指針・原則NIST SP 800-207NCSC Zero Trust Architecture Design Principles
データ中心型セ
キュリティ
1. すべてのデータソースとコン
ピューティングサービスはリソー
スとして扱う
1. アーキテクチャ(ユーザ、端末、サービス、
データ)を把握する
2. ユーザ、サービス、端末のアイデンティティを
把握する
「信頼せず、常に
検証する」
アイデンティティ
検証+アクセス制
御+最小権限原則
+マイクロセグメ
ンテーション
3. 個々の組織リソースへのアクセス
は、セッション単位で付与する
4. リソースへのアクセスは、クライ
アントの属性、アプリケーション
やサービス、要求元の資産の観測
可能なデータを含む動的ポリシー
によって決定され、その他の行動
特性や環境要因も含まれる場合が
ある
5. すべてのリソースの認証・認可は
動的に行われ、アクセスが許可さ
れる前に厳格に適用する
4. ポリシーに基づきリクエストを認可する
5. 認証と認可をあらゆる場面で実施する
あらゆる場所で
のデータ保護
2. すべての通信はネットワークの種
類に関係なく保護する
7. どのネットワークも信頼しない(自分自身の
ネットワークも例外ではない)
「Assume breach」
と継続的監視
5. 組織は、所有するすべての資産お
よび関連資産の完全性とセキュリ
ティ態勢を監視し、測定する
6. 組織は、資産、ネットワークイン
フラストラクチ ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month, and much more.
O’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
I wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
I’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
I'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.