CIS Benchmarksããè¦ã4大ã¯ã©ã¦ãã®IAMè¦ä»¶ããã10ï¼2ï¼
ï½AWSãAzureãGCPãOCIã®IAMæ¨å¥¨çï½
ååã®ç¶ãï¼4大ã¯ã©ã¦ãã®IAMè¦ä»¶ããã10ï¼
ååã¯ãAWSãAzureãGCPãOCIã®å ±éçãªIAMè¦ä»¶ããã10ããã³ãNo.1ã®å¤è¦ç´ èªè¨¼ã®å°å ¥ã«ã¤ãã¦èª¬æãã¾ãããä»åã¯No.2ï½10ã¾ã§ä¸æ°ã«è§£èª¬ãã¾ãã
ç®æ¬¡
- 4大ã¯ã©ã¦ãã®IAMè¦ä»¶ããã10ï¼No.2ï½10ï¼
- No.2ã管çè 権éã®æå°å
- No.3ããã¹ã¯ã¼ãããªã·ã¼ã®è¨å®
- No.4ãæå°éã®ãã®ä»èªè¨¼æ å ±
- No.5ããã®ä»èªè¨¼æ å ±ã®ãã¼ãã¼ã·ã§ã³
- No.6ãã°ã«ã¼ãã«åºã¥ãã¢ã¯ã»ã¹æ¨©éè¨å®
- No.7ãã¯ã©ã¦ããµã¼ãã¹ã¨ã®é£çµ¡å ã®ç¶æ
- No.8ãã¢ããªã±ã¼ã·ã§ã³ã¢ã¯ã»ã¹ã®å¶é
- No.9ãã¢ã«ã¦ã³ãã®ã¬ãã¥ã¼
- No.10ãKMSã¸ã®ã¢ã¯ã»ã¹å¶å¾¡
- ã¾ã¨ã
4大ã¯ã©ã¦ãã®IAMè¦ä»¶ããã10ï¼No.2ï½10ï¼
No.2ãå¿ è¦æå°éã®ç®¡çè 権é
No.2ã¯ãå¿ è¦æå°éã®ç®¡çè 権éã§ããåã¯ã©ã¦ããµã¼ãã¹ã«ããã¦ã管çè ã®æ¨©éããããã¯ãã¼ã«ã«ã¯é常ã«å¤ãã®ç¨®é¡ãããã¾ãã管çè 権éã§ãã£ã¦ããã¹ã¦ã®æ¨©éãä»ä¸ããã®ã§ã¯ãªããæ¥åä¸å¿ è¦ãªæ¨©éç¯å²ã®ã¿ã«éå®ãããã¨ãæã¾ããã§ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»å¿ è¦æå°éã®ç®¡çè 権éã®ä»ä¸ï¼â»ä¸é¨ã¬ãã«2ï¼
- ã»æä¸ä½ç®¡çè ã¢ã«ã¦ã³ãã®å©ç¨å¶é
- ã»ç¹å®ã®ç¬èªãã¼ã«ä½æã®å¶é
- ã»ã¢ã¯ã»ã¹å¶å¾¡æ©è½ã¸ã®ã¢ã¯ã»ã¹å¶é
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
å¿ è¦æå°éã®ç®¡çè 権éã®ä»ä¸ | AWSã1.16ãå®å
¨ãªã*ï¼*ã管çè
権éã許å¯ããIAMããªã·ã¼ãä»ä¸ããã¦ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ Azureã1.25ããAzure ADãã£ã¬ã¯ããªã«å ¥ããµãã¹ã¯ãªãã·ã§ã³ãããã³ãAzure ADãã£ã¬ã¯ããªããåºããµãã¹ã¯ãªãã·ã§ã³ããã誰ã«ã許å¯ããªããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ GCPã1.5ããµã¼ãã¹ã¢ã«ã¦ã³ãã«ç®¡çè 権éããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ GCPã1.6ãIAMã¦ã¼ã¶ã¼ã«ããã¸ã§ã¯ãã¬ãã«ã§ãµã¼ãã¹ã¢ã«ã¦ã³ãå©ç¨è ã¾ãã¯ãµã¼ãã¹ã¢ã«ã¦ã³ããã¼ã¯ã³ä½æè ãã¼ã«ãå²ãå½ã¦ããã¦ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.1ãç¹å®ãµã¼ãã¹ã®ãªã½ã¼ã¹ã管çããããã«ãµã¼ãã¹ã¬ãã«ã®ç®¡çè