PCI DSSã§å¦ã¶AWSã»ãã¥ãªãã£â¢ ï½è¦ä»¶å¥ã®ã»ãã¥ãªãã£å¯¾çå¾ç·¨ï½
ååï¼https://www.intellilink.co.jp/column/security/2021/091000.aspxï¼ã¯ãPCI DSS [1]ã®ãã¡ååé¨åã®è¦ä»¶1ãã6ã«æ²¿ã£ã¦AWSãã©ãããã©ã¼ã ä¸ã®ã»ãã¥ãªãã£å¯¾çãAWSããå ¬éããã¦ããã¬ã¤ãã³ã¹ææ¸ [2]ããã¨ã«èª¬æãã¾ãããä»åã¯ãå¾åã®è¦ä»¶7ãã12ã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãã
è¦ä»¶7ï¼ã«ã¼ãä¼å¡ãã¼ã¿ã¸ã®ã¢ã¯ã»ã¹ããæ¥åä¸å¿ è¦ãªç¯å²å ã«å¶éãã
æ¬è¦ä»¶ã§ã¯ãè·ç¨®ã¨è·åã«åºã¥ããæ¥åã«å¿
è¦ãªæå°éã®ã¢ã¯ã»ã¹æ¨©ã®å²å½ã¦ãæ±ãããã¾ããAWSãã©ãããã©ã¼ã ä¸ã§ã¯AWS Identity and Access Management (IAM)ã«ããAWSã®ãµã¼ãã¹ããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã管çããã¾ããIAMã§ã¯ãã¦ã¼ã¶ã¼/ã¦ã¼ã¶ã¼ã°ã«ã¼ã/ãã¼ã«ã«å¯¾ãã¦ããªã·ã¼ãä½æãã¦é©ç¨ãã¾ããããªã·ã¼ã¯è¨±å¯ã¾ãã¯æå¦ãããã¢ã¯ã·ã§ã³ããªã½ã¼ã¹ãæ¡ä»¶ãå®ç¾©ããJSONå½¢å¼ã®ããã¥ã¡ã³ãã§ãã
以ä¸ã®ä¾ã§ã¯ãAdministratorã¨ããã¦ã¼ã¶ã¼ã«ç®¡çè
ç¹æ¨©ããNWAdminGroupsã¨ããã¦ã¼ã¶ã¼ã°ã«ã¼ãã«ãããã¯ã¼ã¯ãªã½ã¼ã¹ã®ä½æãç¶æ権éããLogsAccessRoleã¨ãããã¼ã«ã«CloudWatchLogsã«ã¢ã¯ã»ã¹ããããã®æ¨©éãä»ä¸ãã¦ãã¾ãããªããã¼ã«ã¨ã¯ãä»»æã®ã¦ã¼ã¶ã¼ãã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ã«å¯¾ãã¦ä¸æçãªèªè¨¼æ
å ±ãæä¾ããã¢ã¯ã»ã¹æ¨©ãå§ä»»ããããã«ä½¿ç¨ããã¾ããä¾ãã°ãèªèº«ãæ§ç¯ããEC2ã¤ã³ã¹ã¿ã³ã¹ã«LogsAccessRoleãå²ãå½ã¦ããã¨ã§ãã¤ã³ã¹ã¿ã³ã¹ä¸ã®OSãã°ãªã©ãCloudWatchLogsã«è»¢éã§ããããã«ãªãã¾ãã
è¦ä»¶8ï¼ã·ã¹ãã ã³ã³ãã¼ãã³ãã¸ã®ã¢ã¯ã»ã¹ãèå¥ã»èªè¨¼ãã
