ãã¹ã¯ãŒãã¬ã¹èªèšŒã§ã¯ããã¹ã¯ãŒãããã®ä»ã®ç¥èããŒã¹ã®èŠçŽ ãæ å ±ã䜿çšããã«ã ãŠãŒã¶ ID ãæ€èšŒããããã®ä»£ããã«ãã»ãã¥ãªãã£ã»ããŒã ã¯ããŠãŒã¶ãäžæã«èå¥ãããªããžã§ã¯ãïŒã¢ãã€ã«ã»ãã¹ããŒãããŒããŠã§ã¢ã»ã»ãã¥ãªãã£ã»ããŒãªã©ïŒã§ãããæã£ãŠãããã®ãã¿ã€ãã®èªèšŒèŠçŽ ããŸãã¯ããããã®ãã¿ã€ãã®èªèšŒèŠçŽ ïŒæçŽãé¡ã¹ãã£ã³ãªã©ã®ãã€ãªã¡ããªã¯ã¹ãªã©ïŒã®ããããã䜿çšããŠããŠãŒã¶ã®èº«å ãæ€èšŒããããå®äºããããã«äœ¿çšãããŸãã å€èŠçŽ èªèšŒ (MFA)ã®èŠä»¶ãš ã·ã³ã°ã«ã»ãµã€ã³ãªã³ ïŒSSOïŒãšäœµçšããããšã§ããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ãŠãŒã¶ã»ãšã¯ã¹ããªãšã³ã¹ãåäžãããã»ãã¥ãªãã£ã匷åããITéçšã®ã³ã¹ããšè€éãã軜æžããããšãã§ããŸãã ããã«ããã¹ã¯ãŒãã®çºè¡ãããŒããŒã·ã§ã³ãèšæ¶ããªã»ããã®å¿ èŠæ§ããªããããšã§ããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ããã«ããã¹ã¯ã®ä»¶æ°ãæžããããã°ã€ã³æéãççž®ããããšã§çç£æ§ãåäžãããITããŒã ããã䟡å€ã®é«ãã¿ã¹ã¯ã«è§£æŸããã
MFA ãšãã¹ã¯ãŒãã¬ã¹èªèšŒã¯ã©ã¡ããããŠãŒã¶ãèªåã®èº«å ã確èªããããã«ãã¹ã¯ãŒã以 äžã®ãã®ãæäŸããããšãèŠæ±ããããšã«ãã£ãŠã»ãã¥ãªãã£ãåäžããããããããäž¡è 㯠1 ã€ã®éèŠãªç¹ã§ç°ãªãïŒMFA ã¯ããŠãŒã¶ãèªåã®èº«å ã確èªããããã« 2 ã€ä»¥äžã®ç¬ç«ããèŠçŽ ãæäŸããããèŠæ±ããããšã§ã»ã㥠ãªãã£ãåäžããããããããã®èŠçŽ ã® 1 ã€ã¯ãã¹ã¯ãŒãã§ããå¯èœæ§ãéåžžã«é«ãã
äžæ¹ããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ããã¹ã¯ãŒããå®å šã«åé¿ããããããã¹ã¯ãŒããããããè匱æ§ãå®å šã«æé€ãã管çã®æéããã«ããã¹ã¯ã®è² æ ããªããããšãã§ããã
ãããã³ã°ããããã
ææãåºæã®èŠçŽ ãšã¯ç°ãªããåŸæ¥ã®èªèšŒã¯ããã¹ã¯ãŒãã®ãããªãŠãŒã¶ãç¥ã£ãŠãããã®ã ãã«åºã¥ããŠããããã®æ§è³ªäžãåå©çšãçé£ããã£ãã·ã³ã°ã«å¯ŸããŠè匱ã§ããããã®ãã 2025 ãã©ã€ãŸã³ ããŒã¿äŸµå®³èª¿æ»å ±åæž ã«ãããšã2024幎ã«ã¯280äžä»¶ã®ãã¹ã¯ãŒããæµåºãŸãã¯å ¬ã«æŒæŽ©ãã54%ã®ã©ã³ãµã ãŠã§ã¢ããã¹ã¯ãŒãã«çŽæ¥é¢é£ããŠããã
ç¶ç¶çãªç®¡ç
