çŸåšãäŒæ¥ã®éèŠãªããžãã¹ããã»ã¹ã®å¯çšæ§ãåäžãããèšç»ãç«ãŠãã®ã«åœ¹ç«ã€ããžãã¹ç¶ç¶æ§ç®¡çæè¡ãå€æ°ãããŸãã ãããããããã®ææ³ã«ã¯ããžãã¹ç¶ç¶æ§ã®çè«çåºç€ãå«ãŸããŠãããããã®ãããªãããžã§ã¯ããå®è£
ããæ¹æ³ããšãã質åã«ã¯çããŸããã ãã®èšäºã§ã¯ãããžãã¹ç¶ç¶æ§ç®¡çã·ã¹ãã ãã©ã®ããã«å®è£
ãããå段éã§ã©ã®ãããªçµæãåŸãããããç解ããããã®äžé£ã®ã¢ã¯ã·ã§ã³ã«ã€ããŠèª¬æããŸãã
äºæ¥ç¶ç¶ç®¡çããã»ã¹ã®ã©ã€ããµã€ã¯ã«äŒæ¥ã®ããžãã¹ç¶ç¶æ§ã®ç®¡çã¯ãçµç¹ãããžãã¹ãITãæ³åŸãããã³çµç¹ã«åœ±é¿ãäžãããã®ä»ã®åéã§èµ·ããããå€åãèæ
®ãããããã®å€åãžã®é©å¿ãæ¯æŽãã埪ç°ããã»ã¹ã§ãã èšãæããã°ãããžãã¹ç¶ç¶æ§ç®¡çã¯ç¶ç¶çãªæ¹åã®ããã»ã¹ã§ããããã®çµæãããžãã¹ç¶ç¶æ§èšç»ã®ä¿¡é Œæ§ã«å¯ŸããäŒæ¥ã®ä¿¡é Œãé«ãŸããŸãã
äºæ¥ç¶ç¶ç®¡çããã»ã¹ã®ã©ã€ããµã€ã¯ã«ã«ã¯7ã€ã®æ®µéãããããããããæé ã®é åºãšçµæã決å®ããŸãïŒæ®µéã®ãªã¹ãã¯BCM Instituteã®ãµã€ã¯ã«[8]ã«åºã¥ããŠäœæãããŸããïŒã
ãããžã§ã¯ãã®éå§ãããžã§ã¯ããšã¯ãç¬èªã®è£œåããµãŒãã¹ãçµæãäœæããããšãç®çãšããã¢ã¯ãã£ããã£ã§ãããããžã§ã¯ã管çèšç»-ãããžã§ã¯ãã®å®è£
æ¹æ³ãç£èŠããã³å¶åŸ¡æ¹æ³ã説æããææžã
PMBOKã¬ã€ã-第5çãã®æ®µéã§ãäºæ¥ç¶ç¶ãããžã§ã¯ãã®å
容ã決å®ããã段éçãªèšç»ãçå®ãããŸãã ãããžã§ã¯ãã®å®è£
æ¹æ³ãç£èŠãå¶åŸ¡ãããã³ã¯ããŒãºã®æ¹æ³ãå®çŸ©ãããããžã§ã¯ãã®å¢çããããžã§ã¯ãããŒã ã®ã¡ã³ããŒã®åœ¹å²ãããã³ãããžã§ã¯ãã®ç®çãå®çŸ©ããŸãã
äžèšã®ã¢ã¯ã·ã§ã³ã«å ããŠããããžã§ã¯ãã®å¿
èŠæ§ãå€æããå¿
èŠããããŸãã äžéšã®äŒæ¥ã§ã¯ãããžãã¹ã®ç¶ç¶æ§ã«ãããããã·ã§ã³ã¯ãªãã£ã«ã«ãªããžãã¹æ©èœã®æå¹æ§ã確ä¿ãã顧客ã«ããžãã¹ã®æç¶å¯èœæ§ãå®èšŒããŠããŸãã ããããäºæ¥ç¶ç¶ã®ããã®èŠå¶äžã®æ³çè¡çºããã³èŠå¶æ©é¢ã®èŠä»¶ãããããšãå¿ããŠã¯ãªããŸããã 以äžã®è¡šã¯ããã·ã¢é£éŠã®é åã§åºã䜿çšãããŠããæšæº/èŠå¶æ³ïŒNLAïŒãããã³ãããã®æšæº/ NLAãããžãã¹ç¶ç¶æ§ã·ã¹ãã ã«å¯ŸããŠæã£ãŠããå€ãã®èŠä»¶ããªã¹ããã説æããŠããŸãã
æšæº/èŠç¯ | èŠä»¶ | 説æ | ã¹ããŒã¿ã¹ |
---|
ISO / IEC 27001ïŒ2013ãæ
å ±æè¡-ã»ãã¥ãªãã£æè¡-æ
å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã -èŠä»¶ãïŒæ
å ±æè¡ãã»ãã¥ãªãã£ææ³ãæ
å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ïŒ | A.17ããžãã¹ç¶ç¶æ§ç®¡çã®æ
å ±ã»ãã¥ãªãã£ã®åŽé¢ ïŒäºæ¥ç¶ç¶ç®¡çã«ãããæ
å ±ã»ãã¥ãªãã£ã®åŽé¢ïŒ | æ
å ±ã»ãã¥ãªãã£ã®ç¶ç¶æ§ã¯ãäŒç€Ÿã®ããžãã¹ç¶ç¶æ§ã·ã¹ãã ã«çµ±åããå¿
èŠããããŸãã ãããè¡ãã«ã¯ã以äžãè¡ãå¿
èŠããããŸãã -æ
å ±ã»ãã¥ãªãã£ã®ç¶ç¶æ§ãèšç»ããã -æ
å ±ã»ãã¥ãªãã£ã®ç¶ç¶æ§ãå°å
¥ããŸãã -æ
å ±ã»ãã¥ãªãã£ã®ç¶ç¶æ§ã確èªãè©äŸ¡ããŸãã
