ããã«ã¡ã¯ïŒä»æ¥ã®ãã¯ãããžãŒã®äžçã§ã¯ããã¯ã©ãŠãããšããèšèãããè³ã«ããŸãããäŒæ¥ãå人ãããŒã¿ãä¿åããããã¢ããªã±ãŒã·ã§ã³ãå®è¡ãããããããã«ãã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹ã§ãããµãŒããŒããµãŒãã¹ãå©çšããããšãäžè¬çã«ãªããŸããããšãŠã䟿å©ãªã¯ã©ãŠãã§ãããèšå®ãééãããšå€§ããªã»ãã¥ãªãã£ãªã¹ã¯ã«ã€ãªããå¯èœæ§ããããŸããããã§ç»å Žããã®ããã¯ã©ãŠãã»ãã¥ãªãã£ãã¹ãã£ãããžã¡ã³ãïŒCSPMïŒãã§ãããªãã ãé£ããããªååã§ãããå¿é ãããŸããïŒãã®èšäºã§ã¯ãCSPMãäœãªã®ãããªãéèŠãªã®ããåå¿è ã«ãåããããã解説ããŸããð
ð€ CSPMã£ãŠäœïŒ
CSPMã¯ãCloud Security Posture Managementãã®ç¥ã§ãæ¥æ¬èªã§ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£æ å¢ç®¡çããšèš³ãããŸããç°¡åã«èšããšãå©çšããŠããã¯ã©ãŠãç°å¢ïŒAWS, Azure, GCPãªã©ïŒã®èšå®ãå®å šãã©ãããç¶ç¶çã«ãã§ãã¯ããåé¡ãããã°æããŠãããããèªåã§ä¿®æ£ããŠããããããä»çµã¿ãããŒã«ã®ããšã§ãã
ããã¹ãã£ïŒPostureïŒããšã¯ã姿å¢ãããæ å¢ããšããæå³ã§ããã€ãŸããCSPMã¯ã¯ã©ãŠãç°å¢ã®ãã»ãã¥ãªãã£ã®å§¿å¢ãïŒãå®å šãªç¶æ ãä¿ãããŠããããã管çãã圹å²ãæ ã£ãŠããŸããð¡ïž
ç¹ã«ãIaaSïŒInfrastructure as a ServiceïŒãPaaSïŒPlatform as a ServiceïŒãšåŒã°ãããèªåã§ã€ã³ãã©ããã©ãããã©ãŒã ã管çããå¿ èŠãããã¯ã©ãŠããµãŒãã¹ã§éèŠã«ãªããŸãã
ð ãªãCSPMãå¿ èŠãªã®ïŒã¯ã©ãŠãã®èšå®ãã¹ã¯æãïŒ
ã¯ã©ãŠããµãŒãã¹ã¯éåžžã«å€æ©èœã§äŸ¿å©ã§ãããèšå®é ç®ããããããããŸãããã®ãããæå³ããèšå®ãééããŠããŸãããšããããŸããããããèšå®ãã¹ãããèšå®äžåããšåŒã³ãŸãã
äŸãã°ãæ¬æ¥ã¯ç€Ÿå ã ãã§ã¢ã¯ã»ã¹ã§ããããã«ãã¹ãããŒã¿ã¹ãã¬ãŒãžãã誀ã£ãŠã€ã³ã¿ãŒãããå šäœã«å ¬éããŠããŸãèšå®ãã¹ãèããããŸãããã®ãããªãã¹ãèµ·ãããšãæ©å¯æ å ±ãå人æ å ±ãæŒæŽ©ããŠããŸãå¯èœæ§ããããŸããð± å®éã«ãã¯ã©ãŠãã®èšå®ãã¹ãåå ã§å€§èŠæš¡ãªæ å ±æŒæŽ©ãçºçããäºäŸã¯å°ãªããããŸãããäŸãã°ã2022幎ã«ã¯ãããäŒæ¥ãå©çšããŠããã¯ã©ãŠããµãŒãã¹ã®èšå®ãã¹ã«ããã1äžäººä»¥äžã®å人æ å ±ãæŒæŽ©ããå¯èœæ§ãå ±ããããŸããã2023幎ã®Verizonã®èª¿æ»å ±åæžã«ãããšãããŒã¿äŸµå®³ã®åå ã®äžäœ3ã€ã®äžã«èšå®ãã¹ãå«ãŸããŠããŸãã
