賌èªè ããŒã¿ã®ä¿è·ã¯åãªãæ³çèŠä»¶ã§ã¯ãããŸãããä¿¡é Œãç¶æããæç¶å¯èœãªã¡ãŒã«ããŒã±ãã£ã³ã°ããã°ã©ã ãéå¶ããããã®åºç€ã§ããGDPR ããã³ãã®ä»ã®ãã©ã€ãã·ãŒèŠå¶ã®äžã§ãçµç¹ã¯å人ããŒã¿ãä¿è·ããããã®é©åãªæè¡çããã³çµç¹çæªçœ®ãå®è£ ããå¿ èŠããããŸãããã®ã¬ã€ãã§ã¯ãèŠå¶èŠä»¶ããå®è·µçãªå®è£ æŠç¥ãŸã§ãã¡ãŒã«ããŒã¿ä¿è·ã«ã€ããŠç¥ã£ãŠããã¹ããã¹ãŠã®ããšãã«ããŒããŸãã
ã¡ãŒã«ããŒã¿ä¿è·èŠä»¶ã®çè§£
ã»ãã¥ãªãã£æªçœ®ãå®è£ ããåã«ãèŠå¶ãäœãèŠæ±ããŠãããããªãä¿è·ãéèŠãªã®ããçè§£ããŸãã
ä¿è·ãå¿ èŠãªããŒã¿
ã¡ãŒã«ããŒã±ãã£ã³ã°ã«ã¯æ§ã ãªçš®é¡ã®å人ããŒã¿ãå«ãŸããŸãã
賌èªè æ å ±:
- ã¡ãŒã«ã¢ãã¬ã¹
- æ°åãšäººå£çµ±èšæ å ±
- äŒç€Ÿãšåœ¹è·æ å ±
- èšå®ãšèå³
ãšã³ã²ãŒãžã¡ã³ãããŒã¿:
- éå°ããã³ã¯ãªãã¯èšé²
- å¿çå±¥æŽ
- è³Œå ¥ããã³ã³ã³ããŒãžã§ã³ããŒã¿
- ããã€ã¹ããã³äœçœ®æ å ±
åæèšé²:
- åæãäžããããææ
- äœã«åæããã
- åæãã©ã®ããã«ååŸãããã
- ãã®åŸã®å€æŽ
ãããã¯ãã¹ãŠ GDPR ã®äžã§å人ããŒã¿ã§ããåæ§ã®èŠå¶ã«ãããé©åãªä¿è·ãå¿ èŠã§ãã
GDPR 第 32 æ¡:åŠçã®ã»ãã¥ãªãã£
第 32 æ¡ã¯ GDPR ã®äžã§ã®ããŒã¿ä¿è·ã®æ çµã¿ãèšå®ããŸãã
å¿ èŠãªæªçœ®: 管çè ããã³åŠçè ã¯ããªã¹ã¯ã«é©ããã»ãã¥ãªãã£ã¬ãã«ã確ä¿ããããã«ãé©åãªæè¡çããã³çµç¹çæªçœ®ãå®è£ ããªããã°ãªããŸãããããã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
- å人ããŒã¿ã®ä»®ååãšæå·å
- åŠçã·ã¹ãã ã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§ãããã³å埩å
- ã¿ã€ã ãªãŒãªæ¹æ³ã§ããŒã¿ãžã®å¯çšæ§ãšã¢ã¯ã»ã¹ã埩å ããèœå
- ã»ãã¥ãªãã£æªçœ®ã®å®æçãªãã¹ããšè©äŸ¡
ãªã¹ã¯ããŒã¹ã®ã¢ãããŒã: ã»ãã¥ãªãã£æªçœ®ã¯ä»¥äžã«é©ãããã®ã§ãªããã°ãªããŸããã
- æè¡ã®çŸç¶(çŸåšã®æè¡)
- å®è£ ã³ã¹ã
- åŠçã®æ§è³ªãç¯å²ãæè
- åäººã®æš©å©ãšèªç±ãžã®ãªã¹ã¯
éèŠãªåå:ç»äžçãªè§£æ±ºçã¯ãããŸãããç¹å®ã®ãªã¹ã¯ãè©äŸ¡ããé©åãªæªçœ®ãå®è£ ããŠãã ããã
ãã®ä»ã®èŠå¶èŠä»¶
CCPA/CPRA: æ å ±ã®æ§è³ªã«é©ãããåççãªã»ãã¥ãªãã£æé ãšæ £è¡ããèŠæ±ããŸãã
å·ã®ããŒã¿äŸµå®³æ³: ç±³åœã®ã»ãšãã©ã®å·ã§ã¯ãåççãªã»ãã¥ãªãã£æªçœ®ãšäŸµå®³éç¥ãå¿ èŠã§ãã
æ¥çæšæº: æ¯æãããŒã¿ã® PCI DSSãå¥åº·ããŒã¿ã® HIPAAãããã³ã»ã¯ã¿ãŒåºæã®èŠä»¶ãé©çšãããå ŽåããããŸãã
æè¡çã»ãã¥ãªãã£æªçœ®
賌èªè ããŒã¿ãä¿è·ããããã«ããããã®æè¡çä¿è·æªçœ®ãå®è£ ããŸãã
æå·å
ä¿åæã®ããŒã¿: ä¿åããã賌èªè ããŒã¿ãæå·åããŸãã
- ããŒã¿ããŒã¹æå·å
- ãã£ã¹ã¯/ããªã¥ãŒã æå·å
- ããã¯ã¢ããæå·å
- ã¢ãŒã«ã€ãæå·å
転éäžã®ããŒã¿: éä¿¡äžã®ããŒã¿ãæå·åããŸãã
- Web ãã©ãã£ãã¯ã® TLS/HTTPS
- æå·åããã API æ¥ç¶
- ã»ãã¥ã¢ãã¡ã€ã«è»¢é
- é©åãªå Žåã®æå·åã¡ãŒã«
æå·åã®ãã¹ããã©ã¯ãã£ã¹:
- çŸåšã®åŒ·åãªã¢ã«ãŽãªãºã ã䜿çš(AES-256)
- æå·åããŒãå®å šã«ç®¡ç
- 宿çã«ããŒãããŒããŒã·ã§ã³
- æå·åãããããŒã¿ãšããŒãäžç·ã«ä¿åããªã
ã¢ã¯ã»ã¹å¶åŸ¡
èªèšŒ:
- 匷åãªãã¹ã¯ãŒãèŠä»¶
- å€èŠçŽ èªèšŒ(MFA)
- é©åãªå Žåã®ã·ã³ã°ã«ãµã€ã³ãªã³(SSO)
- 宿çãªèªèšŒæ å ±ã®ããŒããŒã·ã§ã³
èªå¯:
- ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡(RBAC)
- æå°æš©éã®åå
- è·åã®åé¢
- 宿çãªã¢ã¯ã»ã¹ã¬ãã¥ãŒ
ç£èŠ:
- 賌èªè ããŒã¿ãžã®ãã¹ãŠã®ã¢ã¯ã»ã¹ããã°ã«èšé²
- ç°åžžãªã¢ã¯ã»ã¹ãã¿ãŒã³ã«é¢ããã¢ã©ãŒã
- 宿çãªãã°ã¬ãã¥ãŒ
- ã€ã³ã·ãã³ã調æ»ã®ããã®ãã°ä¿æ
ãããã¯ãŒã¯ã»ãã¥ãªãã£
å¢çé²åŸ¡:
- ãã¡ã€ã¢ãŠã©ãŒã«ãšãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³
- äŸµå ¥æ€ç¥/鲿¢ã·ã¹ãã
- DDoS ä¿è·
- ãªã¢ãŒãã¢ã¯ã»ã¹çšã® VPN
ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£:
- Web ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- å ¥åæ€èšŒ
- SQL ã€ã³ãžã§ã¯ã·ã§ã³é²æ¢
- ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ä¿è·
API ã»ãã¥ãªãã£:
- API èªèšŒãšèªå¯
- ã¬ãŒãå¶é
- å ¥åæ€èšŒ
- ã»ãã¥ã¢ãªããŒç®¡ç
ã¡ãŒã«ãµãŒãã¹ãããã€ããŒã®ã»ãã¥ãªãã£
ãµãŒãããŒãã£ã®ã¡ãŒã«ãã©ãããã©ãŒã ã䜿çšããå Žåã¯ããã®ã»ãã¥ãªãã£ã確èªããŸãã
ãããã€ããŒè©äŸ¡ã®è³ªå:
- ã©ã®ãããªèªèšŒãä¿æããŠããŸãã?(SOC 2ãISO 27001)
- ããŒã¿ã¯ã©ã®ããã«æå·åãããŠããŸãã?