ITã¹ã¿ããããŠãŒã¶ãŒããåžžã«ãã¹ã¯ãŒãã管çããªããã°ãªããªããå¹³åçãªãŠãŒã¶ãŒã«ãšã£ãŠãè€éãã®ç°ãªããã¹ã¯ãŒããåžžã«ç®¡çããããšã¯ãæäœéé¢åãªããšã§ããããã°ãã°ææŠã§ãããããã¹ã¯ãŒããå¿ãããšãä»äºãé ããããã¢ã«ãŠã³ããããã¯ã¢ãŠãããããããŸããèšæ¶ãå©ããããã«ããŠãŒã¶ã¯ãã°ãã°ã¢ã«ãŠã³ãéã§ãã¹ã¯ãŒããåå©çšããããæžãçãããããŠããã§ã«è匱ãªã·ã¹ãã ãããã«å±éºã«ãããããã¹ã¯ãŒãã®åå©çšã¯ãŸããä¹ã£åãããã£ãã·ã³ã°ãããŒã¿æŒæŽ©ã®åœ±é¿ãå¢å€§ãããæ»æè ãçãã 1ã€ã®ãã¹ã¯ãŒãã§è€æ°ã®ã¢ã«ãŠã³ãã®ããã¯ãè§£é€ããããšãå¯èœã«ããã
ãã¹ã¯ãŒãã®é«ãã³ã¹ã
ITæ åœè ã«ãšã£ãŠãæ£åœãªãŠãŒã¶ã®ãã¹ã¯ãŒããªã»ããã管çããããšã¯ãé«é¡ã§æéã®ãããäœæ¥ãšãªããŸããå€§äŒæ¥ã§ã¯ãITãã«ããã¹ã¯ã®ã³ã¹ãã®æå€§ 50ïŒ ããã¹ã¯ãŒããªã»ããã«å ãŠãããŠãããåŸæ¥å¡ã®ãã¹ã¯ãŒããªã»ãã察å¿ã ãã§å¹Žé100äžãã«ä»¥äžã®äººä»¶è²»ããããããšããããŸãããŸãããã¹ã¯ãŒããªã»ãã察å¿ã«æéãå²ãããšã§ããã䟡å€ã®é«ãããžã¿ã«ãã©ã³ã¹ãã©ãŒã¡ãŒã·ã§ã³ã®æšé²ãé«åºŠãªãµã€ããŒæ»æãžã®é²åŸ¡ã«æ³šåã§ããªããªããšããåé¡ããããŸãã
ã»ãã¥ãªãã£
è匱ãªã¯ã¬ãã³ã·ã£ã«ãçãŸããã¯ã¬ãã³ã·ã£ã«ã¯ãçµç¹ãçŽé¢ããæãé »ç¹ã§æãæå®³ãªè åšãã¯ã¿ãŒã®äžã€ã§ããããã® IBM ããŒã¿äŸµå®³ã®ã³ã¹ãã»ã¬ããŒã ã«ãããšããã£ãã·ã³ã°ã¯ããŒã¿æŒããã®æãé »ç¹ãªåå ã®1ã€ã§ãããå¹³å$488äžãã«ãå°ã蟌ãã«å¹³å261æ¥ãèŠããããã£ãã·ã³ã°æ»æãäžè¬çã«èªèšŒæ å ±ãç¹ã«ãã¹ã¯ãŒããæšçãšããŠããããšãèãããšããã®çµ±èšã¯ããã¹ã¯ãŒããçµç¹ã«ããããé倧ãªãµã€ããŒã»ãã¥ãªãã£ã»ãªã¹ã¯ãšããã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã®å°å ¥ã®éèŠæ§ã匷調ããŠããã
ãã¹ã¯ãŒããæŒæŽ©ããå Žåãçµç¹ã¯ããŒã¿ã®çé£ãééçæå€±ãè©å€ã®äœäžã«ã€ãªããæ·±å»ãªãªã¹ã¯ã«çŽé¢ãããã»ãã¥ã¢ãªã¯ã¬ãã³ã·ã£ã«ã»ããªã·ãŒãåªå ãããã¹ã¯ãŒãã¬ã¹ã«ç§»è¡ããããšã¯ããã®ãããªé »çºããåé¿å¯èœãªè匱æ§ã«åããããã«äžå¯æ¬ ãªã¹ãããã§ããã
ãŠãŒã¶ã»ãšã¯ã¹ããªãšã³ã¹
ãŠãŒã¶ã»ãšã¯ã¹ããªãšã³ã¹ã®èгç¹ããèŠããšãå¹³åçãªäŒæ¥ãŠãŒã¶ã¯ æ¥åé¢é£ã®ã¢ã«ãŠã³ãã§ç ©éãª87å, éè·ã§ãããã»ãã¥ãªãã£äžã®ãªã¹ã¯ã§ãããããã® 2025 RSA ID IQã¬ããŒã ã«ãããšãå šåçè ã®ãã¡51%以äžããæ¯æ¥ä»äºã§6å以äžãã¹ã¯ãŒããå ¥åããªããã°ãªããªãã£ããè€æ°ã®ãã¹ã¯ãŒããèŠãã管çããããšã¯ããã¹ã¯ãŒãã®åå©çšãå®å šã§ãªãä¿åãªã©ã®æªç¿æ £ã«ã€ãªãããçµç¹ã®ãµã€ããŒã»ãã¥ãªãã£ã»ãªã¹ã¯ãããã«é«ããããšã«ãªãããŠãŒã¶ãŒèªèšŒãç°¡çŽ åããããšã¯ãã»ãã¥ãªãã£ã匷åããã ãã§ãªããåŸæ¥å¡ã®æ¥ã ã®äœéšãæ¹åãããã©ã¹ãã¬ãŒã·ã§ã³ã軜æžããããè¯ããã¹ã¯ãŒãè¡çãä¿é²ããŸãã
