$B%H%C%W(B $B!!(B$B>k$N2J3X(B $B!!(B$B1"Nq(B $B!!(B$B0[I=5-30Mh8l(B $B!!(B$B%A%'%9(B $B!!(B$BOB>{(B $B!!(B$BCf9q5*9T(B $B!!(B$B%$%s%I5*9T(B $B!!(B$B$7$4$H(B $B!!(B$BJXMxD"(B $B!!(B$B%j%s%/(B
$B%H%C%W(B > $B$7$4$H(B > $B>pJs%;%-%e%j%F%#(B2013 $BG/EY(B $B"+(B | $B"*(B 2016 $BG/EY(B |
$B0E9f2=$7$?@.@S$rH/I=(B$B$7$^$7$?!%(B
$B!D!D(B 2016-02-09, 2016-01-28
2$B7n(B12$BF|0J9_$O!$30It$+$i8+$i$l$J$/$J$j$^$9!%(B
$B$3$N
$B
$B
$BM==,$H$7$F3F9`L\$rD/$a!$E~C#L\I8$rFI$s$G$*$/$3$H$r4+$a$^$9!J(B{$B2s?t(B} $B$O2a5n$N
$B;2>H@h$NJ}!9$K!'(B
$BMxMQ$5$;$F$$$?$@$-$"$j$,$H$&$4$6$$$^$9!%3'$G;w$?$h$&$J65:`$r:n$i$:8_$$$KMxMQ$7$h$&$H$$$&$N$,!$65:`$K$D$$$F$N;d$N%]%j%7!<$G$9!%;d$O!$(BWikipedia $B$K=q$/$3$H$J$I$G9W8%$7$F$$$k$D$b$j$G$9!%;d$,:n$C$?65:`$G$*Lr$KN)$D$b$N$,$"$l$P!$<+M3$K%j%s%/$J$5$C$F$/$@$5$$!%(B
Wikipedia $B;2>H$NE,@Z@-!'(B
$B2<5-$N%j%s%/@h$K$O$B
$B"-(B$BJL%Z!<%8$,3+$/!%(B
$B$3$N?'$NOH$NItJ,(B $B$N9V5A$O4JC1$K$7$^$9$,!$;n83HO0O$K$OF~$j$^$9!%$-$A$s$H<+=,$7$F$/$@$5$$!%(B
$B!z(B
IT $B%Q%9%]!<%H;n83(B$B!J(B$B>pJs%;%-%e%j%F%#$K4X$9$k=PBj$N6/2=!&3H=<(B$B!K(B $BE~C#L\I8!'(B
$B%5%s%W%kLdBj$r8+$?$3$H$,$"$j!$;w$?LdBj$,=P$k$3$H$rCN$C$F$$$k!%>pJs=hM}5;=Q
14.3 SSL/TLS
$B!!Nc!'(B $B;00f=;M'6d9T(B $B$K%m%0%$%s!%(B
{2}
{2'}
$BE~C#L\I8!'(B
$B%V%i%&%6$K80%^!<%/$,8=$l$?>uBV$,2?$+$rCN$C$F$$$k!%(BSSL/TLS $B$NMQES$rCN$C$F$$$k!%(B
$B?.Mj$G$-$J$$(B Web $B%Z!<%8$N8+J,$1J}$rCN$C$F$$$k!%(B
$B%U%#%C%7%s%0$,@bL@$G$-$k!%(B
$B%9%Q%$%&%'%"$N5sF0$H46@w7PO)$rCN$C$F$$$k!%(B
$B%7%9%F%`>c32(B $B>pJs$NO31L$HJ6<:(B $B9q2H4V$N%5%$%P!<@oAh(B $B6=L#$N$"$k?M$@$1$,FI$a$P$h$$!%(B $B6=L#$N$"$k?M$@$1$,FI$a$P$h$$!%(B $BE~C#L\I8!'(B
$B8D?M>pJsO31L;v7o!&;v8N$NNc$r8+$?$3$H$,$"$j!$IQEY$N35?t$rCN$C$F$$$k!%(B
$B8D?M>pJsO31L;v7o!&;v8N$N
$B;vNc!'(B
$B8l8;!'(B
secure (securely) $B"*(B
security $B!a(B
$BJ]0B(B$B!$J]A4!%(B
[2. $B%N!<%H(B]
$BDj5A!'(B
$B>pJs%;%-%e%j%F%#(B
$B!D(B CIA $B$r0];}$9$k$3$H!%(B
{4''}
$B;29M!'(B
$B%3%s%T%e!<%?%;%-%e%j%F%#(B $BE~C#L\I8!'(B
$B>pJs$O;q;:$N0l$D$G$"$j!$;q;:2ACM$,$"$k$3$H$rCN$C$F$$$k!%(B
$B>pJs;q;:$NNc$r$$$/$D$+5s$2$k$3$H$,$G$-$k!%(B
$B%j%9%/!$@H
FeliCa $B$O0BA4$+(B $B!=(B $B@H $BE~C#L\I8!'(B
$B%j%9%/4IM}$NN.$l$,@bL@$G$-$k!%(B
$B%j%9%/4IM}$NMWAG$N35MW$,@bL@$G$-$k!%(B
$B%j%9%/BP1~$N#4J}?K$,@bL@$G$-$k!%(B
$B>pJs4IM}$N#4
$B:R32!'(B
$BKL3$F;Fn@>2-CO?L(B,
$B:e?@!&C8O)Bg?L:R(B,
$BElKLCOJ}B@J?MN2-CO?L(B
$B%F%m!'(B
$B%"%a%j%+F1;~B?H/%F%m;v7o(B (2001$BG/(B 9.11)
$BBP1~!'(B
$BJF(B $B9qEZ0BA4J]>c>J(B,
$BFb3U0BA4J]>c<<(B$B!J(B$BFbD4(B$B!K(B
9.11 $B$G$N4m5!4IM}(B
+$B!J(B$BDL?.ES@d(B$B!K(B,
$B%X%j%3%W%?!<$NMxMQ(B
+
$B $BE~C#L\I8!'(B
$B4m5!H/@8;~$K$*$1$kB.Js$N=EMW@-$rCN$C$F$$$k!%(B
$BF|K\$G$N4m5!BP1~AH?%$rCN$C$F$$$k!%(B
$B4m5!4IM}$N
2003
$B9qL1$N$?$a$N>pJs%;%-%e%j%F%#%5%$%H(B$B!JAmL3>J!K(B,
1990
$B3F
1996
JPCERT/CC $B":(B
CSIRT ,
+
$B>pJs%;%-%e%j%F%#%^%M%8%a%s%H%7%9%F%`(B (ISMS),
PDCA$B%5%$%/%k(B
{11}
{9''}
$B9q:]5,3J$N@oN,E*$JMxMQ(B.pdf,
EU$B$N9q:]5,3J2=@oN,(B
$BE~C#L\I8!'(B
$B9q$HL14V$N>pJs%;%-%e%j%F%#$K
2013 JNSA
$B%$%s%7%G%s%HD4::Js9p=q(B
(2012
11,
10,
09,
08,
07)
{12}
$BK\?M$NF10U!'!J(B$B%*%W%H%"%&%H(B
+$B!K(BOpt-out
$B"*(B Opt-in
$B"*(B Double opt-in
$BE~C#L\I8!'(B
$B!H@Q6KE*%W%i%$%P%7!<8"!I$NDj5A$,@bL@$G$-$k!%(B
$B>pJsO31L;v7o!&;v8N$NB?$5$rCN$C$F$$$k!%(B
OECD $B$N%W%i%$%P%7!<(B 8 $B86B'$K$D$$$F!$CN8+$,$"$k!%(B
$B8D?M>pJsJ]8nK!$K$*$1$k!H8D?M>pJs!I$NDj5A$,@bL@$G$-$k!%(B
$B8D?M>pJs$N=jM-
$B%,%$%I%i%$%s(B$B!J6qBNNc!K(B+
++,
PDCA$B%5%$%/%k(B
ISO 22301 (BCMS)
+,
++
$B"+(B
ISO/PAS 22399,
BS 25999 $BE~C#L\I8!'(B
CISO $B$,2L$?$9Lr3d$,@bL@$G$-$k!%(B
$B>pJs%;%-%e%j%F%#%]%j%7!<$N9=@.$HFbMF$,@bL@$G$-$k!%(B
$B35MW(B$B!JIUO?#2(B, p.91$B!K!'(B
P $B3NN)!J(B$B?^IU(B2.2$B!K(B $B"*(B
D $BF3F~!&1?MQ!J(B$B?^IU(B2.6$B!K(B $B"*(B
C $B4F;k!&%l%S%e!$B?^IU(B2.7$B!K(B $B"*(B
A $B0];}!&2~A1!J(B$B?^IU(B2.8$B!K(B $B"*(B
PDCA...
$B9q:]E*$J(B ISMS $B$NG'>Z4p=`(B
(1) ISO/IEC 27001 "Information security management systems — Requirements"
(2) ISO/IEC 27002 "Code of practice for information security management"
$BF|K\9)6H5,3J(B $B"-(B$B!JK]Lu!K(B
(1') JIS Q 27001 $B!H(BISMS $B!=(B $BMW5a;v9`!I(B
$B!J(B$B5,3JI<(B$B!K(B
(2') JIS Q 27002 $B!H>pJs%;%-%e%j%F%#%^%M%8%a%s%H$N
(3') JIS Q 13335-1 $B!H>pJsDL?.5;=Q%;%-%e%j%F%#$N%^%M%8%a%s%H(B $B!=(B $BBh(B1$BIt!'>pJsDL?.5;=Q$N%;%-%e%j%F%#%^%M%8%a%s%H$N$?$a$N35G05Z$S%b%G%k!I(B
(4') JIS X 5070-1 $B!H%;%-%e%j%F%#5;=Q(B $B!=(B $B>pJs5;=Q%;%-%e%j%F%#$NI>2A4p=`!I(B
{12'}
{12''}
$BE~C#L\I8!'(B
$B>pJs%;%-%e%j%F%#%^%M%8%a%s%H%7%9%F%`$N35MW$,@bL@$G$-$k!%(B
PDCA $B$N3F2aDx$G6qBNE*$K2?$r$9$Y$-$+$rCN$C$F$$$k!%(B
$B3FAH?%$N(B ISMS $B$H(B JIS Q 27001 $B$H$N4X78$,@bL@$G$-$k!%(B
$BHH:a(B $B!a(B $BHH0U$"$k
$BFbItE}@)(B,
$B%3!<%]%l!<%H!&%,%P%J%s%9(B
(govern)
$BF|K\%;%-%e%j%F%#4F::?M6(2q(B (JASA)
$BJ8=q"*(B$B%P%C%/%"%C%W(B$B!$5-O?"*(B$B%"!<%+%$%V(B
$B;qNA!'(B
[8. $B%N!<%H(B]$B!J(B$BC4J](B$B!K(B
$BE~C#L\I8!'(B
$BNc!'(B $B%5%$%HMxMQ5,Ls(B,
$B%W%i%$%P%7!
+,
$BE~C#L\I8!'(B
$B>pJs%;%-%e%j%F%#%,%P%J%s%9$NDj5A$rCN$C$F$$$k!%(B
$B>pJs%;%-%e%j%F%#Js9p=q$N:n@.$,?d>)$5$l$F$$$k$3$H$rCN$C$F$$$k!%(B
$B>pJs%;%-%e%j%F%#Js9p=q%b%G%k$NB8:_$rCN$C$F$$$k!%(B
$B>pJs%;%-%e%j%F%#Js9p=q$r8+$?$3$H$,$"$k!%(B
ITIL $B$,2?$+$rCN$C$F$$$k!%(B
ISO/IEC 20000 $B$rCN$C$F$$$k!%(B
$BE~C#L\I8!'(B
$BMQ8l!H>pJs%;%-%e%j%F%#J82=!I$rCN$C$F$$$k!%(B
$BMQ8l!H=>6H $BE~C#L\I8!'(B
$B
$B%M%C%H%o!<%/
$BBh(B234$B>r$NFs(B$B!JEE;R7W;;5!B;2uEy6HL3K832!K!$(B
$BBh(B246$B>r$NFs(B$B!JEE;R7W;;5!;HMQ:>5=!K!$(B
$BBh(B161$B>r$NFs(B$B!JEE<'E*5-O?IT@5:n=P5Z$S6!MQ!K(B,
$BBh(B163$B>r$NFs!A8^(B$B!J;YJ'MQ%+!<%IEE<'E*5-O?IT@5:n=PEy!$IT@5EE<'E*5-O?%+!<%I=j;}!$;YJ'MQ%+!<%IEE<'E*5-O?IT@5:n=P=`Hw!$L$?k:a!K!$(B
$BBh(B168$B>r$NFs!$;0(B$B!J(B$BIT@5;XNaEE<'E*5-O?:n@.Ey(B$B!K!$(B
$BBh(B258$B>r(B$B!J8xMQJ8=qEyTL4~!K!$(B$BBh(B259$B>r(B$B!J;dMQJ8=qEyTL4~!K(B
$BE~C#L\I8!'(B
$B8xMQJ8$K$*$$$F!H5Z$S!&JB$S$K(B $B!?(B $BKt$O!&
$B$I$NG=F0BN(B (subject) $B$+$i!$$I$N
$BE~C#L\I8!'(B
$BJ*M}E*$J%"%/%;%9@)8fJ}<0$NBeI=Nc$rCN$C$F$$$k!%(B
$B%"%/%;%9@)8f9TNs$N35G0$,@bL@$G$-$k!%(B
$B%"%/%;%9@)8f%j%9%H$NJ}<0$H5!G=$,@bL@$G$-$k!%(B
$BMQ8l!H%U%!%$%k%Q!<%_%C%7%g%s!I$rCN$C$F$$$k!%(B
$B%"%/%;%9@)8f$N(B 3 $B
13.4.4 $B0E9f5;=Q$r;H$C$F$G$-$k$3$H(B$B!J(B$B:F7G(B: $B35MW(B$B!K(B
$BE~C#L\I8!'(B
$B@$3&$ND5Js5!4X$N8=>u$N35MW$rCN$C$F$$$k!%(B
$B0E9f$NDj5A$rCN$C$F$$$k!%(B
$B0E9f7O$N4pK\E*$JMQ8l$,@bL@$G$-$k!%(B
$B0E9f2rFI$N(B 3 $BCJ3,$N>u67$,@bL@$G$-$k!%(B
$B0E9f2rFI$N@.8y$rHkF?$7$?Nc$r$$$/$D$+CN$C$F$$$k!%(B
$B0E9f5;=Q$r;H$C$F
13.3.0
$B6&DL800E9f(B $BE~C#L\I8!'(B
$B6&DL800E9f7O$N35G0$,@bL@$G$-$k!%(B
$BC149$(;z<00E9f$,!$Nc$r5s$2$F@bL@$G$-$k!%(B
$BB?I=<00E9f$rCN$C$F$$$k!%(B
$BE>CV<00E9f$,!$Nc$r5s$2$F@bL@$G$-$k!%(B
$B6qBNE*$J8EE5E*0E9f$r!$(B(1)$BC149$(;z<00E9f!$(B(2)$BB?I=<00E9f!$(B(3)$BE>CV<00E9f(B $B$KJ,N`$9$k$3$H$,$G$-$k!%(B
(1) $B$H(B (3) $B$H%V%m%C%/0E9f$KB0$9$k3F0E9fJ}<0$N80$NAm?t$,<($;$k!%(B
(1), (2), (3) $B$N0E9f2=$HI|9f$N$7$+$?!$$*$h$S2rFI$N$7$+$?$rCN$C$F$$$k!%(B
$B2rFIIT2DG=$J0E9f$,!$Nc$r5s$2$F@bL@$G$-$k!%(B
$B%V%m%C%/0E9f$NMxMQ%b!<%I$N$&$A!$(BECB, CBC, OFB $B$rCN$C$F$$$k!%(B
AES $B$N30It;EMM$,@bL@$G$-$k!%(B
13.4.0 $B8x3+800E9f(B
{11'}
$BE~C#L\I8!'(B
$B8x3+800E9f7O$N35G0$,@bL@$G$-$k!%(B
$B>jM>1i;;$G$N2C;;$H>h;;$HN_>h$,$G$-$k!%(B
RSA $BJ}<0$N35MW$,@bL@$G$-$k!%(B
$B8x3+80G'>Z7O$N35G0$,@bL@$G$-!$2?$, $BE~C#L\I8!'(B
$B0E9f%W%m%H%3%k$N$$$/$D$+$rCN$C$F$$$k!%(B
$B%A%c%l%s%81~Ez%W%m%H%3%k$NL\E*$H35MW$rCN$C$F$$$k!%(B
$BEE;R%^%M!<$N35MW$rCN$C$F$$$k!%(B
TLS $B$N35MW$rCN$C$F$$$k!%(B
$BE~C#L\I8!'(B
$B8x3+804pHW$N35MW$rCN$C$F$$$k!%(B
$BG'>Z6I$N5!G=$,@bL@$G$-$k!%(B
$B>pJs%;%-%e%j%F%#!&%5!<%S%9$N$$$/$D$+$rCN$C$F$$$k!%(B
JIS X 5070 (ISO/IEC 15408) $B5,3J72!H%;%-%e%j%F%#5;=Q(B $B!=(B $B>pJs5;=Q%;%-%e%j%F%#$NI>2A4p=`!I(B
JIS$B4A;zId9f(B$B!J(B$BF|K\$K$*$1$k4A;z(B$B!K!$(B
$B9q:]Id9f2=J8;z=89g(B (UCS)
$B%O%_%s%05wN%(B$B!$(B
$B8m$j8!=PD{@5(B
$B9b9;@88~$1$N(B$BLO5<
$B9V5AFbMF(B A /
$B9V5AFbMF(B B
$B$B
$B!$4IM}$B>pJs%;%-%e%j%F%#(B A
0. $B%,%$%@%s%9(B
0.0
$BMz=$=g=x(B$B!J@oN,%G%6%$%s%3!<%9!K(B
0.1
$B$3$N(B Web $B%Z!<%8$X$N(B$B$?$I$jCe$-J}(B
0.2
$B2a5n$N
0.3 $B2?$r3X$V$+(B
0.4 $B>pJs%;%-%e%j%F%#(B A $B$NL\I8(B
0.5
$B;29M=q(B
0.6 $B>pJs%;%-%e%j%F%#%9%Z%7%c%j%9%H;n83(B, $B2a5nLdBj(B
$B!z(B
$B9q2H;n83!V>pJs%;%-%e%j%F%#%^%M%8%a%s%H;n83!W$NAO@_(B
$B!J(B$B%5%s%W%kLdBj(B$B!K(B
0.7
$B%7%i%P%9(B$B$N@bL@!$@.@SI>2A$NJ}K!(B
0.8
$B@.@SH/I=$NJ}K!(B$B!$(B
$BH4$-BG$A%F%9%H(B
{1}
{1'}
1.