ãä½æããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) OCIã1.2ããã¹ã¦ã®ãªã½ã¼ã¹ã«å¯¾ãã権éãããã³ã·ç®¡çè ã°ã«ã¼ãã«ã®ã¿ä»ä¸ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) OCIã1.3ãIAM管çè ãããã³ã·ç®¡çè ã°ã«ã¼ããæ´æ°ã§ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) OCIã1.14ãã¹ãã¬ã¼ã¸ãµã¼ãã¹ã¬ãã«ã®ç®¡çè ããèªåã管çãããªã½ã¼ã¹ãåé¤ã§ããªãããã«ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ |
æä¸ä½ç®¡çè ã¢ã«ã¦ã³ãã®å©ç¨å¶é | AWSã1.7ã管çããã³æ¥å¸¸ã®ã¿ã¹ã¯ã§ã®ãrootãã¦ã¼ã¶ã¼ã®ä½¿ç¨ãæé¤ããï¼ã¬ãã«1ï½¥èªååï¼ |
ç¹å®ã®ç¬èªãã¼ã«ä½æã®å¶é | Azureã1.23ãã«ã¹ã¿ã ã®ãµãã¹ã¯ãªãã·ã§ã³ææè ãã¼ã«ãä½æããã¦ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ã¢ã¯ã»ã¹å¶å¾¡æ©è½ã¸ã®ã¢ã¯ã»ã¹å¶é | Azureã1.17ã[Azure AD管çãã¼ã¿ã«ã¸ã®ã¢ã¯ã»ã¹ãå¶éãã]ã[ã¯ã]ã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
No.ï¼ããã¹ã¯ã¼ãããªã·ã¼ã®è¨å®
次ã¯ãã¹ã¯ã¼ãããªã·ã¼ã®è¨å®ã§ããCIS Benchmarksã§ã¯å¤è¦ç´ èªè¨¼ãæ¨å¥¨ããã¦ãã¾ããããã¹ã¯ã¼ãããªã·ã¼ã«é¢ããæ¨å¥¨çãæ°å¤ãçãè¾¼ã¾ãã¦ãã¾ãããªããCIS Controlsï¼ãã¼ã¸ã§ã³8ï¼ã®5.2ã§ã¯å¤è¦ç´ èªè¨¼ã使ç¨ããã¢ã«ã¦ã³ãã¯8æå以ä¸ã使ç¨ããªãã¢ã«ã¦ã³ãã¯14æå以ä¸ã®ãã¹ã¯ã¼ãã使ç¨ãããã¨ãæ¨å¥¨ãã¦ãã¾ãããã¹ã¯ã¼ããã©ãã¾ã§é·ããããã¯åçµç¹ã®å¤æ次第ã¨ãªãã¾ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»14æå以ä¸ã®ãã¹ã¯ã¼ãé·
- ã»ãã¹ã¯ã¼ãåå©ç¨ã®é²æ¢
- ã»ãã¹ã¯ã¼ããªã»ããæã®è¿½å 確èª
- ã»ä¸é©åãªãã¹ã¯ã¼ãã®ç¦æ¢
- ã»ãã¹ã¯ã¼ãã®å確èª
- ã»ãã¹ã¯ã¼ããªã»ããæã®éç¥
- ã»365æ¥ä»¥å ã®ãã¹ã¯ã¼ãæå¹æé
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
14æå以ä¸ã®ãã¹ã¯ã¼ãé· | AWSã1.8ãIAMãã¹ã¯ã¼ãããªã·ã¼ããæå°14æå以ä¸ã®é·ããè¦æ±ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.4ãIAMãã¹ã¯ã¼ãããªã·ã¼ããæå°14æå以ä¸ã®é·ããè¦æ±ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ãã¹ã¯ã¼ãåå©ç¨ã®é²æ¢ | AWSã1.9ãIAMãã¹ã¯ã¼ãããªã·ã¼ããã¹ã¯ã¼ãã®åå©ç¨ãé²æ¢ãã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.6ãIAMãã¹ã¯ã¼ãããªã·ã¼ããã¹ã¯ã¼ãã®åå©ç¨ãé²æ¢ãã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ãã¹ã¯ã¼ããªã»ããæã®è¿½å ç¢ºèª | Azureã1.6ãããªã»ããã«å¿ è¦ãªèªè¨¼æ¹æ³ã®æ°ããã2ãã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ä¸é©åãªãã¹ã¯ã¼ãã®ç¦æ¢ | Azureã1.7ãã«ã¹ã¿ã ã®ä¸é©åãªãã¹ã¯ã¼ããªã¹ããçµç¹ã«å¯¾ãã¦ãå¼·å¶ãã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ãã¹ã¯ã¼ãã®åç¢ºèª | Azureã1.8ããã¦ã¼ã¶ã¼ãèªè¨¼æ å ±ã®å確èªãæ±ããããã¾ã§ã®æ¥æ°ããã0ãã«è¨å®ããã¦ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ãã¹ã¯ã¼ããªã»ããæã®éç¥ | Azureã1.9ãããã¹ã¯ã¼ããªã»ããã«ã¤ãã¦ã¦ã¼ã¶ã¼ã«éç¥ãã¾ããï¼ãããã¯ããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) Azureã1.10ããä»ã®ç®¡çè ãèªãã®ãã¹ã¯ã¼ãããªã»ããããã¨ãã«ãã¹ã¦ã®ç®¡çè ã«éç¥ãã¾ããï¼ãããã¯ããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
365æ¥ä»¥å ã®ãã¹ã¯ã¼ãæå¹æé | OCIã1.5ãIAMãã¹ã¯ã¼ãããªã·ã¼ã365æ¥ä»¥å ã«ãã¹ã¯ã¼ããæéåãã«ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
No.4ãæå°éã®ãã®ä»èªè¨¼æ å ±
次ã«æå°éã®ãã®ä»èªè¨¼æ å ±ã§ããé常ãèªè¨¼æ å ±ï¼Credentialsã®ãã¨ãè³æ ¼æ å ±ã¨ããããï¼ã¨ããã°ä¸è¬çã«ã¯ã¦ã¼ã¶ã¼IDããã³ãã¹ã¯ã¼ããã¤ã¡ã¼ã¸ããã¨æãã¾ããããããæ¬ã³ã©ã ã§ã¯ã¦ã¼ã¶ã¼IDããã³ãã¹ã¯ã¼ã以å¤ã®èªè¨¼æ å ±ãããã®ä»èªè¨¼æ å ±ãã¨ãã¦åãæ±ãã¾ããä¾ãã°ã以ä¸ã®ãããªãã®ãæãããã¾ãã
- ã»ã¢ã¯ã»ã¹ãã¼ï¼AWSã«ããã¦å¤é¨ããã¯ã©ã¦ããµã¼ãã¹ã¸CLIã§ããã°ã©ã ã¢ã¯ã»ã¹ããããã®èªè¨¼æ å ±ã
- ã»APIãã¼ï¼APIã¾ãã¯SDKã«å¯¾ãã¦å¼ã³åºããå®è¡ããã¢ãã±ã¼ã·ã§ã³çãèå¥ããããã®èªè¨¼æ å ±ã
- ã»ãµã¼ãã¹ã¢ã«ã¦ã³ãï¼GCPã«ããã¦ã¢ããªã±ã¼ã·ã§ã³çãç¹å®ã®ãªã½ã¼ã¹ã«å¯¾ãã¦ã¢ã¯ã»ã¹ããããã«å²ãå½ã¦ãããèªè¨¼æ å ±ã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»ç®¡çè ãããã®ä»èªè¨¼æ å ±ã®å¶é
- ã»ã¦ã¼ã¶ã¼ãããã®ä»èªè¨¼æ å ±ã®å¶é
- ã»ãµã¼ãã¹ãããã®ä»èªè¨¼æ å ±ã®å¶é
- ã»ãã®ä»èªè¨¼æ å ±ã®ä½¿ç¨ç¯å²ã®å¶éï¼â»ä¸é¨ã¬ãã«2ï¼
