| 講演抄録/キーワード |
| 講演名 |
2007-07-27 15:25
内部統制を実現するためのデータベース・セキュリティ技術 ~ モニタリングからのコントロールへ ~ ○松永 豊(東京エレクトロンデバイス)・大場みち子(日立) |
| 抄録 |
(和) |
情報漏洩の防止や規制遵守の要請により、データベース内の情報アクセスや変更に関するセキュリティ管理が必要になってきている。 ところが、データベースへのアクセスを記録する監査機能が成熟してきたのに比べて、不正な流出や改竄を未然に防止する手だては普及していない。 そこでデータベースのアクセス制御や不正操作の検知、暗号化など、利用可能な技術を調査し、特徴を分析した。 その上で各セキュリティ技術のさまざまなセキュリティ要件に対する適合性を検討した。 |
| (英) |
As the requirements for preventing information leakage and for regulation compliance are getting critical, the security management capability of the information access and modification in database systems is becoming necessity. However, compared with relatively established auditing functionality to log the database acccess, mechanism to prevent the information leakage and unauthorized modification is still not widely deployed. In this research, a variety of the available security technologies including access control, detection of unauthorized operation, and encryption are investigated and analyzed. Then we evaluated the technologies against the different security requirements for the best solution. |
| キーワード |
(和) |
内部統制 / データベース / セキュリティ / アクセス制御 / 暗号化 / 監査 / / |
| (英) |
Internal Control / Database / Security / Access Control / Encryption / Audit / / |
| 文献情報 |
信学技報, vol. 107, pp. 65-70, 2007年7月. |
| 資料番号 |
|
| 発行日 |
2007-07-19 (OIS) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
| PDFダウンロード |
|