ãµãã©ã¤ãã§ã¼ã³ã®æ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ã 第7å ï½ NIST SP800-161ãä¸å¿ã«è§£èª¬
ååã«å¼ãç¶ããããããã¯SP 800-161[1]ã®å 容ã«ã¤ãã¦ã®è§£èª¬ãé²ãã¦ããã¾ãã
2. SP 800-161ã®æ§æ
ã¾ãåãã«ãSP 800-161ã®æ§æãç解ããä¸ã§å¿ è¦ã¨ãªãï¼ã¤ã®è¦æ ¼ã¨ã®é¢ä¿ã«ã¤ãã¦ç¤ºãã¾ã(å³1)ãSP 800-161ã¯ãã®ã¿ã¤ãã«ã示ãéããç±³å½é£é¦æ¿åºæ©é¢ï¼ä»¥ä¸ãé£é¦æ¿åºæ©é¢ï¼ã¨ãã®é¢ä¿æ©é¢ã«å¯¾ããããµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ç®¡çã®å®è·µã®ããã®ã¬ã¤ãã©ã¤ã³ã¨è¦æ ¼ã§ããã主ãªç®çã¯ã以ä¸ã®2ç¹ã«ããã¾ãã
- çµç¹é層ã«å¿ãããµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ç®¡ç/è©ä¾¡ã®æ çµã¿ã®æä¾ã
- SP 800-39[2]ã§ç¤ºããã¦ãããçµç¹é層ã«å¯¾å¿ãããªã¹ã¯ç®¡çããã»ã¹ã«å¯¾å¿ãããµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ç®¡çããã³SP800-53 Rev.4[3]ã®ã»ãã¥ãªãã£ç®¡ççã«å¯¾ãããµãã©ã¤ãã§ã¼ã³ã®ã»ãã¥ãªãã£ç®¡ççã®è¿½å ã
ããã§â °ãâ ±ã«é¢ãã¦ãSP 800-161ãç解ããä¸ã§ã¯SP 800-39ã¨é¢é£ããSP 800-30[4]ã®æ¦è¦ãç解ãã¦ããå¿ è¦ãããã¾ãã
å³1. SP 800-161ã¨ä»ã®è¦æ ¼ã¨ã®é¢ä¿
NIST SP 800-39 æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡ç
ã¾ãSP 800-39ã«ã¤ãã¦ãç°¡åã«æ¦è¦ãç´¹ä»ãã¾ããé£é¦æ¿åºæ©é¢ã®ãããªå¤§ããªçµç¹ã§ã¯ãæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã管çããä¸ã§çµç¹é層ãã¨ã®å½¹å²ãæ確åãããã¨ãæ±ãããã¾ããç¹ã«ãæ å ±ã»ãã¥ãªãã£å¯¾çãçµç¹å ¨ä½ã«æ¸¡ã£ã¦ããªã¹ã¯ãã¼ã¹ã§å¯¾å¿ããã¨ããæèã浸éãããå¿ è¦æ§ããããã¨ãèªèããããã®è¦æ ¼ãä½ããã¾ãããSP 800-39ã§ã¯å³1ã®å·¦å´ã«ç¤ºãéããçµç¹é層ã大ãã3ã¤ã«åé¡ãã¦ãã¾ãããã®è¦æ ¼ã®ç®çã¯ã以ä¸ã®ããã«ã¾ã¨ãããã¦ãã¾ãã
- ä¸ç´ç®¡çè·/çµå¶å¹¹é¨ï¼çµç¹ã¬ãã«ï¼ãæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã管çãããã¨ã®éè¦æ§ãèªèãããªã¹ã¯ç®¡çã®ããã®é©åãªã¬ããã³ã¹æ§é ã確ç«ããã
- çµç¹ã®ãªã¹ã¯ç®¡çããã»ã¹ããçµç¹ãããã·ã§ã³/ãã¸ãã¹ããã»ã¹ãããã³æ å ±ã·ã¹ãã ã®3ã¤ã®å±¤ã«ããã£ã¦å¹æçã«å®æ½ããã¦ãããã¨ã確èªããããã®ã¬ã¤ãã³ã¹ã示ãã