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
管çè ãããã®ä»èªè¨¼æ å ±ã®å¶é | AWSã1.4ãrootã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã®ã¢ã¯ã»ã¹ãã¼ãåå¨ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.11ãããã³ã·ç®¡çè ã¦ã¼ã¶ã¼ç¨ã«APIãã¼ãä½æããã¦ããªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ã¦ã¼ã¶ã¼ãããã®ä»èªè¨¼æ å ±ã®å¶é | AWSã1.11ãã³ã³ã½ã¼ã«ãã¹ã¯ã¼ããæã¤ãã¹ã¦ã®IAMã¦ã¼ã¶ã¼ã®åæã¦ã¼ã¶ã¼ã»ããã¢ããä¸ã«ã¢ã¯ã»ã¹ãã¼ãã»ããã¢ããããªãï¼ã¬ãã«1ï½¥æåï¼ AWSã1.13ã1人ã®IAMã¦ã¼ã¶ã¼ã使ç¨ã§ããã¢ã¯ãã£ããªã¢ã¯ã»ã¹ãã¼ã1ã¤ã ãã§ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ãµã¼ãã¹ãããã®ä»èªè¨¼æ å ±ã®å¶é | GCPã1.4ãåãµã¼ãã¹ã¢ã«ã¦ã³ãã«GCP管çã®ãµã¼ãã¹ã¢ã«ã¦ã³ããã¼ã®ã¿ãåå¨ãããã¨ã確èªããï¼1ï½¥èªååï¼ |
ãã®ä»èªè¨¼æ å ±ã®ä½¿ç¨ç¯å²ã®å¶é | GCPã1.12ãAPIãã¼ãããã¸ã§ã¯ãç¨ã«ä½æããã¦ããªããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ GCPã1.13ãAPIãã¼ãç¹å®ã®ãã¹ãããã³ã¢ããªã®ã¿ã®ä½¿ç¨ã«ãã£ã¦å¶éããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) GCPã1.14ãAPIãã¼ããã¢ããªã±ã¼ã·ã§ã³ãã¢ã¯ã»ã¹ãå¿ è¦ã¨ããAPIã®ã¿ã«å¶éããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
No.5ããã®ä»èªè¨¼æ å ±ã®ãã¼ãã¼ã·ã§ã³
次ã¯ããã®ä»èªè¨¼æ å ±ã®ãã¼ãã¼ã·ã§ã³ã§ãããã¼ãã¼ã·ã§ã³ã¯ã©ãã90æ¥ä»¥å ã¨ããã¦ãã¾ãã
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
ãã®ä»èªè¨¼æ å ±ã®ãã¼ãã¼ã·ã§ã³ | AWSã1.14ãã¢ã¯ã»ã¹ãã¼ã90æ¥ä»¥å
ã«ãã¼ãã¼ã·ã§ã³ããããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ GCPã1.7ããµã¼ãã¹ã¢ã«ã¦ã³ãã®ã¦ã¼ã¶ã¼ç®¡çãã¼ï¼å¤é¨ãã¼ã90æ¥ãã¨ã¾ãã¯ãã以å ã«ãã¼ãã¼ã·ã§ã³ããããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ GCPã1.15ãAPIãã¼ã90æ¥ãã¨ã«ãã¼ãã¼ã·ã§ã³ããããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) OCIã1.8ãã¦ã¼ã¶ã¼ã®APIãã¼ã90æ¥ä»¥å ã«ãã¼ãã¼ã·ã§ã³ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.9ãã¦ã¼ã¶ã¼ã®ã«ã¹ã¿ã ç§å¯éµã90æ¥ä»¥å ã«ãã¼ãã¼ã·ã§ã³ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ OCIã1.10ãã¦ã¼ã¶ã¼èªè¨¼ãã¼ã¯ã³ã90æ¥ä»¥å ã«ãã¼ãã¼ã·ã§ã³ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