ããŒã¿ã«ã³ã¹ããïŒTCO)
ãã¹ã¯ãŒã管çã®ç·ææã³ã¹ãã¯é«ãããã¹ã¯ãŒãã®ãªã»ããèŠæ±ã¯ãITãã«ããã¹ã¯ã®ã³ãŒã«ä»¶æ°ã®æå€§50%ãå ããŠããŸããåãªã»ããèŠæ±ã¯ãããæŠç¥ç㪠IT ã€ãã·ã¢ããã«äœ¿çšã§ããæéãšãªãœãŒã¹ãæ¶è²»ããŸããããå®å šã§å¹ççãªèªèšŒæ¹æ³ã«ãã£ãŠãã¹ã¯ãŒãã»ãªã»ããã®åæ°ãæžããããšã§ãã³ã¹ããåæžããæ¥åå¹çãåäžãããããšãã§ããŸãã
ãã¹ã¯ãŒãã¬ã¹èªèšŒã¯ããŠãŒã¶ã®ã¢ã€ãã³ãã£ãã£ãäžã€ã®åŒ·åãªæ¹æ³ã§ä¿èšŒããŸããçµç¹ã«ãšã£ãŠãããã¯ä»¥äžã®ããšãæå³ããŸãïŒ
- ããè¯ããŠãŒã¶ã»ãšã¯ã¹ããªãšã³ã¹ïŒãŠãŒã¶ã¯ãã¯ãè€éãªãã¹ã¯ãŒãããŠãŒã¶åã®çµã¿åãããèŠãããæŽæ°ãããããå¿ èŠããªããªããçç£æ§ãé«ããããšãã§ããŸããèªèšŒãç°¡çŽ åãããããšã§ããŠãŒã¶ã¯ã¹ãã¬ã¹ãæããããšãªããããéããã°ã€ã³ã§ããããã«ãªããŸãã
- ãã匷åºãªã»ãã¥ãªãã£äœå¶ïŒãŠãŒã¶ã管çãããã¹ã¯ãŒãããªãããããããã³ã°ããããã¹ã¯ãŒãèªäœãååšãããããã«ããäžé£ã®è匱æ§ãšããŒã¿äŸµå®³ã®äž»èŠãªåå ãæé€ãããŸãã
- ç·ææã³ã¹ãïŒTCOïŒã®åæžïŒãã¹ã¯ãŒãã¯é«äŸ¡ã§ãITã¹ã¿ããã«ããåžžæç£èŠãšã¡ã³ããã³ã¹ãå¿ èŠã§ãããã¹ã¯ãŒããåé€ããããšã§ããã¹ã¯ãŒãã®çºè¡ãä¿è·ãããŒããŒã·ã§ã³ããªã»ããã管çãäžèŠã«ãªããŸããããã«ããããã«ããã¹ã¯ããµããŒããã±ããã®éãæžããITéšéã¯ããå·®ãè¿«ã£ãåé¡ã«å¯ŸåŠã§ããããã«ãªããŸãã
- IT管çãšå¯èŠæ§ïŒãã¹ã¯ãŒãã§ä¿è·ãããã·ã¹ãã ã§ã¯ããã£ãã·ã³ã°ãåå©çšãå ±æãäžè¬çãªåé¡ã§ãããã¹ã¯ãŒãã¬ã¹èªèšŒã«ãããITéšéã¯ã¢ã€ãã³ãã£ãã£ãšã¢ã¯ã»ã¹ç®¡çã®å®å šãªå¯èŠæ§ãåãæ»ããŸãã
- èŠæš¡ã«å¿ããã¯ã¬ãã³ã·ã£ã«ã®ã©ã€ããµã€ã¯ã«ç®¡çïŒ ãšã³ã¿ãŒãã©ã€ãºã»ã°ã¬ãŒãã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ å€ãã®å ŽåãFIDO ãã¹ããŒãã¢ãã€ã«èªèšŒæ å ±ãªã©ã倿§ãªãŠãŒã¶ãŒã°ã«ãŒãã«ãããèªèšŒæ å ±ã®å šã©ã€ããµã€ã¯ã«ã管çããããŒã«ãå«ãŸããŠãããããã«ãããåŸæ¥å¡ãè«è² æ¥è ãããã³é«ãæš©éãæã€ãŠãŒã¶ã®å®å šãªãªã³ããŒãã£ã³ã°ã倱å¹ãããã³å埩ãå¯èœã«ãªãã
ãã€ããªããç°å¢ã§ã®ããªã·ãŒå®æœ
