次ã®æ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã«æ±ããããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®åæ©
ï½æ¹è¨çï¼ISO/IEC 27002 ã«è¿½å ãããæ°è¦ç®¡ççï½
ã¯ããã«
æ¨ä»ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ããè¨èãç®ã«ããæ©ä¼ãå¤ããªã£ã¦ããã®ã§ã¯ãªãã§ãããããæ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã®å®è·µã®ããã®è¦ç¯ï¼ISO/IEC27002ï¼ã®æ¹è¨ã«ä¼´ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ãæ°è¦ç®¡ççã«è¿½å ãäºå®ããã¦ãããã¨ãããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ããè¨èã¯æ¢ã«ãåç¥ã®æ¹ãå¤ããã¨æãã¾ãã
ããããè å¨ã¤ã³ããªã¸ã§ã³ã¹ãæ±ãæ å ±ã¯å¤å²ã«æ¸¡ã£ã¦ãããã©ããªæ å ±ãå¿ è¦ã§ãã©ããªãã¨ãåºæ¥ãã®ãï¼ã¯ã¾ã ç解ãæ·±ã¾ã£ã¦ã¯ããªãã®ã§ã¯ãªããã¨æãã¾ããæ¬ã³ã©ã ã§ã¯ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®å®ç¾©ãæ´»ç¨æ¹æ³ãç´¹ä»ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã«ããã»ãã¥ãªãã£ãªã¹ã¯ããã¸ã¡ã³ãã®åæ©çãªã¤ã¡ã¼ã¸ãæ´ã¿ããæ¹åãã«å 容ã解説ãã¾ãã
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã注ç®ãããèæ¯ã¨ã¯ï¼
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã注ç®ããã¦ããè¦å ã®ä¸ã¤ã¨ãã¦ãæ¥ã é«åº¦åãããã¼ã«ãæ»æææ³ã«ããæ»æè æå©ã®ç¶æ³ã«ãååçãªã»ãã¥ãªãã£å¯¾çãã¤ãã¦ãããªããªã£ããã¨ãæãããã¾ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¯ãæ»æè ã®çãã¨æ»æææ³ãå½±é¿ãåæãããã¨ã«ãããã©ããçãããã®ãï¼ã¨ããæ»æè ç®ç·ã§ãªã¹ã¯ã«å¯¾ããåªå 度ãå®ããè½åçã«å¯¾çãããã¨ãç®çã¨ãã¦ãã¾ãããã®ããã«ã¯æ»æè ã®æ å ±ãå¾ãå¿ è¦ãããã¾ãããæ¬æ¥å ¥æãå°é£ã§ãããã¼ã¯ã¦ã§ãããã£ã¼ãã¦ã§ãã«ãããæ»æã°ã«ã¼ãã®ä¼è©±ãæ»æãã£ã³ãã¼ã³æ å ±ãªã©ããã¢ããªã¹ããåæããè å¨ã¤ã³ããªã¸ã§ã³ã¹ãæä¾ãããµã¼ãã¹ãã³ããå¢å ãããã¨ãªã©ã浸éããè¦å ã®ä¸ã¤ã¨èãããã¾ãã
ããããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ã¯ï¼
ãã®ã³ã©ã ã®ä¸ã®å®ç¾©ã§ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ã«å¯¾ããã¤ã³ããªã¸ã§ã³ã¹ããè
å¨ã¤ã³ããªã¸ã§ã³ã¹ãã¨å®ãã¾ãã
