Analysis device, analysis method, and program

The system automates compliance analysis with ISO27001, ISO27002, ISMAP, and FISC standards, addressing inefficiencies in IT system development and operation, ensuring adherence to multiple compliance standards and reducing errors.

JP2025186982AActive Publication Date: 2025-12-24PWC BUSINESS ASSURANCE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024111709
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-11
Publication Date
2025-12-24
Estimated Expiration
2044-06-12

AI Technical Summary

Technical Problem

Companies face significant challenges in complying with various compliance standards during the development and operation of IT systems, as existing technologies fail to address the need to automate the analysis of compliance with these standards, resulting in inefficiencies and compliance risks.

Method used

The system includes an analytical device that analyzes compliance with various compliance standards, including ISO27001, ISO27002, ISMAP, and FISC guidelines, by receiving software designation, acquiring setting information, and determining compliance with the standards, and outputting analysis results.

Benefits of technology

The system automates compliance analysis, reducing labor and risk of errors, and ensuring adherence to multiple compliance standards, enabling automated analysis of software development and operation activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025186982000001_ABST
    Figure 2025186982000001_ABST
Patent Text Reader

Abstract

To automatically analyze compliance with compliance standards related to an IT system.SOLUTION: An analysis device includes: a reception section that receives designation of analysis target software that is an analysis target; an acquisition section that acquires setting information used when the analysis target software operates from a device in which the analysis target software is installed; an analysis section that analyzes whether or not it is possible to explain that development and operation activities utilizing the analysis target software satisfy compliance standards related to an IT system on the basis of the setting information; and an output section that outputs an analysis result by the analysis section.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Currently, there are various compliance standards that must be observed in the development and operation of IT systems. For example, Non-Patent Document 1 describes the IT risks related to financial accounting systems, The control mechanism and the current state of IT control are disclosed. Software that automates parts of code version management, product generation, and delivery to the operating environment The clothing is shown. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] “IT Control and IT Control Standards”, [online], Financial Services Agency, Internet<URL:https: / / www.fsa.go.jp / singi / singi_kigyou / siryou / naibu / 20050310 / 01.pdf> [Non-patent document 2] “Technical Report on Security Considerations in CI / CD Pipelines”, [online], Digital Agency, Internet <URL: https: / / www.digital.go.jp / assets / contents / node / basic_page / field_ref_resources / e2a06143-ed29-4f1d-9c31-0f06fca67afc / 33f31336 / 20240329_resources_standard_guidelines_guideline_01.pdf> Summary of the Invention [Problem to be solved by the invention]

[0004] Companies that develop and operate IT systems must comply with various compliance standards. In addition, some companies require multiple auxiliary solutions for the development and operation of their IT systems. By utilizing software, we aim to reduce labor and the risk of work errors. The software used by companies to develop and operate IT systems has a huge number of functions. Furthermore, the requirements of the compliance standards are wide-ranging, To analyze whether IT systems are being developed and operated while complying with the standards, It will require a huge amount of work.

[0005] Therefore, the present invention provides a system that complies with compliance standards regarding the development and operation of IT systems. The present invention aims to provide a technology that enables automatic analysis of what is happening in a user's environment. [Means for solving the problem]

[0006] An analysis device according to one aspect of the present invention receives designation of analysis target software that is an analysis target. The reception desk where the software to be analyzed is installed and the device where the software to be analyzed is installed. an acquisition unit that acquires setting information used when the software is running, and an analysis unit that acquires setting information based on the setting information. Development and operation activities using software are subject to compliance with IT systems. The analysis part analyzes whether or not the criteria can be met, and the results of the analysis by the analysis part are and an output unit for outputting the signal. [Effects of the Invention]

