公認内部監査人(CIA)tunetterのブログです。 内部監査の試行錯誤を記録していきます。

にほんブログ村 経営ブログ 経営学へ
いま何位?

2010年4月12日月曜日

基準 3.10

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.10です。

Maintainability-related criteria applicable to the system’s security
システムのセキュリティに適用される保守関連の基準

Criteria 3.10
Procedures exist to maintain system components, including configurations consistent with the defined system security policies.

基準 3.10 
定義されたシステムセキュリティポ リシーと一致した設定を含むシステムコンポーネントを維持する手順が存在する。

Illustrative Controls
Entity management receives a third-party opinion on the adequacy of security controls, and routinely evaluates the level of performance it receives (in accordance with its contractual service-level agreement) from the service provider that hosts the entity’s systems and Web site.
The IT department maintains a listing of all software and the respective level, version, and patches that have been applied.
Requests for changes, system maintenance, and supplier maintenance are standardized and subject to documented change management procedures. Changes are categorized and ranked according to priority, and procedures are in place to handle urgent matters.
Change requestors are kept informed about the status of their requests.
Staffing, infrastructure, and software requirements are periodically evaluated and resources are allocated consistent with the entity’s security policies.
System configurations are tested annually, and evaluated against the entity’s security policies and current service-level agreements. An exception report is prepared and remediation plans are developed and tracked.
The IT steering committee, which includes representatives from the lines of business and customer support, meets monthly and reviews anticipated, planned, or recommended changes to the entity’s security policies, including the potential impact of legislative changes.

統制の実例
経営者はセキュリティ統制につ いての妥当性の第三者意見を受け取り、定常的にシステムとウェブサイトをホストするサービスプロバイダーから(契約上のサービスレベル合意に従って)受け取るパフォーマンスレベルを評価する。
IT部門は全てのソフトウェアとそれぞれのレベル、バー ジョン、適用されるパッチの一覧を維持する。
変更要望、システム維持、そしてサプライヤーのメンテナンスは標準化され、文書の変更管理手続に従う。変更は分類され、優先度で順位付けられ、そして緊急事項を処理するための手順がある。
変更要求は要求のステータスに関する情報が保持される。
人材、インフラストラクチャ、およびソフトウェアの要件は、定期的に評価され、リソースは、セキュリティポリシーと一致して割り当てらる。
システム設定は毎年テストされ、セキュリティポリシーと現在のサービスレベル契約に対する評価を行う。例外レポートが用意され、改善計画が開発され、追跡され る。
ビジネスラインの代表とカスタマーサポートを含むIT運営委員会は月例会合を持ち、法改正の潜在的な影響を含む、予想されまたは計画されまたは推奨されるセキュリティポリシーの変更を確認す る。

2010年4月10日土曜日

基準 3.9

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.9です。

Criteria 3.9
Procedures exist to provide that personnel responsible for the design,
development, implementation, and operation of systems affecting security are qualified to fulfill their responsibilities.

基準 3.9 
セキュリティに影響するデザイン、開発、実装、そしてシステムオペレーションに責任を持つ社員の責任を満たすための資 格を提供する手順が存在する。

Illustrative Controls
The entity has written job descriptions specifying the responsibilities and academic and professional requirements for key job positions.
Hiring procedures include a comprehensive screening of candidates for key positions and consideration of whether the verified credentials are commensurate with the proposed position. New personnel are offered employment subject to background checks and reference validation.
Candidates, including internal transfers, are approved by the line-of-business manager before the employment position is offered.
Periodic performance appraisals are performed by employee supervisors and include the assessment and review of professional development activities.
Personnel receive training and development in system security concepts and issues.
Procedures are in place to provide alternate personnel for key system security functions in case of absence or departure.