| äŒæ¥ãISO / IEC 27001ïŒ2013ãæ
å ±æè¡-ã»ãã¥ãªãã£æè¡-æ
å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã -èŠä»¶ããžã®æºæ 蚌ææžãååŸããããšããå Žåãæ
å ±ã»ãã¥ãªãã£ã®ç¶ç¶æ§ã¯èŠä»¶ã®1ã€ã§ãã |
ISO 22301ïŒ2012ã瀟äŒä¿é-äºæ¥ç¶ç¶ç®¡çã·ã¹ãã -èŠä»¶ãïŒç€ŸäŒä¿éãäºæ¥ç¶ç¶ç®¡çã·ã¹ãã ïŒ | ãã®æšæºã¯ãããžãã¹ã®ç¶ç¶æ§ã«çŠç¹ãåœãŠãŠããŸãã | æšæºç¶æ
ïŒ -äŒç€Ÿã§äºæ¥ç¶ç¶ç®¡çã·ã¹ãã ã確ç«ããããã«å¿
èŠãªèŠä»¶ã -äºæ¥ç¶ç¶ç®¡çã·ã¹ãã ã«ãããäžçŽç®¡çè·ã®æ©èœã®èŠä»¶ã -ããžãã¹ç¶ç¶æ§ç®¡çã·ã¹ãã ã®æŠç¥çç®æšãšã¬ã€ãã©ã€ã³ãèšå®ããããã®èŠä»¶ã -ããžãã¹ã®ç¶ç¶æ§ã確ä¿ããããã®èŠä»¶ãã€ã³ã·ãã³ãã®ç®¡çæé ãéçºããããã®æé ã | äŒæ¥ãISO 22301ïŒ2012ã瀟äŒä¿é-äºæ¥ç¶ç¶ç®¡çã·ã¹ãã -èŠä»¶ããžã®æºæ 蚌ææžãååŸããããšããå ŽåãBCP / DRPèšç»ïŒãããã®èšç»ã«ã€ããŠã¯ãèšç»ã®éçºãšå®è£
ãã»ã¯ã·ã§ã³ã§èª¬æïŒã®ååšãåææ¡ä»¶ãšãªããŸãã |
GOST R 53647ãããžãã¹ç¶ç¶æ§ç®¡çã | ãã®æšæºã¯ãããžãã¹ã®ç¶ç¶æ§ã«çŠç¹ãåœãŠãŠããŸãã | ãã®åœéèŠæ Œã¯ãææžåãããããžãã¹ç¶ç¶æ§ç®¡çã·ã¹ãã ã®èšç»ãäœæãéçšãç£èŠãåæãå®æœããµããŒããæ¹åã®èŠä»¶ãå®ããŠããŸãã | ããã¯æ¬è³ªçã«æšå¥šã§ãã |
STO BR IBBS-1.0-2014ããã·ã¢é£éŠã®éè¡ã·ã¹ãã ã®çµç¹ã®æ
å ±ã»ãã¥ãªãã£ã®ç¢ºä¿ã | 8.11ã ããžãã¹ç¶ç¶æ§ç®¡çã®èŠä»¶ äžæåŸã®å埩
| éè¡ã·ã¹ãã ã®çµç¹ã¯ãäºæ¥ã®ç¶ç¶æ§ãšå¯èœãªäžæåŸã®å埩ã確ä¿ããããã®èšç»ãå®çŸ©ããå¿
èŠããããŸãã èšç»ã«ã¯ãéè¡ã·ã¹ãã ã®çµç¹ã®åŸæ¥å¡ãäºæ¥ãå埩ããããã®æ瀺ãšæé ãå«ããå¿
èŠããããŸãã ç¹ã«ãèšç»ã«ã¯ä»¥äžãå«ããå¿
èŠããããŸãã -èšç»ãæå¹åããããã®æ¡ä»¶ã -ISã€ã³ã·ãã³ãåŸã«è¡ãããã¢ã¯ã·ã§ã³ã -å埩æé ã -ãã¹ãããã³æ€èšŒæé ã -åŸæ¥å¡ã®ãã¬ãŒãã³ã°ãšæèåäžã®èšç»ã -åŸæ¥å¡ã®çŸ©åãèšç»ã®åèŠå®ã®å®æœã«è²¬ä»»ãæã€åŸæ¥å¡ã瀺ããŸãã å¿
èŠãªæ
å ±ããœãããŠã§ã¢ãããŒããŠã§ã¢ãéä¿¡ãã£ãã«ã埩å
ããããã®æ段ã®èŠä»¶ãå«ããäºæ¥ç¶ç¶æ§ãšäžæåŸã®å埩ã®åé¡ã管çããISã確ä¿ããããã®èŠä»¶ã確ç«ããå¿
èŠããããŸãã
| ããã¯æ¬è³ªçã«æšå¥šã§ãã |
2013幎2æ11æ¥ä»ãã·ã¢FSTECã®åœä»€ç¬¬17å·ãåœå®¶æ
å ±ã·ã¹ãã ã«å«ãŸããåœå®¶æ©å¯ãæ§æããªãæ
å ±ã®ä¿è·èŠä»¶ã®æ¿èªã«ã€ããŠã | X.æ
å ±ã®ã¢ã¯ã»ã·ããªãã£ã®ç¢ºä¿ïŒCCTïŒ | 2013幎2æ11æ¥ä»ããã·ã¢é£éŠFSTECåœä»€ç¬¬17å·ãåœå®¶æ
å ±ã·ã¹ãã ã«å«ãŸããåœå®¶æ©å¯ãæ§æããªãæ
å ±ã®ä¿è·èŠä»¶ã®æ¿èªãã«åºã¥ãã以äžãå¿
èŠã§ãã -ãã§ãŒã«ã»ãŒãæè¡æ段ã䜿çšããŸãã -äºçŽããŒããŠã§ã¢ããœãããŠã§ã¢ãæ
å ±äŒéãã£ãã«ãæ