$B>pJs%;%-%e%j%F%#(B$B%j%F%i%7!<(B +
1.1
$B:G6a$NOCBj$H$J$C$?;v7o(B
1.2
$B4JC1!*$d$5$7$$%;%-%e%j%F%#65<<(B$B!JLdBj(B 4$B!A(B6$B!K(B
1.3
$B;vNc$HBP:v(B
1.4 $B;vA0CN<1%"%s%1!<%H(B
$B"*(B YeStudy
1.5 $B;29M$H$J$k
2. $B>pJs%;%-%e%j%F%#(B
2.0
$B>pJs$N;q;:2ACM(B$B!'(B
$B>pJs$N;q;:(B$B!J(Bp.24 $B$^$G!K(B
$BI>2A%5!<%S%92q
$B"*(B $B>CLG(B
{3'}
2.1 $B%;%-%e%j%F%#(B
2.2 $B>pJs%;%-%e%j%F%#$NDj5A$HMQ8l(B
$BMQ8l(B
+
$B!'(B
$B%j%9%/(B
$B@H
$B6<0R(B
+
$B%$%s%7%G%s%H(B
$BBP93:v(B + {5}
$BNc(B
$B=;Bp(B $B2P:R(B $B2DG3J* $B%?%P%3(B + $B:rHU$N2P;v(B $BFqG3J*
$B>pJs(B $BO31L(B $B1?HB(B $BCV$-K:$l(B $B@hF|$NO31LL$?k(B $B0E9f2=(B, $B6XBS=P(B
{5''}
$B%a!<%kH/?.
2.3 $B5!L)@-$H2DMQ@-$N%H%l!<%I%*%U(B
2.4 $B%Q%9%o!<%I$X$N967b(B
$B!a(B $B%V%k!<%H!&%U%)!<%9!&%"%?%C%/(B (Brute-force attack)
2014 ANA $B$H(B JAL $B$N;vNc(B
2.6
SQL $B%$%s%8%'%/%7%g%s(B $B967b(B
2.5
$B%j%9%/4IM}(B$B!'(B
$B%j%9%/%"%;%9%a%s%H(B,
+
++
$B"*(B
$B%j%9%/BP1~(B
$B!J%j%9%/4IM}$NMQ8l!'(B JIS Q 0073$B!K(B
2.7
$BNr;K(B
+$B!'(B
$BB9;R(B
+,
$B9q:]5,3J(B$B2=(B,
$B@H
3. $B4m5!4IM}(B$B$K$*$1$k>pJs%;%-%e%j%F%#(B
3.0 $BB.Js!J2DMQ@-$H40A4@-!K$N=EMW@-(B
3.1 $B4m5!4IM}(B$B!'(B
$B!JM=KI(B $B"*(B
$BGD0.(B $B"*(B
$BI>2A(B $B"*(B
$B8!F$(B $B"*(B
$BH/F0(B $B"*(B
$B:FI>2A!K(B
$B4m5!>uBV$G$O!$(B$B@[B.$O9*CY$KM%$k(B$B!%(B
$B4m5!>uBV$G!$AH?%E*$J9TF0$r$9$k$?$a$NMWE@!'(B
$B!!(B(1)$BM-8z$J;X4xE}@)(B
(2)$B0[$J$C$?AH?%4V$NO"F0BN@)(B
+
(3)$BL@3N$J9TF0;X?K(B
$B!!(B(*)$B8"8B$N0Q>y(B
$B6p_7Bg3X(B $B6[5^O"Mm@h!J@5Lg
$BKI:RMQ%7%c%Y%k(B 10 $BK\$O!$7YHw<
6.3 $B;v6H7QB37W2h(B (BCP)$B!'(B
JIS Q 22301
4. $BAH?%$N
4.1 $B9q$N
2003
@police$B!J7Y;kD#!K(B,
2005
$BFb3U%5%$%P!<%;%-%e%j%F%#%;%s%?!<(B (NISC)
4.2 $BL14V$N
1998
$B%W%i%$%P%7!<%^!<%/(B$B!J(BJIPDEC$B!K!$(B
2002
ISMS$BE,9g@-I>2A@)EY(B$B!J(B$BF|K\>pJs7P:Q
2005
$B4k6H$N>pJs%;%-%e%j%F%#$N$"$jJ}$K4X$9$kDs8@(B$B!J(B$B7PCDO"(B$B!K(B
4.3 $B3F4k6H!JAH?%!K$N
4.4 $B9q:]5,3J(B
{9'}
+
+$B!'(B
ISO/IEC 27000 $B%7%j!<%:(B
5. $B%W%i%$%P%7!<(B
5.0 $BEpD0!'(B
Street View
5.1 $B>pJsO31L$N8=>u!'(B
$B>pJsN.=P(B,
$B0lMw(B,
5.2 $BK!@)2=$N5/8;!'(B
OECD
$B%W%i%$%P%7!<(B8$B86B'(B$B!J(B$B86J8(B$B!K(B,
$B8D?M>pJs(B
{10''}
5.3 $B8D?M>pJsJ]8nK!(B
{10'}
$B!c(B Safe Harbor $B86B'(B
$B!c(B EU$B;XNa(B
[5. $B%N!<%H(B]
$B8D?M>pJsJ]8nK!$N>\:Y$K$D$$$F$O!$>pJs%;%-%e%j%F%#(B B $B$G9V5A$9$k!%(B
5.4
$BK:$l$i$l$k8"Mx(B
{13}
5.5 $B8D?M>pJsJ]8n%^%M%8%a%s%H%7%9%F%`(B (PMS) JIS Q 15001, +
6. $B>pJs%;%-%e%j%F%#%]%j%7!<(B
(policy)
Q14$B!A(BQ16, Q19
6.1 $B:G9b>pJs%;%-%e%j%F%#@UG$
6.2 $B>pJs%;%-%e%j%F%#%]%j%7!<(B$B!J4pK\J}?K!$BP:v4p=`!K!$
$B%;%-%e%j%F%#%]%j%7!<$N:n@.2A3J(B
$B!J@=:nHq!a?tI4K|1_(B $B!c(B $B?t2/1_$NB;<:!K(B
{11'}
6.3 $B;v6H7QB37W2h(B (BCP) $B$+$i$NMW@A(B
6.4
$B
7. $B>pJs%;%-%e%j%F%#%^%M%8%a%s%H%7%9%F%`(B (ISMS)
+
++
$BF|K\9)6H5,3J!?4IM}%7%9%F%`(B $B$N0lMw(B
$B%;%-%e%j%F%#5;=Q(B $B$N0lMw(B
8. $B>pJs%;%-%e%j%F%#4F::(B
8.0 $B%5%$%P!
8.1 $BGX7J!'(B $B4F::(B
+$B!$(B
$B%3%s%W%i%$%"%s%9(B
(comply)
+
SOX$BK!(B,
$BF|K\HG(BSOX$BK!(B
$B>pJs%;%-%e%j%F%#%,%P%J%s%9(B
$BIT:n0Y(B$B$N@UG$(B $B"*(B $B@bL@@UG$(B
(accountability)
[8. $B%N!<%H(B]
8.2 $B>pJs%;%-%e%j%F%#4F::(B$B!'(B
$B@)EY(B,
$B4F::?M(B
$B4F::>Z5r!$(B$B;~7ONs$N>Z5r(B $B!a(B $B4F::>Z@W(B
{13'}
{13''}
8.3 $B%3%s%T%e!<%?!&%U%)%l%s%7%/%9(B.pdf
+
(forensics +)
$BJ8=q4IM}%7%9%F%`(B,
$B5-O?4IM}%7%9%F%`(B,
$BEE;R%a!<%k(B,
$BF'$_Bf(B
$B%3%s%W%i%$%"%s%9$H%,%P%J%s%9$,@bL@$G$-$k!%(B
$B!!(B
$B%3%s%T%e!<%?!&%U%)%l%s%7%/%9$N35MW$H;0$D$NL\E*$,@bL@$G$-$k!%(B
$B4F::>Z5r$H4F::>Z@W$K$D$$$F@bL@$G$-$k!%(B
$BJ8=q$H5-O?!$%P%C%/%"%C%W$H%"!<%+%$%V$N:9$,@bL@$G$-$k!%(B
SOX $BK!$,@8$^$l$?GX7J$rCN$C$F$$$k!%(B
$BF|K\HG(B SOX $BK!$N35N,$rCN$C$F$$$k!%(B
$BFbItE}@)$N(B 4 $B$D$NL\E*$H(B 6 $B$D$N4pK\E*MWAG$rCN$C$F$$$k!%(B
9. $B>pJs%;%-%e%j%F%#%,%P%J%s%9(B
9.1 $B
ISO 27001 $BG'>Z
$BF|K\HG(BSOX$BK!$X$NBP1~(B,
$B%3%s%W%i%$%"%s%9;v6H(B;
$B>pJs%;%-%e%j%F%#3JIU(B
9.2 $B>pJs%;%-%e%j%F%#%,%P%J%s%9(B$B!'(B
$B>pJs%;%-%e%j%F%#Js9p=q(B 05,
10,
R
9.3 ITIL
$B"*(B ISO/IEC 20000
10. $B>pJs%;%-%e%j%F%#J82=(B
10.1 $B=>6H
10.2 $B>pJsNQM}(B$B!'(B
$BCx:n8"?/32;v7o(B
{14'}
{14''}
10.3 $B;v8eCN<1%"%s%1!<%H(B
$B"*(B YeStudy
{15}
$B>pJs%;%-%e%j%F%#(B B
B0. $B%,%$%@%s%9(B
B0.0
$BMz=$=g=x(B$B!J@oN,%G%6%$%s%3!<%9!K(B
B0.1
$B<+8J>R2p(B$B!((B
$B$3$N(B Web $B%Z!<%8$X$N(B$B$?$I$jCe$-J}(B
B0.2
$B2a5n$N
B0.3 $B>pJs%;%-%e%j%F%#%9%Z%7%c%j%9%H;n83(B, $B2a5nLdBj(B
B0.4
$B%7%i%P%9(B$B$N@bL@(B$B!J@.@SI>2A$NJ}K!!K(B$B!$(B
$B;29M?^=q(B$B$N>R2p(B
B0.5
$B@.@SH/I=$NJ}K!(B$B!$(B
$BH4$-BG$A%F%9%H(B
B0.6
$B0E9f5;=Q(B$B$N=EMW@-(B $B!J(B$BEE;REjI<(B$B!$(B$BEE;R=pL>K!(B$B!K(B
B0.7
$B>pJs%;%-%e%j%F%#4pHW(B
[0.7 $B%N!<%H(B]$B!JElBg(B $B:4F#<~9T@h@8(B$B!K(B
B0.8 $BCN<1%"%s%1!<%H(B$B!J(BYeStudy$B$K$h$k!K(B
{1}
{1'}
{1''}
*
IoT $B%;%-%e%j%F%#(B: $B!J5H2,!V!D(B IoT $B$N>W7bE*8=>u!D!W!K(B
11. $BK!N'$K$h$kJ]8n(B
11.0 $B>rJ8$NFI$_J}!'(B $B5Z$S!&JB$S$K(B $B!?(B $BKt$O!&
$BK!N'$K$*$1$k#I#TMQ8l!J8eH>!K(B $B!?(B$B!J(B$BA0H>(B$B!K(B
$B@.J8K!(B$B$H(B$B8"Mx(B$B$NF3F~!'(B $B9>8M;~Be(B$B$N(B$B6(D4(B $B"*(B $B8=Be$N(B$B<+8J
11.1 $B>pJs%;%-%e%j%F%#$K4X$9$k9qFbK!5,(B$B!JAmMw!K(B,
{2''}
+,
$BL$?k(B
11.2 $B7:K!(B $B!J(B$BA4J8(B$B!K(B
{3''}
$B%5%$%P!<7:K!(B
$B!\(B
++$B!J(B$BK!L3>J(B$B!K(B
11.3 $BIT@5%"%/%;%96X;_K!(B
11.4 $B8D?M>pJsJ]8nK!(B
{3}
$B2~@5ItJ,(B
11.5
$BCx:n8"K!(B
$B!J(B$BA4J8(B,
{3'}
$B3X9;$G$NJ#@=(B,
$BJ]8n4|4V(B$B!K(B,
$BLdBj(B,
{4''}
$B2~@5Cx:n8"K!(B
$BCx:n8"LdBj(B$B$N2rEz!'(B $B0lIt$@$1$r!$=PE5$rL@5-$7$F(B $B0zMQ$7$F$$$k$N$G!$9gK!$G$7$g$&!%(B
11.6
$B%5%$%P!<%;%-%e%j%F%#4pK\K!(B$B!J;\9T(B: 2014-11-12$B!K(B
11.7 $B$=$NB>(B $B4XO"$9$k
11.8 $B%*!<%W%s%=!<%9(B$B!P%=%U%H%&%'%"!$%i%$%;%s%9!Q(B,
GFDL,
{5''}
$BHf3S(B
+
$B!!!!!z(B
$B9q2H;n83!V>pJs%;%-%e%j%F%#%^%M%8%a%s%H;n83!W$NAO@_(B
$B!J(B$B%5%s%W%kLdBj(B$B!K(B
12. $B%"%/%;%9@)8f(B$B!J(Baccess, $BJ*M}E*!$%3%s%T%e!<%?!$%M%C%H%o!<%/!K(B
12.1 $BJ*M}E*!'(B
$B7YHw0w!$(BID $B%+!<%I(B,
$BFz:LG'<1(B +
{4'}
12.2 $B%"%/%;%9@)8f9TNs(B$B!J(B$B%"%/%;%9@)8f%j%9%H(B,
{5}
+,
$B%Q!<%_%C%7%g%s(B
-$B!K(B
$B$I$N%"%/%;%9(B$B!JFI$_!?=q$-!?
$B%U%!%$%kB0@-$NJQ99$NFFFTP $B$K$h$k!K!%(B
{5'}
{6''}
$B
{6}
13. $B0E9f(B - $B35MW(B
13.0
$B>pJs5!4X(B
(intelligence)$B!'(B
HUMINT,
SIGINT
(Echelon,
PRISM)
{6'}
$BJF(B NSA $B$,3F9q13.1
$B0E9f$N2ACM!'(B
$B2rFI;v
{7''}
13.2
$B0E9f(B$B$H$O!'(B
$B0E9fM}O@(B$B!$(B
$B0E9f7O$H(B$BMQ8l(B
$B!J(B$B%/%j%W%H%s(B$B!K(B
{7}
13.3 $B6&DL800E9f(B
13.3.1
$B49$(;z<00E9f(B
$B!!(B(1) $BC149$(;z<00E9f!'(B
{8}
{7'}
{8''}
$B!H(B$BMY$k?M7A(B$B!I(B$B$N2rFI(B
{9}
{8'}
{9''}
$B!!(B(2) $BB?I=<00E9f(B $B!a(B
$BJ#?t$NC149$(;z<00E9f$r<~4|E*$KMQ$$$k!%(B
$B!!!!!!!!(B$B5!3#<00E9f(B $B!J(B$B%Q!<%W%k0E9f(B$B!K(B
$B!!(B(3) $B%S%C%HC10L$NB?I=<00E9f(B $B"*(B $B%P!<%J%`0E9f(B
13.3.2 $BE>CV<00E9f(B
$B!J(B$B%"%J%0%i%`(B$B!K(B
{10}
{9'}
{10''}
13.3.3 $B0E9f2rFI(B
$B!!(B(0) $B80$NAm?t(B
$B!!(B(1) $BC149$(;z<00E9f$N2rFI!JJ8;zIQEY!K(B
$B!!(B(2) $BB?I=<00E9f$N2rFI!J<~4|!K(B
$B!!(B(3) $BE>CV<00E9f$N2rFI!JO"@\3NN(!K(B$BF|K\$K$*$1$k4A;z(B
$B!!(B(4) $B2rFIIT2DG=$J0E9f(B$B!$(B$B
$B!!(B(5) $B0E9f2rFI5;=Q$NMxMQ(B $B!J(B$B%m%<%C%?!&%9%H!<%s(B$B$N2rFI(B, +, -$B!K(B
$B309q8l(B
{11}
{10'}
{11''}
13.3.4 $B%V%m%C%/0E9f(B(+)
$B$N(B$BMxMQ%b!<%I(B$B!J(B$BF02h(B, $B?^(B$B!K(B
$B$H(B $B%9%H%j!<%`0E9f(B
$B!!!!!!!!(B[$B@~7A5"4T%7%U%H%l%8%9%?(B(LFSR) +]
13.3.5 AES (Rijndael) $B!D(B $B8=BeE*$J6&DL800E9f(B
[13$B>OA0H>$N%N!<%H(B]
+
{12}
{12''}
13.4 $B8x3+800E9f(B
13.4.1 $B>jM>1i;;(B$B!J(B$B$Y$->h>jM>(B$B!$(B$B%U%'%k%^!<$N>.DjM}(B$B!K(B
13.4.2 RSA$BJ}<0(B
$B!J(B$B$Y$->h;;$N9bB.2=(B$B!K(B+
{13}
{12'}
{13''}
13.4.3 $BG'>Z(B$B!'(B
$B!J(B$B=pL>(B$B$H(B$B2V2!(B$B!$(B$BNrBe
$B!!!!!!(B $BEE;R=pL>(B$B!$(B$B0u4U>ZL@$HEE;R=pL>(B$B!$(B+
$B=pL>$D$-$N0E9fJ8(B
13.4.4 $B0E9f5;=Q$r;H$C$F$G$-$k$3$H(B$B!J(B$B35MW(B 5.$B!K(B
{14}
{13'}
13.4.5 $B%O%C%7%e4X?t(B
[13.4 $B$N%N!<%H(B]
+
$B!!(B
$B
13.5
$B0lJ}8~@-4X?t(B
13.6
$BNL;R0E9f(B
$B!!!!!!(B $BCN<1%"%s%1!<%H(B
$B%O%C%7%e4X?t$N35MW$rCN$C$F$$$k!%(B
$B0lJ}8~@-4X?t$N35G0$rCN$C$F$$$k!%(B
$BNL;R0E9f$rCN$C$F$$$k!%(B
14. $B0E9f%W%m%H%3%k(B
14.1 $B%A%c%l%s%81~Ez%W%m%H%3%k(B
14.2 $BEE;R%^%M!<(B
14.3 SSL/TLS
{14'}
15. $B>pJs%;%-%e%j%F%#4pHW(B
15.1 $B8x3+804pHW(B (PKI),
$BG'>Z6I(B (CA),
+
15.2 $B>pJs%;%-%e%j%F%#!&%5!<%S%9(B
$B&A(B. $B>pJs%;%-%e%j%F%#I>2A4p=`(B (Common Criteria)
$B&A(B.1
$BG'>Z@=IJ%j%9%H(B,
+
$B&B(B. $BId9f(B
$B&B(B.1
$BId9f(B$B!'(B
$B%G!<%?%3!<%I!$(B
$B%b!<%k%9Id9f(B$B!$(B
$B#G%3!<%I(B
$B&B(B.2
$BJ8;zId9f(B$B!'(B
ASCII$B"*(BISO 646$B"*(BJIS X 0201$B!$(B
$B&B(B.3
$B8m$jBQ@-!'(B
$B8!::?t;z(B ($B%A%'%C%/%G%#%8%C%H(B$B!a(BCD, ISBN)$B!$(B
$B&C(B. $B$=$NB>(B
$B&C(B.1 $B#2?JK!!'(B
$B0L
$B&C(B.2
$BI8K\2=DjM}(B$B!$(B
$B%S%C%HB.EY(B$B!$(B
$B%G!<%?05=L(B
$B@.@SH/I=(B
$B$R$H$DLa$k(B
$B@>B
2013
$B0l:rG/EY$N%Z!<%8(B