ãã¹ã¯ãŒãã¬ã¹èªèšŒã®äž»ãªå©ç¹ã®1ã€ã¯ãã¯ã©ãŠãããã€ããªãããããã³ãªã³ãã¬ãã¹ã®ã¢ããªã±ãŒã·ã§ã³å šäœã§äžå çãªã¢ã¯ã»ã¹å¶åŸ¡ããµããŒãã§ããããšã§ãããè€æ°ã®ã¢ã€ãã³ãã£ãã£ã»ã·ã¹ãã ãç¶æããããããªã·ãŒãéè€ããããããã®ã§ã¯ãªããçµç¹ã¯çµ±äžãããã¢ã€ãã³ãã£ãã£ã»ã¢ãŒããã¯ãã£ã®äžã§ãã¹ã¯ãŒãã¬ã¹ãå®è£ ããããšãã§ãããããã«ãè€æ°ã®ãŠãŒã¹ã±ãŒã¹ã«å¯Ÿå¿ããããŒããŠã§ã¢ãšãœãããŠã§ã¢ãæäŸãããã³ããŒã1瀟ã«çµãããšã§ãäžè²«ãããŠãŒã¶ãŒã»ãšã¯ã¹ããªãšã³ã¹ã確ä¿ããããšãã§ããã
ååã瀺ãéãããã¹ã¯ãŒãã¬ã¹èªèšŒïŒãã¹ã¯ãŒãäžèŠèªèšŒïŒã¯ãæ¬äººç¢ºèªã®ããã«èšæ¶ããããã¹ã¯ãŒããå¿ èŠãšããŸããããã®ä»£ããã«ããŠãŒã¶ã¯ä»¥äžã®ãããªããå®å šãªæ¹æ³ã§èº«å ãèªèšŒããŸãïŒ
- ã¯ã³ã¿ã€ã ãã¹ã³ãŒãïŒOTPïŒã®çæ
- ã¢ãã€ã«ãã¹ããŒ
- QRã³ãŒã
- ã³ãŒããããã³ã°
- FIDO2 ã»ãã¥ãªãã£ããŒ
- èªèšŒããã»ã¹ãå®äºããããã®çäœèªèšŒ
ãã¹ã¯ãŒãã¬ã¹èªèšŒã¯ãããŸããŸãªèªèšŒãæå·åãããã³ã«ã䜿çšããŸãããã¹ã¯ãŒãã¬ã¹èªèšŒãšåŸæ¥ã®èªèšŒã®å€§ããªéãã®äžã€ã¯ãåŸæ¥ã®èªèšŒãšã¯ç°ãªãããã¹ã¯ãŒãã¬ã¹ã®èªèšŒæ å ±ã¯åºå®ããã䜿ãåãããªãç¹ã§ãããã®ä»£ããã«ãåã»ãã·ã§ã³ã®éå§æã«æ°ããèªèšŒããŒã¿ãçæãããŸãã
ãµã€ããŒã»ãã¥ãªãã£æšæºãšèŠå¶ã¯ãææ°ã®èªèšŒã¢ãããŒããæ€èšŒããäžã§äžå¯æ¬ ã§ããããããã¯ãã©ã®èªèšŒããµã€ã³ã€ã³æ¹æ³ãæè³ãæ§ç¯ãå±éãã䟡å€ãããããããŒã ã倿ããã®ã«åœ¹ç«ã€ãæ¿åºæ©é¢ãéè¡ãªã©ãèŠå¶ãå³ããè€éãªç°å¢ã§ã¯ãã·ã¹ãã èšèšãç£æ»ãã§ãã¯ãªã¹ãã®æéã«ããªãã
ãã¹ã¯ãŒãã¬ã¹èªèšŒã®å®è£ ãæåãããããšããçµç¹ã¯ãèŠå¶ãããç°å¢ãŸãã¯ã»ãã¥ãª ãã£ã»ãã¡ãŒã¹ãã®ç°å¢ã«ãããŠã調éãã¢ãŒããã¯ãã£ãå®è£ ã®æéãšãªãããŸããŸãªã ã¬ãŒã ã¯ãŒã¯ã«æ³šç®ããããšãã§ãããäŸãã°ããŒãã»ãã©ã¹ãæé©åããã³äžçŽã¹ããŒãžã§ã¯ããã¹ããŒãã»ãã¥ãª ãã£ã»ããŒã®ãããªãã£ãã·ã³ã°èæ§ã®ãããã¹ã¯ãŒãã¬ã¹èªèšŒãæ±ããŠããã
NIST 800-63æºæ
- NIST SP 800-63-3 ã¯ãç±³åœé£éŠæ¿åºæ©é¢ããã³éèŠã€ã³ãã©éšéã®ããžã¿ã« ID ã¬ã€ãã©ã€ã³ã®æŠèŠã瀺ããŠããã
- ãã¹ã¯ãŒãã¬ã¹èªèšŒã¯ãèªèšŒä¿èšŒã¬ãã«ïŒAAL2ããã³AAL3ïŒããµããŒãããã
- RSAã¯ãAAL3ãæºãããã£ãã·ã³ã°èæ§ã®èªèšŒæ©èœã§å€èŠçŽ èªèšŒããµããŒãããŠããŸãã
- FIDO2ããã€ãªã¡ããªã¯ã¹ãæå·ããŒã¯ã³ã®ãããªæ¹æ³ã¯ãNISTã®å§åã«ãããã³ã°ããããšãã§ããã
FIDO2ãšãã£ãã·ã³ã°èæ§
- RSAã¯ãããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ãªãŒã»ã³ãã£ã±ãŒã¿çšã®FIDO2ããã³WebAuthnæšæºããµããŒãããŠããŸãã
- FIDO2ã¯å ±æã®ç§å¯ãæé€ããïŒãã¹ã¯ãŒããä¿åããªãïŒ
- FIDOèªå®ããŒããŠã§ã¢ïŒäŸïŒRSA iShield Key 2ïŒã¯ããšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã®èŠä»¶ãæºãããŠããŸãã
- ãµããŒããããŠãããŠãŒã¹ã±ãŒã¹ã«ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã»ãã°ã€ã³ããŠã§ãã»ã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠãSSOãªã©ãããã
ãŒãã»ãã©ã¹ãã»ã¢ãŒããã¯ãã£ãŒïŒZTAïŒã®æŽåæ§
- ãŒãã»ãã©ã¹ãã¯ããŠãŒã¶ãŒãããã€ã¹ã«å¯Ÿããæé»ã®ä¿¡é Œãæ³å®ããŠããªãã
- ãã£ãã·ã³ã°ã«åŒ·ããã¹ã¯ãŒãã¬ã¹ïŒããã€ã¹ã»ãã€ã³ãã»ãã¹ããŒã»ã»ãã¥ãªãã£ã»ããŒïŒã¯ãç¶ç¶çèªèšŒãããã€ã¹ã»ãã€ã³ãã£ã³ã°ãã³ã³ããã¹ãã»ã¢ã¯ã»ã¹ããµããŒãããã
- RSAã¯ããªã¹ã¯ã»ã¹ã³ã¢ãªã³ã°ãè¡ååæãé©å¿åèªèšŒãçµ±åãããŒãã»ãã©ã¹ãã®ã¢ã¯ã»ã¹æ±ºå®ã宿œããŸãã
- ZTAã¯ãããåºç¯ãªIAM/GRCããã³ãšã³ããã€ã³ãã»ãã¥ãªãã£æŠç¥ãšé£æºããŠããã
ã¬ããã³ã¹ããªã¹ã¯ãã³ã³ãã©ã€ã¢ã³ã¹ïŒGRCïŒã®æºå
- 匷åãªèªèšŒã¯ãHIPAAãPCI-DSSãCJISãããã³ãã®ä»ã®ã³ã³ãã©ã€ã¢ã³ã¹äœå¶ã«ãŸãããèŠä»¶ã§ããã
- ãã¹ã¯ãŒãã¬ã¹ã¯ããã¹ã¯ãŒãã®ããŒããŒã·ã§ã³ããªã»ãããã°ãä¿ç®¡ããªã·ãŒãæé€ããããšã§ãç£æ»ç¯å²ãšç®¡çãªãŒããŒããããåæžããŸãã
- RSA ã¯ç£æ»èšŒè·¡ãš ID ä¿èšŒã¡ããªã¯ã¹ãæäŸããã
ãã¹ãŠã«ãã¹ã¯ãŒããäœ¿ãæ¹æ³ãããã¹ã¯ãŒãã¬ã¹ã®æªæ¥ãžç§»è¡ããã«ã¯ãäžæ©ãã€é²ããããšãéèŠã§ãã 以äžã®ãã¹ããã©ã¯ãã£ã¹ã掻çšããŠå®è£ ãé²ããŠãã ããïŒ:
- ãŠãŒã¶ã«è² æ ããããªã段éçãªã¢ãããŒããåã£ãŠãã ããããŸãã¯äžã€ã®ã¢ã¯ã»ã¹å°ç¹ããŠãŒã¶ã°ã«ãŒãããå§ããåŸã ã«æ¡å€§ããŠããããšã§ããŠãŒã¶ãã·ã¹ãã ãåŠã¶æéã確ä¿ã§ããŸãã
- ã»ãã¥ãªãã£ãšåããããå©äŸ¿æ§ã«ã泚åããŸããããèªèšŒæ¹æ³ã䜿ããããã»ã©ããŠãŒã¶ããã®ã«ãŒã«ãå®ãå¯èœæ§ãé«ãŸããŸãã
- ãŸãã¯è匱ãªç®æã«åŒ·åãªèªèšŒãé©çšããŸããããåŸæ¥ã®èªèšŒã§æãå±éºã«ãããããŠããå Žæã¯ã©ãã§ããïŒããããå§ããŠãã ããã
- ç®æšãèŠå€±ããªãã§ãã ãããçå®ãªæ¹åãç©ã¿éãªããŸãã
ã¯ã©ãŠãããã€ããªããããªã³ãã¬ãã¹ãã¬ã¬ã·ãŒã»ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãŸãããè€éãªITç°å¢ã§åãçµç¹ã¯ããã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ãè©äŸ¡ããéã«ã以äžã®è³ªåãããå¿ èŠãããïŒ