統制の実例
主たる業務ポジションに求められる責任と学位と専門的要件を明記した職務記述書がある。
採用手順には、主要ポジションの候補者に ついての、包括的な審査と検査認定が提示されたポジションにふさわしいかどうかの考慮が含まれる。新しい社員はバックグラウンドの確認と推薦状の検証を目 的とした仕事を提示される。
候補者(内部異動者を含む)は、雇用ポジションの提示以前に、ビジネスラインの管理者によって認定される。
定期的なパフォーマンス評価は従業員監 督者によって行われ、専門能力開発活動の見積と確認を含む。
従業員はシステムセキュリティのコンセプトと項目の訓練と開発を受ける。
欠勤や離反に備え、主要システムセキュリ ティ機能について代替要員の供給手順がある。

2010年4月8日木曜日

基準 3.8

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.8です。

Criteria related to the system components used to achieve the objectives
目的を達成するために使用されるシステムコンポーネントに関する基準

Criteria 3.8
Design, acquisition, implementation, configuration, modification, and management of infrastructure and software related to system security are consistent with defined system security policies to enable authorized access and to prevent unauthorized access.
基準 3.8
システムセキュリティ関連のインフラスト ラクチャーとソフトウェアのデザイン、獲得、実装、設定、変更、そして管理は、承認されたアクセスを可能にして未承認のアクセスを防ぐために定義されたシ ステムセキュリティポリシーと一致する。
Illustrative Controls

The entity has adopted a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, and maintenance of computerized information systems and related technology.
The SDLC methodology includes a framework for classifying data and creating standard user profiles that are established based on an assessment of the business impact of the loss of security. Users are assigned standard profiles based on needs and functional responsibilities.
Owners of the information and data classify its sensitivity and determine the level of protection required to maintain an appropriate level of security.
The security administration team reviews and approves the architecture and design specifications for new systems development and/or acquisition to ensure consistency with the entity’s security objectives, policies, and standards.
Changes to system components that may affect security require the approval of the security administration team.
The access control and operating system facilities have been installed, including the implementation of options and parameters, to restrict access in accordance with the entity’s security objectives, policies, and standards.
The entity contracts with third parties to conduct periodic security reviews and vulnerability assessments. Results and recommendations for improvement are reported to management.

統制の実例
コンピュータ化された情報システムと関連する技術の開発、獲得、実装、そして維持の正式なシステム開発ライフサイクルの 方法論を取り入れる。

SDLCの方法論は分類されたデータと標準的なユーザーのプロファイル作成のフレームワークを含む。これらはセキュリ ティ欠如によるビジネスインパクトの見積に基づいて確立される。ユーザーは必要性と機能的な責任に基づいて標準的なプロファイルを与えられる。

情報とデータの所有者は、機微の度合い により分類され、適切なセキュリティレベルを維持するための防御の度合いにより決定される。

セキュリティ管理チームは、セキュリティの目的、ポリシー、そして標準 と一致を確保するために、新システムの開発と(あるいは)獲得の構造とデザイン仕様を確認し承認する
セキュリティに影響するかもしれないシステムコンポーネントの変更は セキュリティ管理チームの承認を要する。

セキュリティの目的、ポリシー、そして標準に従って制限するためのアクセスコントロールとオペレーションシステム設備が 構築されている。(オプションとパラメーターの実装を含む)。

サードパーティと定期的なセキュリティ確認と脆弱性見積実施の契約を結ぶ。結果と改善提案は経営者に報告される。

2010年4月7日水曜日

基準 3.7

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.7です。

Criteria 3.7
Procedures exist to provide that issues of noncompliance with system security policies are promptly addressed and that corrective measures are taken on a timely basis.

基準 3.7
システムのセキュリティポリシーの違反が迅速に処理された結果と適時にとられた是正措置を提 供する手順が存在する。

Illustrative Controls
Security issues are recorded and accumulated in a problem report.
Corrective action is noted and monitored by management.
On a routine basis, security policies, controls, and procedures are audited by the internal audit department. Results of such examinations are reviewed by management, a response is prepared, and a remediation plan is put in place.