å ±ã·ã¹ãã ã®æ©èœã確ä¿ããæ段ã -æè¡æ©åšã®ãã©ãã«ã®ãªãæ©èœãå¶åŸ¡ããŸãã -æè¡çæ段ã®æ©èœã®é害ã®æ€åºãšäœçœ®ç¹å®ã確å®ã«ããããã -倱æããè³éãå埩ããããã®æªçœ®ãè¬ãã -ãã¹ãããŒããŠã§ã¢; -å®æçã«ããã¯ã¢ãããã·ã³ã¡ãã£ã¢ã«æ
å ±ãããã¯ã¢ããããŸãã -æå®ãããæéééå
ã«ããã¯ã¢ãããã·ã³ã®ã¹ãã¬ãŒãžã¡ãã£ã¢ïŒããã¯ã¢ããïŒããæ
å ±ãå埩ããæ©èœãæäŸããŸãã -æ
å ±è»¢éãå«ããã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ïŒãã£ãã·ãã£ïŒã®èš±å¯ããã人ã«ããæäŸã®æ¡ä»¶ãšå質ãå¶åŸ¡ããŸãã
| ã·ã¹ãã ãã»ãã¥ãªãã£ã¯ã©ã¹1ãŸãã¯2ã«åŸã£ãŠåé¡ãããŠããå Žåã泚æã«èšèŒãããŠããèŠä»¶ã¯å¿
é ã§ãã |
2013幎2æ18æ¥ä»ãã·ã¢ã®FSTECã®åœä»€ç¬¬21å· ãå人ããŒã¿æ
å ±ã·ã¹ãã ã§ã®åŠçäžã«å人ããŒã¿ã®ã»ãã¥ãªãã£ã確ä¿ããããã®çµç¹çããã³æè¡çæ段ã®æ§æãšå
容ã®æ¿èªã«ã€ããŠã | X.å人ããŒã¿ã®å¯çšæ§ã®ç¢ºä¿ïŒCCTïŒ | 2013幎2æ18æ¥ä»ããã·ã¢é£éŠFSTECåœä»€ç¬¬21å·ãå人ããŒã¿æ
å ±ã·ã¹ãã ã§ã®åŠçäžã«å人ããŒã¿ã®ã»ãã¥ãªãã£ã確ä¿ããããã®çµç¹çããã³æè¡çæªçœ®ã®æ§æããã³å
容ã®æ¿èªãã«åŸã£ãŠã以äžã確ä¿ããå¿
èŠããããŸãã -æè¡æ©åšã®ãã©ãã«ã®ãªãæ©èœã®å¶åŸ¡ã -æäœäžã®é害ã®æ€åºãšããŒã«ãªãŒãŒã·ã§ã³ã -倱æããè³éãå埩ããããã®å¯Ÿçãè¬ãããããããã¹ãããŸãã -å人ããŒã¿ã®ããã¯ã¢ãããã·ã³ã¹ãã¬ãŒãžã¡ãã£ã¢ãžã®å人ããŒã¿ã®ããã¯ã¢ããã -æå®ãããæéééå
ã«å人ããŒã¿ïŒããã¯ã¢ããïŒã®ãã·ã³ããã¯ã¢ããã¡ãã£ã¢ããå人ããŒã¿ã埩å
ããæ©èœã | å人ããŒã¿æ
å ±ã·ã¹ãã ã«1ãŸãã¯2ã®ã»ãã¥ãªãã£ã¬ãã«ãå®çŸ©ãããŠããå Žåã泚æã«èšèŒãããŠããèŠä»¶ã¯å¿
é ã§ãã |
ãããžã§ã¯ãèšç»ãæçµçã«äœæããã³éçºãããåŸãæ¿èªã®ããã«äŒç€Ÿã®çµå¶é£ã«éä¿¡ããå¿
èŠããããŸãã èšç»ã®äœæ¥ã¯ãçµå¶é£ãšã®åæåŸã«ã®ã¿éå§ãããã¹ãã§ãã
泚æããŠãã ããïŒ äžéšã®äŒæ¥ã§ã¯ããããžã§ã¯ãã¹ãã³ãµãŒã¯ããã«ååãªæ³šæãæã£ãŠãããã責任ã¯äžé管çè
ã«ãããŸãã ããã¯ãå©å®³é¢ä¿è
éã®ã³ãã¥ãã±ãŒã·ã§ã³ã®åé¡ããäžçŽç®¡çè·ãžã®ãµããŒãã®æžå°ã«ã€ãªããå¯èœæ§ããããŸãã ãã®åé¡ã¯ããã¹ãŠã®å©å®³é¢ä¿è
ã®ä»£è¡šè
ãå«ããããžã§ã¯ãå§å¡äŒãäœæããããšã§è§£æ±ºã§ããŸãã å§å¡äŒã¯å®æçã«äŒè°ãéããåé¡ã解決ãããããžã§ã¯ãã®é²æç¶æ³ã«ã€ããŠè©±ãåãå¿
èŠããããŸãã
ããžãã¹åœ±é¿åæããžãã¹ã€ã³ãã¯ãåæ-ã€ã³ã·ãã³ããäŒç€Ÿã®äž»èŠãªæŽ»åãããã»ã¹ã«äžãã圱é¿ã調æ»ã§ããæ¹æ³ããã®æ®µéã§ã¯ãäŒç€Ÿã®ããã»ã¹ã®è©³çŽ°ãªèª¿æ»ãæäŸãããŸãã ãããè¡ãããã«ãã³ã³ãµã«ã¿ã³ãã¯ãããžã§ã¯ããšãªã¢å
ã®éšéã®ç®¡çè
ãšã®ã€ã³ã¿ãã¥ãŒãå®æœããŸãã äŒè©±äžã«ãéšéã®æŽ»åã«é¢ããæ
å ±ãèŠæ±ãããéšéãå®è¡ããããã»ã¹/æ©èœã®ãªã¹ããã³ã³ãã€ã«ãããŸãã ããã«ãããã»ã¹/æ©èœã®è©³çŽ°ãªèª¿æ»ã®ããã«ãããã»ã¹ã®ææè
