PCI DSSã§å¦ã¶AWSã»ãã¥ãªãã£â ï½ã¹ã³ã¼ãã³ã°ã¨ã»ã°ã¡ã³ãã¼ã·ã§ã³ï½
çããã¯ãããªãã¯ã¯ã©ã¦ãç°å¢ã§ã·ã¹ãã æ§ç¯ããéã®ã»ãã¥ãªãã£è¦ä»¶ã¨ãã¦ä½ãæ ãæã«ãã¦ãã¾ããï¼ ãã¾ãã¾ãªã»ãã¥ãªãã£åºæºãã¬ã¤ããåå¨ãããããæ©ã¾ãã¦ããæ¹ãå¤ãã®ã§ã¯ãªãã§ããããã
ããã§æ¬ã³ã©ã ã§ã¯ããã®è§£æ±ºçã®1ã¤ã¨ãã¦PCI DSS[1]ã¨ããåºæºããã¼ã¹ã«ä¸»è¦ãªãããªãã¯ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®1ã¤ã§ããAmazon Web Servicesï¼AWSï¼ä¸ã§ã»ãã¥ã¢ã«ã·ã¹ãã ãæ§æããéã®çæç¹ã«ã¤ãã¦ãAWSããå
¬éããã¦ããã¬ã¤ãã³ã¹ææ¸[2]ããã¨ã«ç´¹ä»ãã¾ãã
PCI DSSã¯ã¯ã¬ã¸ããã«ã¼ãæ¥çã®ã»ãã¥ãªãã£åºæºã§ãããã«ã¼ãæ
å ±ãä¿è·ããããã®å¯¾çãå
·ä½çãã¤ä½ç³»çã«ã¾ã¨ãããã¦ãã¾ããã¯ã¬ã¸ããã«ã¼ãæ¥çåãã®åºæºã§ã¯ããã¾ãããèªåéãå®ãããæ
å ±ã«ç½®ãæãã¦ã¿ã¦ããã ããã°ãã«ã¼ãæ
å ±ãåæ±ãã·ã¹ãã ã«éãããã¾ãã¾ãªã·ã¹ãã ã§æå¹æ´»ç¨ã§ããã®ã§ã¯ãªããã¨æãã¾ãã
第1åç®ã®ãã¼ãã¯ã¹ã³ã¼ãã³ã°ããã³ã»ã°ã¡ã³ãã¼ã·ã§ã³ã¨ããæ¦å¿µã§ãã
è²¬ä»»å ±æã¢ãã«
å
·ä½çãªèª¬æã«å
¥ãåã«ããããªãã¯ã¯ã©ã¦ãã«ãããéè¦ãªæ¦å¿µã§ãã責任å
±æã¢ãã«ãç´¹ä»ãã¾ãããããªãã¯ã¯ã©ã¦ãç°å¢ã§ã¯ãå©ç¨è
ã¨ã¯ã©ã¦ããµã¼ãã¹ãããã¤ãã®éã§ãã»ãã¥ãªãã£ãã³ã³ãã©ã¤ã¢ã³ã¹ã®è²¬ä»»ãå
±æããã¾ãã
ä¾ãã°ãAWSã§ã¯ä»®æ³ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¨ãã¦SecurityGroupã¨ããæ©è½ãç¨æããã¾ãããSecurityGroupãç¨ãã¦ã¤ã³ãã¦ã³ãã¨ã¢ã¦ããã¦ã³ããã©ãã£ãã¯ãæ¥åä¸å¿
è¦æå°éã«å¶éãã責任ã¯å©ç¨è
å´ã«ããã¾ãããã®ããã«ãããªãã¯ã¯ã©ã¦ãç°å¢ã«ããã¦èªåéã責任ããã£ã¦å®è£
ããªããã°ãªããªãç¯å²ãææ¡ããããã«ã責任å
±æã¢ãã«ã¯éè¦ãªæ¦å¿µã§ãããã詳ããç¥ãããæ¹ã¯ãã¡ãã®ã³ã©ã ï¼https://www.intellilink.co.jp/column/pcidss/2018/061800.aspxï¼ãåç
§ãã ããã
åèï¼è²¬ä»»å ±æã¢ãã«ï¼https://aws.amazon.com/jp/compliance/shared-responsibility-model/ï¼ãå ã«ä½æ
