æ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ãã€ãŸãIDMãœãªã¥ãŒã·ã§ã³ã®åžå Žã¯ã西åŽã®ææ°ã®ååã«å¿ããŠéæ¹ããªãããŒã¹ã§æé·ããŠããŸãã ãã®åŸåã¯ãããæ°å¹Žãæ±ãšãŒããããšãã·ã¢ã®åœã
ã§èŠ³å¯ãããŠããŸãã çŸåšãIDMãœãªã¥ãŒã·ã§ã³ã¯å€§äŒæ¥ãšäžèŠæš¡äŒæ¥ã®äž¡æ¹ã§éèŠããããŸãã

ãã·ã¢ã®IDMåžå Žã«ã¯ã西æŽãšåœå
ã®äž¡æ¹ã®ãã³ããŒããããŸãã çŸåšæãäžè¬çãªIDMã·ã¹ãã ã¯ãOracle Identity ManagerãIBM Security Identity ManagerãMicrosoft Forefront Identity ManagerãCMSãAvanpostã§ãã ãããã«ã¯å€ãã®å
±éç¹ããããŸãããæ©èœçãªæ©èœããããŸãããœãªã¥ãŒã·ã§ã³ãéžæããéã顧客ã¯ééããªããã©ã®ã·ã¹ãã ãèŠä»¶ãæãå®å
šã«æºãããŠããããç解ããããã«ãããã®ããããã«ç²Ÿéããå¿
èŠããããŸãã IDMãšã¯äœã§ããïŒ ããã¯ã¢ã«ãŠã³ã管çã·ã¹ãã ã§ãã éåžžãIDMã«ã¯ã¢ã¯ã»ã¹ãæäŸãã2ã€ã®æ¹æ³ããããŸãã人äºç°åïŒãžã§ãã¢ã¯ã»ã¹ïŒã«åºã¥ãæ¹æ³ãšãã»ã«ããµãŒãã¹WebããŒã¿ã«ïŒå人ã¢ã¯ã»ã¹ïŒã䜿çšããæ¹æ³ã§ãã IDMã管çãããšã³ãã£ãã£ã¯ã¢ã«ãŠã³ãã§ãã IDMã¯ã¢ã«ãŠã³ããäœæããäºåèšå®ãããã°ã«ãŒãã¡ã³ããŒã·ããã管çããŸãã

æ¢åã®ãã¹ãŠã®IDMã·ã¹ãã ã«ã¯ãã¯ããã«å¹
åºãæ©èœããããäžéšã®ã·ã¹ãã ã§ã¯ãã詳现ãªæš©éãã®ç®¡çãæšæºã¢ã¯ã»ã¹ã®æ§æïŒã°ã«ãŒãã®äœæãšãªãœãŒã¹ãžã®é¢é£ä»ãïŒãããã«ã¯æ°ãããªãœãŒã¹ã®äœæãå¯èœã§ãã
æè¿ãŸã§ããã·ã¢äŒæ¥ã«ããIDMã®äœ¿çšã¯ãæ¥çã®å·šäººã欧米äŒæ¥ã®ä»£è¡šãªãã£ã¹ãäž»èŠéè¡ã®ç¹æš©ã§ããã ãããã¯ãæ°å人ã®ã¹ã¿ãããšå·šå€§ãªãåç©åãã®æ
å ±ã·ã¹ãã ãæã€äŒæ¥ã§ãããã®å€ãã¯ãããã®äŒæ¥å°çšã«äœæãããä»ã®å Žæã§ã¯äœ¿çšããããæ°åãŸãã¯æ°åã®äºç®ããããŸãã ãªãã§ïŒ
å®éããã·ã¢åžå Žã®ã»ãšãã©ã®IDMãœãªã¥ãŒã·ã§ã³ã¯ãOracleãIBMãMicrosoftãªã©ã®ããŒã±ãããªãŒããŒããã¬ã³ãã»ãã¿ãŒã«ãã£ãŠä»£è¡šãããŠããŸãã
ãããã®ãœãªã¥ãŒã·ã§ã³ã¯èšèšè
ã§ãããããããããžãã¹ããã»ã¹ã«åãããŠã«ã¹ã¿ãã€ãºããããšãã§ããŸãã å®éã西éšã®IDMã¯ãã©ãããã©ãŒã ã§ãã ãããããããã®ã·ã¹ãã ã®ã©ã€ã»ã³ã¹ã®ã³ã¹ãã¯éåžžã«é«ããå®è£
