å®è·µï¼ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ï½ãããã誤解ã¨æ£ããç解ï½
1. ã¯ããã«
2019å¹´ã«æ°åã³ããã¦ã¤ã«ã¹ææçï¼COVID-19ï¼ãæµè¡ãã¦ããããã¼ããã©ã¹ããã¨ããè¨èãé常ã«ããè³ã«ããããã«ãªãã¾ããããã ãå½æã¯åãã¼ããã©ã¹ãã¨ããè¨èã使ã£ã¦ãã¦ãããã®æå³ã¯å°é家ããã³ãã¼ã«ããç°ãªã£ã¦ãããããºã¯ã¼ãã¨ãã¦ã®å´é¢ãå¼·ãã£ãããã«æãã¾ãã
2020å¹´ã«ç±³å½å½ç«æ¨æºæè¡ç 究æï¼NISTï¼ãSP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ããçºè¡ããé ãããå°ããã¤ã¼ããã©ã¹ãã¨ããè¨èãåãæå³ã§ï¼å
±éè¨èªã¨ãã¦ï¼ä½¿ããããã«ãªã£ã¦ãã¾ããã
2023å¹´ç¾å¨ãã¼ããã©ã¹ãã¯ããºã¯ã¼ããä¸éæ§ã®ãã¬ã³ãã¨ãã¦ã ãã§ãã®å½¹å²ãçµãããã¨ãªãããµã¤ãã¼ã»ãã¥ãªãã£ã«ãããæ°ããªååã¨ãã¦ãçå®ã«æµ¸éãã¦ãã¦ãã¾ãã
ããããªãããã¼ããã©ã¹ãã¯æ¦å¿µã§ããç¹å®ã®æè¡ã製åãæå³ãããã®ã§ã¯ãªããã¨ãããä»ã®ç¨èªã¨æ¯ã¹ãã¨æ£ç¢ºãªç解ãé£ããã誤ã£ãç解ã説æãªã©ãæ£è¦ããã¾ãã
æ¬ã³ã©ã ã§ã¯ãã¼ããã©ã¹ãã«é¢ãããããã誤解ããã¼ãã«ãæ£ããç解ã¨å¯¾æ¯ããªãããã¼ããã©ã¹ããããæ·±ãç解ããã ããã¨ãç®æãã¦ããããã¨æãã¾ãã
å³1ï¼ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®å¤é·
2. ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ã®ãããã誤解
åè¿°ã®éããã¼ããã©ã¹ãã¯æ½è±¡åº¦ã®é«ãç¨èªã§ãããããå¿ ç¶çã«ãã¾ãã¾ãªèª¤è§£ãçºçããããã¨èãããã¾ããæ¬ã³ã©ã ã§ã¯ãçè ãå®éã«è¦èããããã¨ã®ãã以ä¸4ç¹ã®èª¤è§£ã«ã¤ãã¦ãåãä¸ãã¦ããã¾ãã
- ã»ãã¼ããã©ã¹ãé¢é£ã®è£½åãå°å ¥ããã°ãããã ãã§ã¼ããã©ã¹ããå®ç¾ã§ãããã¨ãã誤解
- ã»ãã¼ããã©ã¹ãã¨å¢çãã¼ã¹ã®ã»ãã¥ãªãã£ï¼å¢çåé²å¾¡ï¼ã¯ãã©ã¡ããä¸æ¹ãé¸æããªããã°ãªããªããã¨ãã誤解
- ã»ãã¼ããã©ã¹ãã¯ã社å åãã®ã·ã¹ãã ï¼OAç°å¢ï¼ã®ã¿ã対象ã«ãã¦ãããã¨ãã誤解
- ã»ãã¼ããã©ã¹ãã§ã¯ãIPã¢ãã¬ã¹ã«ããã¢ã¯ã»ã¹å¶å¾¡ãè¡ã£ã¦ã¯ãªããªããã¨ãã誤解
3. ãããã誤解ã¨æ£ããç解
ããã§ã¯ãããããæ¬é¡ã§ããæ¬ç« ã§ã¯ãåè¿°ã®ãããã誤解4ç¹ãä¸ã¤ãã¤åãä¸ããNIST SP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãï¼ä»¥ä¸ãNIST ZTAï¼ãªã©ãåèã«ããªããããªã誤解ã¨ãããã®ããã©ã®ããã«ç解ããã®ãæ£ããã®ãã解説ãã¦ããã¾ãã
1ç¹ç®ã¯ããã¼ããã©ã¹ãé¢é£ã®è£½åãå°å
¥ããã°ãããã ãã§ã¼ããã©ã¹ããå®ç¾ã§ãããã¨ãã誤解ã§ãã
NIST ZTAã§ã¯ãã¼ããã©ã¹ãããæ¦å¿µã¨ã¢ã¤ãã¢ã®éåä½ãã¨å®ç¾©ãã¦ãã¾ãããã®æ¦å¿µãã¢ã¤ãã¢ãå
·ç¾åããããã«ãä½ããã®è£½åãå¿
è¦ã«ãªãã±ã¼ã¹ãå¤ãã®ã¯ç¢ºãã§ãããã ããã¨ãã£ã¦ãåã«è£½åãå°å
¥ããã°è¯ãã¨ããçµè«ã«ã¯ãªãã¾ããã
çµå±ã®ã¨ããã製åã®å°å
¥ã¯æ段ã§ããç®çã§ã¯ãªããã¨ãããèªçµç¹ãã¼ããã©ã¹ãã§è§£æ±ºããã課é¡ãç®çãæ£ããèªèãã製åã®å°å
¥ã¯ããã¾ã§ã課é¡è§£æ±ºãç®çãéæããããã®æ段ã®ä¸ã¤ã§ãããã¨ãç解ãã¦ããå¿
è¦ãããã¾ãã
ãã ã以åã¨ã¯ç°ãªãç¹ã¨ãã¦ãããæ°å¹´éã§ã¼ããã©ã¹ãé¢é£ã®è£½åãæçãã¦ãã¦ãããæ°æ©è½ã®è¿½å ãã¢ãããã¼ããç¹°ãè¿ããã¨ã§ãåä¸ãã³ãã¼ã®è£½åã§ã«ãã¼ã§ããç¯å²ãåºããã¤ã¤ããï¼æ段ãå°ããã¤å¤åãã¦ãã¦ããï¼ã¨ããç¶æ³ã¯ç解ãã¦ããã¨è¯ãã§ãããã
å³2ï¼è£½åå°å ¥ã«é¢ãã誤解
2ç¹ç®ã¯ããã¼ããã©ã¹ãã¨å¢çãã¼ã¹ã®ã»ãã¥ãªãã£ï¼å¢çåé²å¾¡ï¼ã¯ãã©ã¡ããä¸æ¹ãé¸æããªããã°ãªããªããã¨ãã誤解ã§ãã
NIST ZTAã§ã¯ã大ãã2ã¤ã®ã¢ã¼ããã¯ãã£ï¼ç´ç²ãªã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ã¨ããã¤ããªããã»ã¢ã¼ããã¯ãã£ï¼ãç´¹ä»ããã¦ãã¾ããããç´ç²ãªã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãå®è¡å¯è½ãªãªãã·ã§ã³ã¨ãªããã¨ã¯ã»ã¨ãã©ãªããã¨è¿°ã¹ããã¦ãã¾ãã
SASEâ»ã«ä»£è¡¨ãããããã«ãã¼ããã©ã¹ãé¢é£ã®è£½åã¯ã¯ã©ã¦ããµã¼ãã¹ã¨ãã¦æä¾ããããã¨ãä¸è¬çã§ãããã®ããããªã³ãã¬ãã¹ã®ãã¼ã¿ã»ã³ã¿ã¼ãå°ç¨ç·ãªã©ãå©ç¨ãã¦ããçµç¹ããä¸è¶³é£ã³ã«ç´ç²ãªã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ã¸ç§»è¡ãããã¨ãã¦ãã¾ãã¨ãæ§æãè¤éã«ãªããææªã®å ´åãããã©ã¼ãã³ã¹ãçç£æ§ãä½ä¸ãã¦ãã¾ãå¯è½æ§ãããã¾ãã
ã¯ã©ã¦ãã®æèã«ããã¦ãã¯ã©ã¦ãããªã³ãã¬ãã¹ãã¨ããäºè
æä¸ã§ã¯ãªããã¤ããªããã¨ããé¸æè¢ãããããã«ãã¼ããã©ã¹ãã«ããã¦ãããã¤ããªããã¨ããé¸æè¢ããããã¨ãç解ãã¦ããå¿
è¦ãããã¾ãã
- â»Secure Access Service Edgeã®ç¥ã2019å¹´ã«ç±³ã¬ã¼ããã¼ç¤¾ãæå±ããããããã¯ã¼ã¯æ©è½ã¨ã»ãã¥ãªãã£æ©è½ãçµ±åãã¦ã¯ã©ã¦ãä¸ã§æä¾ããããµã¼ãã¹ã
å³3ï¼ã¢ã¼ããã¯ãã£é¸æã«é¢ãã誤解
3ç¹ç®ã¯ããã¼ããã©ã¹ãã¯ã社å
åãã®ã·ã¹ãã ï¼OAç°å¢ï¼ã®ã¿ã対象ã«ãã¦ãããã¨ãã誤解ã§ãã
æ¬ã³ã©ã ã®åé ã§ãè¿°ã¹ãéããã¼ããã©ã¹ãã¯2019å¹´é ããä¸æ°ã«æ³¨ç®åº¦ãé«ã¾ããåãæ¹æ¹é©ããã¬ã¯ã¼ã¯ç°å¢ã¸ã®é©ç¨ã代表çãªã¦ã¼ã¹ã±ã¼ã¹ã¨ãã¦æ®åãã¦ãã¾ããã
ããããªãããã¼ããã©ã¹ãããã¬ã¯ã¼ã¯ç°å¢ãªã©ã®OAç°å¢ãã対象ã«ã§ããªããã¨ããã¨ããã§ã¯ãªãã顧客åãã®ã·ã¹ãã ï¼åç¨ç°å¢ï¼ã対象ã«ãããã¨ãã§ãã¾ããï¼OAç°å¢ã¨åç¨ç°å¢ã®å¤§ã¾ããªéãã¯ãå³4ãåç
§ãã¦ãã ããï¼
ãªãããã®ç¹ã¯NIST ZTAã§ããå°å
¥ã·ããªãªï¼ã¦ã¼ã¹ã±ã¼ã¹ãã¨ãã¦ç´¹ä»ããã¦ãã¾ããã¾ãã2023å¹´4æã«ã¯NISTãããSP 800-207A (Draft)ãA Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environmentsï¼è¨³æ³¨ï¼ãã«ãã¯ã©ã¦ãç°å¢ã«ãããã¯ã©ã¦ããã¤ãã£ãã¢ããªã±ã¼ã·ã§ã³ã®ã¢ã¯ã»ã¹å¶å¾¡ã®ããã®ã¼ããã©ã¹ãã¢ã¼ããã¯ãã£ã¢ãã«ï¼ãã¨ããææ¸ãå
¬éããã¦ããã®ã§ãåèã«ãã¦ã¿ãã®ãè¯ãã§ãããã
å³4ï¼ã¼ããã©ã¹ãã®ã¹ã³ã¼ãã«é¢ãã誤解
4ç¹ç®ã¯ããã¼ããã©ã¹ãã§ã¯ãIPã¢ãã¬ã¹ã«ããã¢ã¯ã»ã¹å¶å¾¡ãè¡ã£ã¦ã¯ãªããªããã¨ãã誤解ã§ãã
çããããåãã®éããã¼ããã©ã¹ãã¯å¢çåé²å¾¡ã¨å¯¾æ¯ãã¦èª¬æããããã¨ãé常ã«å¤ãããã¾ããã¾ããå¢çåé²å¾¡ã¨ã¯ç°ãªããç¹å®ã®ãããã¯ã¼ã¯ï¼IPã¢ãã¬ã¹ï¼ãæé»çã«ä¿¡é ¼ããªãã¨ããç¹å¾´ãããã¾ãããããã®èæ¯ãããã¼ããã©ã¹ãã§ã¯ãIPã¢ãã¬ã¹ã«ããã¢ã¯ã»ã¹å¶å¾¡ã¯ä¸åè¡ã£ã¦ã¯ãªããªãã¨èª¤è§£ããã¦ããã±ã¼ã¹ãããã¾ãã
NIST ZTAã§ã¯ããã©ã¹ãã¢ã«ã´ãªãºã ï¼ãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹å¯å¦ã決å®ããããã®ããã»ã¹ï¼ã¸ã®å
¥åã®ä¸ã¤ã¨ãã¦ãä½ç½®ï¼ãããã¯ã¼ã¯ã®ä½ç½®ã¨ã¸ãªãã±ã¼ã·ã§ã³ï¼ãå«ã¾ãã¦ãã¾ãããã®ãã¨ãããã¼ããã©ã¹ãã§ã¯ãIPã¢ãã¬ã¹ã ãã§ãéçã«ã¢ã¯ã»ã¹å¶å¾¡ãè¡ãã®ã§ã¯ãªããIPã¢ãã¬ã¹ãå«ããå¯è½ãªéãå¤ãã®æ
å ±ãããåçã«ã¢ã¯ã»ã¹å¶å¾¡ãè¡ããã¨ãæã¾ããã¨ç解ããã®ãè¯ãã§ãããã
å³5ï¼IPã¢ãã¬ã¹ãç¨ããå¶å¾¡ã«é¢ãã誤解
4. ãããã«
æ¬ã³ã©ã ã§ã¯ãã¼ããã©ã¹ãã«é¢ãããããã誤解ããã¼ãã«ãæ£ããç解ã¨å¯¾æ¯ããªãããã¼ããã©ã¹ããããæ·±ãç解ããã ããã¨ãç®æãã¦ãã¾ããã
ã©ãã»ã©æç¨ãªèãæ¹ãæè¡ã§ãã£ã¦ãã使ãæ¹ã誤ãã¨é©åãªå¹æãå¾ãããªãã ãã§ãªããçµç¹ã«ãã¬ãã£ããªå½±é¿ãä¸ãã¦ãã¾ã£ãããã»ãã¥ãªãã£ã«é¢ããå
容ã§ããã°ãææªã®å ´åãã¤ã³ã·ãã³ãã®çºçã«ç¹ãã£ã¦ãã¾ã£ããã¨ãã£ããªã¹ã¯ãããã¾ãã
æ°å¹´åã¨æ¯ã¹ãã¨ã¼ããã©ã¹ãã®æ®åãé²ã¿ãå®éã«ã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãæ¡ç¨ããã·ã¹ãã ãæ°å¤ãè¦ãããããã«ãªãã¾ãããã¾ããæ¿åºæ©é¢ã«ããã¦ãããã¸ã¿ã«åºããã¯ãã¼ããã©ã¹ãã¢ã¼ããã¯ãã£é©ç¨æ¹éããå ¬éãããç±³å½ã§ã¯ãZero Trust Maturity Model Version 2.0ï¼è¨³æ³¨ï¼ã¼ããã©ã¹ãæç度ã¢ãã«2.0ï¼ãããDepartment of Defense Zero Trust Reference Architectureï¼è¨³æ³¨ï¼å½é²ç·çã¼ããã©ã¹ããªãã¡ã¬ã³ã¹ã¢ã¼ããã¯ãã£ï¼ããªã©ã®ã¼ããã©ã¹ãã«é¢ããææ¸ã次ã ã¨å ¬éããã¦ãã¾ãã
ä»å¾ãã¼ããã©ã¹ãã¯ã»ãã¥ãªãã£ãèããããã§ã®å¸¸èãååã¨ãã¦å®çãããããããã®è¨èã使ããã¨ããå°ãªããªã£ã¦ããã®ããããã¾ãããããããªãããå¤æ§åã»å·§å¦åãããµã¤ãã¼æ»æã«å¯¾æããããã«ããã®èãæ¹ãé常ã«æç¨ã§ãããã¨ã¯ãããç°¡åã«ã¯å¤ãããªãã§ãããã
æ¬ã³ã©ã ã®å 容ããå°ãã§ãçæ§ã®å¤§åãªæ å ±è³ç£ãå®ãããã®ãã³ãã«ãªãã°å¹¸ãã§ãã
é¢é£ãªã³ã¯
INTELLILINK ã¼ããã©ã¹ãã»ã»ãã¥ãªãã£ãµã¼ãã¹
åèæç®
- [1]NIST SP 800-207ãã¼ããã©ã¹ãã»ã¢ã¼ããã¯ãã£ãï¼ç¬ç«è¡æ¿æ³äººæ
å ±å¦çæ¨é²æ©æ§ï¼
https://www.ipa.go.jp/security/reports/oversea/nist/about.html - [2]The Future of Network Security Is in the Cloudï¼Gartner, Inc.ï¼
- [3]NIST SP 800-207A (Draft)ãA Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environmentsãï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼
https://csrc.nist.gov/publications/detail/sp/800-207a/draft - [4]DS-210 ã¼ããã©ã¹ãã¢ã¼ããã¯ãã£é©ç¨æ¹éï¼ãã¸ã¿ã«åºï¼
https://www.digital.go.jp/resources/standard_guidelines/#security - [5]Zero Trust Maturity Model Version 2.0ï¼ç±³å½ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ã»ãã¥ãªãã£åºï¼
https://www.cisa.gov/zero-trust-maturity-model - [6]Department of Defense Zero Trust Reference Architectureï¼ç±³å½å½é²ç·çï¼
https://dodcio.defense.gov/Portals/0/Documents/Library/(U)ZT_RA_v2.0(U)_Sep22.pdf
- â»æä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã