ãã®ããŒãžã§ã¯ãGoogle Cloud ã³ã³ãœãŒã«ã® Security Command Center ã®æŠèŠãšãSecurity Command Center ã®æäžäœããŒãžã§ã§ããããšã«ã€ããŠèª¬æããŸãã
çµç¹ãŸãã¯çµç¹å ã®ãããžã§ã¯ãã« Security Command Center ããŸã èšå®ãããŠããªãå Žåã¯ãGoogle Cloud ã³ã³ãœãŒã«ã§ Security Command Center ã䜿çšããåã«ãæå¹ã«ããå¿ èŠããããŸããæå¹åã®è©³çްã«ã€ããŠã¯ãSecurity Command Center ã®æå¹åã®æŠèŠãã芧ãã ããã
Security Command Center ã®æŠèŠã«ã€ããŠã¯ãSecurity Command Center ã®æŠèŠãã芧ãã ããã
å¿ èŠãª IAM æš©é
Security Command Center ã䜿çšããã«ã¯ãé©åãªæš©éãå«ã Identity and Access ManagementïŒIAMïŒããŒã«ãå¿ èŠã§ãã
- ã»ãã¥ãªã㣠ã»ã³ã¿ãŒç®¡çé²èЧè ã¯ãSecurity Command Center ã衚瀺ã§ããŸãã
- ã»ãã¥ãªã㣠ã»ã³ã¿ãŒç®¡çç·šéè ã¯ãSecurity Command Center ã衚瀺ããŠå€æŽãè¡ãããšãã§ããŸãã
çµç¹ã®ããªã·ãŒããã¡ã€ã³ããšã« ID ãå¶éããããã«èšå®ãããŠããå Žåã¯ãèš±å¯ããããã¡ã€ã³ã®ã¢ã«ãŠã³ãã§ Google Cloud ã³ã³ãœãŒã«ã«ãã°ã€ã³ããå¿ èŠããããŸãã
Security Command Center ã® IAM ããŒã«ã¯ãçµç¹ã¬ãã«ããã©ã«ãã¬ãã«ããŸãã¯ãããžã§ã¯ã ã¬ãã«ã§ä»äžã§ããŸããæ€åºçµæãã¢ã»ãããã»ãã¥ãªã㣠ãœãŒã¹ã衚瀺ãç·šéãäœæãæŽæ°ããæš©éã¯ãã¢ã¯ã»ã¹æš©ãä»äžãããŠããã¬ãã«ã«ãã£ãŠç°ãªããŸããSecurity Command Center ã®ããŒã«ã®è©³çްã«ã€ããŠã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãã芧ãã ããã
Google Cloud ã³ã³ãœãŒã«ã§ Security Command Center ã«ã¢ã¯ã»ã¹ãã
Google Cloud ã³ã³ãœãŒã«ã§ Security Command Center ã«ã¢ã¯ã»ã¹ããã«ã¯:
Security Command Center ã«ç§»åããŸãã
衚瀺ãããããžã§ã¯ããŸãã¯çµç¹ãéžæããŸãã
éžæããçµç¹ãŸãã¯ãããžã§ã¯ãã§ Security Command Center ãã¢ã¯ãã£ããªå Žåã¯ã[ãªã¹ã¯æŠèŠ] ããŒãžãéããæ°ããè åšã®æ€åºã®æŠèŠãšãéå» 7 æ¥éã«ç¢ºèªãããæªå¯Ÿå¿ã®è匱æ§ã®æ€åºçµæã衚瀺ãããŸãã
Security Command Center ãæå¹ã«ãªã£ãŠããªãå Žåã¯ãæå¹ã«ããããã«æç€ºãããŸããSecurity Command Center ã®æå¹åã®è©³çްã«ã€ããŠã¯ãSecurity Command Center ã®æå¹åã®æŠèŠãã芧ãã ããã
Google Cloud ã³ã³ãœãŒã«ã§ã® Security Command Center
ãªã¹ã¯æŠèŠããŒãžã®ã»ãã«ãGoogle Cloud ã³ã³ãœãŒã«ã®æ¬¡ã® Security Command Center ããŒãžã§ã Google Cloud ç°å¢ã®ã»ãã¥ãªãã£ã®åé¡ãã¢ãã¿ãªã³ã°ãã管çã§ããŸããããŒãžåãã¯ãªãã¯ãããšãããŒãžã®èª¬æã衚瀺ãããŸãã
- [ãªã¹ã¯ã®æŠèŠ] ããŒãž
- [è åš] ããŒãž
- [è匱æ§] ããŒãž
- [ã³ã³ãã©ã€ã¢ã³ã¹] ããŒãž
- [ã¢ã»ãã] ããŒãž
- [æ€åºçµæ] ããŒãž
- [ãœãŒã¹] ããŒãž
- äœå¶ããŒãž
[ãªã¹ã¯ã®æŠèŠ] ããŒãž
[ãªã¹ã¯æŠèŠ] ããŒãžã§ã¯ããã¹ãŠã®çµã¿èŸŒã¿ãµãŒãã¹ãšçµ±åãµãŒãã¹ãããæ°ããè åšãšGoogle Cloud ç°å¢ã«ååšããæªå¯Ÿå¿ã®è匱æ§ã®ç·æ°ãç°¡åã«ç¢ºèªã§ããŸãããã®ããŒãžã®ãã¹ãŠã®é åã«è¡šç€ºãããæé㯠1 æéãã 6 ãæã®éã§å€æŽã§ããŸãã
[ãªã¹ã¯ã®æŠèŠ] ããŒãžã«ã¯ã次ã®ãããªããŸããŸãªããã·ã¥ããŒãã衚瀺ãããŸãã
- [äžäœã®è匱æ§ã®æ€åºçµæ] ã«ã¯ãæ»æã®çºçå¯èœæ§ã¹ã³ã¢ãæãé«ã 10 ä»¶ã®æ€åºçµæã衚瀺ãããŸãã
- [æ°ããªè åšã®ä»¶æ°ã®æšç§»] ã«ã¯ã1 æ¥ã«æ€åºãããæ°ããè åšã®ã°ã©ããšã1 æéããšã®åèšæ°ã衚瀺ãããŸããããŒãžã®ã°ã©ãã«åãããŠãã«ããŽãªããªãœãŒã¹ããããžã§ã¯ãããšã«è åšã®æ€åºçµæã衚瀺ãããŸããåãã¥ãŒã¯ãé倧床ã§äžŠã¹æ¿ããããšãã§ããŸãã
- [äžäœã® CVE ã®æ€åºçµæ]ïŒPremium ãš Enterprise ãã£ã¢ã®ã¿ïŒã«ã¯ãCVE ã®æªçšå¯èœæ§ãšåœ±é¿å¥ã«ã°ã«ãŒãåãããè匱æ§ã®æ€åºçµæã衚瀺ãããŸããããŒããããå ã®ãããã¯ãã¯ãªãã¯ãããšã察å¿ããæ€åºçµæã CVE ID å¥ã«è¡šç€ºãããŸãã
- [ãªãœãŒã¹ã¿ã€ãå¥ã®è匱æ§] ã«ã¯ããããžã§ã¯ããŸãã¯çµç¹å ã®ãªãœãŒã¹ã«å¯Ÿããæªå¯Ÿå¿ã®è匱æ§ãã°ã©ãã§è¡šç€ºãããŸãã
- [æªå¯Ÿå¿ã®è匱æ§] ã«ã¯ãè匱æ§ã®æ€åºçµæãã«ããŽãªåã圱é¿ãåãããªãœãŒã¹ããããžã§ã¯ãå¥ã«è¡šåœ¢åŒã§è¡šç€ºãããŸããåãã¥ãŒã¯ãé倧床ã§äžŠã¹æ¿ããããšãã§ããŸãã
- [ID ãšã¢ã¯ã»ã¹ã®æ€åº] ã«ã¯ã誀ã£ãŠæ§æãããŠããããŸã㯠Google Cloud ãªãœãŒã¹ããã㯠AWS ãªãœãŒã¹ïŒaccessïŒã«å¯ŸããŠéå°ã§ãããæ©å¯æ§ã®é«ãæš©éãä»äžãããããªã³ã·ãã« ã¢ã«ãŠã³ãïŒidentitiesïŒã«é¢é£ããæ§æãã¹ã®æ€åºçµæã衚瀺ãããŸããID ãšã¢ã¯ã»ã¹å¶åŸ¡ã®ç®¡çã¯ãã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£è³æ Œç®¡çãšåŒã°ããããšããããŸãã
