Inspection device, inspection method, and program
The inspection apparatus and method offer comprehensive security assessments for public cloud resources by acquiring and comparing environment information with policies, addressing incomplete determinations in existing methods.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-12-02
- Publication Date
- 2026-04-02
AI Technical Summary
Existing cloud monitoring methods fail to provide comprehensive determination of user operations on public cloud resources, leading to incomplete security assessments.
An inspection apparatus and method that acquires environment information from public clouds, compares it with predefined policies, and notifies users of policy violations with severity levels, allowing for comprehensive judgment on resource compliance.
Provides comprehensive judgment results for public cloud resources, enhancing security by identifying and notifying users of policy violations.
Smart Images

Figure 2026057429000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an inspection apparatus, an inspection method, and a program.
Background Art
[0002] The cloud monitoring method and the like described in Patent Document 1 aim to prevent problems in information security caused by loss or intentional operation of cloud resources by users of public clouds. The cloud monitoring method and the like determine whether the operation may increase the security risk based on the log of the operation on the cloud resources by the user in order to achieve the above object.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the above-described cloud monitoring method and the like, as described above, since the determination regarding the operation of the user is based on the log of the operation of the user, the above determination is individual, that is, a comprehensive determination cannot be made.
[0005] An object of the present disclosure is to provide an inspection apparatus, an inspection method, and a program that can give a comprehensive determination result for resources of a public cloud.
Means for Solving the Problems
[0006] To solve the above-mentioned problems, the inspection device relating to this disclosure includes: an acquisition unit that acquires environment information from a public cloud used by a user, which provides a managed service having multiple resources, and which lists the multiple resources within the public cloud and the multiple parameters that the multiple resources have as the status of the managed service; a determination unit that determines whether one of the multiple resources violates one of the multiple policies by comparing the acquired environment information with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environment information must satisfy; and a notification unit that, when it is determined that one resource violates one of the policies, notifies the user of the violation according to the severity of the policy being violated. [Effects of the Invention]
[0007] The inspection device described in this disclosure can provide comprehensive judgment results for public cloud resources. [Brief explanation of the drawing]
[0008] [Figure 1] The configuration of the policy inspection system PKS in Embodiment 1 is shown. [Figure 2] The configuration of the inspection device KS of Embodiment 1 is shown. [Figure 3] The configuration of the public cloud PK in Embodiment 1 is shown. [Figure 4] The configuration of terminal TM in Embodiment 1 is shown. [Figure 5] This shows the operation of the policy inspection system PKS in Embodiment 1. [Figure 6] This shows the compliance KO of Embodiment 1. [Figure 7] This demonstrates the operation of the policy inspection system PKS in Embodiment 2. [Figure 8] The determination result HK for Embodiment 2 is shown. [Figure 9]Shows the determination result HK of Embodiment 2 (Rewrite 1). [Figure 10] Shows the determination result HK of Embodiment 2 (Rewrite 2). [Figure 11] Shows the environmental information KJ of the modified example. [Figure 12] Shows the compliance KO of the modified example. [Figure 13] Shows the hardware configuration of the policy inspection system PKS of Embodiments 1 and 2. [Figure 14] Shows the hardware configuration based on the software implementation of the policy inspection system PKS of Embodiments 1 and 2.
Modes for Carrying Out the Invention
[0009] Embodiments of the policy inspection system according to the present disclosure will be described.
[0010] 〈Embodiment 1〉 The policy inspection system PKS of Embodiment 1 will be described.
[0011] 〈Configuration of Embodiment 1〉 FIG. 1 shows the configuration of the policy inspection system PKS of Embodiment 1.
[0012] As shown in FIG. 1, the policy inspection system PKS of Embodiment 1 includes an inspection device KS, a public cloud PK, and a terminal TM. The inspection device KS, the public cloud PK, and the terminal TM are interconnected via a network NW (for example, the Internet) as shown in FIG. 1.