ã«ã€ã³ã¿ãã¥ãŒããããžãã¹ãžã®åœ±é¿ã®çš®é¡ïŒçŽ æãè©å€ïŒãããã³ITããã³å€éšãµãŒãã¹ãžã®ããã»ã¹ã®äŸå床ã決å®ããŸãã ãããŠãæ倧蚱容åæ¢ã決å®ãããŸãã
æ倧蚱容åæ¢-補åã®äŸçµŠããã³/ãŸãã¯ãµãŒãã¹ã®æäŸãåéãããªãå Žåã«ãçµç¹ã®å®è¡å¯èœæ§ãæçµçã«å€±ãããæããããæéã
GOST R ISO / IEC 31010â2011ããªã¹ã¯ç®¡çã ãªã¹ã¯è©äŸ¡æ¹æ³ ''ããã»ã¹/æ©èœã®ææè
ãMAOã«ãã£ãŠæ±ºå®ãããåŸãITéšéïŒMAOã«åºã¥ãïŒãã€ã³ãžã±ãŒã¿ãŒRTOãRPOãSDOã決å®ããŸãã
-
ç®æšåŸ©æ§æéïŒRTOïŒ ã ç·æ¥æã«ããžãã¹æ©èœãŸãã¯ãªãœãŒã¹ã®åŸ©å
ãçºçããæéã
-
ç®æšåŸ©æ§ãã€ã³ãïŒRPO ïŒã ãªã«ããªã¿ãŒã²ãããã€ã³ãã¯ãæäœãäžæãããå Žåã«èš±å®¹ãããããŒã¿æ倱ã®éã決å®ããŸãã ããšãã°ãRPOã15åã§ããå ŽåãæåŸã®15åéã®ããŒã¿æ倱ã¯èš±å¯ãããŸãã
-
ãµãŒãã¹æäŸç®æšïŒSDOïŒ ã ç¹å®ã®æç¹ã§ã®ãµãŒãã¹ã®å¯çšæ§ã®ã¬ãã«ã
å³ã¯ãäžèšã®ã¡ããªãã¯ãã©ã®ããã«æ±ºå®ããããã瀺ããŠããŸãã
ããžãã¹ã€ã³ãã¯ãåæã®çµæã¯æ¬¡ã®ãšããã§ãã
-åªå
床ããã³é¢é£ããçžäºäŸåæ§ã«ãã£ãŠã©ã³ã¯ä»ããããéèŠãªããã»ã¹ã®ãªã¹ãã
-éèŠãªããã»ã¹ã®éåã«ãã£ãŠåŒãèµ·ããããç»é²æžã¿ã®çµæžçããã³çç£ç圱é¿ã
-ç¹å®ãããéèŠãªããã»ã¹ã«å¿
èŠãªãµããŒããªãœãŒã¹ã
-ããŠã³ã¿ã€ã ã®å¯èœæ§ã®ããæéããã³éèŠãªããã»ã¹ãšçžäºæ¥ç¶ãããæ
å ±æè¡ã®å埩ã
泚æããŠãã ããïŒ å€ãã®å Žåãããžãã¹ããã»ã¹ã®ææè
ã¯ãæå³çãŸãã¯ç¡æèã«å埩åºæºã®ç®æšå€ãé倧è©äŸ¡ããŸããããã¯ãåæã®ããã¿ã«å¯äžããäžåçãªã³ã¹ãã䌎ããŸãã ãã®åé¡ãåé¿ããã«ã¯ããããžã§ã¯ãããŒã ããã³å©å®³é¢ä¿è
ãšãšãã«ãäŒç€Ÿå
šäœã«åœ±é¿ãäžããã€ã³ã·ãã³ãã®ã³ã³ããã¹ãã§ããžãã¹æ©èœã®äŸ¡å€ãæ€èšããå¿
èŠããããŸãã ãã®ã¢ãããŒãã¯ãå埩åºæºã客芳çã«æ±ºå®ããŸãã
ãªã¹ã¯è©äŸ¡ãªã¹ã¯ã¯ãç®æšã«å¯Ÿããäžç¢ºå®æ§ã®åœ±é¿ã§ãã
åå·®ïŒãã®èšäºã§ã¯ããªã¹ã¯è©äŸ¡ã®è©³çŽ°ã«ã€ããŠã¯è§ŠããŠããŸããããªã¹ã¯è©äŸ¡-ãªã¹ã¯ã®ç¹å®ããªã¹ã¯åæããªã¹ã¯è©äŸ¡ãå«ãããã»ã¹ã
ISO 73ïŒ2009ããªã¹ã¯ç®¡çã èŸæžÂ»ããžãã¹ç¶ç¶æ§ç®¡çã®ãã¬ãŒã ã¯ãŒã¯ã§ã®ãªã¹ã¯è©äŸ¡ã®ç®çã¯ãäŒæ¥ã®æ··ä¹±ã«ã€ãªããå¯èœæ§ã®ããã€ãã³ããšãã®çµæïŒæ害ïŒãç¹å®ããããšã§ãã
ãªã¹ã¯è©äŸ¡ã¯ä»¥äžãæäŸããŸã
-æœåšçãªå±éºãšããã®çµæãäŒç€Ÿã®ç®æšã®éæã«äžãã圱é¿ã®ç解ã
-è
åšãšãã®åå ã®ç解ã
-äž»èŠãªãªã¹ã¯èŠå ã®ç¹å®; äŒç€Ÿããã³ãã®ã·ã¹ãã ã®è匱æ§ã
-ãªã¹ã¯æ²»çæ¹æ³ã®éžæ;
-æšæºã®èŠä»¶ãžã®æºæ ã
ãªã¹ã¯è©äŸ¡ããã»ã¹ã¯ä»¥äžã§æ§æãããŸãã
-ãªã¹ã¯èå¥-ãªã¹ã¯èŠçŽ ãèå¥ããããããã説æãããããã®ãªã¹ããç·šéããããã»ã¹ã ãªã¹ã¯ã®ç¹å®ã®ç®çã¯ãäŒç€Ÿã®ç¢ºç«ãããåç®æšã®éæã«åœ±é¿ãäžããå¯èœæ§ã®ãããªã¹ã¯ãšè
åšã®ãœãŒã¹ã®ãªã¹ãããŸãšããããšã§ãã
-ãªã¹ã¯åæ-ãªã¹ã¯æ
å ±ã調æ»ããããã»ã¹ã ãªã¹ã¯åæã¯ãå
šäœçãªãªã¹ã¯è©äŸ¡ããã»ã¹ãžã®å
