Analysis device, analysis method, and program

An analysis device automates compliance checking for IT systems by preprocessing software configuration data against predefined standards, addressing the challenge of manual compliance analysis in complex IT environments.

JP2025186828APending Publication Date: 2025-12-24PWC BUSINESS ASSURANCE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024095219
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-12
Publication Date
2025-12-24

AI Technical Summary

Technical Problem

Companies face significant challenges in determining whether their IT systems comply with various compliance standards due to the wide range of requirements and numerous functions of software used in development and operation, requiring substantial manual effort to analyze compliance.

Method used

An analysis device that automatically analyzes compliance with IT system standards by acquiring configuration information from installed software, preprocessing it, and comparing it against predefined standards to output results, supporting analysis of single or multiple software instances.

Benefits of technology

Enables automated compliance analysis, reducing manual effort and ensuring that IT system development and operation activities meet specified standards, providing clear explanations of compliance status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025186828000001_ABST
    Figure 2025186828000001_ABST
Patent Text Reader

Abstract

To automatically analyze compliance with compliance standards related to an IT system.SOLUTION: An analysis device includes: a reception section that receives designation of analysis target software that is an analysis target; an acquisition section that acquires setting information used when the analysis target software operates from a device in which the analysis target software is installed; an analysis section that analyzes whether or not it is possible to explain that development and operation activities utilizing the analysis target software satisfy compliance standards related to an IT system on the basis of the setting information; and an output section that outputs an analysis result by the analysis section.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Currently, various compliance standards that must be observed in the development and operation of IT systems have been made public. For example, Non-Patent Document 1 discloses IT risks related to financial accounting systems, IT control mechanisms, and the current state of IT control. In addition, Non-Patent Document 2 describes software that automates part of source code version management, product generation, and delivery to the operating environment. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] “IT Control and IT Control Standards”, [online], Financial Services Agency, Internet<URL:https: / / www.fsa.go.jp / singi / singi_kigyou / siryou / naibu / 20050310 / 01.pdf> [Non-patent document 2] “Technical Report on Security Considerations in CI / CD Pipelines”, [online], Digital Agency, Internet <URL: https: / / www.digital.go.jp / assets / contents / node / basic_page / field_ref_resources / e2a06143-ed29-4f1d-9c31-0f06fca67afc / 33f31336 / 20240329_resources_standard_guidelines_guideline_01.pdf> Summary of the Invention [Problem to be solved by the invention]

[0004] Companies that develop and operate IT systems are required to comply with various compliance standards. Some companies also use multiple auxiliary software programs to reduce labor and the risk of operational errors. However, the software used by companies to develop and operate IT systems has a huge number of functions, and the compliance standards have a wide range of requirements. Therefore, analyzing whether IT systems are being developed and operated while complying with compliance standards requires a huge amount of work.

[0005] Therefore, an object of the present invention is to provide a technique that enables automatic analysis of whether or not compliance standards related to the development and operation of IT systems are being observed. [Means for solving the problem]

[0006] An analysis device according to one embodiment of the present invention includes a reception unit that receives the designation of the software to be analyzed, an acquisition unit that acquires configuration information used when the software to be analyzed operates from the device on which the software to be analyzed is installed, an analysis unit that analyzes, based on the configuration information, whether development and operational activities utilizing the software to be analyzed can be explained as meeting compliance standards for IT systems, and an output unit that outputs the analysis results by the analysis unit. [Effects of the Invention]

