æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ã
ããŒã¿ãæ å ±ãããµããçŸä»£ã«ãããŠãåç»ãææžã顧客ããŒã¿ãã¢ã«ãŠã³ãæ å ±ãªã©ã貎éãªã³ã³ãã³ãã®ä¿è·ã¯ãããããçµç¹ã«ãšã£ãŠéèŠãªèª²é¡ã§ããæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ããšã¯ãã³ã³ãã³ãã®ã»ãã¥ãªãã£ã確ä¿ããŠç¬¬äžè ããä¿è·ãããšåæã«ãé©åãªäººãã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ããããšããããŸããæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã·ã¹ãã ïŒISMSïŒã¯ãã³ã³ãã³ãã®å®å šãªä¿è·ãšãæ å ±æŒãããçºçããå Žåã®å¯Ÿå¿ãå¯èœã«ããŸãã
ISMSã®å°å ¥ã«ãããŠã¯ãäžå®ã®åºæºãèŠåã«åŸãããšã§ãã·ã¹ãã ã®ã¹ã ãŒãºãªæ§ç¯ãå¯èœã«ãªããŸããæ¬èšäºã§ã¯ãISMSã®æ§ç¯ã»éçšã«å¿ èŠãªäºæã«ã€ããŠè§£èª¬ããŸããISMSã®å°å ¥ã«ã圹ç«ãŠãã ããã

æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ããšã¯ïŒ
æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ããšã¯ãæ å ±ã»ãã¥ãªãã£ã«ãããCIAã®3èŠçŽ ãç¶æããããã®ãäŒæ¥ã«ããåãçµã¿ããããŸãã
- ç§å¯æ§ïŒç§å¯æ§ã®é«ãã³ã³ãã³ãã¯ã第äžè ã«ãã販売ç®çã»ç§å©ç®çã§ã®å©çšãã§ããªãããã«ä¿è·ããªããã°ãªããŸãããç§å¯æ§ãä¿ã€æ¹æ³ãšããŠã¯ããã¹ã¯ãŒããæå·åããŠãŒã¶ãŒå¶åŸ¡ãªã©ããããŸãã
- å®å šæ§ïŒç¬¬äžè ãã³ã³ãã³ããžã®ã¢ã¯ã»ã¹æš©ãæã€å Žåã¯ã埩å ãäžå¯èœã«ãªãã»ã©ã®å€§å¹ ãªå€æŽã»æ¹å€ãã§ããªãããã«ããŠããå¿ èŠããããŸããã³ã³ãã³ãã®ç§å¯æ§ã®ç¢ºä¿ã¯ãã³ã³ãã³ãã®å®å šæ§ã®ä¿è·ã«ã€ãªãããŸãããŸããæ¹ãããçãããå Žåã«ä»¥åã®ããŒãžã§ã³ã«åŸ©å ã§ããããšããå®å šæ§ã®ä¿è·ã«å¹æçã§ãã
- å¯çšæ§ïŒã³ã³ãã³ãã¯ãå©çšè ããã€ã§ãã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãããããã£ãŠãæ å ±ã»ãã¥ãªãã£ã®äžç°ãšããŠãå¯çšæ§ã®ç¶æãéèŠãšãªããŸããå¯çšæ§ãç¶æããã«ã¯ãã³ã³ãã³ãã®ããã¯ã¢ãããäœæããããšããŠãŒã¶ãŒã«é©åãªæš©éãå²ãåœãŠãããããã«ããããšãéèŠã§ãã

ISMSãšã¯ïŒ
ISMSïŒInformation Security Management Systemãæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã·ã¹ãã ïŒã¯ãCIAã®3èŠçŽ ãå®ãããªã¹ã¯ãäœæžããæ å ±æŒããã®çºçæãäºæ¥ãç¶ç¶ããããã®æ¹éãæé ãå®ãããã®ã§ããISMSã®é©çšç¯å²ã¯ãä¿è·ãã¹ãããŒã¿ã®çš®é¡ãéã«ãã£ãŠå€ãããŸããäžè¬çã«ãISMSã¯ä»¥äžã®ãããª6æ¬ã®æ±ã§æ§æãããŸãã
