Similar documents
Information Security Management System ISO/IEC 27001:2005 ISMS A Copyright JIPDEC ISMS,


Information Security Management System ISMS Copyright JIPDEC ISMS,

untitled

1

納品_ jim_ver099a _3_.docx

Copyright

2006/6/ /9/1 2007/11/9 () 2011/4/ ( ()) ii


untitled

帝国議会の運営と会議録をめぐって

独 立 行 政 法 人 情 報 処 理 推 進 機 構 2

untitled


untitled

スライド 0

野田市ホームページCMS導入・運用業務仕様書


u u u 1 1

Microsoft Word - 教材ガイド一覧ビデオ.doc

内閣官房情報セキュリティセンター(NISC)

5 ISMS 5 4 PC PC USB PDA 2



DX-PC55_−ç(0)-A


( ) ver.2015_01 2

情報セキュリティの現状と課題


net-h12_12.doc

B B B B B B

(資料2)第7回資料その1(ヒアリング概要)




<4D F736F F D DEC8BC A95BD90AC E A982BA81698AB A B B4790DF90AB8EBE8AB FC89408A4F816A82CC93AE8CFC82C98AD682B782E9838C837C815B D

, , ,210 9, ,

橡セキュリティポリシー雛形策定に関する調査報告書

IPA

untitled


AGENDA

スライド 1

( )


untitled

<4D F736F F D2081A193B98BE EA97708CFB8DC08B4B92E D8D878CFB8DC0817A B4B816A81798A6D92E894C5817A2E646F63>


untitled

橡okamura-ppt.PDF

2


1

夏目小兵衛直克

nenkin.PDF

-1-

1 基本的考え方

...i A

untitled

untitled

untitled

CIA+

報告書.PDF

Microsoft Word - 保守運用ガイドライン_080122CSAJ修正.doc

サイプレス 60号(春号)終/P01(目次)

untitled

商学 65‐6☆/15.陶

ITR Market View:クラウド・コンピューティング市場2018目次

00~33.換気マニュアル

16-01 (Page 1)

untitled

ETW15houkoku indd

経済産業省の情報政策について

目  次 (案)

untitled

untitled

<4D F736F F F696E74202D E291AB8E9197BF A F82CC8A A390698DF42E707074>

() () () ()

MSSGuideline ver. 1.0

untitled


untitled

Taro13-学習ノート表紙.PDF

1. 2

untitled

 5月9日、看護の日の記念イベントとして、病院を訪れた方々に絆創膏が配布されました

untitled

随筆 私本太平記

PR IT ISO/IEC TS ,3 ISO/IEC ISO/IEC ISO 9001/ISO JAB JAB (1) (2) OJT 2/11

untitled


高等教育機関の情報セキュリティ対策のためのサンプル規程集

IT IBM Corporation

あっと! デジタル ver.7

.1 [] IPA 2


untitled

生活排水処理施設整備計画策定マニュアル

pdfŠp

untitled

Transcription:

2011 4-1 -

2006/3/10 2006/4/21 2006/6/16 1. 9.3.5 2. ST ST 3. 2006/8/4 2007/11/9 ( ) 2008/9/8 ( ) 2011/4/21 1. 2. 3. - 2 -

1... 5 2... 5 2.1 NISD-K304-101... 5 2.2... 6 3... 6 4... 7 5... 7 5.1... 8 5.2... 11 6... 11 7... 11 7.1... 11 7.2... 12 7.3... 12 7.4... 13 7.5... 13 8... 14 8.1... 14 8.1.1... 14 8.1.2... 15 8.1.3... 16 8.1.4... 17 8.2... 17 9 NISD-K304-101 19 9.1... 19 9.2... 19 9.2.1... 20 9.2.2... 21 9.2.3... 23 9.2.4... 24 9.2.5... 25 9.2.6... 26 9.2.7-3 -

26 9.3... 28 9.3.1... 28 9.3.2... 38 9.3.3... 38 9.3.4... 39 9.3.5... 40 9.4... 41 9.4.1... 41 9.4.2... 42 9.4.3... 42 9.5... 43 9.6... 45 9.6.1 ST ST... 45 9.6.2 IT... 46-4 -

1 NISD-K304-101 2 2.1 NISD-K304-101 1.2.5.1 (1) - 5 -

1.2.5.1 (2) 1.2.5.1 (3) 1.2.5.1 (4) 1.2.5.1 (5) 1.2.5.1 (6) 1.5.1.1 (1) (d) IT (g) ST ST 1.5.2.3 (1) (a)( ) ST ST 2.2 2.1 NISD-K304-101 3-6 -

1 2 3 4 5 6 7 8 9 10 11 1 2 3 4 (1) (2) (3) 5-7 -

5.1 (1) CIO2007 19 3 1 http://www.soumu.go.jp/main_sosiki/gyoukan/kanri/pdf/070301_1.pdf -2006 18 7 26 IT 18 8 31 CIO (2) 2011 4 (3) 19 8 http://www.meti.go.jp/policy/netsecurity/downloadfiles/070824benchmark.pdf IPA http://www.ipa.go.jp/security/benchmark/index.html IPA 17 3 http://www.meti.go.jp/policy/netsecurity/sec_gov-toppage.html http://www.meti.go.jp/policy/netsecurity/downloadfiles/sec_gov-report.pdf 19 8-8 -

(4) IT IPA http://www.ipa.go.jp/security/jisec/index.html IT ISO/IEC 15408 (Common Criteria) 2011 4 IT (5) 2011 4 3 IT (6) ST ST 2011 4 ST ST (7) 2011 3 SBD: Security By Design (8) http://www.meti.go.jp/policy/netsecurity/audit.htm - 9 -