- ããã·ã§ã³/ãã¸ãã¹ããã»ã¹ã®è¨è¨ãå æ¬çãªã¨ã³ã¿ã¼ãã©ã¤ãºã¢ã¼ããã¯ãã£ã®å®ç¾©ãããã³ã·ã¹ãã éçºã©ã¤ããµã¤ã¯ã«ããã»ã¹ã®ã³ã³ããã¹ãå ã§æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ãèæ ®ãããçµç¹é¢¨åãè²æããããã®ã¬ã¤ãã³ã¹ã示ãã
- æ å ±ã·ã¹ãã ã®å®è£ ã¾ãã¯éç¨ã«è²¬ä»»ãæã¤å人ããã·ã¹ãã ã«é¢é£ããæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ããæçµçã«ããã·ã§ã³/ãã¸ãã¹ã®æåã«å½±é¿ãä¸ããå¯è½æ§ã®ããçµç¹å ¨ä½ã®ãªã¹ã¯ã«ã©ã®ããã«å¤æãããããããããç解ã§ããããã«ããã
ããã§ãçµç¹é層éã®ãªã¹ã¯ç®¡çã«é¢ããå½¹å²ã®é£æºã¤ã¡ã¼ã¸ãå³2ã«ç¤ºãã¾ãããã®å³ã«ç¤ºããããã«ãçµç¹ã¯ä¸ä½ã®ã¬ãã«ã§ã®æ¦ç¥çãªæ å ±ã»ãã¥ãªãã£å¯¾çã¨ç¾å ´ã¬ãã«ã§ã®æ¦è¡çãªæ å ±ã»ãã¥ãªãã£å¯¾çãããããã¦ã³ãããã ã¢ãã両æ¹åã§é£æºããã¦å¯¾å¿ãã¦ãããã¨ãæ±ãããã¦ãã¾ããå³ã®å³ã«ã¯æ å ±ã·ã¹ãã ãæèããå³ãæ¸ãã¦ãã¾ãããããã¯æ å ±ã·ã¹ãã ã«éãããåã ã®ãã¸ãã¹ããã»ã¹ã¨èãããã¨ãã§ãã¾ãã
å³2. çµç¹é層éã®ãªã¹ã¯ç®¡çã®é£æº
ã¾ãããã1ã¤ã®ãã¤ã³ãã§ãããªã¹ã¯ç®¡çããã»ã¹ã¨ãã®å 容ãå³3ã«ç¤ºãã¾ãããªã¹ã¯ç®¡çããã»ã¹ã¯ããªã¹ã¯ç®¡çã®æ çµã¿(Framing)ããªã¹ã¯è©ä¾¡(Assessment)ããªã¹ã¯å¯¾å¿ï¼Responseï¼ããªã¹ã¯ç£è¦(Monitoring)ã®4ã¤ã§æ§æããã¦ãã¾ããããã§ãªã¹ã¯ç®¡çã®æ çµã¿ã¨ã¯ãçµç¹ã«ããã¦ã©ã®ãããªæ¹éã§ãªã¹ã¯ç®¡çãè¡ããã決ãããã®ã§ããå¾ã£ã¦ãTier 1ã¨Tier 2ã3ã¨ã®ã³ãã¥ãã±ã¼ã·ã§ã³ã«ããå¿ è¦ãªçµç¹æ å ±ãåéãããã¨ã¨ãã«ãTier 1ã«ãã£ã¦çµç¹æ¦ç¥ãå¤é¨ç°å¢ã¨ã®æ´åæ§ã«åºã¥ãã¦çµç¹å ¨ä½ã¨ãã¦ã®æ çµã¿ã«éç´ããããã¨ã«ãªãã¾ããTier2, 3ã¯ãã®æ çµã¿ã«åºã¥ãã¦ããªã¹ã¯ã®è©ä¾¡ã対å¿ãç£è¦ãå®è¡ãTier 1ã«ã¬ãã¼ããããã¨ã«ãªãã¾ãã
å³3. ãªã¹ã¯ç®¡çããã»ã¹
