã¥ãªãã£ä¸ã®åªå é ä½ä»ããè¡ã→ã»ãã¥ãªãã£ç®¡ççã®é¸æã§å®éã®ã»ãã¥ãªãã£å¯¾çã®æ¤è¨ã»æ±ºå®ãè¡ããã¨ãããã®ã§ãã
ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã¨ä»åã®ç¯å²
ã¹ããã1ããªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼
RMFã®æåã®ã¹ãããã¨ãªããªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼ã¯ãRev2ããæ°ãã«è¿½å ãããã¹ãããã§ãã
ãªã¹ã¯ããã¸ã¡ã³ãã®æºåã¯ãã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®ãªã¹ã¯ã管çããããã®ã³ã³ããã¹ãã¨åªå
é ä½ã確ç«ãã¦ãçµç¹ã¬ãã«ããã³ã·ã¹ãã ã¬ãã«ã®è¦³ç¹ããRMFãå®è¡ããæºåããããã®ã§ãã
â»ãã³ã³ããã¹ããã¨ã¯ããã®å ´åãèæ¯ã«ããåæããå
±éçãªèãæ¹ã®ãã¨ã
ãçµç¹å
¨ä½ã®ãªã¹ã¯ããã¸ã¡ã³ãã¢ããã¼ã
ã¹ããã1ã®åæã¨ãã¦ãçµç¹å
¨ä½ã®ãªã¹ã¯ããã¸ã¡ã³ãã¢ããã¼ãã«ã¤ãã¦ç解ãã¦ããå¿
è¦ãããã¾ããããã¯ãçµç¹ãããã·ã§ã³ï¼ãã¸ãã¹ããã»ã¹ãæ
å ±ã·ã¹ãã ã®3ã¤ã®ã¬ã¤ã¤ã¼ã®ãªã¹ã¯ã«çµ±åçã«å¯¾å¦ãã¦ãçµç¹å
¨ä½ã®ãªã¹ã¯ããã¸ã¡ã³ããå®æ½ãããã¨ããèãæ¹ã§ãã
ã¬ãã«1ããã³2ï¼çµç¹ããã³ããã·ã§ã³ï¼ãã¸ãã¹ããã»ã¹ï¼ã§ã¯ãçµç¹ã¬ãã«ã®æºåãè¡ãå¿
è¦ããããããã¯ç¹å®ã·ã¹ãã ã®ãªã¹ã¯ã«éå®ãã¾ããã
ã¬ãã«3ï¼æ
å ±ã·ã¹ãã ï¼ã®ãªã¹ã¯ããã¸ã¡ã³ãã¯ãã·ã¹ãã ã¬ãã«ã®æºåãè¡ãå¿
è¦ããããç¹å®ã®ã·ã¹ãã ã®ãªã¹ã¯ãåãæ±ãã¾ãã
ãã®ããããªã¹ã¯ããã¸ã¡ã³ãã®æºåã«ã¯ãçµç¹ã¬ãã«ã¨ã·ã¹ãã ã¬ãã«ã®2ã¤ã¬ã¤ã¤ã¼ãåå¨ãããã¨ã«ãªãã¾ãã
å³1ãçµç¹å ¨ä½ã®ãªã¹ã¯ããã¸ã¡ã³ãã¢ããã¼ã
(1)çµç¹ã¬ãã«ã®æºåï¼PREPAREï¼ORGANIZATION LEVELï¼
çµç¹ã¬ãã«ã®æºåã§ã¯ãçµç¹å
¨ä½ã®ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®ãªã¹ã¯ãã¢ã»ã¹ã¡ã³ãããå
±é管ççãç¹å®ãã¾ããå
±é管ççã¨ã¯ãè¤æ°ã®ã·ã¹ãã ããµãã¼ãå¯è½ãªå
±éçãªã»ãã¥ãªãã£ç®¡ççã§ãåã·ã¹ãã ã®è¦ä»¶ã«ãã£ã¦èª¿æ´ãè¡ããããã¨ãããã¾ãã
ã»ãã¥ãªãã£ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½æ¹æ³ã¯ãSP800-30 rev1ï¼ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½ã®æå¼ãï¼ãåèã«ãããã¨ãã§ãã¾ãã
åèã¾ã§ã«SP800-30 rev1ã§ã¯ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½ããã»ã¹ã¨ãã¦ä»¥ä¸ã®æé ã示ããã¦ãã¾ãã
è
å¨æºãç¹å®ããã→ãè
å¨äºè±¡ãç¹å®ããã→ãèå¼±æ§ã¨ç´ å çæ¡ä»¶ãç¹å®ãã
→ãï¼è
å¨äºè±¡ãçºçããï¼å¯è½æ§ãç¹å®ããã→ãå½±é¿ã®å¤§ãããç¹å®ãã
→ããªã¹ã¯ãå¤æãã
å³2ãã¹ããã1(1)çµç¹ã¬ãã«ã®æºå
ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ï¼ä»¥ä¸ãCSFï¼ã®è¦³ç¹ã§ã¯ãããã§ã¯ä¸»ã«ID.RAï¼ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãï¼ãID.RMï¼ãªã¹ã¯ããã¸ã¡ã³ãï¼ãID.SCï¼ãµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ããã¸ã¡ã³ãï¼ãªã©ãå®æ½ãããã¨ã«ãªãã¾ãã
*1ãªã¹ã¯ããã¸ã¡ã³ãæ¦ç¥ï¼çµç¹èªèº«ãèããèªçµç¹ã®ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãããªã¹ã¯ããã¸ã¡ã³ããã©ã®ããã«é²ãããã®èãæ¹ã§ããSP 800-53 Rev.4ã§ã¯ã以ä¸ã®ããã«å®ç¾©ãã¦ãã¾ãã
- çµç¹ã®ãªã¹ã¯è¨±å®¹åº¦ãæ確ã«è¡¨ç¾ãããã¨ã
- åãå ¥ãããããªã¹ã¯ã¢ã»ã¹ã¡ã³ãæ¹æ³ã
- ãªã¹ã¯ç·©åæ¦ç¥ã
- çµç¹ã®ãªã¹ã¯è¨±å®¹åº¦ã¨ç §ããåããã¦ãçµç¹å ¨ä½ã«ããã£ã¦ãªã¹ã¯ãä¸è²«ãã¦è©ä¾¡ããããã®ããã»ã¹ã
- é·æã«ããã£ã¦ãªã¹ã¯ãã¢ãã¿ãªã³ã°ããããã®ã¢ããã¼ããå«ãã
ãªã¹ã¯ããã¸ã¡ã³ãæ¦ç¥ã¯ãISMSãéç¨ãã¦ããçµç¹ã§ã¯ããªã¹ã¯è©ä¾¡åºæºããªã¹ã¯è©ä¾¡æé ãªã©ã¨è¨ãæããã¨åãããããã§ãã
*2ãããã¡ã¤ã«ï¼ãã®å ´åãã»ãã¥ãªãã£å¯¾çã®ç¾å¨ã®ç¶æ³ï¼As-Isï¼ã¨ãç®æ¨ã¨ããç¶æ³ï¼To-Beï¼ã§ãã
(2)ã·ã¹ãã ã¬ãã«ã®æºåï¼PREPAREï¼SYSTEM LEVELï¼
ã·ã¹ãã ã¬ãã«ã®æºåã§ã¯ã対象ã·ã¹ãã ã®å¢çãæããã«ããã»ãã¥ãªãã£ï¼ããã³ãã©ã¤ãã·ã¼ï¼ã®ãªã¹ã¯ãã¢ã»ã¹ã¡ã³ãããã·ã¹ãã ï¼ã¨ãã®éç¨ç°å¢ï¼ã«ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®è¦ä»¶ãå²ãå½ã¦ã¾ããï¼SDLCã®åæããã»ã¹ã¨ãã¦å®æ½ããã¾ãï¼
â»ã»ãã¥ãªãã£ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½æ¹æ³ã¯ãçµç¹ã¬ãã«ã®æºåã¨åæ§ã«SP800-30 rev1ï¼ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½ã®æå¼ãï¼ãåèã«ãããã¨ãã§ãã¾ãã
å³3ãã¹ããã1(2)ã·ã¹ãã ã¬ãã«ã®æºå
CSFã®è¦³ç¹ã§ã¯ãããã§ã¯ä¸»ã«ID.AMï¼è³ç£ç®¡çï¼ãID.BEï¼ãã¸ãã¹ç°å¢ï¼ãID.RAï¼ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãï¼ãID.GVï¼ã¬ããã³ã¹ï¼ãªã©ãå®æ½ãããã¨ã«ãªãã¾ãã
*3ã¨ã³ã¿ã¼ãã©ã¤ãºã¢ã¼ããã¯ãã£:çµç¹ã®äºæ¥æ§é ãæ¥åããã¼ã¿ãæè¡çã«æ§é åãããã®ãRMFã®ããã»ã¹ã¨ãã¦ã¯å¯¾è±¡ã·ã¹ãã ãäºæ¥æ§é ã®ã©ãã«ä½ç½®ãããã®é ç½®ã決ãããã¨ãNISTã®å®ç¾©ã§ã¯ãããã·ã§ã³ãå®ç¾©ããæ¦ç¥çæ å ±è³ç£åºç¤ãããã·ã§ã³éè¡ã«å¿ è¦ãªæ å ±ãæè¡çã¨ãªã£ã¦ããã
è£è¶³ï¼ä¸è¬çã«ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãï¼ãªã¹ã¯è©ä¾¡ï¼ãã¨è¨ãããããã»ã¹ã¯ããã®ãªã¹ã¯ããã¸ã¡ã³ãã®æºåï¼PREPAREï¼ã¹ãããã§å®æ½ããã¢ã»ã¹ã¡ã³ããæãè¿ãã¨èãããã¾ãããã®å¾ã®éçºï¼èª¿éãã§ã¼ãºã§å®éãããã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ãï¼ASSESSï¼ã¯ãã»ãã¥ãªãã£ç®¡ççã主ãªã¢ã»ã¹ã¡ã³ã対象ã¨ãã¦ãã¾ããï¼ãã ããããããæçµçã«ã¯ã»ãã¥ãªãã£ãªã¹ã¯ãç¹å®ããã¨ããç¹ã§ã¯åãã§ãï¼