[0007] According to the present invention, it is possible to provide a technique that enables automatic analysis of whether or not compliance standards related to the development and operation of an IT system are being observed. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a system configuration of an analysis system according to an embodiment of the present invention. [Figure 2] FIG. 2 illustrates an example of a hardware configuration of an analysis apparatus. [Figure 3]FIG. 2 is a diagram illustrating an example of a functional block configuration of an analysis device. [Figure 4] FIG. 10 is a diagram illustrating an example of acquired data definition information. [Figure 5] FIG. 10 is a diagram illustrating an example of first preprocessing information. [Figure 6] FIG. 10 is a diagram illustrating an example of provision definition information. [Figure 7] FIG. 10 is a diagram illustrating an example of a processing procedure performed by the analysis device. [Figure 8] FIG. 10 is a diagram illustrating an example of a processing procedure performed by the analysis device. [Figure 9] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 10] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 11] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 12] FIG. 10 is a diagram showing an example of a screen for accepting input of second pre-processing information. [Figure 13] FIG. 10 is a diagram illustrating an example of an output of an analysis result. DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described with reference to the accompanying drawings, in which the same reference numerals denote the same or similar components.

[0010] <System configuration> 1 is a diagram showing an example of the system configuration of an analysis system 1 according to this embodiment. The analysis system 1 includes an analysis device 10 and one or more information processing devices 20. The analysis device 10 and the one or more information processing devices 20 are connected via a wireless or wired communication network N, and can communicate with each other.

[0011] The analysis device 10 is a device that analyzes whether software running on the information processing device 20 complies with various compliance standards related to the development and operation of IT systems. The analysis device 10 may be a personal computer, or one or more servers, etc.

[0012] The information processing device 20 is a system in which software to be analyzed (hereinafter referred to as "analysis target software") is installed. The analysis target software is software that companies use in the development and operation of their IT systems (for example, their internal systems, internal tools, and software for companies to provide services to their customers). Examples of the analysis target software include source code version management tools, tools that support the generation of executable software from source code, tools that manage development and operation work, and tools that control access to IT systems and manage permissions.

[0013] Various compliance standards for IT systems consist of multiple clauses that set out specific criteria. Examples of compliance standards include, but are not limited to, ISO27001 and ISO27002, which are standards for information security management systems (ISMS), ISMAP (Information system Security Management and Assessment Program), which is a security assessment system for government information systems, and the FISC Guidelines, which are security measures standards for computer systems of financial institutions and other organizations established by the Center for Financial Industry Information Systems (FISC).

[0014] The analysis device 10 analyzes whether development and operation activities utilizing the target software can be explained as satisfying specified compliance standards and outputs the analysis results. More specifically, the analysis device 10 acquires various setting information set in the target software from the information processing device 20 and checks the acquired setting information to analyze whether development and operation activities utilizing the target software can be explained as satisfying the provisions of the compliance standards. The analysis results may be classified into three patterns: explainable, partially explainable, and inexplicable. Explainable means that development and operation activities utilizing the target software satisfy the specified compliance standards (i.e., it is possible to explain to a third party that the standards are satisfied). Partially explainable means that development and operation activities utilizing the target software partially satisfy the specified compliance standards (i.e., it is possible to explain to a third party that the standards are partially satisfied). Inexplicable means that development and operation activities utilizing the target software do not satisfy the specified compliance standards (i.e., it is not possible to explain to a third party that the standards are satisfied). The setting information may be information that can be acquired using an API (Application Programming Interface), or may be information that can be acquired by downloading a setting file from the information processing device 20. In the following description, "whether or not the compliance standards are met" is synonymous with "whether or not it is possible to explain that the compliance standards are met." Similarly, "whether or not the provisions are met" is synonymous with "whether or not it is possible to explain that the provisions are met."

[0015] For example, assume that a security compliance standard includes a clause stating that "the number of users with administrator privileges shall be N or less." In this case, the analysis device 10 acquires setting information related to user account authority settings from the information processing device 20 and analyzes the acquired setting information to analyze whether the number of users with administrator privileges for the software to be analyzed is N or less. If the number of users with administrator privileges is N or less, the analysis device 10 can determine that the development and operation activities utilizing the software to be analyzed satisfy the clause.

[0016] Furthermore, the analysis device 10 may analyze development and operation activities using the software to be analyzed alone to determine whether the development and operation activities using the software to be analyzed satisfy the compliance standard, or may analyze development and operation activities using multiple pieces of software to be analyzed. For example, if there is a provision stating that "the number of users with administrator privileges shall be four or less," the analysis device 10 acquires setting information related to permission settings from each piece of software to be analyzed, aggregates and analyzes the acquired setting information, and analyzes whether the number of users with administrator privileges for all of the software to be analyzed is four or less. For example, suppose that users M, N, and P have administrator privileges for software A, and users M, Q, and R have administrator privileges for software B. In this case, if the development and operation activities using software A alone are analyzed, the number of users with administrator privileges for software A is three (users M, N, and P), so the provision is satisfied. On the other hand, when analyzing development and operation activities using both software A and B, there are five users (users M, N, P, Q, and R) who have administrator privileges for either software A or B, which does not satisfy the provision.

[0017] <Hardware configuration> 2 is a diagram illustrating an example of the hardware configuration of the analysis device 10. The analysis device 10 includes a processor 11 such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), a memory (e.g., RAM (Random Access Memory) or ROM (Read Only Memory)), a storage device 12 such as an HDD (Hard Disk Drive) and / or an SSD (Solid State Drive), a network IF (Network Interface) 13 for wired or wireless communication, an input device 14 for accepting input operations, and an output device 15 for outputting information. The input device 14 is, for example, a keyboard, a touch panel, a mouse, and / or a microphone. The output device 15 is, for example, a display, a touch panel, and / or a speaker.

[0018] <Function block configuration> FIG. 3 is a diagram illustrating an example of a functional block configuration of the analysis device 10. The analysis device 10 includes a storage unit 100, a receiving unit 101, an acquiring unit 102, an analyzing unit 103, and an output unit 104. The storage unit 100 can be realized using a storage device 12 included in the analysis device 10. The receiving unit 101, the acquiring unit 102, the analyzing unit 103, and the output unit 104 can be realized by the processor 11 of the analysis device 10 executing a program stored in the storage device 12. The program can be stored in a storage medium. The storage medium storing the program may be a non-transitory computer-readable medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a universal serial bus (USB) memory or a compact disc read-only memory (CD-ROM).

[0019] The storage unit 100 stores acquired data definition information 100a, first preprocessing information 100b, clause definition information 100c, and second preprocessing information 100d. The acquired data definition information 100a indicates the setting information to be acquired from the software to be analyzed in order to analyze whether the software satisfies compliance standards. The first preprocessing information 100b defines a method for preprocessing the setting information acquired from the software to be analyzed. Specifically, the first preprocessing information 100b defines a processing method for converting the setting information into data in a format usable for analysis, and a generation method for generating data to be used for analysis from the setting information. The setting information acquired from the software to be analyzed is written in a software-specific format, making it difficult to use it for analysis as is. Therefore, in this embodiment, the first preprocessing information 100b is used to preprocess the setting information to generate data that can be directly used to analyze whether the compliance standards are met.

[0020] The provision definition information 100c defines a method for analyzing whether compliance standards are met for each compliance standard and for each provision. The second preprocessing information 100d is information used when analyzing whether development and operation activities utilizing multiple software to be analyzed meet the compliance standards. The data converted or generated according to the first preprocessing information 100b is merely data related to each software to be analyzed and may not be suitable for analyzing whether development and operation activities utilizing multiple software to be analyzed meet the compliance standards. Therefore, in this embodiment, the second preprocessing information 100d is used to convert or process the data converted or generated according to the first preprocessing information 100b into data that can be directly used to analyze development and operation activities utilizing multiple software to be analyzed.

[0021] The receiving unit 101 receives a designation of software to be analyzed. The receiving unit 101 also receives a designation of a clause to be analyzed from among a plurality of clauses included in the compliance standard. The receiving unit 101 may also be configured to receive a designation of a plurality of software to be analyzed.

[0022] The acquisition unit 102 acquires setting information used when the software to be analyzed operates from the information processing device 20 (device) in which the software to be analyzed is installed. The acquisition unit 102 may also acquire setting information for each of the multiple pieces of software to be analyzed from the information processing device 20 in which each of the multiple pieces of software to be analyzed received by the reception unit 101 is installed. The acquisition unit 102 may acquire the setting information by calling an API provided by the information processing device 20 or the software to be analyzed, or may download a file in which the setting information is described from the information processing device 20.

[0023] The analysis unit 103 analyzes whether or not development and operation actions utilizing the software to be analyzed satisfy the compliance standards, based on the setting information acquired by the acquisition unit 102. More specifically, the analysis unit 103 acquires clause definition information 100c corresponding to the specified compliance standards from the storage unit 100. Next, the analysis unit 103 performs preprocessing on the acquired setting information in accordance with first preprocessing information 100b to generate preprocessed setting information, and analyzes whether or not the setting information satisfies the compliance standards by comparing the generated preprocessed setting information with clause definition information 100c (definition information) that defines an analysis method for whether or not the preprocessed setting information satisfies the compliance standards.

[0024] In addition, the analysis unit 103 analyzes the setting information of each of the multiple software to be analyzed, thereby obtaining an evaluation result that aggregates the setting contents set in the setting information of each of the multiple software to be analyzed, and compares the evaluation result with the provision definition information 100c (definition information), which defines an analysis method for whether or not the compliance standards are met, to analyze whether the development and operation activities utilizing the multiple software to be analyzed meet the compliance standards.

[0025] The output unit 104 outputs the analysis results from the analysis unit 103 to a display, a printer, or the like.

[0026] FIG. 4 is a diagram showing an example of the acquisition data definition information 100a. Because the configuration information to be acquired differs for each software to be analyzed, the acquisition data definition information 100a is prepared for each software to be analyzed. FIG. 4A shows an example of the acquisition data definition information 100a corresponding to software A. FIG. 4B shows an example of the acquisition data definition information 100a corresponding to software B. "Category" indicates the type of category to which the configuration information belongs. The category types stored in "Category" are the same as the types of categories stored in "Category" in the compliance standard clauses described later in FIG. 6. In the example in FIG. 4A, "accessControlList" indicates configuration information related to access permissions. "Acquisition Method" indicates the method for acquiring the configuration information. "Configuration Information" indicates the name of the configuration information to be acquired. For example, in the example in FIG. 4A, configuration information called "accessControlList" can be acquired by calling API-A1, and configuration information called "logConfig" can be acquired by calling API-A2.

[0027] FIG. 5 is a diagram showing an example of the first preprocessing information 100b. Since the setting information differs for each software to be analyzed, the first preprocessing information 100b is prepared for each software to be analyzed. "Setting information" indicates the name of the setting information to be preprocessed. "Preprocessed setting information" indicates the content of the data obtained by preprocessing the setting information. "Preprocessing method" indicates the method for generating preprocessed data by preprocessing the setting information. The preprocessing may be any process, but examples include extracting information necessary for analysis from the setting information, converting the format of the setting information to another format, etc.

[0028] In the example of A in Figure 5, it is defined that the number of users who have the authority to change the permission settings of a user ID (authority C) can be extracted by counting the number of user accounts that have either "roles / owner," "roles / iam.roleAdmin," or "roles / iam.securityAdmin" set in the accessControlList.

[0029] FIG. 6 is a diagram showing an example of the provision definition information 100c. "Category" indicates the type of category to which the provision belongs. Note that all or some of the category types that can be stored in "Category" are the same as the category types that can be stored in "Category" of the acquired data definition information 100a. "Data to be analyzed" indicates the type of data used to analyze the provision. If setting information is set in "Data to be analyzed," this means that the provision is analyzed using setting information acquired from the software to be analyzed (more specifically, setting information after preprocessing). Furthermore, if manually input data is set in "Data for analysis," this means that the provision is analyzed using data manually input by the user. Some provisions cannot be analyzed using setting information acquired from the software to be analyzed, such as provisions regarding the physical security of the room where the software to be analyzed is used. When analyzing such provisions, the analysis is performed using manually input data answered by the user.

[0030] "Analysis method" indicates how to analyze the configuration information or manually entered data. For example, in the example of A in Figure 6, if the preprocessed configuration information satisfies the conditions that the number of users with authority A is 1 or less, the number of users with authority B is 1 or less, and the number of users with authority C is 1 or less, the development and operation activities using the software to be analyzed will be analyzed as "Green (explainable)" in terms of compliance with Article No. 1 (Access Rights).

[0031] <Processing Procedure> Below, we will explain an example of the processing procedure when using the analysis device 10 to analyze whether development and operational activities utilizing one or more software to be analyzed installed on the information processing device 20 meet compliance standards.

[0032] Fig. 7 is a diagram showing an example of a processing procedure performed by the analysis device 10. Figs. 9 and 10 show an example of setting information related to the access authority of software A, and Fig. 11 shows an example of setting information related to the access authority of software B. The processing procedure from when the analysis device 10 acquires the setting information of the software to be analyzed to when it performs preprocessing will be described using Figs. 7 and 9 to 11.

[0033] In step S10, the receiving unit 101 receives from the user the designation of one or more pieces of software to be analyzed that will be used in development and operation activities. For example, the receiving unit 101 may extract the software defined in the acquired data definition information 100a, display a list on a screen, and receive the designation of one or more pieces of software to be analyzed from the list of software displayed on the screen.

[0034] In step S11, the receiving unit 101 receives, from the user, designation of one or more provisions to be analyzed. For example, the receiving unit 101 may extract the compliance standards and provisions defined in the provision definition information 100c, display them as a list on a screen, and receive one or more compliance standards and one or more provisions to be analyzed from the list displayed on the screen.

[0035] In step S12, the analysis unit 103 refers to the "analysis target data" in the provision definition information 100c to determine whether the data to be used in analyzing the specified provision to be analyzed is setting information or manually input data. If the data to be used in analyzing the provision is setting information, the process proceeds to step S13, and if it is manually input data, the process proceeds to step S17.

[0036] In step S13, the analysis unit 103 refers to the acquisition data definition information 100a corresponding to the software to be analyzed, and identifies the setting information corresponding to the category of the clause to be analyzed and the method for acquiring the setting information.

[0037] In step S14, the acquiring unit 102 accesses the information processing device 20 and acquires the setting information identified in step S13 according to the identified acquisition method. For example, if the identified acquisition method is API-A1, the acquiring unit 102 acquires the setting information by calling API-A1 provided in the information processing device 20. For example, when acquiring setting information related to the access authority of analysis target software A, the acquiring unit 102 acquires accessControlList from analysis target software A by calling API-A1. When acquiring setting information related to the access authority of analysis target software B, the acquiring unit 102 acquires accessControlConf from analysis target software B by calling API-B1.

[0038] In step S15, the acquisition unit 102 accesses the first preprocessing information 100b corresponding to the software to be analyzed, and acquires the preprocessing method corresponding to the setting information acquired in step S14.

[0039] In step S16, the analysis unit 103 processes the setting information acquired in step S14 according to the preprocessing method acquired in step S15 to generate preprocessed setting information (hereinafter referred to as "first preprocessed setting information").

[0040] Here, a specific example will be described with reference to Figures 9 and 10. For example, when the analysis unit 103 performs preprocessing on the setting information (accessControlList) of software A shown in Figures 9 and 10, it counts the number of users based on the "preprocessing method" of "accessControlList" in the first preprocessing information 100b shown in Figure 5A. For example, in the example of Figure 9, there are two accounts, aaa@example.co.jp and bbb@example.co.jp, and both accounts have the authority of roles / owner. Similarly, in the example of Figure 10, there is one account, ccc@example.co.jp, and it has the authority of roles / storage.objectviewer. Therefore, the analysis unit 103 generates configuration information after the first pre-processing, which indicates that for the configuration information (accessControlList) of the software A to be analyzed, the number of users who have the authority to access data in the commercial environment (hereinafter referred to as "authority A") is three (aaa@example.co.jp, bbb@example.co.jp, and ccc@example.co.jp), the number of users who have the authority to change the settings of the commercial environment (hereinafter referred to as "authority B") is two (aaa@example.co.jp and bbb@example.co.jp), and the number of users who have the authority to change the authority settings of the user ID (hereinafter referred to as "authority C") is two (aaa@example.co.jp and bbb@example.co.jp).

[0041] Furthermore, when preprocessing the setting information (accessControlConf) of software B shown in FIG. 11, the analysis unit 103 counts the number of users based on the "preprocessing method" of "accessControlConf" in the first preprocessing information 100b shown in FIG. 5B. For example, in the example of FIG. 11, there are three accounts: aaa0001, ddd1234, and eee2345. Aaa0001 and ddd1234 have admin authority, and eee2345 has read authority. Therefore, the analysis unit 103 generates setting information after the first preprocessing, which indicates that the number of users with authority A is 0, the number of users with authority B is 0, and the number of users with authority C is 2 (aaa0001 and ddd1234) for the setting information (accessControlConf) of the software B to be analyzed.

[0042] In step S17, the acquisition unit 102 accepts input of manually input data necessary for analyzing the clause to be analyzed. For example, the acquisition unit 102 may accept input of manually input data by displaying on a screen the conditions defined in "Analysis Method" in B of Fig. 6 and having the user select which conditions are satisfied.

[0043] In step 18, analysis device 10 ends the process if it has executed the processing procedures of steps S12 to S17 for all of the articles accepted from the user as analysis targets. On the other hand, if analysis device 10 has not executed the processing procedures of steps S12 to S17 for some of the articles accepted from the user as analysis targets, analysis device 10 returns to the processing procedure of step S12 and executes the processing procedures of steps S12 to S17 for the remaining articles.

[0044] Fig. 8 is a diagram showing an example of a processing procedure performed by the analysis apparatus 10. The processing procedure when the analysis apparatus 10 analyzes development and operation actions utilizing the software to be analyzed based on the setting information after the first preprocessing and the manually input data will be described with reference to Fig. 8.

[0045] In step S21, the receiving unit 101 determines whether the user specified multiple pieces of software to be analyzed in step S10 (FIG. 7). If the user specified multiple pieces of software to be analyzed, that is, if analysis is to be performed on development and operational activities that utilize multiple pieces of software to be analyzed, the process proceeds to step S22. If the user specified a single piece of software to be analyzed, that is, if analysis is to be performed on development and operational activities that use the software to be analyzed alone, the process proceeds to step S24.

[0046] In step S22, the receiving unit 101 receives, from the user, input of second preprocessing information for analyzing development and operation activities utilizing multiple pieces of analysis target software. The receiving unit 101 also stores the data input by the user in the second preprocessing information 100d in the storage unit 100. The content of the second preprocessing information received from the user may be predetermined for each combination of multiple pieces of analysis target software used in the development and operation activities and for each provision. For example, in the case of a provision regarding access rights, the second preprocessing information may be information that identifies a user common to the multiple pieces of analysis target software among multiple users who have access rights identified from the setting information of each piece of analysis target software. The second preprocessing information may be stored in the storage unit 100 in advance, rather than being input by the user.

[0047] Here, an example of a method for accepting input of second preprocessing information will be specifically described with reference to FIG. 12. The accepting unit 101 may accept input of second preprocessing information from a user using a screen shown in FIG. 12. The screen of FIG. 12 is a screen for accepting input of the names and account names of users who have accounts for software A and software B, which are the analysis targets. According to the content entered in FIG. 12, user A has both an account for software A (aaa@example.co.jp) and an account for software B (aaa0001). User B has an account for software A (bbb@example.co.jp). User C has an account for software A (ccc@example.co.jp). User D has an account for software B (ddd1234). User E has an account for software B (eee2345).

[0048] 12, it can be seen that the account for software A (aaa@example.co.jp) and the account for software B (aaa0001) belong to the same user A. In this way, the second preprocessing information may be information that can identify accounts owned by the same user among multiple software accounts.

[0049] In step S23, the analysis unit 103 uses the second preprocessing information and the setting information after the first preprocessing to generate setting information after preprocessing for the entire plurality of software to be analyzed (hereinafter also referred to as "setting information after the second preprocessing"). The setting information after the second preprocessing described below can be said to be information obtained by aggregating the setting information after the first preprocessing for each of the plurality of software to be analyzed, and therefore may also be called "aggregated information."

[0050] As explained in step S16 (FIG. 7), in the examples of FIGS. 9 to 11, the analysis unit 103 generated setting information after the first preprocessing, which indicates that for the setting information (accessControlList) of the analysis target software A, the number of users having authority A is three (aaa@example.co.jp, bbb@example.co.jp, and ccc@example.co.jp), the number of users having authority B is two (aaa@example.co.jp and bbb@example.co.jp), and the number of users having authority C is two (aaa@example.co.jp and bbb@example.co.jp). Furthermore, for the setting information (accessControlConf) of the analysis target software B, the analysis unit 103 generated setting information after the first preprocessing, which indicates that the number of users having authority A is zero, the number of users having authority B is zero, and the number of users having authority C is two (aaa0001 and ddd1234).

[0051] Furthermore, as explained in step S22, information indicating that the account (aaa@example.co.jp) for software A and the account (aaa0001) for software B are the accounts of the same user A has been input as the second preprocessing information. In other words, the user aaa@example.co.jp who has authority C in the software A to be analyzed and the user aaa0001 who has authority C in the software B to be analyzed are the same person. Therefore, the analysis unit 103 generates setting information after the second preprocessing that indicates that, for the software A and B to be analyzed together, the number of users who have authority A is three (3+0), the number of users who have authority B is two (2+0), and the number of users who have authority C is three (2+2-1).

[0052] In step S24, the analysis unit 103 performs an analysis of the provisions based on the post-preprocessing setting information (the post-first preprocessing setting information or the second provision definition information) and the provision definition information. If the software to be analyzed designated by the user in step S21 is a single software, the analysis unit 103 compares the post-first preprocessing setting information with provision analysis information corresponding to one or more provisions of the software to be analyzed to analyze whether the development and operation actions utilizing the software to be analyzed satisfy the provisions. On the other hand, if the user designates multiple software to be analyzed in step S21, the analysis unit 103 compares the post-second preprocessing setting information with provision analysis information corresponding to one or more provisions of the software to be analyzed to analyze whether the development and operation actions utilizing the multiple software to be analyzed satisfy the provisions. For example, when comparing the setting information after the second pre-processing generated in the example described in step S23 with Article No. 1 of Compliance Standard A shown in example A of Figure 6, the setting information after the second pre-processing is determined to fall under Red (unexplainable) because the number of users with authority C is three.

[0053] In step S25, the output unit 104 outputs the analysis results for one or more provisions of the analysis target. Fig. 13 shows an example of the output analysis results. In the example of Fig. 13, as a result of analyzing whether or not the development and operation activities utilizing both of the software A and B to be analyzed satisfy provision No. 1 of the compliance standard A, the analysis result displayed is that it is impossible to explain compliance with the provisions. In addition, the analysis result displayed is that it is possible to explain compliance with provision No. 2 of the compliance standard A.

[0054] In the present embodiment described above, all or part of the information indicated by the acquired data definition information 100a, the first preprocessing information 100b, the provision definition information 100c, and the second preprocessing information 100d may be embedded as processing logic in the program of the analysis device 10, rather than being stored in the storage unit 100. For example, when the acquired data definition information 100a is embedded as processing logic in the program of the analysis device 10, in the processing procedure of step S13 in FIG. 7, the analysis unit 103 may identify setting information corresponding to the category of the provision to be analyzed and a method for acquiring the setting information according to the processing logic.

[0055] <Summary> According to the embodiment described above, the analysis device 10 acquires, from the software to be analyzed, setting information necessary for analyzing whether development and operation activities using the software satisfy the compliance standards, and analyzes the acquired setting information to analyze whether development and operation activities using the software satisfy the compliance standards. This makes it possible to automatically analyze whether development and operation activities using the software comply with the compliance standards for IT systems. The above-described embodiments are intended to facilitate understanding of the present invention and are not intended to limit the present invention. The flowcharts, sequences, elements included in the embodiments, and their arrangements, materials, conditions, shapes, sizes, etc., described in the embodiments are not limited to those illustrated and can be modified as appropriate. Furthermore, configurations shown in different embodiments can be partially substituted or combined with each other. [Explanation of symbols]

[0056] 1 Analysis system, 10 Analysis device, 11 Processor, 12 Storage device, 13 Network IF, 14 Input device, 15 Output device, 20 Information processing device, 100 Storage unit, 100a Acquisition data definition information, 100b First preprocessing information, 100c Provision definition information, 100d Second preprocessing information, 101 Reception unit, 102 Acquisition unit, 103 Analysis unit, 104 Output unit

Claims

1. a reception unit that receives designation of software to be analyzed; an acquisition unit that acquires, from a device in which the software to be analyzed is installed, setting information used when the software to be analyzed operates; an analysis unit that analyzes whether or not it is possible to explain whether development and operation activities utilizing the software to be analyzed satisfy compliance standards for IT systems based on the setting information; an output unit that outputs the analysis result by the analysis unit; An analytical device having:

2. the analysis unit performs preprocessing on the setting information to generate preprocessed setting information, and analyzes whether it is possible to explain whether the setting information satisfies the compliance standard by comparing the generated preprocessed setting information with definition information that defines an analysis method for explaining whether it is possible to explain whether the preprocessed setting information satisfies the compliance standard. The analytical device of claim 1 .

3. the receiving unit receives designation of a plurality of pieces of software to be analyzed; the acquiring unit acquires the setting information of each of the plurality of pieces of software to be analyzed from a device in which each of the plurality of pieces of software to be analyzed is installed; The analysis unit analyzes the setting information of each of the plurality of software to be analyzed, thereby obtaining an aggregation result of the setting information of each of the plurality of software to be analyzed, and compares the aggregation result with definition information that defines an analysis method for determining whether or not the compliance standard is satisfied, thereby analyzing whether or not the development and operation actions utilizing the plurality of software to be analyzed can be determined to satisfy the compliance standard. The analytical device of claim 1 .

4. An analysis method performed by an analysis device, A step of receiving designation of software to be analyzed; acquiring, from a device in which the software to be analyzed is installed, setting information used when the software to be analyzed operates; analyzing whether or not it is possible to demonstrate that development and operational activities utilizing the software to be analyzed satisfy compliance standards for IT systems based on the setting information; outputting an analysis result from the analyzing step; Analytical methods including:

5. On the computer, A step of receiving designation of software to be analyzed; acquiring, from a device in which the software to be analyzed is installed, setting information used when the software to be analyzed operates; analyzing whether or not it is possible to demonstrate that development and operational activities utilizing the software to be analyzed satisfy compliance standards for IT systems based on the setting information; outputting an analysis result from the analyzing step; A program to execute.