æ¬è¦ä»¶ã§ã¯ãã¢ã«ã¦ã³ãããã³èªè¨¼æ å ±ã®é©åãªè¨å®ã¨ç®¡çãæ±ãããã¾ããå ·ä½çã«ã¯ãå人èå¥å¯è½ãªã¢ã«ã¦ã³ãæåºãããã¹ã¯ã¼ãã®è¤éæ§ãæåæ°å¶éãªã©ã®èªè¨¼ããªã·ã¼ã®æ§æãå¤è¦ç´ èªè¨¼ï¼MFAï¼ã®å®è£ ãªã©ãå¿ è¦ã¨ãªãã¾ãããAWSãæä¾ããããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ããAWSãã©ãããã©ã¼ã ã¸ã®ã¢ã¯ã»ã¹ããEC2ã¤ã³ã¹ã¿ã³ã¹ã使ç¨ãã¦èªåéã§æ§ç¯ãããªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã¸ã®ã¢ã¯ã»ã¹ãªã©ã®ã¢ã«ã¦ã³ã管çãèªè¨¼ããªã·ã¼ã®æ§æã¯å©ç¨è å´ã®è²¬ä»»ã§ãã
- â AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«çã«ãããã©ãããã©ã¼ã ã¸ã®ã¢ã¯ã»ã¹
è¤éæ§ï¼æåé·ï¼å®æå¤æ´ï¼åå©ç¨é²æ¢ãªã©ã®ãã¹ã¯ã¼ãããªã·ã¼ãå¤è¦ç´ èªè¨¼ãæ§æå¯è½ã§ããä¸æ¹ããã°ã¤ã³å¤±ææã®ã¢ã«ã¦ã³ãããã¯ãªã©ä¸é¨è¦ä»¶ãç´æ¥æºãããã¨ãã§ããªãããã代æ¿çï¼AWS CloudTrailãLambdaã®çµåãã«ãããã°ã¤ã³å¤±ææ¤ç¥ã»å¶éæ©æ§ã®å®è£ ï¼ã®æ¤è¨ããªããã¯AWS Managed Microsoft Active Directoryï¼AWS Directory Serviceï¼ãªã©ã®å¥ã®èªè¨¼æ©æ§ã®å©ç¨ãå¿ è¦ã§ãã - â¡EC2ã¤ã³ã¹ã¿ã³ã¹ã¸ã®ã¢ã¯ã»ã¹
ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ï¼LinuxãWindowsãªã©ï¼ã¸ã®ã¢ã¯ã»ã¹ã«ãã¹ã¯ã¼ã使ç¨ã¯æ¨å¥¨ããããããã©ã«ãã§Amazon EC2ãã¼ãã¢ã使ç¨ããã¾ããã¾ãå¯è½ãªéããAWS System Manager Sessions Managerã使ç¨ãã¦sshãRDPã®ã¤ã³ã¿ãã§ã¼ã¹ã¯æå°åã¾ãã¯ç¡ããã¦ãããã¨ãæ¨å¥¨ããã¾ãã - â¢AWSãµã¼ãã¹ããã¼ã¿ãã¼ã¹çã¸ã®ããã°ã©ã ã«ããã¢ã¯ã»ã¹
AWSãµã¼ãã¹ã¸ã®APIå¼åºããªã©ã®ããã°ã©ã ã«ããã¢ã¯ã»ã¹ã¯ã¢ã¯ã»ã¹ãã¼ï¼ã¢ã¯ã»ã¹ãã¼ IDããã³ã·ã¼ã¯ã¬ããã¢ã¯ã»ã¹ãã¼ã§æ§æãããèªè¨¼æ å ±ï¼ã§ã¯ãªããã¼ã«ï¼ä¸æçãªèªè¨¼æ å ±ï¼ã®ä½¿ç¨ãæ¨å¥¨ããã¾ããã¾ãããã¼ã¿ãã¼ã¹ãªã©ã¸ã®æ¥ç¶èªè¨¼æ å ±ã¯ã¢ããªã±ã¼ã·ã§ã³ã«ç´æ¥åãè¾¼ã¾ãAWS Secrets Managerãªã©ã«ãã£ã¦ã»ãã¥ã¢ã«ä¿åãããã¨ãéè¦ã§ãã
è¦ä»¶9ï¼ã«ã¼ãä¼å¡ãã¼ã¿ã¸ã®ç©çã¢ã¯ã»ã¹ãå¶éãã
æ¬è¦ä»¶ã§ã¯ç©ççãªã»ãã¥ãªãã£å¯¾çãè¦æ±ããã¾ãããAWSãã©ãããã©ã¼ã ã®ç©çã»ãã¥ãªãã£ãã¡ãã£ã¢ç®¡çã¯AWSã責任ãæ ãã¾ãã
ãAWSãå ¬è¡¨ãã¦ããç©çã»ãã¥ãªãã£ã®ä¾ã
- âç£è¦ã«ã¡ã©ãä¾µå ¥æ¤ç¥ã·ã¹ãã
- â24h365d ã®ç£è¦ä½å¶
- âå°éã»ãã¥ãªãã£ã¹ã¿ããã身å証ææ¸ã®æ示
- âèªå®ã¹ã¿ããã®ããã¢ã¢ã¯ã»ã¹ã¯æä½2åã®å¤è¦ç´ èªè¨¼ãè¦æ±
ãã ããAWSã«æ¥ç¶ãããå©ç¨è ã®ãªã³ãã¬ãã¹ç°å¢ã®ç©çã»ãã¥ãªãã£ãã¡ãã£ã¢ç®¡çã¯å©ç¨è 責任ã¨ãªãããã注æãå¿ è¦ã§ãã
è¦ä»¶10ï¼ãããã¯ã¼ã¯ãªã½ã¼ã¹ããã³ã«ã¼ãä¼å¡ãã¼ã¿ã¸ã®ãã¹ã¦ã®ã¢ã¯ã»ã¹ã追跡ããã³ç£è¦ãã
æ¬è¦ä»¶ã§ã¯ãAWSãµã¼ãã¹ãã¤ã³ã¹ã¿ã³ã¹å ã®å種ã½ããã¦ã§ã¢ãªã©ã®ãã°ã®æå¹åãè¦ä»¶ã«æ²¿ã£ãé©åãªä¿åããã³ç£è¦ãæ±ãããã¾ãã
ãAWSãµã¼ãã¹ã®ãã°è¨å®ã®ä¾ã
- âAWS CloudTrailï¼AWSãµã¼ãã¹ã使ç¨ãã¦è¡ãããã¢ã¯ã·ã§ã³ã®ãã°
- âRDS ç£æ»ãã°ï¼éè¦ãªæ å ±ãç½®ããããã¼ã¿ãã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãã°
- âS3ãµã¼ãã¢ã¯ã»ã¹ãã°ï¼S3ã¹ãã¬ã¼ã¸ä¸ã®ç£æ»ãã°ãã¡ã¤ã«çã¸ã®ã¢ã¯ã»ã¹ãã°
- âAmazon VPCããã¼ãã°ï¼ãããã¯ã¼ã¯ãã©ãã£ãã¯ã®ãã°
- âEC2ã¤ã³ã¹ã¿ã³ã¹ä¸ã®å種ãã°ï¼CloudWatch ã¨ã¼ã¸ã§ã³ããªã©ãä»ãã¦åéããã·ã¹ãã ãã°ãã¢ããªã±ã¼ã·ã§ã³ãã°
ãã°ã¯ã»ãã¥ãªãã£ã¤ã³ã·ãã³ããçºçããéã«ãã°ã®æ¯è¼ãæç³»åã«æ²¿ã£ã¦è¿½è·¡ã§ããããAmazon Time Sync Serviceãªã©ãå©ç¨ãã¦æ£ç¢ºãªæå»æ å ±ã¨ã®åæãå¿ è¦ã§ããã¾ããS3ãªã©ã«éç´ä¿åãã¦IAMããªã·ã¼ã«ããã¢ã¯ã»ã¹å¶éãæå·åãå¤æ´ç£è¦ãè¡ãä¸æ£ãªæ¹ãããåé¤ããä¿è·ãããã¨ãéè¦ã§ããå ãã¦ãä¸å¯©ãªå åãªã©ãæ¤ç¥ãã¦ã»ãã¥ãªãã£ã¤ã³ã·ãã³ããæªç¶ã«é²ããããCloudWatch Eventsã¨AWS Lambdaãªã©ãæ´»ç¨ãã¦ãã°ããªã·ã¼ã«åºã¥ããéç¥ãèªå復æ§ã®ä»çµã¿ãå®è£ ãã¾ãããã
