ãã®ããã°ã¯2025å¹Žã«æ²èŒããããã®ã§ãã.
ããžã¿ã«ã»ãªãã¬ãŒã·ã§ãã«ã»ã¬ãžãªãšã³ã¹æ³ïŒDORAïŒãEUã§æ¡æããããšããéèæ©é¢ããµã€ããŒã»ãã¥ãªãã£ããªã¹ã¯ç®¡çãæ¥åç¶ç¶ã«ã©ã®ããã«åãçµãŸãªããã°ãªããªãããšããæ ¹æ¬çãªè»¢æã瀺ããããèŠå¶åœå±ã¯åããŠãåã«IDã»ãã¥ãªãã£ã«ã€ããŠèšåããã ãã§ãªããã³ã³ãã©ã€ã¢ã³ã¹ã«çŽæ¥çµã¿èŸŒãã ã®ã§ããã
ãã®é²åã¯ãå€ãã®ã»ãã¥ãªãã£å°éå®¶ãé·å¹Žã«ããã£ãŠèªèããŠããçŸå®ãããªãã¡ã¢ã€ãã³ãã£ãã£ãããžã¿ã«ã»ã»ãã¥ãªãã£ã®åºç€ã§ãããæ¥åå埩åã®èŠã§ãããšããããšãèªèããããã®ã§ããäœãå€ãã£ãã®ããDORAãã¢ã€ãã³ãã£ãã£ã»ã»ãã¥ãªãã£ã«äžãã圱é¿ãéèæ©é¢ãçŽé¢ãã課é¡ã2025å¹Žã®æéãŸã§ã«çµç¹ãDORAã®èŠä»¶ãæºããããã«CISOãã©ã®ããã«æºåããªããã°ãªããªãã®ããèŠãŠã¿ããã
DORAã®äžã§ã¯ãéèæ©é¢å ã®ãã¹ãŠã®ããžã¿ã«æ¥åïŒæ±ºæžãã顧客ãªã³ããŒãã£ã³ã°ãååŒã·ã¹ãã ã«è³ããŸã§ïŒã¯ãå®å šã§åŒŸåæ§ããããç¶ç¶çã«å©çšå¯èœã§ãªããã°ãªããªãããããŠãã¢ã€ãã³ãã£ãã£ã®ã»ãã¥ãªãã£ãæéèŠèª²é¡ãšãªã£ãŠããããªããªãã誰ãããã€ãã©ããããäœã«ã¢ã¯ã»ã¹ããŠããããæ€èšŒã§ããªããã°ãã¢ã€ãã³ãã£ãã£æŠç¥ã¯åŽ©å£ããŠããŸãããã ã
æ°ã㪠DORA èŠå¶ã®çŸå®ã«ãããŠãID ã¯ãã¯ãããã¯ãªãã£ã¹ã® IT æ©èœã§ã¯ãªãããªã¹ã¯ã»ãªãŒããŒãã³ã³ãã©ã€ã¢ã³ã¹ã»ãªãã£ãµãŒãããã³çµå¶å¹¹éšãåæ§ã«ææããæŠç¥çå¿ é äºé ãšãªã£ãŠããã
DORAã®ããã€ãã®æ¡é ã§ã¯ã匷åºãªIDããã³ã¢ã¯ã»ã¹ç®¡çïŒIAMïŒæ©èœãçŽæ¥çãŸãã¯æé»çã«èŠæ±ããŠãããäŸãã°
- ã¢ã¯ã»ã¹å¶åŸ¡ãšã¬ããã³ã¹:DORAã¯ãæ©é¢ã«å¯ŸãããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹æš©ããªã¢ã«ã¿ã€ã ã§ç®¡çããç¹æš©ã®ã¯ãªãŒããäžæ£ã¢ã¯ã»ã¹ã鲿¢ããããã«ã宿çãªã¢ã¯ã»ã¹ã¬ãã¥ãŒã宿œããããšã矩åä»ããŠããã
- èªèšŒèŠä»¶:å€èŠçŽ èªèšŒïŒMFAïŒã®ãããªåŒ·åãªèªèšŒæ¹æ³ã¯ãäžæ£ã¢ã¯ã»ã¹ããã·ã¹ãã ãä¿è·ããããšãæåŸ ãããŠããã
- äºæ¥ç¶ç¶æ§:æ©é¢ã¯ããµã€ããŒã€ã³ã·ãã³ããåé»ããŸãã¯æ··ä¹±ãçºçããŠããéèŠãªæ©èœãå©çšå¯èœã§ ããããšãä¿èšŒããªããã°ãªããªããããã«ã¯ã匷迫äžã§ã® ID ãµãŒãã¹ã®ç¶æãå«ãŸããã
- ç£èŠãšç°åžžæ€ç¥:çµç¹ã¯ãµã€ããŒã€ã³ã·ãã³ããè¿ éã«æ€åºãã察å¿ããå埩ããªããã°ãªããªããç°åžžãªã¢ã¯ã»ã¹ãã¿ãŒã³ãªã©ãã¢ã€ãã³ãã£ãã£ã«é¢é£ããç°åžžã¯æ¥µããŠéèŠãªææšã§ããã
ãããã®èŠä»¶ã¯ããªã¹ã¯ãèªèããææ°ã® ID ã»ãã¥ãªãã£ã»ããã°ã©ã ã®å¿ èŠæ§ã匷調ã ãŠããã
ã€ãŸããDORAãéµå®ããªãçµç¹ã«ã¯ãå šäžçã®å¹³å売äžé«ã®2%ããŸãã¯1æ¥ã®å¹³å売äžé«ã®1%ã®çœ°éã課ãããããã«éµå®ãéæãããŸã§æ¯æ¥çœ°éã課ãããããšã«ãªãã ä»ãè³ãéã¯é«ãã