[0013] In the policy inspection system PKS, as shown in FIG. 1, the inspection device KS monitors the status of the managed service MS by scanning the public cloud PK to obtain the environment information KJ indicating the status of the managed service MS from the public cloud PK, and, if necessary, notifies the violation IH of the managed service MS (details will be described later) to the terminal TM of the user US using the public cloud PK.
[0014] As shown in FIG. 1, the public cloud PK has a managed service MS provided for use by the user US, and the managed service MS includes a plurality of resources REa, REb, Rec,.... Here, the resource RE should be interpreted in a broad sense and may, for example, also mean the user US (particularly, matters related to the user US, the behavior of the user US). For example, the identification number ID and password PW that the user US should input when using the public cloud PK, as well as changing the password PW, are also included in the resource RE.
[0015] Hereinafter, for the sake of easy explanation and understanding, for example, a plurality of names may be collectively referred to by one name. For example, the resources REa, REb, Rec,... may be collectively referred to as the resource RE.
[0016] <Configuration of the inspection device KS> FIG. 2 shows the configuration of the inspection device KS according to Embodiment 1.
[0017] As shown in FIG. 2, the inspection device KS according to Embodiment 1 has an input / output unit NY(KS), a processing unit SY(KS), a storage unit KI(KS), and a communication unit TU(KS).
[0018] The input / output unit NY(KS) is used, for example, by an administrator of the inspection device KS (not shown) to perform input / output for monitoring / control of the operation of the inspection device KS. The input / output unit NY(KS) is, for example, a keyboard, a mouse, a liquid crystal monitor, and a printer.
[0019] The processing unit SY(KS) performs processes related to monitoring the status of the managed service MS of the public cloud PK, such as scan SC (shown in Figure 1).
[0020] The memory unit KI(KS) stores, for example, the data necessary for processing by the processing unit SY(KS).
[0021] The communications unit TU(KS) communicates via the network NW. For example, the communications unit TU(KS) receives environment information KJ (shown in Figure 1) from the public cloud PK, indicating the status of the public cloud PK's managed service MS, and, if necessary, notifies the user US terminal TM that resource RE has violated policy PO (shown in Figure 6, for example), i.e., violation IH (shown in Figure 1).
[0022] <Public Cloud PK Configuration> Figure 3 shows the configuration of the public cloud PK in Embodiment 1.
[0023] The public cloud PK of Embodiment 1, as shown in Figure 3, includes an input / output unit NY(PK), a processing unit SY(PK), a storage unit KI(PK), and a communication unit TU(PK).
[0024] The input / output unit NY(PK) is used by the administrator of the public cloud PK (not shown) to monitor and control the operation of the public cloud PK. Examples of input / output units NY(PK) include keyboards, mice, LCD monitors, and printers.
[0025] The processing unit SY(PK) performs, for example, processing to provide the managed service MS (shown in Figure 1) to the user US, and also returns environmental information KJ (shown in Figure 1) indicating the status of the managed service MS in response to the scan SC (shown in Figure 1) from the inspection device KS.
[0026] The memory unit KI(PK) stores, for example, the data necessary for processing by the processing unit SY(PK).
[0027] The communications unit TU(PK) communicates via the network NW. For example, the communications unit TU(PK) receives scan SC from the inspection device KS and sends environmental information KJ back to the inspection device KS.
[0028] <Terminal™ Configuration> Figure 4 shows the configuration of terminal TM in Embodiment 1.
[0029] The public cloud PK of Embodiment 1, as shown in Figure 3, includes an input / output unit NY(TM), a processing unit SY(TM), a storage unit KI(TM), and a communication unit TU(TM).
[0030] The input / output unit NY(TM) is used by the user US to use the terminal TM. Examples of input / output units NY(TM) include a keyboard, mouse, LCD monitor, and printer.
[0031] The processing unit SY(TM) performs, for example, processing related to the use of managed services MS of the public cloud PK.
[0032] The memory unit KI(TM) stores, for example, the data necessary for processing by the processing unit SY(PK).
[0033] The communications unit TU(TM) communicates via the network NW. For example, the communications unit TU(TM) receives notification of a violation IH (shown in Figure 1) from the inspection device KS, and also sends a message to the inspection device KS indicating whether the violation IH will be resolved or not (including the reason).