ã«ã¯æ°å¹Žãããå ŽåããããŸãã åæã«ã顧客ã®ããžãã¹ããã»ã¹ãå€åããŠããå Žåã¯ããœãªã¥ãŒã·ã§ã³ãå®éã«æžãçŽãå¿
èŠããããŸãã
æè¿ãåžå Žã®ç¶æ³ã¯å€åããŠããŸãã 200ã500人ãè¶
ããäŒæ¥ã¯ãæ
å ±ãªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ã軜æžããIDMã·ã¹ãã ã䜿çšããŠã¢ã¯ã»ã¹ã®æäŸãšå¶åŸ¡ã®ããã»ã¹ãèªååããŸãã äœãå€ãã£ãïŒ
- ã€ã³ãã°ã¬ãŒã¿ãŒã®èœåãæé·ãããæšæºãã®è€è£œå¯èœãªãœãªã¥ãŒã·ã§ã³ã圢æããããšã³ãžãã¢ã®èœåãåäžãããããžã§ã¯ãã³ã¹ããåæžãããŸããã
- ããã°ã¹ãªãŒã®æ¬§ç±³äŒæ¥ã¯äŸ¡æ Œèšå®ããªã·ãŒãå€æŽãã倧å¹
ãªå²åŒãæäŸããåæã³ã¹ãã®æ倧70ïŒ
ã«éããŸããã ããã¯ããšããããåœå
ãã³ããŒã®ç«¶åä»ç€Ÿãéåžžã«æå©ãªãªãã¡ãŒãåºããŠããããšã«èµ·å ããŠããŸãã
- 䜿çšãããæ
å ±ã·ã¹ãã ã®è€éããšéãããã³ãã·ã¢äŒæ¥ã®åŸæ¥å¡ã®è³æ Œã¯å¢å ããŠããŸãã
ãããããã·ã¢ã®IDMåžå Žã¯ãŸã 西åŽãšåãéã§ã¯ãããŸããïŒç±³åœã§ã¯ã1000人ãè¶
ãã5瀟ã®ãã¡4瀟ãIDMãœãªã¥ãŒã·ã§ã³ã䜿çšããŠããŸãïŒã ãã·ã¢ã§IDMã¯ã©ã¹ã®è£œåãæåãããã«ã¯ãäœãããå¿
èŠããããŸããïŒ
TrustVersã¯ãIDMãœãªã¥ãŒã·ã§ã³ã®åœå
éçºè
ã§ããã倧èŠæš¡ãªçµç¹ãšæ倧1000人ã®ã¹ã¿ãããæ±ããäŒæ¥ã®äž¡æ¹ã§æåè£ã«å°å
¥ãããŠããŸãã ç§ãã¡ã¯ãããã€ãã®è«æãçå®ããŸããããããã®è«æã¯ããã·ã¢ã®äŒæ¥ã§IDMãæåãããããã®éµã«ãªããšèããŠããŸãã
1. IDMå®è£
ãããžã§ã¯ãã¯ãå¹³åã§3ãæç¶ãå¿
èŠããããŸãã ããã¯ããã€ãã®æ¹æ³ã§å®çŸã§ããŸãã
- ã¿ãŒã²ããã·ã¹ãã ãžã®ã³ãã¯ã¿ã¯ãã®ãŸãŸäœ¿çšã§ããŸãã Oracleãå®è£
ããã€ã³ãã°ã¬ãŒã¿ã¯ãã»ãšãã©ã®ã³ãã¯ã¿ãå®è£
段éã§ãå®æãããŠããããããã®è€è£œã¯æ¡ä»¶ä»ãã§ãããããå®è£
ã®æéãšã³ã¹ãã®å¢å ã«ã€ãªãããŸãã
- ã·ã¹ãã ã¯ãããã°ã©ã ã§ã¯ãªã調æŽããå¿
èŠããããŸããã€ãŸããã·ã¹ãã ã³ã¢ã調æŽããããã®ã€ã³ã¿ãŒãã§ã€ã¹ãå¿
èŠã§ãã ããã«ãããã·ã¹ãã ã®æè»æ§ãäœäžããŸãããã¯ããã«é«éã«æ§æã§ããŸãã ãã©ã³ã¹ãå¿
èŠã§ãã
- IDMã·ã¹ãã ã«ã¯ãæ
å ±ã·ã¹ãã ã®çŸåšã®ç¶æ
ãšçŸåšã®ISããªã·ãŒã«åºã¥ããŠããŒã«ã¢ãã«ãäœæããã³æé©åããåæã¢ãžã¥ãŒã«ãå¿
èŠã§ãã åšåº«æé©åæäœã®ååã ããã«ãããå¿
é ã®äºåãããžã§ã¯ãåæã®æ®µéãã·ã¹ãã å®è£
ããã»ã¹ã«çµ±åã§ãããããæéã³ã¹ãã倧å¹
ã«åæžãããããã»ã¹ãèªååãããŸãã
2. IDMã¯ãäŒç€Ÿã®æ
å ±ã»ãã¥ãªãã£ã確ä¿ããä»ã®ã·ã¹ãã ãšé£æºããŠåäœããå¿
èŠããããŸãã ã©ã®äŒæ¥ãIDMããŒããã䜿çšãå§ãããã¯ãã£ãã«ãããŸããã ã»ãšãã©ã®å Žåãå瀟ã¯ãã§ã«ã¯ã©ã¹ITSMãSIEMãSSOãPKIãACSã®ããããã®ã·ã¹ãã ã䜿çšããŠããŸãã Identity Managementã¯ã©ã¹ã·ã¹ãã ãé¢é£ãœãªã¥ãŒã·ã§ã³ãšçµã¿åãããŠäœ¿çšââããæ¹æ³ã詳ããèŠãŠã¿ãŸãããã
- ITSMãšã®çµ±å㯠ããåäžã®ãšã³ããªãã€ã³ãããšåæ§ã«èå³æ·±ããã®ã§ãã çµç¹ã®åŸæ¥å¡ã¯ããµãŒãã¹ãã¹ã¯ã§ã¢ããªã±ãŒã·ã§ã³ãäœæããã¢ã¯ã»ã¹ãæäŸããã¢ããªã±ãŒã·ã§ã³ã§ããå ŽåãIDMã«èªåçã«éä¿¡ãããããã§åæãããå®è¡ããïŒèªåçã«ïŒããã®åŸç£èŠãããŸãã

- KUBãšSIEMã®çµ±åã¯ã次ã®ã¹ããŒã ã«åŸã£ãŠç·šæãããŸããIDMKUB㯠ãã»ãã¥ãªãã£èšå®ã®å€æŽïŒã¢ã¯ã»ã¹æš©ã®å€æŽãã¢ã«ãŠã³ãã®äœæãåé€ãæ°ãããªãœãŒã¹ïŒã«ã€ããŠã¿ãŒã²ããã·ã¹ãã ãç£èŠããã¢ããªã±ãŒã·ã§ã³ã®èŠä»¶ãšæ¯èŒããŸãã å€æŽãã¿ãŒã²ããã·ã¹ãã ã§çŽæ¥çºçããå ŽåãIDMã¯ã¢ããªã±ãŒã·ã§ã³ã¡ã«ããºã ããã€ãã¹ããŠã責任è
ã«ã³ã³ãã©ã€ã¢ã³ã¹éåãéç¥ããã¬ããŒããSIEMã«éä¿¡ããŸãã ãã®çµ±åã®å©ç¹ã¯ãSIEMããåæãããã€ãã³ããšã¢ããªã±ãŒã·ã§ã³ã·ã¹ãã ããã€ãã¹ããŠçºçããã€ãã³ããåºå¥ããªããããISæ
åœè
ãç解ãã«ããå€æŽã®ãããŒãããåãåãããšã§ãã

- ACSãšã®çµ±åã äŒç€Ÿã®åŸæ¥å¡ãä»ã®äººã®ããŒã¿ã䜿çšããŠã·ã¹ãã ã§äœæ¥ããç¶æ³ã«ã©ã®ãããã®é »åºŠã§ééããŸããïŒ ãã®ç¶æ³ã¯ã©ã®çšåºŠåãå
¥ããããŸããïŒ ããªãã¯ãããããã®è³ªåã«åå¥ã«çããããšãã§ããŸãããã»ãšãã©ã®å Žåã圌ãã¯ãã®åé¡ãšæŠãããšããŸãã IDMãšACSã䜵çšãããšããã¡ã€ã³ãå«ãã¿ãŒã²ããã·ã¹ãã ãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ãå¶åŸ¡ã§ããŸãã 人ãå¶åŸ¡ã·ã¹ãã ãééããACSå¢çãå