ã»ãã¥ãªãã£ãžã®æè³ãå¢å ããŠããã«ãããããããå€ãã®éèæ©é¢ã¯ãã»ãã¥ãªãã£ã𠿥忩èœã«ããã ID é¢é£ã®ã®ã£ããã«èŠæ ®ããŠããïŒ
- ã¬ã¬ã·ãŒIAMã·ã¹ãã é©å¿æ§ãšèŠèªæ§ã«æ¬ ãã
- ãµã€ãåãããIDããŒã« ãªã³ãã¬ãã¹ç°å¢ãšã¯ã©ãŠãç°å¢ã«ãŸããã
- è匱ãªèªèšŒæ¹æ³ ãã£ãã·ã³ã°ã«åŒ±ã
- æäœæ¥ã«ããã¬ããã³ã¹ã»ããã»ã¹ ã³ã³ãã©ã€ã¢ã³ã¹å ±åã«æéããããããã¹ãèµ·ããããã
ãã®ãããªèª²é¡ã«ãããçµç¹ã¯æ»æè ã ãã§ãªããèŠå¶åœå±ã®ç£èŠãã³ã³ãã©ã€ã¢ã³ã¹ã®çœ°éã«ããããããããšã«ãªãã
éèéšéã® CISO ã¯ãID æŠç¥ã DORA ãšæŽåãããããã«äž»å°æš©ãæ¡ããªããã°ãªããªããã€ãŸã
- æ¡çš ãªã¹ã¯ã»ããŒã¹ã»ã¢ã¯ã»ã¹ ã³ã³ããã¹ããšè¡åã«åºã¥ããŠã³ã³ãããŒã«ã調æŽããã¢ãã«
- ç¢ºä¿ äºæ¥ç¶ç¶ èªèšŒãšã¢ã¯ã»ã¹ã®ãã€ããªãããã§ã€ã«ãªãŒããŒ
- 匷å ã¬ããã³ã¹ èªååãããããããžã§ãã³ã°ãã¬ãã¥ãŒãã¢ã¯ã»ã¹èªèšŒ
- æ±æ ãã¹ã¯ãŒãã¬ã¹èªèšŒ äžè¬çãªæ»æãã¯ãã«ãæé€ãã
DORAã®èŠå¶æèšã¯æç¢ºã§ããããã®å®æœæ¹æ³ã¯åçµç¹ã®èŠæš¡ãçµç¹æ§é ãããã³çŸç¶ã«ãã£ãŠç°ãªããŸãã以äžã®ã·ããªãªã§ã¯ãããŸããŸãªç¹åŸŽãæã€éèãµãŒãã¹äŒæ¥ããå®éã«DORAãžã®æºæ ã«ã©ã®ããã«åãçµãã§ãããã瀺ããŠããŸãã.
ã·ããªãª1ïŒDORAãžã®å¯Ÿå¿æºåãé²ããæ¬§å·ã®å€§æéè¡
èª²é¡ 12ã«åœã§äºæ¥ãå±éããEUã®å€§æãªããŒã«éè¡ã¯ãããå ±éã®åé¡ã«çŽé¢ããŠããŸããããã¯ãæ°å幎ã«ãããè²·åã«ãã£ãŠID管çã€ã³ãã©ãè¥å€§åãã7ã€ã®å¥ã ã®IAMã·ã¹ãã ãååšããããšãäºæ¥éšéããšã«MFAããªã·ãŒã«äžè²«æ§ããªãããšããããŠã¢ã¯ã»ã¹æš©éã®èŠçŽãã«æå€§30æ¥ããããããšã§ãã DORAã®ç¬¬9æ¡ã§å®ããããã¢ã¯ã»ã¹å¶åŸ¡ããã³ç¶ç¶çãªã¬ããã³ã¹ã®èŠä»¶ã«ç §ãããšããã®ãããªæçåã¯ã³ã³ãã©ã€ã¢ã³ã¹äžã®ã®ã£ããã§ãããšåæã«ããªãã¬ãŒã·ã§ãã«ãªã¹ã¯ãåãã§ããã.
é©çšãããDORAèŠä»¶
- 第9æ¡ïŒICTãªã¹ã¯ç®¡çãã¬ãŒã ã¯ãŒã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãããã³æå°æš©éã®åŸ¹åº
- 第10æ¡ïŒç°åžžãªæŽ»åããã³ICTé¢é£ã€ã³ã·ãã³ãã®æ€ç¥
- 第17æ¡ïŒICTé¢é£ã€ã³ã·ãã³ã管çããã»ã¹
å®è£ æé
- ID管çã·ã¹ãã ãåäžã®ãã©ãããã©ãŒã ã«çµ±åããïŒRSA ID Plus) ãã¹ãŠã®åäŒç€Ÿã«ãããŠãã¯ã©ãŠãããªã³ãã¬ãã¹ãããã³ãã€ããªããç°å¢ããµããŒãããŠããŸãã.
- ãã£ãã·ã³ã°å¯Ÿçæ©èœãåããMFAãå°å ¥ããïŒRSA iShield Key 2 ã·ãªãŒãº) 90æ¥ä»¥å ã«ããã¹ãŠã®ç¹æš©ã¢ã«ãŠã³ãããã³ç®¡çè ã¢ã«ãŠã³ãã«ã€ããŠã.
- 以äžã®æ©èœã䜿çšããŠãã¢ã¯ã»ã¹èªèšŒããã³ããããžã§ãã³ã°ã®ã¯ãŒã¯ãããŒãèªååããŸãã RSAã¬ããã³ã¹ãšã©ã€ããµã€ã¯ã«, ãæäœæ¥ã«ããã¹ãã¬ããã·ãŒããçšãã確èªäœæ¥ã«åã£ãŠä»£ããã.