ã¹ã³ã¼ãã³ã°
PCI DSSã§ã¯ãã«ã¼ãæ å ±ã®æµããèå¥ããPCI DSSãé©ç¨ãããç¯å²ãç¹å®ãããã¨ãã¹ã³ã¼ãã³ã°ã¨å¼ã³ã¾ããå ·ä½çã«ã¯ã以ä¸ã®èãæ¹ã§é©ç¨ç¯å²ã¨ãªãç°å¢ãæ´çãã¾ãã
- ã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ï¼CDEï¼
PANï¼ã«ã¼ãä¼å¡çªå·ï¼ãªã©PCI DSSã§å®ç¾©ãããã«ã¼ãæ å ±ãä¼éãå¦çãä¿åãããã·ã¹ãã ãããã³åä¸ã»ã°ã¡ã³ãç°å¢
- æ¥ç¶å
ã·ã¹ãã ãã»ãã¥ãªãã£ã«å½±é¿ãä¸ããã·ã¹ãã
CDEã«å¯¾ãã¦ç´æ¥ã¾ãã¯éæ¥çã«æ¥ç¶ãã¦ããã·ã¹ãã ãã¾ãã¯ç®¡çãµã¼ãã¹ãã»ãã¥ãªãã£ãµã¼ãã¹ãæä¾ããã·ã¹ãã
- é©ç¨ç¯å²å¤ã®ã·ã¹ãã
CDEã®ã»ãã¥ãªãã£ã¾ãã¯è¨å®ã«å½±é¿ãä¸ãããé©ç¨ç¯å²ã«å«ã¾ããªã
ã«ã¼ãæ
å ±ãä¼éãå¦çãä¿åãããé åãã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ã¨å¼ã³ã¾ãããã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ã«å¯¾ãã¦é©ç¨ç¯å²å¤ã®ã·ã¹ãã ããç´æ¥ã¾ãã¯éæ¥çã«ãã¢ã¯ã»ã¹ã§ããªãããã«ãããã¨ããPCI DSSã§ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³â»ã¨å¼ã³ã¾ããã»ã°ã¡ã³ãã¼ã·ã§ã³ã«ããããããã¯ã¼ã¯ãé©åã«ã»ã°ã¡ã³ãåãããã¨ã§ãã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ã®ç¯å²ãçããçµæã¨ã㦠PCI DSS ãé©ç¨ãããç¯å²ã縮å°ãããã¨ãã§ãã¾ããããã¯å®ãã¹ãéè¦ãªæ
å ±ãéãããç°å¢ã«éç´ã»çµ±åãããã®ç°å¢ã«å¯¾ããã»ãã¥ãªãã£ã³ã³ããã¼ã«ãå¼·åãããªã©çµç¹ã®ãªã¹ã¯ä½æ¸ã«ãã¤ãªããã¾ãã
â»PCI DSSã§ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³ã®æ段ã¨ãã¦ãé©åã«æ§æããããã¡ã¤ã¢ã¦ã©ã¼ã«ãç¹å®ã®ãããã¯ã¼ã¯ã»ã°ã¡ã³ãã¸ã®ã¢ã¯ã»ã¹ãå¶éããå¼·åãªã¢ã¯ã»ã¹å¶å¾¡ãªã¹ãã¾ãã¯ä»ã®ãã¯ããã¸ã¼ããã¤ã«ã¼ã¿ã¼ãªã©ãããã¤ãã®ç©ççã¾ãã¯è«ççãªæ段ãéãã¦å®ç¾å¯è½ã¨ä¾ç¤ºããã¦ãã¾ãã
AWSã®ã»ã°ã¡ã³ãã¼ã·ã§ã³è¨è¨