ã¹ããã2ãæ å ±ã·ã¹ãã ã®åé¡(CATEGORIZE)
æ
å ±ã·ã¹ãã ã®åé¡ã§ã¯ãã·ã¹ãã ã®ã¿ã¤ããåé¡ããã»ãã¥ãªãã£ã®åé¡ãå®æ½ãã¾ããåé¡ã«ããã£ã¦ã¯ãFIPS199ãSP 800-60ãªã©ã®ææ¸ã§æ
å ±ããã³æ
å ±ã·ã¹ãã ã®ã¿ã¤ãã¨ã»ãã¥ãªãã£åé¡ã®ãããã³ã°ãåèã«ãããã¨ãã§ãã¾ãã
ãªããã»ãã¥ãªãã£åé¡ã¨ã¯ãæ
å ±ã®æ©å¯æ§ãå®å
¨æ§ãã¾ãã¯å¯ç¨æ§ã®åªå¤±ããçããçµç¹éå¶ãçµç¹è³ç£ãå人ãä»ã®çµç¹ãããã³å½ã¸ã®æ½å¨çãªæªå½±é¿ãèæ
®ããã·ã¹ãã ã®æ©å¯æ§ãå®å
¨æ§ãå¯ç¨æ§ãé«ãä¸ãä½ã«åé¡ãããã¨ã§ãã
ä¾ãã°ãSP 800-60 Ver2.0ã§ã¯ã以ä¸ã®ä¾ã示ããã¦ãã¾ãã
å³4ãã¹ããã2æ å ±ã·ã¹ãã ã®åé¡
CSFã®è¦³ç¹ã§ã¯ãããã§ã¯ä¸»ã«ID.AMï¼è³ç£ç®¡çï¼ãå®æ½ãã¾ãã
ã¹ããã3ãã»ãã¥ãªãã£ç®¡ççã®é¸æï¼SELECTï¼
ã»ãã¥ãªãã£ç®¡ççã®é¸æã§ã¯ãã»ãã¥ãªãã£ç®¡ççï¼ã»ãã¥ãªãã£å¯¾çã¨ãã©ã¤ãã·ã¼ä¿è·çï¼ãé¸æãã¾ããã»ãã¥ãªãã£ç®¡ççã®é¸æã®åæ段éã§ã¯ã
- ãã¼ã¹ã©ã¤ã³ç®¡ççã®é¸æã¢ããã¼ã
- çµç¹çå®ç®¡ççã®é¸æã¢ããã¼ã
ãã¼ã¹ã©ã¤ã³ç®¡ççã®é¸æã¢ããã¼ãã¨ã¯ãããããã¦ã³çã«ãããããå®ããã»ãã¥ãªãã£ç®¡ççã®ä¸ããé¸æããæ¹æ³ã§ãä¾ãã°SP800-53 rev.4ï¼é£é¦æ¿åºæ å ±ã·ã¹ãã ããã³é£é¦æ¿åºã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡ççï¼ã«è¨è¼ããã¦ããã»ãã¥ãªãã£ç®¡ççããã¼ã¹ã©ã¤ã³ã«ããæ¹æ³çãèãããã¾ãã
çµç¹çå®ç®¡ççã®é¸æã¢ããã¼ãã¨ã¯ãããã ã¢ããçã«çµç¹åºæã®è¦ä»¶ããã»ãã¥ãªãã£ç®¡ççãçå®ã使ç¨ã»é¸æããæ¹æ³ã§ãã
ããããé¸æãããå¾ãå
±é管ççãã·ã¹ãã åºæã®ç®¡ççããã¤ããªãã管ççã®ããããã«ãªãã¾ãã
å³5ãã»ãã¥ãªãã£ç®¡ççãé¸æããã¢ããã¼ã
å³6ãã¹ããã3ã»ãã¥ãªãã£ç®¡ççã®é¸æ
ã»ãã¥ãªãã£ç®¡ççã®é¸æã¯ã対çãã®ãã®ãé¸æããã¿ã¹ã¯ã®ãããCSFã®è¦³ç¹ã§ã¯ãé¢é£ãã対çã¯ã»ã¨ãã©è©²å½ãããã®ãããã¾ãããããã§ã¯ä¸»ã«ãããã¡ã¤ã«ï¼å¯¾è±¡ã·ã¹ãã ã®ã»ãã¥ãªãã£å¯¾çã®ç¾å¨ã®ç¶æ³ï¼As-Isï¼ã¨ç®æ¨ã¨ããç¶æ³ï¼To-Beï¼ï¼ã®æ¤è¨ãå®æ½ãããã¨ã«ãªãã¾ãã
ã¾ã¨ã
ä»åã¯ãRMFã®ååã®3ã¹ãããã説æãã¾ãããæåã«å®æ½ããã¹ãããã§ãããªã¹ã¯ããã¸ã¡ã³ãã®æºåã¯ãå®æ½ããã¿ã¹ã¯ãããªãå¤ãã®ã§ãããä¾ãã°ãçµç¹ã®å
±éçãªã»ãã¥ãªãã£å¯¾çãæåã«æ±ºãã¦ãããã¨ã対象ã·ã¹ãã ã®å¢çãæåã«æ確ã«ãããã¨ãã»ãã¥ãªãã£å¯¾çã®æå¹æ§ã®ç£è¦æ¹æ³ã決ãã¦ãããã¨ãªã©ããããã¯æçµçã«ã¯å
¨ä½ã®ãªã¹ã¯ç®¡çã³ã¹ãã®æå¶ã«ã¤ãªããã¾ãã