- ããŒã¿ã¯ã©ãã«ä¿åãããŠããŸãã?
- ã©ã®ãããªã¢ã¯ã»ã¹å¶åŸ¡ãååšããŸãã?
- ããã¯ã¢ããã¯ã©ã®ããã«ä¿è·ãããŠããŸãã?
- ã€ã³ã·ãã³ã察å¿ããã»ã¹ã¯äœã§ãã?
å¥çŽäžã®èŠä»¶:
- ããŒã¿åŠçå¥çŽ(DPA)
- ã»ãã¥ãªãã£èŠä»¶
- 䟵害éç¥çŸ©å
- ç£æ»æš©
- ãµãããã»ããµãŒã®éææ§
ã¡ãŒã«æ€èšŒãšããŒã¿å質
æ£ç¢ºãªããŒã¿ãç¶æããããšã¯ã»ãã¥ãªãã£ããµããŒãããŸãã
æ€èšŒãéèŠãªçç±:
- åé¡ã瀺ãå¯èœæ§ã®ããç¡å¹ãªã¢ãã¬ã¹ãåé€
- åœã®ãµã€ã³ã¢ããããã®æ»æé¢ãåæž
- ããŒã¿æ£ç¢ºæ§èŠä»¶ããµããŒã
EmailVerify ã®äœ¿çš: ã¡ãŒã«æ€èšŒã¯ããŒã¿å質ã®ç¶æã«åœ¹ç«ã¡ãŸãã
- ãµã€ã³ã¢ããæã«æ€èšŒããŠäžæ£ãªã¢ãã¬ã¹ããã£ãã
- 宿çãªäžæ¬æ€èšŒã§å£åããããŒã¿ãåé€
- äœ¿ãæšãŠã¡ãŒã«æ€åºã§çããããµã€ã³ã¢ããããããã¯
çµç¹çã»ãã¥ãªãã£æªçœ®
æè¡çæªçœ®ã ãã§ã¯ååã§ã¯ãããŸãããçµç¹çæ £è¡ãåæ§ã«éèŠã§ãã
ããªã·ãŒãšæé
ããŒã¿ä¿è·ããªã·ãŒ: ããŒã¿ä¿è·ãžã®ã¢ãããŒããææžåããŸãã
- ç¯å²ãšç®ç
- 圹å²ãšè²¬ä»»
- ã»ãã¥ãªãã£èŠä»¶
- ã€ã³ã·ãã³ãå¯Ÿå¿æé
- ã¬ãã¥ãŒãšæŽæ°ã¹ã±ãžã¥ãŒã«
å©çšèŠå®ããªã·ãŒ: ã¹ã¿ããã賌èªè ããŒã¿ãã©ã®ããã«æ±ããããå®çŸ©ããŸãã
- èš±å¯ããã䜿çš
- çŠæ¢ãããè¡å
- ããã€ã¹èŠä»¶
- å ±å矩å
ããŒã¿ä¿æããªã·ãŒ: ããŒã¿ãä¿æããæéãæå®ããŸãã
- ããŒã¿ã¿ã€ãå¥ã®ä¿ææé
- å逿é
- äŸå€åŠç
- ã¢ãŒã«ã€ã管ç
ã¹ã¿ãããã¬ãŒãã³ã°
ã»ãã¥ãªãã£æè:
- ãã£ãã·ã³ã°èªè
- ãã¹ã¯ãŒãã»ãã¥ãªãã£
- ããŒã¿åãæ±ãæé
- ã€ã³ã·ãã³ãå ±å
圹å²åºæã®ãã¬ãŒãã³ã°:
- ããŒã±ãã£ã³ã°ããŒã :é©åãªããŒã¿äœ¿çšãåæèŠä»¶
- æè¡ããŒã :ã»ãã¥ãªãã£æ§æãã¢ã¯ã»ã¹ç®¡ç
- 管çè :ç£ç£è²¬ä»»ããªã¹ã¯è©äŸ¡
宿çãªåŸ©ç¿:
- æäœå¹Žæ¬¡ãã¬ãŒãã³ã°
- è åšãå€åãããšãã®æŽæ°
- ãã¹ããšæ€èšŒ
- å®äºã®ææžå