ããã§ã¯ãAWSã§ã¯ã©ã®ããã«ã»ã°ã¡ã³ãã¼ã·ã§ã³ãå®ç¾ãããã¨ãã§ããã®ã§ãããããããã§ã¯ä¸»è¦ãª3ã¤ã®æ段ãç´¹ä»ãããã¨æãã¾ãã
1. AWSã¢ã«ã¦ã³ã
AWSã¢ã«ã¦ã³ãã¯ãªã½ã¼ã¹ã課é管çã®åä½ãç°å¢åé¢ã®ããã«ä½¿ç¨ããã¾ãã
AWSã¢ã«ã¦ã³ããåå²ãããã¨ã§ãä»ã®AWSã¢ã«ã¦ã³ãã®ãªã½ã¼ã¹ããè«ççã«åé¢ããããããæ示çã«éä¿¡ãã£ãã«ã確ç«ããªãéããå®ãã¹ãé åã§ããã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ãé©ç¨ç¯å²å¤ã®ç°å¢ããã»ã°ã¡ã³ãã¼ã·ã§ã³ãããã¨ãã§ãã¾ãã
åè¿°ã®PCI DSSã®ã¹ã³ã¼ãã³ã°ã®èãæ¹ã«ç
§ããã¦æ§æããã¨ãä¾ãã°ä»¥ä¸ã®ãããªAWSã¢ã«ã¦ã³ãã®æ§æãèãããã¾ãã
2. VPC/SecurityGroup
ã»ãã¥ãªãã£ã°ã«ã¼ãã¯ããã¹ããã¼ã¹ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ã«ç¸å½ããAmazon Virtual Private Cloudï¼VPCï¼ã®æ©è½ã§ããå¿
è¦ãªãã¼ããéä¿¡å
ããã³å®å
ã¢ãã¬ã¹ã«åºã¥ãã¦ãããã¯ã¼ã¯éä¿¡ãå¶éãããã¨ã§ã»ã°ã¡ã³ãã¼ã·ã§ã³å¢çã確ç«ãã¾ãã
ä¾ãã°ä»¥ä¸ã®å³ã§ã¯ãSecurity Group Aããã³Bãã«ã¼ãä¼å¡ãã¼ã¿ç°å¢ãSecurity Group Cãæ¥ç¶å
ã·ã¹ãã ãSecurity Group Dã対象å¤ã·ã¹ãã ã§ããã¨ããå ´åãSecurity Group Aããã³Bã«å¯¾ãã¦Cããã®å¿
è¦æå°éã®æ¥ç¶ã®ã¿ã許å¯ããã«ã¼ã«è¨å®ãè¡ããã¨ã§ãDããã®ç´æ¥æ¥ç¶ãä¸åæå¦ãããã¨ãå¯è½ã§ãã
3. æ½è±¡åãããAWSãµã¼ãã¹
æ½è±¡åããããµã¼ãã¹ã¨ã¯ãAmazon Simple Storage Service (Amazon S3) ãªã©ã®ããã¼ã¸ããµã¼ãã¹ã該å½ãã¾ããé¸æãããµã¼ãã¹ãã¨ã«å©ç¨è
å´ã®è²¬ä»»ã¨ãªãç¯å²ã¯ç°ãªãã¾ãããé常ã¯ãã«ããã¼ã¸ãã®ãµã¼ãã¹ã§ãã£ã¦ããã¼ã¿ä¿è·ãã¢ã¯ã»ã¹æ¨©è¨å®ãªã©ã®å¯¾çã¯å©ç¨è
å´ã責任ãè² ãã¾ãããã®ããããããã¤ãã¼ããæä¾ãããã»ãã¥ãªãã£ã³ã³ããã¼ã«ãç¨ãã¦ã¢ã¯ã»ã¹å¶å¾¡ãå®æ½ããå®ãã¹ãæ
å ±ãç½®ãããé åã«ã¤ãã¦é©ç¨ç¯å²å¤ã·ã¹ãã ããã¢ã¯ã»ã¹ãããªãããå¶éããå¿
è¦ãããã¾ãã
ä¾ãã°ã以ä¸ã®å³ã§ã¯S3ã®bucket Policyãä½æãã¦å®ãã¹ãæ
å ±ãä¿ç®¡ãããbucketã«å¯¾ãã¦VPC A以å¤ã®ã¢ã¯ã»ã¹ãæå¦ããè¨å®ãè¡ããã¨ã§ãä»ã®é©ç¨ç¯å²å¤ã·ã¹ãã ãªã©ããã®ã¢ã¯ã»ã¹ãå¶éãã¾ãã