è¦ä»¶11ï¼ã»ãã¥ãªãã£ã·ã¹ãã ããã³ããã»ã¹ãå®æçã«ãã¹ããã
æ¬è¦ä»¶ã§ã¯ãã»ãã¥ãªãã£è¨ºæï¼èå¼±æ§ã¹ãã£ã³ããã³ãããã¬ã¼ã·ã§ã³ãã¹ãï¼ã®å®æ½ãIDS/IPSãå¤æ´æ¤åºã¡ã«ããºã ã«ããç£è¦ãªã©ãæ±ãããã¾ããAWSããæä¾ãããå種ãµã¼ãã¹ãå°ç¨ã®è£½åãåå¥å°å ¥ãã¦å®ç¾ãã¾ãã
- âã»ãã¥ãªãã£è¨ºæã®å®æ½
EC2ã¤ã³ã¹ã¿ã³ã¹ãªã©AWSã§è¨±å¯ããããµã¼ãã¹ã«å¯¾ãã¦äºåæ¿èªãªãã«ã»ãã¥ãªãã£è¨ºæã®å®æ½ãå¯è½ã§ãããã ããç¦æ¢ãããè¡çºï¼DoSæ»æãªã©ï¼ã«ã¤ãã¦è¨è¼ããã¦ãããä¾µå ¥ãã¹ãã®AWSã«ã¹ã¿ãã¼ãµãã¼ãããªã·ã¼ãã¸ã®çæãå¿ è¦ã§ãã - âIDS/IPSã«ããç£è¦
å®å ¨ã§ãªããããã¯ã¼ã¯ã¨ã®å¢çããã®ä»éè¦ãªãã¤ã³ããééãããã¹ã¦ã®ãã©ãã£ãã¯ãç£è¦ãã侵害ã®çããããå ´åã«æ å½è ã«è¦åãããããæ§æãããã¨ãæ±ãããã¾ããIDS/IPSã¢ãã©ã¤ã¢ã³ã¹è£½åãå¢çé¨åãéè¦ãªãã¤ã³ãã«å°å ¥ãããããã¹ããã¼ã¹ã®IDS/IPSã½ãªã¥ã¼ã·ã§ã³ã対象ã¤ã³ã¹ã¿ã³ã¹ã«å°å ¥ããããããã¨ã«ãã£ã¦å®ç¾ãã¾ããAWSã®ãµã¼ãã¹ã§ããGuardDutyã«ãã£ã¦ãæªæããã¢ã¯ãã£ããã£ãªã©ã®ç£è¦ãå¯è½ã§ããããããã¯ã¼ã¯ãã±ãããã¼ã¿ã®ã³ã³ãã³ãæ¤æ»ã¾ã§ã¯ããªããã¨ããPCI DSSã¸ã®æºæ æ§ã«ã¤ãã¦QSAï¼èªå®ã»ãã¥ãªãã£è©ä¾¡æ©é¢ï¼ã«ãã£ã¦æè¦ãåããã¦ããã¨ããçæãå¿ è¦ã§ãã - âå¤æ´æ¤åºã¡ã«ããºã ã«ããç£è¦
éè¦ãªã·ã¹ãã ãã¡ã¤ã«ãæ§æãã¡ã¤ã«ãã³ã³ãã³ããªã©ã«å¯¾ããå¤æ´æç¡ãç£è¦ããæ å½è ã«è¦åãããããæ§æãããã¨ãæ±ãããã¾ããAWSãµã¼ãã¹ã®æ§æè¨å®ã¯AWS Configãæå¹åããEC2ã¤ã³ã¹ã¿ã³ã¹ä¸ã®ãã¡ã¤ã«ã¯å¤æ´ç£è¦æ©è½ãæã¤ã½ãªã¥ã¼ã·ã§ã³ãå°å ¥ããçã«ãã£ã¦å¤æ´ç£è¦ã®ä»çµã¿ã確ç«ãããã¨ãå¯è½ã§ãã
è¦ä»¶12ï¼ãã¹ã¦ã®æ å½è ã®æ å ±ã»ãã¥ãªãã£ã«å¯¾å¿ããããªã·ã¼ãç¶æãã