No.6ãã°ã«ã¼ãã«åºã¥ãã¢ã¯ã»ã¹æ¨©éè¨å®
次ã«ã°ã«ã¼ãã«åºã¥ãã¢ã¯ã»ã¹æ¨©éè¨å®ã§ããåã¯ã©ã¦ããµã¼ãã¹ã§ãã¢ã¯ã»ã¹æ¨©éã®è¨å®ã«ã¯ã°ã«ã¼ãã使ç¨ããæ¹æ³ãæ¨å¥¨ããã¦ãã¾ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»ã°ã«ã¼ããä»ããã¦ã¼ã¶ã¼ã¸ã®ã¢ã¯ã»ã¹è¨±å¯
- ã»ã°ã«ã¼ããä»ããã¤ã³ã¹ã¿ã³ã¹ãªã©ã¸ã®ã¢ã¯ã»ã¹è¨±å¯
- ã»ã°ã«ã¼ãã®ä½æã管çã®å¶éï¼â»ã¬ãã«ï¼ï¼
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
ã°ã«ã¼ããä»ããã¦ã¼ã¶ã¼ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ | AWSã1.15ãIAMã¦ã¼ã¶ã¼ãã°ã«ã¼ããä»ãã¦ã®ã¿ã¢ã¯ã»ã¹è¨±å¯ãåãåããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ã°ã«ã¼ããä»ããã¤ã³ã¹ã¿ã³ã¹ãªã©ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ | OCIã1.13ãOCIã¤ã³ã¹ã¿ã³ã¹ãOCIã¯ã©ã¦ããã¼ã¿ãã¼ã¹ãããã³OCI FunctionãOCIãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããããã«åçã°ã«ã¼ãã使ç¨ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æåï¼ |
ã°ã«ã¼ãã®ä½æã管çã®å¶é | Azureã1.18ããã¢ã¯ã»ã¹æ ã«ãããã°ã«ã¼ãæ©è½ã«ã¢ã¯ã»ã¹ããã¦ã¼ã¶ã¼ã®æ©è½ãå¶éãããããã¯ããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ Azureã1.19ããã¦ã¼ã¶ã¼ãAzureãã¼ã¿ã«ãAPIãã¾ãã¯PowerShellã§ã»ãã¥ãªãã£ã°ã«ã¼ããä½æã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ Azureã1.20ããææè ãã¢ã¯ã»ã¹ããã«ã§ã°ã«ã¼ãã¡ã³ãã¼ã·ãããªã¯ã¨ã¹ãã管çã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ Azureã1.21ããã¦ã¼ã¶ã¼ãAzureãã¼ã¿ã«ãAPIãã¾ãã¯PowerShellã§Microsoft365ã°ã«ã¼ããä½æã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ |
No.7ãã¯ã©ã¦ããµã¼ãã¹ã¨ã®é£çµ¡å ã®ç¶æ