ãã³ããŒç®¡ç
è©äŸ¡ããã»ã¹: ã¡ãŒã«ãµãŒãã¹ãããã€ããŒãããŒã±ãã£ã³ã°ããŒã«ãšå¥çŽããåã«:
- ã»ãã¥ãªãã£ã¢ã³ã±ãŒã
- èªèšŒã¬ãã¥ãŒ
- ãªãã¡ã¬ã³ã¹ãã§ãã¯
- å¥çŽäº€æž
ç¶ç¶çãªç£èŠ:
- 宿çãªã»ãã¥ãªãã£ã¬ãã¥ãŒ
- èªèšŒã®ç¶æ
- ã€ã³ã·ãã³ãéç¥
- ããã©ãŒãã³ã¹ç£èŠ
å¥çŽäžã®ä¿è·:
- ããŒã¿åŠçå¥çŽ
- ã»ãã¥ãªãã£èŠä»¶
- 䟵害éç¥ SLA
- ç£æ»æš©
- ãµãããã»ããµãŒç®¡ç
ã€ã³ã·ãã³ã察å¿
æºå:
- ææžåãããã€ã³ã·ãã³ã察å¿èšç»
- å®çŸ©ããã圹å²ãšè²¬ä»»
- é£çµ¡å ãªã¹ããšãšã¹ã«ã¬ãŒã·ã§ã³ãã¹
- 宿çãªèšç·Žãšãã¹ã
æ€åº:
- ã»ãã¥ãªãã£ã€ãã³ãã®ç£èŠ
- ã¢ã©ãŒããããå€ãšãšã¹ã«ã¬ãŒã·ã§ã³
- ãã°ã¬ãã¥ãŒããã»ã¹
- è åšã€ã³ããªãžã§ã³ã¹ã®çµ±å
察å¿:
- å°ã蟌ãæé
- 調æ»ãããã³ã«
- 蚌æ ã®ä¿å
- ã³ãã¥ãã±ãŒã·ã§ã³ãã³ãã¬ãŒã
埩æ§:
- åŸ©å æé
- æ€èšŒã¹ããã
- éåžžéçšãžã®åŸ©åž°
- ææžå
ã€ã³ã·ãã³ãåŸ:
- æ ¹æ¬åå åæ
- æèš
- ããã»ã¹ã®æ¹å
- å¿ èŠã«å¿ããèŠå¶å ±å
ããŒã¿äŸµå®³å¯Ÿå¿
賌èªè æ å ±ã«åœ±é¿ãäžããããŒã¿äŸµå®³ã«ã¯æ éãªå¯Ÿå¿ãå¿ èŠã§ãã
GDPR 䟵害éç¥
ç£ç£æ©é¢ãž:
- èªèãã 72 æé以å ã«éç¥ããå¿ èŠããããŸã
- 䟵害ãå人ãžã®ãªã¹ã¯ãããããå¯èœæ§ãäœãå Žåãé€ã
- 䟵害ãšè¬ããæªçœ®ã«é¢ãã詳现ãæäŸ
å人ãž:
- äŸµå®³ãæš©å©ãšèªç±ã«å¯Ÿãããé«ããªã¹ã¯ããããããå¯èœæ§ãããå Žåã«å¿ èŠ
- æç¢ºã§å¹³æãªèšèã§ã³ãã¥ãã±ãŒã·ã§ã³
- äŸµå®³ãšæœåšçãªçµæã説æ
- è¬ããæªçœ®ãšæšå¥šãããè¡åã説æ
䟵害察å¿ã¹ããã
ã¹ããã 1:å°ã蟌ã:
- é²è¡äžã®å Žåã¯äŸµå®³ã忢
- 远å ã®ããŒã¿æå€±ãé²ã
- 蚌æ ãä¿å
ã¹ããã 2:è©äŸ¡:
- ã©ã®ããŒã¿ã圱é¿ãåããŸããã?
- äœäººã®å人ã圱é¿ãåããŸããã?
- ã©ã®ã¿ã€ãã®äŸµå®³ã§ãã(æ©å¯æ§ãå®å šæ§ãå¯çšæ§)?
- 圱é¿ã®å¯èœæ§ã¯ã©ã®çšåºŠã§ãã?