[0007] According to the present invention, compliance standards regarding the development and operation of IT systems are observed. It is possible to provide a technique that enables automatic analysis of the presence of [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a system configuration of an analysis system according to an embodiment of the present invention. [Figure 2] FIG. 2 illustrates an example of a hardware configuration of an analysis apparatus. [Figure 3] FIG. 2 is a diagram illustrating an example of a functional block configuration of an analysis device. [Figure 4] FIG. 10 is a diagram illustrating an example of acquired data definition information. [Figure 5] FIG. 10 is a diagram illustrating an example of first preprocessing information. [Figure 6] FIG. 10 is a diagram illustrating an example of provision definition information. [Figure 7] FIG. 10 is a diagram illustrating an example of a processing procedure performed by the analysis device. [Figure 8] FIG. 10 is a diagram illustrating an example of a processing procedure performed by the analysis device. [Figure 9] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 10] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 11] FIG. 10 is a diagram illustrating an example of setting information regarding access authority. [Figure 12] FIG. 10 is a diagram showing an example of a screen for accepting input of second pre-processing information. [Figure 13] FIG. 10 is a diagram illustrating an example of an output of an analysis result. DETAILED DESCRIPTION OF THE INVENTION

[0009] An embodiment of the present invention will be described with reference to the accompanying drawings. Those marked with the same or similar symbols have the same or similar configurations.

[0010] <System configuration> FIG. 1 is a diagram showing an example of the system configuration of an analysis system 1 according to this embodiment. The system 1 includes an analytical device 10 and one or more information processing devices 20. The information processing devices 20 are connected to each other via a wireless or wired communication network N. They can communicate with each other.

[0011] The analysis device 10 is configured such that software running on the information processing device 20 is used for the development and It is a device that analyzes whether various compliance standards related to the operation and management are being observed. The analysis device 10 may be a personal computer, or may be one or more servers, etc. It's okay to have it.

[0012] The information processing device 20 is configured to process software to be analyzed (hereinafter referred to as "analysis target software"). The software to be analyzed is a system in which the company has installed IT systems (e.g., a company's internal systems, internal tools, and the systems that a company uses to provide services to its customers) It is software used in the development and operation of software for providing services. For example, source code version control tools, Tools to help create, manage development and operation work, and access to IT systems Includes tools to control access and manage permissions.

[0013] Various compliance standards for IT systems consist of multiple clauses that set specific standards. Compliance standards are made up of statements such as: ISO27001 and ISO27002, which are standards related to information systems (ISMS), ISMAP (Information system Security Assessment Program for Information Systems) ity Management and Assessment Program), FISC(The Center for Financial Indus Security standards for computer systems of financial institutions, etc., established by the Financial Services Agency (FSA) Examples of such guidelines include, but are not limited to, the FISC guidelines.

[0014] The analysis device 10 determines whether development and operation activities utilizing the software to be analyzed are performed in accordance with the designated code. Analyze whether or not it is possible to demonstrate compliance with compliance standards, and output the analysis results More specifically, the analysis device 10 receives from the information processing device 20 the information set in the software to be analyzed. By acquiring various setting information set in the software and checking the acquired setting information, the software to be analyzed can be Developing and operating activities using software meet the provisions of the compliance standards. The results of the analysis are classified into, for example, explainable, partially explainable, and It can be classified into three types: explainable and inexplicable. The state in which the development and operation activities performed meet the specified compliance standards (i.e. (The state in which it is possible to explain to a third party that it meets the standards.) Being able to be explained in a specific way means that the development and operation activities using the software being analyzed are Partial compliance (i.e., partial compliance with the standard) In addition, the term "unexplainable" refers to the state in which the software being analyzed is If development and operation activities using the software do not meet the specified compliance standards, This means that the product is in a state where it is not possible to explain to a third party that it meets the standards. Setting information can be obtained using API (Application Programming Interface) Alternatively, the setting file may be downloaded from the information processing device 20. In the following explanation, the term "compliance standards" may be used. "Meets or does not meet the compliance standards" is "Can you explain that you meet the compliance standards?" Similarly, "whether the provisions are met" is synonymous with "whether the provisions are met." This is synonymous with "whether it is possible to explain why something is so."