ã¾ããã»ãã¥ãªãã£ç®¡ççã®é¸æã«ããã¦ãããããã¦ã³ã¨ããã ã¢ããã®2ã¤ã®ã¢ããã¼ãã示ããã¦ãããã¨ãããåèã«ã§ãããã¼ã¹ã©ã¤ã³ãæ´»ç¨ããã ãã§ãªãçµç¹åºæã®è¦ä»¶ã«åºã¥ãç¬èªã®å¯¾çãæã¡åºããã¨ã«ãã£ã¦ããç¾å®ã«å³ãããªã¹ã¯ããã¸ã¡ã³ããé²ãããã¨ãæå³ãã¦ãã¾ãã
第3åã§ã¯ãRMFã®æ®ãã®4ã¹ãããã«ã¤ãã¦è¦ã¦ããã¾ãã
åèæç®
- NISTãSP 800-30 Rev.1ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½ã®æå¼ãï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025325.pdf - NISTãSP 800-37 Rev.1ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ã«å¯¾ãããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯é©ç¨ã¬ã¤ãï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025329.pdf - NISTãSP 800-37 Rev.2ãæ
å ±ã·ã¹ãã ããã³çµç¹ã®ããã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf - NISTãSP 800-53 Rev.4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡ççï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000056415.pdf - NISTãSP 800-53A Rev4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ç®¡çã®ã¢ã»ã¹ã¡ã³ãã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf - IPAãSP 800-60 Vol.2ãæ
å ±ããã³æ
å ±ã·ã¹ãã ã®ã¿ã¤ãã¨ã»ãã¥ãªãã£åé¡ã®ãããã³ã°ã¬ã¤ãï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025340.pdf - NISTãSP 800-64 Rev.2ãæ
å ±ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ã«ãããã»ãã¥ãªãã£ã®èæ
®äºé
ï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025343.pdf - NISTãFramework for Improving Critical Infrastructure Cybersecurity Ver1.1ãéè¦ã¤ã³ãã©ã®ãµã¤ãã¼ã»ãã¥ãªãã£ãæ¹åããããã®ãã¬ã¼ã ã¯ã¼ã¯ï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000071204.pdf - NISTãFIPS 199ãé£é¦æ¿åºã®æ å ±ããã³æ å ±ã·ã¹ãã ã«å¯¾ããã»ãã¥ãªãã£åé¡è¦æ ¼ï¼é¦è¨³çï¼ãhttps://www.ipa.go.jp/files/000025321.pdf
- NISTãFISMA Implementation Projectãhttps://csrc.nist.gov/projects/risk-management/risk-management-framework-(RMF)-Overview
Writer Profile
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨
ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½ã課é·
æ¸ç° åä¹ï¼CISSPãCEHãCISAï¼
Tweet