ç¶ãã¦ã¤ã³ããªã¸ã§ã³ã¹ã®å®ç¾©ã«ãç°¡åã«è§¦ãããã¨æãã¾ããã¤ã³ããªã¸ã§ã³ã¹ã¨ããè¨èã¯æ¦å¿µçãªæå³åããå¼·ããæ確ãªå®ç¾©ãããã¾ããããã¨ãã¨ã¯è»äºé åã§ç¨ãããã¦ãããæµå¯¾å½å®¶ã®æ
å ±ãåéãåæãè¡ããææ決å®ã対çå®æ½ã®ããã«æ
å ±ãæ´çããçµæãã¤ã³ããªã¸ã§ã³ã¹ã¨å¼ã°ãã¾ãã
ãµã¤ãã¼é åã®è å¨ã¤ã³ããªã¸ã§ã³ã¹ã§ã¯ãä¼æ¥ãã·ã¹ãã ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã«å¯¾ãã¦ãåéããè å¨æ å ±ãããã誰ããã©ãã«ãã©ããªææ³ã§ãã©ããªå½±é¿ãããããå½±é¿ã®æ ¹æ ãã¨ãã£ãæ å ±ãåæããé©åãªã¢ã¯ã·ã§ã³ãåãããã®ä¸é£ã®æ å ±ãæ´çããçµæãæãã¾ãã
誰ã | æ»æè ï¼æªæãæã£ãæ»æè ã ãã§ãªãæå³ããæªå½±é¿ãä¸ããã¦ã¼ã¶ãå«ãï¼ |
---|---|
ã©ãã« | æ å ±è³ç£ï¼å ¬éãµã¼ãã ãã§ãªãæ©å¯æ å ±ãä¼æ¥ã¤ã¡ã¼ã¸ãå«ãï¼ |
ææ³ | åæ©ããMITRE ATT&CKã«ä»£è¡¨ãããTTP |
å½±é¿ | æ å ±è³ç£ã¸ã®å½±é¿ã¨ãã®ãªã¹ã¯ï¼ééçå½±é¿ãå¯ç¨æ§ã¸ã®å½±é¿ã風è©è¢«å®³â¦ï¼ |
å½±é¿ã®æ ¹æ | å½±é¿ãå¤æããããã®ä¾µå®³ã®çè·¡ï¼IoC:Indicator of Compromiseï¼ |
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ´»ç¨æ¹æ³ã¨ã¯ï¼
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã¯æ§ã ãªæ´»ç¨æ¹æ³ãããã¾ãããã®ç« ã§ã¯ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ãã©ãã®ããã«æ´»ç¨ããã®ããç´¹ä»ãã¾ãã
ãããããä½ããã£ã¦è å¨ã¤ã³ããªã¸ã§ã³ã¹ãæ´»ç¨ããã¨è¨ããã®ã§ããããï¼çãã¯æ´»ç¨æ¹æ³ã«ãã£ã¦ç°ãªãã¾ããæ´»ç¨ã«ããã£ã¦ã¯ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ãã誰ã«ãæä¾ããã®ãï¼ãéè¦ãªãã¤ã³ãã§ããã誰ã«ãã¨ããã¿ã¼ã²ããã¯ä¸»ã«çµå¶å±¤ã¨ã»ãã¥ãªãã£ç®¡çè ãç¾å ´ã®3ã¤ã«åãããã¨ãã§ãããçµå¶å±¤åããã§ã¯ä¼æ¥ã®æ¥çã«å¯¾ããè å¨ååãããµãã©ã¤ãã§ã¼ã³ãªã¹ã¯ãªã©ä¼ç¤¾ã®ã»ãã¥ãªãã£æ¹éãææ決å®ããããã®ã¤ã³ããªã¸ã§ã³ã¹ãæä¾ãããæ¦ç¥çã¤ã³ããªã¸ã§ã³ã¹ãããã»ãã¥ãªãã£ç®¡çè ãåãã¯ãæ»æãã£ã³ãã¼ã³ããæ»æææ³ãªã©ãªã¹ã¯ã¢ã»ã¹ã¡ã³ããã»ãã¥ãªãã£ããªã·ã¼ãè¦ç´ãããã®ã¤ã³ããªã¸ã§ã³ã¹ãæä¾ãããçµ±å¶çã¤ã³ããªã¸ã§ã³ã¹ãããç¾å ´åããã§ã¯æ©å¨ã®èå¼±æ§æ å ±ãIoCãã»ãã¥ãªãã£æ©å¨ã¸ã®æ å ±é£æºãè¡ãããã®ã¤ã³ããªã¸ã§ã³ã¹ãæä¾ãããæ¦è¡çã¤ã³ããªã¸ã§ã³ã¹ããããã¾ããã誰ã«ãæä¾ããã®ãã«ãããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ´»ç¨æ¹æ³ãç¹å®ãããã¨ãåºæ¥ã¾ãã
表2ãã¤ã³ããªã¸ã§ã³ã¹ã®ç¨®å¥ã¨æ´»ç¨ä¾
ç¨®å¥ | æ¦è¦ | 主ãªæ´»ç¨ä¾ |
---|---|---|
æ¦ç¥çã¤ã³ããªã¸ã§ã³ã¹ | çµå¶å±¤åãã«ã»ãã¥ãªãã£å¯¾çã®ææ決å®ã®ããã«å©ç¨ãã | ã»ã»ãã¥ãªãã£ãã¼ããããçå® ã»ã»ãã¥ãªãã£æè³ã®æææ±ºå® â¦ãªã© |
çµ±å¶çã¤ã³ããªã¸ã§ã³ã¹ | ã»ãã¥ãªãã£ç®¡çè åãã«ã»ãã¥ãªãã£ããªã·ã¼ãã¬ããã³ã¹åä¸ã®ããã«å©ç¨ãã | ã»ãªã¹ã¯ã¢ã»ã¹ã¡ã³ã ã»ãããã¬ã¼ã·ã§ã³ãã¹ã â¦ãªã© |
æ¦è¡çã¤ã³ããªã¸ã§ã³ã¹ï¼â»1ï¼ | SOCãCSIRTãªã©ç¾å ´åãã®ã»ãã¥ãªãã£å¯¾çã®ããå©ç¨ãã | ã»ã»ãã¥ãªãã£ã¢ãã©ã¤ã¢ã³ã¹ã¸ã®æ
å ±é£æº ã»ã¹ã¬ãããã³ãã£ã³ã° ã»ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ â¦ãªã© |
â»1 æ¦è¡çã¤ã³ããªã¸ã§ã³ã¹ã®è©³ç´°ãã¤ã³ããªã¸ã§ã³ã¹ã®æ´»ç¨ãµã¤ã¯ã«ã¯å¥ã³ã©ã ã§è©³ãã解説ãè¡ã£ã¦ãã¾ãã
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ å ±æºã¨ã¯ï¼
ãã®ç« ã§ã¯ãã¤ã³ãããã¨ãã¦åéããè å¨æ å ±ã«ã¤ãã¦ç´¹ä»ãã¾ããå ã«ã触ããã¨ãããè å¨æ å ±ã¯å¤ç¨®å¤æ§ã§ãããåæ対象ã¨ããä¼æ¥ãã·ã¹ãã ã«ãã£ã¦å¿ è¦ã¨ããæ å ±ãå¤ãããããåç« ã§ç´¹ä»ããéããããããã誰ã«å¯¾ãã¦ã©ã®ãããªæ´»ç¨æ¹æ³ãå®ããããã§ãã©ã®ãããªè å¨æ å ±ãåéããã®ãã決ããå¿ è¦ãããã¾ãã
è å¨æ å ±ã¨ãã¦åé対象ã¨ãªãæ å ±ã¯ä»¥ä¸ã®è¡¨ã®ããã«åé¡ããã¾ããããã¤ãã®è å¨æ å ±ã¯æ¢ã«æ¬ã³ã©ã ã®èªè ãåéãæ´»ç¨ãã¦ããã®ã§ã¯ãªãã§ãããããèå¼±æ§æ å ±ãããã£ãã·ã³ã°ãµã¤ãã®æ å ±ãªã©ä»¥åããåå¨ããæ å ±ãè å¨æ å ±ã¨ãã¦æ´»ç¨ããã¦ãã¾ããOSINT (â»2) ã«ããåéã容æãªãã®ãããè å¨ã¤ã³ããªã¸ã§ã³ã¹ãã³ããç¬èªã®ãã¦ãã¦ã§åéãããã¼ã¯ã¦ã§ãï¼ãã£ã¼ãã¦ã§ãã®æ å ±ãªã©åéãå°é£ãªãã®ã¾ã§æ§ã ãªæ å ±æºããè å¨æ å ±ãåéãã¾ãã
表3ãè å¨æ å ±ç¨®å¥ã®ä¾
è å¨æ å ±ç¨®å¥ | ä½ãåããï¼ |
---|---|
ãã¼ã¯ã¦ã§ãï¼ãã£ã¼ãã¦ã§ãæ å ± | ã»åæ対象ä¼æ¥ã®æ¥çåå |
ã»åæ対象ä¼æ¥ãçãæ»æã°ã«ã¼ãã®æ å ± | |
ã»æ»æã°ã«ã¼ãã®æ»æææ³ï¼TTPsï¼ | |
æ¼æ´©æ å ± | ã»èªè¨¼æ å ± |
ã»æ©å¯æ å ± | |
ã»ã¡ã¼ã«ã¢ãã¬ã¹ | |
IoCæ å ± | ã»ãã«ã¦ã§ã¢ã®ããã·ã¥å¤ |
ã»C2ãµã¼ãæ å ± | |
ãã£ãã·ã³ã°æ å ± | ã»ãã£ãã·ã³ã°ãã¡ã¤ã³æ å ± |
ã»é¡ä¼¼ãã¡ã¤ã³æ å ± | |