[0034] <Correspondence> The processing unit SY(KS) of the inspection device KS corresponds to the "acquisition unit," "determination unit," "notification unit," and "rewrite unit," while the storage unit (KI) of the inspection device KS corresponds to the "storage unit."
[0035] <Operation of Embodiment 1> Figure 5 shows the operation of the policy inspection system PKS in Embodiment 1.
[0036] Figure 6 shows the compliance KO of Embodiment 1.
[0037] The operation of the policy inspection system PKS in Embodiment 1 will be explained with reference to Figures 5 and 6.
[0038] To facilitate explanation and understanding, we will assume that user US (shown in Figure 1) should change their password PW (corresponding to resource REc shown in Figure 1) periodically, i.e., every predetermined period (for example, every month), but that the password PW has exceeded the predetermined period (for example, every month and a half).
[0039] Step ST1: In the inspection device KS (shown in Figure 1), the processing unit SY (KS) scans the public cloud PK (shown in Figure 1) via the network NW (shown in Figure 1) through the API (Application Programming Interface) by scanning SC (shown in Figure 1), thereby obtaining environmental information KJ from the public cloud PK, which includes the status of managed services MS, and more specifically, the status of multiple resources RE. Here, the environmental information KJ includes the status of the password PW that user US should enter when using the public cloud PK (for example, the date and time the password PW was changed).
[0040] In the inspection device KS, the processing unit SY(KS) (shown in Figure 2) stores the environmental information KJ obtained from the public cloud PK in the storage unit KI(KS) (shown in Figure 2).
[0041] Step ST2: In the inspection device KS, the processing unit SY(KS) compares the environmental information KJ described above with the multiple policy POs (shown in Figure 6) defined in the compliance KO (shown in Figure 6) to determine whether the status of resource RE indicated by the environmental information KJ violates any of the policy POs specified in the compliance KO.
[0042] Here, the policy POs (e.g., policies PO1, PO2, PO3) during compliance KO define the desired state of resource REs (e.g., resource REa, REb, REc (illustrated in Figure 1)). More specifically, as shown in Figure 6, policy PO02 defines the content of "authentication," and more precisely, specifies that "the password PW should be changed within '1 month'," defines that the importance is "high," and the threshold is "TH(P02)."
[0043] In the inspection device KS, the processing unit SY(KS) determines that the resource REc (corresponding to the password PW of user US) indicated by the environmental information KJ has not been changed for "one and a half months," thus violating policy PO2.
[0044] Step ST3: In the inspection device KS, if the processing unit SY(KS) determines in step ST2 that a violation has occurred as described above, it notifies the user US terminal TM that resource REc, i.e., user US's password PW, violates policy PO2 (violation IH), according to the importance level "High" (shown in Figure 6) and threshold "TH(PO2)" of policy PO2. Here, the threshold "TH(PO2)" is, for example, numerical information representing the importance level "High".
[0045] In contrast to the above, if the importance level of policy PO2 is "low", the processing unit SY(KS) will not notify the user US terminal TM of the aforementioned violation (violation IH).
[0046] <Effects of Embodiment 1> As described above, in the policy inspection system PKS of Embodiment 1, when the inspection device KS determines that resource REc, which is one of the resource REs, i.e., the password PW of user US, violates policy PO2, which is one of the multiple policy POs included in compliance KO, it notifies user US's terminal TM of the violation (violation IH). As a result, user US can find out whether or not a violation IH exists as a comprehensive determination result of whether or not the resource RE of the managed service MS of the public cloud PK violates policy PO of compliance KO.
[0047] Instead of the password-based authentication described above, an alternative authentication method may be used, similar to the previously known method, in which, for example, user US issues authentication information NJ (not shown) for the public cloud PK, and this authentication information NJ is passed to the inspection device KS.
[0048] <Embodiment 2> The policy inspection system PKS of Embodiment 2 will be described.
[0049] <Configuration of Embodiment 2> The configuration of the policy inspection system PKS in Embodiment 2 is the same as the configuration of the policy inspection system PKS in Embodiment 1 (shown in Figures 1 to 4).
[0050] <Operation of Embodiment 2> The operation of the policy inspection system PKS in Embodiment 2 is a continuation of the operation of the policy inspection system PKS in Embodiment 1 (shown in Figure 5).
[0051] Figure 7 shows the operation of the policy inspection system PKS in Embodiment 2.
[0052] Figure 8 shows the determination result HK for Embodiment 2.
[0053] Figure 9 shows the determination result HK for Embodiment 2 (rewritten 1).
[0054] Figure 10 shows the determination result HK of Embodiment 2 (rewritten 2).
[0055] The operation of the policy inspection system PKS in Embodiment 2 will be described with reference to Figures 7 to 10.
[0056] To facilitate explanation and understanding, we will consider the following scenarios when a resource RE (shown in Figure 1) violates a policy PO (shown in Figure 6) (i.e., when there is a violation IH): (1) User US resolves the violation IH, and (2) User US does not resolve the violation IH.
[0057] <If user US resolves the IH violation> Step ST4: In the inspection device KS, the processing unit SY(KS) notifies the user US terminal TM of the violation IH (that user US's password PW violates policy PO2) in step ST3, and then stores the result of the judgment (step ST2 in Figure 5) (hereinafter referred to as "judgment result HK," shown in Figure 8) in the storage unit KI(KS).
[0058] Step ST5A: When user US of terminal TM receives the above-mentioned violation IH from inspection device KS in step ST3, resolve the violation IH. More specifically, user US promptly changes their password PW.
[0059] Step ST6A: User US's terminal TM sends a message to the inspection device KS indicating that the IH violation has been resolved. In other words, the inspection device KS receives a message from User US's terminal TM indicating that the IH violation has been resolved.
[0060] Step ST7A: In the inspection device KS, the processing unit SY(KS) adds "Resource REc, which violated policy PO2, was resolved at 07:15:24" to the judgment result HK stored in the memory unit KI(KS), as shown by the dotted line in Figure 9, that is, it rewrites the judgment result HK.
[0061] <If user US does not resolve the IH violation> Step ST4: In the inspection device KS, the processing unit SY(KS) stores the determination result HK (shown in Figure 8) in the storage unit KI(KS), similar to step ST4 when user US resolves a violation IH (that user US's password PW violates policy PO2).
[0062] Step ST5B: Even if user US of terminal TM receives a violation IH from inspection device KS in step ST3, they do not resolve the violation IH. More specifically, user US does not change the password PW in any way.
[0063] Step ST6B: User US's terminal TM transmits to the inspection device KS that it has not resolved the violation IH and the reason why it has not been resolved, i.e., that it is unresolved and the reason for the unresolved status. In other words, the inspection device KS receives from User US's terminal TM that it is unresolved and the reason for the unresolved status.
[0064] Step ST7B: In the inspection device KS, the processing unit SY(KS) adds "Resource REc, which violated policy PO2, was not resolved at 07:15:24" (unresolved) to the judgment result HK stored in the memory unit KI(KS), as shown by the dotted line in Figure 10, and also adds "Reason for not resolving" (reason for unresolved), thus rewriting the judgment result HK.
[0065] <Effects of Embodiment 2> As described above, in the policy inspection system PKS of Embodiment 2, the user US of terminal TM resolves or leaves unresolved resource REc that violates policy PO2, and in the inspection device KS, the processing unit SY(KS) appends the resolved or unresolved (including the reason for unresolved) status to the judgment result HK stored in the storage unit KI(KS), that is, rewrites the judgment result HK. This allows the user US to see a list of how the user US responded after resource RE violated policy PO.
[0066] <Variations> Modifications of the embodiment will be described.
[0067] Figure 11 shows the environmental information KJ for the modified example.
[0068] Figure 12 shows the compliance KO of a modified example.