ããã§è©³ç´°ã¯å²æãã¾ãããSP 800-39ï¼ç¬¬3ç« ï¼ã§ã¯åããã»ã¹ãæ§æããã¿ã¹ã¯ã®ãåææ¡ä»¶ã»å ¥åãæ´»åãåºåã®è©³ç´°ãè¿°ã¹ããã¦ãã¾ããã¾ãããã®ããã»ã¹ã®å®è¡ä¸éè¦ã¨ãªããªã¹ã¯è©ä¾¡ã«é¢ãã¦ã¯ä»¥ä¸ã§è§£èª¬ããSP 800-30ã§ã¾ã¨ãããã¦ãã¾ãããã®ãªã¹ã¯è©ä¾¡ã®æ¹æ³ã¯å ¨ã¦ã®é層ã§é©ç¨ããããã®ã«ãªãã¾ããããã«ãSP 800-37 Rev.2[5]ã§ã¾ã¨ãããã¦ãããªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼Risk Management Frameworkï¼1ã®åé¡ããã·ã¹ãã ã®æ¿èªã管ççã®ã¢ãã¿ãªã³ã°ã¾ã§ã®ããã»ã¹ã¯ä¸»ã«Tier 3ã«ããã¦å®è¡ãããããã»ã¹ã«ãªãã¾ããåé層ã®ä¸»ãªæ´»åã®ä¾ã表1ã«ã¾ã¨ãã¾ãã
表1. åé層ã®ãªã¹ã¯ç®¡çæ´»åã®ä¾
- 1: SP 800-37ã«é¢ãã¦ã¯ãå½ç¤¾ã³ã©ã ãNISTã®ãªã¹ã¯ããã¸ã¡ã³ããã¬ã¼ã ã¯ã¼ã¯ï¼RMFï¼ã¨ã¯ãã§è©³ããç´¹ä»ãè¡ã£ã¦ãã¾ãã
NIST SP 800-30 ãªã¹ã¯è©ä¾¡å®æ½æé
NIST SP 800-30ã§ã¯ãSP 800-39ã§ç¤ºããã¦ãããªã¹ã¯ç®¡çããã»ã¹ã®ä¸ã§å¿ è¦ãªããªã¹ã¯è©ä¾¡ã¨ãã®æ çµã¿ã®é²ãæ¹ã«ã¤ãã¦è©³ç´°åãã¦ãã¾ãããã®æ´»ç¨ç®çã¯ã以ä¸ã®ããã«ã¾ã¨ãããã¦ãã¾ãã
- çµç¹ã®æ å ±ã»ãã¥ãªãã£ã¢ã¼ããã¯ãã£ï¼ããªã·ã¼ãçµç¹/ããã·ã§ã³ãããã»ã¹ï¼ã®éçº
- æ å ±ã·ã¹ãã ï¼ããã·ã§ã³ï¼æ¥åããã»ã¹ããã³å ±éã¤ã³ãã©ï¼æ¯æ´ãµã¼ãã¹ãæ¯æ´ããã·ã¹ãã ãå«ãï¼ã®ç¸äºé£æºã«é¢ããè¦æ±äºé ã®å®ç¾©
- æ å ±ã·ã¹ãã ããã³éç¨ç°å¢ã«å¯¾ããã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ã®è¨è¨ï¼ã»ãã¥ãªãã£ç®¡ççãIT製åãä¾çµ¦æ¥è ï¼ãµãã©ã¤ãã§ã¼ã³ãããã³åè¨æ¥è ã®é¸æãå«ãï¼
- æ å ±ã·ã¹ãã ã®éç¨ããããã¯ããããã®ã·ã¹ãã ã«ãã£ã¦ç¶æ¿ãããã»ãã¥ãªãã£ç®¡ççï¼ããªãã¡ãå ±é管ççï¼ã®ä½¿ç¨ã«å¯¾ããèªå¯ï¼ã¾ãã¯èªå¯ã®æå¦ï¼
- ããã·ã§ã³ï¼æ¥åæ©è½ããã³ï¼ã¾ãã¯ããã·ã§ã³ï¼æ¥åããã»ã¹ãæ°¸ç¶çã«ãã¾ãã¯ç¹å®æéã«ããã£ã¦ï¼ãã¨ãã°ãæ°ãã«çºè¦ãããè å¨ã¾ãã¯èå¼±æ§ã対å¦ãããã¾ã§ãè£å®ç管ççãç½®ãæããããã¾ã§ï¼å¤æ´ãããã¨
- ã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ã®é©ç¨ï¼ä¾ï¼ç¹å®ã®IT製åãã¾ãã¯ãããã®è£½åã®è¨å®ããå®ããããè¦æ±äºé ãæºãããå¦ãï¼ ã¨ãã®éç¨ã¨ä¿å®ä¾(ç¶ç¶çãªã¢ãã¿ãªã³ã°æ¦ç¥ããã³è¨ç»ãç¶ç¶çãªèªå¯ãªã©ï¼
ã¤ã¾ããæ
å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ããå®è¡ããããã®åºæ¬çãªç®çã¨æ¹éã®çå®ã«å¿
è¦ãªããã»ã¹ã¨è¨ãã¾ãã