ã¹ããã 3:éç¥:
- å¿ èŠã«å¿ããŠèŠå¶åœå±ã«
- é«ããªã¹ã¯ãããå Žåã¯åœ±é¿ãåããå人ã«
- è¡åãåãå¿ èŠãããå Žåã¯ãµãŒãããŒãã£ã«
ã¹ããã 4:修埩:
- è匱æ§ãä¿®æ£
- å¶åŸ¡ã匷å
- æé ãæŽæ°
ã¹ããã 5:ææžå:
- 䟵害ãšå¯Ÿå¿ãèšé²
- èŠå¶ã¬ãã¥ãŒã®ããã«ç¶æ
- æ¹åã«äœ¿çš
äŸµå®³é²æ¢
äžè¬çãªã¡ãŒã«ããŒã±ãã£ã³ã°äŸµå®³ã®åå :
- èªèšŒæ å ±ã®äŸµå®³(ãã£ãã·ã³ã°ã匱ããã¹ã¯ãŒã)
- 誀ã£ãŠæ§æãããã·ã¹ãã (éããŠããããŒã¿ããŒã¹ãAPI ãšã©ãŒ)
- å éšè åš(æªæã®ãããŸãã¯é倱ã«ãã)
- ãµãŒãããŒãã£äŸµå®³(ãã³ããŒäŸµå®³)
鲿¢æªçœ®:
- 匷åãªèªèšŒ(MFA)
- 宿çãªã»ãã¥ãªãã£ãã¹ã
- åŸæ¥å¡ãã¬ãŒãã³ã°
- ãã³ããŒè©äŸ¡
- æ§æç®¡ç
- ã¢ã¯ã»ã¹ç£èŠ
ãã¶ã€ã³ã«ããããŒã¿ä¿è·
æåããã¡ãŒã«ããŒã±ãã£ã³ã°ããã»ã¹ã«ä¿è·ãçµã¿èŸŒã¿ãŸãã
ãã©ã€ãã·ãŒãã€ãã¶ã€ã³ã®åå
äºé²çãäºåŸå¯Ÿå¿çã§ã¯ãªã: åé¡ãçºçããåã«ãã©ã€ãã·ãŒã«å¯ŸåŠããŸãã
ããã©ã«ãã®ä¿è·: ãã©ã€ãã·ãŒãããã©ã«ãèšå®ã§ããããšã確èªããŸãã
ãã¶ã€ã³ã«çµã¿èŸŒãŸããŠãã: ãã©ã€ãã·ãŒãã·ã¹ãã ã«çµã¿èŸŒã¿ãåŸä»ããšããŠã§ã¯ãããŸããã
å®å šãªæ©èœ: æ£ã®åã®ã¢ãããŒã - ãã©ã€ãã·ãŒãšæ©èœã
ãšã³ãããŒãšã³ãã®ã»ãã¥ãªãã£: ããŒã¿ã©ã€ããµã€ã¯ã«å šäœãéããŠä¿è·ããŸãã
éææ§: å®è·µãå¯èŠåãæ€èšŒå¯èœã«ããŸãã
ãŠãŒã¶ãŒäžå¿: ãŠãŒã¶ãŒã®å©çãšèšå®ãå°éããŸãã
ã¡ãŒã«ããŒã±ãã£ã³ã°ãžã®é©çš
åé:
- å¿ èŠãªãã®ã ããåé
- ç®çã«ã€ããŠéææ§ãä¿ã€
- ã»ãã¥ã¢ãªãµã€ã³ã¢ããããã»ã¹ãå®è£
- EmailVerify ã§ã¡ãŒã«ã¢ãã¬ã¹ãæ€èšŒ
ä¿å:
- 賌èªè ããŒã¿ãæå·å
- å¿ èŠãªäººã ãã«ã¢ã¯ã»ã¹ãå¶é
- ä¿æå¶éãå®è£
- ã»ãã¥ã¢ãªããã¯ã¢ãã
䜿çš:
- èšèŒãããç®çã®ããã«ã®ã¿ããŒã¿ã䜿çš
- æ©èœå¥ã«ã¢ã¯ã»ã¹ãã»ã°ã¡ã³ãå
- ããŒã¿ã¢ã¯ã»ã¹ããã°ã«èšé²
- ç°åžžãç£èŠ
å ±æ:
- ãµãŒãããŒãã£ãšã®å ±æãæå°éã«
- ãã³ããŒã培åºçã«å¯©æ»
- ããŒã¿åŠçå¥çŽã䜿çš
- ãã³ããŒã®ã³ã³ãã©ã€ã¢ã³ã¹ãç£èŠ
åé€:
- ä¿æã¹ã±ãžã¥ãŒã«ãå®è£
- åé€ãªã¯ãšã¹ãã«è¿ éã«å¯Ÿå¿
- åé€ã®å®äºã確èª
- æå¶ãªã¹ããç¶æ
ã¡ãŒã«ããŒã±ãã£ã³ã°ã®ã»ãã¥ãªãã£ãã§ãã¯ãªã¹ã