[0069] In the modified policy inspection system PKS (shown in Figure 1), the processing unit SY(KS) (shown in Figure 2) of the inspection device KS determines whether the parameter P of resource RE included in the environmental information KJ (shown in Figure 11) satisfies the condition JO of the policy content PO(CON) which is resource type RT2 in compliance KO (shown in Figure 12), corresponding to resource type RT1, which is the type of resource RE.
[0070] The processing unit SY(KS) of the inspection device KS determines, for example, whether the parameter P "MFA status = disabled" of resource RE "IAM user ID or name" in the environment information KJ violates the condition JO "MFA is enabled for all IAM users who can access the console" of the policy content PO(CON) "IAM users for whom MFA is not enabled" in the compliance KO, which corresponds to resource type RT1 "IAM user" of resource RE "IAM user ID or name".
[0071] The processing unit SY(KS) of the inspection device KS also, for example, the parameter P "Inbound rule with source "0.0.0.0 / 0" and port range from 20 to 25" of resource RE "Security Group ID or name" in the environmental information KJ corresponds to resource type RT1 "Security Group" in the compliance KO, which is resource type RT2 "Security Determine whether the policy content PO(CON) "The security group allows unrestricted access to high-risk ports" is violated by condition JO "There is no security group with an inbound rule that uses "0.0.0.0 / 0" or ":: / 0" as the source and has port ranges of 20, 21, 22, 23, 25, 110, 135, 143, 445, 1433, 1434, 3000, 3306, 3389, 4333, 5000, 5432, 5500, 5601, 8080, 8088, 8888, 9200, 9300".
[0072] <Hardware configuration of the embodiment> Figure 13 shows the hardware configuration of the policy inspection system PKS in Embodiments 1 and 2.
[0073] The policy inspection system PKS of Embodiments 1 and 2 includes a processing circuit SYO, as shown in Figure 13, to perform the functions described above, and optionally further includes an input circuit NYU and an output circuit SYU.
[0074] The processing circuit SYO is dedicated hardware. The processing circuit SYO implements the functions of the inspection device KS, the public cloud PK, and the terminal TM's processing units SY(KS), SY(PK), and SY(TM) (shown in Figures 2 to 4).
[0075] The processing circuit SYO can be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination of these.
[0076] The input circuit NYU and output circuit SYU exchange inputs and outputs related to the operation of the processing circuit SYO with external devices such as the inspection device KS, the public cloud PK, and the terminal TM.
[0077] <Hardware configuration based on software implementation of the embodiment> Figure 14 shows the hardware configuration based on the software implementation of the policy inspection system PKS in Embodiments 1 and 2.
[0078] The policy inspection system PKS of Embodiments 1 and 2 includes a processor PRO and a memory circuit KIO, as shown in Figure 14, and optionally further includes an input circuit NYU and an output circuit SYU.
[0079] The processor PRO is a CPU (Central Processing Unit, also known as a microprocessor, microcomputer, or DSP (Digital Signal Processing)) that executes programs. The processor PRO implements the functions of the inspection device KS, the public cloud PK, and the terminal TM's processing units SY(KS), SY(PK), and SY(TM) (shown in Figures 2 to 4).
[0080] Processor PRO implements the above-mentioned functions through software, firmware, or a combination of software and firmware. The software and firmware are written as programs and stored in the memory circuit KIO.
[0081] Processor PRO achieves the above-described functions by reading and executing the program described above from the memory circuit KIO. The program described above can also be said to cause the computer to execute the procedures and methods of the inspection device KS, the public cloud PK, and the terminal TM's processing units SY(KS), SY(PK), and SY(TM).
[0082] Here, memory circuits (KIO) include, for example, non-volatile or volatile semiconductor memories such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), and EEPROM (Electrically Erasable Programmable Read-Only Memory), as well as magnetic disks, flexible disks, optical disks, compact disks, minidiscs, DVDs (Digital Versatile Discs), etc.
[0083] Some of the functions of the inspection device KS, the public cloud PK, and the terminal TM's processing units SY(KS), SY(PK), and SY(TM) may be implemented by the processing circuit SYO (shown in Figure 13), while other functions may be implemented by the processor PRO (shown in Figure 14).