æ¢åã®ã€ã³ãã©ãå®å šã«åæ§ç¯ããããšãªãããã€ããªããç°å¢ããã«ãã¯ã©ãŠãç°å¢ã§ãã¹ã¯ãŒãã¬ã¹èªèšŒãæ¡åŒµããã«ã¯ã©ãããã°ããã®ã ãããã
ã»ãã¥ãªãã£ã匷åããã³ã¹ããæå¶ããããã«ãè€éãªç°å¢ã«ãŸãããçµç¹ã¯ãããããå Žæã§åããã¹ãŠã®ãŠãŒã¶ãŒããµããŒãã§ãããã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ãåªå ãã¹ãã§ããããã¹ã¯ãŒãããªããã° ãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã®ãœãªã¥ãŒã·ã§ã³, ãã®ãããªããããªãœãªã¥ãŒã·ã§ã³ã§ã¯ãã»ãã¥ãªãã£ã»ã®ã£ãããæ®ãããã®ãããªããããªãœãªã¥ãŒã·ã§ã³ã¯ãã»ãã¥ãªãã£ã»ã®ã£ãããæ®ãããŠãŒã¶ãŒã«ãšã£ãŠç®¡çãé¢åã§ãããã»ãã¥ãªãã£ã»ããŒã ã財åããŒã ã«ãšã£ãŠç®¡çãéå¹ççã§ããã
ãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã¯ãããããéå¹çæ§ãè§£æ¶ããŸããç°å¢å šäœã«ããã£ãŠ 1 ã€ã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããããšã§ãäŒæ¥ã¯ãã¹ãŠã®èªèšŒã«å¯Ÿããå æ¬çãªå¯èŠæ§ãç²åŸããããªã·ãŒãå€§èŠæš¡ã«å®æœããããšã§ã»ãã¥ãªãã£ã匷åã§ããŸããæè¯ã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã¯ãããªããã»ã¢ã³ãã»ãªãã¬ãŒã¹ãã®ã€ãã·ã¢ãããåãããšãªããã¬ã¬ã·ãŒãšãªã³ãã¬ãã¹ãžã®æè³ãç¶æããããšãå¯èœã«ããŸãã
ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã¯ããªã¢ãŒãããã³ãªã³ãµã€ãã®åŸæ¥å¡ã«äžè²«ããã»ãã¥ãªãã£ãšãŠãŒã¶ãŒã»ãšã¯ã¹ããªãšã³ã¹ãæäŸã§ãããïŒ
äžè²«ããã»ãã¥ãªãã£ãšãŠãŒã¶ãŒã»ãšã¯ã¹ããªãšã³ã¹ãæäŸããããã«ã¯ãããããç°å¢ã®ãããããŠãŒã¶ãŒããµããŒãã§ããäŒæ¥ã¬ãã«ã®ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ããäŒæ¥æšªæçãªãœãªã¥ãŒã·ã§ã³ããªããšãäŒæ¥ã¯åã ã®ãŠãŒã¶ãŒã»ã°ã«ãŒããç°å¢ã«ãã€ã³ãæ©èœãå°å ¥ããå¿ èŠãçããããã®ãããªãã€ã³ãã»ãœãªã¥ãŒã·ã§ã³ã§ã¯ãäžè²«ãããŠãŒã¶ãŒã»ãšã¯ã¹ããªãšã³ã¹ãæäŸã§ãããã»ãã¥ãªãã£ã»ã®ã£ãããçããŸãã
ã¬ããã³ã¹ãšã³ã³ãã©ã€ã¢ã³ã¹ã®ããã®ã«ã¹ã¿ãã€ãºå¯èœãªããªã·ãŒã³ã³ãããŒã«