¥åãæäŸãããªã¹ã¯æ²»çã®å¿
èŠæ§ã«é¢ãã決å®ãäžããé©åãªæ²»çæŠç¥ãšæ¹æ³ãéžæããã®ã«åœ¹ç«ã¡ãŸãã
-ãªã¹ã¯è©äŸ¡ã®æ¯èŒ-ãªã¹ã¯ã®çš®é¡ãšãã®éèŠæ§ãå€æããããã«ããªã¹ã¯ç®¡çã®ç¯å²ã決å®ããéã«ç¢ºç«ãããåºæºãšã¬ãã«ãæ¯èŒããŸãã
å°æ¥ã®ãªã¹ã¯è©äŸ¡ã«ãããããžãã¹ç¶ç¶æ§æŠç¥ãåççã«éçºã§ãããã®å®è£
ã«æé©ãªã·ããªãªã決å®ããã®ã«ã圹ç«ã¡ãŸãã
äºæ¥ç¶ç¶æŠç¥ã®çå®ç¶ç¶æ§ã®èŠä»¶ãåæããåŸãå¯èœãªæè¡çããã³çµç¹çãœãªã¥ãŒã·ã§ã³ãéžæããŠæ£åœåããå¿
èŠããããŸãã ãœãªã¥ãŒã·ã§ã³ãéžæããããã»ã¹ã§ã¯ãæœèšãæè¡ãæ
å ±è³ç£ãè«è² æ¥è
ãããã³ããŒãããŒã«é¢ããèããããã¢ã¯ã·ã§ã³ã詳现ã«æ€èšããå¿
èŠããããŸãã ãããã®æ±ºå®ã¯éåžžã次ã®ç®çã§éžæãããŸãã
-äŒç€Ÿã®åªå
掻åã®ä¿è·ã
-圌ãã®å¹æçãªå埩;
-ã€ã³ã·ãã³ãã®çµæã®ç·©åã察å¿ã®éçºããã³äºé²æªçœ®ã
泚ïŒãœãªã¥ãŒã·ã§ã³ã®éžæã¯ã埩æ§ã®ã³ã¹ããšããŠã³ã¿ã€ã ã®ã³ã¹ãã«åºã¥ããŠè¡ãå¿
èŠããããŸãããããã®æ±ºå®ã«ã¯ä»¥äžãå«ãŸããŸãã
-ããã©ãŒããã©ãããã©ãŒã ã
-ããããããµã€ãã
-ããŠã©ãŒã ããã©ãããã©ãŒã ã
-ãã³ãŒã«ãããµã€ãã
-åçãªè² è·åæ£ã®ããã®ãã©ãããã©ãŒã ã
-ã¢ãŠããœãŒã·ã³ã°\å¥çŽ;
-ã¢ãã€ã«ãã©ãããã©ãŒã ã
äœè«ïŒäžèšã®ãœãªã¥ãŒã·ã§ã³ã«ã€ããŠã¯ãå¥ã®èšäºã§è©³ãã説æããŸããäžèšã®ãœãªã¥ãŒã·ã§ã³ã®äž»ãªéãã¯ãäŒç€Ÿã®ã³ã¹ããšå埩æéã§ãã
泚æããŠãã ããïŒ ãœãªã¥ãŒã·ã§ã³ã¯ãå¹æçãªããžãã¹ç¶ç¶æ§æŠç¥ã®å®è£
ãæ¯æŽããŸãã ãã ããæé©ãªãªãã·ã§ã³ã決å®ããã«ã¯ãããžãã¹ãžã®åœ±é¿ã®åæçµæãšãªã¹ã¯è©äŸ¡ã®çµæã«åºã¥ããŠæŠç¥çãªæ±ºå®ãéžæããå¿
èŠããããŸãïŒãã®ã¢ãããŒãã¯ãçµå¶é£ãããžãã¹ç¶ç¶æ§ç®¡çãããžã§ã¯ããžã®æè³ã®å¿
èŠæ§ãæ£åœåããã®ã«åœ¹ç«ã¡ãŸãïŒã
äºæ¥ç¶ç¶èšç»ã®éçºãšå®æœèšç»ã¯ãäœæ¥ã®å®æœã®é åºãé åºãããã³æéãèŠå®ããäºåã«èšç»ããã枬å®ã·ã¹ãã ã§ãããã¹ããã©ã¯ãã£ã¹[1ã2ã4]ã«åŸã£ãŠãç¶ç¶æ§ç®¡çèšç»ã¯æ¬¡ã®3ã€ã®ã³ã³ããŒãã³ãã§æ§æããå¿
èŠããããŸãã
1.ç·æ¥å¯Ÿå¿-ã€ã³ã·ãã³ããæ€åºããããšãã«å®è¡ããå¿
èŠãããäžé£ã®ã¢ã¯ã·ã§ã³ã決å®ããŸãã
2.ã€ã³ã·ãã³ã管ç-ã€ã³ã·ãã³ãã®èŠæš¡ã軜æžãŸãã¯åæžããããã«å¿
èŠãªæ¹æ³ãå®çŸ©ããŸãã
3.ã¢ã¯ãã£ããã£ã®å埩-ç¹å®ã®ã¬ãã«ã§ãµãŒãã¹ã埩å
ããããã«å®è¡ããå¿
èŠãããäžé£ã®ã¢ã¯ã·ã§ã³ã決å®ããŸãã
泚ïŒæ確ã«ããããã«ããããŒãã£ãŒãããã®ä»ã®ã°ã©ãã£ã«ã«ãªæ¹æ³ã䜿çšããŠæ
å ±ã衚瀺ããŸããäºæ¥ç¶ç¶èšç»ã®ãµã³ãã«æ§é ïŒ
1.ã¯ããã«
1.1ã ãœãŒã¹æ
å ±
1.2ã èšç»ã®å¢ç
1.3ã èšç»ãäœæããããã®åææ¡ä»¶
2.ã³ã³ã»ãã
2.1é£ç¶æ§ã·ã¹ãã ã®èª¬æ
2.2ãé£ç¶æ§ãå埩ããæé ã®èª¬æ
2.3圹å²ãšãã®è²¬ä»»
3.ã¢ã¯ãã£ããŒã·ã§ã³ãã©ã³
3.1ãåºæºãšã¢ã¯ãã£ããŒã·ã§ã³æé
3.2ãé¢ä¿è
ãžã®éç¥æé
3.3ãã€ã³ã·ãã³ãã®è©äŸ¡æé
