PCI DSSã§å¦ã¶AWSã»ãã¥ãªãã£â¡ ï½è¦ä»¶å¥ã®ã»ãã¥ãªãã£å¯¾çåç·¨ï½
ååï¼https://www.intellilink.co.jp/column/security/2021/070800.aspxï¼ã¯ãPCI DSS [1]ã®ã¹ã³ã¼ãã³ã°ã¨ã»ã°ã¡ã³ãã¼ã·ã§ã³ã¨ããæ¦å¿µãç¨ãã¦AWSãã©ãããã©ã¼ã ä¸ã§å®ãã¹ãæ
å ±ã¨æ±ãç¯å²ãç¹å®ãä»ã®ç°å¢ããåé¢ãã¦ä¿è·ããæ¹æ³ã«ã¤ãã¦ç´¹ä»ãã¾ããã
ä»åã¯ãAWSããå
¬éããã¦ããã¬ã¤ãã³ã¹ææ¸[2]ããã¨ã«PCI DSSã®åè¦ä»¶ã«æ²¿ã£ã¦AWSãã©ãããã©ã¼ã ä¸ã®ã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦èª¬æãã¦ããããã¨æãã¾ããPCI DSSã¯6ã¤ã®ç®æ¨ã¨12åã®è¦ä»¶ã§æ§æããã¦ãã¾ãããä»åã¯ååé¨åã®è¦ä»¶1ãã6ã«ã¤ãã¦ç´¹ä»ãã¾ãã
è¦ä»¶ï¼ï¼ã«ã¼ãä¼å¡ãã¼ã¿ãä¿è·ããããã«ããã¡ã¤ã¢ã¦ã©ã¼ã«ãã¤ã³ã¹ãã¼ã«ãã¦æ§æãç¶æãã
æ¬è¦ä»¶ã§ã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ãé©åã«æ§æããå®ãã¹ãæ å ±ãä¼éãå¦çãä¿åãããç°å¢ã¸ã®ã¤ã³ã¿ã¼ãããããã®ç´æ¥ã¢ã¯ã»ã¹ã®ç¦æ¢ããæ¥åä¸å¿ è¦ãªéä¿¡ã«å¶éãããã¨ãªã©ãæ±ãããã¾ããAWSãã©ãããã©ã¼ã ä¸ã§ã¯ãAWSããæä¾ããããã¯ããã¸ãç¨ãã¦å®ç¾ãããã¨ãå¯è½ã§ãã
- â ã»ãã¥ãªãã£ã°ã«ã¼ã
VPCå ã®ãªã½ã¼ã¹ã®ã¹ãã¼ããã«ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¨ãã¦æ©è½ããä»®æ³ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ã§åä¿¡ããã³éä¿¡ãããã©ãã£ãã¯ãå¶å¾¡ - â¡VPCã¨ã³ããã¤ã³ã
å©ç¨è èªèº«ã®VPCã§ãã©ã¤ãã¼ãIPã¢ãã¬ã¹ã使ç¨ãã¦ããµãã¼ãããã¦ããAWSãµã¼ãã¹ã«æ¥ç¶
ä¾ãã°ä»¥ä¸ã®å³ã§ã¯ãPublic subnetä¸ã®Web Serversãããã³Private subnetä¸ã®AP Serversã«ã»ãã¥ãªãã£ã°ã«ã¼ããé©ç¨ãã¦ãã¤ã³ã¿ã¼ãããããã®httpsããWeb Servers â AP Serverséã®httpsããªã©ã®å¿ è¦æå°éã®ãã©ãã£ãã¯ã«å¶éããã¨å ±ã«ãå®ãã¹ãæ å ±ãä¿åããã¦ããS3ã«å¯¾ãã¦ã¯ãããªãã¯ã¢ã¯ã»ã¹ãããã¯è¨å®ããã±ããããªã·ã¼è¨å®ãªã©ãç¨ãã¦ã¤ã³ã¿ã¼ãããããã®ç´æ¥ã¢ã¯ã»ã¹ãç¦æ¢ãã¦å©ç¨è ãããã¯ã¼ã¯ããVPCã¨ã³ããã¤ã³ãçµç±ã§ã®ãã©ã¤ãã¼ãæ¥ç¶ã®ã¿å¯è½ãªæ§æã¨ãã¦ãã¾ãã
è¦ä»¶2ï¼ã·ã¹ãã ãã¹ã¯ã¼ãããã³ãã®ä»ã®ã»ãã¥ãªãã£ãã©ã¡ã¼ã¿ã«ãã³ãã¼æä¾ã®ããã©ã«ãå¤ã使ç¨ããªã
æ¬è¦ä»¶ã§ã¯ãæ¥çã§èªç¥ããã¦ããã·ã¹ãã å¼·ååºæºãç¨ãã¦ã·ã¹ãã ãã»ãã¥ã¢ã«æ§æãããã¨ãæ±ãããã¾ããã·ã¹ãã å¼·ååºæºã«ã¯ãä¾ãã°ç±³å½ã®CISï¼Center for Internet Securityï¼ãçºè¡ããCIS Benchmarkã¨ãããã®ããããã·ã¹ãã ãå®å ¨ã«æ§ç¯ã»ç¶æããããã®ãã¹ããã©ã¯ãã£ã¹ãã¾ã¨ãããã¦ãã¾ãã以ä¸ã®åºæºãªã©ã«å¾ããAWSãã©ãããã©ã¼ã ä¸ã§èªèº«ãæ§ç¯ããã¤ã³ã¹ã¿ã³ã¹ã ãã§ãªããèªèº«ãå©ç¨ãã¦ããAWSã®ãµã¼ãã¹ãã»ãã¥ã¢ã«æ§æããå¿ è¦ãããã¾ãã
- âã¤ã³ã¹ã¿ã³ã¹ã®æ§æåºæºï¼CIS Benchmarks for EC2 instance types
- âAWSãµã¼ãã¹ã®æ§æåºæºï¼CIS Benchmark for AWS
- âã¤ã³ã¹ã¿ã³ã¹ã®è©ä¾¡ï¼Amazon Inspector
- âAWSãµã¼ãã¹ã®è©ä¾¡ï¼AWS Security Hub
ã¾ããAWSããæä¾ããã¦ãã以ä¸ã®ãµã¼ãã¹ãæ´»ç¨ãããã¨ã§CIS Benchmarkã«æ²¿ã£ã¦ã·ã¹ãã ãæ§æããã¦ããããæ¤è¨¼ãããã¨ãå¯è½ã§ãã
è¦ä»¶3ï¼ä¿åãããã«ã¼ãä¼å¡ãã¼ã¿ãä¿è·ãã
æ¬è¦ä»¶ã§ã¯ãå®ãã¹ãæ
å ±ã®ä¿åã¯å¿
è¦æå°éï¼ä¿åæéãå ´æãªã©ã®è¦³ç¹ï¼ã¨ããä¿åããå ´åã¯æå·åãªã©ã«ããä¿è·ãããã¨ãæ±ãããã¾ããã¾ãæå·åãç¨ãã¦ä¿è·ããå ´åãæå·åã«ä½¿ç¨ããéµèªä½ãã»ãã¥ã¢ã«ä¿åããã³ç®¡çãããã¨ãæ±ãããã¾ããAWSã§ã¯KMSã¨ããæå·éµç®¡çãµã¼ãã¹ãæä¾ããã¦ãããFIPS140-2ï¼æå·åã¢ã¸ã¥ã¼ã«ã®ã»ãã¥ãªãã£è¦ä»¶ãè¦å®ããç±³å½ããã³ã«ããæ¿åºã®è¦æ ¼ï¼æ¤è¨¼æ¸ã¿ã¾ãã¯æ¤è¨¼æ®µéã§ããã»ãã¥ã¢ãªãã¼ãã¦ã§ã¢ä¸ã«æå·éµãä¿åããã¾ãããã ããKMSã使ç¨ããããã°è¯ãããã§ã¯ããã¾ãããæå·éµã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ãéµç®¡çããªã·ã¼ã®å®è£