ãã¹ã¯ãŒãã¬ã¹æŠç¥ã®æåã¯ã誰ãã¢ã¯ã»ã¹ã§ããããèå¥ãã匷åãªèªèšŒæ¹æ³ã䜿çšããã ãã§ãªãããŠãŒã¶ãŒãé©åãªãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãã¢ã¯ã»ã¹ã»ããªã·ãŒãçµç¹ã®ããŒãºã«åãããŠèª¿æŽããããšã«ãããã£ãŠãããå€ãã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã¯ãèšå®å¯èœãªããªã·ãŒã»ãšã³ãžã³ãæäŸããã»ãã¥ãªãã£ããã³ã³ã³ãã©ã€ã¢ã³ã¹ã»ããŒã ã圹å²ããŒã¹ã®ã¢ã¯ã»ã¹èš±å¯ãå®çŸ©ããè·ååæã宿œããç¹å®ã®ã¬ããã³ã¹èŠä»¶ã«ã¢ã¯ã»ã¹å¶åŸ¡ãé©åãããããšãå¯èœã«ããããããã®å¶åŸ¡ã¯ãç£æ»å¯èœæ§ãæå°æš©éã¢ã¯ã»ã¹ãæ¡ä»¶ä»ãèªèšŒã瀟å ããªã·ãŒãå€éšæšæºãšäžèŽããªããã°ãªããªãèŠå¶ç°å¢ã§ã¯äžå¯æ¬ ã§ãã
å€ãã®çµç¹ã¯ãActive DirectoryãLDAPãªã©ã®ãªã³ãã¬ãã¹IDãããã€ãã«é¢é£ããããã·ã§ã³ã¯ãªãã£ã«ã«ãªã€ã³ãã©ã«äŸåããŠãããæè»ãªãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã¯ããããã®ã¬ã¬ã·ãŒã»ã·ã¹ãã ãšã®çµ±åãå¯èœã§ãããšåæã«ãã¯ã©ãŠãã»ãã£ã¬ã¯ããªã«ã察å¿ããŠããªããã°ãªããªãããã®çžäºéçšæ§ã«ãããæ¢åã®ã€ã³ãã©ã«ææ°ã®èªèšŒãæ¡åŒµããããšã§ã¹ã ãŒãºãªç§»è¡ãå®çŸããæ··ä¹±ãæå°éã«æãããšãšãã«ãITããŒã ãã·ã¹ãã ãå šé¢çã«å ¥ãæ¿ããããšãªãIDã¢ã¯ã»ã¹ãçµ±äžã§ããããã«ãªããŸãã
å埩åã¯ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã«ãšã£ãŠéèŠã§ãããæ»æããã®ä»ã®æœåšçãªæ¥åäžæã®è åšã«ãããããŠãã確å®ã«æ¥åãç¶ç¶ã§ããããã«ããå¿ èŠããããDORAã NIS2 ã€ã³ã·ãã³ãå ±åãäºæ¥ç¶ç¶ããµãŒãããŒãã£ã»ãã¥ãªãã£ãªã©ã®åéã§ã®ã¬ã€ãã³ã¹ãå®ããŠããã
RSAã¯ãäžçã§æãåºãå°å ¥ãããŠããå€èŠçŽ èªèšŒïŒMFAïŒæ©èœãæäŸããŠãããã»ãã¥ãªãã£éèŠã®çµç¹ãããªã³ãã¬ãã¹ãã¯ã©ãŠãç°å¢ã§å©çšãããä¿¡é ŒãããŠããŸããRSAã®MFAã«ã¯ä»¥äžãå«ãŸããŸãïŒ
- FIDOèªå®ã®RSA iShield Key 2ã·ãªãŒãºããiOSããã³Androidåãã®RSA Authenticator App 4.5ãã¯ãããšããã倿§ãª ãã¹ã¯ãŒãã¬ã¹èªèšŒ ãªãã·ã§ã³ã«ã¯ãFIDOèªèšŒååŸåãå«ã ãRSA iShield Key 2ã·ãªãŒãºã ãŸãã RSA iOSããã³Androidã¢ãã€ã«ããã€ã¹åãèªèšŒã¢ããª4.5ïŒããã·ã¥æ¿èªãã³ãŒãç §åïŒæçŽããã³é¡èªèšŒãã€ãªã¡ããªã¯ã¹ïŒãBYOAïŒBring Your Own AuthenticatorïŒãïŒãããŠããŒããŠã§ã¢ããŒã¯ã³ïŒæé«æ°Žæºã®èªèšŒææ®µïŒããããã®åãœãªã¥ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒãã¯ã©ãŠã/SaaSãWebããŒã¹ã®ã¢ããªã±ãŒã·ã§ã³ããªãã³ã«Windowsããã³macOSãã·ã³ã«ãã°ã€ã³ããéããã£ãã·ã³ã°èæ§ãæäŸããæ©èœãåããŠããŸãã.
