IGA ã«ãããããŒã«ããŒã¹ã¢ã¯ã»ã¹å¶åŸ¡
ãã®èšäºã¯ https://docs.evolveum.com/iam/iga/rbac/ ã®ç¿»èš³ã§ãã
ã¯ããã«
ååã瀺ããšãããããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ (RBAC) 㯠ããŒã« ã®æŠå¿µã«åºã¥ãã¢ã¯ã»ã¹å¶åŸ¡æ©æ§ã§ãã å€ãã®çµç¹ã§ã¯ãåãæš©é矀ããŠãŒã¶ãŒã«äœåºŠãç¹°ãè¿ãå²ãåœãŠãããŸãã åãè·åãããŠãããŠãŒã¶ãŒã¯ãåãæš©éãæã€å¯èœæ§ãé«ãã§ãã RBAC ã®èãæ¹ã¯åçŽã§ãããããã®æš©éã ããŒã« ã«ã°ã«ãŒãåãããã®ããŒã«ããŠãŒã¶ãŒã«å²ãåœãŠãŸãã ã€ãŸãå²ãåœãŠããã®ã å°ãªã ãªããŸããããã€ãã®æš©éãå²ãåœãŠã代ããã«ã1ã€ã®ããŒã«ãå²ãåœãŠãŸãã 管çãããã®ãå°ãªããã°ã管çåŽåãå°ãªããªããŸãã å°ãªããšãçè«äžã¯ããã§ãã

ãã€ãã®ããã«ãå®åã¯å°ãç°ãªããŸãã RBAC ã¯ãããªã èŠåç ã§ éç ãªçµç¹ã§ã¯éåžžã«ããŸãæ©èœããŸããå€ãã®äººãåãè·åãè¡ãããã®è·åããã£ãã«å€ãããªãçµç¹ã§ãã ãã®å Žåãå¿ èŠãªããŒã«ã¯ã»ãã®å°æ°ã§ãããããå€ãã®ãŠãŒã¶ãŒã«å²ãåœãŠãããŒã«å®çŸ©ãé »ç¹ã«æŽæ°ããå¿ èŠããããŸããã æ®å¿µãªãããç§ãã¡ã¯21äžçŽã®çŸå®ã«ããŸãã çµç¹ã¯ãã¯ãããã»ã© èŠåç ã§ã éç ã§ããªããçãæ®ãããã«ã¯æè»ã§å¹ççã§ããå¿ èŠããããŸãã åŸæ¥å¡ã¯éåžžãè€æ°ã®è²¬ä»»ãæã¡ããããã¯ããªãé »ç¹ã«å€ãããŸãã ãã㯠RBAC ã«ãšã£ãŠçæ³çãªç°å¢ã§ã¯ãããŸããã çµç¹ã¯ãéåžžã«åçãªç°å¢ã§ã倧éã®ããŒã«ãšããŒã«å²ãåœãŠã管çããå¿ èŠããããŸãã ããã§ã RBAC ã¯ãæ£ãã䜿ãã°å€ãã®äŸ¡å€ããããããŸãã
ãŸãåºæ¬ããå§ããŸãããã
çšèª
NOTE: RBAC ãšããçšèªã¯ã人ã«ãã£ãŠå€ãã®æå³ãæã¡ãŸãã ç§ãã¡ã¯ RBAC ãšããçšèªãããªãåºãæå³ã§äœ¿ããŸãã NIST RBAC ã¢ãã«ã ããå³å¯ã«æå³ããŠããããã§ã¯ãããŸããã ç§ãã¡ã RBAC ã§æå³ããã®ã¯ãããŒã«ã®æŠå¿µã«åºã¥ãäžè¬çãªæ©æ§ã§ãã midPoint RBAC ã®åºæ¬åå㯠NIST RBAC ã¢ãã«ãšéåžžã«ãã䌌ãŠããŸãããå¿ èŠãªå Žå㯠NIST ã¢ãã«ããéžè±ããèªç±ãåããŸãã
IGA åºæ
NOTE: ãã®æ¬æã¯ãã¢ã€ãã³ãã£ãã£ã¬ããã³ã¹ããã³ç®¡ç (IGA) ã·ã¹ãã ã以åã¯ã¢ã€ãã³ãã£ãã£ç®¡ç (IDM) ã·ã¹ãã ãŸãã¯ããããžã§ãã³ã°ã·ã¹ãã ãšåŒã°ããŠããã·ã¹ãã ã«ããã RBAC ã®å©çšã説æããŠããŸãã ã¢ããªã±ãŒã·ã§ã³å ã®çްç²åºŠã®ã¢ã¯ã»ã¹å¶åŸ¡ã« RBAC ã䜿ãããšã«ã¯çŠç¹ãåœãŠãŠããŸããã
åºæ¬ããŒã«éå±€
æš©éãããŒã«ã«ã°ã«ãŒãåããèœåã¯ããªãæçšã§ãã ããããã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã極端ã«åçŽã§ãªãéããããã ãã§ã¯ãŸã ååã§ã¯ãããŸããã å®åçãªããªã·ãŒã®å€ãã¯ããŒã«ãããŒã«ã®äžã«çœ®ããããŒã«éå±€ãäœãããšãå¿ èŠãšããŸãã
2ã€ã®è·åäžã®äœçœ®ä»ããæ åœè ãšç£ç£è ãèããŠã¿ãŸãããã æ åœè ã¯åºæ¬çãªæš©ééåãæã£ãŠããŸãã ç£ç£è ã¯æ åœè ãã§ããããšããã¹ãŠè¡ããŸãããããã«è¿œå æš©éãæã£ãŠããŸãã çŽ æŽãªæ¹æ³ã¯ãæ åœè ã®æš©éããã¹ãŠç£ç£è ããŒã«ã«åçŽã«ã³ããŒããããšã§ãã ãããæš©éã¯ãã£ãã«éçã§ã¯ãããŸããã ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã¯ãç°å¢ã®å€åãšåããããå€åãé²åããŸãã æ åœè ã®æš©éãå€ããå¯èœæ§ã¯é«ãã§ãã ãã®å Žåãç£ç£è ããŒã«ãæŽæ°ããå¿ èŠããããŸãã ããã¯ç¶æç®¡çè² æ ã«ãªããŸãã ã§ã¯ãç¶ç¶çãªç¶æç®¡çãå¿ èŠãªé¢é£ããŒã«ãæ°çŸãæ°åããå Žåãæ³åããŠãã ããã ãã®ãããªæ§é ãç¶æç®¡çãã人ã«ã¯ãè¶ äººçãªæ£ç¢ºããšå¿èãå¿ èŠã«ãªããŸãã
ããèªç¶ãªèãæ¹ã¯ãæ åœè ããŒã«ãç£ç£è ããŒã«ã«å«ããããšã§ãã æ åœè ã®æš©éãå€ãããšãç£ç£è ã®æš©éãèªåçã«æŽæ°ãããŸãã ç¶æç®¡çã¯ãã£ãšå®¹æã§ãã ãããããŒã«éå±€ã®åºæ¬èãæ¹ã§ãã åºæ¬æš©éã¯äœã¬ãã«ã®ããŒã«ã«çœ®ãããŸãã äœã¬ãã«ã®ããŒã«ãçµã¿åãããŠäžäœã¬ãã«ã®ããŒã«ãäœããŸãã ãã®ããŒã«ãããã«çµã¿åãããããšãã§ããŸãã

ããŒã«çš®é¡
ãã¹ãŠã®ããŒã«ãåãããã«äœãããŠããããã§ã¯ãããŸããã çæ³çã«ã¯ãäžèšã®äŸã®ããŒã«ã¯ãã¹ãŠåçã«æ±ãããã¹ãã§ãã ãã¹ãŠãæ¥åäžã®è·äœãŸãã¯è²¬ä»»ã衚ãããã¹ãŠããŠãŒã¶ãŒã«å²ãåœãŠããããã¹ãŠãåãããã»ã¹ã§äœæã»ç¶æç®¡çãããããšãã圢ã§ãã ãã¹ãŠã®ããŒã«ã¯ããã®æ¥åäžã®è·äœãŸãã¯è²¬ä»»ã«å¿ èŠãªæš©éãå«ãã¹ãã§ãã ãããçŸå®äžçã§ã¯éåžžããã§ã¯ãããŸããã
ãçŽç²ãªã RBAC çè«ã§ã¯ãããŒã«ã¯æ¥åæŠå¿µã衚ãããšã«ãªã£ãŠããŸãã ããã¯ç¢ºãã«è¯ãæ¹æ³ã§ãã ããŒã«ã¯ãæ¥åéšéã®æ åœè ãçè§£ã§ãããã®ãè·åäžã®äœçœ®ä»ãã責任ãçµç¹äžã®åäœãªã©ã衚ããšãã«æãããæ©èœããŸãã ãããŸã§ã¯åé¡ãããŸããã ãããããŒã«ã®äžãèŠããšè€éã«ãªããŸãã ããŒã«ã¯æš©éãã€ãŸãå®éã® IT ç°å¢ã«å¯Ÿå¿ä»ããããæš©éãå«ãããšã«ãªã£ãŠããŸãã ããããæ¥åäžã®æå³ãšè€éã§æŽçãããŠããªã IT 詳现ã®äž¡æ¹ãæã€ããŒã«ãæ§ç¯ããããšã¯å°é£ã§ãã ãã®ãããªããŒã«ãäœãã«ã¯ãæ¥åéšéã®æ åœè ã IT æ åœè ãšéåžžã«å¯æ¥ã«ååããå¿ èŠããããŸãã ãããæ¥åãš IT ã®ååã¯ãéåžžãŸã ãŸã æ¹åã®äœå°ããããŸãã ç°ãªãæŠå¿µãšèšèªã䜿ã£ãŠãããååã¯å®å šã«åæ»ã§ã¯ãããŸããã ãã®ããäžè¬çãªå®è·µã¯ãå°ãªããšã2çš®é¡ã®ããŒã«ãæã€ããšã§ãã
- ããžãã¹ããŒã« ã¯ãè·åã責任ãªã©ã®æ¥åæŠå¿µã衚ããŸãã
- ã¢ããªã±ãŒã·ã§ã³ããŒã« 㯠IT äžã®æŠå¿µã衚ããéåžžã¯ç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ãžã®æè¡çãªã¢ã¯ã»ã¹æš©ã衚ããŸã (ãã®ãããã®ååã§ã)ã
ããžãã¹ããŒã«ã¯ä»ã®ããžãã¹ããŒã«ããæ§æã§ããŸãã ãããéå±€ã®æäžå±€ã«ã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ããããŸãã

ã¢ããªã±ãŒã·ã§ã³ããŒã« 㯠IT æ
åœè
ã«ãã£ãŠäœæãããŸãã
ãã㯠Active Directory accountãActive Directory group "files-int"ãDMS access to internal files (read-write)ãCRM account with access to customer database ãªã©ã® æè¡ç æŠå¿µã衚ããŸãã
ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ããŒã«éå±€ã®æ§æèŠçŽ ã§ãã
æšå¥šãããæ¹æ³ã¯ãã¢ããªã±ãŒã·ã§ã³ããŒã«ãããã衚ããã®ã«ãçµã³ä»ããããããšã§ãã ããšãã°ããã¹ãŠã® Active Directory ã°ã«ãŒããåã蟌ã¿ãåã°ã«ãŒãããã¢ããªã±ãŒã·ã§ã³ããŒã«ãäœæã§ããŸãã ããã«è¯ãã®ã¯ãActive Directory ã°ã«ãŒããã¢ããªã±ãŒã·ã§ã³ããŒã«ã®ãå°åœ±ããšããŠäœæããããšã§ãã IT æ åœè ã IGA ã·ã¹ãã ã§ã¢ããªã±ãŒã·ã§ã³ããŒã«ãäœæãããã®åŸ IGA ã·ã¹ãã ã Active Directory ã«å¯Ÿå¿ããã°ã«ãŒããäœæããŸãã ããã¯ã°ã«ãŒãã«å¯Ÿããã¬ããã³ã¹ãç¶æç®¡çããè¯ãæ¹æ³ã§ããããšãã°ããã¹ãŠã®ã°ã«ãŒãã«è²¬ä»»è ãæåãããŠããããšãä¿èšŒã§ããŸãã æ®å¿µãªãããã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ããŸãã«é »ç¹ã«æåã§ç¶æç®¡çãããŠãããåŽåéçŽçã§ã誀ãã®äœå°ã倧ããæ®ããŸãã
ããžãã¹ããŒã« ã¯æ¥åéšéã®æ
åœè
ã«ãã£ãŠäœæãããã¹ãã§ãã
ããã¯ç¹å®ã®è·åãè·åäžã®äœçœ®ä»ããæ¥åããã»ã¹ãã¯ãŒã¯ã°ã«ãŒã掻åã«å¿
èŠãªè²¬ä»»ãªã©ã® æ¥å æŠå¿µã衚ããŸãã
äŸãšã㊠Marketing ManagerãBranch SupervisorãClaim ReviewerãInnovation Task Force Member ããããŸãã
ããžãã¹ããŒã«ã¯éåžž è€åç ã§ãããã¢ããªã±ãŒã·ã§ã³ããŒã«ãŸãã¯ä»ã®ããžãã¹ããŒã«ããäœãããŸãã
ããžãã¹ããŒã«ãæ§ç¯ããæ¹æ³ã¯ããã€ããããŸãã å€å žçãªæ¹æ³ã¯ããŒãããŒã¹ã§ããžãã¹ããŒã«ãäœæããããšã§ãã ããã«ã¯ãåã ã®è·åãè·åäžã®äœçœ®ä»ããããŒã ã®è²¬ä»»ã®æ¥ååæã掻åãéè¡ããããã«å¿ èŠãªæš©é/æš©éã®åœ¢åŒç仿§åãæš©éã®ããžãã¹ããŒã«ãžã®ã°ã«ãŒãåãå«ãŸããŸãã ããã¯ããªãæ£ç¢ºãªæ¹æ³ã§ãããéåžžã¯éåžžã«é ããéå±ã§åŽåéçŽçã§ãã ä»ã®æ¹æ³ã¯ãæ¢åããŒã¿ããããžãã¹ããŒã«å®çŸ©ãçºèŠãŸã㯠ãã€ãã³ã° ããããšã«çŠç¹ãåœãŠãŸãã ãã®æ¹æ³ã¯å®å šã«æ£ç¢ºã§ã¯ãããŸããããã¯ããã«éãçµæãæäŸã§ããŸãã çŸå®äžçã®å®åã§ã¯äž¡æ¹ã®æ¹æ³ãçµã¿åãããããšããããããŸãã