- [ããŒã¿ ã»ãã¥ãªãã£ã«é¢ããæ€åºçµæ] ã«ã¯ãSensitive Data Protection æ€åºãµãŒãã¹ããã®æ€åºçµæã衚瀺ãããŸãããã®æŠèŠã«ã¯ãç°å¢å€æ°ã®ã·ãŒã¯ã¬ããã®ååšã瀺ãè匱æ§ã®æ€åºçµæãšãããŒã¿ã®æ©å¯æ§ãšããŒã¿ãªã¹ã¯ ã¬ãã«ã瀺ã芳å¯çµæãå«ãŸããŸãã
[ãªã¹ã¯æŠèŠ] ããŒãžã§æ€åºçµæã®ã«ããŽãªåãã¯ãªãã¯ãããšã[æ€åºçµæ] ããŒãžã衚瀺ãããæ€åºçµæã®è©³çްã確èªã§ããŸãã
è åšããŒãž
[è åš] ããŒãžã§ã¯ãæå®ããæéäžã« Google Cloud ãªãœãŒã¹ã«ååšããå¯èœæ§ãããæå®³ãªã€ãã³ãã確èªã§ããŸããããã©ã«ãã®æé㯠7 æ¥éã§ãã
[è åš] ããŒãžã§ã¯ãæ€åºçµæã次ã®ã»ã¯ã·ã§ã³ã§ç¢ºèªã§ããŸãã
- [é倧床ããšã®è åš] ã«ã¯ãè åšã®æ°ãé倧床ããšã«è¡šç€ºãããŸãã
- [ã«ããŽãªå¥ã®è åš] ã«ã¯ããã¹ãŠã®ãããžã§ã¯ãã®æ€åºçµæã®æ°ãã«ããŽãªå¥ã«è¡šç€ºãããŸãã
- [ãªãœãŒã¹ããšã®è åš] ã«ã¯ããããžã§ã¯ããŸãã¯çµç¹å ã®ãªãœãŒã¹ããšã«æ€åºçµæã®æ°ã衚瀺ãããŸãã
è åšã衚瀺ããæéãæå®ããã«ã¯ã[æé] ãã£ãŒã«ãã®ãã«ããŠã³ ãªã¹ãã䜿çšããŸãããã«ããŠã³ ãªã¹ãã«ã¯ 1 æéãã [å šæé] ãŸã§è€æ°ã®ãªãã·ã§ã³ã衚瀺ãããŸãã[å šæé] ãéžæãããšããµãŒãã¹ãæå¹ã«ããæç¹ããã®ãã¹ãŠã®æ€åºçµæã衚瀺ãããŸããéžæããæéã¯ã»ãã·ã§ã³éã§ä¿åãããŸãã
è匱æ§ããŒãž
[è匱æ§] ããŒãžã«ã¯ãSecurity Command Center ã®çµã¿èŸŒã¿æ€åºãµãŒãã¹ãã¯ã©ãŠãç°å¢ã§å®è¡ããæ§æãã¹ãšãœãããŠã§ã¢ã®è匱æ§ã®æ€åºæ©èœããã¹ãŠäžèŠ§è¡šç€ºãããŸããäžèŠ§è¡šç€ºãããããããã®æ€åºæ©èœã«ã€ããŠãã¢ã¯ãã£ããªæ€åºçµæã®æ°ã衚瀺ãããŸãã
èåŒ±æ§æ€åºãµãŒãã¹
[è匱æ§] ããŒãžã«ã¯ãSecurity Command Center ã®æ¬¡ã®çµã¿èŸŒã¿æ€åºãµãŒãã¹ã®æ€åºæ©èœãäžèŠ§è¡šç€ºãããŸãã
- ã»ãã¥ãªãã£åæã®ç¶æ³
- ã¢ããŸã³ ãŠã§ã ãµãŒãã¹ïŒAWSïŒã®è匱æ§è©äŸ¡
- Web Security Scanner
Security Command Center ãšçµ±åãããŠããä»ã® Google Cloud ãµãŒãã¹ãããœãããŠã§ã¢ã®è匱æ§ãšæ§æãã¹ãæ€åºããŸãããããã®ãµãŒãã¹ã®æ€åºçµæã¯ã[è匱æ§] ããŒãžã«ã衚瀺ãããŸããSecurity Command Center ã§è匱æ§ã®æ€åºçµæãçæãããµãŒãã¹ã®è©³çްã«ã€ããŠã¯ãæ€åºãµãŒãã¹ãã芧ãã ããã
èåŒ±æ§æ€åºæ©èœã®ã«ããŽãªã«é¢ããæ å ±
[è匱æ§] ããŒãžã«ã¯ãæ§æãã¹ãŸãã¯ãœãããŠã§ã¢ã®èåŒ±æ§æ€åºæ©èœããšã«æ¬¡ã®æ å ±ã衚瀺ãããŸãã
- ã¹ããŒã¿ã¹: æ€åºæ©èœãæå¹ãã©ããã察åŠã®å¿ èŠãããæ€åºçµæãæ€åºããããã©ããã瀺ãã¢ã€ã³ã³ã衚瀺ãããŸããã¹ããŒã¿ã¹ ã¢ã€ã³ã³ã®äžã«ãã€ã³ã¿ã眮ããšãçµæãæ€åºããæ¥æããŸãã¯æšå¥šäºé ãæ€èšŒããæ¹æ³ã«é¢ããæ å ±ãããŒã«ãããã«è¡šç€ºãããŸãã
- ååã®ã¹ãã£ã³æ¥æ: æ€åºæ©èœãæåŸã«ã¹ãã£ã³ãè¡ã£ãæ¥æã
- ã«ããŽãª: è匱æ§ã®ã«ããŽãªãŸãã¯ã¿ã€ããå Security Command Center ãµãŒãã¹ãæ€åºããã«ããŽãªã®ãªã¹ãã«ã€ããŠã¯ã以äžãã芧ãã ããã
- æšå¥š: æ€åºçµæã®ä¿®æ£æ¹æ³ã®æŠèŠã詳现ã«ã€ããŠã¯ãSecurity Health Analytics ã®æ€åºçµæã®ä¿®æ£ãã芧ãã ããã
- æå¹: ã«ããŽãªã®æ€åºçµæã®åèšæ°ã
- æšæº: æ€åºçµæã«ããŽãªãé©çšãããã³ã³ãã©ã€ã¢ã³ã¹ ãã³ãããŒã¯ïŒè©²åœããå ŽåïŒããã³ãããŒã¯ã®è©³çްã«ã€ããŠã¯ãè匱æ§ã®æ€åºçµæãã芧ãã ããã
è匱æ§ã®æ€åºçµæã®ãã£ã«ã¿ãªã³ã°
å€§èŠæš¡ãªçµç¹ã§ã¯ããããã€ã¡ã³ãå šäœã§ç¢ºèªãåªå é äœä»ãã远跡ãå¿ èŠãªè匱æ§ã®æ€åºçµæã倧éã«è¡šç€ºãããå ŽåããããŸããGoogle Cloud ã³ã³ãœãŒã«ã® Security Command Center ã® [è匱æ§] ããŒãžãš [æ€åº] ããŒãžã§å©çšå¯èœãªãã£ã«ã¿ã䜿çšããŠãçµç¹å šäœã§æãé倧床ã®é«ãè匱æ§ã«éç¹ã眮ããã¢ã»ããã®ã¿ã€ãããããžã§ã¯ãããšã«è匱æ§ã確èªã§ããŸãã
è匱æ§ã®æ€åºçµæã®ãã£ã«ã¿ãªã³ã°ã®è©³çްã«ã€ããŠã¯ãSecurity Command Center ã§è匱æ§ã®æ€åºçµæããã£ã«ã¿ãããã芧ãã ããã
ã³ã³ãã©ã€ã¢ã³ã¹ ããŒãž
[ã³ã³ãã©ã€ã¢ã³ã¹] ããŒãžã䜿çšãããšãäžè¬çãªã»ãã¥ãªãã£æšæºããã³ãããŒã¯ã®éµå®ç¶æ³ãè©äŸ¡ããŠå¯ŸåŠã§ããŸãããã®ããŒãžã«ã¯ãSecurity Command Center ã§ãµããŒããããŠãããã¹ãŠã®ãã³ãããŒã¯ãšããã³ãããŒã¯ ã³ã³ãããŒã«ã«åæ Œããå²åã衚瀺ãããŸãã
åãã³ãããŒã¯ã® [ã³ã³ãã©ã€ã¢ã³ã¹ã®è©³çް] ããŒãžãéããŠãSecurity Command Center ããã³ãããŒã¯ã§ãã§ãã¯ããã³ã³ãããŒã«ãåã³ã³ãããŒã«ã§æ€åºãããéåã®æ°ããã³ãããŒã¯ã®ã³ã³ãã©ã€ã¢ã³ã¹ ã¬ããŒãããšã¯ã¹ããŒããããªãã·ã§ã³ã«é¢ããŠããã«è©³çްã«ç¢ºèªã§ããŸãã
Security Command Center ã®è匱æ§ã¹ãã£ãã¯ãGoogle ãæäŸãããã¹ã ãšãã©ãŒã ãããã³ã°ã«åºã¥ããŠãäžè¬çãªã³ã³ãã©ã€ã¢ã³ã¹ ã³ã³ãããŒã«ã®éåãã¢ãã¿ãªã³ã°ããŸããSecurity Command Center ã®ã³ã³ãã©ã€ã¢ã³ã¹ ã¬ããŒãã¯ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ã«ä»£ãããã®ã§ã¯ãããŸããããã³ã³ãã©ã€ã¢ã³ã¹ ã¹ããŒã¿ã¹ãç¶æãšæ©æã®é忀åºã«åœ¹ç«ã¡ãŸãã
Security Command Center ãã³ã³ãã©ã€ã¢ã³ã¹ç®¡çããµããŒãããæ¹æ³ã®è©³çްã«ã€ããŠã¯ã次ã®ããŒãžãã芧ãã ããã
ã¢ã»ããããŒãž
[ã¢ã»ãã] ããŒãžã«ã¯ããããžã§ã¯ããŸãã¯çµç¹å ã®ãã¹ãŠã®Google Cloud ãªãœãŒã¹ïŒã¢ã»ãããšãåŒã°ããŸãïŒã®è©³çްã衚瀺ãããŸãã
[ã¢ã»ãã] ããŒãžã§ã¢ã»ãããæäœããæ¹æ³ã«ã€ããŠã¯ãã³ã³ãœãŒã«ã§ãªãœãŒã¹ãæäœãããã芧ãã ããã
æ€åºçµæããŒãž
[æ€åºçµæ] ããŒãžã§ã¯ãSecurity Command Center ã®æ€åºçµæïŒSecurity Command Center ãµãŒãã¹ãç°å¢å ã®ã»ãã¥ãªãã£åé¡ãæ€åºããéã«äœæããã¬ã³ãŒãïŒã®ã¯ãšãªãã¬ãã¥ãŒããã¥ãŒããããŒã¯ãè¡ãããšãã§ããŸãã
[æ€åºçµæ] ããŒãžã§æ€åºçµæãæäœããæ¹æ³ã«ã€ããŠã¯ãæ€åºçµæã確èªããŠç®¡çãããã芧ãã ããã
ãœãŒã¹ããŒãž
[ãœãŒã¹] ããŒãžã«ã¯ãæå¹ã«ããã»ãã¥ãªã㣠ãœãŒã¹ã®ã¢ã»ãããšæ€åºçµæã®æŠèŠã瀺ãã«ãŒãã衚瀺ãããŸããã»ãã¥ãªã㣠ãœãŒã¹ã®ã«ãŒãã«ã¯ããã®ãœãŒã¹ã®æ€åºçµæã®äžéšã衚瀺ãããŸããæ€åºã«ããŽãªåãã¯ãªãã¯ãããšããã®ã«ããŽãªã®ãã¹ãŠã®æ€åºçµæã衚瀺ã§ããŸãã
æ€åºã®æŠèŠ
[æ€åºã®æŠèŠ] ã«ãŒãã«ã¯ãæå¹ã«ãªã£ãŠããã»ãã¥ãªã㣠ãœãŒã¹ããæäŸãããæ€åºçµæã®åã«ããŽãªã®æ°ã衚瀺ãããŸãã
- ç¹å®ã®ãœãŒã¹ããã®æ€åºçµæã®è©³çްã衚瀺ããã«ã¯ããœãŒã¹åãã¯ãªãã¯ããŸãã
- ãã¹ãŠã®æ€åºçµæã®è©³çްã衚瀺ããã«ã¯ã[æ€åºçµæ] ããŒãžãã¯ãªãã¯ããŸããããã§ãæ€åºçµæãã°ã«ãŒãåããããåã ã®æ€åºçµæã®è©³çްã衚瀺ã§ããŸãã
ãœãŒã¹ã®æŠèŠ
[æ€åºã®æŠèŠ] ã«ãŒãã®äžã«ãæå¹ã«ãªã£ãŠããçµã¿èŸŒã¿ãœãŒã¹ãçµ±åãœãŒã¹ããµãŒãããŒã㣠ãœãŒã¹ã®ã«ãŒãã衚瀺ãããŸããåã«ãŒãã«ã¯ããã®ãœãŒã¹ã§æå¹ãªæ€åºçµæã®æ°ã衚瀺ãããŸãã
äœå¶ããŒãž
[äœå¶] ããŒãžã§ã¯ãçµç¹ã§äœæããã»ãã¥ãªãã£äœå¶ã®è©³çްã衚瀺ãããã®äœå¶ãçµç¹ããã©ã«ããŸãã¯ãããžã§ã¯ãã«é©çšã§ããŸãã䜿çšå¯èœãªäºåå®çŸ©ããã察çãã³ãã¬ãŒãã衚瀺ã§ããŸãã
次ã®ã¹ããã
- æ€åºãµãŒãã¹ã«ã€ããŠç¢ºèªããã
- ã»ãã¥ãªã㣠ããŒã¯ã®äœ¿ç𿹿³ã確èªããã
- Security Command Center ãæ§æããæ¹æ³ãåŠç¿ããã