Netwrix 1Secureは、データとアイデンティティ全体にわたる統合された可視性を提供します。14日間の無料トライアルでフルアクセス可能です。無料トライアルを開始

リソースセンターブログ

リスク分析の例:リスクを評価する方法

リスク分析の例:リスクを評価する方法

Mar 17, 2023

組織は、サイバーセキュリティ、責任、投資など、複数の面でリスクに苦慮しています。リスク分析(またはリスクアセスメント)は、リスク管理プロセスにおける最初のステップです。 IT risk analysis は、内部・外部の脅威が availability, confidentiality, and integrity にもたらすリスクに焦点を当てます。リスク分析の過程で、企業は、事件が起きた場合にビジネスに生じ得る潜在的な損失など、リスクと結果(影響)のレベルを特定します。

リスク分析のプロセスでは、リスクにさらされる資産(ITシステムとデータ)を定義し、各資産に対する脅威を特定し、各脅威がどれほど重大か、さらにその脅威に対してシステムがどの程度脆弱かを評価します。NIST SP 800-30 や ISO/IEC 27005:2018、31010:2019 で示されているような、構造化されプロジェクトベースのアプローチでリスク分析を進めるのが賢明です。

リスク分析は、さまざまな理由で重要です。インフラにおけるリスクを軽減する責任を負う IT 専門家は、どのリスクをできるだけ早く解決すべきか、どのリスクは後で対処できるのかを判断するのに苦労することがよくあります。リスク分析は、そうした判断を適切に優先順位づけるのに役立ちます。さらに、多くの規制・コンプライアンス要件には security risk assessment を必須の構成要素として含めています。

この記事では、リスク分析の例を取り上げ、IT リスク分析プロセスの主要な構成要素を解説します。

リスク分析の例

以下のセクションでは、リスク分析文書の主要な構成要素を示します。

はじめに

このセクションでは、評価プロセスがなぜ、そしてどのように取り扱われたのかを説明します。レビューしたシステムの説明を含み、情報の提供・収集およびそれを分析するために必要な責任(役割)の割り当ても明記します。

目的

このセクションでは、ITシステムに対する詳細な評価の目的を定義します。以下は例です:

年次の企業リスク評価の結果、< system name > は潜在的な高リスク システムとして特定されました。リスク評価の目的は、< system name > に関連する脅威と脆弱性を特定し、これらのリスクを軽減するための計画を明らかにすることです。

スコープ

このセクションでは、IT システム評価の範囲を定義します。リスク評価において考慮するシステムの構成要素、ユーザー、およびその他のシステム詳細を説明してください。

本リスク評価の範囲は、< system name > の内外に存在する脅威によって悪用可能な脆弱性を排除および/または管理するために、リソースとコントロール(実装済みまたは計画中)の活用状況を評価することです。

システムの説明

調査対象となるシステム、ハードウェア、ソフトウェア、インターフェイス、またはデータを列挙し、それらのうち評価の範囲外となるものを明記してください。これは、システムの境界、機能、システムおよびデータの重要度と機密性をさらに分析するために必要です。以下は例です:

< system name > は < sensitive / critical / regulated > データを処理する < components, interfaces > で構成されています。< system name > は < details on physical environment > に設置されています。システムは < core functions > を提供します。

参加者

このセクションには、参加者の氏名と役割の一覧が含まれます。資産の所有者、IT およびセキュリティチーム、ならびにリスク評価チームを含める必要があります。

評価アプローチ

このセクションでは、リスク評価に使用するすべての方法論および技法について説明します。たとえば:

リスクは、脅威イベント、その脅威イベントが発生する可能性、既知のシステム脆弱性、軽減要因、および会社のミッションへの影響に基づいて決定されます。 データ収集フェーズでは、組織内の主要担当者を特定し、インタビューを行うほか、文書レビューを実施します。インタビューは運用環境に焦点を当てます。文書レビューは、リスク評価チームがポリシーおよび手順への準拠(コンプライアンス)を評価するための根拠を提供します。

リスクの特定と評価

ここから 情報セキュリティリスク の評価の中核部分が始まります。この段階で、評価の現地調査作業の結果を取りまとめます。

厳選した関連コンテンツ:

データインベントリ

スコープ内の価値ある資産をすべて特定し、定義します。例:サーバー、重要なデータ、規制対象データ、またはそれらが漏えいした場合に業務運営へ大きな影響を与えるその他のデータ。例えば:

Type of data

Description

Level of sensitivity (High, Moderate, Low)

Personally identifiable information

  • Name
  • Address
  • Social Security number
  • Credit card number

High

Financial information

  • Credit card number
  • Verification code
  • Expiry date
  • Authorization reference
  • Transaction reference

High

システムユーザー

システムを使用しているのが誰かを説明し、ユーザーの所在地とアクセス権限のレベルに関する詳細も含めてください。以下の例を参考にできます:

System name

User Category

Access Level (Read, Write, Full)

Number of users

Home Organization

Geographic Location

<Name of business application>

Regular user

Read/Write

10

ABC Group

Atlanta

脅威の特定

脅威の発生源(脅威ソース)のカタログを作成します。セキュリティ侵害や技術的なミスから、人為的なエラーやインフラ障害まで、組織の業務に悪影響を与え得るリスクを簡潔に説明してください:

Threat source

Threat action

Cyber criminal

  • Web defacement
  • Social engineering
  • System intrusions (break-ins)
  • Identity theft

Malicious insider

  • Browsing of personally identifiable information
  • Unauthorized system access
  • Accidental or ill-advised actions taken by employees that result in unintended physical damage, system disruption or exposure

Employees

  • Illness, death, injury or other loss of a key individual

Reputation

  • Loss of confidence from employees
  • Damage to the reputation of the company

Organizational (planning, schedule, estimation, controlling, communication, logistics, resources and budget)

  • Improper worker termination and reassignment actions

Legal and administrative actions

  • Regulatory penalties
  • Criminal and civil proceeding

Technical

  • Malicious code (e.g., virus)
  • System bugs
  • Failure of a computer, device, application, or protective technology or control that disrupts or harms operations or exposes the system to harm

Environmental

  • Natural or man-made disasters

脆弱性の特定

脅威があなたのセキュリティを侵害できる可能性のある脆弱性や弱点を評価します。以下は例です:

Vulnerability

Description

Poor password strength

Passwords used are weak. Attackers could guess the password of a user to gain access to the system.

Lack of disaster recovery

There are no procedures to ensure ongoing operation of the system in the event of a significant business interruption or disaster.

リスクの特定

ここでは、脅威と脆弱性が損害を引き起こす可能性の確率と、それらの結果の程度を評価します。

リスク発生確率の特定

このステップでは、リスク発生確率(リスクが起こる可能性)を評価することに集中してください。

Level

Probability Definition

Example

High

The threat source is highly motivated and sufficiently capable, and controls to prevent the vulnerability from being exercised are ineffective.

Unauthorized malicious disclosure, modification, or destruction of information

Moderate

The threat source is motivated or capable, but controls are in place that may impede successful exercise of the vulnerability.

Unintentional errors and omissions

Low

The threat source lacks motivation or capability, or controls are in place to prevent, or at least significantly impede, the vulnerability from being exercised.

IT disruptions due to natural or man-made disasters

影響分析

事故が発生した場合にビジネスへ及ぼす影響の結果を理解するために、リスク影響分析を実施します。リスク分析には、データ損失、システム停止、法的な影響など、最も危険性の高いリスクを特定するための定性的なリスク評価を含めることができます。定量的なリスク評価は任意であり、影響を金銭的な観点で測定するために使用されます。

Incident

Consequence

Impact

Unauthorized disclosure of sensitive information

The loss of confidentiality with major damage to organizational assets.

The incident may result in the costly loss of major tangible assets or resources, and may significantly violate, harm or impede the organization’s mission, reputation or interests.

High

IT disruptions due to unauthorized changes to the system

The loss of availability with a serious adverse effect on organizational operations.

The organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced.

Medium

Non-sensitive data is lost by unauthorized changes to the data or system

The loss of integrity with a limited effect on organizational operations assets, or individuals.

The organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced.

Low

リスクレベルの評価

このステップでは、リスク分析の結果をリスク評価基準と比較します。その結果は リスクの優先順位付け に用いられ、リスクのレベルに応じて決定します。

Level of Impact

Risk Level Definition

High

There is a strong need for corrective measures. The system may continue to operate, but a corrective action plan must be put in place as soon as possible.

Moderate

Corrective actions are needed and a plan must be developed to incorporate these actions within a reasonable period of time.

Low

The system’s owner must determine whether corrective actions are still required or decide to accept the risk.

リスク評価結果

Risk Assessment Results テーブルにリスクを列挙してください。レポートでは、脅威と脆弱性を説明し、リスクを測定したうえで、統制(コントロール)を実装するための推奨事項を提示する必要があります。

Threat

Vulnerabilities

Mitigation

Likelihood

Impact

Risk

Hurricane

Power outage

Install backup generators

Moderate

Low

Low

Lack of disaster recovery plan

Disaster recovery

Develop and test a disaster recovery plan

Moderate

High

Moderate

Unauthorized users can access the server and browse sensitive company files

Open access to sensitive content

Perform system security monitoring and testing to ensure adequate security is provided for <server name>.

Moderate

High

Moderate


結論

リスク分析により、どのリスクが最優先事項かを把握できます。権限、ポリシー、データ、ユーザーなどの主要な領域を継続的に見直すことで、IT エコシステムに対して最も高いリスクをもたらす脅威を特定し、セキュリティとコンプライアンスを改善するために必要な統制(コントロール)を調整できます。

共有する

もっと詳しく

著者について

Ryan Brooks

プロダクトエバンジェリスト

Netwrix Corporation のプロダクトエバンジェリスト、ライター、プレゼンターです。Ryan はサイバーセキュリティの普及活動に特化し、IT の変更とデータアクセスに対する可視性の重要性を広めることに力を注いでいます。著者としては、IT セキュリティのトレンド、調査、そして業界の洞察に焦点を当てています。