NISTã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ã¨ã¯ ï½ç¬¬3åãå®æ½ï½ã¢ã»ã¹ã¡ã³ãï½éç¨èªå¯ï½ç£è¦ï½
第2åã§ã¯ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼ä»¥ä¸ãRMFï¼ã®ãã¡ããªã¹ã¯ããã¸ã¡ã³ãã®æºå~ã»ãã¥ãªãã£ç®¡ççã®é¸æã¾ã§ã®åå3ã¤ã®ããã»ã¹ã解説ãã¾ããã
第3åã§ã¯å¾åã®ã»ãã¥ãªãã£ç®¡ççã®å®è£ ãã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ããæ å ±ã·ã¹ãã ã®éç¨èªå¯ãã»ãã¥ãªãã£ç®¡ççã®ç£è¦ã®ï¼ã¤ã®ããã»ã¹ãè¦ã¦ããã¾ãã
ãããã®å¤§ã¾ããªæµãã¯ãã»ãã¥ãªãã£ç®¡ççã®å®è£ ã§ã»ãã¥ãªãã£å¯¾çãã·ã¹ãã çã«å®è£ ããã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ãã§ã»ãã¥ãªãã£å¯¾çã®æå¹æ§ãè©ä¾¡ããæ å ±ã·ã¹ãã ã®éç¨èªå¯ã§å¯¾è±¡ã·ã¹ãã ã®éç¨èªå¯ãå¤æããã»ãã¥ãªãã£ç®¡ççã®ç£è¦ã§ç¶ç¶çã«ã»ãã¥ãªãã£å¯¾çãè©ä¾¡ãéç¨èªå¯ãå¤æãããã¨ãããã®ã§ãã
ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã¨ä»åã®ç¯å²
ã¹ããã4ãã»ãã¥ãªãã£ç®¡ççã®å®è£ ï¼IMPREMENTï¼
ã»ãã¥ãªãã£ç®¡ççã®å®è£
ã§ã¯ãé¸æããã»ãã¥ãªãã£ç®¡ççï¼ã»ãã¥ãªãã£å¯¾çããã³ãã©ã¤ãã·ã¼ä¿è·çï¼ã®å®è£
ãè¡ãã¾ãã
â»ãIMPLEMENTãããå®æ½ãã¨è¨³ããèãæ¹ãããã¾ãããããã§ã¯ãããããããåå¾ã®æèãèæ
®ãããå®è£
ãã¨è¨³ãã¾ããã
å³1ãã¹ããã4ã»ãã¥ãªãã£ç®¡ççã®å®è£
ãã®ã¹ãããã¯å¯¾çãã®ãã®ã®å®è£
ã»éç¨ã®ãããCSFã®è¦³ç¹ã§ã¯ãé¢é£ãã対çã¯ã»ã¨ãã©è©²å½ãããã®ãããã¾ãããCSFã«ããããPR.IPï¼æ
å ±ãä¿è·ããããã®ããã»ã¹ããã³æé ï¼ã®ä¸é¨ãå®æ½ãã¾ãã
â»å®è³ªçã«ã¯ãCSFã«ãããé²å¾¡ãæ¤ç¥ãªã©ã®ã«ãã´ãªã«é¢é£ä»ããããå対çãå®è£
ãããã¨ã«ãªãã¾ãã
ã¹ããã5ãã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ãï¼ASSESSï¼
ã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ãã§ã¯ãã»ãã¥ãªãã£ç®¡ççãæ£ããå®è£
ãããæå³ããã¨ããã«æ©è½ããè¦ä»¶ãæºããã¦ãããã®æå¹æ§ãã¢ã»ã¹ã¡ã³ããã¾ãã
ã¢ã»ã¹ã¡ã³ãæ¹æ³ã®ä¾ã¨ãã¦ãSP800-53A Revision4ï¼é£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ç®¡çã®ã¢ã»ã¹ã¡ã³ãï¼ã§ã¯ã以ä¸ã®3ã¤ã示ãã¦ãã¾ãã