4.å¶åŸ¡
5.ãªã«ããªãŒ
5.1é£ç¶æ§å埩ã·ãŒã±ã³ã¹
NISTã®å°é家ãã¬ã€ã[1]ãäœæããŸãããããã¯ãå¿
èŠãªããžãã¹ç¶ç¶æ§èšç»ãåå詳现ã«èª¬æããŠããŸãã 以äžã¯ãåèšç»ïŒNISTããã¥ã¢ã«ã§æå®ãããŠããïŒãšããã®ãããªèšç»ã®éçºãå¿
èŠãšããæšæº/ NLAãžã®ãªã³ã¯ã説æããè¡šã§ãã
èšç»ã®åå | èšç»ã®èª¬æ | æšæº/èŠç¯ |
---|
äºæ¥ç¶ç¶èšç»ïŒBCPïŒ äºæ¥ç¶ç¶èšç» | ã€ã³ã·ãã³ãçºçæã®äœ¿çšãèæ
®ããŠéçºãèŠçŽãæŽæ°ãããäžé£ã®ææžåãããæé ã§ãããäŒæ¥ãéèŠãªéèŠãªæŽ»åãèšå®ããã蚱容ã¬ãã«ã§ç¶ç¶ããŠå®è¡ã§ããããã«ããããšãç®çãšããŠããŸãã | ISO 22301ã瀟äŒä¿éã äºæ¥ç¶ç¶ç®¡çã·ã¹ãã ãïŒ 8.4.4äºæ¥ç¶ç¶èšç» |
éçšç¶ç¶èšç»ïŒCOOPïŒ äºæ¥ç¶ç¶èšç» | 代æ¿ãµã€ãã§ã®äŒç€Ÿã®éèŠãªæ©èœã®åŸ©å
ãšã30æ¥ä»¥å
ã®å®è£
ã«çŠç¹ãåœãŠãŠããŸãã | - |
å±æ©ã³ãã¥ãã±ãŒã·ã§ã³èšç» å±æ©ã³ãã¥ãã±ãŒã·ã§ã³èšç» | ãã®èšç»ã«ã¯ãç·æ¥æã®å€éšããã³å
éšéä¿¡ã®æé ãšèŠåãææžåãããŠããŸãã | 1994幎12æ21æ¥ã®é£éŠæ³ç¬¬68å·ãèªç¶ããã³æè¡çç·æ¥äºæ
ããã®äººå£ãšå°åã®ä¿è·ã«ã€ããŠãïŒ ç¬¬14æ¡ç·æ¥äºæ
ãã人å£ãšå°åãä¿è·ããåéã®çµç¹ã®çŸ©å
|
éèŠã€ã³ãã©ä¿è·èšç»ïŒCIPïŒ éèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ä¿è·èšç» | ãã®èšç»ã¯ãåœå®¶ã€ã³ãã©ã®äž»èŠãªãªãœãŒã¹ãšã³ã³ããŒãã³ããä¿è·ããããšãç®çãšããŠããŸãã | 2013幎1æ15æ¥N 31sã®ãã·ã¢é£éŠå€§çµ±é 什ããã·ã¢é£éŠã®æ
å ±ãªãœãŒã¹ã«å¯Ÿããã³ã³ãã¥ãŒã¿ãŒæ»æã®çµæãæ€åºãé²æ¢ãæé€ããããã®åœå®¶ã·ã¹ãã ã®äœæã«ã€ããŠãã |
ãµã€ããŒã€ã³ã·ãã³ã察å¿èšç» ãµã€ããŒã€ã³ã·ãã³ã察å¿èšç» | ããã«ãŒæ»æãæ
å ±ã·ã¹ãã ãžã®äŸµå
¥ãããã³ãã®ä»ã®ã»ãã¥ãªãã£åé¡ã«é¢é£ããã€ã³ã·ãã³ããžã®å¯Ÿå¿æé ã説æããèšç»ã | GOST R ISO / IEC TO 18044-2007ãæ
å ±æè¡ã ã»ãã¥ãªãã£æ¹æ³ãšããŒã«ã æ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã管çã; NIST 800-61ãã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ã ã€ã³ã·ãã³ãåŠçã¬ã€ããã
|
çœå®³åŸ©æ§èšç»ïŒDRPïŒ çœå®³åŸ©æ§èšç» | äºæ
åŸã®äŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®åŸ©å
ãèšç»ããŸãã | ISO 22301ã瀟äŒä¿éã äºæ¥ç¶ç¶ç®¡çã·ã¹ãã ãïŒ 8.4.5å埩ã |
æ
å ±ã·ã¹ãã ç·æ¥æ察å¿èšç»ïŒISCPïŒ æ
å ±ã·ã¹ãã ã®ç·æ¥èšç» | ã¯ã©ãã·ã¥åŸã®ã·ã¹ãã ããããã¯ãŒã¯ãããã³ã³ã¢ã¢ããªã±ãŒã·ã§ã³ã®å埩èšç»ã ãã®èšç»ã¯ãéèŠãªã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ããšã«äœæããå¿
èŠããããŸãã | - |
ä¹å¡ç·æ¥èšç»ïŒOEPïŒ ç·æ¥æ察å¿èšç» | ãã®èšç»ã¯ãç·æ¥æã«äººå¡ã®å®å