å Žåã«ãã£ãŠã¯ãã¢ããªã±ãŒã·ã§ã³ ãš æ¥å ããŒã«ã ãã§ãªããããã«å€ãã®ããŒã«çš®é¡ããããŸãã ä»ã®ããŒã«ã¯ãã£ãšå°ãªããã®ã®ãæã 䜿ãããŸãã äžã®è¡šã¯ããŒã«çš®é¡ããŸãšãããã®ã§ãã
| ããŒã«çš®é¡ | 説æ | å 容 | ãŠãŒã¶ãŒã«å²ãåœãŠãã¹ãã? | äŸ |
|---|---|---|---|---|
| ã¢ããªã±ãŒã·ã§ã³ããŒã« | åäžã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹æš©ã説æããããŒã«ã§ããéåžžãã¢ããªã±ãŒã·ã§ã³ã°ã«ãŒããæš©éãããŒã«ãªã©ãã¢ããªã±ãŒã·ã§ã³å
ã®ç¹å®ã® entitlement ã1ã€è¡šããŸããç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã«çµã³ä»ããããŠããŸã (ãã®ãããã®ååã§ã)ã ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ããšã³ã¿ã€ãã«ã¡ã³ãã®åã蟌ã¿/åæã«ãã£ãŠèªåäœæãããããšããããããŸããããšãã° Active Directory ã°ã«ãŒãã®åã蟌ã¿ã§ãã |
åäžã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ã | ãããã ãã ããããªãé »ç¹ã«ãŠãŒã¶ãŒã«å²ãåœãŠãããŠããŸãã |
Active Directory Domain Administrators äŒç€Ÿ Web ãµã€ã Editors ããŒã¿ããŒã¹ foo èªã¿åãå°çšã¢ã¯ã»ã¹ |
| æè¡ããŒã« IT ããŒã« |
è€æ°ã®ã¢ããªã±ãŒã·ã§ã³ããŒã«ãŸãã¯äœã¬ãã«ã®æš©éãã管çãããã1ã€ã®åäœã«çµã¿åãããŸããããšãã°ããŒã¿ããŒã¹ç®¡çãè¡ãããã«ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¢ã¯ã»ã¹ãå¿ èŠãªå Žåãªã©ãäºãã«äŸåããã¢ããªã±ãŒã·ã§ã³ããŒã«ã«ãã䜿ãããŸããã¢ããªã±ãŒã·ã§ã³ããŒã«ãšããžãã¹ããŒã«ã®äžéã«ãããã®ãšèããããŸããè€æ°ã®ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹æš©ãäžãåŸãããã¢ããªã±ãŒã·ã§ã³ããŒã«ã§ã¯ãããŸããããŸãå®å šãªæ¥å責任ã説æãããéåžžã«æè¡çã§æ¥åéšéã«åããããããšã¯èšããªãçšèªã䜿ãããšãå€ããããããžãã¹ããŒã«ã§ããããŸãããç¬èªã®çš®é¡ã§ããããŸãé »ç¹ã«ã¯äœ¿ãããŸããã | äºãã«äŸåããããŸãã¯äžç·ã«æå³ãæã€ããã€ãã®ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ã | äŸå€çãªå Žåãããšãã°éåžžã«ç¹æ®ã§è€é㪠IT 責任ã | ããŒã¿ããŒã¹ bar 管çïŒOS ã¢ã¯ã»ã¹ä»ãïŒããã¯ã¢ãã/ãªã¹ãã¢ç®¡ç |
| èªå¯ããŒã« | ãããå®çŸ©ãããã·ã¹ãã å éšã®èªå¯ãŸãã¯æš©éãæäŸããŸããIGA ãã©ãããã©ãŒã ã§ã¯ããã©ãããã©ãŒã èªèº«ã®äžéšãžã®ã¢ã¯ã»ã¹ãæäŸããããŒã«ã§ããèªå¯ããŒã«ã¯ä»ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãä»äžããŸããã | èªå¯æ (ä»äž)ã | ãããã ãã ãå°å ¥ã®åææ®µéã§ããžãã¹ããŒã«ããŸã åå圢æãããŠããªãå Žåãäžéšã®ããŒã«ããŠãŒã¶ãŒã«å²ãåœãŠãããããšããããŸããç¹ã«ã¹ãŒããŒãŠãŒã¶ãŒããŒã«ã§ãã |
Superuser ããŒã«IGA ãã©ãããã©ãŒã å éšã® Approver ããŒã« |
| ããžãã¹ããŒã« | æ¥åè²¬ä»»ãæ¥åããã»ã¹å ã®æ©èœãæ¥åé¢é£ã®è·åäžã®äœçœ®ä»ãããŸãã¯é¡äŒŒã®æ¥åæŠå¿µã衚ããŸããããžãã¹ããŒã«ã¯ãããå°ããªãèŠçŽ çãªãããŒã«ã®çµã¿åããã§ããããšãæ³å®ãããŠããŸãã | ä»ã®ããžãã¹ããŒã«ãå«ããä»»æã®ããŒã«çš®é¡ã | ã¯ã | ClerkBranch SupervisorMarketing AssistantCall Center Operator |
ããŒã«éå±€
RBAC ã¯éå±€çã§ããããŒã«ã®äžã«ããŒã«ãååšã§ããŸãã IGA ã«é¢ããŠã¯ãã»ãŒãã¹ãŠã®ããŒã«æ§é ã¯æè¡çã«ã¯éå±€çã§ãã éå±€ã®æäžå±€ã«ã¯ ã¢ããªã±ãŒã·ã§ã³ ããŒã«ããããŸãã ããžãã¹ ããŒã«ã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ããæ§ç¯ãããŸãã ããã¯æè¡çã«ã¯ããŒã«éå±€ã§ãããRBAC ã¢ãã«ãæå³ããããŒã«éå±€ã®å¹æãæã€ãšã¯éããŸããã
éå±€ã®å®å
šãªå¹æã¯ãããžãã¹ããŒã«ãä»ã®ããžãã¹ããŒã«ã®äžã«çœ®ããããšãã«åŸãããŸãã
ããšãã° Sales Manager ããŒã«ã¯ Sales Agent ããŒã«ãå«ã¿ããšãŒãžã§ã³ãã®ãã¹ãŠã®æš©éããããŒãžã£ãŒã®æš©éã«å«ããããŸãã
ãã®æ¹æ³ã¯ãçè«äžããŒã«ç¶æç®¡çãæžãããŸãã
Sales Agent æš©éã倿Žããå Žåããã®å€æŽã¯ Sales Manager ã®æš©éã«ãèªåçã«é©çšãããŸãã
ããããã®å¹æã¯ãããŒã«éå±€ãããæ§ç¯ãããããŒã«éè€ã誀çšãé¿ããŠããå Žåã«ã®ã¿åŸãããŸãã
ã¢ã¯ã»ã¹ç³è«ããã»ã¹
çæ³çã«ã¯ãããŒã«ã¯ãŠãŒã¶ãŒã«èªåçã«å²ãåœãŠãããã¹ãã§ãã ããžãã¹ããŒã«ã¯æ¥åæŠå¿µã«å¯Ÿå¿ããããšãæ³å®ãããŠããŸãã ãããã£ãŠãå€åå°ãè·åã³ãŒãããããžã§ã¯ãã¡ã³ããŒã·ãããªã©ã®ãŠãŒã¶ãŒå±æ§ã«åºã¥ããŠããžãã¹ããŒã«ãèªåå²ãåœãŠãã®ã¯ç°¡åã§ããã¹ãã§ãã ãããå®è·µçãªé害ããããŸãã è·åã³ãŒããå€åå°ã¯å©çšã§ããªãããããããæ£ç¢ºã§ã¯ãªããããããŸããã åæ§ã®åé¡ã¯ä»ã®æ¥åããŒã¿ã«ãé©çšãããå¯èœæ§ããããŸãã å šäœçãªããŒã¿å質ãäœãããŠããã®ãããªèªååãã§ããªãå ŽåããããŸãã ãŸããé¢é£ããæ¥åæŠå¿µããã¹ãŠããžãã¹ããŒã«ã§ã«ããŒãããŠãããšã¯éããŸããã ããã«ãæ¥å ããŒã¿ (å€åå°ãè·åã³ãŒããªã©) ãšæ¥å ããŒã« ã®å¯Ÿå¿ä»ããæããã§ã¯ãªãå ŽåããããŸãã èšãæãããšããŠãŒã¶ãŒãã©ã®ã¢ã¯ã»ã¹æš©ãæã€ã¹ãããæ¬åœã«ç¥ã£ãŠãã人ãããŸããã ãã®èª²é¡ã¯å®éããªãäžè¬çã§ãã
å®è·µç㪠IGA å°å ¥ã§ã¯ããã°ãã° ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã«é ŒããŸãã ããã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
-
ãŠãŒã¶ãŒãããŒã«ã ç³è« ããŸãã IGA ã·ã¹ãã ã¯ããŒã«ç³è«ã®ããã®å°çšã®ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ãæäŸããŸãã ãŠãŒã¶ãŒã¯ role ã«ã¿ãã° ããããŒã«ãéžæããŸãã
-
ç³è«ã æ¿èª ã«éä¿¡ãããŸãã
-
ããŒã«ããŠãŒã¶ãŒã« å²ãåœãŠ ãããŸãã ã¢ã¯ã»ã¹ãããããžã§ãã³ã°ãããæš©éãä»äžãããŸãã
ããã¯å€ãã® variation ãæãŠãæ±çšããã»ã¹ã§ãã ãŠãŒã¶ãŒãèªåèªèº«ã®ããã«ããŒã«ãç³è«ããå Žåãããã°ããããŒãžã£ãŒããŠãŒã¶ãŒã® behalf ã§ããŒã«ãç³è«ããå ŽåããããŸãã æ¿èªæé ã¯ è€æ°æ®µé ã«ãªãåŸãŸããããšãã° ã©ã€ã³ãããŒãžã£ãŒãšã¢ããªã±ãŒã·ã§ã³ææè ã®æ¿èªãå¿ èŠã§ãã High-privilege ããŒã«ã¯ã»ãã¥ãªã㣠office ã«ãã additional æ¿èªãå¿ èŠãšããå ŽåããããŸãã
çæ³çãªã±ãŒã¹ã§ã¯ãrole ã«ã¿ãã° ã¯éžææžã¿éåã® æ¥å ããŒã«ã ããå«ãã¹ãã§ãã ãããã«ã¿ãã°ã¯éåžžããã¹ãŠã®ããžãã¹ããŒã«ãšãã¢ããªã±ãŒã·ã§ã³ ããŒã«ãå«ãã§ããŸãã ããŸãã«å€ãã®çµç¹ã¯ãŠãŒã¶ãŒãã©ã®ã¢ã¯ã»ã¹ãæã€ ã¹ã ããç¥ããŸããããããéåžž ã¢ã¯ã»ã¹ç³è« ããã»ã¹ãå°å ¥ãã䞻㪠motivation ã§ãã ãŠãŒã¶ãŒãã©ã®ã¢ã¯ã»ã¹æš©ãæã€ã¹ããã誰ãç¥ããªããšããããšã¯ãããžãã¹ããŒã«ãã©ã®ãããªå§¿ã§ããã¹ããã誰ãç¥ããªãããšãæå³ããŸãã ãã®ãããŠãŒã¶ãŒã¯ä»£ããã«ã¢ããªã±ãŒã·ã§ã³ããŒã«ãç³è«ããŸãã ãã®æ¹æ³ã¯ããŸãã«ãäžè¬çã§ãã ãã®ãããªããã»ã¹ã¯æ£ãããããŸããããã¹ããã©ã¯ãã£ã¹ã«åããåžžèã«ãåããŸãã ããããäœããã® åäœç³»ç㪠ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãé©çšããå¯äžçŸå®çãªããã»ã¹ã§ããããšãå€ãã§ãã
èŠç¹ã¯ãã¢ã¯ã»ã¹ç³è« ããã»ã¹ããã°ãã° over-provisioningãã€ãŸããŠãŒã¶ãŒãå¿ èŠãšãã以äžã®ã¢ã¯ã»ã¹ãä»äžããããšã«ã€ãªããç¹ã§ãã ãã®åé¡ã®çç±ã¯ããªãæããã§ãã ã¢ã¯ã»ã¹ãåŸãã®ã¯éåžžã«ç°¡åã§ãã¢ã¯ã»ã¹ã åé€ãã motivation ã¯ãããŸããã Over-provisioning ã¯éåžž èªå® æ©æ§ã§å¯ŸåŠãããŸãã ç°¡åã«èšãã°ãèªå®ã¯è²¬ä»»è ãããŠãŒã¶ãŒãç³è«ããã¢ã¯ã»ã¹ãä»ãå¿ èŠãšããŠããããšã ç¢ºèª ããªããã°ãªããªãããã»ã¹ã§ãã äžè¬çãªæ¹æ³ã¯ã宿çã«ã¢ã¯ã»ã¹ã確èªãã certification campaign ãèšå®ããããšã§ã (äŸ: 幎1å)ã
ããŒã«ã¬ããã³ã¹
ããŒã«ãå®çŸ©ããå®çšç㪠RBAC ã¢ãã«ãäœæããããšã¯ç°¡åãªäœæ¥ã§ã¯ãããŸããã ãããããã®ã¢ãã«ãè¯å¥œã«åãç¶æ ã§ maintain ããããšã¯ããã«å°é£ã§ãã