- RSA ReadyããŒãããŒã·ããã«ããã FIDOèªèšŒã®ãªãŒããŒäŒæ¥, FIDOããŒã¹ã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ãšããã«çžäºéçšã§ããã
- é«åºŠãªAIãšæ©æ¢°åŠç¿ã«ãããªã¹ã¯ã¹ã³ã¢ãªã³ã°ã«ãããããžãã¹ã³ã³ããã¹ããããã€ã¹å±æ§ãè¡ååæãªã©ã®ããŸããŸãªã·ã°ãã«ã«åºã¥ããŠã¢ã¯ã»ã¹ãªã¹ã¯ãç®åºããããã«å¿ããŠèªèšŒã匷åãŸãã¯ãããã¯ããŸããRSAã®ãã¹ã¯ãŒãã¬ã¹ç°å¢ã¯ãSplunkã®ãããªSOCããŒã«ãšãçµ±åã§ããŸãã
- ãã¹ã¯ãŒãã«äŸåããã¯ãŒã¯ãããŒãæé€ããä¿è·ãããã»ã«ããµãŒãã¹ã»ã¯ã¬ãã³ã·ã£ã«ç®¡çãªãã·ã§ã³ã«ããããªã³ããŒãã£ã³ã°ãã¯ã¬ãã³ã·ã£ã«å埩ãããã³ç·æ¥ã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ã匷åããã
- 99.99%+ã®å¯çšæ§ãšç¬èªã®ãã«ããã©ãããã©ãŒã ã«ããåžžææ¥ç¶ã®åŒ·åãªèªèšŒ ãã€ããªãããã§ã€ã«ãªãŒã㌠ãããã¯ãŒã¯æ¥ç¶ã鮿ãããå Žåã§ããå®å šã§äŸ¿å©ãªã¢ã¯ã»ã¹ãä¿èšŒããæ©èœ
ãã¹ã¯ãŒãã¬ã¹ã®æå³ãšã¯ïŒ
ãã¹ã¯ãŒãã¬ã¹åãšã¯ãèªèšŒæ¹æ³ãšããŠãã¹ã¯ãŒããæé€ããç»é²ãããã¢ãã€ã«ã»ããã€ã¹ãããŒããŠã§ã¢ã»ããŒã¯ã³ãªã©ã®çäœèªèšŒïŒããªããäœè ãã§ããããšïŒãææã«åºã¥ãèŠçŽ ïŒããªããäœããæã£ãŠããããšïŒãªã©ãããå®å šãªèŠçŽ ãéããŠãŠãŒã¶ãŒIDãæ€èšŒããããšãæå³ããããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ããŠãŒã¶ããã¹ã¯ãŒããèšæ¶ããªã»ããã管çããå¿ èŠæ§ããªãããšåæã«ããã£ãã·ã³ã°ãã¯ã¬ãã³ã·ã£ã«ããŒã¹ã®æ»æã«å¯Ÿãããã匷åãªé²åŸ¡ãæäŸããŸããRSAãå©çšããããšã§ãäŒæ¥ã¯ãã¹ã¯ãŒãã¬ã¹èªèšŒãåŸã ã«å°å ¥ãããªã¹ã¯ã®é«ããšãªã¢ããå§ããŠãå šç€Ÿçãªé©çšç¯å²ã«æ¡å€§ããããšãã§ããŸãã
ãã¹ã¯ãŒãã¬ã¹èªèšŒã§äžè¬çã«äœ¿ãããŠããæè¡ã¯ïŒ
ãã¹ã¯ãŒãã¬ã¹èªèšŒãœãªã¥ãŒã·ã§ã³ã¯ãFIDO2ã»ãã¥ãªãã£ã»ããŒããã€ãªã¡ããªã¯ã¹ïŒæçŽãŸãã¯é¡èªèšŒïŒãã¢ãã€ã«ã»ããã·ã¥éç¥ãããã€ã¹ã»ãã€ã³ãã»ã¯ã¬ãã³ã·ã£ã«ãã¯ã³ã¿ã€ã ã»ãã¹ã³ãŒãïŒOTPïŒãªã©ãå®å šãªæè¡ãçµã¿åãããŠäœ¿çšããŸããRSAã®ãã¹ã¯ãŒãã¬ã¹ã»ãªãã·ã§ã³ã«ã¯ããã£ãã·ã³ã°ã«åŒ·ãããŒããŠã§ã¢èªèšŒçšã®RSA iShield Key 2ã·ãªãŒãºããRSA Authenticatorã¢ããªãä»ããã¢ãã€ã«ã»ãã¹ããŒããããŸãããããã®ãã¯ãããžãŒã¯ãNIST 800-63ãFIDO2ãZero Trust Architectureãªã©ã®ãã¬ãŒã ã¯ãŒã¯ãšé£æºããŠããããã€ããªããç°å¢ã§ã®ã»ãã¥ã¢ã§ã¹ã±ãŒã©ãã«ãªå°å ¥ãå®çŸããŸãã
ãã¹ã¯ãŒãã¬ã¹ã¯æ¬åœã«å®å šãªã®ãïŒ
ããããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ãåŸæ¥ã®ãã¹ã¯ãŒãããŒã¹ã®æ¹æ³ãããæ Œæ®µã«å®å šãªã®ã ããã¹ã¯ãŒãã¯ããã£ãã·ã³ã°ãããããçãŸããããåå©çšããããããã«ãŒããã©ãŒã¹ããããããå¯èœæ§ããããããã»ãã¥ãªãã£ã®æã匱ããªã³ã¯ã§ããããšãå€ãããã¹ã¯ãŒããå®å šã«æé€ããããšã§ RSA ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ ãã£ãã·ã³ã°ãã¯ã¬ãã³ã·ã£ã«ã»ã¹ã¿ããã£ã³ã°ãäžéè æ»æããä¿è·ããäž»èŠãªæ»æãã¯ãã«ãæé€ããŸãããã£ãã·ã³ã°ã«èæ§ã®ããèªèšŒæ©èœãããã€ã¹ã«ãã€ã³ããããèªèšŒæ å ±ãããã³çäœèªèšŒã«ãããèªèšŒããããŠãŒã¶ãŒã«ã®ã¿ã¢ã¯ã»ã¹ãèš±å¯ãããèªèšŒæ å ±ã«åºã¥ã䟵害ã®ãªã¹ã¯ãåçã«äœæžããŸãã