次ã¯ãã¯ã©ã¦ããµã¼ãã¹ã¨ã®é£çµ¡å ã®ç¶æã§ããã»ãã¥ãªãã£ä¸ã®æäºãçºçããå ´åãã¯ã©ã¦ãå´ããã®é£çµ¡ãæ©ãã«åãä»ãã¦å¯¾å¦ããå¿ è¦ãããã¾ããã·ã¹ãã éç¨ç®¡çãã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ã®è¦³ç¹ãããéè¦ãªè¦ä»¶ã§ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»éè¦ãªé£çµ¡å ã®ç¶æ
- ã»ã¦ã¼ã¶ã¼é£çµ¡å ã®ç¶æ
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
éè¦ãªé£çµ¡å ã®ç¶æ | AWSã1.2ãã»ãã¥ãªãã£é£çµ¡å
æ
å ±ãç»é²ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) GCPã1.16ãéè¦ãªé£çµ¡å ãçµç¹ç¨ã«æ§æããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ã¦ã¼ã¶ã¼é£çµ¡å ã®ç¶æ | AWSã1.1ãç¾å¨ã®é£çµ¡å
ã®è©³ç´°ãç¶æãããã¨ï¼ã¬ãã«1ï½¥æåï¼ OCIã1.12ããã¹ã¦ã®OCIã®IAMã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã«æå¹ã§ææ°ã®é»åã¡ã¼ã«ã¢ãã¬ã¹ããããã¨ã確èªããï¼ã¬ãã«1ï½¥æåï¼ |
No.8ãã¢ããªã±ã¼ã·ã§ã³ã¢ã¯ã»ã¹ã®å¶é
次ã¯ãã¢ããªã±ã¼ã·ã§ã³ã¢ã¯ã»ã¹ã®å¶éã§ãããã®è¦ä»¶ã¯ã¢ããªã±ã¼ã·ã§ã³ã«ããã¢ã¯ã»ã¹ã®å¶éã¨ãã¦ã¼ã¶ã¼ã«ããã¢ããªã±ã¼ã·ã§ã³ã®å©ç¨å¶éã®ä¸¡æ¹ããã¼ãã¨ãªãã¾ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»ã¢ããªã±ã¼ã·ã§ã³åæã®å¶éï¼â»ä¸é¨ã¬ãã«2ï¼
- ã»ã¢ããªã±ã¼ã·ã§ã³è¿½å ã®å¶é
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
ã¢ããªã±ã¼ã·ã§ã³åæã®å¶é | Azureã1.11ããã¦ã¼ã¶ã¼ã¯èªåã®ä»£ããã«ä¼ç¤¾ã®ãã¼ã¿ã«ã¢ã¯ã»ã¹ããã¢ããªã«åæã§ãããããæ¤è¨¼æ¸ã¿ã®çºè¡å
ã許å¯ãããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ Azureã1.12ããã¦ã¼ã¶ã¼ã¯èªåã®ä»£ããã«ä¼ç¤¾ã®ãã¼ã¿ã«ã¢ã¯ã»ã¹ããã¢ããªã«åæã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
ã¢ããªã±ã¼ã·ã§ã³è¿½å ã®å¶é | Azureã1.13ããã¦ã¼ã¶ã¼ãã®ã£ã©ãªã¼ã¢ããªããã¤ã¢ããªã«è¿½å ã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æåï¼ Azureã1.14ããã¦ã¼ã¶ã¼ãã¢ããªã±ã¼ã·ã§ã³ãç»é²ã§ãããããããããã«è¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥æåï¼ |
No.9ãã¢ã«ã¦ã³ãã®ã¬ãã¥ã¼
次ã¯ãã¢ã«ã¦ã³ãã®ã¬ãã¥ã¼ã§ããããã¯ä¸è¦ãªã¢ã«ã¦ã³ãã®ææ¡ããã³ç¡å¹åãæ±ããè¦ä»¶ã§ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»ã²ã¹ãã¦ã¼ã¶ã¼ã®ã¬ãã¥ã¼ï¼â»ä¸é¨ã¬ãã«2ï¼
- ã»æªä½¿ç¨ã¢ã«ã¦ã³ãã®ç¡å¹å
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
ã²ã¹ãã¦ã¼ã¶ã¼ã®ã¬ãã¥ã¼ | Azureã1.3ãAzure AD Privileged Identity Managementã§å¤é¨ã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹ã¬ãã¥ã¼ãè¨å®ããã¦ãããã¨ã確èªããï¼ã¬ãã«2ï½¥æåï¼ Azureã1.4ãã²ã¹ãã¦ã¼ã¶ã¼ãæ¯æã¬ãã¥ã¼ããããã¨ã確èªããï¼ã¬ãã«1ï½¥æå) |
æªä½¿ç¨ã¢ã«ã¦ã³ãã®ç¡å¹å | AWSã1.12ã45æ¥ä»¥ä¸ä½¿ç¨ããã¦ããªãèªè¨¼æ å ±ãç¡å¹ã«ãªã£ã¦ãããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
No.10ãKMSã¸ã®ã¢ã¯ã»ã¹å¶å¾¡
æå¾ã«KMSã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ã§ããKMSã¨ã¯ãKey Management Serviceï¼éµç®¡çãµã¼ãã¹ï¼ã®ç¥ã§ããã¡ã¤ã«ãªã©ãæå·åããããã®æå·éµã®çæã使ç¨ããã¼ãã¼ã·ã§ã³ãç ´æ£ãªã©ãè¡ãããµã¼ãã¹ã§ããKMSã®æå·éµã¸ã®ã¢ã¯ã»ã¹ã¯ãå¿ è¦æå°éã«å¶éããå¿ è¦ãããã¾ãã
ç´°ããã¯ä»¥ä¸ã®ãµãè¦ä»¶ã«åé¡ããã¾ãã
- ã»KMSæå·éµã¸ã®ã¢ã¯ã»ã¹å¶å¾¡
- ã»KMSæå·éµã®ãã¼ãã¼ã·ã§ã³
CIS Benchmarksã«ãããæ¨å¥¨çã¯ä»¥ä¸ã®éãã§ããï¼æ«å°¾ã«ãããã¡ã¤ã«ã»è©ä¾¡ã¹ãã¼ã¿ã¹ãè¨è¼ï¼
ãµãè¦ä»¶ | IAMæ¨å¥¨ç |
---|---|
KMSæå·éµã¸ã®ã¢ã¯ã»ã¹ã®å¶é | GCPã1.9ãCloud KMSæå·éµãå¿åã¢ã¯ã»ã¹ã¾ãã¯ãããªãã¯ã¢ã¯ã»ã¹ãå¯è½ã§ãªããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
KMSæå·éµã®ãã¼ãã¼ã·ã§ã³ | GCPã1.10ãKMSæå·éµã90æ¥ä»¥å ã«ãã¼ãã¼ã·ã§ã³ããããã¨ã確èªããï¼ã¬ãã«1ï½¥èªååï¼ |
ã¾ã¨ã
ç¹°ãè¿ãã«ãªãã¾ãããCIS Benchmarksã«ãããAWSãAzureãGCPãOCIã®å ±éçãªIAMè¦ä»¶ããã10ã¯ä»¥ä¸ã®çµæã§ããã
大ã¾ãã«ä»¥ä¸ã®ããã«ã¾ã¨ãããã¾ãã
- ã»No.1ã2ã3ã6ã9ï¼å¤è¦ç´ èªè¨¼ã®å°å ¥ã管çè 権éã®æå°åããã¹ã¯ã¼ãããªã·ã¼ã®è¨å®ãã°ã«ã¼ãã«åºã¥ãã¢ã¯ã»ã¹æ¨©éè¨å®ãã¢ã«ã¦ã³ãã®ã¬ãã¥ã¼ï¼ã¯IAMã«ããã¦ããããè¦ä»¶ã§ããããã¯ã¤ã¡ã¼ã¸ãããããã¼ãã ã¨æãã¾ãã