ã»SNSãªããã¾ãã¢ã«ã¦ã³ãæ å ± | |
èå¼±æ§æ å ± | ã»å¤é¨å ¬éã·ã¹ãã ã®èå¼±æ§æ å ± |
ãµãã©ã¤ãã§ã¼ã³æ å ± | ã»OSINTã«ããä¼æ¥ã®ãªã¹ã¯å¤æ |
â»2 OSINT: ãªã¼ãã³ ã½ã¼ã¹ ã¤ã³ããªã¸ã§ã³ã¹ï¼Open Source INTelligenceï¼ã®ç¥ã§ããµã¤ãã¼ã»ãã¥ãªãã£é åã§ã¯ã¤ã³ã¿ã¼ãããçã®å ¬éæ å ±ããæç¨ãªæ å ±åéããææ³ãæãã
è å¨ã¤ã³ããªã¸ã§ã³ã¹ã®éç¨ã¤ã¡ã¼ã¸
ããã¾ã§ãè
å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ´»ç¨æ¹æ³ãã¤ã³ãããã¨ããè
å¨æ
å ±ã«ã¤ãã¦ç´¹ä»ãã¦ãã¾ããã
æå¾ã«è
å¨ã¤ã³ããªã¸ã§ã³ã¹ã®åæãµã¤ã¯ã«ãç´¹ä»ãã¾ãã
æ´»ç¨æ¹æ³ã«åããã¦ãåéããè å¨æ å ±ã®é¸å®ã¨åæå 容ãå®ããã¿ã¼ã²ããã«å¯¾ããã¬ãã¼ãåã¾ã§ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®ä¸é£ã®åæããã»ã¹ã¨ãªãã¾ãã
å³1ãè
å¨ã¤ã³ããªã¸ã§ã³ã¹ã®åæãµã¤ã¯ã«
ï¼å¼ç¨ï¼ããªã©ã¤ãªã¼ï¼ã¤ã³ããªã¸ã§ã³ã¹é§ååã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹(2018å¹´12æ çºè¡)ãï¼
æ¹éçå® | 誰åãã«ã©ããªæ å ±ãåéãã¦ã©ã®ãããªæ´»ç¨ãããããæ¤è¨ãã |
---|---|
åé | è å¨æ å ±ãåéããããã®æ å ±æºã¨åéããã»ã¹ã®ç¹å®ãè¡ã |
å å·¥ | å種æ å ±æºããåéããæ å ±ããåæç¨ã«æåãè¡ã |
åæ | è å¨æ å ±ããã誰ãã©ãã«ã©ããªå½±é¿ãä¸ããã®ããã¾ããã®ãªã¹ã¯ã®åæãè¡ã |
é å¸ | ç¹å®ããè å¨ã®ãªã¹ã¯å¤ã対çæ¹éã対çã®ã¬ãã¼ãåãè¡ã |
ãã£ã¼ããã㯠| 対çã®å®æ½ã¨è å¨ã¤ã³ããªã¸ã§ã³ã¹ã®å¹æã®æ¸¬å®ãè¡ã |
ã¾ã¨ã
ä»åãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ¦è¦ã«ã¤ãã¦ç´¹ä»ãã¾ãããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¯ãNIST SP800-172ãä»å¾æ¹è¨ãããISO/IEC 27002ã§ããªã¹ã¯ã¢ã»ã¹ã¡ã³ããè¡ãéã«æ´»ç¨ãããã¨ãæ¨å¥¨ããã¦ãã¾ããæ´»ç¨æ¹æ³ã«ãã£ã¦ã¯ãä»åç´¹ä»ããå 容以å¤ã®æ å ±ãå¿ è¦ã¨ãªãã¾ããæ å½ããã¦ããã·ã¹ãã ã®è¦ä»¶ã«åããã¦é©åãªè å¨æ å ±ãåéãããã¨ãéè¦ã§ãã
åèæç®
- ã» ãã¸ãã¹ã³ãã¥ãã±ã¼ã·ã§ã³ãBUSINESS COMMUNICATIONã2021å¹´8æå·ï½2022å¹´1æå·é£è¼ãããã ãã¯ç¥ã£ã¦ããããã¤ã³ããªã¸ã§ã³ã¹ãæ´»ç¨ãããµã¤ãã¼ã»ãã¥ãªãã£å¯¾çãï¼å½ç¤¾å·çï¼ï¼https://www.bcm.co.jp/
- æç« ä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã