クラウドサービス事業者の名称 クラウドサービスの名称 株式会社エヌ・ティ・ティ・データ OpenCanvas(IaaS) 富⼠通株式会社 FUJITSU Hybrid IT Service FJcloud Google LLC Apigee Edge Google Cloud Platform Google Workspace 株式会社セールスフォース・ドットコム Salesforce Services Heroku Services Amazon Web Services,Inc. Amazon Web Services ⽇本電気株式会社 NEC Cloud laaS KDDI株式会社 KDDIクラウドプラットフォームサービス Oracle Corporation Oracle Cloud Infrastructure Oracle Cloud Infrastructure Platform as a Service Oracle Exadata Cloud@Customer ⽇本マイクロソフト株式会社 Microsoft Azure, Dynamics 365, and Other Online Services Microsoft Office 365 株式会社⽇⽴製作所 エンタープライズクラウドサービス/エンタープライズクラウドサービ ス G2/フェデレーテッドポータルサービス Cisco Systems, Inc. Cisco Webex サイボウズ株式会社 クラウドサービス運⽤基盤cybozu.com 並びにcybozu.com 上で提供するGaroon及びkintone Box, Inc. Box エヌ・ティ・ティ・コミュニケーションズ株式会社 Smart Data Platform サービス
and/or its affiliate 29 Compute Storage Networking Oracle Databases Open Source Databases Operating Systems, Native VMWare Developer Services Containers and Functions Application Integration Data Lake House Machine Learning and AI Analytics and BI Oracle Applications Custom Applications Global Cloud Datacenter Infrastructure Commercial and Government Public Cloud Regions | Hybrid Cloud: Cloud@Customer, Dedicated Regions, Roving Edge Security | Observability and Management | Compliance ISV Applications
from Bare Metal Hardware to Customer Apps & Data Operations Constant Software, Hardware, and Process Hardening Compliance Building Compliance in All Regions for All Services OF THE CLOUD ON THE CLOUD CROSS CLOUD 37
affiliate Isolated Network Virtualization To / From Other Tenants To / From Other Tenants 1st Generation Clouds: Most Prevalent Today 2nd Generation Cloud: Oracle Cloud Infrastructure-Wide Host OS/Kernel Network Virtualization Hypervisor Server Virtualization Separates Network and Tenant Environment Server Virtualization Hypervisor Network Virtualization VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS Host OS/Kernel Network Virtualization Host OS/Kernel Hypervisor Container (Optional) VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS 39
its affiliate Host OS/Kernel Network Virtualization Hypervisor Server Virtualization Server Virtualization Hypervisor Network Virtualization Host OS/Kernel Isolated Network Virtualization Host OS/Kernel Hypervisor Container (Optional) Server Virtualization Hypervisor Network Virtualization Network Virtualization Hypervisor Server Virtualization Server Virtualization Hypervisor Network Virtualization Server Virtualization Hypervisor Network Virtualization 1st Generation Cloud Oracle 2nd Generation Cloud VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS Isolated Network Virtualization Security Prevents Lateral Movement VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS Isolated Network Virtualization Host OS/Kernel Hypervisor Container (Optional) VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS VM/ Guest OS 40
Metal Instances | VM Instances Network VCN and Subnets Data Data-at-rest and Data-in-Transit encryption using customer-controlled keys Back-end Infrastructure Secure isolation between customer instances and back-end hosts Identity and Access Management Compartments and IAM policies • 部署を他の部署から分離したい – リソースの可視化とアクセスの区分が可能 • ⾃社のクラウドリソースを分離したい – 他のテナント、オラクル社員、外部の脅威から – セキュリティとコンプライアンスの要求を満たす 42
技術的なセキュリティ対策の宝庫︕例えば・・・ Data Erasure – Bare Metal Compute ........................ The provisioning workflow is an automated process that connects to the Integrated Lights Out Manager (ILOM) within the physical hardware................Once the erasure process is complete, the service commences a process to “flash” the basic input/output system (BIOS), update drivers, and return the hardware to the initial factory state..................... ................................ Access to Individual Devices Once a user has authenticated to the relevant bastion server, .................., operators must also enter a one- time password (OTP) that expires after 24 hours. Access to hosts is provisioned using a SSH public/private key pairing. ............................................ OCIユーザなら⼊⼿可能︕︕
Government Industry Regional 27001 : 27017 : 27018 27701 SOC 1 : SOC 2 : SOC 3 Self-Assessment PIPEDA - Canada DoD DISA SRG IL2 Moderate – Agency ATO VPAT – Section 508 G-Cloud 11 - UK Model Clauses - EU US Privacy Shield HIPAA Level 1 PCI DSS FISC - Japan IG Toolkit - UK My Number - Japan Cyber Essentials Plus - UK TISAX - Germany BSI C5 - Germany GDPR - EU C5 FINMA - Switzerland Cloud Security Principles - UK DoD DISA SRG IL5 3 Ministries Healthcare - Japan
https://www.oracle.com/cloud/ n オラクルのクラウドセキュリティ https://www.oracle.com/jp/security/ https://www.oracle.com/security/ n オラクルのコーポレートセキュリティ https://www.oracle.com/jp/security/ https://www.oracle.com/corporate/security-practices/corporate/ n オラクル・クラウドのセキュリティ・プラクティス https://www.oracle.com/corporate/security-practices/cloud/ n セキュリティ ホワイトペーパー https://docs.oracle.com/cd/E97706_01/Content/General/Reference/aqswhitepapers.htm#security https://docs.cloud.oracle.com/en-us/iaas/Content/General/Reference/aqswhitepapers.htm#security (参考)その他リンク⼀覧 86
https://docs.cloud.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm n コンプライアンス https://www.oracle.com/cloud/cloud-infrastructure-compliance/ n ソフトウェア・セキュリティ保証 /Oracle Software Security Assurance(OSSA) https://www.oracle.com/jp/corporate/security-practices/assurance/ https://www.oracle.com/corporate/security-practices/assurance n オラクルのセキュリティ敢⾏ https://www.oracle.com/jp/corporate/security-practices/ n Oracle Cloud Infrastructureセキュリティ・ガイド https://docs.oracle.com/ja-jp/iaas/Content/Security/Concepts/security_guide.htm n オラクルセキュリティ サービス概要 https://www.oracle.com/jp/security/ n クラウドセキュリティの最新情報︓クラウドセキュリティナビ https://blogs.oracle.com/sec (参考)その他リンク⼀覧 87