ç§ãã¡ãåãå·»ãäžçã¯åžžã«å€åããŠããŸãã çµç¹ãå€åãããŠãŒã¶ãŒã®è·åãšè²¬ä»»ãå€åããŸãã ã¢ããªã±ãŒã·ã§ã³ã¯ upgrade ãããæ°ããã¢ããªã±ãŒã·ã§ã³ãå°å ¥ãããå€ãã¢ããªã±ãŒã·ã§ã³ã¯å»æ¢ed ãããŸãã Re-organizationãmergerãspin-offã倿°ã® unforeseen 倿ŽããããŸãã RBAC ã¢ãã«ã¯ããŒã«å®çŸ©ãæŽæ°ããé©å¿ããªããã°ãªããŸããã
ããŒã«ç®¡çã¯éäžåãããã«ããŠãRBAC ã¢ãã«ç¶æç®¡çã®è²¬ä»»ãåäžããŒã ã«çœ®ãããšãã§ããŸãã ãã®æ¹æ³ã¯ããªãæããã§ãããããªãééã£ãŠããŸãã RBAC ã¢ãã«ã¯ãããŒã«å®çŸ©ãããã衚ããã®ã« align ããŠãããšãã«æãããæ©èœããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ã¢ããªã±ãŒã·ã§ã³æš©éã« align ããããžãã¹ããŒã«ã¯æ¥åå¿ èŠæ§ã« align ãã¹ãã§ãã éåžžã« rare ãªã±ãŒã¹ãé€ããçµç¹å šäœã«ããã IT ã® intricacy ãšæ¥åè€éæ§ã®äž¡æ¹ã cover ã§ããåäžããŒã ã¯ååšããŸããã
å®è·µçãªæ¹æ³ã¯ãããŒã«ç®¡çåŽåã distribute ããããšã§ãã
ã¢ããªã±ãŒã·ã§ã³ããŒã« 㯠IT éšé ã«ãã£ãŠç®¡çãããã¹ãã§ãã ããã㯠IT äžã®æŠå¿µã« align ãã¹ãã§ãã çæ³çã«ã¯ãã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯èªåãŸãã¯åèªåã§ç®¡çãããã¹ãã§ãã ããŒã«ã¯ã¢ããªã±ãŒã·ã§ã³ãšã³ã¿ã€ãã«ã¡ã³ãããèªåçã«åæã§ããŸããããšãã° Active Directory ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ Active Directory ã°ã«ãŒãããèªåäœæã§ããŸãã éæ¹åãçŸå®çã§ããIGA ãã©ãããã©ãŒã ã§æ°ããã¢ããªã±ãŒã·ã§ã³ããŒã«ãå®çŸ©ããããšãActive Directory ã°ã«ãŒããèªåçã«äœæãããŸãã ã©ã¡ãã«ãããã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ IT domain ã§ãããèªååãããç¶æç®¡çã®è¯ãåè£ã§ãã
ããžãã¹ããŒã« ã¯æ¥ååäœã«ãã£ãŠç®¡çãããã¹ãã§ãã ããžãã¹ããŒã«ã¯æ¥åæŠå¿µã説æãããããæ¥åéšéã®æ åœè ã«ãã£ãŠç®¡çãããã¹ãã§ãã ããŒã«ãå®çŸ©ããæŽæ°ãç¶ããããã«ãæ¥åã®æŠå¿µãšå¿ èŠæ§ãååã«ç¥ã£ãŠããã®ã¯æ¥åéšéã®æ åœè 以å€ã«ããŸããã æ¥åãš IT ã® ååäœæ¥ãšããŠããžãã¹ããŒã«ãç¶æç®¡çããããšã¯å¯èœã§ãããæ¥åéšéã®æ åœè ã® engagement 㯠crucial ã§ãã
ã¢ããªã±ãŒã·ã§ã³ããŒã«ãšç°ãªããããžãã¹ããŒã«ã®ç¶æç®¡çãèªååããããšã¯éåžžã«å°é£ã§ãã ç¹ã«ããŒã«å®çŸ©ãæŽæ°ã«ä¿ã€ã«ã¯å€ãã®åŽåãå¿ èŠã§ãã éåžžã®å®åã¯ãç¹ã«ããžãã¹ããŒã«ã«å¯Ÿã㊠role owner ãå²ãåœãŠãããšã§ãã ããŒã« owner ã¯ããŒã«å®çŸ©ã«è²¬ä»»ãæã€äººç©ã§ãã ããžãã¹ããŒã«ã®å ŽåãããŒã«ææè ã¯éåžžããã®ããŒã«ãé¢é£ããè·åãŸãã¯ããã»ã¹ã«è²¬ä»»ãæã€æ¥å人ç©ã§ãã æ¥åå¿ èŠæ§ãå€ãããã³ã«ãããŒã«ææè ãããŒã«å®çŸ©ãæŽæ°ããããšãæåŸ ãããŸãã å€ãã® IGA ãã©ãããã©ãŒã ã¯ãIGA ãã©ãããã©ãŒã èªäœã®äžã§ããŒã« owner ãæå®ã§ããŸãã
ããŒã«ææè 㯠æ¥å ããŒã«ã®ç¶æç®¡çã«äžå¯æ¬ ã§ãã ããããç¹ã«ã¢ããªã±ãŒã·ã§ã³ããŒã«ããŠãŒã¶ãŒã«çŽæ¥å²ãåœãŠãããããšãå€ãå Žåãã¢ããªã±ãŒã·ã§ã³ ããŒã«ã«ã owner ãå¿ èŠãªå ŽåããããŸãã
Owner ãšåæ§ãIGA ã·ã¹ãã ã¯éåžžããŒã« approver ã®ä»æ§åãèš±å¯ããŸãã æ¿èªè 㯠ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã«ãããããŒã«ç³è«ã®æ¿èªã«è²¬ä»»ãæã€äººç©ã§ãã
RBAC ããªã·ãŒ
ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ (RBAC) ã¢ãã«ã¯1990幎代ãã2000幎代ã«åœ¢äœãããŸããã ããã RBAC ã®ãåŸæ¥ã®ããªåœ¢ã§ãã ãã® RBAC ã®åœ¢åŒã¯å®å šã« éç ã§ãã ããŒã«å²ãåœãŠã¯éçãããŒã«å ã®æš©ééåã¯éçãã¢ãã«ã«ãã£ãŠä»äžãããã¢ã¯ã»ã¹ã¯ç®¡çè ãæåã§å€æŽããªãéãå€ãããŸããã ãã®æ¹æ³ã¯2000幎代ã«ã¯æçšã ã£ããããããŸããã ããã20幎åŸã®çŸåšãç§ãã¡ã¯éåžžã«åçãªäžçã«ããŸãã éçã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ã¯ãã¯ãããŸãããŸãæ©èœããŸããã éç RBAC ã¢ãã«ã«ã¯ãããŒã«ççº ãããŒã« abuse ãªã©å€æ°ã®åé¡ããããŸãã

ãã¹ãŠã®æ¬ ç¹ã«ãããããããåŸæ¥ã®ãª éç RBAC ã¢ãã«ã¯æãä»ãããªãåºã䜿ãããŠããã ãããéç RBAC ã¯ããã® inception çŽåŸããã»ãŒæ¹å€ãããŠããŸããã ãã® critique ã®çµæã2000å¹Žä»£ã®æ©ãææãããRBAC ãããåçã«ããæ©æ§ãå°å ¥ãããŸããã åœæã®äžéšã®ã¢ã€ãã³ãã£ãã£ç®¡çã·ã¹ãã ã¯ãåçŽã«ãŒã«ã«åºã¥ããŠãŠãŒã¶ãŒã«ããŒã«ãåçã«å²ãåœãŠãããšããµããŒãããŠããŸããã ããããã®æ©èœã¯ãŸã ããªã rare ã§ããã ã¢ã€ãã³ãã£ãã£ç®¡çã·ã¹ãã ã¯2010å¹Žä»£ã«æçããã¢ã€ãã³ãã£ãã£ã¬ããã³ã¹ããã³ç®¡ç (IGA) ã·ã¹ãã ãšããŠç¥ãããããã«ãªããŸããã çŸåšãå€ãã® IGA ãã©ãããã©ãŒã ã«ã¯åç RBAC ã®å°ãªããšã partial ãµããŒããå«ãŸããŠããŸãã ãããåã ã®è£œåã®æ©èœã«ã¯äŸç¶ãšããŠå€§ããªå·®ããããåçæ©èœã¯ IGA åéã®å€ã§ã¯ããŸãåºã䜿ãããŠããããã§ã¯ãããŸããã ããã§ãåç RBAC æ¹æ³ã¯ãéç RBAC ã ãã§ãªããABAC ã PBAC ãªã©ä»ã®ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ã«å¯ŸããŠãå€ãã® advantage ãæäŸããŸãã 2020幎代ã®çŸåšãåç RBAC æ©èœã¯ãè€éãªã¢ã¯ã»ã¹å¶åŸ¡èŠä»¶ãå¹ççã«æ±ããããã©ã® IGA ãã©ãããã©ãŒã ã«ãšã£ãŠã絶察ã«äžå¯æ¬ ã§ãã

åç RBAC ãžã®æãå®è·µçã§æè»ãªæ¹æ³ã®1ã€ã¯ãmidPoint IGA ãã©ãããã©ãŒã ã«å®è£ ãããŠãã Policy-Driven RBAC ã§ãã Policy-driven RBAC ã¯3ã€ã®ã¬ãã«ã§ æè»æ§ ãæäŸããŸãã
-
åçãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã ãŠãŒã¶ãŒãžã®ããŒã«å²ãåœãŠ (ããã³ unassignment) ã¯ã«ãŒã«ã§å¶åŸ¡ã§ããŸãã Rule ã¯éåžžãè·åã³ãŒããå€åå°ãªã©ã®ãŠãŒã¶ãŒå±æ§ãæ±ããŸãã ãŠãŒã¶ãŒå±æ§ã«ä¿åãããæ¥åããŒã¿ã«åºã¥ããŠãããŒã«ããŠãŒã¶ãŒã«åçãã€èªåçã«å²ãåœãŠã§ããŸãã
ããã« midPoint ã§ã¯ãããŒã«ã çµç¹æ§é ã«çŽæ¥ link ã§ããŸãã ãã®å Žåãçµç¹äžã®åäœãããŒã ããããžã§ã¯ãã®ã¡ã³ããŒã·ããã¯ãç¹å®ã®ããŒã«ãŸãã¯æš©éãèªåçã« imply ããŸãã
åçãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã¯ãããŒã«å²ãåœãŠã®ããªãã®éšåã管çè ã® æç€ºçãªå¯Ÿå¿ãªãã«èªå管çã§ãããããRBAC 管çè² æ ã倧ããæžãããŸãã
-
ãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠãã©ã¡ãŒã¿ãŒsã ãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã¯åŸæ¥ã® RBAC ã®ãããªåçŽãª äºé é¢ä¿ ã§ã¯ãããŸããã ãã㯠parametrized ã§ãã rich ããŒã¿æ§é ã§ãã ããšãã°å²ãåœãŠã¯ãlimited æé period ã®éã ãã¢ã¯ã»ã¹ãæäŸããããŸãã¯ã¢ã¯ã»ã¹ãç¹å®çµç¹ã« limit ãããã parametrized ã§ããŸãã midPoint ã® é¢ä¿ ãã©ã¡ãŒã¿ãŒã®ãããªç¹æ®ãªãã©ã¡ãŒã¿ãŒã¯ããŠãŒã¶ãŒãšããŒã«ã® é¢ä¿ ãæ±ºå®ããããã«äœ¿ããŸãã ããã«ãããéåžžã®ããŒã«ã¡ã³ã㌠ãšããŒã«ææè ããªãœãŒã¹ãžã®èªã¿åãå°çšã¢ã¯ã»ã¹ãš èªã¿æžãã¢ã¯ã»ã¹ãªã©ãåºå¥ã§ããŸãã
ããã« midPoint ã§ã¯ãããŒã«ãšåæ§ã®æ©èœãæã€ä»ã®ãªããžã§ã¯ãçš®é¡ã«ãå²ãåœãŠã§ããŸãã ããšãã° çµç¹äžã®åäœ ã¯ãéšéãããŒã ããããžã§ã¯ãã«æäŸãããã¢ã¯ã»ã¹ãçŽæ¥ã¢ãã«åã§ããé¢ä¿ ãã©ã¡ãŒã¿ãŒã䜿ã£ãŠããŒã member ãšãããŒãžã£ãŒã®ã¢ã¯ã»ã¹ãåºå¥ã§ããŸãã ããã« ãµãŒãã¹ ã®æŠå¿µã¯ã¢ããªã±ãŒã·ã§ã³ãã¢ãã€ã«ããã€ã¹ãAPIãé¡äŒŒ entity ãã¢ãã«åã§ãããããã¯ãã¹ãŠããŒã«ã®ããã« behave ããŸãã
Parametric ããŒã«å²ãåœãŠã¯ ããŒã«ççº åé¡ãšæŠãéåžžã«å¹ççãªããŒã«ã§ãã å²ãåœãŠãã©ã¡ãŒã¿ãŒã§åºå¥ããããšã«ãããåäžããŒã«ãããŸããŸãª circumstance ã§äœ¿ããŸãã åŸæ¥ã® RBAC ãå€ãã®ããŒã«ãå¿ èŠãšããå Žæã§ãpolicy-based RBAC ã¯1ã€ã ãã§æžã¿ãŸãã
-
åçããŒã«æš©éã ããŒã«ã¯ãã¯ãéçãªæš©ééåã ãã§ã¯ãããŸããã éçæš©ééåãåŒãç¶ã䜿ããŸãããåç expression ã䜿ã£ãŠæš©éãæ±ºå®ãã additional æ©æ§ããããŸãã ãã®ãããªåŒã¯ããŠãŒã¶ãŒãããŒã«ãããŒã«ãšãŠãŒã¶ãŒã®å²ãåœãŠãè©äŸ¡ context ãããã©ã¡ãŒã¿ãŒãååŸããŸãã Parameter ã¯ãããŒã«ã«ãã£ãŠä»äžãããæš©éãæ±ºå®ããããã«äœ¿ãããŸãã ããã¯éåžžå²ãåœãŠãã©ã¡ãŒã¿ãŒã«åºã¥ããŠãããŸããŸãª situation ãæ±ºå®ããå¹ççæ©æ§ã§ãã ããšãã°åŒã䜿ã£ãŠãéåžžã®ããŒã«ã¡ã³ã㌠ã«ã¯ããæš©éããããŒã«ææè ã«ã¯å¥ã®æš©éãä»äžã§ããŸãã ããã«äžè¬çãªã±ãŒã¹ã¯ãlocation ãã©ã¡ãŒã¿ãŒã䜿ã£ãŠæš©éãç¹å®ã® ç©çå€åå°ãŸãã¯åœã«ã ãå¶é ããåŒã§ãã
ããã« midPoint ã§ã¯ãåŒã䜿ã£ãŠ midPoint ã provision ããã¢ã«ãŠã³ãã®ãšã³ã¿ã€ãã«ã¡ã³ããšå±æ§ãèšå®ã§ããŸãã ããšãã°ãã°ã«ãŒãã® naming convention ã«åŸãã
foo-readerãfoo-writerãfoo-adminã®äžããé©åãªã°ã«ãŒããèªåéžæããããããã°ã©ã ã§ããŸãããããã¯ãã¹ãŠåäžããŒã«ã§æ±ãããŸãã MidPoint ã¯çµç¹äžã®åäœãããŒã«ãšããŠæ±ãããããã®æ©æ§ã䜿ã£ãŠãè€éããªã·ãŒå®çŸ©ãå¿ èŠãšããã«ãããžã§ã¯ã member ãšãããŒãžã£ãŒã®ã¢ã¯ã»ã¹ãåºå¥ã§ããŸãã å¯èœæ§ã¯ã»ãŒç¡éã§ããåçããŒã«åŒã¯ãABAC ã PBAC ã®ãããªåçã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ãšéåžžã«äŒŒãæ©èœãæäŸããŸãã ããã policy-based RBAC ã¯ãRBAC ã®å¹æã®å€§åãç¶æããŸãã ããªã·ãŒã¯ããŒã«ã«ãããã«åå²ããããã®äžã« encapsulated ãããŸãã å€ãã®ããŒã«ã¯ä»ãã independent ã«ç¶æç®¡çã»æŽæ°ã§ãããããABAC/PBAC ã¢ãã«ã«äžè¬çãªããªã·ãŒç¶æç®¡çæªå€¢ãæžãããŸãã
Policy-driven RBAC 㯠RBAC æŠå¿µã®èªç¶ãª evolution ã§ãã Traditional éç RBAC ã¢ãã«ã®åé¡ã«å¯ŸåŠããªãããRBAC ã® advantage ãåŒãç¶ãæäŸããŸãã åçã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ã® æè»æ§ ã RBAC world ã«æã¡èŸŒã¿ãŸãã
ããŒã«ãšã³ãžãã¢ãªã³ã°
çµç¹ããŒã«ãšã³ãžãã¢ãªã³ã°
NOTE: ãã®ç¯ã§æäŸãããæŠå¿µã®å€§åã¯ãorganizational ããŒã«ãšã³ãžãã¢ãªã³ã° ã«é©çšãããŸããã€ãŸããšã³ã¿ãŒãã©ã€ãºãacademiaãæ¿åºã«ããã åŸæ¥å¡ãstudentãã¹ã¿ãããcontractor ãªã©ã®çµç¹äžã®ã¢ã€ãã³ãã£ãã£ã®ããã®ããŒã«ãšã³ãžãã¢ãªã³ã° ã§ãã Customerãbusiness partnerãcitizen ã¢ã€ãã³ãã£ãã£ã«ã¯å®å šã«ã¯é©çšã§ããªãå ŽåããããŸãã ãã®ãããªã¢ã€ãã³ãã£ãã£ã«ã¯ã倧éã®ã¢ã€ãã³ãã£ãã£ãããåçŽã§æ¢ç¥ãã€äžè²«ããŠé©çšãããããªã·ãŒãªã©ãç¹å®ã® characteristic ããããŸãã ãã®ãããªç°å¢ã«ã¯ãä»ã®æ¹æ³ã®æ¹ãé©ããŠããå¯èœæ§ããããŸãã IGA ã« silver bullet ã¯ãããŸããã
ããŒã«ãšã³ãžãã¢ãªã³ã° ã¯ãRBAC ã¢ãã«ãäœæã»ç¶æç®¡çããããã»ã¹ã§ãã ããŒã«ã®äœæãšæŽæ°ããããŠé¢é£ãããã¹ãŠã®ã«ãŒã«ãšããªã·ãŒã®äœæã»æŽæ°ãäžå¿ã§ãã å³å¯ã«èšãã°ããŠãŒã¶ãŒãžã®ããŒã«å²ãåœãŠã¯ããŒã«ãšã³ãžãã¢ãªã³ã° ã®äžéšã§ã¯ãããŸããã ãããããŒã«ãšã³ãžãã¢ãªã³ã° ãšå¯æ¥ã«é¢é£ããŠãããããŒã«ãšã³ãžãã¢ãªã³ã° ããåé¢ããããšã¯éåžžã«å°é£ã§ãã
åºæ¬çã«ãããŒã«ãšã³ãžãã¢ãªã³ã° ã«ã¯2ã€ã®æ¹æ³ããããŸãã
- ãããããŠã³ æ¹æ³ ã¯æ¥åæŠå¿µããå§ããããããã现ããªããŒã«å®çŸ©ãæçµçã«ã¯æš©éã«è¡šçŸããããšããŸãã ããšãã°ããŒã«ãšã³ãžãã¢ãªã³ã° ã¯çµç¹æ§é ãè·åãè·åäžã®äœçœ®ä»ããããã»ã¹ã®åæããå§ãŸããŸãã åã ã®è·åã®ããã« top-level ããžãã¹ããŒã«ãäœæãããããŒã«ã¯åã ã®è²¬ä»»ã«åå²ããããããã lower-level ããžãã¹ããŒã«ã圢æããŸãã Lower-level ããžãã¹ããŒã«ã¯æš©éã§æºããããŸã (éåžžã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ãéããŠéæ¥çã«)ã
- ããã ã¢ããæ¹æ³ ã¯æš©éããå§ããããããããŒã«ã«ã°ã«ãŒãåããããŒã«ãæ¥åæŠå¿µã« match ãããŸãã ããã»ã¹ã¯æš©éãéåžžã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ã®åœ¢ããå§ãŸããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ã°ã«ãŒãåãããIT/æè¡ããŒã«ãŸã㯠lower-level ããžãã¹ããŒã«ã圢æããŸãã äžäœã¬ãã«ããžãã¹ããŒã«ã¯ lower-level ããŒã«ãã圢æãããŸãã ããžãã¹ããŒã«ã¯è·åãè·åäžã®äœçœ®ä»ããçµç¹äžã®åäœãªã©ã®æ¥åæŠå¿µã«å¯Ÿå¿ä»ããããŸãã
ã©ã¡ãã®æ¹æ³ãå®åã§äœ¿ãããŠãããã©ã¡ãã«ã plus ãš minus ããããŸãã
ãããããŠã³ æ¹æ³ã¯ãæ¥ååæã®èгç¹ãããæ£ãããæ¹æ³ãšèªèããããã®ã§ãã 確ãã«ãåæãææ°ã§å®å šãªæ¥åããŒã¿ã«åºã¥ããŠããéãããããããŠã³æ¹æ³ã¯æ£ç¢ºã§ä¿¡é Œã§ããçµæãäžããåŸåããããŸãã ãããããŠã³ æ¹æ³ã¯çè«äžãover-provisioning ãªã©ãã¢ã¯ã»ã¹å¶åŸ¡å®åã«é ããå€ãã®èª²é¡ã uncover ã remedy ã§ããŸãã ããã ãããããŠã³æ¹æ³ã¯éåžžã«åŽåéçŽçã§ãã Top-tier æ¥åéšéã®æ åœè ã®éåžžã« intensive ãªååãå¿ èŠã§ãããããã確ä¿ããã®ã¯å°é£ã§ãã ãããããŠã³ æ¹æ³ã®é ãé«äŸ¡ãª progress ã¯éåžž é倧ãªé害ã§ãããå€§èŠæš¡ å©çšã§ã¯ å®è¡å°é£ ã«ãªãããšããããããŸãã
ããã«ãæ£ç¢ºæ¥åããŒã¿ãžã®äŸå㯠ãããããŠã³æ¹æ³ã®éèŠãªåé¡ã«ãªãåŸãŸãã ããŸãã«å€ãã®çµç¹ã§ãåŸæ¥å¡ãã©ã®ã¢ã¯ã»ã¹ãæã€ ã¹ã ããæ¬åœã«ç¥ã£ãŠãã人ã¯ããªãããšããã®ã¯å ¬ç¶ã®ç§å¯ã§ãã æ¥åããã»ã¹ãè·åã責任ã¯ååã«ææžãããŠããŸããã 圢åŒççµç¹æ§é 㯠real æ¥åå®åãš align ããŠããŸããã Combined ã§ temporary ãªè²¬ä»»ãæã€è·åäžã®äœçœ®ä»ããã«ãŒã«ã® exceptionãææžåãããŠããªã 管ç倿ã«ç±æ¥ããå®åãinformal communication back-channel ãªã©ã倿°ãããŸãã ãã®ãããªç°å¢ã§ã¯ããããããŠã³æ¹æ³ã¯å®¹æã« futile exercise ã«ãªããŸãã ãããããŠã³ æ¹æ³ã¯ãçŸå®äžçã®ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ã«å¿ èŠãª ææžåãããŠããªã intricacy ãèŠèœãšãããããããunder-provisioned ã¢ã¯ã»ã¹ã§çµããããšããããããŸãã
ã¢ã€ãã³ãã£ãã£ç®¡çã¯ãŒãããŒã¹ããå§ãŸãããã§ã¯ãããŸããã åžžã«æ¢åã® ããŒã¿ããããŸãã çµç¹ã¯æé·ããéãããªãã®æéã¢ã€ãã³ãã£ãã£ç®¡çã IGA ãã©ãããã©ãŒã ãªãã§éå¶ããªããã°ãªããŸããã§ããã ãŠãŒã¶ãŒãšã°ã«ãŒãã§ãã£ã±ãã® Active Directory ãããã§ãããã å€ãã® connected ã¢ããªã±ãŒã·ã§ã³ãæã€äžå€®LDAP ãã£ã¬ã¯ããªãµãŒããŒããããããããŸããã å€§èŠæš¡ãŠãŒã¶ãŒ baseãããŒã«ãæ¥åå¿ èŠæ§ã«åãããŠã«ã¹ã¿ãã€ãºãããããªã·ãŒãæã€æ¥åã¢ããªã±ãŒã·ã§ã³ããããããããŸããã äœããã®åœ¢ã§ãæš©éããšã³ã¿ã€ãã«ã¡ã³ããã¢ããªã±ãŒã·ã§ã³ã¢ã¯ã»ã¹ããã§ã«ããããžã§ãã³ã°ãããæ¢åãŠãŒã¶ãŒ base ãååšããŸãã ãã㯠IGA å°å ¥ã®é害ãã€ãŸãåã蟌ã¿ãããã»ã¹ãalign ããªããã°ãªããªãæ¢åç¶æ ãšèŠãªããããããããŸããã ããããã㯠advantage ã§ããããprecious ããŒã¿éåã§ããããŸãã æ¢åã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ã¯ (ã»ãšãã©ã®å Žå) æ¢åã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã«åºã¥ããŠããŸããã ããªã·ãŒã«é¢ããæ å ±ã¯ãŸã ããŒã¿ã®äžã«é ããŠãããçºèŠãããã®ãåŸ ã£ãŠããŸãã æ¢åããŒã¿ããããªã·ãŒæ å ±ãçºèŠããããšããããŒã«ãšã³ãžãã¢ãªã³ã° ã«ããã ããã ã¢ããæ¹æ³ã®åºæ¬èãæ¹ã§ãã
éåžžã®å®åã¯ãActive Directory ã LDAP ãªã©ã®äžå€®ãã£ã¬ã¯ããªãµãŒãã¹ããå§ããããšã§ãã ãã®ãããªã·ã¹ãã ã¯å€ãã®ã¢ããªã±ãŒã·ã§ã³ã® basis ãèªèšŒãœãŒã¹ãšããŠäœ¿ããããããéåžžããªãå®å šãªãŠãŒã¶ãŒããŒã¿ããŒã¹ãæã£ãŠããŸãã ãŸããapplication-specific æš©éã衚ãã°ã«ãŒããååšããå¯èœæ§ãéåžžã«é«ãã§ãã ã°ã«ãŒã㯠IGA ãã©ãããã©ãŒã ã«åã蟌ã¿ã§ããã¢ããªã±ãŒã·ã§ã³ããŒã«ãèªåäœæã§ããŸãã ãã®æ¹æ³ã«ã¯ããã€ãã®å¹æããããŸãã 第äžã«ãã¢ã¯ã»ã¹ç³è« ããã»ã¹ã® base ãæäŸããŸãã ã°ã«ãŒãã¡ã³ããŒã·ãããæåã§ç®¡çããå¿ èŠããªããªããŸãã ãŠãŒã¶ãŒã¯ ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã䜿ã£ãŠã¢ããªã±ãŒã·ã§ã³ããŒã«ã®ã¡ã³ããŒã·ãããç³è«ã§ããå®äºæã« Active Directory ãŸã㯠LDAP ã°ã«ãŒãã®ã¡ã³ããŒã·ãããä»äžãããŸãã 第äºã«ãã¢ããªã±ãŒã·ã§ã³ããŒã«ãžã®ãŠãŒã¶ãŒå²ãåœãŠã¯ bottom-up ããŒã«ãšã³ãžãã¢ãªã³ã° ã® starting ããŒã¿ãæäŸããŸãã æãã㪠åºçºç¹ ã¯åºã䜿ãããŠããã°ã«ãŒããã€ãŸã倿°ã® member ãæã€ã°ã«ãŒãã§ãã ããã¯ããªã·ãŒèªååã® prime candidate ã§ãã ã¡ã³ããŒã·ãã overlap 㯠é ãã ããªã·ãŒ fragment ã®è¯ã indicator ã§ãã 䌌ã member éåãæã€ã¢ããªã±ãŒã·ã§ã³ããŒã«ãæ¢ããŠãã ããããããã¯ããžãã¹ããŒã«ã« combine ã§ããå¯èœæ§ãé«ãã§ãã