- ã»No.4ã5ï¼æå°éã®ãã®ä»èªè¨¼æ å ±ããã®ä»èªè¨¼æ å ±ã®ãã¼ãã¼ã·ã§ã³ï¼ã¯ã¢ã¯ã»ã¹ãã¼ãAPIãã¼ããµã¼ãã¹ã¢ã«ã¦ã³ããªã©ãIDã»ãã¹ã¯ã¼ã以å¤ã®èªè¨¼æ å ±ã対象ã¨ãã¦ãããæ®æ®µæèãã¥ãããã¼ãã ã¨æãã¾ããèªè¨¼æ å ±ã«ã¯æ§ã ãªç¨®é¡ãããããããã«ãã³ã³ããã¼ã«ãå¿ è¦ã§ãããã¨ã示ãã¦ãã¾ãã
- ã»No.7ï¼ã¯ã©ã¦ããµã¼ãã¹ã¨ã®é£çµ¡å ã®ç¶æï¼ã¯IAMã®ç¯å²ã«å ¥ãã®ãå°ã è¿·ãã¾ãããã¯ã©ã¦ããµã¼ãã¹ã¨ã®é©åãã¤ã¹ãã¼ãã£ãªã³ãã¯ã·ã§ã³ãç¶æãããã¨ã¯ç·æ¥æã¸ã®å¯¾å¿ã«ã¯ã¨ã¦ãéè¦ã§ãã
- ã»No.8ã10ï¼ã¢ããªã±ã¼ã·ã§ã³ã¢ã¯ã»ã¹ã®å¶éãKMSã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ï¼ã¯ã¢ããªã±ã¼ã·ã§ã³ããã³éµç®¡çã«ãã³ã³ããã¼ã«ãå¿ è¦ã§ãããã¨ã示ãã¦ãã¾ãã
ããã10ããããã®IAMæ¨å¥¨çãè¦ã¦ã¿ãã¨ãå¿
ããã4ã¤ãã¹ã¦ã®ã¯ã©ã¦ããµã¼ãã¹ãå«ã¾ãã¦ããããã§ã¯ãªããã¨ãåããã¾ããããããããããä¸æ¦ã«ã¯ã©ã¦ããµã¼ãã¹ã®åªå£ã¨æ±ºãã¤ãã¦ãã¾ãã®ã§ã¯ãªããæ§ã
ãªã»ãã¥ãªãã£è¦³ç¹ãå¾ãæ段ã¨èãã¦ã»ãã¥ãªãã£è¨è¨ã«æ´»ç¨ãããã¨ãæã¾ããã§ãã
ãªããæ¬ã³ã©ã ã®å¯¾è±¡ã¯ã¯ã©ã¦ããµã¼ãã¹èªä½ã®IAMã§ããããããã®ä¸ã«æ§ç¯ããä»®æ³ãã·ã³ãã¹ãã¬ã¼ã¸ããã¼ã¿ãã¼ã¹ããããã¯ã¼ã¯ãªã©ã対象ã¨ããã»ãã¥ãªãã£å¯¾çã¯å¥ã«æ¤è¨ããå¿
è¦ãããã®ã§ã注æãã ããã
æå¾ã«ãªãã¾ãããåã¯ã©ã¦ããµã¼ãã¹ã«ããã¦æ©è½è¿½å ã¯æç¶çã«è¡ããã¦ãããCIS Benchmarksãã¾ãä¸å®æã«ãã¼ã¸ã§ã³ã¢ããããã¦ãã¾ããã¾ããã¯ã©ã¦ãå©ç¨ä¼æ¥ã«ããã¦ãæ¥ã
ãæ©è½è¿½å ãå¤æ´ãå ãã¦ãããã¨ã¨æãã¾ãã
ãã®ããã¯ã©ã¦ããµã¼ãã¹ã«ããã¦ã»ãã¥ãªãã£å¯¾çãå®è£
ããå¾ããå®æçã«ãã®å¦¥å½æ§ã確èªãããã¨ãæã¾ããã§ãã4大ã¯ã©ã¦ããããããæä¾ããã»ãã¥ãªãã£è¨å®è¨ºææ©è½ããå°éæ¥è
ã®ã¯ã©ã¦ãè¨å®è¨ºæãµã¼ãã¹ãæ´»ç¨ãããã¨ãæå¹ã§ãã
åèè³æ
- [1]Center for Internet Security CIS Benchmarks
- [2]CISãCIS_Amazon_Web_Services_Foundations_Benchmark_v1.5.0ã
- [3]CISãCIS_Microsoft_Azure_Foundations_Benchmark_v1.5.0ã
- [4]CISãCIS_Google_Cloud_Platform_Foundation_Benchmark_v1.3.0ã
- [5]CISãCIS_Oracle_Cloud_Infrastructure_Foundations_Benchmark_v1.1.0ã
- [6]CISãCIS Critical Security Controls® Version 8ã
â»æç« ä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã