ãŒããã©ã¹ããæ¯ãããã¯ãããžãŒãç¹å®ãã
åŠç¿ã®ç®ç
ãã®åå ãå®äºãããšã次ã®ããšãã§ããããã«ãªããŸãã
- æ¢åã®ãã¯ãããžãŒã掻çšã㊠ZT ã»ãã¥ãªãã£ã¢ãã«ãå®è£ ããæ¹æ³ãç¹å®ããã
- ZT ã»ãã¥ãªãã£ã¢ãã«ãå®è£ ããéã«äžå¯æ¬ ãªã¢ã»ãããç¹å®ããããšã®éèŠæ§ã説æããã
- ZT ã»ãã¥ãªãã£ã¢ãã«ã«ãããŠããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãID ãšã¢ã¯ã»ã¹ç®¡ç (IAM)ãæå°æš©éã®ååãããã€ã¹ã¢ã¯ã»ã¹å¶åŸ¡ãªã©ãå®è£ ããæ¹æ³ã説æããã
æ¢åã®ãã¯ãããžãŒã䜿çšãããŒããã©ã¹ãã»ãã¥ãªãã£ã®å®è£
ãŒããã©ã¹ã (ZT) ã¯æ°ããããã«æãããããããŸããããå®éã«ã¯ãçµç¹ã¯ ZT ã»ãã¥ãªãã£ã¢ãã«ãæ¯ããå€ãã®ãã¯ãããžãŒã以åãã䜿çšããŠããŸãããŸããçŸæç¹ã§ããã«äœ¿çšã§ããã³ã³ãããŒã«ã»ããã«ã€ããŠæ€èšããŸããZT ã§ãã䜿çšããããã¯ãããžãŒãããã€ãèŠãŠã¿ãŸããããÂ
ZT å®è£ ã«åªå é äœãä»ãã
ZT ã¢ãŒããã¯ãã£ã§ã¯ãæå·åããããã©ãã£ãã¯ãªã©ãçµç¹ã®ãŠãŒã¶ãŒãšãã©ãã£ãã¯ãå¯èŠåããå¶åŸ¡ããå¿ èŠããããŸããæåã®é çªã§ ZT å°å ¥ã®åªå 床ä»ããè¡ãã«ã¯ãã»ãã¥ãªãã£ã®åŒ·åã«ãã£ãŠæ»æé¢ãæå°åãããéèŠãªããŒã¿ãšãµãŒãã¹ã®ç¹å®ããå§ãããšããã§ãããããŸããçµç¹ã®æãéèŠãªããŒã¿ãã¢ã»ãããã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãç¹å®ããå¿ èŠããããŸããããã«ãããæ»æé¢ (æªæ¿èªã®ãŠãŒã¶ãŒãã·ã¹ãã ã«ã¢ã¯ã»ã¹ããŠããŒã¿ãæœåºããããšãå¯èœãªããã¹ãŠã®èãããããã€ã³ã (æ»æãã¯ãã«) ã®æ°) ãããæ·±ãçè§£ã§ããŸãããŸããã©ãããã³ã³ãããŒã«ã®å®è£ ãéå§ãã¹ããåªå é äœãä»ããZT ã»ãã¥ãªãã£ããªã·ãŒãäœæã§ããŸãã
ãŒããã©ã¹ãã»ãã¥ãªãã£ãå®è£ ãã
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³
ZT ããŒã«ããã¯ã¹ã®éèŠãªããŒã«ã¯ããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã§ãããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãåŸæ¥ã®ãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ãããäžæ©é²ãã§ããµãŒããŒãããµãŒããŒãã¢ããªã±ãŒã·ã§ã³ãããµãŒãã¹ããŠãŒã¶ãŒããã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãã©ãã£ãã¯ã«ä¿è·ã¬ã€ã€ãŒã远å ãããŠããŸããåãšå ã«äŸãããšãå€éšãããã¯ãŒã¯ã®å¢çã¯åã®åãå£ãšåºãå ã§ãããå éšãããã¯ãŒã¯ã¯ããã¢ã®åã«è¡å µãç«ã£ãŠããéšå±ã§ãã

ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ããšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ãç¬èªã®ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãšã²ãŒããŠã§ã€ãæã€ã»ã°ã¡ã³ãã»ããã«ããããåå²ããã»ãã¥ãªãã£ãã¯ãããžãŒã§ãã
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã§ã¯ãã»ãã¥ãªãã£ã¢ãŒããã¯ããçµç¹ã®ããŒã¿ã»ã³ã¿ãŒãåã ã®ã¯ãŒã¯ããŒãã»ã°ã¡ã³ãã«åå²ããã¯ãŒã¯ããŒãããšã«ã»ãã¥ãªãã£ã³ã³ãããŒã«ãå®çŸ©ããŸããZT ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãç°å¢ã«é¢ä¿ãªããæ»æè ãæ¿èªãããŠããªãæ¥ç¶ã䜿çšãã䟵害ãããã¢ããªã±ãŒã·ã§ã³ãã·ã¹ãã ãä»ããŠæšªæ¹åã«ç§»åããããšãé²ããŸããäŸµå ¥ã被害ã¯å¯èœãªéãå°ããªå¯Ÿè±¡é åã«æããããæ»æè ã¯äŸµå®³ãããã¢ã»ããã䜿çšããŠå¥ã®ã¢ã»ããã«ã¢ã¯ã»ã¹ããããšãã§ããªããªããŸãã
ID ãšã¢ã¯ã»ã¹ç®¡ç
ã¯ãŒã¯ããŒããã»ã°ã¡ã³ãåããããæ¬¡ã¯ãã®ã¯ãŒã¯ããŒããžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸããããZT ã§ã¯ãã¢ã¯ã»ã¹ã³ã³ãããŒã«ãå¢çããåã ã®ããã€ã¹ãšãŠãŒã¶ãŒã«ç§»è¡ãããŸããID 㯠ZT ã®åå°ã§ããããããã¹ãŠã®ãŠãŒã¶ãŒãšããã€ã¹ã«ã€ããŠãçµç¹å ã§æãã圹å²ãšå ±ã«ãã® ID ã確èªããå¿ èŠããããŸãã
ID ãšã¢ã¯ã»ã¹ç®¡ç (IAM) ãœãªã¥ãŒã·ã§ã³ã§ã¯ãçµç¹ã ZT ãžã£ãŒããŒã§éå§ããããã®ã³ã¢ãã¯ãããžãŒãæäŸãããŸããIAM ã·ã¹ãã ã§ã¯ ID ã®æ€èšŒãšæš©éã®å¶åŸ¡ãè¡ãããŸããIAM ã䜿çšããããšã§ããŠãŒã¶ãŒã誰ã§ããããã¢ã¯ã»ã¹æš©ãååŸããããšããéã«ã©ã®ããã€ã¹ã䜿çšããããäœãèš±å¯ãããŠããããªã©ã®èŠçŽ ã«åºã¥ããŠæš©éãå²ãåœãŠãããšãã§ããŸãã
IAM ãå®è£ ããã«ã¯ãå®å šã§äžè¬çãªçµ±å ID 管çã·ã¹ãã ãäœæããããID ãããã€ã㌠(IdP) ã䜿çšããããšããå§ããŸããIdP ã¯ãçµç¹ã® ID 管çãäžå åãã€ç°¡çŽ åãããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãã¯ãããžãŒãšçµ±åããå Žåã«åœ¹ç«ã¡ãŸãããŸããIdP ã䜿çšãããšãSecurity Assertion Markup Language (SAML) ãæå¹ã«ããŠãã¢ã¯ã»ã¹ãåçåããããšãã§ããŸããSAML ãšã¯ããŠãŒã¶ãŒã 1 ã€ã®ãã°ã€ã³æ å ±ã»ããã䜿çšããŠè€æ°ã® Web ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ããæšæºã§ããIAM ã®è©³çްã«ã€ããŠã¯ããCenter for Internet Security ã®éèŠãªã»ãã¥ãªãã£ã³ã³ãããŒã«ãã¢ãžã¥ãŒã«ãåç §ããŠãã ããã