- æŠç¥ã®çå®
æ¥åã®éè¡ã«ã¯ããªã¹ã¯ãæå°éã«æããŠã³ã³ãã³ããä¿è·ããããã®å ç¢ãªã»ãã¥ãªãã£æŠç¥ãå¿ èŠã§ããæŠç¥ãçå®ããããšããCIAã®3èŠçŽ ã®å®å®ç¶æã«ã€ãªãããŸãã
- ã¬ããã³ã¹ããªã¹ã¯ç®¡çãã³ã³ãã©ã€ã¢ã³ã¹
æ å ±ã»ãã¥ãªãã£ããã»ã¹ãèªç€Ÿã®ç®æšã«åèŽããããšãç®çãšãããã®ã§ãããŸãã宿çã«å 容ãå€ããæ³ä»€ã»èŠå¶ãã¬ã€ãã©ã€ã³ãžã®å¯Ÿå¿ãšãªã¹ã¯ã®äœæžãå¯èœã«ããŸãã
- ã»ãã¥ãªãã£ã®å¶åŸ¡
ã»ãã¥ãªãã£ã®å¶åŸ¡ã¯ãäŒæ¥ã®ISMSã®äžæ žã§ãããäžæ£ã¢ã¯ã»ã¹ãçé£ãªã©ã®ãªã¹ã¯ã軜æžããããã®å¯ŸçããããŸããã€ã³ã·ãã³ãã®çºçãæªç¶ã«é²ããäºé²åããåé¡ã解決ãããæ¯æ£åããçºçäžãŸãã¯çºçããã€ã³ã·ãã³ããåé¡ãçºèŠãããæ€ç¥åãããããŸãã
- ãµãŒãããŒãã£ãªã¹ã¯ã®ç®¡ç
ã³ã³ãã³ãã瀟å å šäœã«åœ±é¿ãäžãåŸã第äžè ã®è¡åãå¶åŸ¡ããŸããäŸãã°ããµãŒãããŒãã£ã®ãœãããŠã§ã¢äŒç€ŸãããŒã¿æŒããã®ãªã¹ã¯ãé«ããããããããå Žåããããã¯ãææºããŠãããã³ããŒã®è¡åãäŒç€Ÿã®ã¬ãã¥ããŒã·ã§ã³ã«æªåœ±é¿ãåãŒãããããããå Žåãªã©ã察象ãšãªããŸãã
- ã»ãã¥ãªãã£ããã°ã©ã ã®ç®¡ç
äŒæ¥ã®ã»ãã¥ãªãã£ããã°ã©ã ãšã¯ãISMSã«å«ãŸããèªç€Ÿã®ããªã·ãŒã掻åãããã»ã¹ããããžã§ã¯ãã®å šãŠããããŸããCIAã®3èŠçŽ ã®ç¶æãç®çãšããããã°ã©ã ã§ãã
- ç£æ»ã®ç®¡ç
ç£æ»ãè¿ éãã€å®¹æã«ããããšãç®çãšãããã®ã§ããç£æ»ç®¡çããã°ã©ã ãå°å ¥ããããšã§ããªã¹ã¯ã®è¿ éãªæ€ç¥ãšãè åšã«å¯Ÿããé©åãªå¯Ÿå¿ãå¯èœã«ãªããŸãã

ISO 27001
åœéæšæºåæ©æ§ïŒISOïŒã¯ãISMSã«é¢ããèŠæ±äºé ããŸãšããèŠæ ŒISO 27001ãå ¬éããŠããŸããISO 27001ã«åŸãããšã§ãåŸæ¥å¡ã®æ å ±ãç¥ç財ç£ããµãŒãããŒãã£ã®ã³ã³ãã³ããè²¡åæ å ±ãã¯ãããšããã³ã³ãã³ãã®ã»ãã¥ãªãã£ã確ä¿ã§ããŸããISO 27001ã¯ãISMSã«é¢ããå¯äžã®åœéèªèšŒèŠæ Œã§ããå®å¹æ§ã®ããISMSãå°å ¥ããŠããããšã蚌æããã«ã¯ãISO 27001èªå®ã®ååŸã广çã§ãã
ISO 27001ã«ã¯ãäŒæ¥ãèªå®ãåããããã«æ±ãããã管ççãšç®¡çäœå¶ã瀺ãããŠããŸãã管ççã¯å šéšã§93ãããŸãããªã¹ã¯ã®æ€ç¥ã»ç®¡çã»å¯ŸåŠã«åœ¹ç«ãŠãããšãç®çãšãããã®ã§ã倧ãã4ã€ã®ã°ã«ãŒãã«åé¡ãããŸãã

管ççã«ã¯æ¬¡ã®ãã®ããããŸãã
- æå·å
- ãµãã©ã€ã€ãŒãšã®é¢ä¿
- ç©ççã»ç°å¢çã»ãã¥ãªãã£
- éçšäžã®ã»ãã¥ãªãã£
- æ å ±ã»ãã¥ãªãã£ããªã·ãŒ
èŠæ Œã®åç®æ¡ã¯ãISMSã®å°å ¥ã»ç¶æã»æ¹åãæ¯æŽããããšãç®çãšããŠããŸãã
ISMSãéèŠãªçç±ãšã¯ïŒ