¥åããªãéããADã¢ã«ãŠã³ãã¯ãããã¯ãããåŸæ¥å¡ãä»äºã«å°±ããšããã«ããã¡ã€ã³ã«ãã°ã€ã³ããæ©äŒãäžããããŸãã ãã¡ããããã¹ãšãªã¢ãŒãã¢ã¯ã»ã¹ã®åªå€±ãå«ãå€ãã®å¶éããããŸãããããã¯IDMãä»ããŠå®çŸããããšãã§ããŸãïŒããšãã°ãã«ãŒããå¿ããåŸæ¥å¡ã®é·ãäœæããã¢ããªã±ãŒã·ã§ã³ã䜿çšïŒã

- IDMã䜿çšããŠPKIã€ã³ãã©ã¹ãã©ã¯ãã£ã管çããŸãã æãäžè¬çãªã·ããªãªã¯ãåŸæ¥å¡ã®åãå
¥ã/解éæã®èšŒææžã®èªåçºè¡ãšå€±å¹ã§ãã ãã ããIDMã¯ãããšãã°ãåŸæ¥å¡ãã»ãã¥ãªãã£èšŒææžãå¿
èŠãšããã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãèŠæ±ããå Žåãªã©ãèŠæ±ã«å¿ããŠèšŒææžãçºè¡ã§ããŸãã PKI-IDMã¯ã蚌ææžç®¡çããããã®èªåçºè¡ãšå€±å¹ãããã³èŒžéã«é¢ããŠãNIBãšITã®è² è·ã倧å¹
ã«åæžã§ããŸãã 2çªç®ã®ãããã»ã©èŠæ±ãããªãæ©èœã¯ãã¢ããªã±ãŒã·ã§ã³ã®äœæããã³æ¿èªã®æ®µéã§ã®ESã®äœ¿çšã§ããããã«ã¯ãè³æ Œã®ããESïŒæå·ãããªã©ïŒã®äœ¿çšãå«ãŸããŸãã

- SSO æ°ããåŸæ¥å¡ãåãããã«ãªããšã人äºã·ã¹ãã ã®ããŒã¿ã«åºã¥ããŠãIDMã¯åœ¹è·ã«åºã¥ããŠç¹æš©ãäžããã¯ã³ã¿ã€ã ãã¹ã¯ãŒããçæããŸãã
ã³ã³ãã¥ãŒã¿ãŒã«åããŠã¢ã¯ã»ã¹ãããšãããŠãŒã¶ãŒã¯ãã¡ã€ã³ã¢ã«ãŠã³ãåãšãã¹ã¯ãŒããæå®ããŸãã ãã°ã€ã³ã«æåããåŸããŠãŒã¶ãŒã¯åŸç¶ã®äœ¿çšã«ä»£ããèªèšŒã·ã¹ãã ïŒã¹ããŒãã«ãŒããããŒã¯ã³ãã¯ã³ã¿ã€ã ãã¹ã¯ãŒããžã§ãã¬ãŒã¿ãŒãçäœèªèšŒããŒã«ãªã©ïŒãæ§æã§ããŸãã CUBã§ã¯ããã®æé ã¯Indeed-Id Enterprise SSOãšãŒãžã§ã³ãã®è³éã䜿çšããŠå®è¡ãããŸãã 䜿çšå¯èœãªå
šãªãŒã»ã³ãã£ã±ãŒã¿ãŒã¯ãIndeed-Id Enterprise SSOèšå®ã«ãã£ãŠæ±ºãŸããŸãã å¿
èŠãªèšå®ããã¹ãŠå®äºãããšããŠãŒã¶ãŒã¯éžæãããèªèšŒã·ã¹ãã ã䜿çšããŠããã¡ã€ã³ãšãã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã IPã®ãã¹ã¯ãŒããèŠããŠããå¿
èŠã¯ãããŸããã

3. IDMãœãªã¥ãŒã·ã§ã³ã¯æçã§ããå¿
èŠããããŸãã æ®å¿µãªãããèªåŒµãããæåŸ
ãã¢ããªã±ãŒã·ã§ã³äœæã«ãŒã«ã䜿çšããäŒæ¥å«çã®æ¬ åŠãã€ã³ãã°ã¬ãŒã¿ãŒã®çµéšäžè¶³ãIDMãœãªã¥ãŒã·ã§ã³ãå®è£
ãããããžã§ã¯ãã¯ãå¿
ãããäŒç€Ÿã«æåŸ
ãããå¹æããããããšã¯éããŸããã IDMã®å®è£