ã¯ã©ãŠãç°å¢ã¯åžžã«å€åããŠãããæ°ãããµãŒãã¹ãè¿œå ãããããèšå®ãå€æŽããããããŸããæåã§ãã¹ãŠã®èšå®ããã§ãã¯ãç¶ããã®ã¯éåžžã«å°é£ã§ããããã§ãCSPMãèªåã§ç£èŠããŠãããããšã§ãèšå®ãã¹ãæ©æã«çºèŠãããªã¹ã¯ãæžããããšãã§ããã®ã§ãã
âïž CSPMã®äž»ãªæ©èœ
CSPMããŒã«ã«ã¯ãäž»ã«ä»¥äžã®ãããªæ©èœããããŸãã
- ç¶ç¶çãªç£èŠãšå¯èŠå: ã¯ã©ãŠãç°å¢å ã®ãªãœãŒã¹ïŒãµãŒããŒãã¹ãã¬ãŒãžãããŒã¿ããŒã¹ãªã©ïŒãèšå®ãèªåçã«æ€åºããåžžã«ç£èŠããŸããããã«ãããã©ã®ãããªè³ç£ããããã©ã®ããã«èšå®ãããŠããããäžç®ã§ææ¡ã§ããŸãïŒå¯èŠåïŒã
- èšå®ãã¹ã®æ€åº: æ¥çã®ãã¹ããã©ã¯ãã£ã¹ããäŒæ¥ãå®ããã»ãã¥ãªãã£ããªã·ãŒãåœéçãªåºæºïŒPCI DSSãHIPAAãGDPRãISO 27017ãªã©ïŒã«åºã¥ããŠãèšå®ã«åé¡ããªãããèªåã§ãã§ãã¯ããŸãã
- ãªã¹ã¯è©äŸ¡ãšåªå é äœä»ã: èŠã€ãã£ãèšå®ãã¹ãè匱æ§ããã©ããããå±éºãªã®ããè©äŸ¡ãã察å¿ãã¹ãåªå é äœãã€ããŠãããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ç®¡ç: æ¥çãæ³èŠå¶ã®åºæºïŒäŸïŒã¯ã¬ãžããã«ãŒãæ¥çã®PCI DSSãå»çæ å ±ã®HIPAAãªã©ïŒãæºãããŠãããã確èªããã¬ããŒããäœæããŸããç£æ»å¯Ÿå¿ã«ã圹ç«ã¡ãŸãã
- èªå修埩ïŒãªãã·ã§ã³ïŒ: çºèŠãããèšå®ãã¹ãèªåçã«ä¿®æ£ããæ©èœãæã€ããŒã«ããããŸããäŸãã°ãå ¬éèšå®ã«ãªã£ãŠããã¹ãã¬ãŒãžãèªåã§éå ¬éã«æ»ããªã©ã§ããããã«ãããè¿ éãªå¯Ÿå¿ãå¯èœã«ãªããŸãã
- è åšæ€åº: äžå¯©ãªã¢ã¯ãã£ããã£ãäžæ£ã¢ã¯ã»ã¹ã®å åãæ€ç¥ããããšããããŸãã
ð CSPMå°å ¥ã®ã¡ãªãã
CSPMãå°å ¥ããããšã§ã以äžã®ãããªã¡ãªãããæåŸ ã§ããŸãã
ã¡ãªãã | 説æ |
---|---|
ã»ãã¥ãªãã£åŒ·å | èšå®ãã¹ã«ããæ å ±æŒæŽ©ãäžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ãå€§å¹ ã«åæžã§ããŸããGartnerã«ãããšãCSPMããŒã«ã䜿çšããããšã§ãèšå®ãã¹ã«ããã¯ã©ãŠãããŒã¹ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã80%åæžã§ããå¯èœæ§ããããšãããŠããŸãã |
å¯èŠæ§ã®åäž | è€éãªã¯ã©ãŠãç°å¢å šäœãææ¡ãããããªãããã·ã£ããŒITãïŒç®¡çéšéãææ¡ããŠããªãITå©çšïŒãªã©ã®çºèŠã«ãç¹ãããŸãã |
ã³ã³ãã©ã€ã¢ã³ã¹ç¶æ | æ¥çæšæºãæ³èŠå¶ãžã®æºæ ç¶æ³ãç¶ç¶çã«ç¢ºèªã§ããç£æ»å¯Ÿå¿ã®è² æ ã軜æžããŸããã³ã³ãã©ã€ã¢ã³ã¹éåã«ãã眰éãåé¿ããå©ãã«ããªããŸãïŒäŸïŒGDPRéåãªã©ïŒã |
éçšå¹çã®åäž | æåã§ã®ãã§ãã¯äœæ¥ãèªååããããšã§ãã»ãã¥ãªãã£æ åœè ã®è² æ ãæžãããããéèŠãªæ¥åã«éäžã§ããŸããåé¡ã®çºèŠããä¿®æ£ãŸã§ã®æéãççž®ãããŸãã |
