ãã¼ããã©ã¹ããã®å°å ¥ãé²ã¾ãªããããã§ãæ»æè ã¯å¾ ã£ã¦ãããªãã
ï½ç±³å½æ¨æºã¨å½å äºä¾ããèããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹ï½
1. ã¯ããã«
2019å¹´ã«æ°åã³ããã¦ã¤ã«ã¹ææçï¼COVID-19ï¼ãæµè¡ãã¦ããããã¼ããã©ã¹ããã¨ããè¨èãé常ã«ããè³ã«ããããã«ãªãã¾ããããã ãå½æã¯åãã¼ããã©ã¹ãã¨ããè¨èã使ã£ã¦ãã¦ãããã®æå³ã¯å°é家ããã³ãã¼ã«ããç°ãªã£ã¦ãããããºã¯ã¼ãã¨ãã¦ã®å´é¢ãå¼·ãã£ãããã«æãã¾ãã
2020å¹´ã«ç±³å½å½ç«æ¨æºæè¡ç 究æï¼NISTï¼ãSP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ããçºè¡ããé ãããå°ããã¤ã¼ããã©ã¹ãã¨ããè¨èãåãæå³ã§ï¼å
±éè¨èªã¨ãã¦ï¼ä½¿ããããã«ãªã£ã¦ãã¾ããã
ããããªãããã¼ããã©ã¹ãã¯æ¦å¿µã§ããç¹å®ã®æè¡ã製åãæå³ãããã®ã§ã¯ãªããã¨ããããã¾ã ã«ãã¼ããã©ã¹ãã¯é£ãããããä½ãã©ãããã°ããã®ãåãããªããã¨ãã£ã声ãèããã¦ãã¾ãã
æ¬ã³ã©ã ã§ã¯ãã¼ããã©ã¹ãã«é¢ããç±³å½æ¨æºã¨æ¥æ¬å½å ã®äºä¾ãåèã«ããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹ããèãã¦ããã¾ãã
å³1ï¼ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®å¤é·
ãªããã¼ããã©ã¹ãã¨ããè¨èèªä½ã®è§£èª¬ã«ã¤ãã¦ã¯ãæ¢ã«å¤ãã®è¨äºçãå ¬éããã¦ãã¾ãã®ã§ãæ¬ã³ã©ã ã§ã¯çç¥ãã¾ãã
2. ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ãé²ããããã§ã®åæ
æ¬é¡ã«å ¥ãåã«ãã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ãé²ããããã§ã®åæã¨ãªããä¼æ¥çµå¶ã«ãããã¼ããã©ã¹ãã®ä½ç½®ã¥ãã確èªãã¦ããã¾ãããã
- ã»ã¼ããã©ã¹ãã¯ç®çã§ã¯ãªãæ段ã§ãããã¼ããã©ã¹ããããåã«çµå¶ã»DXæ¦ç¥ï¼ä¾ï¼åãæ¹æ¹é©ï¼ããµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯çããããããããæ¨é²ã»è§£æ±ºããããã®æ段ã®ä¸ã¤ã¨ãã¦ãã¼ããã©ã¹ããããã
- ã»ã¼ããã©ã¹ãã¯ãã®å¤ããæè¡çã»ãã¥ãªãã£ã§æ§æãããããµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ãé©åã«ã³ã³ããã¼ã«ããããã«ã¯ã人çã»ãã¥ãªãã£ãã¼ããã©ã¹ã以å¤ã®æè¡çã»ãã¥ãªãã£çãå«ãã¦æ¤è¨ããå¿ è¦ãããã
ä¸è¨ã«è¦ç´ããã¨ãã¼ããã©ã¹ãã¯ç®çã§ã¯ãªãéæ³ã®æã§ããªããã¨ãããã¨ã§ãã
3. ç±³å½æ¨æºããèããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹
ããã§ã¯ããããæ¬é¡ã§ããã¾ãã¯å ã»ã©ãç»å ´ããNIST SP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãï¼ä»¥ä¸ãNIST ZTAï¼ããè¦ã¦ããã¾ãããã
NIST ZTAã§ã¯ãã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹ãã¨ãã¦ã大ãã2ã¤ã®ã¢ã¼ããã¯ãã£ãç´¹ä»ããã¦ãã¾ãã1ã¤ç®ã¯ãç´ç²ãªã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãã§ãããå¢çãã¼ã¹ï¼å¢çåé²å¾¡ï¼ã®è¦ç´ ãä¸åå«ã¾ãªããã¼ããã©ã¹ãã®ã¿ã§æ§æãããã¢ã¼ããã¯ãã£ã«ãªãã¾ãã2ã¤ç®ã¯ããã¤ããªããZTAã¨å¢çãã¼ã¹ã®ã¢ã¼ããã¯ãã£ãï¼ä»¥ä¸ããã¤ããªããã»ã¢ã¼ããã¯ãã£ï¼ã§ãããã¼ããã©ã¹ãã¨å¢çãã¼ã¹ãçµã¿åããã¦æ§æãããã¢ã¼ããã¯ãã£ã«ãªãã¾ãã
ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ãé²ããä¼æ¥ã®å¤ããå¢çãã¼ã¹ã®è³ç£ãæã£ã¦ããã¨èãããããã¨ãããNIST ZTAã§ããç´ç²ãªã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãå®è¡å¯è½ãªãªãã·ã§ã³ã¨ãªããã¨ã¯ã»ã¨ãã©ãªããã¨è¿°ã¹ããã¦ãã¾ããã¾ããNIST ZTAã§ã¯ã¢ã¼ããã¯ãã£ã®åé¡ã ãã§ã¯ãªãå ·ä½çãªå°å ¥ã¹ãããã示ããã¦ãã¾ãããããã¯ãã¤ããªããã»ã¢ã¼ããã¯ãã£ã対象ã¨ãããã®ã«ãªã£ã¦ãã¾ãã
å³2ï¼ã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ã®åé¡
NIST ZTA以å¤ã®åèã«ãªãè³æã¨ãã¦ãç±³å½ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ã»ãã¥ãªãã£åºï¼CISAï¼ãçºè¡ãã¦ãããZero Trust Maturity Modelãï¼ä»¥ä¸ãã¼ããã©ã¹ãæç度ã¢ãã«ï¼ãããã¾ãã
ã¼ããã©ã¹ãæç度ã¢ãã«ã¯2021å¹´ã«ç½²åãããç±³å½å¤§çµ±é 令ï¼EO 14028ï¼ã«é¢é£ãã¦ãããç±³å½ã®æ¿åºæ©é¢ã¯æ¬ã¢ãã«ãåç §ããã¼ããã©ã¹ãã®å®è£ è¨ç»ãCISAã«æåºããå¿ è¦ãããã¾ãã
ã¼ããã©ã¹ãæç度ã¢ãã«ã§ã¯ãã¼ããã©ã¹ãã®æ§æè¦ç´ ï¼IdentityãDeviceãNetwork/EnvironmentãApplication WorkloadãDataï¼ã5æ¬ã®æ±ã«è¦ç«ã¦ãããããã®è¦ç´ ã«å¯¾ãã¦ãTraditionalãããAdvancedãããOptimalãã®3段éã§æç度ãå®ç¾©ãã¦ãã¾ããæ±ã«è¦ç«ã¦ã¦ãããã¨ã示ãããã«ããããã1æ¬ï¼1è¦ç´ ï¼ã ããé«ãããï¼æçãããï¼ã®ã§ã¯ãªãããã©ã³ã¹ã調æ´ããªããé«ããããã¨ãæ±ãããã¦ãã¾ãã
å³3ï¼ã¼ããã©ã¹ãæç度ã¢ãã«ã®ã¤ã¡ã¼ã¸
ï¼CISA Zero Trust Maturity Model ãå
ã«ä½æï¼
ããã以å¤ã«ãåèã«ãªãè³æã¯ããã¾ããã以ä¸ã®ãããªç¹ã«ã¤ãã¦ã¯ãããããå ±éããã¡ãã»ã¼ã¸ã¨ãã¦æããããã®ã§ã¯ãªããã¨æãã¾ãã
- ã»ã¼ããã©ã¹ãã¯ãªã¹ã¯ããã¸ã¡ã³ãã®ä¸ç°ã¨ãã¦åãçµãã¹ãã§ããã
- ã»ã¼ããã©ã¹ãã®å°å ¥ã¯çæéã§å®äºãããã®ã§ã¯ãªããå°å ¥ã¯æ°å¹´ãããã¦æ®µéçã«é²ããå¿ è¦ããããé¨éãã·ã¹ãã ãæ¥åçã®åä½ã§é²ãããã¨ãèããããã
4. å½å äºä¾ããèããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹
ã3. ç±³å½æ¨æºããèããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹ãã¨ã¯ç°ãªãæ¹æ³ã¨ãã¦ãæ¥æ¬å½å ã§å è¡ãã¦ããäºä¾ãåèã«ããã¨è¯ãã¨çè ã¯èãã¦ãã¾ããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®ããã¹ã姿ï¼To-Beï¼ãé²ãæ¹ï¼ãã¼ããããï¼ã«ã¤ãã¦ã¯ãå ¨ã¦ã®ä¼æ¥ã«å½ã¦ã¯ã¾ãæ£è§£ã¨ãããã®ã¯åå¨ãã¾ããããã ãWebãµã¤ãçã§å¤ãã®äºä¾ãå ¬éããã¦ãããã¨ãããããããæå¹æ´»ç¨ãããã¨ã§æ¤è¨ãã¹ã ã¼ãºã«é²ããããå¯è½æ§ãããã¾ãã
å³4ï¼ã¼ããã©ã¹ãäºä¾ã®æ´»ç¨ã¨å¹æ
äºä¾ã¯æ¥ã å¢å ãã¦ããæ¬ã³ã©ã ã§ãã®ä¸èº«ãç´¹ä»ãããã¨ã¯ãã¾ããããçè ã確èªããç¯å²ã§ã¯ããããã以ä¸ã®ãããªç¹å¾´ãè¦åãããã¾ããã
- ã»ã¼ããã©ã¹ããå°å ¥ããç®çã¯ããã¬ã¯ã¼ã¯ç°å¢ã®ã»ãã¥ãªãã£å¼·åããããã¯ã¼ã¯ã®æ§è½æ¹åï¼å¾æ¥å¡ã®çç£æ§åä¸ï¼ã§ããã±ã¼ã¹ãå¤ãã
- ã»ãã¬ã¯ã¼ã¯ç°å¢ã®ã»ãã¥ãªãã£å¼·åã¯ãç°å¢ã®å¤åã«ããå¢çã®å å´ããå¤å´ã«ç§»åãããã¨ã«ãªã£ããã¨ã³ããã¤ã³ãããçæããã±ã¼ã¹ãå¤ãã
- ã»ãããã¯ã¼ã¯ã®æ§è½åä¸ã¯ãããã«ããã¯ãææ¡ããããã§ãVPNããZTNAï¼SDPã»IAPãå«ãï¼ã¸ã®ç§»è¡ããã¤ã³ã¿ã¼ããããã¬ã¤ã¯ã¢ã¦ãã®å°å ¥ã«ãã解決ãã¦ããã±ã¼ã¹ãå¤ãã
- ã»ã¼ããã©ã¹ããå°å ¥ããåãããä½ããã®èªè¨¼åºç¤ï¼ä¾ï¼Active Directoryï¼ãéç¨ãã¦ããã±ã¼ã¹ãå¤ãããã®å ´åãIDaaSãå°å ¥ããã«æ¢åã®èªè¨¼åºç¤ãæµç¨ããã±ã¼ã¹ã¨ãIDaaSãå°å ¥ãã¦æ¢åã®èªè¨¼åºç¤ã¨é£æºãããã±ã¼ã¹ãããã
ãã®ããã«ãäºä¾ããã¯å¤ãã®ãã³ããå¾ããã¨ãã§ãã¾ãããäºä¾ããã®ã¾ã¾èªç¤¾ã«é©ç¨ããã°è¯ãã¨ãããã¨ã§ã¯ããã¾ãããã¾ããäºä¾ã«ãã£ã¦ã¯åºåã¨ãã¦ã®è²åããå¼·ããã®ãå«ã¾ãã¾ãã®ã§ãããç¨åº¦ã®æ å ±ãªãã©ã·ã¼ã¯å¿ è¦ã«ãªãã¾ãã
5. ã¾ã¨ã
æ¬ã³ã©ã ã§ã¯ç±³å½æ¨æºã¨æ¥æ¬å½å ã®äºä¾ãåèã«ããã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®é²ãæ¹ããèãã¦ãã¾ããã2019å¹´é ã«ã¯ããºã¯ã¼ãã¨ãã¦ã®å´é¢ãå¼·ãã£ããã¼ããã©ã¹ããã¨ããè¨èããNIST SP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãã®çºè¡ãæ©ã«ãå ±éè¨èªã¨ãã¦ã®ãã¼ããã©ã¹ããã«å°ããã¤å¤åãã¦ãã£ãããã«æãã¾ãã
ãã ãã¼ããã©ã¹ãã¯ä¾ç¶ã¨ãã¦çºå±éä¸ã«ããããã¹ããã©ã¯ãã£ã¹ããªãã¡ã¬ã³ã¹ã¢ã¼ããã¯ãã£ã®ãããªæ¨æºåã®åãã¯ã¾ã ãã¾ãé²ãã§ãã¾ããããã®ãããå
·ä½çãªé²ãæ¹ã«ã¤ãã¦ã¯ããããã®ä¼æ¥ãã¼ãããæ¤è¨ãã¦ããå¿
è¦ãããã¾ãã
ããããæ»æè
ã¯æºåãæ´ãã¾ã§å¾
ã£ã¦ã¯ããã¾ãããç§ãã¡ãä»ã§ãããã¨ã¯ããµã¤ãã¼ã»ãã¥ãªãã£æ¦ç¥ã¨ãã¦ã®ãã¼ããã©ã¹ãããæ£ããç解ããä»ããæ
å ±ãæ大éæ´»ç¨ããªãããæåãå°½ãããã¨ä»¥å¤ã«ããã¾ããã
æ¬ã³ã©ã ã®å 容ããå°ãã§ãçæ§ã®å¤§åãªæ å ±è³ç£ãå®ãããã®ãã³ãã«ãªãã°å¹¸ãã§ãã
é¢é£ãªã³ã¯
INTELLILINK ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ãµã¼ãã¹
åèæç®
- [1]NIST SP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãï¼ç¬ç«è¡æ¿æ³äººæ
å ±å¦çæ¨é²æ©æ§ï¼
https://www.ipa.go.jp/security/publications/nist/index.html - [2]Zero Trust Maturity Modelï¼ç±³å½ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ã»ãã¥ãªãã£åºï¼
https://www.cisa.gov/zero-trust-maturity-model
â»æä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã