気になる情報(サイバー)セキュリティ用語集
最短突破 情報セキュリティ管理士認定試験 公式テキスト [ 五十嵐 聡 ] 価格:3058円 |
用語に関係する試験問題を載せています。理解度の確認にお使いください。
情報セキュリティ管理士試験の紹介ページ
スマートフォンの「脱獄」と同じ言葉ですが、AI分野では「AIの安全装置を外す試み」を指します。現代のAIには「暴力的な内容を教えない」「違法行為を支援しない」といった安全ルールが組み込まれています。ジェイルブレイクは、このルールを巧みな言葉で回…
共通鍵暗号方式とは、データの暗号化と復号の両方に同じ鍵を使用する暗号方式です。送信者と受信者があらかじめ同じ鍵を共有し、その鍵を用いてデータを暗号化・復号します。最大のメリットは処理速度の速さです。公開鍵暗号方式と比べて計算負荷が低く、大…
セキュリティエリアへの不正侵入を防ぐためには、入退室管理の徹底が基本となります。入室を許可するための認証方法としては、IDカードによる認証、パスワード入力、そして指紋や顔認証などのバイオメトリクス(生体認証)の3つが代表的な手段として挙げられ…
公開鍵暗号方式とは、データの暗号化と復号に異なる鍵を使用する暗号方式です。暗号化には誰でも利用できる「公開鍵」を使い、復号には本人だけが持つ「秘密鍵」を使います。この2つの鍵は数学的に対になっており、公開鍵で暗号化したデータは対応する秘密鍵…
可用性とは、情報セキュリティの3要素(CIA)のひとつで、必要なときに必要な情報やシステムへ確実にアクセスできる状態を維持する特性です。残る2要素である機密性・完全性と並んで、情報セキュリティの根幹をなす重要な概念です。どれほど優れたシステムや…
通信傍受法とは、正式名称を「犯罪捜査のための通信傍受に関する法律」といい、警察などの捜査機関が一定の条件のもとで通信の傍受(盗聴)や電子メールの閲覧を行うことを法的に認めた法律です。本来、通信の秘密は日本国憲法によって保障されており、他人…
RC4とは、共通鍵暗号方式のひとつで、データを1ビット単位で順次暗号化・復号するストリーム暗号アルゴリズムです。1987年にRon Rivestによって設計され、シンプルな構造と高速処理が特徴です。かつてはSSL/TLS通信や無線LAN規格のWEP・WPAなど、幅広いプロ…
クエリストリングはクエリ文字列のことで、WebブラウザなどがWebサーバに送信するデータを、送信先を指定するURLの末尾に特定の形式で表記したものです。URLの途中に「?」記号があれば、「?」以降の文字列はクエリストリングとなります。クエリストリングに…
PMBOKとは「Project Management Body of Knowledge(プロジェクトマネジメント知識体系ガイド)」の略称で、プロジェクトマネジメントの国際的な標準手法です。米国のPMI(プロジェクトマネジメント協会)によって策定・発行されており、世界中の企業や組織…
クリアデスクとは、離席する際に机の上に書類やUSBメモリなどを放置しないことです。帰宅・外出時に個人情報や機密情報が記載された書類や記憶媒体を机上に残さないようにすることで、情報漏えいや盗難のリスクを防ぎます。クリアスクリーンとは、離席する際…
非形式的アプローチとは、リスク分析手法のひとつで、セキュリティ専門家の経験や直感をもとにリスクを評価する方法です。この手法の最大のメリットは、自社特有のリスクを把握しやすい点と、分析にかかる工数が少なく済む点です。専門家の知見を直接活かせ…
詳細リスク分析とは、リスク分析手法のひとつで、情報資産に対して資産価値・脅威・脆弱性・セキュリティ要件を体系的に識別・評価し、リスクの大きさを算出する手法です。分析は「守るべき情報資産の洗い出し」から始まり、「情報資産の評価」「脅威の洗い…
YARA: The Virus Detective's Pattern Book YARA is a special tool that helps security experts find and identify malware (bad software). It's like a detective's notebook that describes what different criminals look like! What is YARA? Imagine…
AIチャットボットに話しかけるとき、私たちは普通に質問や指示を入力します。しかし悪意ある人が、AIの動作ルールを無視させるような特殊な命令を紛れ込ませることがあります。これが「プロンプトインジェクション」です。たとえば、カスタマーサポート用のA…
Zero Trust: Never Trust, Always Verify Zero Trust is a modern security approach that says "Never automatically trust anyone or anything — always check!" It's like having security guards check everyone's ID, even people who work in the buil…
X.509: The Digital ID Card X.509 is a standard format for digital certificates — like an official ID card that proves a website or a service is who they say they are on the internet. What is X.509? Imagine someone says "Hi, I'm the real ba…
WAF: The Shield That Protects Websites WAF stands for "Web Application Firewall." It’s like a **security guard** standing in front of your website, checking all visitors before they enter! What is a WAF? Imagine a large office building wit…
VLAN: Building Separate Neighborhoods in a Network VLAN stands for "Virtual Local Area Network." It's like dividing one big network into smaller, separate groups — just like creating different neighborhoods inside a big city! What is a VLA…
URL Filtering: The Internet's Security Guard URL Filtering is like having a security guard at the entrance of the internet who checks every website before letting you visit it. If a website is dangerous, the guard says "Stop! You can't go …
Token: Your Digital Ticket A token is like a special temporary ticket that proves you're allowed to do something. It's used in computer security to keep you logged in safely without sending your password over and over again! What is a Toke…
SSL/TLS: The Secret Envelope for Your Information SSL and TLS are special technologies that protect your information when it travels across the internet. They're like putting your message in a locked envelope that only the right person can…
Rootkit: The Invisible Spy in Your Computer A rootkit is a sneaky type of malware that hides deep inside your computer and makes itself invisible. It's like a burglar who not only breaks into your house but also erases all the security cam…
Quarantine: Putting Sick Files in Isolation Quarantine in cybersecurity means putting suspicious or infected files in a safe, locked place where they can't cause harm. It's just like when sick people stay home so they don't make others sic…
Penetration Testing: Friendly Hackers Testing Your Security Penetration Testing (also called "Pen Testing") is when good guy hackers try to break into your computer system ON PURPOSE to find weak spots before bad guys do! What is Penetrati…
OAuth: Lending Your Key Without Giving It Away OAuth is a special system that lets you share access to your information without giving away your password. It's like letting someone borrow your toy without giving them the key to your whole …
NIST: The Rulebook Makers for Cybersecurity NIST stands for "National Institute of Standards and Technology." It's a special organization in the United States that creates important rules and guidelines to keep computers and information sa…
MITM: The Sneaky Spy in the Middle MITM stands for "Man-in-the-Middle Attack." It's when a hacker secretly gets between you and the person you're talking to, listening to everything you say! What is a MITM attack? Imagine you want to send …
Log: The Computer's Diary A log is like a diary or journal that computers keep. It writes down everything that happens so we can look back and see what occurred! What is a log? Imagine you keep a diary where you write: "Monday 9:00 AM - Wo…
Kerberos: The Three-Headed Guard Dog Kerberos is a special system that checks if you are who you say you are when you log into a computer network. It's named after a three-headed dog from Greek mythology that guarded the gates of the under…
Jailbreak: Breaking Free from Rules Jailbreak means breaking out of the rules and restrictions on your device. It's like escaping from jail - that's why it's called "jailbreak!" What is jailbreak? When you buy a smartphone or tablet (like …