šã確ä¿ããããã®æé ãšé¿é£æé ãå®çŸ©ããŠããŸãã | 1994幎12æ21æ¥ã®é£éŠæ³ç¬¬68å·ãèªç¶ããã³æè¡çæ§è³ªã®ç·æ¥äºæ
ããã®äººå£ããã³é åã®ä¿è·ã«ã€ããŠãã 1994幎12æ21æ¥ã®é£éŠæ³ç¬¬69å·ãç«çœå®å
šã«é¢ãããã |
äžèšã®ææžã¯äŒç€Ÿã®ããŒãºã«åºã¥ããŠäœæãããŠããŸãããå®éã«ã¯æ¬¡ã®ã¿ã€ãã®èšç»ãæãé »ç¹ã«é©çšãããŸãã
-ã€ã³ã·ãã³ã察å¿èšç»-ãã®ã¿ã€ãã®èšç»ã«ã¯ããµã€ããŒã€ã³ã·ãã³ã察å¿èšç»ãæ
å ±ã·ã¹ãã ã®ç·æ¥æ察å¿èšç»ãå«ãŸããå ŽåããããŸãã ãã®èšç»ã¯ãçœå®³ã®èŠæš¡ãçž®å°ãããã®çµæã軜æžããã®ã«åœ¹ç«ã¡ãŸããããã«ãããæéãç¯çŽããæ©äŒãåŸãããä»ã®ã¿ã€ãã®èšç»ãã¢ã¯ãã£ãåããéã®è¿œå ã®å©ç¹ãåŸãããŸãã
-人å¡ã®ç·æ¥è¡åèšç»-1994幎12æ21æ¥ã®é£éŠæ³ç¬¬68 68å·ãèªç¶ããã³æè¡çç·æ¥äºæ
ããã®äººå£ãšé åã®ä¿è·ãããã³1994幎12æ21æ¥ã®é£éŠæ³ç¬¬69å·ãç«çœå®å
šâãã®èšç»ã¯ãã¹ãŠã®äŒæ¥ã«å¿
é ã§ãã
-é害å埩èšç»-éèŠãªæ
å ±ã·ã¹ãã ã®å埩ã«çŠç¹ãåœãŠãŠããŸãã ãã®ã¿ã€ãã®èšç»ã¯ãããžãã¹ç¶ç¶æ§èšç»ããµããŒãããåã
ã®ã·ã¹ãã ããã³ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ã埩å
ããããšãç®çãšããŠããŸãã
-äºæ¥ç¶ç¶èšç»-ç·æ¥æããã³ç·æ¥åŸã®äŒç€Ÿã®ããžãã¹ããã»ã¹ã®ãµããŒãã«éç¹ã眮ããŠããŸãã ããã¯ãäŒç€Ÿã確ç«ããã蚱容ã¬ãã«ã§éèŠãªã¿ã€ãã®æŽ»åãå®è¡ãç¶ããå¯èœæ§ã確ä¿ããããšãç®çãšããŠããŸãã
-å±æ©é²æ¢ã³ãã¥ãã±ãŒã·ã§ã³èšç»-ãã®èšç»ã¯ãå±æ©çç¶æ³ã«ãããäŒç€Ÿã®è©å€ãç¶æããã®ã«åœ¹ç«ã¡ãŸãã ã¡ãã£ã¢ãæ³å·è¡æ©é¢ãç·æ¥äºæ
çãªã©ãšã®ããåãã®æé ãææžåããŠããŸãã
泚æããŠãã ããïŒ äºæ¥ç¶ç¶èšç»ã®æ®µéã§ã¯ãäžéšã®äŒæ¥ã¯æè¡çãªãœãªã¥ãŒã·ã§ã³ã«çŠç¹ãåœãŠãŠãããçµç¹çãªå¯ŸçãéèŠããŠããŸããã ãã®ç¹ã§ãçµç¹çãªå¯Ÿçã®å¿
èŠæ§ãæè¡çãªå¯Ÿçãšãšãã«ç€ºãå¿
èŠããããŸãã ãããè¡ãã«ã¯ããã¬ãŒãã³ã°ã»ãããŒããã¹ãèšç»ããã¬ãŒãã³ã°è³æãçºè¡ãããŸãã
èšç»ã®ãã¹ããšã¬ãã¥ãŒäŒç€Ÿã®æŽ»åã«åœ±é¿ãåãŒãç¹å®ã®ç¶æ³ãçºçããå Žåã«ãèšç»ã®éçšæ§ãæ€èšŒããããã«ãã¹ããå®æœãããŸãã ãã¹ãèšç»ã¯ãäŒç€Ÿã®ã¿ã€ããšãã®ç®æšã«åºã¥ããŠéžæãããŸãã
ãã¹ãã¯ãå®éçã¡ããªãã¯ã䜿çšããŠITã·ã¹ãã ãŸãã¯ã³ã³ããŒãã³ãã®æ£åžžæ§ãæ€èšŒããè©äŸ¡ããŒã«ã§ãã
NIST Special Publication 800-84ãITèšç»ãšæ©èœã®ããã®ãã¹ãããã¬ãŒãã³ã°ãããã³æŒç¿ããã°ã©ã ã®ã¬ã€ãããã¹ãã®ç®æšã¯æ¬¡ã®ãšããã§ãã
-èšç»ã®èšŒæ ã®åé ã
-æ¹æ³è«çããã³æè¡çãµããŒãã®ååæ§ã®æ€èšŒã
-å¿
èŠãªã¹ãã«ãšç¥èã®ååŸã
ãã¹ãã®ç®çã決å®ãããåŸãã·ããªãªãéçºããããã¹ãæ¹æ³ã決å®ãããçµå¶é£ãšåæãããŸãã æãäžè¬çã«äœ¿çšãããæ¹æ³ã¯æ¬¡ã®ãšããã§ã[2]ïŒ
-ãã¹ã¯ãããæ€èšŒïŒåäžïŒ;
-æš¡å£ïŒæš¡å£ïŒ;
-å®å
šãªãã¹ãïŒå®å
šãªããžãã¹ç¶ç¶æ§ãã¹ãïŒã