å€èŠçŽ èªèšŒ
ãŠãŒã¶ãŒãšã¢ã»ãããç¹å®ãããã®ã¢ã¯ã»ã¹ã管çãã IAM ã·ã¹ãã ãå®è£ ããããæ¬¡ã¯ã¢ã¯ã»ã¹ãå®å šãªæ¹æ³ã§èªèšŒãããŠããããšãæ€èšŒããå¿ èŠããããŸããçäœèªèšŒãã¯ã³ã¿ã€ã ã³ãŒããªã©ããã¹ã¯ãŒã以å€ã®å€èŠçŽ èªèšŒ (MFA) æ¹æ³ãå®è£ ããããšããZT ãå®çŸããéµãšãªããŸããÂ
ãã¹ããã©ã¯ãã£ã¹ã¯ãMFA ãå°å ¥ããŠããŠãŒã¶ãŒãããã€ã¹ãä¿è·ãããããŒã¿ãžã®ã¢ã¯ã»ã¹ãèŠæ±ãããã³ã« ID 確èªãè¡ãããšã§ãããããã¯ãŒã¯ã»ãã¥ãªãã£ã«å¯ŸããåŸæ¥ã®ã¢ãããŒãã§ã¯ãæåã®ãããã¯ãŒã¯ãã°ã€ã³æã«ã¢ã¯ã»ã¹ãèªèšŒããŠæ¿èªããããšã«éç¹ã眮ãããŠããŸãããZT ã§ã¯ããããã¯ãŒã¯å¢çãä¿è·ãããšããæŠå¿µãè¶ ããæœåšçãªè åšãç¹å®ããããã®ãªã¹ã¯ããŒã¹ã®é©å¿åè©äŸ¡ãä»ããŠãç¶ç¶çã«ã¢ã¯ã»ã¹ãèªèšŒããŠæ¿èªããããšã«éç¹ã眮ãããŠããŸããÂ
ãã¹ãŠã®ã¢ã¯ã»ã¹èŠæ±ã¯ãã¢ã¯ã»ã¹æš©ãä»äžããåã«ãå®å šã«èªèšŒãæ¿èªãæå·åãããå¿ èŠããããŸãããã®ããã«èªèšŒãç¹°ãè¿ãããããšã§ãäŸµå ¥ãæ©å¯æ å ±ãžã®ã¢ã¯ã»ã¹ã鲿¢ãã(äŸµå ¥ãããå Žåã§ã) 暪æ¹åãžã®ç§»åããããã¯ããŠè¢«å®³ã軜æžã§ããŸãã
詳现ãªãªãœãŒã¹ã¢ã¯ã»ã¹å¶åŸ¡
ããã§ããŠãŒã¶ãŒãããã€ã¹ã®ã¢ã¯ã»ã¹ãšèªèšŒã管çããããã®ã·ã¹ãã ãæŽåã§ããŸãããZT ã»ãã¥ãªãã£ã¢ãã«ã®æ¬¡ã®ã¹ãããã¯ãé©åãªã¢ã¯ã»ã¹æš©ãä»äžããããã®éæè¡çããªã·ãŒãšæè¡çããªã·ãŒãå®è£ ããããšã§ãããã®ãããªããªã·ãŒã¯ããŠãŒã¶ãŒã® IDãã¢ã¯ã»ã¹ã詊ã¿ãããã€ã¹ (ã¢ãã®ã€ã³ã¿ãŒããã (IoT) ããã€ã¹ãå«ã)ãããã«æ¥æãå°çäœçœ®æ å ±ã䜿çšãã¿ãŒã³å±¥æŽãããã€ã¹ãã¹ãã£ãŒãªã©ã®ãã®ä»ã®ã³ã³ããã¹ãããŒã¿ã«åºã¥ããŠããŸããéæè¡çãªããªã·ãŒã¯ãçµç¹ãã¢ã»ãããä¿è·ããæ¹æ³ãåŸæ¥å¡ã«æžé¢ã§èª¬æãããã®ã§ãããŸããZT ã»ãã¥ãªãã£ã¢ãã«ãå®è£ ããéã®åœ¹å²ãšè²¬åããã¹ãŠã®ãŠãŒã¶ãŒã«ç¢ºå®ã«çè§£ãããéµãšãªããŸãã
æè¡çããªã·ãŒã¯ãäžè¬çã«ããããã¯ãŒã¯å ã§äœãã§ããŠäœãã§ããªãããšããã³ã³ããã¹ããå®çŸ©ããããã«ãã»ãã¥ãªãã£ã³ã³ãããŒã«ãä»ããŠå®è£ ãããæš©éä»äžãšé©çšã®ã¡ã«ããºã ã§ããçµç¹ã¯ãããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹ã³ã³ãããŒã« (RBAC) ãŸãã¯å±æ§ããŒã¹ã®ã¢ã¯ã»ã¹ã³ã³ãããŒã« (ABAC) ã«ãã£ãŠæè¡çã«å®è¡ããã詳现ãªãªãœãŒã¹ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãé©çšããŠãæ©å¯æ§ã®é«ãã·ã¹ãã ãããŒã¿ãä¿è·ããããšãã§ããŸãã