2002 9 2003 3 Ver1.02003 3 26 2003 4 http://www.meti.go.jp/policy/netsecurity/is-kansa/index.html (9) SaaS SLA 2008 1 http://www.meti.go.jp/press/20080121004/03_guide_line_set.pdf SaaS ASP SaaS IPA SaaS (10) ASP SaaS 2008 1 http://www.soumu.go.jp/menu_news/s-news/2008/pdf/080130_3_bt3.pdf 2007 6 2008 1 ASP SaaS ASP SaaS ASP SaaS (11) 2010 8 http://www.meti.go.jp/press/20100816001/20100816001.html 2010 7 2010 8 (12) 2011 4 http://www.meti.go.jp/policy/netsecurity/docs.html - 10 -

ISO/IEC27002:2005 ISO/IEC27002:2005 5.2 (1) JIPDEC http://www.isms.jipdec.jp/isms.html JIS Q 27001:2006 JIS Q 27002:2006 6 7 7.1 (1) 2.1 NISD-K304-101 (2) - 11 -

7.2 (1) (2) 2.1 NISD-K304-101 7.3 (1) (2) (3) (4) (5) (6) - 12 -

7.4 (1) 9.1 (2) 9.2 (3) 9.3 (4) 9.4 (5) 9.5 7.5-13 -

(1) (2) 8 8.1 1 8.1.1 9.3.1 (1) 1 NISD-K304-101C 1.2.5.1-14 -

(2) (9) (2) (3) (4) (5) (6) (7) (1) (6) (8) (1) (6) (9) 8.1.2-15 -

ASP 8.1.1 (1) (2)(4) (9) (3) (3) 9.3.1 8.1.3 9.3.1 (1) (2) (5) (2) (3) - 16 -

(4) (1) (3) (5) 8.1.4 8.2 2 2 3 1)SaaS Web 2)PaaS 3)IaaS - 17 -

- 18 -

9 NISD-K304-101 9.1 1.2.5.1 (1) (a) (1) (2) (3) (1)(2) 9.2-19 -

9.2.1 1.2.5.1 (1) (b) (1) 8 9.2.2 (2) 9.2.3 9.2.6-20 -

9.2.2 1.2.5.1 (1) (c) (1) JIPDEC ISMS http://www.isms.jipdec.jp/isms.html (2) 25 15 19 8 http://www.meti.go.jp/policy/netsecurity/sec_gov-toppage.html http://www.meti.go.jp/policy/netsecurity/downloadfiles/070824benchmark.pdf IPA http://www.ipa.go.jp/security/benchmark/index.html - 21 -

JIPDEC ISMS JIS Q 27001:2006 ISO/IEC 27001:2005 JIS Q 27002:2006 ISO/IEC 17799:2005 1 1 3 JIS Q 27001:2006 A 25 (3) - 22 -

ISO/IEC 17799:2000 (JIS X 5080:2002) http://www.meti.go.jp/policy/netsecurity/audit.htm http://www.meti.go.jp/policy/netsecurity/is-kansa/index.html JASA http://www.jasa.jp/index.html 9.2.3 1.2.5.1 (2) (a) 9.3.1-23 -

ASP (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (11) 9.2.2 9.2.4-24 -

1.2.5.1 (2) (b) 2 (1) (2) 9.2.5-25 -

1.2.5.1 (2) (c) 9.2.3 (1) (7) 9.2.6 1.2.5.1 (3) (a) (1)(b) 9.2.7 1.2.5.1 (3) (b) - 26 -

(1)(c) (1) 9.2.3 (1) (2) (7) (3) JIPDEC ISMS 2007 11 1 ISMS JIPDEC (2) - 27 -

25 5 2007 11 2 (3) 2007 11 3 9.3 9.3.1 1.2.5.1 (4) (a) - 28 -

- 29 -

ASP (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (11) (12) (13) (1) (2) (13) - 30 -

(2) (3) - 31 -

2007 11 ST Security Target ST ST 9.6.1 ST ST ST ST ST ST 2007 11 (4) (5) - 32 -

3 (6) (7) 3 JPCERT - 33 -

(8) (9) (1) (8) - 34 -

捗 4 4-35 -

9.5 (10) (1) (8) http://www.meti.go.jp/policy/netsecurity/audit.htm http://www.jasa.jp/index.html 2007 11 3 (11) (9) (10) - 36 -

(12) 9.3.2 (13) 9.3.5 (14) - 37 -

9.3.2 1.2.5.1 (4) (b) (1) (2) (3) 9.3.3-38 -

1.2.5.1 (4) (c) 6.1.2 (3) (a) (1) (2) (3) 9.3.4 1.2.5.1 (4) (d) 5-39 -

9.3.5 1.2.5.1 (4) (e) (1) (2) 5-40 -

9.4 9.4.1 1.2.5.1 (5) (a) 3.2.5-41 -

6.1.2 (5)(a) 9.4.2 1.2.5.1 (5) (b) 9.3.1 (8) 9.4.3 1.2.5.1 (5) (c) 9.3.1 (9) (1) (8) (10) (11) - 42 -

9.5 1.2.5.1 (6) (a) 9.3.1 9.3.2 (1) - 43 -

(2) (3) - 44 -

9.6 9.6.1 ST ST ST ST 1.5.1.1 (1) (g) ST Security Target ST ST 1.5.2.3 (1) (a) ( ) ST Security Target ST ST ST ST ISO/IEC 15408 ST ST ST ST ST ST (1) ST ST - 45 -

(2) ST ST (3) ST ST (4) ST ST ST ST ST ST ST ST ST ST ST 2007 11 9.6.2 IT IT 1.5.1.1 (1) (d) IT ISO/IEC 15408 IT (1) - 46 -

IT (2) IT (3) IT IT 2007 11 2011 4-47 -