æ¬è¦ä»¶ã§ã¯æ å ±ã»ãã¥ãªãã£ããªã·ã¼ã¨ããã°ã©ã ã®ç¶æãæ±ãããã¾ãããAWSãã©ãããã©ã¼ã ä¸ã§ã®ããªã·ã¼ã®ç¢ºç«ãç¶æã¯å©ç¨è 責任ã§ããã¾ããPCI DSSã¸ã®æºæ ã¹ãã¼ã¿ã¹ã®ç£è¦ãªã©ã«ããAWSãªã©ã®ãµã¼ããã¼ãã£ãããã¤ãã管çãããã¨ãæ±ãããã¾ããå ãã¦ãAWSããæä¾ãããã¤ã³ã·ãã³ã対å¿ã«é¢ããã¬ã¤ãã³ã¹ï¼EC2ã¤ã³ã¹ã¿ã³ã¹ã®ã¡ã¢ãªãã³ããã¡ã¤ã«åå¾æ¹æ³ãªã©ï¼ã確èªãã¦ãã»ãã¥ãªãã£ã¤ã³ã·ãã³ãçºçæã®å¯¾å¿è¨ç»ã«åæ ããå¿ è¦ãããã¾ãã
ã¾ã¨ã
ã¯ã¬ã¸ããã«ã¼ãæ¥çã®ã»ãã¥ãªãã£åºæºã§ããPCI DSSããã¼ã¹ã«AWSãã©ãããã©ã¼ã ä¸ã§ã»ãã¥ã¢ã«ã·ã¹ãã ãæ§æããéã®çæç¹ã«ã¤ãã¦å
¨3åã«ããã£ã¦ç´¹ä»ãã¦ãã¾ããã
ãç´¹ä»ãã¦ãããªãã§ç¹ã«çæããã ããããã¤ã³ãã¨ãã¦ä»¥ä¸ã®ç¹ãæãããã¾ãã
- â ã»ã°ã¡ã³ãã¼ã·ã§ã³ã«ããã¹ã³ã¼ãã®æå°å
ç°å¢ã®åé¢ï¼AWSã¢ã«ã¦ã³ãåå²ï¼ããããã¯ã¼ã¯ã®åé¢ï¼VPC/Security Groupã«ããã¢ã¯ã»ã¹å¶å¾¡ï¼ãªã©ã®æ段ã«ããã»ã°ã¡ã³ãã¼ã·ã§ã³å¢çãè¨ãã¦éè¦ãªæ å ±ãåãæ±ãé åãä»ã®ç°å¢ããåé¢ãã¾ãããããã¹ã¦ã®ç°å¢ã«å¯¾ãã¦åã¬ãã«ã®å¯¾çãè¬ãããã¨ã«ã¯éçãããã¾ããç¹ã«å®ãã¹ãç¯å²ã«ãã©ã¼ã«ã¹ãã¦ãéè¦ãªæ å ±ã®æå·åãå³æ ¼ãªéµç®¡çãªã©PCI DSSã¬ãã«ã®å¯¾çãè¬ãã¦ãããã¨ãæ¨å¥¨ããã¾ãã - â¡åè¦ä»¶ã§é¢é£ããAWSãµã¼ãã¹ã®ç解ã責任ç¯å²ã®æ£ç¢ºãªææ¡
è²¬ä»»å ±æã¢ãã«ã«åºã¥ãã¦èªèº«ã®è²¬ä»»ç¯å²ãææ¡ããããã§PCI DSSè¦ä»¶ãªã©ã«æ²¿ã£ã対çã確å®ã«è¬ããå¿ è¦ãããã¾ããEC2ã¤ã³ã¹ã¿ã³ã¹ä¸ã«ã¦èªåãã¡ã§ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ããæ§ç¯ãã¦ãããããªå ´åã¯è²¬ä»»ã®æå¨ãåãããããã®ã§ãããAWSããã¼ã¸ãã®ãµã¼ãã¹ãå©ç¨ãã¦ãããããªå ´åã«ããã¦å¯¾çãæãæ¼ãã¦ãã¾ãã±ã¼ã¹ãã¿ããã¾ããä¾ãã°S3ã®ãããªã¹ãã¬ã¼ã¸ãµã¼ãã¹ã使ç¨ããå ´åã«ãã¤ã³ã¿ã¼ãããããã¢ã¯ã»ã¹ã§ããªãããæ§æããããéè¦ãªæ å ±ãç½®ãããé åã«å¯¾ãã¦å³æ ¼ãªã¢ã¯ã»ã¹å¶å¾¡ãè¡ã£ãããå¿ è¦ã¨èãããããã°ãæå¹åããããã責任ã¯å©ç¨è ã«ããã¾ããèªåãã¡ãå©ç¨ããAWSã®ãµã¼ãã¹ãæ£ç¢ºã«ç解ããå¿ è¦ãªå¯¾çã«æ¼ãã®ãªããã注æãã¾ãããã
