公認内部監査人(CIA)tunetterのブログです。 内部監査の試行錯誤を記録していきます。

にほんブログ村 経営ブログ 経営学へ
いま何位?

2010年5月31日月曜日

e. Restriction of access to system configurations, superuser functionality, master passwords, powerful utilities, and security devices

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表のe. Restriction of access to system configurations, superuser functionality, master passwords, powerful utilities, and security devicesです。

e. Restriction of access to system configurations, superuser functionality, master passwords, powerful utilities, and security devices:
e. システム設定やスーパーユーザー機能、マスターパスワード、強力なユーティリティー、そしてセキュリティデバイスへのアクセス制限:
  • Hardware and operating system configuration tables are restricted to appropriate personnel.
  • ハードウェアとオペレーティングシス テムの設定テーブルは適切な従業員に制限される。
  • Application software configuration tables are restricted to authorized users and under the control of application change management software.
  • アプリケーションソフトウェアの設定テーブルは承認されたユーザーに制限され、アプリケーション変更管理ソフトウェアの コントロール下に置かれる。
  • Utility programs that can read, add, change, or delete data or programs are restricted to authorized technical services staff. Usage is logged and monitored by the manager of computer operations.
  • データやプ ログラムを読むこと、追加、変更または消去できるユーティリティプログラムは権限のあるテクニカルサービススタッフに制限される。使用状況は記録され、コ ンピューターオペレーションのマネージャーによって監視される。
  • The information security team, under the direction of the CIO, maintains access to firewall and other logs, as well as access to any storage media. Any access is logged and reviewed quarterly.
  • CIOの 指示のもと、情報セキュリティチームは、あらゆるストレージへのアクセスと同様に、ファイアウォールと他の記録の保守を行う。あらゆるアクセスは記録さ れ、四半期ごとに確認される。
  • A listing of all master passwords is stored in an encrypted database and an additional copy is maintained in a sealed envelope in the entity safe.
  • 全てのマスターパスワードは暗号化されたデータベースに格納され、別途コピーが封緘され金庫に保管される。

2010年5月28日金曜日

d. The process to grant system access privileges and permissions

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表のd. The process to grant system access privileges and permissionsです。

d. The process to grant system access privileges and permissions:
d. システムのアク セス権限およびアクセス許可を付与するプロセス:
  • All paths that allow access to significant information resources are controlled by the access control system and operating system facilities. Access requires users to provide their user ID and password. Privileges are granted to authenticated users based on their user profiles.
  • 重要な情報資源へのアクセスを許可する全てのパスはアクセスコントロールシステムとオペレーティングシステム設備によ り制御される。特 権は認証され たユーザーのユーザープロファイルに基づいて付与される。
  • The login session is terminated after three unsuccessful login attempts. Terminated login sessions are logged for follow-up.
  • ログインセッションは3回ログインを試みて失敗すると終了される。終了されたログインセッションはフォローアップのために記録される。

2010年5月27日木曜日

c. Changes and updates to user profiles

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表のc. Changes and updates to user profilesです。

c. Changes and updates to user profiles:
c. ユーザープロファイルの変更と更新:
  • Changes and updates to self-registered customer accounts can be done by the individual user at any time on the entity’s Web site after the user has successfully logged onto the system. Changes are reflected immediately.
  • 自己登録顧客アカウントの変更と更新は、ログオンに成功後、個々のユーザーがいつでも ウェブサイトで行うことができる。
  • Unused customer accounts (no activity for six months) are purged by the system.
  • 利用されない顧客アカウント(6ヶ月以上活動なし)はシステムによって削除される。
  • Changes to other accounts and profiles are restricted to the security administration team and require the approval of the appropriate line-of-business supervisor or customer account manager.
  • 他のアカウントとプロファイルへの変更はセキュリティ管理チームに限定され、適切なビジネスラインの管理者や顧客のアカウ ントマネージャの承認が必要であ る。
  • Accounts for terminated employees are deactivated upon notice of termination being received from the human resources team.
  • 雇用が終了した従業員のアカウントは人事チームからの終了通知に基づき無効化される。

2010年5月26日水曜日

b. Identification and authentication of users

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表のb. Identification and authentication of usersです。

b. Identification and authentication of users:
b. ユーザーの識別と認証:
  • Users are required to log on to the entity’s network and application systems with their user ID and password before access is granted. Unique user IDs are assigned to individual users. Passwords must contain at least characters, one of which is nonalphanumeric. Passwords are case sensitive and must be updated every 90 days.
  • ユー ザーはアクセスが認められる前に、ユーザーIDとパスワードでのネットワークとアプリケーションシステムへのログオンを求められる。ユニークユーザーIDが個人ユーザーに割り当てられる。パスワードは少なくとも6文字を含み、内1文字は英数字以外でなければならない。パスワードは大文字と小文字が区別され、90日毎に更新されなければならない。