å³4ã«ãªã¹ã¯ç®¡çã®æ çµã¿ã¨ãªã¹ã¯è©ä¾¡ã®æ¹æ³ãæ§æãã4ã¤ã®æ¦å¿µã示ãã¾ãã
å³4. ãªã¹ã¯ç®¡çã®æ çµã¿ã¨ãªã¹ã¯è©ä¾¡
ãªã¹ã¯ç®¡çã®æ çµã¿ã¨ãªã¹ã¯è©ä¾¡ã«ããã£ã¦ã¯ã¾ã対象ã¨ããçµç¹ã®ãªã¹ã¯ã¢ãã«ã®ç¹å®ãå¿ è¦ã«ãªãã¾ããä¸è¬çã«ããªã¹ã¯ã¢ãã«ã¨ã¯å³5ã«ç¤ºãããã«ãè å¨ãèå¼±æ§ãè³ç£ã®ä¾¡å¤ãè³ç£æ失ã®å¯è½æ§ã®ï¼ã¤ã®ãã¡ã¯ã¿ã§èãããã¨ãã§ãã¾ããããã«ãã£ã¦ããªã¹ã¯ã¨ã¯
ï¼æ å ±ã»ãã¥ãªãã£ï¼ãªã¹ã¯ ï¼ è³ç£ã®ä¾¡å¤(失ãããå ´åã®å½±é¿) × æ失ã®å¯è½æ§
ã¨ãã¦è©ä¾¡ã§ãããã¨ã«ãªãã¾ãããããããªã¹ã¯ã¢ãã«ã§ãããã®ã¢ãã«ã«å¾ã£ã¦ããªã¹ã¯åæãè©ä¾¡ãè¡ããã¨ã«ãªãããã§ãããã㧓影鿔ã¨è¨è¿°ãã¦ãã¾ãããããã¯çµç¹ã®ããã·ã§ã³ãå½±é¿ãåãããã¨ã§ããã¤ã¾ããè³ç£ã®ä¾¡å¤ã¯ããã失ãããå ´åã®çµç¹ã®ãã¸ãã¹/ããã·ã§ã³ã¸ã®å½±é¿åº¦ã§æ±ºã¾ãã¾ãã
å³5. ä¸è¬çãªãªã¹ã¯ã¢ãã«
ããã§ãæ å ±ã»ãã¥ãªãã£ã«å¯¾ããè å¨ã¨ãã¦ã¯æ¬¡ã®ãã®ãèãããã¾ãã
- æµæãæã£ããµã¤ãã¼æ»æã¾ãã¯ç©ççæ»æ
- æ æ ¢ã¾ãã¯é失ã«ãã人çãã¹
- çµç¹ã管çããè³æºï¼ä¾ï¼ãã¼ãã¦ã§ã¢ãã½ããã¦ã§ã¢ãç°å¢å¶å¾¡ï¼ã®æ§é ä¸ã®æ¬ é¥
- èªç¶ç½å®³ã¨äººç½ãã¢ã¯ã·ãã³ããçµç¹ãã³ã³ããã¼ã«ã§ããªãé害
- ä¸è¨ã®äºè±¡ã®è¤åççºçãè å¨ã®ã·ãã2
ããã«å¯¾ãã¦ãèå¼±æ§ã¨ã¯è å¨æºã«ãã£ã¦å©ç¨ãããå¯è½æ§ãããæ å ±ã·ã¹ãã ã®è¦ç´ ãã·ã¹ãã ã»ãã¥ãªãã£æé ãå é¨çµ±å¶ãã¾ãã¯å®è£ ï¼ç©çç°å¢ãé»åä¾çµ¦çãå«ãï¼çã®ã»ãã¥ãªãã£ç®¡ççã®å¼±ç¹ãæå³ãã¾ããã¾ããèå¼±æ§ã¯çµç¹ã®ããã·ã§ã³ï¼æ¥åæ©è½ã®é²åãéç¨ç°å¢ã®å¤åãæ°æè¡ã®å°å ¥ãã·ã¹ãã ã®æ´æ°ã«ããæ°ããªè å¨ã®åºç¾çãæéã®çµéã¨ã·ã¹ãã ã®ã©ã¤ãã¹ãã¼ã¸ã«ä¼´ã£ã¦çããæ°ããªèå¼±æ§ãããã¾ããããã«ãå°ççç°å¢ï¼ç½å®³çºçé »åº¦ï¼ããã¸ãã¹èªä½ã®ç¹æ§ï¼æ¥åã·ã¹ãã ãçç£å¶å¾¡ã·ã¹ãã çï¼ãå°æ¿å¦çãªè¦ç´ ãããå¾ã¾ã3ã
ã¾ããè³ç£æ失ã®å¯è½æ§ã¯è å¨ã®åé¡ã¨ã対å¿ããè³ç£ã®èå¼±æ§ããã¨ã«ãæ害ãçºçããå¯è½æ§ãæ¨å®ãããã¨ã§ãªã¹ã¯åæãè¡ããã¨ãæå³ãã¾ããæ¨å®ã«ããã£ã¦ã¯ãè©ä¾¡ã®ããã®å®éçãããã¯å®æ§çææ³ãããã¤ãããã¾ã4ãã¾ãããªã¹ã¯åæãå®æ½ããæé ã¨ãã¦ãâ °. è å¨ãéè¦ãâ ±. æ失å¯è½æ§ã®ããè³ç£ãéè¦ãâ ². èå¼±æ§ãéè¦ãã¨ãã£ããã®ãããå¾ã¾ããããã§æ³¨æãå¿ è¦ãªã®ã¯ãããè³ç£ã®è å¨ãããã¯èå¼±æ§ã«ããã»ãã¥ãªãã£ä¾µå®³ãä»ã®è³ç£ã«å¯¾ãã侵害ã®å¯è½æ§ã大ãããããã¨ãã£ãå ´åããããã¨ã§ããå¾ã£ã¦ããªã¹ã¯åæã«ããã£ã¦ã¯ããªã¹ã¯ã®ç¸é¢æ§ãä¸ç¢ºå®æ§çãèæ ®ããå¿ è¦ãããããªã¹ã¯åæãç°ãªãæé ã§è¡ãäºãæå¹ã¨èãããã¾ãããæçµçã«ããªã¹ã¯è©ä¾¡ã¯åã ã®è³ç£ã®ä¾¡å¤ã¨ããã失ãããå¯è½æ§ã«åºã¥ãã¦è¡ããã¾ããå ·ä½çã«ã¯åã ã®è³ç£ã失ãããå ´åã®å½±é¿ã®ç¨åº¦ï¼éè¦åº¦ï¼ã¨ããã失ãããå¯è½æ§ãããããå®æ§çããããã¯å®éçã«è©ä¾¡ããçµç¹ã¨ãã¦è¨±å®¹ç¯å²ã«åã¾ã£ã¦ãããã©ããã®å¤æãã§ããããã«ãã¾ãã
- 2: æ»æè ããæç¥ããä¿è·æ段ï¼å¯¾çï¼ããªãã¡ãã»ãã¥ãªãã£ç®¡ççï¼ã«å¯¾ãã¦åã対ææªç½®ãä¿è·æ段ï¼å¯¾çãåé¿ãæã¡ç ´ãããã«ãèªèº«ã®æå³ï¼æ¨çã®ä¸é¨ã®ç¹æ§ãå¤æ´ãããè å¨ã®ã·ããã¯ãåä¸ã®é åããããã¯è¤æ°ã®é åã«ããã¦çºçãããAPTæ»æãããã«è©²å½ããã
- 3: èå¼±æ§ãèæ ®ããã«ããã£ã¦ããã®çµç¹ã®æ¡ä»¶ã¨ãã¦èæ ®ãã¹ããã®ã§ãããç´ å çæ¡ä»¶(predisposing condition)ãã¨å¼ã°ããã
- 4: ãªã¹ã¯è©ä¾¡ã®å種ææ³ã«ã¤ãã¦ã¯ãä¾ãã°ISO/IEC 27005[6] Annex EãNIST SP 800-30Annex Dï½Jã«ã¾ã¨ãããã¦ãã¾ãã
以ä¸ã®ããªã¹ã¯åæãè©ä¾¡ãå«ãããªã¹ã¯è©ä¾¡ããã»ã¹ã¨ãã¦ã¾ã¨ãããããã®ãå³6ã«ç¤ºãã¾ãããã®ããã»ã¹ã¯ãå ¨é¨ã§4ã¤ã®ã¹ãããã§æ§æããã¦ãããåã¹ãããã¯ããã«ç´°ããã¿ã¹ã¯ã§æ§æããã¦ãã¾ããããã§ã¯ãåã ã®ã¿ã¹ã¯ã¾ã§ã¯è§¦ãã¾ããããåã¹ãããã®ä¸»ãªå 容ã以ä¸ã«ç¤ºãã¾ãã
ã¹ããã1ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®æºå
- ã¢ã»ã¹ã¡ã³ãã®ç®çãé©ç¨ç¯å²ãæ³å®ããã³å¶éäºé ãç¹å®ããã
- ã¢ã»ã¹ã¡ã³ãã¸ã®å ¥åãã¼ã¿ã¨ãã¦ä½¿ç¨ããæ å ±ã®æ å ±æºãããã³ã¢ã»ã¹ã¡ã³ãæã«ä½¿ç¨ãã¹ããªã¹ã¯ã¢ãã«ã¨åæã¢ããã¼ãï¼ããªãã¡ãã¢ã»ã¹ã¡ã³ãã¢ããã¼ãã¨åæã¢ããã¼ãï¼ãç¹å®ããã
ã¹ããã2ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®å®æ½
- çµç¹ã«é¢é£ããè å¨æºã¨çæããããè å¨äºè±¡ãç¹å®ããã
- ç¹å®ã®è å¨äºè±¡ã¨è å¨æºã«ãã£ã¦å©ç¨ããããçµç¹å ã®èå¼±æ§ãç¹å®ããæåãå·¦å³ããç´ å çæ¡ä»¶ãç¹å®ããã
- è å¨æºãç¹å®ã®è å¨äºè±¡ãéå§ããå¯è½æ§ã¨æåããå¯è½æ§ãç¹å®ããã