ãã®ãã§ãã¯ãªã¹ãã䜿çšããŠãã¡ãŒã«ããŒã¿ä¿è·ãè©äŸ¡ããŸãã
æè¡çå¶åŸ¡
æå·å:
- [ ] ä¿åæã®è³Œèªè ããŒã¿ããŒã¹ãæå·åãããŠãã
- [ ] ããã¯ã¢ãããæå·åãããŠãã
- [ ] ãã¹ãŠã® Web ãã©ãã£ãã¯ã HTTPS çµç±
- [ ] API æ¥ç¶ãæå·åãããŠãã
ã¢ã¯ã»ã¹ç®¡ç:
- [ ] å€èŠçŽ èªèšŒãå¿ èŠ
- [ ] ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹ãå®è£ ãããŠãã
- [ ] 宿çãªã¢ã¯ã»ã¹ã¬ãã¥ãŒã宿œãããŠãã
- [ ] éè·ããåŸæ¥å¡ã®ã¢ã¯ã»ã¹ãè¿ éã«åé€ãããŠãã
ç£èŠ:
- [ ] ã¢ã¯ã»ã¹ãã°ãæå¹
- [ ] ç°åžžãªã¢ã¯ãã£ããã£ã¢ã©ãŒããæ§æãããŠãã
- [ ] ãã°ä¿æãé©å
- [ ] 宿çãªãã°ã¬ãã¥ãŒããã»ã¹
ã€ã³ãã©ã¹ãã©ã¯ãã£:
- [ ] ãã¡ã€ã¢ãŠã©ãŒã«ãé©åã«æ§æãããŠãã
- [ ] ã·ã¹ãã ã宿çã«ããããããŠãã
- [ ] è匱æ§ã¹ãã£ã³ã宿œãããŠãã
- [ ] ãããã¬ãŒã·ã§ã³ãã¹ãã宿œãããŠãã
çµç¹çå¶åŸ¡
ããªã·ãŒ:
- [ ] ããŒã¿ä¿è·ããªã·ãŒãææžåãããŠãã
- [ ] å©çšèŠå®ããªã·ãŒãæŽã£ãŠãã
- [ ] ä¿æããªã·ãŒãå®çŸ©ãããŠãã
- [ ] ã€ã³ã·ãã³ã察å¿èšç»ãææžåãããŠãã
ãã¬ãŒãã³ã°:
- [ ] ã»ãã¥ãªãã£æèãã¬ãŒãã³ã°ã宿œãããŠãã
- [ ] 圹å²åºæã®ãã¬ãŒãã³ã°ãæäŸãããŠãã
- [ ] ãã¬ãŒãã³ã°å®äºã远跡ãããŠãã
- [ ] 宿çãªåŸ©ç¿ãã¬ãŒãã³ã°
ãã³ããŒ:
- [ ] ESP ã»ãã¥ãªãã£ãè©äŸ¡ãããŠãã
- [ ] ããŒã¿åŠçå¥çŽãæŽã£ãŠãã
- [ ] ç¶ç¶çãªç£èŠã宿œãããŠãã
- [ ] ãµãããã»ããµãŒãææžåãããŠãã
ã³ã³ãã©ã€ã¢ã³ã¹
GDPR:
- [ ] 第 32 æ¡ã®èŠä»¶ã«å¯ŸåŠãããŠãã
- [ ] ããŒã¿ä¿è·åœ±é¿è©äŸ¡ã宿œãããŠãã
- [ ] åŠçèšé²ãç¶æãããŠãã
- [ ] DPO ãä»»åœãããŠãã(å¿ èŠãªå Žå)
䟵害æºå:
- [ ] ã€ã³ã·ãã³ã察å¿èšç»ããã¹ããããŠãã
- [ ] éç¥ãã³ãã¬ãŒããæºåãããŠãã
- [ ] é£çµ¡å ãªã¹ããææ°
- [ ] 72 æéã®èœåãæ€èšŒãããŠãã
ã¡ãŒã«ãµãŒãã¹ãããã€ããŒãšã®åå
ESP ã¯ããŒã¿ä¿è·ã«ãããéèŠãªããŒãããŒã§ãã
ã»ãã¥ãªãã£è©äŸ¡åºæº
èªèšŒ:
- SOC 2 Type II
- ISO 27001
- GDPR ã³ã³ãã©ã€ã¢ã³ã¹èšŒæ
- æ¥çåºæ(HIPAAãPCI)
ããŒã¿åãæ±ã:
- ããŒã¿ã¯ã©ãã«ä¿åãããŠããŸãã?