ãããã¢ããªã±ãŒã·ã§ã³ããŒã«ã®åæãæäœæ¥ã§è¡ãããšã¯ããªãå°é£ã§ãã äžéšã® ãã¿ãŒã³ ãã¡ã³ããŒã·ãã overlap ã¯æããã§ããã倧åã¯ããã§ã¯ãããŸããã ããžãã¹ããŒã«ã¯ããŒã¿ãã mined ãããªããã°ãªããŸããã ããã€ãã® IGA ããŒã«ã¯ããã®ç®çã®ããã« role mining æ©æ§ãæäŸããŸãã Role mining ã¯éåžžãã¯ã©ã¹ã¿ãŒingããã¿ãŒã³ æ€ç¥ãããã«ã¯ é«åºŠãª æ©æ¢°åŠç¿ ã 人工ç¥èœ (AI) æ¹æ³ãªã©ãã¢ããªã±ãŒã·ã§ã³ããŒã«ã® é¡äŒŒæ§ ãæ€åºãã mathematical ã¢ã«ãŽãªãºã ã«åºã¥ããŸãã æ©æ§ã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ãåæããé¡äŒŒ æš©éã®ã°ã«ãŒããæ€åºããæ°ããããžãã¹ããŒã«ãææ¡ããŸãã
ããŒã«ãã€ãã³ã°æ©æ§ã¯éåžžã« useful ã§ãã ããã blind ã«äœ¿ã£ãŠã¯ãããŸããã ããŒã«ãã€ãã³ã°ã¯ã»ãŒåžžã« approximate ã§ãã Similar ãªæš©éãæã€ããŒã«ãããã»ã¹ããå ã®æš©éãå°ãå¢ããããæžããããããããžãã¹ããŒã«ãææ¡ããããšããããããŸãã ããã«ã¢ã«ãŽãªãºã ã«ã¯æ¥åæèã®æ å ±ããããŸããã ããŒã«ãã€ãã³ã°ã¯ãå€ãã®æš©éãšé«ã é¡äŒŒæ§ ãæã€ãŠãŒã¶ãŒãå«ãããžãã¹ããŒã«ã ææ¡ ãããããããŸããã ãããããã®ããŒã«ã¯å¶ç¶äŒŒãæš©éãæã€2ã€ã® independent ãŠãŒã¶ãŒã°ã«ãŒããæ··ããŠãããããããŸããããããæ·±ãããŒã«éå±€ã®æ¹ãé©åãããããŸããã ããŒã«ãã€ãã³ã°ã«ã¯åžžã« human ç£ç£ ãå¿ èŠã§ãã ããžãã¹ããŒã« ææ¡ ã¯ãæ¥åæèãèªèãããã® ææ¡ ãæ¥åãšçµç¹äžã® èŠ³ç¹ ããæå³ãæã€ã倿ã§ãã人ç©ã«ãã£ãŠèŠçŽãããªããã°ãªããŸããã ç°¡åã«èšãã°ã人工ç¥èœã¢ã«ãŽãªãºã ãè£ã natural ã€ã³ããªãžã§ã³ã¹ãšæè awareness ãå¿ èŠã§ãã
ããã ã¢ããæ¹æ³ã¯ãããªã·ãŒãå®å šã«ã¯ known ã§ãªãçŸå®äžçã® situation ã§éåžžéåžžã«å®è·µçã§ãã ããã ã¢ããæ¹æ³ã«ã¯ããã€ãã®å€§ã㪠advantage ããããŸãã ç¹ã«ããŒã«ãã€ãã³ã°æ©æ§ã䜿ã£ãŠããã»ã¹ã speed up ã§ããå Žåãéåžžã«çŸå®çãªæ¹æ³ã§ãã æ¢åã¢ã¯ã»ã¹å¶åŸ¡ããã»ã¹ (äŸ: ã¢ã¯ã»ã¹ç³è« ããã»ã¹) ãšäžŠè¡ããŠãåæ»ã§ ç¶ç¶ç ã«é©çšã§ããŸãã ãããããŠã³ æ¹æ³ãšç°ãªããããã ã¢ããæ¹æ³ã¯åœ¢åŒç㪠rubber-stamped 仿§åã§ã¯ãªããreal 㪠practical ããªã·ãŒãåæããŸãã ããã disadvantage ããããŸãã ããã ã¢ããæ¹æ³ã¯ approximate ã§ãªããã°ãªããŸããã Policy-based 倿ãããªã·ãŒ exceptionãå€ããªã£ãããªã·ãŒã«åºã¥ã倿ãªã©ãæ··åšããããŒã¿ãæ±ããŸãã Input ããŒã¿ã¯ clean ã§ã¯ãªããoutput ã perfect ã§ããããšã¯æåŸ ã§ããŸããã ããã ã¢ããæ¹æ³ã¯ status quo ã legalize ããåŸåããããããã¯éåžžéå°ããããžã§ãã³ã°ã¢ã¯ã»ã¹ãæå³ããŸãã Over-provisioning ã systemic ã ã£ãå Žåãããã ã¢ããæ¹æ³ã¯éå°ããããžã§ãã³ã°ã¢ã¯ã»ã¹ãããžãã¹ããŒã«ã«åæ ããŸãã ããã¯ããžãã¹ããŒã« ææ¡ ãèŠçŽãããæç¹ã§å¯ŸåŠã§ããŸãã ããããã®æç¹ã§ã¯éåžž priority ã§ã¯ãªããbroader æ¥åæèã known ã§ã¯ãªããããããŸããã ãããã£ãŠ bottom-up ããŒã«ãšã³ãžãã¢ãªã³ã° ã®åŸã«ã¯ãããŒã« consolidation ãš ã¯ãªãŒã³ã¢ãã æé ãç¶ãã¹ãã§ãã
å šäœãšããŠããããããŠã³æ¹æ³ã¯ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ãåªå ããæ¥å disruption ãš high è²»çšã®å€§ããªãªã¹ã¯ã䌎ããŸãã äžæ¹ ããã ã¢ããæ¹æ³ã¯æ¥å continuity ãåªå ããã»ãã¥ãªãã£ã«å€§ã㪠æ¹å ããããããªããŸãŸ status quo ãåã蟌ã倧ããªãªã¹ã¯ã䌎ããŸãã å®åã§ã¯ãtop-down ãš bottom-up ã®äž¡æ¹ã®æ¹æ³ã useful ã§ãããå¿ èŠã§ãã ç§ãã¡ã®æšå¥šã¯ãããããçµã¿åãããããšã§ãã
- ãããããŠã³ æ¹æ³ã䜿ã£ãŠãwhalesããåŠçããŸããã¡ã³ããŒãå€ãããŒã«ã圱é¿ã倧ããããŒã«ãæ©å¯æ§ã®é«ãããŒã«ã§ãã ãããããŠã³ æ¹æ³ã¯é ããé«äŸ¡ã§ãdisruptive ã«ãªãåŸãããããã®ãããªããŒã«ã®æ°ã¯æ¯èŒçå°ãªãä¿ã£ãŠãã ããã
- Bottom-up æ¹æ³ã䜿ã£ãŠãfishããåŠçããŸããordinary 㪠mid-size ããŒã«ã§ãã ããŒã«ãã€ãã³ã°ãäž»ãªåæããŒã«ãšããŠäœ¿ãããšã§ãããªãå€ãã®ããŒã«ããã°ããåŠçã§ããŸãã Reasonably high é¡äŒŒæ§ ãæã¡ãæ¥åäžã®æå³ãããããŒã«ãéžãã§ãã ããã ãã ããããããªãã§ãã ããã é¡äŒŒæ§ãäœãããŒã«ãæ¥åäžã®æå³ããªãããŒã«ãç¡çã«åŠçããããšããªãã§ãã ããã ãã¹ãŠã®æš©éãããžãã¹ããŒã«ã«åŠçããå¿ èŠã¯ãããŸããã
- ãplanktonããåŠçããããšããªãã§ãã ãããããªã·ãŒ exceptionãéåžžã«å°ããªããŒã«ãhistorical leftover ã§ãã ãã®ãããªã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ãŠãŒã¶ãŒã«çŽæ¥å²ãåœãŠããŸãŸã«ããŠãã ããã å®å šã«å¿ããŠã¯ãããŸããããããžãã¹ããŒã«ã«åŠçããããšããªãã§ãã ããã åŽåã«èŠåããŸããã èŠçŽããšèªå®ãã£ã³ããŒã³ãèšå®ããæ®µéçã« åé€ããããå¶åŸ¡äžã«çœ®ããŠãã ããã
ããŒã«ãšã³ãžãã¢ãªã³ã° ããã»ã¹ã®ãã¹ãŠã® 段é ã§å¿ã«çããŠããã¹ãããšã1ã€ãããŸããåžžã«æ¥åéšéã®æ åœè ã® assistance ãæ±ããŠãã ããã ããŒã«ã¯ãŸãæ¥å sense ãæããªããã°ãªããŸããã ãããããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ã®äž»ãªèãæ¹ã§ãã æ¥åéšéã®æ åœè ã®åå㯠ãããããŠã³æ¹æ³ã«çµ¶å¯Ÿäžå¯æ¬ ã§ãã ããã ããã ã¢ããæ¹æ³ã§ããæ¥åç¥èãªãã«ã¯æ©èœããŸããã æ¥åéšéã®æ åœè ã¯äžå¯æ¬ ã§ãã
ããŒã« ãšã³ãžãã¢ing ã¯ããŒã« 管ç ã®æé ã®1ã€ã«ãããŸããã ããŒã«ã¯ useful ã§ããããã«ãŠãŒã¶ãŒã«å²ãåœãŠãããªããã°ãªããŸããã åã«èŠãããã«ããŠãŒã¶ãŒãžã®éçããŒã«å²ãåœãŠã¯æãŸãããããŸããã ãŠãŒã¶ãŒãžã®èªååãããããŒã«å²ãåœãŠã®ããã® policy å®çŸ©ã¯ãrole 管ç åŽåã®äžå¯æ¬ ãªéšåã§ããã¹ãã§ãã
é·æçãªæç¶å¯èœæ§
RBAC ãæ©èœãããã ãã§ãååã«å°é£ã§ãã ãããããŸãåãç¶ããããããšã¯ããã«å°é£ã§ãã ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«äžè¬ã® æç¶å¯èœæ§ ã¯ç°¡åãªåé¡ã§ã¯ãªãããŸã å®å šã«ã¯è§£æ±ºãããŠããŸããã RBAC ãäŸå€ã§ã¯ãããŸããã
ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ã¯ãçè«äžã¯å³æ Œã«ããªã·ãŒã«åºã¥ãã¹ãã§ãã ãããèŠãŠããããã«ããã®ãã㪠strict æ¹æ³ã¯éåžžçŸå®çã§ã¯ãããŸããã åžžã« discrepancy ããããŸããããªã·ãŒ exceptionãããŒã¿èª€ããå€ããªã£ãããŒã¿ãhistorical baggageãleftoverããã®ä»å€æ°ã®å°ããªèª²é¡ã§ãã RBAC ã¢ãã«ã¯ãã®æ§è³ªäžããªãå ç¢ã§ãå€ãã® discrepancy ã tolerate ããªããã éçšã§ããŸãã ããããããã RBAC ã® popularity ã®çç±ã®1ã€ã§ãã ããããã®ãã㪠discrepancy ã¯æãŸãããªããå šå¡ã®ç掻ãè€éã«ããŸãã ããããç©ã¿äžããã®ã§ã¯ãªããæéãšãšãã« discrepancy ã®æ°ãæžããã«ã¯ã©ãããã°ããã§ããããã
å°ãªããšãä»ã®ãšããããã®åé¡ãžã® definitive answer ã¯ãããŸããã æäŸã§ããã®ã¯èãæ¹ãš ææ¡ ã®éåã§ãã
- äœããããŸããå¯èœãªéãåºã ããªã·ãŒ ãš èªååãé©çš ããŠãã ããã ããŒã«ã¯èªåçã«å²ãåœãŠããã ã¹ã ã§ãã ããã«éèŠãªã®ã¯ãäžèŠã«ãªã£ããšãã«èªåçã« unassigned ãããã¹ãããšã§ãã RBAC ãçµç¹æ§é ãšçµ±åããŠãã ããã ãã¹ãŠã®ããŒã«å²ãåœãŠãåèªå®ããã®ã§ã¯ãªããããŒã«å®çŸ©ãšããªã·ãŒãèŠçŽããŠãã ããã