ã¯å©ç¨è
å´ã®è²¬ä»»ã§ãã
ä¾ãã°ãéµã®çæãªã©éµç®¡çä½æ¥ã¯æå·éµç®¡çè
ã®ã¿ãæå·åã復å·å¦çã¯ã¢ããªã±ã¼ã·ã§ã³ã®ã¿ã¨ããéçºè
ãªã©ä»ã®ã¢ã¯ã»ã¹ã¯æå¦ããããKMSã®ãã¼ããªã·ã¼è¨å®ãç¨ãã¦æ§æãããã¨ãå¯è½ã§ãã
è¦ä»¶4ï¼ãªã¼ãã³ãªå ¬å ±ãããã¯ã¼ã¯çµç±ã§ã«ã¼ãä¼å¡ãã¼ã¿ãä¼éããå ´åãæå·åãã
æ¬è¦ä»¶ã§ã¯ãã¤ã³ã¿ã¼ããããªã©ã®ãªã¼ãã³ãããã¯ã¼ã¯ãä»ãã¦æ
å ±ãä¼éããå ´åã«å¼·åãªæå·åæ¹å¼ãªã©ãç¨ãã¦ä¿è·ãããã¨ãæ±ãããã¾ãã
ä¾ãã°ä»¥ä¸ã®å³ã®Amazon Elastic Load Balancingãªã©å¤é¨ã«å
¬éããã¦ãããµã¼ãã¹ï¼â ï¼ã§ã¯ãåãµã¼ãã¹ã®è¨å®ãªãã·ã§ã³ã¨ãã¦ç¨æããã¦ããããªã·ã¼è¨å®ã®ãã¡tls1.2ãªã©ã»ãã¥ã¢ãªæ§æã®ã¿ã許å¯ããã¦ããããªã·ã¼ãé¸æããå¿
è¦ãããã¾ãã
ã¾ããã¤ã³ã¿ã¼ããããä»ãã¦ãããªãã¯AWSã¨ã³ããã¤ã³ãï¼â¡ï¼ã«æ¥ç¶ããå ´åãäºææ§ã®ããã«åæã®TLSè¨å®ããµãã¼ãããã¦ãããµã¼ãã¹ããããããå¼åºãå´ã®ã¯ã©ã¤ã¢ã³ãã¢ããªã±ã¼ã·ã§ã³ããtls1.2ãªã©ã»ãã¥ã¢ãªæ§æã®ã¿ã使ç¨ãã¦æ¥ç¶ããå¿
è¦ãããã¾ãã
ãªããD
irect Connectï¼â¢ï¼ã¯AWSã¸ã®å°ç¨ãããã¯ã¼ã¯æ¥ç¶ãµã¼ãã¹ã§ããããªã³ãã¬ãã¹ç°å¢ã¨AWSéã®éä¿¡ã¯ããã©ã«ãã§ã¯æå·åããã¦ããªããããDirect Connectãå©ç¨ããéã®èªç¤¾ãã¼ã¿ã»ã³ã¿ã¼ããã®æ¥ç¶çµè·¯ã«ãªã¼ãã³ãããã¯ã¼ã¯ãç¡ãããªã©æ¤è¨¼ãã追å å¶å¾¡ã®å¿
è¦æ§ãå¤æãããã¨ãå©ç¨è
ã«æ±ãããã¦ãã¾ãã
è¦ä»¶5ï¼ãã«ã¦ã§ã¢ã«å¯¾ãã¦ãã¹ã¦ã®ã·ã¹ãã ãä¿è·ããã¦ã¤ã«ã¹å¯¾çã½ããã¦ã§ã¢ãå®æçã«æ´æ°ãã
æ¬è¦ä»¶ã§ã¯ããã«ã¦ã§ã¢ã®å½±é¿ãåãããããã¹ã¦ã®ã·ã¹ãã ã«å¯¾ããã¦ã¤ã«ã¹å¯¾çã½ããã¦ã§ã¢ã®å°å ¥ããã³é©åãªç®¡çãæ±ãããã¾ããAmazon RDSãªã©ã®AWSããã¼ã¸ãã®ãµã¼ãã¹ã¯AWSå´ã«å¯¾çãæ ã責任ãããã¾ãããEC2ã¤ã³ã¹ã¿ã³ã¹ã使ç¨ãã¦ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ãèªåéã§æ§ç¯ãã¦ãããããªå ´åã¯ãå©ç¨è èªèº«ã§é©åãªã¦ã¤ã«ã¹å¯¾çã½ããã¦ã§ã¢ã®é¸å®ãå°å ¥ããã³ç®¡çãå¿ è¦ã§ãã