è¿ éãªã€ã³ã·ãã³ãå¯Ÿå¿ | åé¡ãæ€åºãããéã«ã¢ã©ãŒãã§éç¥ãããèªå修埩æ©èœãããã°å³åº§ã«å¯Ÿå¿ã§ããããã被害ãæå°éã«æããããŸãã |
â ïž CSPMãšä»ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®éã
ã¯ã©ãŠãã»ãã¥ãªãã£ã«ã¯CSPM以å€ã«ãæ§ã ãªãœãªã¥ãŒã·ã§ã³ããããŸããããã€ã代衚çãªãã®ãšã®éããç°¡åã«èŠãŠã¿ãŸãããã
- CWPP (Cloud Workload Protection Platform): ãµãŒããŒã€ã³ã¹ã¿ã³ã¹ãã³ã³ãããªã©ãåã ã®ãã¯ãŒã¯ããŒããèªäœãä¿è·ããããšã«çŠç¹ãåœãŠãŸãïŒè匱æ§ã¹ãã£ã³ããã«ãŠã§ã¢å¯Ÿçãªã©ïŒãCSPMã¯äž»ã«ã€ã³ãã©ã®èšå®ã察象ãšããŸãããCWPPã¯ã¯ãŒã¯ããŒãå éšã®ä¿è·ãäžå¿ã§ãã
- CASB (Cloud Access Security Broker): ãŠãŒã¶ãŒãšã¯ã©ãŠããµãŒãã¹ã®éã®ã¢ã¯ã»ã¹ãç£èŠã»å¶åŸ¡ããŸããã·ã£ããŒITã®çºèŠããããŒã¿æã¡åºãã®å¶åŸ¡ãªã©ãäž»ãªç®çã§ããCSPMã¯ã€ã³ãã©èšå®ãCASBã¯å©çšè ã®ã¢ã¯ã»ã¹å¶åŸ¡ãäžå¿ã§ãã
- SSPM (SaaS Security Posture Management): SaaSã¢ããªã±ãŒã·ã§ã³ïŒMicrosoft 365, Google Workspace, Salesforceãªã©ïŒã®èšå®ãã¹ãã»ãã¥ãªãã£ãªã¹ã¯ã管çããŸããCSPMã¯äž»ã«IaaS/PaaSã察象ãšããŸãããSSPMã¯SaaSã«ç¹åããŠããŸãã
- CIEM (Cloud Infrastructure Entitlement Management): ã¯ã©ãŠãç°å¢ã«ãããã¢ã¯ã»ã¹æš©éïŒèª°ãäœã«ã¢ã¯ã»ã¹ã§ãããïŒã管çã»æé©åããŸããéå°ãªæš©éãªã©ãæ€åºããŸãã
- CNAPP (Cloud Native Application Protection Platform): CSPM, CWPP, CIEMãªã©ã®æ©èœãçµ±åãããããå æ¬çãªã¯ã©ãŠããã€ãã£ãç°å¢åãã®ã»ãã¥ãªãã£ãã©ãããã©ãŒã ã§ããCSPMã¯CNAPPã®æ§æèŠçŽ ã®äžã€ãšèŠãªãããããšãå€ãã§ãã
ãããã圹å²ãç°ãªããããçµã¿åãããŠå©çšããããšã§ããã匷åºãªã¯ã©ãŠãã»ãã¥ãªãã£äœå¶ãç¯ãããšãã§ããŸãã
â ãŸãšã
CSPMïŒã¯ã©ãŠãã»ãã¥ãªãã£ãã¹ãã£ãããžã¡ã³ãïŒã¯ãã¯ã©ãŠãç°å¢ã®èšå®ãã¹ãèªåã§ç¶ç¶çã«ãã§ãã¯ããã»ãã¥ãªãã£ãªã¹ã¯ãäœæžããããã®éèŠãªãœãªã¥ãŒã·ã§ã³ã§ãã
ã¯ã©ãŠãå©çšãåœããåã«ãªã£ãä»ããã®äŸ¿å©ããå®å šã«äº«åããããã«ã¯ãCSPMã®ãããªããŒã«ã掻çšããŠãåžžã«ã»ãã¥ãªãã£ã®ç¶æ ãè¯å¥œã«ä¿ã€ããšãäžå¯æ¬ ã§ããããããªãã®äŒç€Ÿãã¯ã©ãŠãã䜿ã£ãŠãããªããCSPMã®å°å ¥ãæ€èšããŠã¿ã䟡å€ã¯ååã«ãããŸããïŒâš
ã³ã¡ã³ã