- ããªã·ãŒãšããŒã«å®çŸ©ã® éè€ãé¿ã㊠ãã ããã "Don't Repeat Yourself" (DRY) ã¯æ å ±æè¡ã®åºæ¬ mantra ã®1ã€ã§ãã ã»ãŒåãã ãå®å šã«ã¯åãã§ãªãã³ããŒã10åäœãã®ã§ã¯ãªããåŒãæã€1ã€ã® parametric ããŒã«ã䜿ã£ãŠãã ããã ããŒã« assignment ã®éè€ãé¿ããŠãã ããã ããžãã¹ããŒã«ãŸãã¯æè¡çãª/IT ããŒã«ã䜿ãããŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã®æ°ãæžãããŠãã ããã
- ããªã·ãŒãããŒã«å ã« encapsulate ããŠãã ããã ããŒã«å®çŸ©ã¯ããã®ããŒã«ã衚ãããªã·ãŒã衚çŸããããã«éèŠãªãã®ããã¹ãŠå«ãã¹ãã§ãã æš©ééå (ãŸãã¯åŒ) ãããŒã«å ã«çœ®ããèªåå²ãåœãŠã®ããã®ã«ãŒã«ãããŒã¿ãããŒã«å ã«çœ®ãã説æ (ãŠãŒã¶ãŒåã) ãšææž (ããŒã« ãšã³ãžã㢠åã) ãããŒã«å ã«çœ®ããŠãã ããã ããŒã«ã¯ã§ããã ãäºãã« independent ã«ä¿ã£ãŠãã ããã 1ã€ã®ããŒã«ã®æŽæ°ãã·ã¹ãã ã®ä»éšåã«äºæž¬äžèœãª cascading side effect ãäžããªãããã«ããŠãã ããã
- ãªã¹ã¯ã«åŸã£ãŠ ãã ããã ã¢ã¯ã»ã¹ç³è«æ¿èªãšèŠçŽãã§ã¯ high-risk é å ã«çŠç¹ãåœãŠãŠãã ããã é«ãªã¹ã¯ããŒã«å²ãåœãŠã®èªå®ãåªå ããŠãã ããã Cumulative ãªã¹ã¯ååã ç£èŠ ããŠãã ããã ãã¡ããããªã¹ã¯ããŒã¹æ¹æ³ãé©çšããã«ã¯ãªã¹ã¯ãã©ãã«ããããç¥ãå¿ èŠããããŸãã ãã®ããã«ã¯ãIGA ãã©ãããã©ãŒã ã®çµã¿èŸŒã¿æ©èœãšããŠèªååããããªã¹ã¯ ã¢ããªã³ã° ãå¿ èŠã§ãã
- åé¡ã carpet ã®äžã« é ããªãã§ ãã ããã ããªã·ãŒ exceptionãtemporary hackãhistorical baggage ãæç¢ºã« mark ããŠãã ããã ã¬ããŒãããããã·ã¥ããŒãã«è¡šç€ºãããã®æ°ãäžåçã«å¢ããŠããªãããšã確èªããŠãã ããã ããããç¶ç¶çã«åŠçãããã£ããæŽçããããã»ã¹ãèšå®ããŠãã ããã
- å¯èœãªéã IT ãšæ¥åã align ããŠãã ããã IGA ã·ã¹ãã 㯠IT ã·ã¹ãã ã§ãã ããã倧éã®æ¥åæ å ±ãæ±ããŸãã IGA ã¯æ¥åç¥èãæèãæ¥åéšéã®æ åœè ã®ååãªãã«ã¯æå³ãæã¡ãŸããã IGA ãã©ãããã©ãŒã ã«ã管çæç€ºããæ¥ã䟡å€ã®ãªã slide ã§ã¯ãªããå®çšçã§ææ°ãªçµç¹æ§é ããŒã¿ãããããšã確èªããŠãã ããã ããžãã¹ããŒã«ãæ¥å責任ãè·åãããã»ã¹ãšäžèŽããŠããããšã確èªããŠãã ããã ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ã real IT ã·ã¹ãã ã衚ããŠããããšã確èªããŠãã ããã IGA 㯠reality ã® ç¶ç¶ç 管çã§ããäœãããéãããå¿ãããã monthly spreadsheet ã§ã¯ãããŸããã
- ããŒã¿å質ã管ç ããŠãã ããã "Garbage in, garbage out" ãšããèšè㯠ã³ã³ãã¥ãŒã¿ãŒæè¡ã®é»ææã«ãŸã§ããã®ãŒããŸãã ä»ã§ããŸã£ããçå®ã§ãã ããªã·ãŒããŒã¹ã®æ¹æ³ã¯å質ããŒã¿ã«äŸåããŠããŸãã ã¢ã€ãã³ãã£ãã£å±æ§ã¯ããŒã«ãèªåå²ãåœãŠãããã«äœ¿ãããŸãã ãã®ãããªå±æ§ã®äŸ¡å€ãééã£ãŠããã°ãããŒã«å²ãåœãŠãééããŸãã è·åã³ãŒããçµç¹äžã®åäœå²ãåœãŠãé¡äŒŒããŒã¿ãæ£ããããšã確èªããŠãã ããã ãã®ãããªããŒã¿ã¯å€ãã®å Žå人äºïŒHRïŒã·ã¹ãã ã«ç±æ¥ããŸãã HR ã·ã¹ãã ã§ã¯ãã®ããŒã¿ãéèŠãªç®çã«äœ¿ãããŠããªããããããŒã¿å質ãäœãå ŽåããããŸãã ããã IGA ãã©ãããã©ãŒã ã¯ããã«äŸåããŸãã IGA ãã©ãããã©ãŒã ã¯éåžžãããŒã¿äžæŽåãæ€åºããæåã®ã·ã¹ãã ã§ãããããã倧ã㪠damage ãåŒãèµ·ããå¯èœæ§ããããŸãã Imä»²ä» åé¡ãåé¿ããããã«ãIGA ãã©ãããã©ãŒã å ã®ããŒã¿ããã°ãã correct ããæ©æ§ãæã£ãŠãã ããã ãŸãããã® å ã·ã¹ãã (é垞㯠HR) ã®ããŒã¿ãä¿®æ£ ãã ãã£ãŒãããã¯ããã»ã¹ ãããããšã確èªããŠãã ããã ãã®ããã»ã¹ã¯é ãçãŸããã§ããã絶察ã«å¿ èŠã§ãã
- ã·ã¹ãã ãè¯ãç¶æ ã«ä¿ã€ããã® assistive ããŒã« ãå°å ¥ããŠãã ããã ãã®ãããªããŒã«ã¯çŸåš IGA ãã©ãããã©ãŒã ã«çŸãå§ããŠããŸãã ããšãã°ãã©ãããã©ãŒã 㯠ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã§ãŠãŒã¶ãŒã®ããŒã«éžæ ãæ¯æŽãããããããŸããã ãŠãŒã¶ãŒãéžæããå°æ°ã®ã¢ããªã±ãŒã·ã§ã³ããŒã«ã®ä»£ããã«ãããžãã¹ããŒã«ããŠãŒã¶ãŒã« ææ¡ ãããããããŸããã ããªãã design ããŠããããŒã«ãæ¢åã®å¥ããŒã«ãšããªãåãã§ãããš warn ãããããããŸããã ããŒã«ãã€ãã³ã°ããã»ã¹ãç¶ç¶çã«å®è¡ãããæ°ããçºèŠãããããŒã« candidate ã notify ãããããããŸããã Future ãããããåŸã æ¹å ã¯å€æ°ãããŸãã
- ããªã·ãŒãã€ãã³ã° 㯠future ã«åãã倧ããªèãæ¹ã§ãã ããžãã¹ããŒã«ã¯ã¢ããªã±ãŒã·ã§ã³ããŒã«ããŒã¿ãããã€ãã³ã°ã§ããŸãã ãããããŒã«ããŒã¿ããŠãŒã¶ãŒå±æ§ãšçµç¹æ§é ãšçµã¿åãããã°ãpolicy ããã€ãã³ã°ã§ãããããããŸããã ç¹å®ããŒã«ããã€å²ãåœãŠæžã¿ã»unassigned ãããããæ±ºå®ããã«ãŒã«ããã€ãã³ã°ã§ããŸãã ããªã·ãŒãã€ãã³ã° ã¯ãpolicy-driven RBAC ãžã® ããã ã¢ããæ¹æ³ã® ultimate ããŒã«ã«ãªãå¯èœæ§ããããŸãã
ãã®ä»ã®æ³šèš
RBAC ã¢ãã«ã¯è·ååæ (SoD) æ©èœãå®è£ ãã elegant ãªæ¹æ³ãæäŸããŸãã åçŽããŒã«æä» ã«ãŒã«ã§ãè€æ°ã®ããžãã¹ããŒã«ãçžäºæä»çã«ããã«ã¯ååã§ãã
çæ³çã«ã¯ãRBAC ã¢ãã«ã®ããŒã«ã¯ independent ã§ããã¹ãã§ãã ãã®ãããªæ¹æ³ã¯ãã·ã¹ãã å ã®ä»»æã®ããŒã«ã independent ã« ä¿®æ£ ã§ããã·ã¹ãã å ã® interference ãæãŸãããªãäžæŽåã®ãªã¹ã¯ãé¿ããããŸãã ãããããŒã«éã® dependency ã¯ãç¹ã«è€éããŒã«éå±€ã§ã¯å®å šã«ã¯é¿ããããŸããã äžéšã®ã·ã¹ãã ã¯ããŒã«ã¢ãã« versioning ãš staging æ©èœãæäŸããŸãã è€æ°ããŒã«ã®ä¿®æ£ãåäž atomic åäœãšããŠé©çšã§ããŸãã
å®å šãª RBAC ã¢ãã« (NIST RBAC æšæºãªã©) ã¯ã»ãã·ã§ã³ãš active ããŒã«ã®æŠå¿µãå«ã¿ãŸãã åã»ãã·ã§ã³ã®éå§æã«ããŠãŒã¶ãŒã¯ãã®ã»ãã·ã§ã³ã®é active ã«ããããŒã«ãéžæããããæ±ããããŸãã ãããããã®æ©èœã¯ RBAC ã¢ãã«ãžã®å®å šãªã³ã³ãã©ã€ã¢ã³ã¹ã䞻匵ããã¢ããªã±ãŒã·ã§ã³ã§ãããå®è£ ãããŠããªãããšããããããŸãã IGA ã·ã¹ãã ã«ã€ããŠã¯ããã®æ©èœã¯ããããžã§ãã³ã°/ãã«ãã£ã«ã¡ã³ãã§ã¯å®å šã«ã¯ãµããŒãã§ããŸãããIGA ã·ã¹ãã ã¯ãŠãŒã¶ãŒã»ãã·ã§ã³ãçŽæ¥å¶åŸ¡ããŠããªãããã§ãã å¿ èŠãªå Žåããã®æ©èœã¯ã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠå®è£ ãããªããã°ãªããŸããã
RBAC ã®ããŒã«æ§é ã¯ããªã¹ã¯ exposure calculation ããµããŒãããéèŠãªããŒã«ã§ãã ãŠãŒã¶ãŒã¯ããŒã«ã«å²ãåœãŠãããããŒã«ã¯æš©éã imply ããããããŠãŒã¶ãŒãšæš©éã®é¢ä¿ã known ã«ãªããŸãã åã ã®æš©éã®ãªã¹ã¯ exposure ã¯ãŠãŒã¶ãŒã«ãããžã§ã¯ãã§ãããªã¹ã¯ãããã¹ããããç¹å®ã§ããŸãã RBAC ã¯ãã®ããã»ã¹ãæ¯èŒçç°¡åã«ããŸãããä»ã®ã¢ãã« (ç¹ã« PBAC/ABAC) ã¯ãã®æ©èœã容æã«ã¯ãµããŒãããŸããã
éåžžã® RBAC éå±€ã«å ããŠãRBAC ã¢ãã«ã¯ããã«å¥ã® dimension ãæãŠãŸãã
RBAC ã¢ãã«ã¯èªèº«ã«é©çšã§ããããŒã«ãããŒã«ãæã€ããšã§ ã¡ã¿ããŒã« ãäœããŸãã
ããšãã° Business role ãš Application role ã¯ãããããããžãã¹ããŒã«ãšã¢ããªã±ãŒã·ã§ã³ããŒã«ã«é©çšããã ã¡ã¿ããŒã« ã«ãªãåŸãŸãã
ç¹å®ããŒã«çš®é¡ã«å
±éããæ©èœã¯ ã¡ã¿ããŒã« ã«æå®ã§ããããªã·ãŒå®çŸ©ã®éè€ãæžãããŸãã
ããšãã° midPoint ã® archetype 㯠ã¡ã¿ããŒã« ãšããŠæ©èœããŸãã
RBAC ã¯äž»ã«ããŒã«ãæ±ããŸãããä»ã®çš®é¡ã®ãªããžã§ã¯ããããŒã«ãšé¡äŒŒããæ©èœãæã¡åŸãŸãã ããšãã°çµç¹äžã®åäœã¯ããŒã«ãšããŠåäœãããã®åäœã®ãã¹ãŠã® member ã«çŽæ¥æš©éãä»äžã§ããŸãã ãã®æ¹æ³ã«ãããRBAC ã®å¹æãä»ã®ãªããžã§ã¯ãçš®é¡ã«çŽæ¥é©çšã§ããããªã·ãŒæã®æ°ãšè€éæ§ãæžãããŸãã ããšãã° midPoint ã® çµç¹æ§é ãš ãµãŒãã¹ ã¯ããŒã«ãšããŠåäœããŸãã
ãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã¯ãããŒã«ã¬ããã³ã¹ã®ãã㪠é«åºŠãª use-case ããµããŒãããããæ¡åŒµã§ããŸãã ããšãã° parametrized ãŠãŒã¶ãŒã»ããŒã« å²ãåœãŠã¯ããŠãŒã¶ãŒã plain member ã§ã¯ãªãããŒã«ã® owner ã§ããããšã瀺ããŸãã ãã®çµ±åãããæ¹æ³ã«ãããå€ãã® RBAC-related æ©æ§ãåå©çšããããããããŒã«ã¬ããã³ã¹ã«ãåé©çšã§ããŸãã ããšãã°ãŠãŒã¶ãŒã¯ ordinary ããŒã«ã¡ã³ããŒã·ãããšåã ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã䜿ã£ãŠããŒã« owner ã«ãªãããšãç³è«ã§ããŸãã ããŒã«æææš© ã¯ãããŒã«ã¡ã³ããŒã·ããã«é©çšãããã®ãšåãã¢ã¯ã»ã¹èªå®æ©æ§ã䜿ã£ãŠç¢ºèªã§ããŸãã
ããŒã«ã¯ãŠãŒã¶ãŒã« birthright permission ãæäŸããããã«äœ¿ãããããšããããŸãã ãã®æ¹æ³ã¯å®å šã«ã¯æ£ãããªããå¯èœã§ããã°é¿ããã¹ãã§ãã Birthright permission ã¯ãŠãŒã¶ãŒçš®é¡ããŸãã¯ãŠãŒã¶ãŒã®é¡äŒŒãã inherent å質ã«ãã£ãŠäžããããŸãã ããšãã°ãŠãŒã¶ãŒã¯ååšãã (registered ãããŠãã) ã ãã§ããŸãã¯ã¢ã€ãã³ãã£ãã£ã åŸæ¥å¡ çš®é¡ã§ããã ãã§ãç¹å®ã¢ã¯ã»ã¹ãåŸããããããŸããã Birthright ã¯ãŠãŒã¶ãŒçš®é¡ã決å®ããã®ãšåãæ©æ§ãŸãã¯ããªã·ãŒã«ãã£ãŠä»äžãããã¹ãã§ãã ããšãã° midPoint ã§ã¯ãbirthright 㯠archetype ã«ãã£ãŠæäŸãããŸãã
ä»ã®ã¢ã¯ã»ã¹ã¢ãã« (ç¹ã« PBAC) ã®æå±è ã¯ãpolicy-based ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ãš ããŒã«ããŒã¹ã® ã¢ã¯ã»ã¹å¶åŸ¡ã察æ¯ããRBAC ã policy-based ã§ã¯ãªããã®ããã«ç€ºããŸãã ããããããŒã«ãããŒã«æ§é ããŠãŒã¶ãŒãžã®ããŒã«å²ãåœãŠã¯ ããªã·ãŒ ã§ãã ãããã®ããŒã¿æ§é ã¯ã¢ã¯ã»ã¹å¶åŸ¡ã«ãŒã«ãæå®ãããããã£ãŠèª°ãäœã«ã¢ã¯ã»ã¹ã§ãããã®ããªã·ãŒãæå®ããŸãã ãã®ããªã·ãŒã¯ algorithmic ã§ã¯ãªããããã declarative ã§ãããããã§ãããªã·ãŒã§ãã ããã«åç RBAC ã¢ãã«ã¯ algorithmic ããªã·ãŒãå®è£ ããææ®µãæäŸããŸãã
RBAC ã®äžè¬çãªåé¡
RBAC ã¯åçŽã«èŠããã¢ã¯ã»ã¹å¶åŸ¡æ©æ§ã§ãã ãããæ£ãã䜿ããªããšãäºæããªãè€éæ§ãš complication ãçã¿åºãããšããããŸãã ãã®ç¯ã¯ãRBAC æ©æ§ã®å©çšã«é¢ããäžè¬ç誀ããmisconceptionãåé¡ããŸãšããŸãã
-
ã¢ããªã±ãŒã·ã§ã³ããŒã«ã®éå°å©çš ã¯ãããããæãäžè¬çãªèª€ãã§ãã ã¢ããªã±ãŒã·ã§ã³æš©éãšãšã³ã¿ã€ãã«ã¡ã³ããã¢ããªã±ãŒã·ã§ã³ããŒã«ã®åœ¢ã§ IGA ãã©ãããã©ãŒã ã«åã蟌ã¿ããããšã¯ãéåžžã«äžè¬çã§æ£ããå®åã§ãã ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã¢ã«ãŠã³ããžã®ã¢ããªã±ãŒã·ã§ã³æš©é/ãšã³ã¿ã€ãã«ã¡ã³ãã®æ¢åå²ãåœãŠã«åŸã£ãŠãŠãŒã¶ãŒã«å²ãåœãŠãããŸãã ãã®å®å㯠RBAC å°å ¥ã®éåžžã«è¯ã åºçºç¹ ãæäŸãããããè¯ããã®ã§ãã åé¡ã¯ãå€ãã®äººãããã宿ãã RBAC å°å ¥ãšèŠãªãããšã§ããããã§ã¯ãããŸããã ã¢ããªã±ãŒã·ã§ã³ããŒã«ã¯æš©éã® IGA equivalent ã§ãã ã¢ããªã±ãŒã·ã§ã³ããŒã«ããŠãŒã¶ãŒã«çŽæ¥å²ãåœãŠãããšã¯ãpermission ããŠãŒã¶ãŒã«çŽæ¥å²ãåœãŠãããšãæå³ããŸãã ãã㯠RBAC æ§é ã§ã¯ãããŸãããããŒã« ã¯ã»ãšãã©é¢äžããŠããªãããã§ãã ãã®æç¹ã§æã£ãŠãããã®ã¯ RBAC ã§ã¯ãããŸããã
åŽå㯠business role ã®å°å ¥ãžç¶ãã¹ãã§ããããã RBAC ã¢ãã«ãäœãæåã®æé ã§ãã ããžãã¹ããŒã«å²ãåœãŠã èªåå ããã¢ããªã±ãŒã·ã§ã³ããŒã«ã®çŽæ¥å©çšã minimize ããããã«ããªã·ãŒãé©çšãã¹ãã§ãã ãŠãŒã¶ãŒãžã®ã¢ããªã±ãŒã·ã§ã³ããŒã«ã®çŽæ¥å²ãåœãŠã¯ æšæº ãšèŠãªãã¹ãã§ã¯ãªããããªã·ãŒ exceptionãæçµçã« ã¯ãªãŒã³ã¢ãã ãããã¹ãè² åµãšèŠãªãã¹ãã§ãã å®è·µçãªå°å ¥ã§ã¯ãç¹æ®ãªã±ãŒã¹ãããžãã¹ããŒã«ã«æŽçããåŽåã«èŠåããªããããçŽæ¥ã¢ããªã±ãŒã·ã§ã³ããŒã«å²ãåœãŠãããçšåºŠæ®ããŸãã ãããããã¯æå°éã«ä¿ã¡ãã¢ããªã±ãŒã·ã§ã³ããŒã«ã®éå°å©çš ãé¿ããããã«æ³šææ·±ã ç£èŠ ãã¹ãã§ãã
-
ã¢ã¯ã»ã¹ç³è« frenzy ãéåžžã«äžè¬çãªèª²é¡ã§ãã ã¢ã¯ã»ã¹ç³è« ããã»ã¹ãå°å ¥ããããšããããããããåé¡ã解決ããæ±çšããŒã«ãšããŠäœ¿ãåŸåããããŸãã ãŠãŒã¶ãŒã¯ããŒã«ãäœãæå³ãããªãå¿ èŠãªã®ããæ¬åœã«çè§£ããªããŸãŸã倿°ã®ããŒã«ãç³è«ããããšããããããŸãã ååãæã£ãŠããããŒã«éåãšåããã®ã blindly ã«ç³è«ããããšã¯éåžžã«äžè¬çãªå®åã§ãã ãŸãæ¿èªè ããã¢ããªã±ãŒã·ã§ã³ããŒã«ã®ç³è«ã substantiated ãã©ãããç¥ããªãããšããããããŸãã圌ãã¯ãã®ãããªããŒã«ã®ç®çãçè§£ããŠããªãããã§ãã ç³è«ããlooks goodãã§ããéããæ·±ãèããã«æ¿èªããŸãã ããã¯å¿ ç¶çã«ã¢ããªã±ãŒã·ã§ã³ããŒã«å²ãåœãŠã®ç¡é spaghetti ã«ã€ãªãããŸãã
IGA å°å ¥ã® start æç¹ã§ RBAC æ§é ããŸã ã»ãšãã©ãªãå Žåãã¢ã¯ã»ã¹ç³è« ããã»ã¹ã® wild å©çšã¯èš±å®¹ããããããããŸããã ãããžã§ã¯ãã®åŸåã§ã¯ãã¢ã¯ã»ã¹ç³è« ããã»ã¹ã¯ããžãã¹ããŒã«ç³è«ã prefer ãããã tune ãããã¹ãã§ãã Recommender ããã®ä» é«åºŠãª ææ³ã®äœ¿çšã¯ãå°æ¥ããã»ã¹ãããã«æ¹åã§ããŸãã ãããæãéèŠãªæåèŠå ã¯ãããžãã¹ããŒã«ã® ãšã³ãžãã¢ing ãšããã®ç®¡çã®ããã®èªåããªã·ãŒãé²ããããšã§ãã ããŒã«ãã€ãã³ã°ã¯å°å ¥åæã® ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã® uncontrolled å©çšã«ãã£ãŠçãã mess ã ã¯ãªãŒã³ã¢ããããããã®éåžžã« æçšãªããŒã«ã«ãªãåŸãŸãã
-
Rubber-stamp èªå® ã¯å·šå€§ã§ç¡æå³ãª exercise ã§ãããé垞㯠ã¢ã¯ã»ã¹ç³è« ããã»ã¹ abuse ã® consequence ã§ãã ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã¯ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãåŸãããã® quick ã§éåžžã« convenient ãªæ¹æ³ã§ãã ãããã¢ã¯ã»ã¹ãäžèŠã«ãªã£ããšãã«ããã åé€ ãã motivation ã¯ã»ãšãã©ãããŸããã Excessive ã¢ã¯ã»ã¹ã åé€ããããã«èªå®ãã£ã³ããŒã³ã䜿ãããŸãã ã¢ã¯ã»ã¹ç³è« ããã»ã¹ã«ãã£ãŠä»äžããããã¹ãŠã®ããŒã«ã¯ã宿ç ã§ç¢ºèªãããªããã°ãªããŸããã 責任è ã¯ããã®ã¢ã¯ã»ã¹ããŸã å¿ èŠã§ããããšã ç¢ºèª ããªããã°ãªããŸããã ãããèšå€§ãªæ°ã®ããŒã«ããŠãŒã¶ãŒã«ä»äžãããŠããå Žåãèªå®ãã£ã³ããŒã³ã巚倧ã«ãªããŸãã èªå®è ããã¹ãŠã®ãŠãŒã¶ãŒã«ä»äžããããã¹ãŠã®ããŒã«ã責任ãæã£ãР倿ããããã宿ç ã§ç¹°ãè¿ãããšã¯ããã®æ©èœãè¶ ããŠããŸãã èªå®ãã£ã³ããŒã³ã¯ 圢åŒçãªæ¿èª exercise ã«ãªããå€ãã®èªå®è ã¯æ·±ãèããã«ãã¹ãŠã®ããŒã«ã accept ããŸãã ã€ãŸããåé€ ãããã¢ã¯ã»ã¹ã¯éåžžã«å°ãªããªããŸãã æ°ããã¢ã¯ã»ã¹ãç¶ç¶çã«ä»äžãããã¢ã¯ã»ã¹ã åé€ ãããªããããèªå®ãã£ã³ããŒã³ã¯å€§ãããªããããã 圢åŒçãªæ¿èª ã® motivation ãããã«é«ããŸããçµæãšã㊠vicious spiral ã«ãªããŸãã
Symptom ãçºçããåŸã«ããã treat ããæ¹æ³ã¯ãããŸãã ãªã¹ã¯ããŒã¹ã®èªå®ã¯ãèªå®è 㮠泚æãæ©å¯æ§ã®é«ãããŒã«ã«éäžãããå°ãªããšã é«ãªã¹ã¯ããŒã«ã® 圢åŒçãªæ¿èª ãæžããããšããããã«äœ¿ããŸãã ããã¯è¯ã æåã®æé ãããããŸããã äžéšã® IGA ãã©ãããã©ãŒã ã¯èªå®å€æãæ¯æŽãã 人工ç¥èœæ©æ§ãæäŸããŸãã ããã 圢åŒçãªæ¿èª å®åããã§ã« æšæº ã«ãªã£ãŠããå Žåã人工ç¥èœã§ãããã®å®åã«åŸããŸãã ãã®æ¹æ³ã¯ 圢åŒçãªæ¿èª ãããå¹ççã«ããããšã¯ã§ããŸãããåé¡ã® core ã«ã¯å¯ŸåŠããªããããããŸããã
æè¯ã®ãœãªã¥ãŒã·ã§ã³ã¯ çç¶ãžã®å¯ŸåŠ ã«çŠç¹ãåœãŠãã®ã§ã¯ãªããåé¡ã®æ ¹æ¬ åå ã«å¯ŸåŠããŸãã ãœãªã¥ãŒã·ã§ã³ã¯ãããžãã¹ããŒã«ãš policy-driven èªååãå°å ¥ããŠã¢ããªã±ãŒã·ã§ã³ããŒã«å²ãåœãŠã®æ°ãæžããããšã§ãã Root åå ã¯æ¬è³ªçã«åãã§ããããããã®ãœãªã¥ãŒã·ã§ã³ã¯ä»ã®åé¡ã®ãœãªã¥ãŒã·ã§ã³ãšåºæ¬çã«åãã§ãã
-
ããŒã«ççº ã¯éç RBAC ã¢ãã«ã®ããç¥ãããåé¡ã§ãã ããã€ãã® åå ãããåŸãŸãã ããããææªã® åå ã¯ãåçã§å€æ¬¡å çãªæŠå¿µãéçã¢ãã«ã§èª¬æããããšããæ¬²æ± ã§ãã ããšãã°è²¬ä»»ãšå€åå°ã®äž¡æ¹ãããŒã«ã«å«ããããšãããšã