â 調æ»ï¼ææ¸ï¼ããªã·ã¼ãæé ãè¨è¨ãªã©ï¼ãã¡ã«ããºã ï¼HWãSWã«å®è£
ãããæ©è½ãªã©ï¼ãæ´»åï¼ã·ã¹ãã éç¨ãæ¼ç¿ãªã©ï¼ã«å¯¾ãããã§ãã¯ãã¬ãã¥ã¼ãæ¤æ»ãè¡ãã証跡ãåå¾ããã
â¡ã¤ã³ã¿ãã¥ã¼ï¼å人ã¾ãã¯ã°ã«ã¼ãã«ã¤ã³ã¿ãã¥ã¼ãè¡ãã
â¢ãã¹ãï¼ã¡ã«ããºã ï¼HWãSWã«å®è£
ãããæ©è½ãªã©ï¼ãæ´»åï¼ã·ã¹ãã éç¨ãæ¼ç¿ãªã©ï¼ãå®è¡ããæå¾
éãã®åä½ãã©ãããæ¯è¼ããã
â»ããã§ã®ã¢ã»ã¹ã¡ã³ãã¯ãã»ãã¥ãªãã£ç£æ»ãã»ãã¥ãªãã£è¨ºæã®ãããªã¤ã¡ã¼ã¸ã«ãªãã¾ãããã®ããããããã¬ã¼ã·ã§ã³ãã¹ããã¢ã»ã¹ã¡ã³ãæ¹æ³ã®ä¸ã¤ã«ãªãã¾ãã
å³2 ã¹ããã5ã»ãã¥ãªãã£ç®¡ççã®ã¢ã»ã¹ã¡ã³ã
ãã®ã¹ãããã¯å¯¾çèªä½ã®ã¢ã»ã¹ã¡ã³ããè¡ããããCSFã®è¦³ç¹ã§ã¯é¢é£ãã対çã¯ã»ã¨ãã©è©²å½ãããã®ãããã¾ãããé¢é£ãããã®ã¨ãã¦ã¯ID.RA-6ï¼ãªã¹ã¯å¯¾å¿ã®èå¥ã¨åªå é ä½ä»ãï¼ãããã¾ãã
ã¹ããã6ãæ å ±ã·ã¹ãã ã®éç¨èªå¯ï¼AUTHORIZEï¼
æ
å ±ã·ã¹ãã ã®éç¨èªå¯ã§ã¯ãã·ã¹ãã ãªã¼ãã¼ãã対象ã·ã¹ãã ã®éç¨ãããã¯å
±é管ççã®å©ç¨ã«ã¤ãã¦ãéç¨èªå¯è²¬ä»»è
ã«ç³è«ããéç¨èªå¯ã®æ±ºå®ãè¡ããã¾ãã
éç¨èªå¯ã¨ã¯ãéç¨èªå¯è²¬ä»»è
ããéç¨ã«ãã£ã¦çãããªã¹ã¯ãæ示çã«å容ãããã®éç¨ãèªå¯ãããã¨ã§ããéç¨èªå¯è²¬ä»»è
ã¨ã¯ã対象ã·ã¹ãã ã®éç¨ã«ãã£ã¦çãããªã¹ã¯ãå容å¯è½ãªã¬ãã«ã«åãã責任ãè² ã責任è
ã§ãå容ã§ããªããªã¹ã¯ãåå¨ããå ´åã«ã¯ã対象ã·ã¹ãã ã®éç¨ãèªå¯ãã¾ããã対象ã·ã¹ãã ãæ¢ã«éç¨ããã¦ããå ´åã¯ããã®éç¨ãåæ¢ãããã¨ãããã¾ãã
å³3ãã·ã¹ãã ãªã¼ãã¼ã¨éç¨èªå¯è²¬ä»»è ã¨ã®ããã¨ã
å³4ãã¹ããã6æ å ±ã·ã¹ãã ã®éç¨èªå¯
ãã®ã¹ãããã§ã¯ãCSFã®è¦³ç¹ã§ã¯ãé¢é£ãã対çã¯ã»ã¨ãã©è©²å½ãããã®ãããã¾ãããé¢é£ãããã®ã¨ãã¦ã¯ID.RA-6ï¼ãªã¹ã¯å¯¾å¿ã®èå¥ã¨åªå é ä½ä»ãï¼ãããã¾ãã
*1ã»ãã¥ãªãã£éç¨èªå¯ããã±ã¼ã¸ï¼ã»ãã¥ãªãã£ï¼ããã³ãã©ã¤ãã·ã¼ï¼è¨ç»ãã»ãã¥ãªãã£ï¼ããã³ãã©ã¤ãã·ã¼ã®ï¼ã¢ã»ã¹ã¡ã³ãå ±åãè¡åè¨ç»ã¨ãã¤ã«ã¹ãã¼ã³ãªã©ãéç¨èªå¯ãåããããã«æåºããææ¸é¡ã
ã¹ããã7ãã»ãã¥ãªãã£ç®¡ççã®ç£è¦ï¼MONITORï¼
ã»ãã¥ãªãã£ç®¡ççã®ç£è¦ã§ã¯ãã·ã¹ãã ããã³é¢é£ããã»ãã¥ãªãã£ç®¡ççãç¶ç¶çã«ç£è¦ãã¾ãããã®ç£è¦ã®ä¸ã«ã¯ãã»ãã¥ãªãã£ç®¡ççã®æå¹æ§ã®ã¢ã»ã¹ã¡ã³ãããã·ã¹ãã ã®å¤æ´ã®ææ¸åãå¤æ´ã«ããã»ãã¥ãªãã£å½±é¿ã®åæãã·ã¹ãã ã®ã»ãã¥ãªãã£ç¶æ ã®å ±åãå«ã¿ã¾ãã
å³5ãã¹ããã7ã»ãã¥ãªãã£ç®¡ççã®ç£è¦
CSFã®è¦³ç¹ã§ã¯ãããã§ã¯ä¸»ã«DE.CMï¼ã»ãã¥ãªãã£ã®ç¶ç¶çãªã¢ãã¿ãªã³ã°ï¼ãID.GVï¼ã¬ããã³ã¹ï¼ãRS.ANï¼åæï¼ãRS.IMï¼æ¹åï¼ãªã©ãå®æ½ãã¾ãã
5ï¼RMFã¨CSFï¼ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ï¼
ããã¾ã§ã§RMFã®7ã¹ããããã¹ã¦ãè¦ã¦ããã¾ããããæå¾ã«ãããã¨CSFï¼ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ãVer1.1ï¼ã®é¢ä¿ãæ´çãããã¨æãã¾ãã
RMFã®ä¸é¨ã®ã¿ã¹ã¯ã¯ããã¹ã¦ã§ã¯ããã¾ãããCSFã®å¯¾çï¼ã«ãã´ãªã»ãµãã«ãã´ãªï¼ã¨é£æºãã¦ããããã®ä¸é¨ã¨ãã¦å®è¡ãããã¨ãã§ãã¾ããRMFã¯ããªã¹ã¯ç®¡çã®ãã¬ã¼ã ã¯ã¼ã¯ã®ãããCSFã®ä¸ã§ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãï¼ID.RAï¼ããªã¹ã¯ããã¸ã¡ã³ãï¼ID.RMï¼ãåãæ±ããç¹å®ï¼IDï¼ãã«é¢é£ããã¿ã¹ã¯ãå¤ãã§ãã
ä¸æ¹ã§ãå³2ã§ç¤ºãã¦ããããã«ãé²å¾¡ï¼PRï¼ãããæ¤ç¥ï¼DEï¼ããã対å¿ï¼RSï¼ãã«ä½ç½®ã¥ããããã¿ã¹ã¯ãããã¾ããç¹ã«ãã»ãã¥ãªãã£ã®ç¶ç¶çãªã¢ãã¿ãªã³ã°ï¼DE.CMï¼ã¯ãã»ãã¥ãªãã£ç®¡ççã®æå¹æ§ãæ¤è¨¼ãæ¹åã«çµã³ä»ããéè¦ãªå¯¾çã§ãã
ãã®ãããRMFã¨CSFã¯å¥åã«å®è¡ããã®ã§ãªããå
±éããé¨åã«ã¤ãã¦ã¯ç¸äºã«é©ç¨å¯è½ãªã¿ã¹ã¯ã¨ãã¦å®æ½ããã®ãæã¾ããã§ãã
å³6ãRMFã®ã¿ã¹ã¯ã«é¢ä¿ãããµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ã ã¯ã¼ã¯ã®ã«ãã´ãª
ã¾ã¨ã
ä»åã¯ãRMFã®å¾åï¼ã¹ãããã説æãã¾ãããæ§ã ãªé¢ä¿è ãã»ãã¥ãªãã£å¯¾çã®æå¹æ§ã¨ãã観ç¹ãããªã¹ã¯ã®æç¡ãæ¤è¨¼ãããã®çµæã«åºã¥ãã¦æ¹åãé²ãããµã¤ã¯ã«ãç¹°ãè¿ãã®ãå¾åã®ä¸»ãªå 容ã§ãã
ä»åã®Rv2ã¸ã®æ¹è¨ã«ãããRMFã¯SDLCï¼ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ï¼ã ãã§ãªãCSFã¨ãé£æºããããã«ãªãã¾ããããã®ãããCSFããã¼ã¹ã«ã»ãã¥ãªãã£å¯¾çãæ¤è¨ãã¦ããä¼æ¥ã§ã¯RMFã®ã¿ã¹ã¯ãã¤ã¡ã¼ã¸ãããããªã£ãã¨æãã¾ãã
ã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ï¼ä¼ç»ã»è¨è¨æ®µéããã»ãã¥ãªãã£å¯¾çã確ä¿ãã¦ãããã¨ï¼ã®ç¢ºå®ãªå®ç¾ãå³ãããã«ã¯ãRMFã®ããã«ã·ã¹ãã éçºã®å段éã§ãªã¹ã¯ã®æç¡ã確èªã対å¦ãè¡ããã¨å¿