- æå¹ã«ãã RSAãªã¹ã¯AI ç¶ç¶çãªè¡ååæããã³ãªã¢ã«ã¿ã€ã ã®ç°åžžæ€ç¥ã®ããã«ã.
- DORAã³ã³ãã©ã€ã¢ã³ã¹å ±åããã·ã¥ããŒãã«çŽæ¥é£æºãããäžå åãããIAMç£æ»èšŒè·¡ãæ§ç¯ããã.
æåææš
- å¯©æ»æéã30æ¥ãã3æ¥ã«ççž®
- ãã©ãããã©ãŒã ã®å°å ¥ãã60æ¥ä»¥å ã«ããã£ãã·ã³ã°å¯Ÿçæ©èœãåããå€èŠçŽ èªèšŒïŒMFAïŒã«ç»é²ãããç¹æš©ã¢ã«ãŠã³ãïŒ100%
- ååæããšã«èªåçã«çæããããç£æ»å¯Ÿå¿æžã¿ã®ã¢ã¯ã»ã¹èªèšŒã¬ããŒã
- DORAã«ããåã®èŠå¶æ€æ»ã«ãããŠãèªèšŒé¢é£ã®ã€ã³ã·ãã³ãã¯1ä»¶ãææãããªãã£ã
éèŠãªæèš çµ±åã¯åãªãã³ã³ãã©ã€ã¢ã³ã¹ãããžã§ã¯ãã§ã¯ãªããã¬ãžãªãšã³ã¹åäžã®ããã®ãããžã§ã¯ãã§ããçµ±åãããIAMãã©ãããã©ãŒã ã¯ãçžäºã«é£æºããŠããªãã·ã¹ãã éã®ç¶ãç®ã«ååšããæ»è§ãè§£æ¶ããŸãããŸãã«ãã®æ»è§ããããæ»æè ãéãæ¢ãæ±ããå Žæãªã®ã§ãã.
ã·ããªãª 2ïŒãã€ããªããã€ã³ãã©ãéçšããäžèŠæš¡ã®éèãµãŒãã¹äŒæ¥
èª²é¡ ãªã³ãã¬ãã¹äžã®ã³ã¢ååŒã·ã¹ãã ãAzureäžã®é¡§å®¢åãã¢ããªã±ãŒã·ã§ã³ããããŠäºæ¥å šäœã§SaaSããŒã«ãæ··åšããŠããŸãããããŸã§ãã¯ã©ãŠãã®é害ããªã³ãã¬ãã¹ãããã¯ãŒã¯ã®é害ãçºçãããšãèªèšŒãšã©ãŒã«ããã¹ã¿ãããéèŠãªã·ã¹ãã ã«æ°æéã«ãããã¢ã¯ã»ã¹ã§ããªããªãäºæ ãçããŠããŸãããããã¯ãDORA第11æ¡ã«å®ããäºæ¥ç¶ç¶èŠä»¶ã«æããã«éåãããã®ã§ãã.
é©çšãããDORAèŠä»¶
- 第11æ¡ïŒICTã®äºæ¥ç¶ç¶ããã³çœå®³åŸ©æ§
- 第9æ¡ïŒãããã¯ãŒã¯ããã³ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹å¶åŸ¡
- 第30æ¡ïŒICT第äžè ãµãŒãã¹ãããã€ããŒã«é¢ããå¥çŽäžã®èŠä»¶
å®è£ æé
- ããã〠RSA ID Plusãã€ããªãããã§ã€ã«ãªãŒã㌠ã¯ã©ãŠããŸãã¯ãªã³ãã¬ãã¹ã®ã³ã³ããŒãã³ãã«é害ãçºçããå Žåã§ããèªèšŒãµãŒãã¹ãå©çšå¯èœãªç¶æ ãç¶æãããããç°å¢éã®èªåãã§ã€ã«ãªãŒããŒã60ç§ä»¥å ã«å®è¡ããŸãã.
- å®è£ ãã RSAã¢ãã€ã«ãã㯠ã¢ãã€ã«ç«¯æ«ã管ç察象å€ã®ç«¯æ«ããååŒã·ã¹ãã ã«ã¢ã¯ã»ã¹ããåŸæ¥å¡ã«å¯Ÿãã端æ«ã®ç¶æ 確èªã矩åä»ããã.
- ICTã«ããããã¹ãŠã®ç¬¬äžè èªèšŒãžã®äŸåé¢ä¿ãæŽãåºãã第30æ¡ã«åºã¥ãå¥çŽäžã®DORAæºæ æ§ãæ€èšŒããã.
- èªèšŒã·ã¹ãã ã®é害ã·ããªãªãå«ãååæããšã®çœå®³åŸ©æ§ã·ãã¥ã¬ãŒã·ã§ã³ã宿œããèŠå¶åœå±ã«ãã審æ»ã«åããŠãåŸ©æ§æéç®æšïŒRTOïŒããã³åŸ©æ§æç¹ç®æšïŒRPOïŒãææžåããã.