äœè«ïŒäžèšã®ãã¹ãæ¹æ³ã«ã€ããŠã¯ãå¥ã®èšäºã§èª¬æããŸãããã¹ãåŸããã¹ãã®ã·ããªãªãšçµæãããã³äºæ¥ç¶ç¶èšç»ãæ¹åããããã®ææ¡ã瀺ãã¬ããŒããäœæãããŸãã
泚æããŠãã ããïŒ äŒæ¥ã¯ãç®æšãšè²¡åèœåã«åºã¥ããŠãã¹ãæ¹æ³ãéžæããå¿
èŠããããŸãã
泚æããŠãã ããïŒ å®å
šãªãã¹ãã¯å€ãã®æ¬ ç¹ãç¹å®ã§ããããæãå¹æçã§ããããªã¹ã¯ãé«ãããå®éã«ã¯ã»ãšãã©äœ¿çšãããŸããã ãã®ã¿ã€ãã®ãã¹ãã䜿çšããããšãäŒç€Ÿã決å®ããå Žåããªã¹ã¯ãæå°éã«æãã倧å¹
ãªããŠã³ã¿ã€ã ãé²ãããã«ãããŒãããŒã®ãµããŒããäŸé Œããããè«è² æ¥è
ã®ãµãŒãã¹ã䜿çšããå¿
èŠããããŸãã
ã¡ã³ããã³ã¹ããã³æŽæ°èšç»äžèšã®ããã«ãäŒæ¥ã®äºæ¥ç¶ç¶æ§ã®ç®¡çã¯åŸªç°çãªããã»ã¹ã§ãã ããã¯ãèšç»ã®åœ¢æã ãã«éå®ã§ããªãããšãæå³ããŸããèšç»ãæ¯å¹ŽããããŠæã«ã¯ããé »ç¹ã«ãäŸãã°æ¬¡ã®å Žåã«ç¶æãæŽæ°ãæ¹åããå¿
èŠããããŸãã
1. ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã
2.äŒç€Ÿã®çµç¹æ§é ã®å€æŽã
3.æ³åŸã®å€æŽã
4.ãã¹ãäžã®èšç»ã®äžåã®æ€åºã
èšç»ãææ°ã®ç¶æ
ã«ä¿ã€ã«ã¯ã次ãå®è¡ããå¿
èŠããããŸãã
-çœå®³åŸ©æ§ã¬ãã¥ãŒãç¶ç¶æ§ææžãããã³é¢é£æé ãå«ãå
éšç£æ»ãå®æœããŸãã
-èšç»ã®å®æœã«é¢ããå®æçãªå®è·µçãã¬ãŒãã³ã°ãå®æœããã
-ããžãã¹ç¶ç¶æ§ã®åé¡ãäŒç€Ÿã®å€æŽç®¡çããã»ã¹ã«çµ±åããŸãã
ãããã«äºæ¥ç¶ç¶ç®¡çã¯ãäŒæ¥ã§é©çšããããã¹ãŠã®å¯Ÿçããå®éã®è
åšã«é©åãªå
šäœçã§é©åãªè€åäœã«çµ±åããããšã«ãããäŒæ¥ãç¶ç¶çã«ãµãŒãã¹ãæäŸããç·æ¥äºæ
ã掻åã«äžãã圱é¿ãåé¿ããèµ·ããããæ害ãæå°éã«æããããšãã§ããŸã
ãã®è€åæœèšã¯ããµãŒãã¹ã®ç¶ç¶æ§ãšè£œåã®çç£ã確ä¿ããããã«ç€Ÿå
ã§å®è£
ããå¿
èŠããã7ã€ã®ã¹ããŒãžã§æ§æãããŠããŸãã
ãã®èšäºã§ã¯ããã·ã¢ã®çŸå®ãåèã«ããŠå段éã«ã€ããŠèª¬æãããã®ãããžã§ã¯ããå®è£
ããéã«æ³šæãã¹ãç¹ã«ã€ããŠèª¬æããŸãã
æåŠ1. ISO 22301瀟äŒã»ãã¥ãªãã£-ããžãã¹ç¶ç¶æ§ç®¡çã·ã¹ãã -èŠä»¶
2. GOST R 53647ãããžãã¹ç¶ç¶æ§ç®¡çã
3. GOST R ISO / IEC 31010-2011ãããªã¹ã¯ç®¡çã ãªã¹ã¯è©äŸ¡æ¹æ³ ''
4. NIST Special Publication 800-34 Rev. 1ãé£éŠæ
å ±ã·ã¹ãã ã®ç·æ¥æ察å¿èšç»ã¬ã€ãã
5. NIST Special Publication 800-84ãITèšç»ããã³æ©èœã®ããã®ãã¹ãããã¬ãŒãã³ã°ãããã³éåããã°ã©ã ã®ã¬ã€ãã
6.ããžãã¹ç¶ç¶æ§ç®¡çã®æçµãã³ãããã¯ç¬¬2çCopyright 2007 John WileyïŒSons Ltdã
7.äºæ¥ç¶ç¶ç®¡çå±éºããäŒç€Ÿãå®ãæ¹æ³ãã€ã±ã«ã»ã®ã£ã©ã¬ãŒãã¢ãœã³ãšãã¥ã±ãŒã·ã§ã³ãªãããã2003
8.
www.bcmpedia.org/wiki/BCM_Body_of_Knowledge_ïŒBCMBoK ïŒ
Softline Webãµã€ãã®ãããžã§ã¯ãã«é¢ããæ
å ±ïŒ
services.softline.ru/security/upravleniya-ibEvgeny Kachurovãã³ã³ãµã«ã¿ã³ããåæéšããœããã©ã€ã³