ã¾ã¨ã
ä»åã¯ãPCI DSSã®ã¹ã³ã¼ãã³ã°ããã³ã»ã°ã¡ã³ãã¼ã·ã§ã³ã¨ããæ¦å¿µãç´¹ä»ãã¾ããã
ã¾ãã¯AWSãã©ãããã©ã¼ã ä¸ã§ãéè¦ãªæ
å ±ãä¼éãå¦çãä¿åãããç°å¢ããã®ç°å¢ã«æ¥ç¶ãã¦ããã·ã¹ãã ã管çãµã¼ãã¹ãã»ãã¥ãªãã£ãµã¼ãã¹ãæä¾ããã·ã¹ãã ãæ´ãåºããèªåéãå®ãã¹ãç¯å²ãç¹å®ãããã¨ãéè¦ã§ãã
ãã®ä¸ã§ãä»åç´¹ä»ããAWSã¢ã«ã¦ã³ãã®åå²ãVPC/Security Groupã«ãããããã¯ã¼ã¯ã¢ã¯ã»ã¹å¶å¾¡ãæ½è±¡åãããAWSãµã¼ãã¹æ¯ã®ã¢ã¯ã»ã¹å¶å¾¡ãªã©ã®æ段ã«ããã»ã°ã¡ã³ãã¼ã·ã§ã³å¢çãè¨ãã¦èªåéãå®ãã¹ãç¯å²ãä»ã®ç°å¢ããåé¢ããéè¦ãªæ
å ±ã®ä¾µå®³ãªã¹ã¯ãä½æ¸ãã¾ãããã
åèãªã½ã¼ã¹
-
[1]
Payment Card Industry (PCI) Data Security Standard Version 3.2.1
https://www.pcisecuritystandards.org/document_library -
[2]
PCI DSSã¹ã³ã¼ãã³ã°ããã³AWSä¸ã§ã®ã»ã°ã¡ã³ãã¼ã·ã§ã³ã®ããã®ã¢ã¼ããã¯ãã£ã®è¨è¨
https://d1.awsstatic.com/whitepapers/ja_JP/pci-dss-scoping-on-aws.pdf
AWSã«ãããPCI DSS (Payment Card Industry Data Security Standard) 3.2.1ã³ã³ãã©ã¤ã¢ã³ã¹ã¬ã¤ã
https://d1.awsstatic.com/whitepapers/ja_JP/compliance/pci-dss-compliance-on-aws.pdf
ãåãåãã
AWSãªã©ã®ãããªãã¯ã¯ã©ã¦ãç°å¢ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ã¾ãã¯ç¾ç¶ææ¡ãéè¦ã§ããPCI DSSãªã©ã®ã»ãã¥ãªãã£åºæºã«åºã¥ããã¢ã»ã¹ã¡ã³ããµã¼ãã¹ãå種ã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãªã©ã§ã®ãæ¯æ´ãå¯è½ã§ãããæ°è»½ã«ãåãåãããã ããã
https://www.intellilink.co.jp/contact-us.aspx
â»Amazon Web ServicesããPowered by Amazon Web Servicesããã´ãããã³ãããè³æã§ä½¿ç¨ããããã®ä»ã®AWSåæ¨ã¯ãç±³å½ããã³/ã¾ãã¯ãã®ä»ã®è«¸å½ã«ããããAmazon.com, Inc.ã¾ãã¯ãã®é¢é£ä¼ç¤¾ã®åæ¨ã§ãã