è¦ä»¶6ï¼å®å ¨æ§ã®é«ãã·ã¹ãã ã¨ã¢ããªã±ã¼ã·ã§ã³ãéçºããä¿å®ãã
æ¬è¦ä»¶ã§ã¯ãã»ãã¥ãªãã£èå¼±æ§ã®ç¹å®ã»ã©ã³ã¯å²å½ã¦ã»ãããé©ç¨ãã»ãã¥ã¢ãªéçºã»ãã¹ãã»å¤æ´ç®¡çãWebã¢ããªã±ã¼ã·ã§ã³ã®ä¿è·ãªã©ãã·ã¹ãã éçºãä¿å®ãè¡ãä¸ã§ã®æ§ã ãªå¯¾çãæ±ãããã¾ããAWSã§ã¯å対çãæ¯æ´ããæ§ã ãªãµã¼ãã¹ãæä¾ããã¦ãã¾ããããããã®ãµã¼ãã¹ããããã¯åå¥å°å ¥ãã製åãæ´»ç¨ããã»ãã¥ã¢ãªããã»ã¹ãæ§ç¯ãéç¨ãã¦ããã®ã¯å©ç¨è ã®è²¬ä»»ã§ãã
ãAWSããæä¾ããããµã¼ãã¹ã®ä¾ã
- âã»ãã¥ãªãã£èå¼±æ§ã®ç¹å®ã»ã©ã³ã¯å²å½ã¦ã»ãããé©ç¨
使ç¨ãã¦ããã½ããã¦ã§ã¢ã®èå¼±æ§ãèå¥ããã³ã©ã³ã¯åãããä¸ã§ãé©åãªæéå ã«ããããé©ç¨ãã¦èå¼±æ§ã«å¯¾å¦ããããã»ã¹ã®ç¢ºç«ãå¿ è¦ã§ããã¤ã³ã¹ã¿ã³ã¹ã®ã»ãã¥ãªãã£è©ä¾¡ãµã¼ãã¹ã§ããAmazon Inspectorã使ç¨ãããã¨ã§ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ãªã©ç¹å®ã®èå¼±æ§ã®èå¥ãå¯è½ã§ããã¾ãAWS Systems Manager Patch Managerãæ´»ç¨ãããã¨ã§ãããé©ç¨ã®èªååããã»ã¹ã®ç¢ºç«ãå¯è½ã§ãã - âã»ãã¥ã¢ãªéçºã»ãã¹ãã»å¤æ´ç®¡ç
OWASP Top10ï¼The Open Web Application Security Projectãçºè¡ããWebã¢ããªã±ã¼ã·ã§ã³ã«ãããé大è å¨ã«é¢ããã¬ã¤ãã³ã¹ï¼ãªã©æ¥çã®ãã¹ããã©ã¯ãã£ã¹ã«ãã¨ã¥ãã¦ã»ãã¥ã¢ã«ã½ããã¦ã§ã¢ã®éçºããã³ãã¹ããå®æ½ãæ¬çªç°å¢ã«ãªãªã¼ã¹ããããã»ã¹ã®ç¢ºç«ãå¿ è¦ã§ããAWS Code Pipelineãªã©ãªãªã¼ã¹ããã»ã¹ã®ã¢ãã«åããã³èªååãå¯è½ãªãµã¼ãã¹ãæ´»ç¨ããAmazon Inspectorã«ããã»ãã¥ãªãã£è©ä¾¡ä½æ¥ãªã©ã®ãã§ãã¯å·¥ç¨ããªãªã¼ã¹ããã»ã¹ã«çµã¿è¾¼ããã¨ãå¯è½ã§ãã - âWebã¢ããªã±ã¼ã·ã§ã³ä¿è·