æš©éã®ãªã第äžè ãã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ãããšãã©ããªãã§ããããïŒé¡§å®¢ã®ãªã¹ããæ å ±ããããã³ã°ãããå人æ å ±ãçãŸãããã転売ãããããããããããããŸãããŸããæ¬¡ã®äž»åååã®èšèšå³ãæµåºãããšãä»ç€Ÿãå ã«è£œé ããã競売ã«ãããããŠé«å€ã§å£²ããããªã©ã®ãªã¹ã¯ãçããŸãã
ããŒã¿ã®æŒãããã³ã³ãã³ãã®çé£ã¯ãå人ãäŒæ¥å šäœã®æå®³ã«ã€ãªãããŸããæ å ±ãçãŸãããšãäŒæ¥ã®ã¬ãã¥ããŒã·ã§ã³ã«ãæªåœ±é¿ãåãŒããŸããã³ã³ãã³ããæ¹ãããããå Žåã«ã¯ãæäŸãããµãŒãã¹ãååã®å質ãäœäžããã¬ãã¥ããŒã·ã§ã³ãæãªããããããããããŸãã
ISMSã¯ãäžæ£ã¢ã¯ã»ã¹ã鲿¢ã»é»æ¢ããããšãã³ã³ãã³ãã®å®å šæ§ãä¿è·ããããšãé©åãªäººãã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ããããšãããããä»çµã¿ã§ãããªã¹ã¯ãæå°éã«æãããããã³ã°ãçé£ãäºé²ããã«ã¯ãISMSãå¿ èŠã§ããæ¥çã«ãã£ãŠã¯ãèŠå¶ã«æºæ ããããã«ISMSã®å°å ¥ãæ±ããããããšããããŸãã
èª°ãæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã«æºããã®ãïŒ

æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã¯ãå šç€Ÿçã«åãçµãã¹ãéèŠãããžã§ã¯ãã§ããISMSã®å°å ¥ã»éçšãæåãããã«ã¯ãçµå¶å¹¹éšãã¯ããã人äºãITã財åãã«ã¹ã¿ããŒãµãŒãã¹ãªã©ã®éšéã®è³åãšååãæ¬ ãããŸãããæ å ±ã»ãã¥ãªãã£ã®éèŠæ§ãèªèããã³ã³ãã³ãã®å®å šãªåãæ±ããéèŠããäŒæ¥æåãéžæããããšãå¿ èŠã§ããåéšéã«ããåãçµã¿ã®å ·äœäŸã以äžã«ç€ºããŸãã
çµå¶å¹¹éš
çµå¶å¹¹éšã¬ãã«ã§ã¯ãæé«ã»ãã¥ãªãã£è²¬ä»»è ãæé«æè¡è²¬ä»»è ãªã©ãISMSã®ç£ç£ãããã³èŠæ Œã該åœèŠå¶ã«å¯Ÿããã·ã¹ãã ã®éµå®ç¶æ³ã®ç¢ºèªã«é¢ãã責任è ãæäœ1å眮ããšããã§ãããããã®è²¬ä»»è ãä»ã®çµå¶å¹¹éšãšé£æºããISMSã®éèŠæ§ã蚎ããã³ã³ãã©ã€ã¢ã³ã¹ãä¿é²ããããšãéèŠã§ãã
人äºéšé
人äºéšéã¯ãã»ãã¥ãªãã£ã«é¢ããã«ãŒã«ãåŸæ¥å¡ãæ°èŠæ¡çšè ã«äŒããéèŠãªåœ¹å²ãæ ã£ãŠããŸããåçš®èŠåã®éèŠæ§ãçè§£ããŠãããããŸããã©ã®ãããªè¡åãæ±ããããŠããããç¥ã£ãŠãããããã«ã瀟å ç ä¿®ãæ°äººç ä¿®ã«æ å ±ã»ãã¥ãªãã£ãçã蟌ããšããã§ãããã瀟å€ç§ã®ã³ã³ãã³ããèªå® ã«æã¡åž°ããªããæªæ¿èªã®ãœãããŠã§ã¢ãäŒç€Ÿã®ããã€ã¹ã«ã€ã³ã¹ããŒã«ããªãããªã©ã®èŠåã«ã€ããŠæ³šæåèµ·ã§ããŸãã
ITéšé