- ã©ã®ããã«æå·åãããŠããŸãã?
- ã©ã®ãããªä¿æãé©çšãããŸãã?
- ã©ã®ããã«åé€ãããŸãã?
ã¢ã¯ã»ã¹å¶åŸ¡:
- ã¢ã¯ã»ã¹ã¯ã©ã®ããã«ç®¡çãããŠããŸãã?
- MFA ã¯å©çšå¯èœ/å¿ é ã§ãã?
- ç£æ»æ©èœã¯äœã§ãã?
- ç¹æš©ã¢ã¯ã»ã¹ã¯ã©ã®ããã«å¶åŸ¡ãããŠããŸãã?
ã€ã³ã·ãã³ã察å¿:
- 䟵害éç¥ SLA ã¯äœã§ãã?
- 顧客ã«ã¯ã©ã®ããã«éç¥ãããŸãã?
- ã©ã®ãããªãµããŒããæäŸãããŸãã?
- å®çžŸã¯ã©ãã§ãã?
ããŒã¿åŠçå¥çŽ
GDPR ã®äžã§å¿ èŠãªèŠçŽ :
- äž»é¡ãšæé
- åŠçã®æ§è³ªãšç®ç
- å人ããŒã¿ã®ã¿ã€ã
- ããŒã¿äž»äœã®ã«ããŽãª
- 管çè ã®çŸ©åãšæš©å©
- åŠçè ã®ã»ãã¥ãªãã£çŸ©å
- ãµãããã»ããµãŒèŠä»¶
- ç£æ»æš©
- åé€/è¿åŽèŠä»¶
- 䟵害éç¥
ESP ã«å°ããã¹ã質å
- 賌èªè ããŒã¿ã¯ã©ãã«ä¿åãããŠããŸãã(å°ççäœçœ®)?
- ä¿åæããã³è»¢éäžã®ããŒã¿ã«ã©ã®ãããªæå·åã䜿çšãããŠããŸãã?
- 顧客ããŒã¿ãžã®ã¢ã¯ã»ã¹ã¯ã©ã®ããã«å¶åŸ¡ãããŠããŸãã?
- ã©ã®ãããªèªèšŒãç¶æããŠããŸãã?
- ããã¯ã¢ããã¯ã©ã®ããã«ä¿è·ãããŠããŸãã?
- ã€ã³ã·ãã³ã察å¿ããã»ã¹ã¯äœã§ãã?
- 䟵害ãã©ã®ãããè¿ éã«éç¥ãããŸãã?
- ãµãŒãã¹ããã£ã³ã»ã«ãããšããŒã¿ã¯ã©ããªããŸãã?
- ãµãããã»ããµãŒã¯èª°ã§ãã?
- ã»ãã¥ãªãã£ç£æ»ã宿œã§ããŸãã?