PCI DSSã¯å®ãã¹ãæ å ±ãä¿è·ããããã®ã»ãã¥ãªãã£å¯¾çãå ·ä½çãã¤ä½ç³»çã«ã¾ã¨ãããã¦ãã¾ããAWSãã©ãããã©ã¼ã ã§ã·ã¹ãã æ§ç¯ããã«ããããã«ã¼ãæ å ±ãæ±ãã·ã¹ãã ã«éããæ§ã ãªã·ã¹ãã ã§PCI DSSãæ´»ç¨ãã¦ããã ããã°å¹¸ãã§ãã
ãåèãªã½ã¼ã¹
-
[1]
Payment Card Industry (PCI) Data Security Standard Version 3.2.1
https://www.pcisecuritystandards.org/document_library -
[2]
AWSã«ãããPCI DSS (Payment Card Industry Data Security Standard) 3.2.1ã³ã³ãã©ã¤ã¢ã³ã¹ã¬ã¤ã
https://d1.awsstatic.com/whitepapers/ja_JP/compliance/pci-dss-compliance-on-aws.pdf
ãåãåãã
AWSãªã©ã®ãããªãã¯ã¯ã©ã¦ãç°å¢ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ã¾ãã¯ç¾ç¶ææ¡ãéè¦ã§ããPCI DSSãªã©ã®ã»ãã¥ãªãã£åºæºã«åºã¥ããã¢ã»ã¹ã¡ã³ããµã¼ãã¹ãå種ã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãªã©ã§ã®ãæ¯æ´ãå¯è½ã§ãã
ã¾ããæ¬ã³ã©ã ã§ã¯AWSã®ã¬ã¤ãã³ã¹ããã¨ã«å種AWSãµã¼ãã¹ãæ´»ç¨ãã¦ã®ã»ãã¥ãªãã£å¯¾çãä¸å¿ã«èª¬æãã¾ãããããã«ãã¯ã©ã¦ãããã¤ããªããã¯ã©ã¦ãã§ã®å¯¾å¿ã24h365dã§ã®ç£è¦ãããå³æ ¼ãªæ
å ±ä¿è·ãæ±ãããã¦ããå ´åãªã©AWSãµã¼ãã¹ã ãã§ã¯ã«ãã¼ã§ããªãç¹ã«ã¤ãã¦å¼ç¤¾ã½ãªã¥ã¼ã·ã§ã³ã«ããå®ç¾å¯è½ãªç¯å²ããããã¾ãããæ°è»½ã«ãåãåãããã ããã
https://www.intellilink.co.jp/contact-us.aspx
â»Amazon Web ServicesããPowered by Amazon Web Servicesããã´ãããã³ãããè³æã§ä½¿ç¨ããããã®ä»ã®AWSåæ¨ã¯ãç±³å½ããã³/ã¾ãã¯ãã®ä»ã®è«¸å½ã«ããããAmazon.com, Inc.ã¾ãã¯ãã®é¢é£ä¼ç¤¾ã®åæ¨ã§ãã