ITéšéã¯ãäŒç€Ÿã®ISMSã®æ ¹å¹¹ãšãªãããªã·ãŒãšé²åŸ¡çãçå®ããŸããã·ã¹ãã äžã®åŸæ¥å¡ã®è¡åã®ç£èŠãç°åžžãªè¡çºã®æ€ç¥ãäŒç€Ÿã®ããŒããŠã§ã¢ã«æªæ¿èªã®è£œåã®ã€ã³ã¹ããŒã«ã詊ã¿ããªã©ã®è¡çºã®é»æ¢ããäž»ã«ITéšéãæ ããŸããã³ã³ãã³ããä¿è·ããç®çã§ãç¹å®ãµã€ãã®ãããã¯ããç¹å®ã®ããŠã³ããŒãã®çŠæ¢ãªã©ã®å¶åŸ¡ãè¡ããŸãã
財åéšé
財åéšéã¯ãéè¡å£åº§æ å ±ã顧客ã®å人æ å ±ãªã©ãå€ãã®æ©å¯æ å ±ãæ±ããŸãããã®ãããã³ã³ãã³ããä¿è·ããããã®ããã»ã¹ãããªã·ãŒãçè§£ããããšãå¿ èŠã§ãã財åããŒã¿ä¿è·èŠåããäžæ£é²æ¢èŠåã確å®ã«å®ãããšãæ±ããããŸãã
ã«ã¹ã¿ããŒãµãŒãã¹éšé
ã«ã¹ã¿ããŒãµãŒãã¹éšéã¯ã顧客ããã®åãåããããæ å ±æŒãããçºçããå Žåã®çªå£ãšãªãéšéã§ããæžå¿µãåé¡ã«è¿ éã«å¯Ÿå¿ã§ãããããISMSã«é¢ããææ°æ å ±ãåžžã«ææ¡ããŠããå¿ èŠããããŸããæ£ããæ å ±ã«åºã¥ããŠç確ã«å¯Ÿå¿ã§ããã«ã¹ã¿ããŒãµãŒãã¹éšéãååšããããšã§ãäŒç€Ÿã®ã¬ãã¥ããŒã·ã§ã³ã®ç¶æãããŒã¿æŒãããã»ãã¥ãªãã£åé¡ãèµ·ããå Žåã®ä¿¡çšã®å埩ãå¯èœã«ãªããŸãã
忥çã«ãããæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ã
ä¿è·ãã¹ãã³ã³ãã³ããããå Žåã¯ãæ¥çãåããã©ã®äŒæ¥ã§ãISMSã¯å¿ é ã§ãããªãã§ããã³ã³ãã©ã€ã¢ã³ã¹èŠå¶ãå ±åèŠä»¶ã®ããæ¥çã«ãšã£ãŠã¯ç¹ã«éèŠã§ããäŸãã°ãæ£è ã«é¢ãããã«ã¹ã±ã¢ã»å»çã³ã³ãã³ãã¯ãå»çä¿éºã®çžäºéçšæ§ãšèª¬æè²¬ä»»ã«é¢ããæ³åŸïŒHIPAA: Health Insurance Portability and Accountability ActïŒã«åŸããªããã°ãªããŸããããŸããéèäŒæ¥ã¯ãPCIããŒã¿ã»ãã¥ãªãã£åºæºïŒPCI-DSS: Payment Card Industry Data Security StandardïŒããç±³åœéèæ¥èŠå¶æ©æ§ïŒFINRA: Financial Industry Regulatory AuthorityïŒã®èŠä»¶ã«åŸã£ãŠã³ã³ãã³ããä¿è·ããå¿ èŠããããŸãã
é£éŠæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãæ³ãšã¯ïŒ
é£éŠæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãæ³ïŒFISMA: Federal Information Security Management ActïŒã¯ã2002幎ã«å¶å®ã2014å¹Žã«æ¹æ£ãããæ³åŸã§ãFISMAã¯ãæ¿åºæ©é¢ã®æ å ±ã®ä¿è·ãç®çãšãããªã¹ã¯ç®¡çã®ãã¬ãŒã ã¯ãŒã¯ïŒæ çµã¿ïŒãšããŠãåºæºãèŠå¶ãå®ããŠããŸããåœåã¯é£éŠæ¿åºæ©é¢ã®ã¿ãé©çšå¯Ÿè±¡ã§ããããã®åŸé©çšç¯å²ãæ¡å€§ãããçŸåšã§ã¯ãå·æ¿åºæ©é¢ããã³ãæ¿åºæ©é¢ããæ¥åå§èšãåããŠããæ°éäŒæ¥ã察象ãšãªã£ãŠããŸãã

FISMAãæœè¡ãããããšã«ãããæ¿åºæ©é¢ã®ããŒã¿ã»ãã¥ãªãã£ã®ãªã¹ã¯ã軜æžããåæã«æ å ±ã»ãã¥ãªãã£ã®ã³ã¹ããåæžããæ¹æ³ãçã¿åºãããŸãããFISMAãéµå®ããã«ã¯ãé£éŠæ¿åºæ©é¢ãã¯ãããšããå¯Ÿè±¡ã®æ©é¢ãäŒæ¥ã¯ãæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãããã°ã©ã ãçå®ããŸãããã®ããã°ã©ã ã«ã¯ãææžåãšå®æœèšç»ãå¿ èŠã§ãããŸããFISMAã¯ãåæ¿åºæ©é¢ãäŒæ¥ã®æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãããã°ã©ã ã«é¢ãã幎次ã¬ãã¥ãŒã矩åä»ããŠããŸããã¬ãã¥ãŒã®çµæã¯è¡æ¿ç®¡çäºç®å±ïŒOMBïŒã«éãããããã§è°äŒåãã®å¹Žæ¬¡å ±åæžãäœæãããŸãã
æ¹æ£æ³ã§ãã2014幎é£éŠæ å ±ã»ãã¥ãªãã£è¿ä»£åæ³ïŒFISMA 2014ïŒã§ã¯ãã»ãã¥ãªãã£ããªã·ãŒã®å®æœã«å¯Ÿããåœåå®å šä¿éçïŒDHSïŒã®æš©éã匷åãããŸãããDHSããã³ã³ãã©ã€ã¢ã³ã¹ã®ç£ç£ã®ã»ããOMBãšå ±ã«ã»ãã¥ãªãã£ããªã·ãŒã®çå®ãè¡ããŸãã
FISMA 2014ã«ãããDHSã¯ãè¡æ¿åºããæ¥åå§èšãåããŠããæ°éæ©é¢ã«å¯ŸããèŠè«ã«å¿ããŠæè¡é¢ã»éçšé¢ã§ã®æ¯æŽæäŸãå¯èœã«ãªããŸãããåæ©é¢ãèŠè«ããå Žåã«ã¯ãDHSã®æè¡ãåèªã®ãããã¯ãŒã¯ã§äœ¿çšããããšãèªããããŠããŸããäžæ¹ãFISMA 2014ã§ã¯ãéå€§ãªæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããããŒã¿æŒãããè°äŒã«å ±åããããšãæ°ãã«çŸ©åä»ããããŸãããçºçæããã³å¹Žæ¬¡ã®å ±åã矩åä»ããããŠããŸãã
é£éŠæ©é¢ãå·æ¿åºæ©é¢ãæ¿åºæ©é¢ãšææºããŠããæ°éäŒæ¥ãFISMAãéµå®ããããã®äž»ãªæé ã¯æ¬¡ã®ãšããã§ãã
1. åºæ¬ç®¡ççãéžã¶
å šãŠã®é£éŠæ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã·ã¹ãã ã¯ãäžå®ã®èŠä»¶ãæºããå¿ èŠããããŸãããããã®èŠä»¶ã¯åºæ¬ç®¡ççã«åºã¥ããŠå®çŸ©ãããISMSãæ©é¢ã«ãã£ãŠç°ãªãå 容ãšãªããŸãã
2. ãªã¹ã¯ãåé¡ãã
çŸç¶ã®ãªã¹ã¯ã¬ãã«ãæç¢ºã«ããæé©ãªã»ãã¥ãªãã£ã¬ãã«ã確ä¿ããããã«ISMSãã©ãæ§ç¯ãã¹ãããæ±ºå®ããŸãã
3. 管ççãææžåãã
管ççå šäœãææ¡ã§ããããææžåããŸããISMSãšãããã¯ãŒã¯ã®é£æºã«ã€ããŠã®æ å ±ãèšèŒããŸãã
4. 管ççãæ¹åãã
ãªã¹ã¯è©äŸ¡ãè¡ãããšã§ã管ççã®æ¹åããã³ã宿œäžã®ç®¡ççãã»ãã¥ãªãã£ã®ããŒãºãæºãããŠãããã©ããã®å€æãå¯èœã«ãªããŸãã
5. ã»ãã¥ãªãã£ã¬ãã¥ãŒã宿œãã
ã»ãã¥ãªãã£ã¬ãã¥ãŒã幎次ã§å®æœããŸãããã®ã¬ãã¥ãŒã¯ãèªå®ã®ååŸã»ç¶æã«ç¹ã«éèŠã§ãã
6. 管ççãç£èŠãã
ã»ãã¥ãªãã£ç®¡ççã宿çã«ç£èŠããããšã§ãå 容ã®é©åæ§ã®ç¢ºèªãšãã€ã³ã·ãã³ãã«å¯Ÿããè¿ éãªå¯Ÿå¿ãå¯èœã«ãªããŸãã管ççã倿Žããå Žåã¯ããã®å å®¹ãææžåããããšãéèŠã§ãã
æ å ±ã»ãã¥ãªãã£ããªã·ãŒãšã¯ïŒ