2010年5月25日火曜日

a. Registration and authorization of new users

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表のa. Registration and authorization of new usersです。

Illustrative Controls
統制の実例

a. Registration and authorization of new users:
a. 新規ユーザーの登録と認証:
  • Customers can self-register on the entity’s Web site, under a secure session in which they provide new user information and select an appropriate user identification (ID) and password. Privileges and authorizations associated with self-registered customer accounts provide specific limited system functionality.
  • 顧客は ウェブサイトにて、新規ユーザーに関する情報が供給され、専用のユーザー識別(ID)とパスワードを選べる安全なセッションのもとで、自身で登録すること ができる。自己登録の顧客アカウントは特定の限定された権利と権限が与えられる。
  • The ability to create or modify users and user access privileges (other than the limited functionality “customer accounts”) is limited to the security administration team.
  • ユー ザーを新規作成したり変更する能力とユーザーアクセスの権利(機能限定された"顧客アカウント"以外の) はセキュリティ管理チームに限定される。
  • The line-of-business supervisor authorizes access privilege change requests for employees and contractors. Customer access privileges beyond the default privileges granted during self-registration are approved by the customer account manager. Proper segregation of duties is considered in granting privileges.
  • 基幹業務管理者 が従業員や請負業者のためのアクセス権限の変更要求を承認します。自己登録時に付与されたデフォルトの権限を超えた顧客のアクセス権限は、顧客アカウントのマネージャによって承認される。権利を認めるには職務の分離が考慮される。

2010年5月21日金曜日

基準3.4

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準3.4です。

Security-related criteria relevant to the system’s availability
システムの可用性に関連したのセキュリティ関係の基準

Criteria 3.4
Procedures exist to restrict logical access to the defined system including, but not limited to, the following matters:
a. Registration and authorization of new users.
b. Identification and authentication of users.
c. The process to make changes and updates to user profiles.
d. The process to grant system access privileges and permissions.
e. Restriction of access to system configurations, superuser functionality,
master passwords, powerful utilities, and security devices (for example, firewalls).

基 準 3.4
以下の事柄を含む(がそれらに限定されない)定義された システムへの論理的アクセスを制限する手順が存在する。
a. 新規ユーザーの登録と認証
b. ユーザーの識別と認証
c. ユーザープロファイルの変更と更新手順
d. システムのアクセス権限およびアクセス許可の付与手順
e. システム設定、スーパーユーザー機能、マスターパスワード、強力なユーティリティ、セキュリティデバイス(例:ファイアウォール)へのアクセス制限

2010年5月20日木曜日

基準3.3

引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準3.3です。
Criteria 3.3
Procedures exist to provide for the integrity of backup data and systems maintained to support the entity’s defined system availability and related security policies.
基準 3.3
バックアップデーターの完全性と定義されたシステムの可用性をサポートするシステム保 守と関連するセキュリティーポリシーを供給するための手順が存在する。

Illustrative Controls 
統制の実例
Automated backup processes include procedures for testing the integrity of the backup data.
自動バックアッププロセスにはバックアップデーターの完全性のテストの手順が含まれる。

Backups are performed in accordance with the entity’s defined backup strategy, and usability of backups is verified at least annually.
Backup systems and data are stored offsite at the facilities of a thirdparty service provider.

バックアップはバックアップ戦略にしたがって行われ、 バックアップの有用性は少なくとも年次に検証される。
バックアップシステムとデー ターは第三者のサービス提供者の施設においてオフサイトで保管される。

Under the terms of its service provider agreement, the entity performs an annual verification of media stored at the offsite storage facility. As part of the verification, media at the offsite location are matched to the appropriate media management system. The storage site is reviewed biannually for physical access security and security of data files and other items.
サービス提供者との合意条件のもとでオフサイト倉庫施設に保管さ れた媒体の年次検証を行う。検証の一環として、オフサイトの倉庫施設に保管されている媒体は 適切な媒体管理システムと照合される。ストレージサイトは隔年ごとに物理的なアクセスセキュ リティとデーターファイルや他のアイテムのセキュリティを確認される。

Backup systems and data are tested as part of the annual disaster recovery test.
バックアップシステムとデーターは年次災害復旧テストの一環としてテストされる。