[0015] For example, security compliance standards include "Users with administrative privileges" Assume that there is a clause that states "the number of people is N or less." In this case, the analysis device 10 The setting information regarding the authority setting of the user account is acquired from the information processing device 20. By analyzing the configuration information, it is possible to identify N users who have administrator privileges for the software being analyzed. Analyze whether there are N or fewer users with administrator privileges. The analysis device 10 determines whether the development and operation activities using the software to be analyzed satisfy the provisions. It can be concluded that

[0016] Furthermore, the analysis device 10 is configured to check whether development and operation activities using the software to be analyzed are compliant. The software being analyzed was used alone to determine whether it met the application criteria. The analysis may be performed on development and operation activities, or on multiple software to be analyzed. For example, the development and operational activities using "administrator privileges" may be analyzed. If there is a provision that states "the number of users who have the same password shall be four or less," the analysis device 10 Acquire setting information regarding permission settings from each of the software to be analyzed, and By aggregating and analyzing the configuration information of multiple target software, Analyze whether there are four or fewer authorized users. For example, for software A, The users who have administrative privileges are users M, N, and P, and they have administrative rights over software B. The users with administrator privileges are users M, Q, and R. In this case, if the software When analyzing development and operational activities using Software A alone, Since there are three users with user authority (users M, N, and P), the provision is met. On the other hand, the development and operation activities using both software A and B are analyzed. When this is done, there are five users with administrator privileges in either software A or B (users M, N, P, Q and R), so the provisions are not met.

[0017] <Hardware configuration> 2 is a diagram illustrating an example of the hardware configuration of the analysis device 10. The analysis device 10 includes a CPU (Central Processing Unit), GPU (Graphics Processing Unit) and other processors1 1. Memory (e.g., RAM (Random Access Memory) or ROM (Read Only Memory)) a storage device 12 such as a hard disk drive (HDD) and / or a solid state drive (SSD) a network interface (IF) 13 for wired or wireless communication; The input device 14 receives information and outputs information. For example, the output device 15 is a keyboard, a touch panel, a mouse, and / or a microphone. For example, a display, a touch panel and / or a speaker.

[0018] <Function block configuration> 3 is a diagram showing an example of a functional block configuration of the analysis device 10. The analysis device 10 includes a storage unit 100, a receiving unit 101, an acquiring unit 102, an analyzing unit 103, and an output unit 104. The storage unit 100 can be realized by using the storage device 12 included in the analysis device 10. The receiving unit 101, the acquiring unit 102, the analyzing unit 103, and the output unit 104 are an analysis device 1. The processor 11 executes a program stored in the storage device 12. The program can be stored in a storage medium. The storage medium storing the program is a computer-readable non-transitory storage medium (Non- Non-transitory computer-readable medium may also be used. Although not specified, for example, USB (Universal Serial Bus) memory or CD-ROM (Compact The recording medium may be a recording medium such as a disc read-only memory.

[0019] The storage unit 100 stores acquired data definition information 100a, first preprocessing information 100b, clause definition information 100c, and The acquired data definition information 100a stores the first pre-processing information 100c and the second pre-processing information 100d. To analyze whether the software meets the compliance standards, The first preprocessing information 100b indicates the setting information to be acquired from the software to be analyzed. A method for preprocessing the acquired setting information is defined. Specifically, the first preprocessing information 100 is defined as follows: b) describes the processing method for converting the configuration information into data in a format that can be used for analysis, and Define the method for generating data to be used for analysis from the software to be analyzed. The setting information obtained from the software is written in a format specific to the software. Therefore, in this embodiment, the first pretreatment By using the processing information 100b to preprocess the setting information, compliance standards are It is designed to generate data that can be directly used to analyze whether the requirements are met.

[0020] The provision definition information 100c is a method for analyzing whether or not compliance standards are met. The second pre-processing information 100d defines a plurality of compliance standards and clauses. The development and operation activities using the software to be analyzed meet the compliance standards. This information is used to analyze whether the first preprocessing information 100b is converted or not. The generated data is only data about each software being analyzed, and Whether the development and operation activities using the software to be analyzed meet the compliance standards Therefore, in this embodiment, the second preprocessing The data converted or generated according to the first preprocessing information 100b is then processed using the information 100d. The number of analyzed data is directly usable for analyzing development and operational activities using the software. It is intended to be converted or processed.