ããæ倧ã®å¹æãåŸãã«ã¯ã©ãããã°ããã§ããïŒ
- æãéèŠãªèŠå ã®1ã€ã¯ãããžãã¹ãŠãããã®äœ¿ããããã§ãã ã¢ã¯ã»ã¹ãããªãã¯ã¹ãšããŒã«ã®æ§é ã¯ç解å¯èœã§ããå¿
èŠããããããã€ãã®åºæºã«åŸã£ãŠæ€çŽ¢ããå¿
èŠããããŸããã³ãŒãã£ããŒã¿ãŒãã¢ããªã±ãŒã·ã§ã³ã調æŽã§ããå¿
èŠããããŸãã åæã«ããžã§ãæš©éãèšå®ããããšã«ãããããŒã«ããªã¯ãšã¹ãããããã»ã¹ãæå°éã«æããå¿
èŠããããŸãã åŸæ¥å¡ã¯ãååã®ããã«è³æ Œæ
å ±ãèŠæ±ã§ããå¿
èŠããããŸãã
- èªååãµãŒãã¹ãšæ
å ±ã»ãã¥ãªãã£ã®çžäºäœçšãããã³IDMã®éçšã«é¢ããæ£åŒãªèŠå¶ã ITãµãŒãã¹ã®åŸæ¥å¡ãã¢ããªã±ãŒã·ã§ã³ã·ã¹ãã ããã€ãã¹ããŠãããšãã°åŸæ¥å¡ã®å£é ã®èŠæ±ãéè¡ããå ŽåãISæ
åœè
ã¯ãççŸãã«å§åãããISãµãŒãã¹ã®äœæ¥ã¯éº»çºããŸãã IDMã®äœ¿çšã«çŠç¹ãåœãŠãŠããã®ã¯ãã¢ããªã±ãŒã·ã§ã³ã®é»åããã¥ã¡ã³ããããŒãé
眮ããããšã§ãã IDMãåäžã®ã¢ã¯ã»ã¹èŠæ±ã·ã¹ãã ã«ããŸãã å Žåã«ãã£ãŠã¯ããªãã¬ãŒã¿ãCUBã§ãªã¯ãšã¹ãã解éããããéšéã®è²¬ä»»è
ãæå®ããŠãååãã¢ã¯ã»ã¹ããããã®ã¢ããªã±ãŒã·ã§ã³ãäœæãããããã®ãçã«ããªã£ãŠããŸãã
- ãããžã§ã¯ããžã®åå ãåŸæ¥å¡ã亀æãã矩åã®å±¥è¡ãéåŸæ¥å¡ã®ä»äºã«ã¯ãããŸããŸãªå¯Ÿè±¡ã·ã¹ãã ã®å
žåçãªç¹æš©ãããªãç¹å®ã®ããžãã¹ããŒã«ã®ã»ããã®åœ¢æãå¿
èŠã§ãã åããŒã«ãšèŠªããŒã«ãçµã¿åãããäžé£ã®ããŒã«ã䜿çšãããšãã¢ã¯ã»ã¹èŠæ±æé ã倧å¹
ã«ç°¡çŽ åãããæš©éã®å¶åŸ¡ãšåèªèšŒãç°¡çŽ åã§ããŸãã
- æ©èœã®è©³çŽ°ãªèª¿æ»ãIDM管çè
ã®é«åºŠãªãã¬ãŒãã³ã°ãã»ã«ããµãŒãã¹ããŒã¿ã«ã§äœæ¥ããããã®äžè¬ã¹ã¿ããã®ãã¬ãŒãã³ã°ã¯ãã©ã®çµç¹ã§ãæ°ãããœãªã¥ãŒã·ã§ã³ã«åãæ¿ããå°é£ãæå°éã«æããŸãã
IDMãœãªã¥ãŒã·ã§ã³ã®ååŸã¯ãã·ã¹ãã ã®å®è£
ãšãã®åŸã®éçšãæåãããããã®éèŠãªã¹ãããã§ããããŸããŸãªIDMã®æ©èœçç¹åŸŽãæ
éã«ç解ããçµéšè±å¯ãªã€ã³ãã°ã¬ãŒã¿ãŒãéžæããå°é家åãã®ãã¬ãŒãã³ã°ãå®æœããå¿
èŠããããŸãã å®è£
ã«é¢ãã決å®ã¯ãããžãã¹ãITãããã³NISã®ã¹ã¿ãããåå ããŠããŸãšããŠè¡ãããå¿
èŠããããŸãã
ãã¬ã»ãŒã«ãããŒãžã£ãŒAlexey Pavlov
LLC Trust Trust
http://trustverse.ru