æåææš
- ã€ã³ãã©ã®åæ¢æã«ãããèªèšŒã®å¯çšæ§ãã67%ãã99.9%ãžãšåäžããŸããã
- IDãµãŒãã¹ã®RTOã4æéãã3åæªæºã«ççž®ããã
- 12ãæã®æºåæéå ã«ããã¹ãŠã®ICTé¢é£ã®ç¬¬äžè å¥çŽãæŽæ°ããDORAã§çŸ©åä»ããããã¬ãžãªãšã³ã¹ã«é¢ããæ¡é ãçã蟌ãã ã
- 埩æ§ã·ãã¥ã¬ãŒã·ã§ã³ã®çµæãææžåãããæç®¡åœå±ã«ãã審æ»ã®æºåãæŽã£ãŠãã
éèŠãªæèš DORAã«åºã¥ãæ¥åç¶ç¶æ§ãšã¯ãåã«æ»æãé²ãããšã ãã§ãªããæ»æãçºçããŠããéãæ©èœãç¶æããããšã«ãããŸããèªèšŒã«ããããã€ããªãããã§ã€ã«ãªãŒããŒã¯ã匷åãªèªèšŒãã®ãã®ãšåæ§ã«ãDORAãžã®æºæ ã«ãšã£ãŠæ¥µããŠéèŠã§ãã.
ã·ããªãª3ïŒDORAã«åºã¥ããµã€ããŒã€ã³ã·ãã³ãã«å¯Ÿå¿ããæè³éçšäŒç€Ÿ
èª²é¡ éçšè³ç£ç·é¡ïŒAUMïŒã400åãŠãŒãã«äžãEUæ ç¹ã®è³ç£éçšäŒç€Ÿããèªç€Ÿã®ãã¡ã³ã管çãã©ãããã©ãŒã ãæšçãšããèªèšŒæ å ±ã«åºã¥ãæ»æãåãããäžéè æ»æïŒAdversary-in-the-MiddleïŒåã®ãã£ãã·ã³ã°æ»æã«ãããµãŒãã¹ã¢ã«ãŠã³ãã䟵害ããããããã¯ãŒã¯å ã§ã®æšªæ¹åã®ç§»åãå¯èœãšãªã£ãã DORAã®ã€ã³ã·ãã³ãåé¡ããã³å ±åæ çµã¿ã«åºã¥ããåœè©²çµç¹ã¯ãåœè©²ã€ã³ã·ãã³ãããé倧ããšåé¡ããŠãã24æé以å ã«æç®¡åœå±ãžéç¥ãããšãšãã«ã72æé以å ã«äžéå ±åæžãã1ã¶æä»¥å ã«æçµå ±åæžãæåºããªããã°ãªããªãã.
é©çšãããDORAèŠä»¶
- 第17æ¡ïŒICTé¢é£ã€ã³ã·ãã³ãã®ç®¡çãåé¡ãããã³å ±å
- 第19æ¡ïŒéå€§äºæ¡ã®å ±å矩åããã³å ±åæé
- 第9æ¡ïŒã€ã³ã·ãã³ãçºçäžã皌åãç¶æããªããã°ãªããªãèªèšŒããã³ã¢ã¯ã»ã¹å¶åŸ¡
äºä»¶ã®çµç·¯ãšå¯Ÿå¿
- 0æéç®: RSA Risk AI ã¯ãç°åžžãªèªèšŒåäœïŒéåžžãšã¯ç°ãªãå°ççäœçœ®ãããµãŒãã¹ã¢ã«ãŠã³ãããã°ã€ã³ããéåžžã®ã¢ã¯ã»ã¹ãã¿ãŒã³ãšã¯ç°ãªãã·ã¹ãã ã«ã¢ã¯ã»ã¹ããŠããç¶æ ïŒãæ€ç¥ããŸãã調æ»ãå®äºãããŸã§ãã¢ã¯ã»ã¹ã¯èªåçã«åæ¢ãããŸãã.
- 第2æé: ã»ãã¥ãªãã£ããŒã ã䟵害ã確èªãããRSA ID Plus ãéããŠã60ç§ä»¥å ã«åœè©²ã¢ã«ãŠã³ãã®ã¢ã¯ã»ã¹æš©éãè§£é€ããããæšªæ¹åã®ç§»åã¯å°ã蟌ããããã.
- 第6æé: å éšã®åé¡ã«åºã¥ããã³ã¢ã·ã¹ãã ã®å¯çšæ§ãžã®åœ±é¿ãèæ ®ãããšãæ¬ä»¶ã¯DORAã®ãé倧ã€ã³ã·ãã³ããã®åºæºãæºãããŠããããšã確èªãããŸããã.
- 18æéç®: 24æé以å ã®èŠä»¶ã«åŸããæç®¡åœå±ã«å¯ŸããŠãäºè±¡ã®çš®é¡ãåé¡ã®æ ¹æ ãããã³çŽã¡ã«è¬ããå°ãèŸŒãæªçœ®ãå«ãåæå ±åãæåºããã.
- 60æéç®: 72æé以å ã®æåºèŠä»¶ãæºãããã€ã³ã·ãã³ãã®å šçµç·¯ãæ ¹æ¬åå åæïŒäŸµå®³ãããã¢ã«ãŠã³ãã«ããããã£ãã·ã³ã°æ»æã®æšçãšãªããããå€èŠçŽ èªèšŒïŒã圱é¿ãåããã·ã¹ãã ãããã³æ¯æ£æªçœ®ãèšèŒããäžéå ±åæžãæåºããã.
- 第4é±: äºåŸæ€èšŒã宿œããã管çäžã®æ¹åæªçœ®ïŒãã¹ãŠã®ãµãŒãã¹ã¢ã«ãŠã³ãã«ãã£ãã·ã³ã°å¯Ÿçæ©èœãåããå€èŠçŽ èªèšŒãå°å ¥ïŒãããã³ç£èŠéŸå€ã®å€æŽãå«ããæçµçãªã€ã³ã·ãã³ãå ±åæžãæåºããŸããã.