æ å ±ã»ãã¥ãªãã£ããªã·ãŒãšã¯ãå šãŠã®ã³ã³ãã³ããITã»ãã¥ãªãã£ãããžã¡ã³ãã®èŠä»¶ã確å®ã«æºããããããçµç¹ãçå®ããæé ãèŠåããããŸããæç¢ºãªã»ãã¥ãªãã£ããªã·ãŒã¯ãã³ã³ãã³ããžã®ã¢ã¯ã»ã¹æš©ãæã€å šãŠãŒã¶ãŒã«èŠåãèŠå¶ãåšç¥ãããããã«ã圹ç«ã¡ãŸãã
æ å ±ã»ãã¥ãªãã£ããªã·ãŒã«ã¯ãäžè¬çã«æ¬¡ã®ãããªç®çããããŸãã
- ã»ãã¥ãªãã£å¯Ÿçã®çå®ãšææžå
- ã³ã³ãã³ããžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®å¶åŸ¡
- çµç¹ã®ã¬ãã¥ããŒã·ã§ã³ã®ä¿è·
- èŠå¶ã»æ³åŸã«å¯Ÿããã³ã³ãã©ã€ã¢ã³ã¹ã®ç¢ºä¿
- 顧客æ å ±ãªã©ã®ç§å¯æ§ã®é«ãã³ã³ãã³ããããŒã¿ã®ä¿è·
- è åšãããŒã¿æŒãããªã©ã®ã€ã³ã·ãã³ããçºçããå Žåã®å¯Ÿå¿æ¹æ³ã®çå®
- å©çšèŠå®ã®çå®ããã³èŠå®ã®ç¢ºå®ãªå®æœ
äžè¬çã«ãæ å ±ã»ãã¥ãªãã£ããªã·ãŒã¯å æ¬çãªé©çšã广çã§ããäŒæ¥ãçæã»ææããã³ã³ãã³ããæ å ±ã®å šãŠã察象ã«ãããšããã§ããããã³ã³ãã³ãã«ã¯ãã¯ã©ãŠãããªã³ãã¬ãã¹ã®ãµãŒããŒã«ä¿åããããžã¿ã«åœ¢åŒã®ãã®ããããŸãããŸãããã£ããããããªãã£ã¹å ã§ä¿åããæžé¡ãã¡ã€ã«ãDVDãããŒããã£ã¹ã¯ãããŒã¿ãã«ãã©ã€ããªã©ã®ç©ççãªåœ¢åŒã®ãã®ããããŸãã

æ å ±ã»ãã¥ãªãã£ããªã·ãŒã§ã¯ãäžè¬çã«ãçµç¹ã®ã³ã³ãã³ãããªã¹ã¯ãã¢ã¯ã»ã¹é »åºŠã«åºã¥ããŠåé¡ããŸããå顿¹æ³ã®äŸã¯æ¬¡ã®ãšããã§ãã
- èŠå¶å¯Ÿè±¡ã®é«ãªã¹ã¯æ å ±ïŒHIPAAããå®¶åºã«ãããæè²æš©å©ãšãã©ã€ãã·ãŒã«é¢ããæ³ïŒFEPRA: Family Educational Rights and Privacy ActïŒãªã©ã®èŠå¶ã«ããä¿è·ãããéå ¬éã®ã³ã³ãã³ããå人ã®éèæ å ±ãå«ãããŒã¿ãªã©ãããã«å«ãŸããã
- ç§å¯æ å ±ïŒé²èЧãã¢ã¯ã»ã¹ã«èš±å¯ãå¿ èŠãªã³ã³ãã³ãããã ããããŒã¿èªäœã¯æ³åŸãèŠå¶ã®å¯Ÿè±¡ã«ãªããªãããšãããã
- å ¬éæ å ±ïŒèª°ã§ãé²èЧã»ã¢ã¯ã»ã¹å¯èœãªã³ã³ãã³ãã
æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ããã¬ãŒã ã¯ãŒã¯ãšã¯ïŒ
æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ããã¬ãŒã ã¯ãŒã¯ãšã¯ãäŒæ¥ã®ããŒã¿ãè匱æ§ããä¿è·ããããã®åºæºã®ããšã§ããISO 27001ãã¯ãããããŸããŸãªçš®é¡ããããŸããã©ã®ãã¬ãŒã ã¯ãŒã¯ãèªç€Ÿã«æãé©ããŠãããã¯ãæ¥çš®ãå¿ èŠãšããã»ãã¥ãªãã£ç¯å²ã«ãã£ãŠç°ãªããŸãããŽãŒã«ãã¹ã¿ã³ããŒããšãããŠããã®ã¯ISO 27001ã§ããããããä»ã«ã次ã®ãããªãã®ããããŸãã
NIST SP 800-53