Webãã¼ã¹ã®æ»æã«ç¶ç¶çã«å¯¾å¦ãããããWebã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼WAFï¼ã®å°å ¥ãªã©ã«ããæ¢ç¥ã®æ»æããä¿è·ãããã¨ãæ±ãããã¾ããAWSãã©ãããã©ã¼ã ã§ã¯AWS WAFã¨ããWAFãµã¼ãã¹ãç¨æããã¦ãã¾ããOWASP Top10ãªã©ã«æãããã¦ããé大ãªèå¼±æ§ãæ¤ç¥ãããã¨ãå¯è½ãªããã¼ã¸ãã«ã¼ã«ã®é¸æãå¿ è¦ã§ãã
ã¾ã¨ã
ä»åã¯PCI DSSè¦ä»¶1ãã6ããã¨ã«AWSãã©ãããã©ã¼ã ä¸ã§æ±ããããã»ãã¥ãªãã£å¯¾çã®æ¦è¦ãç´¹ä»ãããã¾ããã次åã¯æ®ãã®è¦ä»¶7ãã12ããã¨ã«èª¬æãããã¨æãã¾ãã
åèãªã½ã¼ã¹
-
[1]
Payment Card Industry (PCI) Data Security Standard Version 3.2.1
https://www.pcisecuritystandards.org/document_library -
[2]
AWSã«ãããPCI DSS (Payment Card Industry Data Security Standard) 3.2.1ã³ã³ãã©ã¤ã¢ã³ã¹ã¬ã¤ã
https://d1.awsstatic.com/whitepapers/ja_JP/compliance/pci-dss-compliance-on-aws.pdf
ãåãåãã
AWSãªã©ã®ãããªãã¯ã¯ã©ã¦ãç°å¢ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ã¾ãã¯ç¾ç¶ææ¡ãéè¦ã§ããPCI DSSãªã©ã®ã»ãã¥ãªãã£åºæºã«åºã¥ããã¢ã»ã¹ã¡ã³ããµã¼ãã¹ãå種ã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãªã©ã§ã®ãæ¯æ´ãå¯è½ã§ãããæ°è»½ã«ãåãåãããã ããã
ã¾ããæ¬ã³ã©ã ã§ã¯AWSã®ã¬ã¤ãã³ã¹ããã¨ã«å種AWSãµã¼ãã¹ãæ´»ç¨ãã¦ã®ã»ãã¥ãªãã£å¯¾çãä¸å¿ã«èª¬æãã¾ãããããã«ãã¯ã©ã¦ãããã¤ããªããã¯ã©ã¦ãã§ã®å¯¾å¿ã24h365dã§ã®ç£è¦ãããå³æ ¼ãªæ
å ±ä¿è·ãæ±ãããã¦ããå ´åãªã©AWSãµã¼ãã¹ã ãã§ã¯ã«ãã¼ã§ããªãç¹ã«ã¤ãã¦å¼ç¤¾ã½ãªã¥ã¼ã·ã§ã³ã«ããå®ç¾å¯è½ãªç¯å²ããããã¾ãããæ°è»½ã«ãåãåãããã ããã
https://www.intellilink.co.jp/contact-us.aspx
â»Amazon Web ServicesããPowered by Amazon Web Servicesããã´ãããã³ãããè³æã§ä½¿ç¨ããããã®ä»ã®AWSåæ¨ã¯ãç±³å½ããã³/ã¾ãã¯ãã®ä»ã®è«¸å½ã«ããããAmazon.com, Inc.ã¾ãã¯ãã®é¢é£ä¼ç¤¾ã®åæ¨ã§ãã