ç°ãªã賌èªè ã»ã°ã¡ã³ãã®ããŒã¿ä¿è·
ç¹å®ã®ããŒã¿ã¿ã€ãã«å¯Ÿãã远å ã®ä¿è·ãæ€èšããŠãã ããã
EU 賌èªè ããŒã¿
GDPR ã®äžã§ã¯ã远å ã®èŠä»¶ãé©çšãããŸãã
- åæ³çæ ¹æ ã®ææžå
- ããŒã¿äž»äœã®æš©å©ã®å±¥è¡
- åœå¢ãè¶ãã転éã®ä¿è·æªçœ®
- é«ãªã¹ã¯åŠçã®ããã®ããŒã¿ä¿è·åœ±é¿è©äŸ¡
ã«ãªãã©ã«ãã¢å± äœè ããŒã¿
CCPA/CPRA ã®äžã§:
- åççãªã»ãã¥ãªãã£æªçœ®
- åé€ãªã¯ãšã¹ãã®å±¥è¡
- 販売/å ±æã®ãªããã¢ãŠã
- 䟵害ã«å¯Ÿããç§ç蚎暩
æ©å¯æ§ã®é«ãæ¥ç
ãã«ã¹ã±ã¢:
- 該åœããå Žåã® HIPAA èŠä»¶
- å¥åº·é¢é£ããŒã±ãã£ã³ã°ã«çްå¿ã®æ³šæ
- ããžãã¹ã¢ãœã·ãšã€ãå¥çŽ
éèãµãŒãã¹:
- GLBA èŠä»¶
- å·ã®éèãã©ã€ãã·ãŒæ³
- 匷åãããã»ãã¥ãªãã£æåŸ
æè²:
- FERPA ã®èæ ®äºé
- åŠçããŒã¿ä¿è·
- 芪/ä¿è·è ã®åæ
çµè«
ã¡ãŒã«ããŒã¿ä¿è·ã¯ãæè¡çä¿è·æªçœ®ãšçµç¹çæ £è¡ã®äž¡æ¹ãå¿ èŠãšããç¶ç¶çãªè²¬ä»»ã§ããé©åãªæªçœ®ãå®è£ ããããšã§ã賌èªè ãä¿è·ããèŠå¶ã«æºæ ããé·æçãªã¡ãŒã«ããŒã±ãã£ã³ã°ã®æåãæ¯ããä¿¡é Œãæ§ç¯ããŸãã
éèŠãªãã€ã³ã:
ãªã¹ã¯ããŒã¹ã®ã¢ãããŒã:åŠçãçã¿åºããªã¹ã¯ã«æ¯äŸããã»ãã¥ãªãã£æªçœ®ãå®è£ ããŸãã
æè¡çããã³çµç¹ç:äž¡æ¹ã®ã¿ã€ãã®æªçœ®ãå¿ èŠã§ããæå·åã ãã§ã¯é©åãªããªã·ãŒãšãã¬ãŒãã³ã°ãªãã«ã¯ååã§ã¯ãããŸããã
ãã³ããŒç®¡ç:ESP ããã³ãã®ä»ã®ããŒã«ã¯ã»ãã¥ãªãã£æ å¢ã®äžéšã§ããè©äŸ¡ãšç£èŠãè¡ããŸãã
䟵害æºå:ã€ã³ã·ãã³ã察å¿èšç»ãæºåããŠãã ãããå¿ èŠã«ãªãåã«ãã¹ãããŠãã ããã
ç¶ç¶çæ¹å:ã»ãã¥ãªãã£ã¯äžåéãã®ãããžã§ã¯ãã§ã¯ãããŸããã宿çãªã¬ãã¥ãŒãšæŽæ°ãäžå¯æ¬ ã§ãã
ããŒã¿å質:ããŒã¿ä¿è·æŠç¥ã®äžç°ãšããŠã¡ãŒã«æ€èšŒã§æ£ç¢ºãªããŒã¿ãç¶æããŸãã
ææžå:æªçœ®ãææžåããã³ã³ãã©ã€ã¢ã³ã¹å®èšŒã®ããã«èšé²ãä¿æããŸãã
ããŒã¿ä¿è·ã¯çœ°åãåé¿ããã ãã§ã¯ãªãã賌èªè ãå人æ å ±ãå ±æããéã«ããªãã«å¯ããä¿¡é Œãå°éããããšã§ããããšãå¿ããªãã§ãã ãããä¿è·ãåªå ããçµç¹ã¯ããã匷åã§æç¶å¯èœãªã¡ãŒã«ããŒã±ãã£ã³ã°ããã°ã©ã ãæ§ç¯ããŸãã
ã¡ãŒã«ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ããå æ¬çãªã¬ã€ãã³ã¹ã«ã€ããŠã¯ãå®å šãªã¡ãŒã«ã³ã³ãã©ã€ã¢ã³ã¹ã¬ã€ããã芧ãã ãããEmailVerify ã®ã¡ãŒã«æ€èšŒãµãŒãã¹ã§æ£ç¢ºãªè³Œèªè ãªã¹ããç¶æããŠãã ããã