è¦ãããã¾ãããã®ããã«ã¯ãã»ãã¥ãªãã£è¨è¨ãã»ãã¥ãªãã£ç£æ»ãã»ãã¥ãªãã£è¨ºæã¨ãã£ãã¢ã¯ã·ã§ã³ãã·ã¹ãã éçºã»éç¨ã®é©åãªã¿ã¤ãã³ã°çµã¿å
¥ãããã¨ãæã¾ãã¾ãã
åèæç®
- IPAãSP 800-37 Rev.1ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ã«å¯¾ãããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯é©ç¨ã¬ã¤ãï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000025329.pdf - NISTãSP 800-37 Rev.2ãæ
å ±ã·ã¹ãã ããã³çµç¹ã®ããã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf - IPAãSP 800-53 Rev.4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ããã®ã»ãã¥ãªãã£ç®¡ççã¨ãã©ã¤ãã·ã¼ç®¡ççï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000056415.pdf - NISTãSP 800-53A Rev4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ç®¡çã®ã¢ã»ã¹ã¡ã³ãã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf - NISTãSP 800-160ãVol1ãã·ã¹ãã ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãªã³ã°ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf - SP 800-53A Rev4ãé£é¦æ¿åºæ
å ±ã·ã¹ãã ããã³é£é¦çµç¹ã®ã»ãã¥ãªãã£ããã³ãã©ã¤ãã·ã¼ç®¡ççã®ã¢ã»ã¹ã¡ã³ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf - NISTãSP 800-160ãVol1ãã·ã¹ãã ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãªã³ã°ã
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf - IPAãFramework for Improving Critical Infrastructure Cybersecurity Ver1.1ãéè¦ã¤ã³ãã©ã®ãµã¤ãã¼ã»ãã¥ãªãã£ãæ¹åããããã®ãã¬ã¼ã ã¯ã¼ã¯ï¼é¦è¨³çï¼ã
https://www.ipa.go.jp/files/000071204.pdf
Writer Profile
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨
ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½ã課é·
æ¸ç° åä¹ï¼CISSPãCEHãCISAï¼
Tweet