New York SupervisorãNew York DirectorãBoston SupervisorãBoston Directorãªã©ãããŒã«çµã¿åããã® explosion ãèµ·ãããŸãã ãŸããããžãã¹ããŒã«ã¬ãã«ã§æå°æš©éã®ååãããããã attempt ãããã¹ãŠã®ããªã·ãŒ exception ãš anomaly ã systemic ããžãã¹ããŒã«ã§ cover ããããšãã attempt ã ããŒã«ççº ã«ã€ãªããåŸãŸããããŒã«ççº ã® systemic åå ãšæŠãæè¯ã®æ¹æ³ã¯ã¢ã«ãŽãªãºã ã«ããããªã·ãŒã䜿ãããšã§ãã ããšãã° åçããŒã«åŒ ãš ãã©ã¡ãŒã¿ãŒ ã¯ãåçã§å€æ¬¡å çãªæŠå¿µã«ãã£ãŠèµ·ããççº ãé¿ããéåžžã«å¹ççãªæ¹æ³ã§ãã Overzealous ãªããŒã«ã¢ããªã³ã°ã«ããããŒã«ççº ã¯ãã¢ãã«ã¯æ±ºã㊠perfect ã«ã¯ãªãããåžžã« exception ãš leftover ãããããšãèªããããšã§ãæ¯èŒç容æã«å¯ŸåŠã§ããŸãã
-
ããžãã¹ããŒã«éè€ ã¯ãããå°ãªãåé¡ã§ãã ããŒã«ãšã³ãžãã¢ãªã³ã° ãè€æ°äººã«åæ£ããŠããå ŽåããŸãã¯ã¢ãã«ãéåžžã«è€éã§å€ããªã£ãã«ãªã£ãå Žåã«çºçããŸãã åãããžãã¹ããŒã«ã2人ã«ãã£ãŠäœæãããããå ã®ãäœæããå¿ããããŠããé·ãæéã®åŸã«åäœæããããããŸãã ãŸããéåžžã¯ããŒã« ãšã³ãžã㢠㮠neglect ã limited ç¥èã«ãããããããŒã«ã®äžéšãå¥ã®ããŒã«ã«ã³ããŒãããåœ¢ã§æå³çã«çºçããããšããããŸãã
Unintentional ããŒã«éè€ã¯ãæ°ããããžãã¹ããŒã«ãäœæããåã« ãšã³ãžã㢠ã é¡äŒŒ ããŒã«ã®ååšã 確èªããªããã°ãªããªãããšããããŒã«ãšã³ãžãã¢ãªã³ã° ããã»ã¹ã«ãã£ãŠéšåçã«å¯ŸåŠã§ããŸãã ããã RBAC ã¢ãã«ãæé·ããã«ã€ããŠãããã¯ãŸããŸãé£ãããªããŸãã çæ³çãªãœãªã¥ãŒã·ã§ã³ã¯ IGA tooling ã®ãµããŒãã§ãããæ°ããããŒã«ãæ¢åã®å¥ããŒã«ãšéåžžã« é¡äŒŒ ã§ãããš ãšã³ãžã㢠㫠warn ããããšã§ãã Intentional ããžãã¹ããŒã«éè€ã¯å¥ã§ãã ããŒã«å®çŸ©ã®äžéšãã³ããŒãã¹ãã§ã¯ãããŸããã 代ããã«å°ããªããŒã«éå±€ãäœããäž¡æ¹ã®ããŒã«ãäžè¬ç sub-role ã share ããã¹ãã§ãã
-
ããŒã« decay ã¯å€ãå°å ¥ã®åé¡ã§ãã ããããããŒã«ãå®çŸ©ããã ãã§ãååã«å°é£ã§ãã ãããããŒã«å®çŸ©ã¯èŠçŽããç¶æç®¡çãããå¿ èŠããããŸããããããªããã°ãæçµçã«æ¥åçŸå®ãã ä¹é¢ ããŸãã ããŒã«èŠçŽããšç¶æç®¡çã¯å°é£ã§ãããæå³éå±ãªäœæ¥ã§ããããããã°ãã°è»œèŠãããŸãã
1人ã entire RBAC ã¢ãã«ãé©åã«ç¶æç®¡çããããšã¯éåžžäžå¯èœã§ãã ãœãªã¥ãŒã·ã§ã³ã¯äœæ¥ã distribute ããããšã§ãã ããŒã«ã« ownerãã€ãŸãããŒã«å®çŸ©ã®ç¶æç®¡çã«è²¬ä»»ãæã€äººç©ãå²ãåœãŠãŠãã ããã ããžãã¹ããŒã«ã§ã¯ãowner ã¯éåžžæ¥åéšéã®æ åœè ã§ãã ç¹ã«ããŒã«ããéå°ãªæš©éã åé€ ããå€ããªã£ãããŒã«ã廿¢ããããšã«éç¹ã眮ãããããŒã«å®çŸ©ã®èŠçŽããšæŽæ°ã®èŠåçããã»ã¹ãèšå®ããŠãã ããã
ããã ultimate ãœãªã¥ãŒã·ã§ã³ã¯ãèªåãã¡ã®æ©èœãçè§£ããããšã§ãã ã¢ãã«ãç¶æç®¡çã§ããªãã»ã© é床ã«è€éåããªãã§ãã ããã ããªããšããŒã ãå®å šãª RBAC ã¢ãã«ãç¶æç®¡çã§ããªãå ŽåãåŠ¥åæ¡ãæ€èšããŠãã ããã å¶åŸ¡ããã over-provisioning ã蚱容ããããåçŽã§ã倧ããªãããŒã«ãäœãæ¹ã lesser evil ãããããŸããã Outdated ããŒã«å®çŸ©ã over-provisioning ãããããå¯èœæ§ããããŸããããã㯠é ãã ã§ããå¯èœæ§ãé«ãã§ãã ã·ã¹ãã å ã®å€§éã®äžæãªã¹ã¯ãçãããããknown ãªã¹ã¯ãããçšåºŠåãå ¥ããæ¹ã wise ãããããŸããã
-
Phantom ããªã·ãŒ ã¯äžè¬ççµç¹äžã®åé¡ã§ãããRBAC ã«éãããŸããã çè«äžãã©ã®çµç¹ã§ãã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã¯ well-known ã§ãclearly-formulated ã§ãææžå ãããproperly ç¶æç®¡çãããã¹ãã§ãã éåžžã¯ããã§ã¯ãããŸããã ããªã·ãŒã¯ ææžåãããŠããªããambiguous ã§ãsubjective èæ ® ãšã¢ãããã¯å€æã«åºã¥ããŠããŸãã ãã®ãããªãããªã·ãŒããã¢ã¯ã»ã¹å¶åŸ¡æ©æ§ã§è¡šçŸã§ããã§ããããã
æããã« ãããããŠã³æ¹æ³ã¯ããã§ã¯æ©èœããŸããã ãããçµç¹ã¯äœããã®æ¹æ³ã§åããŠãããããæããã§ã¯ãªããŠããäœããã® åäœç³»ç㪠ããªã·ãŒãååšããŠããã¯ãã§ãã ç§ãã¡ã¯ããªã·ãŒããŸãã¯å°ãªããšããã®äžéšãçºèŠããªããã°ãªããŸããã åè¿«ããç¶æ³ã«ã¯æãåã£ã察çãå¿ èŠ ã§ãã ã¢ããªã±ãŒã·ã§ã³ããŒã«ãšã¢ã¯ã»ã¹ç³è«ããã»ã¹ã®çµã¿åããã¯ãã°ãã°å€±æã«ã€ãªãããŸããããã®ã±ãŒã¹ã§ã¯é©çšãã䟡å€ããããããããŸããã ã¢ã¯ã»ã¹ç³è«ããã»ã¹ããããŒã¿ãåŸãŠãmining ããŒã«ã§ããŒã«ãåæããããªã·ãŒã®äžéšãæœåºããŠã¿ãããšãã§ããŸãã ç°¡åã§ã¯ãããŸããããstart ã«ã¯ãªããŸãã
éèŠãªã®ã¯ããã㯠start ã§ãããšããããšã§ãã ããã»ã¹ã¯ããã§æ¢ãŸã£ãŠã¯ãããŸããã çµç¹ã phantom ããªã·ãŒã«åºå·ããŠããŠã¯é ããžè¡ããŸããã ããªã·ãŒã®äžéšã æ€åºãããããããã¯ææžåãreviewedãæ¹åãããªããã°ãªããŸããã IGA æ¹æ³ ãš æ¥åã®äž¡æ¹ãäºãã«é©å¿ããªããã°ãªããŸããã æ¥ååŽãå€ãããªãå Žåããã® IGA åŽåå šäœã¯ããã death march ã«ãªããŸãã
-
IT éšé ã«ããéäžåãããããŒã«ç®¡ç ã¯ãIGA ãœãªã¥ãŒã·ã§ã³å°å ¥æã®äžè¬çãªå®è·µã§ãã ãããããã誀ãå®åã§ãã 確ãã« ã¢ããªã±ãŒã·ã§ã³ ããŒã«ã¯ IT éšé ã管çã§ããŸããã管çãã¹ãã§ãã ããã IT éšé ã«ã¯ æ¥å ããŒã«ã管çããããã«å¿ èŠãªç¥èããããŸããã IT éšé ãããžãã¹ããŒã«ãå®çŸ©ããããšãã attempt 㯠ç¹less ã§ãã çµæãšããŠçããããŒã«ã¯æ¥ååäœã«ãšã£ãŠ åœ¹ã«ç«ããªã ã§ãå¿ èŠæ§ã«åãããã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãåŸãããã®ãããªã confusing é害ã«ãªãã ãã§ããã¹ãŠãæªåãããŸãã
ããžãã¹ããŒã«ã¯æ¥åæŠå¿µã« align ãããªããã°ãªããŸããã æ¥åæŠå¿µãç¥ã£ãŠããã®ã¯æ¥åéšéã®æ åœè ã ãã§ãã ãããã£ãŠæ¥åéšéã®æ åœè ã¯ããžãã¹ããŒã«ãšã³ãžãã¢ãªã³ã° ã«é¢äžããªããã°ãªããŸããã 以äžã§ãã
ãã¡ãããæ¥åéšéã®æ åœè ã¯éåžžããŒã«ãå®çŸ©ããæè¡ç㪠skill ãæã£ãŠããŸãããç¹ã«ããŒã«ãšã³ãžãã¢ãªã³ã° åŽåã® åæ ã§ã¯ãIT æ åœè ã§ããå°ãè¿·ãããšããããŸãã ãããã£ãŠãããŒã«ãšã³ãžãã¢ãªã³ã° ããã»ã¹ã IT ãšæ¥åã®å¯æ¥ãªååãšããŠå§ãŸãããšãéèŠãªã§ãã ããŒã ãçµéšãåŸãã«ã€ããŠãããå€ãã®åŽåãæ¥åéšéã®æ åœè ã« å§ä»»ã§ããå¯èœæ§ããããŸãã ããã§ãããŒã«ãšã³ãžãã¢ãªã³ã° ããã»ã¹ã¯åžžã«æ¥åãš IT ã®äž¡æ¹ãå«ã ååäœæ¥ã§ãã
-
ãããããã®ãããŒã«ã«ããã Engineer ãããŒã«ã®æŠå¿µãã€ãããšããã¹ãŠãããŒã«ã«èŠãå§ããŸãã ãã¡ãã
Branch supervisorãMarketing assistantã®ããŒã«ã¯ãããŸãã ãããçªç¶ãEmployeeãMarketing éšéãNew York BranchãProject X memberã®ããŒã«ãçŸããŸãã ãããŠã«ãŒã«ãçŸããŸããlocation屿§ã®äŸ¡å€ãNYã§ãããŠãŒã¶ãŒã¯New York BranchããŒã«ãåŸãããšããå ·åã§ãã æçµçã«ã¯ããŒã«ãã«ãŒã«ãnaming conventionãã«ããŽãª ã® avalanche ã«ãªããŸãã RBAC labyrinth ãžããããããã®æ¹æ³ã¯äžèŠ sound ã«èŠããŸãããããã§ã¯ãããŸããã éè€ãå€ãããŸãã
Employeeã¯ããŒã«ã§ã¯ãªãããããããŠãŒã¶ãŒçš®é¡ã§ãã åŸæ¥å¡ã«å±ãã birthright permission ã¯ããŒã«ã«ãã£ãŠä»äžãããã¹ãã§ã¯ãªãããŠãŒã¶ãŒãåŸæ¥å¡ã§ãããšæ±ºå®ããã®ãšåãæ©æ§ã«ãã£ãŠå²ãåœãŠãããã¹ãã§ãã ããã¯éåžžãäœããã® HR åæããŸã㯠IGA ãã©ãããã©ãŒã ã®çµã¿èŸŒã¿ typing æ©æ§ã§ãã ãããããŒã«ã«ããããªã good reason ããããŸãããã®ããŒã«ã unassigned ããããäœãèµ·ããã®ã§ããããã ãŸãMarketing éšéã¯ããŒã«ã§ã¯ãªãçµç¹äžã®åäœã§ãã ã·ã¹ãã å ã«Marketing éšéçµç¹äžã®åäœãšMarketing éšéããŒã«ã®äž¡æ¹ãæã¡ããã¯ãããŸããããã㯠confusion ã®åŠæ¹ç®ã§ãã Marketing éšé ã§åãããã«å¿ èŠãªæš©éã¯ããŒã«ã§ã¯ãªããMarketing éšéorganizational unit ã«ãã£ãŠä»äžãããã¹ãã§ãã åæ§ã«ãNew York BranchãšProject Xã¯çµç¹äžã®åäœã®å¥åœ¢æ ã«ãããŸããã åãè«çãããã«ãé©çšãããŸããçµç¹æ§é ãããŒã«ã§ã¢ãã«åããããšããªãã§ãã ããã代ããã« real çµç¹æ§é ã䜿ã£ãŠãã ããã å€åå°ãããŒã«ã§ã¢ãã«åããããšããªãã§ãã ããã代ããã«å€åå°ãã£ã¬ã¯ããªã䜿ã£ãŠãã ããã ã¢ããªã±ãŒã·ã§ã³ãããŒã«ã§ã¢ãã«åããããšããªãã§ãã ããã代ããã«ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ã䜿ã£ãŠãã ããã è·åã«é©ããããŒã«ãéžãã§ãã ããã Role 㯠golden hammer ã§ã¯ãããŸããã