- èå¼±æ§ãè å¨æºã«ãã£ã¦å©ç¨ãããå ´åã®å½±é¿ãè©ä¾¡ããã
- æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ï¼ä¸ç¢ºå®æ§ãå«ãï¼ãç¹å®ããã
ã¹ããã3ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãçµæã®ä¼é
- ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãçµæãä¼éããããã®é©åãªæ¹æ³ãç¹å®ããã
- çµç¹ã®æå®ãããå©å®³é¢ä¿è ã«ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãçµæãä¼éããã
- çµç¹ããªã·ã¼ã¨æé ã«å¾ãããªã¹ã¯ã¢ã»ã¹ã¡ã³ãçµæã¨ãçµæãè£ä»ãã証æ ãå ±æããã
ã¹ããã4
- ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã«ããã¦ç¹å®ããããªã¹ã¯å åãç¶ç¶çã«ã¢ãã¿ãªã³ã°ããå¤æ´ãææ¡ããã
- ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã®ã³ã³ãã¼ãã³ãï¼è å¨ãèå¼±æ§ãè³ç£ä¾¡å¤çï¼ãæ´æ°ããã
å³6. ãªã¹ã¯è©ä¾¡ããã»ã¹
以ä¸ãããã¾ã§SP 800-161ãç解ããä¸ã§å¿ è¦ãªãä»ã®ä¸»ãªè¦æ ¼ãã¬ã¤ãã³ã¹ã¨ã®é¢é£ããã³ãã®å 容ãè¦ã¦ãã¾ããã次åã¯ãããã®ç¥èã«åºã¥ãã¦ããã®å 容ã®ç´¹ä»ãé²ãã¾ãã
åç §æç®
- [1] NIST, SP800 161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations, 2015.
- [2] NIST, SP 800-30 Rev.1 Guide for Conducting Risk Assessments, 2012.
- [3] NIST, SP 800-37 Rev.2 Risk Management Framework for Information Systems and Organizations, A System Life Cycle Approach for Security and Privacy, 2018.
- [4] NIST, SP 800-39 Managing Information Security Risk, Organization, Mission, and Information System View, 2011.
- [5] NIST, SP 800-53 Rev.4 Security and Privacy Controls for Federal Information Systems and Organizations.
- [6] ISO/IEC, 27005 Information technology — Security techniques — Information security risk management, 2018.
Writer Profile
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾ ãã§ãã¼
å·¥å¦å士ãCISSP, CISA
ä¸å®
å
Tweet