æåææš
- äºæ¡ã¯çºèŠãã2æé以å ã«åæãã
- DORAã®å ±åæé3ã€ãã¹ãŠãéµå®ããŸããâ24æé以å ã®åæå ±åã72æé以å ã®äžéå ±åã1ãæä»¥å ã®æçµå ±å
- èªèšŒã®ãã§ã€ã«ãªãŒããŒã«ãããæ¬ä»¶çºçäžããã¡ã³ã管çãµãŒãã¹ã«æ¯éã¯äžåçããªãã£ã
- çŽã¡ã«è¡ãæ¯æ£æªçœ®ïŒã€ã³ã·ãã³ãçºçãã30æ¥ä»¥å ã«ããµãŒãã¹ã¢ã«ãŠã³ãã100%ãããã£ãã·ã³ã°å¯ŸçèªèšŒã«ç§»è¡ãã
éèŠãªæèš DORAã®ã€ã³ã·ãã³ãå ±åèŠä»¶ã¯ãè¿ éãªæ€ç¥ãšå°ã蟌ãã«ãã§ã«æè³ãè¡ã£ãŠããçµç¹ãè©äŸ¡ãããã®ã§ãã. RSAãªã¹ã¯AI è¡ååæã®å°å ¥ã«ãããæ»æã®éå§ããå°ã蟌ããŸã§ã®æéããå¹³åã§æå€§254æ¥ïŒèªèšŒæ å ±æŒæŽ©ã«ãããæ¥çã®æšæºå€ïŒãã2æéæªæºã«ççž®ãããã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ãã説æãã䟵害ãåããããããDORAã®æ çµã¿ã«åºã¥ããæ€ç¥ã»å°ã蟌ãã»å ±åãè¡ã£ãããžãšäžå€ãããâ
RSAã§ã¯ãéèæ©é¢ãã¬ãžãªãšã³ã¹ã®æ±ãšããŠIDãéçšã§ããããæ¯æŽããŠããŸããã»ãã¥ãªãã£ã»ãã¡ãŒã¹ãã®ã¢ã€ãã³ãã£ãã£ã»ãã©ãããã©ãŒã ã§ãã RSA ID Plus, ããã¯ãéèã®ãããªèŠå¶ãããç°å¢åãã«æ§ç¯ãããŠããã
- RSAãªã¹ã¯AI è¡åãšæèã®ã·ã°ãã«ãåæããé©å¿çãªã¢ã¯ã»ã¹ã»ããªã·ãŒã宿œããã
- RSAã¢ãã€ã«ãã㯠管çãããŠããªãããã€ã¹ãå±éºãªããã€ã¹ããã®ã¢ã¯ã»ã¹ãä¿è·
- RSA iShield Key 2 ã·ãªãŒãº ãã£ãã·ã³ã°ã«åŒ·ãFIDOèªèšŒãšOTPèªèšŒãå¯èœã«ããèªèšŒæ©èœ
- RSAã¬ããã³ã¹ãšã©ã€ããµã€ã¯ã« ã¢ã¯ã»ã¹ã¬ããã³ã¹ãšã³ã³ãã©ã€ã¢ã³ã¹ã®ã¯ãŒã¯ãããŒãèªåå
- RSAãã€ããªãããã§ã€ã«ãªãŒã㌠å黿ã«ãèªèšŒãäžæããªã
ãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãDORAã«é©åããããã«å¿ èŠãªçµ±å¶ãæäŸããã³ã³ãã©ã€ã¢ã³ã¹ãè¶ ããŠçµç¹ã匷åããŸãã
DORA ã¯éèãµãŒãã¹ã«ãããã¢ã€ãã³ãã£ãã£ã®è»¢æç¹ãšãªããDORA ã¯ãIAM ãæè¡çãªé¢å¿äºããèŠå¶äžã®çŸ©åä»ãã«æ Œäžãããéçšã®åŒŸåæ§ãæŠç¥çã«å®çŸãããã®ã§ããã
IDãã¡ãŒã¹ãã®ã»ãã¥ãªãã£æŠç¥ãæ¡çšããéèæ©é¢ã¯ãDORAã®èŠä»¶ãæºããã ãã§ãªããã»ãã¥ãªãã£ãææ·æ§ã顧客ã®ä¿¡é Œã«ãããŠç«¶äºäžã®åªäœæ§ãåŸãããšãã§ãããDORAã®æœè¡ãå§ãŸãåã®ä»ãããã¢ã€ãã³ãã£ãã£æ å¢ãèŠçŽãæã§ãã
ãããžã¿ã«ã»ãªãã¬ãŒã·ã§ãã«ã»ã¬ãžãªãšã³ã¹æ³ïŒDORAïŒãã¯2023幎1æ16æ¥ã«çºå¹ãã 2025幎1æ17æ¥ â ãã®æ¥ä»ããã£ãŠã察象ãšãªããã¹ãŠã®éèæ©é¢ããã³éèŠãªICT第äžè ãããã€ããŒã¯èŠä»¶ãéµå®ããããšã矩åä»ããããEUå ç27ã«åœãã¹ãŠã«ãããŠå·è¡æš©éãçºåãããããŸã èŠä»¶ãæºãããŠããªãæ©é¢ã«å¯Ÿããç¶äºæéã¯èšããããŠããããæç®¡åœå±ã¯åœè©²æ¥ä»ä»¥éã調æ»ãéå§ãã眰åãç§ãããšãã§ããã.
å®å šãªã³ã³ãã©ã€ã¢ã³ã¹éæã«åããŠãŸã åãçµãã§ããçµç¹ã«ãšã£ãŠãåªå ãã¹ãã¯ãææžåãããçå®ã«é²å±ããŠããã³ã³ãã©ã€ã¢ã³ã¹ã»ããã°ã©ã ã蚌æããããšã§ããç¹ã«ãäžå€ã«ããŠè¿ä»£åã§ããªãè€éãªã¬ã¬ã·ãŒã®IDã€ã³ãã©ã«ã€ããŠã¯ããã®éèŠæ§ãéç«ã£ãŠããŸãã.
DORAã¯ã2段éã®çœ°åå¶åºŠãå®ããŠããã. éèæ©é¢ æå€§ å šäžçã®å¹Žéç·å£²äžé«ã®2% ããã ããã äžçå šäœã®1æ¥å¹³åååŒé«ã®1%âæç®¡åœå±ã®è©äŸ¡ã«åºã¥ã該åœããããããâããéµå®ãéæããããŸã§ç¶ç¶çãªçœ°éãšããŠæ¥é¡ã§é©çšãããéåã®è²¬ä»»ããããšèªå®ãããåã ã®äžçŽç®¡çè·ã«ã¯ãæå€§ â¬1,000,000.
éèŠãªãµãŒãããŒãã£ICTãããã€ããŒïŒCTPPïŒ æ¬§å·ç£ç£åœå±ã«ãã£ãŠæå®ãããæ©é¢ã¯ããã倧ããªãªã¹ã¯ã«ãããããŠããããã®é¡ã¯æå€§ã§ â¬5,000,000 éå1ä»¶ã«ã€ããå人ã«å¯Ÿãã眰éã¯æå€§ â¬500,000, ãããã«æå€§ äžçã®1æ¥å¹³åååŒé«ã®1% æé·6ãæéãééçãªçœ°åã«å ããæç®¡åœå±ã¯DORAéåãå ¬è¡šããå Žåããããããã«ããçããè©å€ãªã¹ã¯ã¯ãèŠå¶å¯Ÿè±¡ã®éèæ©é¢ã«ãšã£ãŠã眰éãã®ãã®ã®ééçã³ã¹ããäžåãå¯èœæ§ãããã.
DORAã¯ãEUã®éèã»ã¯ã¿ãŒã®ã»ãŒãã¹ãŠã«é©çšãããŸãã 察象ãšãªãäºæ¥äœã«ã¯ãä¿¡çšæ©é¢ãæ±ºæžæ©é¢ããã³é»åãããŒæ©é¢ãæè³äŒç€Ÿãæå·è³ç£ãµãŒãã¹æäŸè ïŒCASPsïŒãäžå€®èšŒåžä¿ç®¡æ©é¢ãäžå€®æž ç®æ©é¢ãååŒæãä»£æ¿æè³ãã¡ã³ãéçšäŒç€Ÿãä¿éºäŒç€Ÿããã³åä¿éºäŒç€Ÿãä¿¡çšæ Œä»ãæ©é¢ãå ¬çäºæ¥äœã®ç£æ»æ³äººããªãã³ã«ã¯ã©ãŠããã¡ã³ãã£ã³ã°ãµãŒãã¹æäŸè ãå«ãŸããŸãã.
éèŠãªç¹ãšããŠãDORAã®é©çšç¯å²ã¯EUã«æ¬æ ã眮ãéèæ©é¢ã«ãšã©ãŸããŸããã EUåå ã§äºæ¥ãè¡ãéEUã®éèæ©é¢ãããã³EUã®é©çšå¯Ÿè±¡ãšãªãéèæ©é¢ã«ãµãŒãã¹ãæäŸããICTãµãŒãããŒãã£ãµãŒãã¹ãããã€ããŒïŒã¯ã©ãŠããããã€ããŒãå«ãïŒãã第30æ¡ã®å¥çŽèŠå®ã«åºã¥ããDORAã®èŠä»¶ã®å¯Ÿè±¡ãšãªããŸããEUåå ã§äºæ¥ãå±éããŠããããããã¯EUåå ã«é¡§å®¢ãæã€ç±³åœæ ç¹ã®éèãµãŒãã¹äŒæ¥ã¯ãèªç€Ÿã®äºæ¥ãé©çšç¯å²å€ã§ãããšå®æã«æ³å®ãã¹ãã§ã¯ãããŸããã.
DORAã¯ç¹å®ã®æè¡ãèŠå®ããŠããããã§ã¯ãããŸãããã第9æ¡ããã³ç¬¬10æ¡ã«å®ãããããªã¹ã¯ç®¡çããã³ã¢ã¯ã»ã¹å¶åŸ¡ã®èŠä»¶ã¯ããã®ãŸãŸå¿ é ã®IAMæ©èœã«çŽçµããŸããéèæ©é¢ã¯ã以äžã®æªçœ®ãè¬ããªããã°ãªããŸããã
- 匷åãªèªèšŒ ãã¹ãŠã®ã·ã¹ãã ã«ã€ããŠïŒå€èŠçŽ èªèšŒïŒMFAïŒã«é¢ããããªã·ãŒãšãããã³ã«ã®çå®ãæç¢ºã«æ±ããããŠãããç¹æš©ã¢ã¯ã»ã¹ãé«ãªã¹ã¯ã®ã¢ã¯ã»ã¹ã«ã€ããŠã¯ããã£ãã·ã³ã°æ»æã«èæ§ã®ããææ³ãæšå¥šãããŸãã.
- æå°æš©éã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒ ãŠãŒã¶ãŒããã³ã·ã¹ãã ã«ã¯ããã®æ©èœã«å¿ èŠãªã¢ã¯ã»ã¹æš©ã®ã¿ãä»äžããããããç¶ç¶çã«èŠçŽãããªã¢ã«ã¿ã€ã ã§èª¿æŽãã¹ãã§ããã.
- ã¢ã¯ã»ã¹ã¬ããã³ã¹ïŒ ç¹æš©ã®æ¡å€§ãé²ãããã宿çãã€ææžåãããã¢ã¯ã»ã¹ã¬ãã¥ãŒãšèªèšŒãµã€ã¯ã«ãå¿ èŠã§ãããããããžã§ãã³ã°ããã³ããããžã§ãã³ã°è§£é€ã¯èªååãããå¿ èŠããããŸãã.
- ç°åžžæ€ç¥ïŒ èªèšŒãã¢ã¯ã»ã¹ãã¿ãŒã³ãç¶ç¶çã«ç£èŠããããšã§ãã·ã¹ãã ãžã®äŸµå ¥ã瀺åããç°åžžãªæŽ»åãæ€ç¥ããé©åã«å¯Ÿå¿ããããšãå¯èœã«ãªããŸãã.
- IDãµãŒãã¹ã®äºæ¥ç¶ç¶æ§ïŒ èªèšŒã€ã³ãã©ã¯ããµã€ããŒã€ã³ã·ãã³ããã·ã¹ãã 忢æã«ãããŠãå©çšå¯èœãªç¶æ ãç¶æããªããã°ãªããã埩æ§ç®æšãææžåããŠããå¿ èŠãããã.
- ç£æ»èšŒè·¡ã®ç®¡çïŒ ãã¹ãŠã®IDããã³ã¢ã¯ã»ã¹ã€ãã³ãã«é¢ãããå æ¬çãã€æ¹ãã鲿¢æ©èœãåãããã°ããèŠå¶åœå±ã«ãã審æ»ãã€ã³ã·ãã³ã調æ»ã®ããã«çšæããŠãããªããã°ãªããªãã.
éèãµãŒãã¹åã RSA ID Plus ãããã®èŠä»¶ã®ããããã«çŽæ¥å¯Ÿå¿ããŠããŸãã.
ãæ±ºæžãµãŒãã¹æä»€2ïŒPSD2ïŒãã¯ãç¹ã«ããžã¿ã«æ±ºæžã®ã»ãã¥ãªãã£ç¢ºä¿ã«éç¹ã眮ããæ±ºæžãµãŒãã¹äºæ¥è ã«å¯Ÿããé倧ãªã€ã³ã·ãã³ããæ€ç¥ããŠãã2æé以å ã«èŠå¶åœå±ãžå ±åããããšã矩åä»ããŸããã DORAã¯ãäž¡æ¹ã®æ çµã¿ã®å¯Ÿè±¡ãšãªããã¹ãŠã®äºæ¥äœã«ã€ããŠãPSD2ã®ã€ã³ã·ãã³ãå ±åèŠåã«åã£ãŠä»£ãããã®ã§ãããæ¬§å·éè¡ç£ç£å±ïŒEBAïŒã¯ã2025幎1æ17æ¥ä»ã§PSD2ã®é倧ã€ã³ã·ãã³ãå ±åã¬ã€ãã©ã€ã³ãæ£åŒã«å»æ¢ããDORAã®èª¿ååãããæ çµã¿ã«çœ®ãæããã.
äž»ãªéãã¯é©çšç¯å²ã«ãããŸããPSD2ã¯æ±ºæžã®ã»ãã¥ãªãã£ã察象ãšããŠããŸããããDORAã¯ãã¹ãŠã®éèæ©é¢ã®ICTãªã¹ã¯æ å¢å šäœã察象ãšããæ±ºæžé¢é£ã®ãã®ã«éãããããããéçšäžããã³ã»ãã¥ãªãã£äžã®ã€ã³ã·ãã³ããç¶²çŸ ããŠããŸãããŸããDORAã«ãããã€ã³ã·ãã³ãå ±åã®ã¿ã€ã ã©ã€ã³ããããäœç³»åãããŠããŸãïŒ 24æé ååéç¥ã«ã€ããŠã¯ã, 72æé äžéå ±åãšããŠãããã³ 1ãæ æçµå ±åæžã®ãããDORAã§ã¯ãéèŠãªICT第äžè äºæ¥è ã«å¯ŸããçŽæ¥çãªç£ç£æš©éãå°å ¥ãããŠãããããã¯PSD2ã«ã¯é¡äŸã®ãªã説æè²¬ä»»ã®ä»çµã¿ã§ããã.
DORA第17æ¡ããã³ç¬¬19æ¡ã«åºã¥ããåæ©é¢ã¯å®ããããã€ã³ã·ãã³ã察å¿ããã³å ±åããã»ã¹ã«åŸããªããã°ãªããŸããã ãŸããã€ã³ã·ãã³ããæ€ç¥ããèšé²ããåé¡ããå¿ èŠããããŸããDORAã§ã¯ããµãŒãã¹ã®å¯çšæ§ãžã®åœ±é¿ã圱é¿ãåããã¯ã©ã€ã¢ã³ãã®æ°ãå°ççãªåºãããããã³çµæžç圱é¿ã«åºã¥ããŠããé倧ããªã€ã³ã·ãã³ããæ§æããåºæºãå®çŸ©ããŠããŸããé倧ãšåé¡ããããšãå ±åã®ã¿ã€ã ãªããããéå§ãããŸãïŒ
- ååéç¥ ç®¡èœåœå±ã«å¯Ÿããïœä»¥å ã« 24æé éå€§äºæ¡ãšããŠã®åé¡ã«ã€ããŠ
- äžéå ±åæž å 72æé åœè©²äºæ¡ã®è©³çްãªçµç·¯ã宿œãããå°ãèŸŒãæªçœ®ãããã³åæã®æ ¹æ¬åå è©äŸ¡ãå«ã
- æçµå ±åæž å 1ãæ äžéå ±åæžã®å 容ïŒäºåŸåæã®å šå®¹ãæä¹ çãªæ¯æ£æªçœ®ãããã³åŸãããæèšãå«ãïŒ
ã€ã³ã·ãã³ãçºçäžããæ¬äººç¢ºèªããã³èªèšŒãµãŒãã¹ã¯çšŒåãç¶ããªããã°ãªããªããDORAã§ã¯ãäºæ¥ç¶ç¶èšç»ã«ã¢ã¯ã»ã¹ããã³èªèšŒã·ã¹ãã ãå«ãICTã€ã³ãã©ãçã蟌ãããšãæç€ºçã«çŸ©åä»ããŠãããæ©é¢ã¯ãçºçäžã®ã€ã³ã·ãã³ããçç±ã«èªèšŒã·ã¹ãã ãå©çšã§ããªãç¶æ ãæ£åœåããããšã¯ã§ããªãã.
ã¯ãããã ãããã®ã¯ã©ãŠãããŒã¹ã®ãœãªã¥ãŒã·ã§ã³ããã³å¥çŽæ¡ä»¶ããDORA第30æ¡ã«å®ãã第äžè ICTãããã€ããŒã®èŠä»¶ãæºãããŠããããšãæ¡ä»¶ãšãªããŸããã¯ã©ãŠãIDãããã€ããŒã¯ããµãŒãã¹ã®å¯çšæ§ãã€ã³ã·ãã³ãéç¥ã®ã¿ã€ã ã©ã€ã³ãç£æ»æš©ãããã³ããŒã¿ããŒã¿ããªãã£ã«é¢ããŠãå¥çŽäžã®ä¿èšŒãæäŸããªããã°ãªããŸããã ãã€ããªãããªãã§ã€ã«ãªãŒããŒæ©èœãåããŠããªãã¯ã©ãŠãèªèšŒãµãŒãã¹ã«ã®ã¿äŸåããŠããæ©é¢ã¯ãDORAãæ±ããæ¥åç¶ç¶æ§ãç«èšŒããã®ã«èŠåŽããå¯èœæ§ããããŸãã.
RSA ID Plus ãã®èª²é¡ã«ç¹åããŠèšèšãããŠãããåäžã®ãã©ãããã©ãŒã ããã¯ã©ãŠãããã€ããªããããªã³ãã¬ãã¹ã®èªèšŒããµããŒããã ãã€ããªãããã§ã€ã«ãªãŒã㌠ã¯ã©ãŠããžã®æ¥ç¶ãéçµ¶ããå Žåã§ããèªèšŒãµãŒãã¹ãå©çšå¯èœãªç¶æ ãç¶æããããšãããã«ãããã¯ã©ãŠã管çãããããã³ã³ãã©ã€ã¢ã³ã¹äžã®ã¡ãªããïŒäžå 管çãèªåæŽæ°ãæ¡åŒµæ§ïŒã享åãã€ã€ãèŠå¶åœå±ãå³ããç£èŠããŠãããåäžé害ç¹ãã®ãªã¹ã¯ãåé¿ã§ããŸãã.
DORAã§ã¯ãéèæ©é¢ã«å¯Ÿãã以äžã®æžé¡ãä¿ç®¡ããèŠæ±ã«å¿ããŠæç€ºã§ããããšã矩åä»ããŠããŸãïŒ
- ICTãªã¹ã¯ç®¡çãã¬ãŒã ã¯ãŒã¯ã«é¢ããææžâDORAã®èŠä»¶ã«ç §ãããŠçå®ãããæ¹éãæé ãããã³çµ±å¶æªçœ®ã«ã€ããŠãçµå¶é£ãå°ãªããšã幎1åãæ€èšã»æ¿èªãè¡ãããš
- ã¬ãã¥ãŒèšé²ã«ã¢ã¯ã»ã¹ããâæå°æš©éã®ååã確å®ã«é©çšãããéè·ããåŸæ¥å¡ã圹å²ã倿ŽãããåŸæ¥å¡ã«å¯ŸããŠé©æã«ã¢ã¯ã»ã¹æš©éã®è§£é€ãè¡ãããŠããããšã瀺ããèšé²ä»ããã€ã¿ã€ã ã¹ã¿ã³ãä»ãã®ã¢ã¯ã»ã¹èªèšŒãµã€ã¯ã«
- ã€ã³ã·ãã³ãç»é²ç°¿âICTé¢é£ã®ãã¹ãŠã®ã€ã³ã·ãã³ãããã®åé¡ãæç³»åãå¯Ÿå¿æªçœ®ãããã³çµæã«é¢ããå®å šãªèšé²
- éå€§äºæ¡å ±åæžâDORAã®ãé倧ãåé¡åºæºãæºããããããäºè±¡ã«ã€ããŠãæåºããããã¹ãŠã®éç¥ïŒåæãäžéãæçµïŒ
- 第äžè ãšã®ICTå¥çŽâã¯ã©ãŠãèªèšŒããã³ID管çãã³ããŒãå«ãããã¹ãŠã®ICTãµãŒãã¹ãããã€ããŒãšã®éã§ã第30æ¡ã«æºæ ããå¥çŽãç· çµããããš
- äºæ¥ç¶ç¶èšç»ããã³çœå®³åŸ©æ§èšç»âèªèšŒã·ã¹ãã ã®å¯çšæ§ãç¶²çŸ ãããææžåããã³æ€èšŒæžã¿ã®èšç»ãã·ãã¥ã¬ãŒã·ã§ã³ã«ããRTO/RPOã®çµæãèšé²ãããŠããã
RSAã¬ããã³ã¹ãšã©ã€ããµã€ã¯ã« ã¢ã¯ã»ã¹å¯©æ»èšé²ãã³ã³ãã©ã€ã¢ã³ã¹å ±åæžã®äœæã»ç®¡çãèªååããç£æ»å¯Ÿå¿å¯èœãªæžé¡ã®äœæã«ãããæéãæ°é±éããæ°æéã«ççž®ããŸãã.