[0021] The receiving unit 101 receives the designation of the software to be analyzed. Section 101 specifies the provisions to be analyzed from among the multiple provisions contained in the compliance standards. The receiving unit 101 also receives the designation of multiple pieces of software to be analyzed. You can do this.

[0022] The acquisition unit 102 acquires the information processing device 20 (device) in which the software to be analyzed is installed. ) to acquire the configuration information used when the target software runs. 102 is a system for analyzing the installed software of each of the plurality of software to be analyzed received by the receiving unit 101. The setting information of each of the plurality of pieces of software to be analyzed is acquired from the information processing device 20. The acquisition unit 102 may acquire the information provided by the information processing device 20 or the software to be analyzed. Alternatively, the setting information may be acquired by calling an API corresponding to the setting information. Alternatively, a file containing the setting information may be downloaded from the

[0023] The analysis unit 103 analyzes the software to be analyzed based on the setting information acquired by the acquisition unit 102. Analyze whether development and operational activities using software meet compliance standards More specifically, the analysis unit 103 analyzes the clause definitions corresponding to the specified compliance standards. The information 100c is acquired from the storage unit 100. Next, the analysis unit 103 analyzes the acquired setting information. The information is preprocessed in accordance with the first preprocessing information 100b to generate preprocessed setting information. The generated pre-processed configuration information and the pre-processed configuration information meet the compliance standards. The analysis method for whether or not the condition is satisfied is compared with the provision definition information 100c (definition information) in which the condition is defined. By doing so, it analyzes whether the configuration information meets the compliance standards.

[0024] The analysis unit 103 analyzes the setting information of each of the plurality of pieces of software to be analyzed. The evaluation is based on the aggregated settings of each software configuration. A clause that defines how to obtain the results and analyze whether or not they meet compliance standards. By comparing the definition information 100c (definition information) with the evaluation results, multiple analysis target solutions are Whether development and operation activities using software meet compliance standards Analyze.

[0025] The output unit 104 outputs the analysis results from the analysis unit 103 to a display, a printer, etc. .

[0026] 4 is a diagram showing an example of the acquired data definition information 100a. Since the acquired data definition information 100a differs depending on the software to be analyzed, It is prepared for each software. A in Figure 4 is the acquisition data definition corresponding to software A. 4 shows an example of the information 100a. Also, B in FIG. 4 shows the acquired data corresponding to the software B. 1 shows an example of data definition information 100a. "Category" indicates the type of category to which the setting information belongs. The types of categories stored in "Category" are explained in Figure 6 below. It is the same as the category type stored in the "Category" of the compliance standard article. In the example of Figure 4A, "accessControlList" is setting information related to access authority. "Acquisition method" indicates the method for acquiring the setting information. "Setting information" indicates the method for acquiring the setting information. For example, in the example in Figure 4, calling API-A1 indicates the name of the setting information to be acquired. You can get the setting information called "accessControlList" by calling API-A2. By calling this command, you can obtain configuration information called "logConfig".

[0027] 5 is a diagram showing an example of the first preprocessing information 100b. Since the software differs depending on the software, the first preprocessing information 100b is "Setting information" indicates the name of the setting information to be preprocessed. The "setting information" indicates the content of the data obtained by preprocessing the setting information. " shows how to generate preprocessed data by preprocessing the configuration information. However, for example, it is possible to extract information necessary for analysis from the setting information. , converting the format of the setting information into another format, etc.

[0028] In the example of A in Figure 5, the number of users who have the authority to change the authority settings of the user ID (authority C) In the accessControlList, "roles / owner", "roles / iam.roleAdmin" or "roles Count the number of user accounts that have either "es / iam.securityAdmin" or "iam.securityAdmin" set. It is defined that the data can be extracted by

[0029] 6 is a diagram showing an example of the provision definition information 100c. It represents the category type. All or part of the category types that can be stored in "Category" is the same as the type of category that can be stored in the "category" of the acquired data definition information 100a. "Data to be analyzed" indicates the type of data used to analyze the provisions. If the setting information is set in ", the setting information obtained from the software to be analyzed (more Specifically, this means analyzing the clauses using the preprocessed setting information. If "Data for analysis" is set to manual input data, the data manually input by the user This means that the clauses are analyzed using the software to be analyzed. The settings obtained from the software being analyzed, such as the provisions regarding the physical security of the room in which the software is used, There are provisions that cannot be analyzed from the fixed information. In this case, the analysis will be performed using manually entered data from the user's responses.

[0030] "Analysis method" indicates how to analyze the setting information or manually entered data. For example, In the example of A in FIG. 6, the setting information after preprocessing indicates that the number of users with authority A is 1 or less, and If the number of users with authority B is 1 or less and the number of users with authority C is 1 or less, If the conditions are met, the development and operation activities using the software to be analyzed are Compliance with No. 1 (access rights) is considered "Green (explainable)." It has been shown that the

[0031] <Processing Procedure> Hereinafter, the analysis device 10 is used to analyze one or more components installed in the information processing device 20. Compliance standards are met for development and operation activities using the software to be analyzed. An example of a processing procedure for analyzing whether or not the device is connected will be described.

[0032] FIG. 7 is a diagram showing an example of a processing procedure performed by the analysis device 10. Also, FIGS. 9 and 10 are , an example of setting information regarding the access authority of software A. 7 and 9 to 11, which are examples of setting information regarding the access authority of A and B, Processing procedure from when the analysis device 10 acquires the setting information of the software to be analyzed to when it performs pre-processing Explain.

[0033] In step S10, the reception unit 101 receives from the user one or more items to be used in development and operation activities. For example, the receiving unit 101 receives the specification of the software to be analyzed. The software defined in the definition information 100a is extracted and displayed as a list on the screen. From the list of software displayed in the It may be possible to attach it.

[0034] In step S11, the reception unit 101 receives from the user the specification of one or more articles to be analyzed. For example, the reception unit 101 receives the compliance information defined in the provision definition information 100c. The answer criteria and clauses are extracted and displayed on the screen as a list. It accepts one or more compliance standards and one or more articles to be analyzed. That's fine.

[0035] In step S12, the analysis unit 103 refers to the "analysis target data" in the provision definition information 100c. By checking the data, it is possible to determine whether the data used to analyze the specified provisions of the analysis target is setting information or not. Identify whether the data is manually entered or not. If the data used to analyze the provisions is setting information If the data is manually input, the process proceeds to step S13. Proceed in order.

[0036] In step S13, the analysis unit 103 obtains the acquired data definition corresponding to the software to be analyzed. By referring to the information 100a, setting information corresponding to the category of the article to be analyzed and the setting information Identify how to obtain it.

[0037] In step S14, the acquisition unit 102 accesses the information processing device 20, and The setting information specified in the step (1) is acquired according to the specified acquisition method. When the acquisition method is API-A1, the acquisition unit 102 acquires the API- By calling A1, the setting information is acquired. For example, When acquiring setting information related to the access authority, the acquisition unit 102 calls the API-A1. Then, obtain the accessControlList from the analysis target software A. When acquiring setting information regarding the access authority of the software B, the acquisition unit 102 By calling B1, accessControlConf is obtained from the software B to be analyzed.

[0038] In step S15, the acquisition unit 102 acquires first preprocessing information corresponding to the software to be analyzed. 100b and obtains the preprocessing method corresponding to the setting information obtained in step S14. do.

[0039] In step S16, the analysis unit 103 analyzes the setting information acquired in step S14 as By processing according to the preprocessing method acquired in S15, the preprocessed setting information (hereinafter referred to as 1) to generate the post-preprocessing setting information.

[0040] Here, a specific example will be described with reference to Figs. 9 and 10. For example, the analysis unit 103 The setting information (accessControlList) of software A shown in FIG. 10 is preprocessed. In this case, the "preprocessing" of "accessControlList" in the first preprocessing information 100b shown in A of FIG. For example, in the example in Figure 9, the number of users is counted based on the "administration method." There are two accounts, p and bbb@example.co.jp, and both accounts have roles / ow Similarly, in the example in Figure 10, one account, ccc@example.co.jp, has the authority to exists and has the role / storage.objectviewer authority. Regarding the configuration information (accessControlList) of the software A to be analyzed, There are three users (aaa@example.com) who have the authority to view the data (hereinafter referred to as "Authority A"). co.jp, bbb@example.co.jp and ccc@example.co.jp), and change the settings for the commercial environment The number of users with authority (hereinafter referred to as "Authority B") is two (aaa@example.co.jp and bbb@e xample.co.jp) and the authority to change the authority settings of the user ID (hereinafter referred to as "Authority C" ) is two users (aaa@example.co.jp and bbb@example.co.jp). Then, the setting information after the first pre-processing is generated.

[0041] In addition, the setting information (accessControlConf) of software B shown in Figure 11 is preprocessed. When performing the above, the analysis unit 103 uses the “access The number of users is counted based on the "preprocessing method" of "ControlConf". For example, in Figure 11 In this example, there are three accounts: aaa0001, ddd1234, and eee2345. 4 has admin authority and eee2345 has read authority. The analysis unit 103 then analyzes the setting information (accessControlConf) of the analysis target software B. Therefore, the number of users with authority A is 0, the number of users with authority B is 0, and the number of users with authority C is 0. The setting information after the first preprocessing indicates that the number of users is two (aaa0001 and ddd1234). Generates information.

[0042] In step S17, the acquisition unit 102 acquires the manual input data necessary to analyze the article to be analyzed. For example, the acquisition unit 102 receives the input of the data defined in "Analysis Method" in B of FIG. The conditions are displayed on the screen and the user is allowed to select which conditions are met. The input of input data may be accepted.

[0043] In step 18, the analysis device 10 receives all the articles that have been accepted as the subject of analysis from the user. When the processing procedure from step S12 to step S17 has been executed for the above, the processing ends. On the other hand, the analysis device 10 receives a status report for a part of the article accepted as an analysis target from the user. If the processing procedure from step S12 to step S17 has not been executed, the processing procedure of step S12 Returning to the previous step, the processing procedure of steps S12 to S17 is executed for the remaining clauses. .

[0044] FIG. 8 is a diagram showing an example of a processing procedure performed by the analysis device 10. 10 uses the software to be analyzed based on the setting information after the first preprocessing and the manually input data. This section explains the procedure for analyzing development and operational activities using the

[0045] In step S21, the reception unit 101 receives the address specified by the user in step S10 (FIG. 7). It is determined whether there are multiple pieces of software to be analyzed. In the case where there are multiple target software, that is, development using multiple target software If analysis is to be performed on the issuing and operating actions, the process proceeds to step S22. When the analyzed software is a standalone software, that is, when the analyzed software is a standalone software, If the development and operation actions used in the step S21 are to be analyzed, the process proceeds to step S24.

[0046] In step S22, the receiving unit 101 receives a request from the user for utilizing a plurality of pieces of software to be analyzed. The system accepts input of second pre-processing information for analyzing the development and operation activities. In addition, the receiving unit 101 stores the data input by the user in the second preprocessing information 1 in the storage unit 100. The contents of the second pre-processing information received from the user are stored in 00d. The combination of multiple software to be analyzed and the For example, in the case of provisions related to access rights, the second preprocessing information may be Among multiple users with access rights identified from the software configuration information, multiple It may also be information that identifies a user common to the software to be analyzed. The preprocessing information is not input by the user, but is stored in advance in the storage unit 100. It's fine.

[0047] Here, an example of a method for receiving input of the second pre-processing information will be specifically explained with reference to FIG. 12. The receiving unit 101 receives input of second pre-processing information from the user using the screen shown in FIG. The screen in FIG. 12 shows software A and software B to be analyzed. For each of Software B, the name and account number of the user who has an account According to the information entered in Figure 12, User A is Software A's account (aaa@example.co.jp) and Software B's account (aaa0001 ) and User B has an account for Software A (bbb@example. User C has an account for Software A (ccc@example.co.jp). User D has an account (ddd1234) for Software B. In addition, user E has an account for software B (eee2345).

[0048] From the information entered in Figure 12, the account of software A (aaa@example.co.jp) The account (aaa0001) for software B is the same account for user A. In this way, the second preprocessing information is used to identify the same user among multiple software accounts. It may also be information that can identify the account held by the user.

[0049] In step S23, the analysis unit 103 uses the second preprocessing information and the setting information after the first preprocessing. In this case, the setting information after preprocessing for the entire software to be analyzed (hereinafter referred to as "second preprocessing") The second pre-processed setting information described below is generated by It can be said that this information is a compilation of the configuration information after the first preprocessing of each software to be analyzed. Therefore, it may be called "aggregated information."

[0050] As explained in step S16 (FIG. 7), in the examples of FIGS. 9 to 11, the analysis unit 103 For the setting information (accessControlList) of the software A to be analyzed, There are three users (aaa@example.co.jp, bbb@example.co.jp, and ccc@example.co.jp), The number of users with authority B is two (aaa@example.co.jp and bbb@example.co.jp). The number of users with limit C is two (aaa@example.co.jp and bbb@example.co.jp). The analysis unit 103 generates the setting information after the first preprocessing, which is shown in FIG. Regarding the setting information (accessControlConf) of A B, the number of users with authority A is 0, The number of users with authority B is 0, and the number of users with authority C is 2 (aaa0001 and ddd12 34), we generated the setting information after the first preprocessing.

[0051] As explained in step S22, the second pre-processing information is The account (aaa@example.co.jp) and the account (aaa0001) of Software B are the same user. The information entered indicates that it is the account of User A. A user aaa@example.co.jp with authority C in software A and a user aaa@example.co.jp with authority C in software B The user of aaa0001 who has C is the same person. For software A and B as a whole, the number of users with authority A is 3 (3+0), and The number of users with authority B is 2 (2+0), and the number of users with authority C is 3 (2+2- 1) The second pre-processed setting information is generated, which indicates that the second pre-processed setting information is 1).

[0052] In step S24, the analysis unit 103 analyzes the pre-processed setting information (first pre-processed setting information or The second analysis is performed on the clause based on the clause definition information. In step S21, if the software to be analyzed designated by the user is a single piece of software, The analysis unit 103 analyzes the setting information after the first preprocessing and the clauses corresponding to one or more clauses to be analyzed. By comparing the analysis information with the software, the development and operation activities using the software to be analyzed can be On the other hand, in step S21, the system analyzes whether the clause is satisfied. If there are multiple pieces of software to be analyzed, the analysis unit 103 , and compare the analysis information with the analysis information corresponding to one or more articles to be analyzed. Analyze whether the development and operation activities using the target software meet the provisions. For example, the setting information after the second pre-processing generated in the example described in step S23 and A in FIG. When comparing the example of Compliance Standard A with Article No. 1, the second pre-processing The information indicates that there are three users with authority C, so it falls under Red (unexplainable). It will be determined that this is the case.

[0053] In step S25, the output unit 104 outputs the analysis results for one or more articles to be analyzed. Figure 13 shows an example of the analysis result output. In the example of Figure 13, the analysis target software A and The development and operation activities that utilize both A and B meet Article No. 1 of Compliance Standard A. As a result of analyzing whether or not the product complies with the provisions, the analysis result shows that it is impossible to explain whether the product complies with the provisions. In addition, it has been confirmed that the company complies with Article No. 2 of Compliance Standard A. The analysis results show that the explanation is possible.

[0054] In the present embodiment described above, the acquired data definition information 100a, the first preprocessing information 10 0b, the provision definition information 100c, and the second preprocessing information 100d are all or part of the information indicated by The processing logic is not stored in the memory unit 100, but is stored in the program of the analysis device 10. For example, the acquired data definition information 100a may be embedded in the profile of the analysis device 10. If the processing logic is embedded in the program, the processing procedure in step S13 of FIG. In this case, the analysis unit 103 determines the category of the clause to be analyzed according to the processing logic. The setting information corresponding to the above and the method for acquiring the setting information may be specified.

[0055] <Summary> According to the embodiment described above, the analysis device 10 extracts the relevant Whether software development and operation practices meet compliance standards By acquiring the configuration information necessary for analyzing the software, Analyze whether the development and operational activities used meet compliance standards. This has enabled software-based development and operation activities to be implemented in accordance with the IT system regulations. This allows automated analysis of compliance with applicable compliance standards. The above-described embodiments are intended to facilitate understanding of the present invention and are not intended to limit the present invention. The flowcharts, sequences, and implementations described in the embodiments are not intended to be interpreted as a single entity. The elements of the embodiment, as well as their arrangement, materials, conditions, shapes, sizes, etc., are merely examples. The present invention is not limited to the above and can be modified as appropriate. The components may be partially substituted or combined. [Explanation of symbols]

[0056] 1 analysis system, 10 analysis device, 11 processor, 12 storage device, 13 network Network IF, 14 input device, 15 output device, 20 information processing device, 100 memory unit 100a: Acquired data definition information; 100b: First preprocessing information; 100c: Provision definition information , 100d second preprocessing information, 101 reception unit, 102 acquisition unit, 103 analysis unit, 10 4 Output section

Claims

1. a reception unit that receives designation of software to be analyzed; The software to be analyzed is transmitted from the device on which the software to be analyzed is installed. an acquisition unit that acquires setting information used when the Based on the setting information, the development and operation activities utilizing the software to be analyzed are performed. Analyze whether it is possible to demonstrate that compliance standards for the T system are met. an analysis section, an output unit that outputs the analysis result by the analysis unit; An analytical device having:

2. The analysis unit performs preprocessing on the setting information to generate preprocessed setting information. The generated pre-processed configuration information and the pre-processed configuration information satisfying the compliance standard are then By comparing the analysis method with the definition information, it is possible to explain whether the Analyzing whether or not it is possible to demonstrate that the setting information satisfies the compliance standard. Ru, The analytical device of claim 1 .

3. the receiving unit receives designation of a plurality of pieces of software to be analyzed; The acquisition unit acquires the software from a device in which each of the plurality of software to be analyzed is installed. acquire the setting information for each of the plurality of software to be analyzed; The analysis unit analyzes the setting information of each of the plurality of pieces of analysis target software. and obtaining a result of aggregating the setting information of each of the plurality of software to be analyzed. A method for analyzing whether or not the compliance criteria are met is defined. By comparing the definition information with the aggregation results, the software to be analyzed can be utilized. Whether it is possible to explain that the development and operation activities using the Analyze The analytical device of claim 1 .

4. An analysis method performed by an analysis device, A step of receiving designation of software to be analyzed; The software to be analyzed is transmitted from the device on which the software to be analyzed is installed. acquiring setting information used when the Based on the setting information, the development and operation activities utilizing the software to be analyzed are performed. Analyze whether it is possible to demonstrate that compliance standards for the T system are met. and outputting an analysis result from the analyzing step; Analytical methods including:

5. On the computer, A step of receiving designation of software to be analyzed; The software to be analyzed is transmitted from the device on which the software to be analyzed is installed. acquiring setting information used when the Based on the setting information, the development and operation activities utilizing the software to be analyzed are performed. Analyze whether it is possible to demonstrate that compliance standards for the T system are met. and outputting an analysis result from the analyzing step; A program to execute.