æå°æš©é
æè¡çããªã·ãŒã«ã¯ãæå°æš©éã®ååãå®è£ ããããšã«ããã¢ã¯ã»ã¹ã®å¶éãå«ãŸããŸããæå°æš©éãšã¯ãæ©èœãå®è¡ããããã«å¿ èŠãªã¢ã¯ã»ã¹ã®ã¿ãæäŸããããšãæå³ããŸããããšãã°ããããŠãŒã¶ãŒã®ã¢ã«ãŠã³ãã䟵害ãããå Žåãæå°æš©éã«ãã£ãŠããããã¯ãŒã¯ã®æ©å¯æ§ã®é«ãéšåãžã®ã¢ã¯ã»ã¹ãæå°éã«æãããããã®ã¢ã«ãŠã³ãã«çµç¹ã®å¹ åºãç¯å²ã®ããŒã¿ã«ã¢ã¯ã»ã¹ããããã®åºç¯ãªæš©éãä»äžãããªãããã«ããããšãã§ããŸãã
æå°æš©éãå®è£ ãããšãZT ã»ãã¥ãªãã£ã¢ãã«ã®äž»èŠã³ã³ããŒãã³ãã§ããç¶ç¶çãªæ€èšŒãæå¹ã«ãªããŸããç¶ç¶çãªæ€èšŒã§ã¯ãæåã«ã¢ã¯ã»ã¹æš©ãä»äžãããåŸãäžå®ã®æéãçµéãããšããŠãŒã¶ãŒã¯èªåèªèº«ãåæ€èšŒããããèŠæ±ãããŸãã
ããã€ã¹ã¢ã¯ã»ã¹å¶åŸ¡
ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®å¶åŸ¡ã«å ããŠãZT ã§ã¯ããã€ã¹ã¢ã¯ã»ã¹ã®å³å¯ãªå¶åŸ¡ãå¿ èŠã§ããããã€ã¹ã¢ã¯ã»ã¹å¶åŸ¡ãšã¯ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšããŠããçµç¹å å€ã®ããŸããŸãªããã€ã¹ã®æ°ãç£èŠãããã¹ãŠã®ããã€ã¹ãæ¿èªãããŠããããšã確èªãããã¹ãŠã®ããã€ã¹ã䟵害ãããŠããªãããšãè©äŸ¡ããããšã§ãããã®ããã«ã¯ãããŸããŸãªã¢ã»ãã管çãã¯ãããžãŒã䜿çšããŸãã
èªåãããã¯ãŒã¯æ€åºããŒã«ã¯ããããã¯ãŒã¯ããã€ã¹ (ããã³ã¢ããªã±ãŒã·ã§ã³ãšãŠãŒã¶ãŒ) ã®è©³çްãªã€ã³ãã³ããªãèªåçã«æ€åºãç£èŠã察å¿ä»ããçæããã®ã«åœ¹ç«ã¡ãŸãããã®ãããªããŒã«ã§ã¯ãç¹å®ã®ãããã³ã«ã»ããã䜿çšããŠããããã¯ãŒã¯äžã®æ¥ç¶ããã€ã¹ã® IP ã¢ãã¬ã¹ãããã€ã¹ IDããã³ããŒæ å ±ãã¹ãã£ã³ãããŸãããã®ãããªããŒã«ãèšå®ç®¡çããŒã«ãè匱æ§ç®¡çããŒã«ãšçµ±åãããšããããã¯ãŒã¯äžã®ãã¹ãŠã®ã¢ã»ãããæ¢ç¥ã§ãããé©åã«èªèšŒãèšå®ããããé©çšãããŠããããšã確èªã§ããŸãããã®ãã¯ãããžãŒã䜿çšããããšã§ãã»ãã¥ãªãã£ããŒã ã¯ãããŸã§ç¥ãããŠããªãã£ã (ããããäžæ£ãª) ã¢ã»ãããæ€åºãããã®ã¢ã»ããã«åã ZT ã¢ã¯ã»ã¹ããªã·ãŒãç¶ç¶çã«é©çšã§ããŸãã
ã¢ãã€ã«ããã€ã¹ç®¡ç (MDM) ããŒã«ã¯ãçµç¹ã®æ å ±ãã¯ãããžãŒ (IT) 管çè ãã¢ãã€ã«ããã€ã¹ã§ããªã·ãŒãå¶åŸ¡ãä¿è·ãé©çšããããšãå¯èœã«ããŸãããŸããçµç¹ãå人ææããã€ã¹ (BYOD)ãçµç¹æ¯çµŠããã€ã¹ããŸãã¯ãã€ããªããã¢ãã€ã«ããã€ã¹ã®ãããã®ç°å¢ãéçšããŠãããã«é¢ä¿ãªãã圹ç«ã¡ãŸããã·ã¹ãã 管çè 㯠MDM ã䜿çšããŠãçµç¹ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ãä¿è·ããªããããŠãŒã¶ãŒã«ã¢ãã€ã«çç£æ§ããŒã«ãæ¿èªæžã¿ã¢ããªã±ãŒã·ã§ã³ãæäŸããŸããMDM ã¯ããšã³ããã€ã³ãã«ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ããªãªãŒã¹ããããã«äœ¿çšããããšãã§ããŸãã
ç¶ç¶çãªç£èŠãšæ€èšŒ
ID ãšã¢ã¯ã»ã¹ã¯ç®¡çããããŠãŒã¶ãŒãšããã€ã¹ã®èªèšŒãç¹°ãè¿ãè¡ãããŠããŸãããã ããZT ã§ã¯ããã ãã«ãšã©ãŸãããèªèšŒåŸã®ç£èŠã«ãéç¹ã眮ãããŠããŸãã
ZT ã¢ãŒããã¯ãã£ã§ã¯ãçµç¹ã¯ãŠãŒã¶ãŒãšããã€ã¹ã«é©åãªæš©éãšå±æ§ãããããšãç¶ç¶çã«ç£èŠããŠæ€èšŒããå¿ èŠããããŸãããã®ããã«ãçµç¹ã¯è±å¯ãªã€ã³ããªãžã§ã³ã¹ãšåæã䜿çšããŠããªã¢ã«ã¿ã€ã ã§ç°åžžãæ€ç¥ããŠå¯Ÿå¿ããŸããåè¿°ã®è©³çްãªã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒããªã¹ã¯ããŒã¹ã§é©å¿çã«å®è£ ããã«ã¯ããŠãŒã¶ãŒãããã€ã¹ãéèŠãªããã»ã¹ã察象ãšããç£èŠããŒã¿ãªã©ãIT ç°å¢ãŸãã¯ãªãã¬ãŒã·ã§ãã«ãã¯ãããžãŒ (OT) ç°å¢å ã«ãã倿°ã®ãœãŒã¹ããããŒã¿ãåã蟌ãå¿ èŠããããŸãã
ãã®ç£èŠããŒã¿ã®ç®¡çããµããŒãããããã«ãã»ãã¥ãªãã£æ å ±ã€ãã³ã管ç (SIEM) ãæŽ»çšã§ããŸããSIEM ã¯ããŠãŒã¶ãŒãããã€ã¹ããµãŒãã¹ã®ãã°ããŒã¿ãäžå åããŠçžé¢ä»ããããšã§ãäžå¯©ãªæŽ»åãç£èŠã§ããããã«ããããŒã«ã§ãã
ãŸãšã
ãã®ã¢ãžã¥ãŒã«ã§ã¯ãZT ã»ãã¥ãªãã£ã¢ãã«ãçè§£ããŸããããŸããZT ã®æŽå²ãšãã®äž»ãªååã«ã€ããŠåŠç¿ããZT ã»ãã¥ãªãã£ã¢ãã«ã®åºç€ã圢æãããã¯ãããžãŒã«ã€ããŠãåŠã³ãŸããã
次ã®ã¢ãžã¥ãŒã«ãã¯ã©ãŠãã®ãŒããã©ã¹ãã»ãã¥ãªãã£ãã§ã¯ãã¯ã©ãŠãã« ZT ã»ãã¥ãªãã£ã¢ãã«ãå®è£ ããæ¹æ³ãåŠã³ãŸãããŸããZT ãç¶æããããã«å¿ èŠãªç¶ç¶çãªäœæ¥ã«ã€ããŠåŠç¿ããŸãããµã€ããŒã»ãã¥ãªãã£ã®åããŒã«ã«ã€ããŠåŠã³ãã»ãã¥ãªãã£ã®ãããã§ãã·ã§ãã«ã®è©±ãèãå Žåã¯ãTrailhead ã®ãµã€ããŒã»ãã¥ãªãã£ã®åŠç¿ãããåç §ããŠãã ããã
ãªãœãŒã¹
- Trailhead: ãµã€ããŒã»ãã¥ãªãã£ã®è åšã𿻿è
- å€éšãµã€ã: Fortinet: What Is Network Segmentation? (ãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ãšã¯?)
- Trailhead: ãµã€ããŒã»ãã¥ãªãã£ã¢ãŒããã¯ãã£å ¥é
- Trailhead: Center for Internet Security ã®éèŠãªã»ãã¥ãªãã£ã³ã³ãããŒã«
- å€éšãµã€ã: ç±³åœæšæºæè¡å± (NIST): RBAC