Special Publication 800-53ã¯ãç±³åœåœç«æšæºæè¡ç ç©¶æïŒNIST: National Institute of Standards and TechnologyïŒã«ãã£ãŠ1990幎ã«çå®ãããŸãããé£éŠæ¿åºæ©é¢ã«ããé£éŠæ å ±åŠçæšæºã®æ¡çšä¿é²ãç®çãšãããã®ã§ãæ å ±ã»ãã¥ãªãã£ã«é¢ãããã¹ããã©ã¯ãã£ã¹ã詳ããèšãããŠããŸããåœåã¯é£éŠæ¿åºåãã«çå®ãããŸãããçŸåšã§ã¯å€ãã®æ°éäŒæ¥ãæ¡çšããŠããŸãã
Payment Card Industry Data Security StandardïŒPCI DSSïŒ
PCI DSSïŒPCIããŒã¿ã»ãã¥ãªãã£åºæºïŒã¯ã倧æã¯ã¬ãžããã«ãŒãäŒç€Ÿ5瀟ã«ãã£ãŠçå®ããããã¬ãŒã ã¯ãŒã¯ã§ããã¯ã¬ãžããã«ãŒãã®äžæ£äœ¿çšã®é²æ¢ãç®çãšããŠããŸãã2004幎ã«åããŠå°å ¥ãããŸããã
Control Objectives for Information and Related TechnologiesïŒCOBITïŒ
COBITïŒæ å ±ããã³é¢é£æè¡ã®ããã®ç®¡çç®æšïŒã¯ãISACAïŒæ å ±ã·ã¹ãã ã³ã³ãããŒã«åäŒïŒãéèæ¥çåãã«çå®ãããã¬ãŒã ã¯ãŒã¯ã§ãã
Health Information Trust AllianceïŒHITRUSTïŒ
HITRUSTïŒå»çæ å ±ãã©ã¹ãã¢ã©ã€ã¢ã³ã¹ïŒã¯ããã«ã¹ã±ã¢ã»å»çæ©é¢åãã«ãæ å ±ã»ãã¥ãªãã£ã®æç¢ºãªã¬ã€ãã©ã€ã³ãæäŸããããã«çå®ããããã¬ãŒã ã¯ãŒã¯ã§ããHIPAAã³ã³ãã©ã€ã¢ã³ã¹ã®ç¢ºä¿ã容æã«ããããšãç®çãšããŠããŸãããã«ã¹ã±ã¢ã»å»çæ¥çã ãã§ãªããæ¥çãåããæ¡çšãå¯èœã§ãèŠå¶èŠä»¶ãå³ããæ¥çãäžå¿ã«æ¡çšãããŠããŸãã
æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã·ã¹ãã ãå°å ¥ããæ¹æ³

ISMSãå°å ¥ããæ¹æ³ã¯è€æ°ãããŸãããã®ãªãã§ç¹ã«ããçšããããã®ããPDCAïŒPlanãDoãCheckãActïŒãµã€ã¯ã«ãšåŒã°ããæ¹æ³ã§ããPDCAãµã€ã¯ã«ã¯ãISMSã®å°å ¥ãªã©ãçµç¹ãæ°ããåãçµã¿ãå§ããéã«åœ¹ç«ã¡ãŸãããŸããæ¥åã®æ¹åããåé¡ã®åå ã®ç¹å®ã»ç©¶æãå¿ èŠãªãšãã«ã掻çšã§ããŸããISMSãå°å ¥ããéã«ã¯ã次ã®ãããªPDCAãµã€ã¯ã«ãå®è¡ããŸãã
1. PlanïŒèšç»ïŒ
èšç»ã®æ®µéã§ã¯ãçµç¹ã®åé¡ãæŽãåºããçµå¶å¹¹éšãåéšéãªã©é¢ä¿åæå šãŠããã®è³åã»ååãåãä»ããŸãããã®æ®µéã§ISMSã®æ§ç¯ãå§ããŸããæ§ç¯ãšã¯ã䜿çšããã³ã³ãã³ããã©ãããã©ãŒã ã®æ±ºå®ããæå·åããã¹ã¯ãŒãä¿è·ãã¯ãããšããçµ±å¶æ¹æ³ã®éžæãããããšããããŸããèšç»ãç«ãŠãéã«ã¯ãå©çšå¯èœãªãªãœãŒã¹ãšãISMSã®éçšæåã®ããã«å¿ èŠãªãªãœãŒã¹ã確èªããŸãã
2. DoïŒå®è¡ïŒ
èšç»ãå®è¡ããŸããBoxã®éçšããããã¯ãçå®ããåçš®çµ±å¶ææ®µã®éçšãéå§ããããšãæå³ããŸãã äžè¬çã«ã¯ãå°ããå§ããã®ãæåã®ç§èš£ã ãšããããŸãããŸãã¯1ã€ã®éšçœ²ã§å®è¡ããç¶æ³ã芳å¯ããã®ãããã§ããããå°ããå§ããããšã§åé¡ãç¹å®ãããããªãããµã€ã¯ã«ã®æ¬¡ã®æ®µéã§ã®ä¿®æ£ãå¯èœã«ãªããŸãã
3. CheckïŒè©äŸ¡ïŒ
èšç»ãå®è¡ããããææãè©äŸ¡ããããšãéèŠã§ããè©äŸ¡ã®æ®µéã§ã¯ãæåŸ ã©ããã«å®è¡ã§ãããã©ãããæ€èšŒããŸããæåŸ ã©ããã§ãªãã£ãå Žåã¯ãåé¡ç¹ãæŽãåºããæ¹åçãæ±ºå®ããŸãã
4. ActïŒæ¹åïŒ
æ¹åã®æ®µéã§ã¯ãè©äŸ¡æ®µéã§åŸãæ°ã¥ããããšã«æåã®èšç»ãèŠçŽããããã«æ²¿ã£ãŠèšç»ãå®è¡ããŸãããã®æ®µéãŸã§æ¥ãããå šãŠã®éšçœ²ã§èšç»ãå®è¡ã«ç§»ãããããã¯ãå šç€Ÿçã«ããªã·ãŒã®éçšãéå§ããŸãã
PDCAã¯1ã€ã®ãµã€ã¯ã«ã§ãããç¹°ãè¿ãããšãæ³å®ãããã®ã§ããç¹°ãè¿ãããšã§ãäŒæ¥ã®ç¶ç¶çãªæ¹åãå³ããŸãããã¯ãããžãŒã¯åžžã«é²åããããã«ãŒã®æå£ãåžžã«å€åããŠããŸããPDCAãµã€ã¯ã«ã«ãã£ãŠISMSãã¢ããããŒããç¶ããããšã§ãåžžã«äžæ©å ãè¡ãããšãã§ããŸãã
æ å ±ã»ãã¥ãªãã£ãããžã¡ã³ãã¯Boxã§
äŒæ¥ã®ããŒã¿ãšã³ã³ãã³ãã®ä¿è·ã¯ãISMSã®éèŠãªèŠçŽ ã§ããæ¥çããªãŒãããBoxã®ã€ã³ããªãžã§ã³ãã³ã³ãã³ã管çãã©ãããã©ãŒã ã¯ãAES 256ãããæå·åããã³ã³ãã³ãã®é²èЧã»ã¢ã¯ã»ã¹è ãå¶éã»ç®¡çããã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®æ©èœã«ãããããªã¯ã·ã§ã³ã¬ã¹ãªã»ãã¥ãªãã£ãå®çŸããŸãã ããŒã¿æŒããã®é²æ¢ã«ã¯ãBox Shieldãã¯ãããšããåçš®Box補åã䟿å©ã§ãããŸããBox Governanceã«ãã£ãŠãã³ã³ãã³ããå®å šç®¡çããããªã·ãŒãäœæããããšãã§ããŸãã
Boxã«çµã¿èŸŒãŸããåçŽã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹æ©èœã¯ã以äžã®åºæºã«æºæ ããŠããŸãã
- å šæ¥çã察象ãšããFLSAãOSHAãSOXïŒ1ã2ã3ïŒãPCI DSSãIRSã«é¢ããNIST 800-53ãFIPS 140-2ãTLS
- éèãµãŒãã¹ã«é¢ããFINRAãMiFid II
- ç±³åœé£éŠæ¿åºã«é¢ããFedRAMPãDoD Cloud SRGãITAR/EARãNIST 800-171/DFARS
- ç±³åœã®ãã«ã¹ã±ã¢ã»å»çã«é¢ããHIPAAãHITECH
- ã©ã€ããµã€ãšã³ã¹ã«é¢ããGxP
Fortune 500äŒæ¥ã®67%ããã»ãã¥ã¢ãªã€ã³ããªãžã§ã³ãã³ã³ãã³ã管çã«Boxãå©çšããŠããŸããBoxã®å©çšã¡ãªããã宿ããŠããã ããç¡æãã©ã€ã¢ã«ãæ¯éã詊ããã ããã
**Boxã¯ãé«åºŠãªãã©ã€ãã·ãŒãã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ãåãã補åãšãµãŒãã¹ã®æäŸã«å°œåããŠããŸãããã ãããã®ããã°èšäºã§æäŸãããæ å ±ã¯ãæ³çå©èšã®æäŸãæå³ãããã®ã§ã¯ãããŸãããé©çšãããæ³åŸã«å¯Ÿããã³ã³ãã©ã€ã¢ã³ã¹ãæ€èšŒããéã«ã¯ãã客ããŸãèªããã¥ãŒããªãžã§ã³ã¹ã宿œããããšãæšå¥šããŸãã