統制の実例
セキュリティ結果は問題報告に記録さ れ蓄積される。
是正対応は経営者により記録され監視される。
定期的に、セキュリティポリシーと統制、そして手続は内部監査部門により監査 される。このような検査の結果は経営者によって確認され、対応が準備され、改善計画が整備される。

2010年4月6日火曜日

基準 3.6

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.6です。

Criteria 3.6
Procedures exist to identify, report, and act upon system security breaches and other incidents.

基準 3.6
認証、報告そしてシステムセキュリティ侵害やその他ゆ事故への対応の手続が存在する。

Illustrative Controls
Users are provided instructions for communicating potential security breaches to the information security team. The information security team logs incidents reported through customer hotlines and e-mail.
Intrusion detection and other tools are used to identify, log, and report potential security breaches and other incidents. The system notifies the security administration team and/or the network administrator via e-mail and pager of potential incidents in progress.
Incident logs are monitored and evaluated by the information security
team daily.

Documented incident identification and escalation procedures are approved by management.
統制の実例
ユー ザーは、情報セキュリティチームへ潜在的なセキュリティ侵害を伝達する訓練がなされている。情報セキュリティチームは顧客ホットラインや電子メールを通じ て報告された事故を記録する。
侵入検知と他のツールは認証、記録そして潜在的なセキュリティ侵害とその他事故の報告に使用される。システムはセ キュリティ管理者と(または)ネットワーク管理者に潜在的で進行中の事故についてメールまたはポケットベルにて警告する。
事故の記録は毎日情報セ キュリティチームによって監視され評価される。
文書化された事故識別と上位報告の手順は経営者によって承認されている。

2010年4月5日月曜日

基準 3.5

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.5です。

Criteria 3.5
Encryption or other equivalent security techniques are used to protect user authentication information and the corresponding session transmitted over the Internet or other public networks.

基準 3.5
ユーザー認証情報と対応する インターネットまたは他の公衆網上で送信されたセッションは、暗号化または同等のセキュリティ技法が使われて保護される

Illustrative Controls
The entity uses 128-bit secure sockets layer (SSL) encryption for transmission of private or confidential information over public networks, including user ID and password. Users are required to upgrade their browser to the most current version tested and approved for use by the security administration team to avoid possible security problems.
Account activity, subsequent to successful login, is encrypted through a 128-bit SSL session. Users are logged out on request (by selecting the “Sign-out” button on the Web site) or after 10 minutes of inactivity.

統制の実例
ユーザーIDとパスワードを 含むプライベートまたは機密情報を公衆網上で送信するために128ビットのセキュアソケット レイヤー(SSL)暗号を使用する。ユーザーはブラウザを、起こりうるセキュリティ問題を回避するためにテストされセキュリティ管理チームに使用を認められた、最 新版へアップグレードすることが要求される。
ログイン成功後のアカウントの動作は、128ビットSSL通信によって暗号化される。ユーザーは要求(ウェブサイト上の「サインアウト」ボタンを選ぶこ とによる)があった場合または 10分間動作がなければログア ウトする。

2010年4月2日金曜日

基準 3.4

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 3.4です。

Criteria 3.4
Procedures exist to protect against infection by computer viruses, malicious codes, and unauthorized software.

基準 3.4
コンピューターウィルスや悪意のあるコード、認められていないソフトウェアによる感染を防御 する手続が存在する。

Illustrative Controls
In connection with other security monitoring, the security administration team participates in user groups and subscribes to services relating to computer viruses.
Antivirus software is in place, including virus scans of incoming email messages. Virus signatures are updated at least weekly.
Any viruses discovered are reported to the security team and an alert is created for all users notifying them of a potential virus threat.

統制の実例
他のセキュリティー監視と関連して、セキュリティー管理チームはユーザーグループに参加し、コンピューターウィルス関連 のサービスに申し込む。アンチウィルスソフトウェアが導入され、受信メールのウィルススキャンを含んでいる。ウィルスシグネチャは少なくとも週ごとに更新 される。
発見され たあらゆるウィルスはセキュリティーチームに報告され、全ユーザーに潜在的なウィルスの脅威を喚起する警告が作成される。