ãµãã©ã¤ãã§ã¼ã³ã®æ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ã 第5å ï½ ISOã§ã®æ¨æºåã®ç¶æ³ãä¸å¿ã«è§£èª¬
6. ã¯ã©ã¦ããµã¼ãã¹ã®æ å ±ã»ãã¥ãªãã£ç®¡ç
6.5 ãµãã©ã¤ãã§ã¼ã³ã¨ãã¦è¦ãå ´åã®ã¯ã©ã¦ããµã¼ãã¹ã®ç¹å¾´
以ä¸ã§ã¯ãISO/IEC 27036 Part4[1]ã«å¾ã£ã¦ãã¯ã©ã¦ããµã¼ãã¹ããµãã©ã¤ãã§ã¼ã³ã¨ãã¦è¦ãå ´åã®ç¹å¾´ã«é¢ãã¦ã¾ã¨ãã¾ããã¯ã©ã¦ããµã¼ãã¹ããµãã©ã¤ãã§ã¼ã³ã¨ãã¦è¦ãå ´åããã¾ãã¾ãªã±ã¼ã¹ãåå¨ãã¾ãã以ä¸ã«ããã¤ãã®ä¾ã示ãã¾ãã
- â ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãèªèº«ã®ãµãã©ã¤ãã§ã¼ã³ï¼ã¯ã©ã¦ããµã¼ãã¹ãæä¾ããããã®ãã¼ãã¦ã¨ã¢ãã½ããã¦ã¨ã¢ãè¨è¨ã»æ§ç¯ã»éç¨ã»å»æ£ã®ããã®æ¥åå§è¨ããã¸ãã¹ããã»ã¹ã¢ã¦ãã½ã¼ã·ã³ã°
- â¡ ã¯ã©ã¦ããµã¼ãã¹ãããã¤ããä»ã®ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®ã¯ã©ã¦ãè½åãå©ç¨ãã¦ãµã¼ãã¹ãæä¾ããã±ã¼ã¹1ã
- ⢠ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ããè¤æ°ã®ãã©ã¤ãã¼ãããããªãã¯ã¯ã©ã¦ããµã¼ãã¹ãããã¤ããå©ç¨ããã±ã¼ã¹ããã¤ããªããã¯ã©ã¦ããå ¸åä¾ã§ãããè¤æ°ã®ãããªãã¯ã¯ã©ã¦ããã³ãã¥ããã£ã¯ã©ã¦ãã使ãåããã±ã¼ã¹ããããã¨æããã¾ãã
ISO/IEC 27036ã®åºæ¬çãªçºæ³ã¯ãã¢ã¯ã¢ã¤ã¢ããµãã©ã¤ã¢åæ¹ãISMSã確ç«ããã¨åæã«ã両è
ã®éã§çµã°ããæ
å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã«é¢ããåæãã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ããã»ã¹ã«å¯¾å¿ãã¦å®è·µããã¨å½æã«ããã®é¢ä¿ãä¸æµã®ãµãã©ã¤ã¢é¢ä¿ã«ç¶æ¿ããããã¨ã§ããµãã©ã¤ãã§ã¼ã³å
¨ä½ã«æ¸¡ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ãä½æ¸ããã¦ãããã¨ã«ããã¾ãã
ã¨ããã§ãã¯ã©ã¦ããµã¼ãã¹ã®ç¹å¾´ã¨ãã¦ãµã¼ãã¹ã®åå¾ãå©ç¨ãå»æ£ã«é¢ããåæå½¢æã¯ã¯ã©ã¦ããµã¼ãã¹ã®æä¾å½¢æ
ã«ãã£ã¦ç°ãªã£ã¦ãã¾ããç¹ã«ããããªãã¯ã¯ã©ã¦ããµã¼ãã¹ã«é¢ãã¦ã¯ã
- ãµã¼ãã¹ã¯ä¸è¬çã«æ¨æºåããã¦ãããæä¾æ©è½ã«å¯¾ããã«ã¹ã¿ãã¤ãºã®æè»æ§ã¯éå®ãããã
- 顧客ã«æå®(Off the Shelf)ã®æ å ±ã»ãã¥ãªãã£ã³ã³ããã¼ã«ãæä¾ããã
- 顧客ãã¨ã®ç£æ»ã¯åãå ¥ããªãã
- 顧客ã®æ å ±ã»ãã¥ãªãã£ç®¡çã¯ãããã¤ãã®è½åã«ä¾åããã
- “As Is”ã®å¥ç´ã«åºã¥ãã¦ãµã¼ãã¹ãæä¾ããã
ã¨ãã£ãç¹å¾´ãæãã¦ãããããã«ãã£ã¦çµæ¸çãªã¯ã©ã¦ããµã¼ãã¹ã®æä¾ãç®æãã¦ãã¾ããã¤ã¾ãå¤ãã®é¡§å®¢ï¼ã«ã¹ã¿ãï¼ã«åãå ¥ãå¯è½ãªæä¾æ¡ä»¶ãç¨æãããããä¿®æ£ãªãã«åãå ¥ãã¦ãããã¨ããä»çµã¿ã§ãããã®é¢ä¿ãå³10ã«ç¤ºãã¾ãã
- 1: ãã®å ´åãã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã«ã¯ã©ã¦ããµã¼ãã¹è½åããã¢ãµã¼ãã¹ã¯ã©ã¦ãã¨å¼ã³ããããæä¾ãããããã¤ãããã¢ãµã¼ãã¹ã¯ã©ã¦ããããã¤ã(peer cloud service provider)ã¨å¼ã³ã¾ã[3][4]ã
å³10. ãµã¼ãã¹æä¾å½¢æ ã«ããåæå½¢æã®éã
ä¸æ¹ã§ããã©ã¤ãã¼ãã¯ã©ã¦ãããã¤ããªããã¯ã©ã¦ãã¯åæå½¢æã«ããã£ã¦ãã¢ã¯ã¢ã¤ã¢ã®è¦ä»¶ã«ããç¨åº¦å¯¾å¿å¯è½ã§ãããã¨ãããä¸è¬çãªICTãµãã©ã¤ãã§ã¼ã³ã®ä¸å½¢æ ã¨è¦ããã¨ãã§ãã¾ãã
6.6 ã¯ã©ã¦ããµã¼ãã¹å©ç¨ã«é¢ããè å¨ã¨ãªã¹ã¯
以ä¸æ´çãã¦ããããµãã©ã¤ãã§ã¼ã³ã®ä¸å½¢æ ã¨ãã¦è¦ãã¯ã©ã¦ããµã¼ãã¹ã®ç¹å¾´ã«åºã¥ãã¦ãã¯ã©ã¦ããµã¼ãã¹å©ç¨ã«é¢ããè å¨ã¨ãªã¹ã¯ã«ã¤ãã¦æ´çãã¦ããã¾ãã
ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã®è¦ç¹
ã¯ã©ã¦ããµã¼ãã¹ã®ã«ã¹ã¿ãï¼é¡§å®¢ï¼ã¯ãã¯ã©ã¦ããµã¼ãã¹ãããã¤ããå«ãå¤é¨ãµãã©ã¤ã¢ãæä¾ããæ å ±ã·ã¹ãã ãµã¼ãã¹ã®ä½¿ç¨ã«ãã£ã¦çºçããæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã«å¯¾ãã¦è²¬ä»»ã¨ã¢ã«ã¦ã³ã¿ããªãã£ãè² ãã¾ããå¾ã£ã¦ãã¯ã©ã¦ããµã¼ãã¹ã使ç¨ãããªã¹ã¯ãè©ä¾¡ãããµã¼ãã¹ã使ç¨ãããã©ããã決å®ããç¹å®ã®ãããã¤ããé¸æãã責任ãããã¾ããã¯ã©ã¦ããµã¼ãã¹ã«é¢é£ãããªã¹ã¯ã¯ãé¸æããã¯ã©ã¦ãæ©è½ã¿ã¤ãããµã¼ãã¹ã«ãã´ãªãå±éã¢ãã«ã®çµã¿åããã«ãã£ã¦ç°ãªãã¾ããç¹ã«ãå©ç¨ããã¯ã©ã¦ããµã¼ãã¹ã«ãã£ã¦ã¯ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã®æ å ±ã»ãã¥ãªãã£ç®¡çã«ä¿ãæ©è½ã®å©ç¨ãå¶éããããã¨ãããã¤ã³ã·ãã³ãã®æ¤åºããã¼ã¿ãèç©ã»å¦çãããå ´æã¨ãã®ä¿è·ãã¢ã¯ã»ã¹ãå©ç¨ã®ç¶æ³ããã«ã¦ã§ã¢ããã®ä¿è·ãªã©ã®ãå¯è¦åããä¸ååã«ãªãã±ã¼ã¹ãããå¾ã¾ãããããã¯ã¯ã©ã¦ããµã¼ãã¹ã®å©ç¨ã«ããã£ã¦ã®èå¼±æ§ãæ¡å¤§ãããè¦å ã«ãªãã¾ããå¾ã£ã¦ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã¯ãµã¼ãã¹å©ç¨ã«ããã£ã¦ã®ãã¼ã¿ãå¦çã®éè¦æ§ãèå¥ãã¦ãªã¹ã¯è©ä¾¡ãè¡ããé©åãªã¯ã©ã¦ããµã¼ãã¹ãé¸æããå¿ è¦ãããã¾ãã
ãããªãã¯ã¯ã©ã¦ãã®ãµã¼ãã¹æä¾æ©è½ã«ããè å¨ã¨ãªã¹ã¯
ãããªãã¯ã¯ã©ã¦ããµã¼ãã¹ã§ã¯ãå©ç¨ãããµã¼ãã¹æä¾æ©è½ã«å¿ãã¦ãããå©ç¨ãã顧客ã®è å¨ã¨ãªã¹ã¯ã¯å¤åãã¾ãããã®æ¦è¦ã表11ã«ã¾ã¨ãã¾ããããã§åãä¸ãã¦ãããªã¹ã¯ã¯ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãããªã¹ã¯ã«å¯¾å¿ããæ©è½ãã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã«ç§»è»¢ãããã¨ã§çºçãããã®ã説æãã¦ãã¾ããå¾ã£ã¦ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã¯ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãããããã®ãªã¹ã¯ã«åå対å¿ã§ãã¦ãããããªã¹ã¯ãå容å¯è½ããå¤æããä¸ã§ãã¯ã©ã¦ããµã¼ãã¹ãå©ç¨ãããã¨ãæ±ãããããã¨ã«ãªãã¾ãã表ã®ä¸ã®éè²ã§ç©ºç½ã®æ¬ã¯ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ããèªããªã¹ã¯å¯¾å¦ãè¡ãé¨åã«ãªãã¾ããã¤ã¾ããã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ããèªã対å¿ãè¡ãå¿ è¦ããããªã¹ã¯ã«ãªãã¾ãã以éã®ã6.6ç¯ã§ã¯ã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ããã»ã¹ã®è¦³ç¹ã§ãã®ãªã¹ã¯ã«å¯¾å¿ããããã«å¿ è¦ãªè¦ä»¶ãã¾ã¨ãã¦ãã¾ãã
å ¸åçãªè å¨ã¨ãªã¹ã¯ | ã¯ã©ã¦ããµã¼ãã¹ã®æä¾æ©è½ã«å¯¾ãã顧客ã®ãªã¹ã¯ | ||
---|---|---|---|
ã¤ã³ãã©ã¹ãã©ã¯ãã£æ©è½å | ãã©ãããã©ã¼ã æ©è½å | ã¢ããªã±ã¼ã·ã§ã³æ©è½å | |
顧客ãã¼ã¿ã®ä¿åå ãå¶å¾¡ã§ããªã | 顧客ãã¼ã¿ã®å®å ¨æ§ã追跡å¯è½æ§ããã©ã¤ãã·ã¼ä¿è·ã®æ¬ å¦ | ||
ã¹ã¼ãã¦ã¼ã¶ã¼ã管çè ãç¹æ¨©ã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹æ¨©ãç¹å®ã§ããªã | é«ãç¹æ¨©ãæã£ã¦ãã人ç©ã«ããå®å ¨æ§ã追跡å¯è½æ§ãæ©å¯æ§ããã©ã¤ãã·ã¼ã®ä¾µå®³ | ||
ãã«ã¦ã§ã¢å¯¾çã®æ¬ å¦ | å ¨ã¦ã®ã¬ã¤ã¢ã«å¯¾ãããã«ã¦ã§ã¢ã®ä¾µå ¥ | å®å ¨ã§ãªããã©ãããã©ã¼ã ã«å¯¾ãããã«ã¦ã§ã¢ã®ä¾µå ¥ | ã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ãããã«ã¦ã§ã¢ã®ä¾µå ¥ |
顧客ãã¼ã¿ã¸ã®ä¸æãªã¢ã¯ã»ã¹æ¨© | 管çè 権éã«ããæ©å¯æ§ããã©ã¤ãã·ã¼ãå®å ¨æ§ã®ä¾µå®³ | ã¦ã¼ã¶ã¼æ¨©éã«ããæ©å¯æ§ããã©ã¤ãã·ã¼ãå®å ¨æ§ã®ä¾µå®³ | |
ãã°ãã¼ã¿ã®æ¬ å¦ | ãã°ãã¼ã¿æ¬ å¦ã«ãã追跡å¯è½æ§ãå®å ¨æ§ã®åªå¤± | ã¢ããªã±ã¼ã·ã§ã³ãã°ãã¼ã¿æ¬ å¦ã«ãã追跡å¯è½æ§ãå®å ¨æ§ã®åªå¤± | |
ãã©ãããã©ã¼ã ã®å®å ¨æ§ãä¸æ | ãã©ãããã©ã¼ã ã®å®å ¨æ§ãä¿è¨¼ãããªããã¨ã«ãããã¾ãã¾ãªãªã¹ã¯ï¼æ³å®å¤ã®æä½ã«ãããã¼ã¿ã®å®å ¨æ§ã®ä¾µå®³çï¼ | ||
å¶å¾¡ããã¦ããªãã¢ããªã±ã¼ã·ã§ã³ã®å¤æ´ | ã¢ããªã±ã¼ã·ã§ã³ã®å®å ¨æ§ã®ä¾µå®³ | ||
å¶å¾¡ããã¦ããªãã¢ããªã±ã¼ã·ã§ã³ã®éçº | éçºã«ãããã»ãã¥ãªãã£è¦ä»¶ã®æ¬ å¦ | ||
ãµã¼ãã¹ã®æä¾ä¸ã«é¡§å®¢ãã¼ã¿ãåå¾ã§ããªã | 顧客ãã¼ã¿ãåå¾ã§ããªããã¨ã«ãããµã¼ãã¹ã®åæ¢ | ||
ãµã¼ãã¹æä¾ä¸ããã³æä¾å¾ã®ã¯ã©ã¦ããµã¼ãã¹é¡§å®¢ãã¼ã¿ã®å¶å¾¡ã«é¢ããä¸ç¢ºå®æ§ | ãããã¯ã¼ã¯ãã©ãã£ãã¯æ å ±çã®é¡§å®¢ãã¼ã¿ã«å¯¾ããææ権ã®ç解ä¸è¶³ã«ããå¯ç¨æ§ã®åªå¤± | ã¯ã©ã¦ããµã¼ãã¹ã®é¡§å®¢ãã¼ã¿ï¼ã¦ã¼ã¶ã¼æ å ±çï¼ã®ææ権ã®ç解ä¸è¶³ã«ããå¯ç¨æ§ã®åªå¤± | |
顧客ãã¼ã¿ããµã¼ãã¹ã®çµäº/çµäºå¾ã«å®å ¨ã«åé¤ããããã©ãããå¤æã§ããªã | 顧客ãã¼ã¿ï¼å¦çãã¹ãã¬ã¼ã¸ããããããã¯ã¼ã¯å©ç¨ãã¼ã¿çï¼ã®åé¤ãä¿è¨¼ãããªããã¨ã«ããæ©å¯æ§ãå¯ç¨æ§ã®åªå¤± | 顧客ãã¼ã¿ï¼ã¢ããªã±ã¼ã·ã§ã³ã®ãã¼ã¸ã§ã³ã試é¨ãå®è¡ç°å¢ï¼ã®åé¤ãä¿è¨¼ãããªããã¨ã«ããæ©å¯æ§ãå¯ç¨æ§ã®åªå¤± | 顧客ãã¼ã¿ï¼ã¢ããªã±ã¼ã·ã§ã³ã®å©ç¨çãå¦çãããã¦ã¼ã¶ã¼ãã¼ã¿ã¨ãã®ã¿ã¤ãï¼ã®åé¤ãä¿è¨¼ãããªããã¨ã«ããæ©å¯æ§ãå¯ç¨æ§ã®åªå¤± |
ãã©ã¤ãã¼ãã¯ã©ã¦ãããã¤ããªããã¯ã©ã¦ãå©ç¨æã®è å¨ã¨ãªã¹ã¯
表11ã«ç¤ºããã¯ã©ã¦ããµã¼ãã¹ã®æä¾æ©è½ã«å¯¾å¿ãã¦çºçãããªã¹ã¯ã«é¢ãã¦ããã©ã¤ãã¼ãã¯ã©ã¦ããå©ç¨ããå ´åã¯ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã¨ãããã¤ãã¨ã®éã§ãªã¹ã¯ä½æ¸ã®ããã®æ¹çã交æ¸ã«ããæ¡ç¨ãããã¨ãå¯è½ã¨ãªãã¾ãããªã¹ã¯ä½æ¸ã®ããã®ã»ãã¥ãªãã£ç®¡ççã®ãã¼ã¹ã©ã¤ã³ã¯ISO/IEC 27017[2]ãåèã«ãããã¨ãã§ãã¾ãããã¤ããªããã¯ã©ã¦ãã®å ´åã¯ãå©ç¨ãããããªãã¯ã¯ã©ã¦ãã«é¢ãããªã¹ã¯ã¨ãã©ã¤ãã¼ãã¯ã©ã¦ãã®å©ç¨ããã£ã¦ä½æ¸å¯è½ãªãªã¹ã¯ãåæ¡ãã¦å©ç¨ãã¦ãããã¨ã«ãªãã¾ãã
6.7 ã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ããã»ã¹ã«å¯¾å¿ãããµãã©ã¤ãã§ã¼ã³ã¨ãã¦ã®ã¯ã©ã¦ããµã¼ãã¹ã®æ å ±ã»ãã¥ãªãã£ç®¡ç
ããã¾ã§ã§è¦ã¦ããããã«ãã¯ã©ã¦ããµã¼ãã¹ãå©ç¨ããã«ããã£ã¦ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãããããã¤ãå ±ã«å¿ è¦ãªæ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ããå®è£ ãã¦ããå¿ è¦ãããã¾ããããããã®æ å ±ã»ãã¥ãªãã£ç®¡çã«å¯¾ããè¦æ±äºé ã¨ç®¡ççã¯ISO/IEC 27001, 27002ããã³ããã«ã¯ã©ã¦ããµã¼ãã¹å¯¾å¿ã®è¦æ±æ¡ä»¶ã¨ç®¡ççã¨ãã¦è¿½å ãããISO/IEC 27017, 27018ãããã¾ããããã«å¯¾ãã¦ãISO/IEC27036 Part4ã§ã¯ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã¨ãããã¤ãã®é¢ä¿ããµãã©ã¤ãã§ã¼ã³ã®é¢ä¿ã¨è¦ã¦ãããã«å¯¾ããæ å ±ã»ãã¥ãªãã£ç®¡çã«é¢ããè¦ä»¶ãæ´ãåºãã¦ãã¾ããããã¯ãä»ã¾ã§Part1ããPart3ã§è¦ã¦ããããã«ã·ã¹ãã ã©ã¤ããµã¤ã¯ã«ããã»ã¹ã«å¯¾å¿ãããã®ã¨ãã¦ã¾ã¨ãããã¦ãã¾ãã以ä¸ã§ã¯ãPart1ï½Part3ã«å ãã¦è¿½å ããããã¤ã³ãã¨ãªãã©ã¤ããµã¤ã¯ã«ããã»ã¹ã«å¯¾å¿ããè¦ä»¶ãè¦ã¦è¡ãã¾ãããªãã以ä¸ã§ã®åé çªã¯ISO/IEC 27036 Part4ã§ã®é çªã«å¯¾å¿ããã¦ãã¾ãã
6.1 å¥ç´ããã»ã¹
6.1.1 調éããã»ã¹ï¼ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã«å¯¾ããè¦ä»¶
ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã¨ã®é¢ä¿ã確ç«ãã
- 対象ã¨ããã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã§å®æ½ããã¦ããæ å ±ã»ãã¥ãªãã£ç®¡çãç解ããã
- ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã¨ã®åæ»ãªã³ãã¥ãã±ã¼ã·ã§ã³ã確ä¿ããããã«ãåæ¹ã®çªå£ãè¨å®ããã
- ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã¨ã®éã§ã®æ確ãªå½¹å²ã¨è²¬ä»»ã®å²ãå½ã¦åæ ãå®ç¾©ããã
- ã¯ã©ã¦ãåºæã®ãªã¹ã¯ã軽æ¸ããããã®æéã¨ãªãååãåãå ¥ããã
- æ¢åã®ã»ãã¥ãªãã£ããªã·ã¼ãã¯ã©ã¦ããµã¼ãã¹ã«æ¡å¼µããã
6.1.2 ä¾çµ¦ããã»ã¹ï¼ã¯ã©ã¦ããããã¤ãã«å¯¾ããè¦ä»¶
- ã¯ã©ã¦ããµã¼ãã¹ãããã¤ããåãå ¥ãã責任ã®ç¯å²ãå®ç¾©ããã ã¯ã©ã¦ããµã¼ãã¹ãããã¤ããä»ã®ã¯ã©ã¦ããµã¼ãã¹ãå©ç¨ãã¦ããå ´åã¯ãã®ãµã¼ãã¹ã®ä½¿ç¨ã«å¯¾ãã責任ãæå®ããã
- æä¾ããã¯ã©ã¦ããµã¼ãã¹ã«å¯¾ãã責任ã宣è¨ãã¦å ¬éããã
- 顧客ã®æ å ±ã®ä¿è·ã«é¢ããæ å ±ã¨æ©è½ãæä¾ããã
- å¯è½ãªãããµã¼ãã¹ã®ä¿¡é ¼æ§ã¨é¡§å®¢æ å ±ä¿è·ãä¿è¨¼ãããããæ å ±ã»ãã¥ãªãã£ç®¡çã«å¯¾ãã第ä¸è ããã®ææ°ã®ä¿è¨¼ãé示ããã
- å®å ¨ãªããã¯ã¢ãã/ã¢ã¼ã«ã¤ãæ©è½ã«ã¤ãã¦èª¬æããã
- é害èå対çï¼ãã¸ãã¹ç¶ç¶æ§ã¨é害復æ§è¨ç»ãå«ãï¼ã説æããã
- ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãå ã®å¤æ´ãéç¥ããããã»ã¹ã説æããã
- 顧客ã«ãµã¼ããã¼ãã£ã®ç£æ»è¨¼ææ¸ãç£æ»/証æã¬ãã¼ããªã©ã®ä¿è¨¼è¨¼æ ãæä¾ããã
- ãã«ãããã³ãå¦çãæ å ±ã®è«ççããã³ç©ççãªåé¢ãæä¾ããããã®é¡§å®¢ã«å¯¾ããè¦ä»¶ã確ç«ããã
- 顧客ã®è³ç£ãå®å
¨ã«è»¢éããããã®è¦ä»¶ã確ç«ããããã
- 顧客æ å ±ã®ç§»åãéä¿¡ãããã³ä¿åãå¶éããããã®è¦ä»¶ã確ç«
- 顧客ã«æ å ±ã®è«ççãç©ççåé¢ãæä¾ããæ©è½ã«é¢ãã¦ãµã¼ãã¹ãè©ä¾¡ããæ¹æ³ã¨è¨±å®¹åºæºãå®ç¾©ããã
- 顧客ã®è³ç£ãå¥ã®ã¯ã©ã¦ããµã¼ãã¹ãããã¤ã移è¡ããããã»ã¹ãå®ç¾©ããã
- å¥ç´çµäºæã®ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãç°å¢ã«ããã顧客ã®è³ç£ã®å»æ£ããã³ãã®ç¢ºèªã®ããã»ã¹ãå®ç¾©ããã
- ãµã¼ãã¹ã¬ãã«å¥ç´ï¼SLAï¼ãå«ããã¯ã©ã¦ããµã¼ãã¹ã®æ å ±ã»ãã¥ãªãã£ã«é¢é£ããå¥ç´ææ¸ã®åéã¨åæã®ããã»ã¹ãå®ç¾©ããã
6.3 ããã¸ã§ã¯ã管çããã»ã¹
ISO/IEC15288ã®é ç® | ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã®è¦ä»¶ | ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®è¦ä»¶ | |
---|---|---|---|
6.3.4 | ãªã¹ã¯ç®¡çããã»ã¹ | a) ã¯ã©ã¦ãã§å¦çã§ããæ
å ±ã®ã¿ã¤ããåé¡ãããã³éè¦æ§ãæå®ããï¼ä¾ï¼åæ¥æ
å ±ãç¥ç財ç£ãæ³çæ
å ±ãè¦å¶æ
å ±ãç¹æ¨©æ
å ±ãç©æµæ
å ±ã管çæ
å ±ãå人æ
å ±çï¼ã b) ã¯ã©ã¦ããµã¼ãã¹ä¸ã§å¦çãããæ å ±ã«é¢ãããçµç¹ã«å¯¾ããæ³ç/è¦å¶ä¸ã®ãªã¹ã¯ãæè¨ããï¼ä¾ï¼èä½æ¨©ãæ å ±ä¿è·ã財åè¦å¶ããã©ã¤ãã·ã¼ä¾µå®³ãã³ã¼ãã¬ã¼ãã¬ããã³ã¹çï¼ã c) ãªã¹ã¯ãè©ä¾¡ããæ®åãªã¹ã¯ãåãå ¥ããã |
a) 顧客ã¨åæããSLAã§æå®ãããã»ãã¥ãªãã£ãµã¼ãã¹ã¬ãã«ãæä¾ããã b) ã¯ã©ã¦ããµã¼ãã¹ã®ä¸ç°ã¨ãã¦ãçµäºããã»ã¹ã¨é¢é£æ å ±ã®è¿å´ããã³/ã¾ãã¯å»æ£ã管çããã |
6.3.5 | æ§æ管çããã»ã¹ | a) ã¯ã©ã¦ããµã¼ãã¹ã®å¤æ´ã«ããå½±é¿ãç¹å®ããã | aï¼å
¨ã¦ã®ãµã¼ãã¹å¤æ´ã¯ãããã¤ãã«ãã£ã¦åæãããçµã°ããå¥ç´ã¨æ¯è¼ããã bï¼å¤æ´ãã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã«éç¥ããã |
6.3.6 | æ å ±ç®¡çããã»ã¹ | èªè¨¼ãã¼ã¿ãå人æ å ±ã«ç´ã¥ããã©ãããå¤æããã | ã¯ã©ã¦ããµã¼ãã¹ã®èªè¨¼ã½ãªã¥ã¼ã·ã§ã³ã«ããããã©ã¤ãã·ã¼æ å ±ã¨è¦ãªãããIDãã¼ã¿ããããã©ãããå¤æãããããã«ã¯èªè¨¼ãã¼ã¿ãå人æ å ±ã¨ã¿ãªããã©ããã®æ³çå´é¢ã¨ãµã¼ãã¹ã¢ãã«ã«ãã£ã¦ç°ãªãã±ã¼ã¹ãåºã¦ããã |
6.4 æè¡ããã»ã¹
ISO/IEC15288ã®é ç® | ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã®è¦ä»¶ | ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®è¦ä»¶ | |
---|---|---|---|
6.4.4 | å®è£ ããã»ã¹ | ç¹ã«æ©å¯æ å ±ãéè¦ãªæ å ±ãã¯ã©ã¦ããµã¼ãã¹ã«ä¿åãå¦çããå ´åã¯ã段éçã«ã¯ã©ã¦ããµã¼ãã¹ãå®è£ ããã ã«ã¹ã¿ãã¯ããªã¹ã¯ã軽æ¸ããããã«ã段éçãªã¢ããã¼ãã§ã¯ã©ã¦ããµã¼ãã¹ãå±éããå¿ è¦ããããç¶æ³ãæ¦è¦³ããªããããªã¹ã¯ã®å°ãªãã¯ã©ã¦ããµã¼ãã¹ã®ä¸é¨ãå±éãããµã¼ãã¹ã®ä½¿ç¨ã段éçã«æ¡å¤§ããå¿ è¦ãããã | ã»ãã¥ãªãã£ç®¡ççãå®è£ ã管çãå®è¡ããã |
6.4.9 | éç¨ããã»ã¹ |
a) å©ç¨è
åãã®ãã¯ã©ã¦ã使ç¨ããªã·ã¼ããã¬ã¼ãã³ã°ãå®æ½ b) ã¯ã©ã¦ããµã¼ãã¹ã®å¤æ´ãç£è¦ããå¤æ´ã®å½±é¿ã«å¯¾å¦ããã c) ã¯ã©ã¦ããµã¼ãã¹ã«é¢é£ããæ å ±ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«é¢ããæ å ±ãåéãã¦å¯¾å¿ããã |
a) ã¯ã©ã¦ããµã¼ãã¹ã®æä¾ããã»ã¹ã§å®ç¾©ãããæ
å ±ã¨æ©è½ã顧客ã«æä¾ããã
1) éç¨ããã»ã¹ã確ç«ããã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãã«é©åãªæ
å ±ã¨æ©è½ãæä¾ããã
b) ã«ã¹ã¿ãã¨ã®éã®åæã®ç¯å²å
ã§ã«ã¹ã¿ãã®æ´»åãç£è¦ãããããã¯ã©ããµã¼ãã¹ã®ãããã¸ã§ãã³ã°ã«å½±é¿ãä¸ããå¯è½æ§ãããå ´åã¯ãã«ã¹ã¿ãã«å¯¾å¿ããã2) éç¨ããã»ã¹ãéãã¦æ å ±ã¨æ©è½ãæä¾ããã 3) ããã»ã¹ãé©åã«éç¨ããã¦ãããã¨ã確èªããå¿ è¦ã«å¿ãã¦ããã»ã¹ãè©ä¾¡ããããã®ç£è¦ãè¡ãã c) ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®æ´»åãç£è¦ãããµã¼ãã¹ã¾ãã¯ãµã¼ãã¹ã®ãããã¸ã§ãã³ã°ã®ããã«ã¤ã³ãã©ã¹ãã©ã¯ãã£ã«å¯¾ãã¦è¡ããããã¹ã¦ã®æ´»åã®èª¬æ責任ã確ä¿ããã |
6.4.11 | å»æ£ããã»ã¹ | a) ã¯ã©ã¦ããµã¼ãã¹ã§ã®ãµã¼ãã¹å©ç¨çµäºæã®æ å ±å»æ£ã®ç¢ºèªãè¡ãã | a) ã¯ã©ã¦ããµã¼ãã¹ã«ã¹ã¿ãããµã¼ãã¹ã®ä½¿ç¨ãçµäºãããã¨ã«åæããä¸ã§ã顧客ã®æ
å ±è³ç£ã®å»æ£ãè¨é²ããããã»ã¹ã確ç«ããã b) å»æ£ãã°ãé©åã«ç¶æããããã»ã¹ã確ç«ããã c) 顧客ããã®è¦æ±ã«å¿ãã¦ãå»æ£ãã°ãé示ããæé ã確ç«ããã |
7. ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®æä¾æ©è½ã®é¡åã«å¯¾å¿ããã»ãã¥ãªãã£ç®¡çæ©è½
ã¯ã©ã¦ããµã¼ãã¹ãããã¤ããã«ã¹ã¿ãã«å¯¾ãã¦ãµã¼ãã¹ãæä¾ããã«ããã£ã¦ã¯ãã©ã®ãããªæ å ±ã»ãã¥ãªãã£ç®¡çãè¡ã£ã¦ããããæ確ã«ä¼ãããã¨ãéè¦ã¨ãªãã¾ããããã«ã¯ãããã¾ã§ã«è¦ã¦æ¥ããã¾ãã¾ãªæ¨æºãã¬ã¤ãã©ã¤ã³ã«æºæ ãã¦ããäºãä¼ããã¨ã¨ãã«ãå¿ è¦ã«å¿ãã¦ãµã¼ããã¼ãã£ã«ããç£æ»çã§æ確åãããã¨ãå¿ è¦ã¨èãããã¾ããISO/IEC 27036 Part4ã§ã¯ãã®ç®çãããæ確ã«ããããã«ãã¯ã©ã¦ããµã¼ãã¹ã®æä¾æ©è½ã«å¿ãã¦ãããã¤ãå´ã§å¿ è¦ã¨èããããæ å ±ã»ãã¥ãªãã£ç®¡çãã¾ã¨ãããã¦ãã¾ããã¾ãããããªãã¯ã¯ã©ã¦ããµã¼ãã¹ã«å¯¾ããæ å ±ã»ãã¥ãªãã£ç®¡çã以ä¸ã«ç¤ºãã¾ãã
ã¤ã³ãã©ã¹ãã©ã¯ãã£æ©è½å | ãã©ãããã©ã¼ã æ©è½å | ã¢ããªã±ã¼ã·ã§ã³æ©è½å |
---|---|---|
|
å·¦è¨ã«å ãã¦ã
|
å·¦è¨ã«å ãã¦ã
|
ãã©ã¤ãã¼ãã¯ã©ã¦ãããã³ãã¤ããªããã¯ã©ã¦ãã«é¢ãã¦ã¯ããããã®æ å ±ã»ãã¥ãªãã£ç®¡çãå©ç¨å½¢æ ããªã¹ã¯åæã«åºã¥ãã¦é¸æãã¦ãããã¨ã«ãªãã¾ãããããã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã«æ±ããããå ·ä½çãªè¦ä»¶ã«å¯¾ãããã»ãã¥ãªãã£ç®¡ççæ¨æºã¨ã®å¯¾å¿é¢ä¿ã¯ãä»å±æ¸A(Annex A)ã«ã¾ã¨ãããã¦ãã¾ã2ã
8. ããã¾ã§ã®ã¾ã¨ã
以ä¸ãISO/IEC 27036 Part1ããPart4ã®æ¦è¦ã解説ãã¦ãã¾ããããããã®æ¨æºã¯ãå¼ãç¶ãæ¹å®ãè¡ããã¦ããã¨èãããã¾ããã¾ããPart4ã®ã¯ã©ã¦ããµã¼ãã¹ã«é¢ãã¦ã¯ãã¯ã©ã¦ããµã¼ãã¹ã®ã¢ã¼ããã¯ãã£ã®æ´çã¨ã¨ãã«ãSLAã®è¦³ç¹ã§ã®ã»ãã¥ãªãã£è¦ä»¶ãã¾ã¨ãããã¦ãã¾ãï¼å³11ï¼ãSLAã®è¦³ç¹ããã®ã»ãã¥ãªãã£è¦ä»¶ã«ã¤ãã¦ã¯ã¾ãå¥ã®æ©ä¼ã«è§£èª¬ãããã¨èãã¦ãã¾ãã次åããã¯ãNIST SP800-161ã«é¢ãã解説ãé²ãã¦è¡ãã¾ãã
å³11. ã¯ã©ã¦ããµã¼ãã¹ã®SLAã«å«ã¾ããã»ãã¥ãªãã£åã³PIIä¿è·ã®æ¨æº3
â»åç
§æç®[3]ãåç
§æç®[4]ãåç
§æç®[5]ãåç
§æç®[6]ã
åç
§æç®[7]ãåç
§æç®[8]ãåç
§æç®[9]ã
- 2: å ·ä½çã«ã¯ãISO/IEC 27002, 27017, 27018åã³ãã®ä»ã®ISOæ¨æºãåç §ããã¦ãã¾ãã
- 3: [9]ã®Figure 1 — Relationship of parts of ISO/IEC 19086 (all parts) and other cloud computing standardsã«åºã¥ãã¦ä½æã
åç §æç®
- [1] ISO/IEC, 27036 Part4, Information technology — Security techniques — Information security for supplier relationships Part4-Guidelines for security of cloud services, 2016.
- [2] ISO/IEC, 27017, Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services, 2015.
- [3] ISO/IEC, 17788, Information technology — Cloud computing — Overview and vocabulary, 2014.
- [4] ISO/IEC, 17789, Information technology — Cloud computing — Reference architecture, 2014.
- [5] ISO/IEC, 27018, Information technology — Security techniques — Code of practice for protection of Personally Identifiable Information (PII) in public clouds acting as PII processors, 2019.
- [6] ISO/IEC, 19086-1, Information technology — Cloud computing — Service level agreement (SLA) framework — Part 1: Overview and concepts, 2016.
- [7] ISO/IEC, 19086-2, Cloud computing — Service level agreement (SLA) framework — Part 2: Metric model, 2018.
- [8] ISO/IEC, 19086-3, Information technology — Cloud computing — Service level agreement (SLA) framework — Part 3: Core conformance requirements, 2017.
- [9] ISO/IEC, 19086-4, Cloud computing — Service level agreement (SLA) framework — Part 4: Components of security and of protection of PII, 2019.
Writer Profile
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾ ãã§ãã¼
å·¥å¦å士ãCISSP, CISA
ä¸å®
å
Tweet