[0084] As described above, the functions of the inspection device KS, the public cloud PK, and the terminal TM's processing units SY(KS), SY(PK), and SY(TM) can be realized through hardware, software, firmware, or a combination thereof.
[0085] The input circuit NYU and output circuit SYU exchange inputs and outputs related to the operation of the processor PRO with external devices such as the inspection device KS, the public cloud PK, and the terminal TM.
[0086] <Example of structure> The inspection device, inspection method, and program relating to this disclosure have, for example, the following configurations.
[0087] [Item 1] An acquisition unit that acquires environment information from a public cloud used by a user, which provides a managed service having multiple resources, and which lists the multiple resources within the public cloud and the multiple parameters that the multiple resources have, as the status of the managed service. A determination unit determines whether one of the multiple resources violates one of the multiple policies by comparing the acquired environmental information with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy. When it is determined that one of the aforementioned resources violates one of the aforementioned policies, a notification unit notifies the user of the violation according to the severity of the policy being violated, Inspection equipment including...
[0088] [Item 2] The inspection apparatus described in item 1, wherein each of the contents of the aforementioned multiple policies is further defined by the importance of each of the aforementioned multiple policies.
[0089] [Item 3] The inspection apparatus according to item 1, further comprising a storage unit for storing the result of the determination made by the determination unit.
[0090] [Item 4] When the user resolves that one of the resources violates one of the policies, and the user receives notification of the resolution from a terminal used by the user, the storage unit includes a rewrite unit that rewrites the violation to a resolution. The inspection apparatus described in item 3, which further includes the following.
[0091] [Item 5] If the user fails to resolve that one resource violates one policy, and the user receives a notification from the terminal used by the user indicating that the matter has not been resolved, the storage unit includes a rewrite unit that rewrites the information about the violation to the information that the matter is unresolved, The inspection apparatus described in item 3, which further includes the following.
[0092] [Item 6] When the rewriting unit receives the reason for the unresolved status from the terminal used by the user, in addition to rewriting the statement that the status is unresolved in the storage unit, it also adds the reason for the unresolved status. The inspection device described in item 5.
[0093] [Item 7] Computers An acquisition step of acquiring environment information from a public cloud used by a user, which provides a managed service having multiple resources, and which lists the status of the managed service, including the multiple resources within the public cloud and the multiple parameters that each resource has, and storing this information in a storage unit. A determination step of determining whether one of the multiple resources violates one of the multiple policies by comparing the environmental information stored in the storage unit with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy, When it is determined that one of the resources violates one of the policies, a notification step is made to notify the user of the violation, according to the severity of the policy being violated. A testing method that performs this task.
[0094] [Item 8] On the computer, A user-accessible public cloud that provides a managed service with multiple resources, and an acquisition step of environment information which lists the multiple resources within the public cloud and the multiple parameters of those resources as the status of the managed service, A determination step of determining whether one of the multiple resources violates one of the multiple policies by comparing the acquired environmental information with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy, When it is determined that one of the resources violates one of the policies, a notification step is made to notify the user of the violation, according to the severity of the policy being violated. A program to be executed. [Explanation of Symbols]
[0095] PKS Policy Inspection System, KS Inspection Equipment, PK Public Cloud, MS Managed Services, RE Resources, TM Terminals, US Users.
Claims
1. An acquisition unit acquires environment information from a public cloud used by a user, which provides a managed service having multiple resources, and which lists the multiple resources within the public cloud and the multiple parameters that the multiple resources have, as the status of the managed service. A determination unit determines whether one of the multiple resources violates one of the multiple policies by comparing the acquired environmental information with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy. When it is determined that one of the resources violates one of the policies, a notification unit notifies the user of the violation according to the severity of the policy being violated. Inspection equipment including...
2. The inspection apparatus according to claim 1, wherein each of the contents of the plurality of policies is further defined by the importance of each of the plurality of policies.
3. The inspection apparatus according to claim 1, further comprising a storage unit for storing the result of the determination made by the determination unit.
4. When the user resolves that one of the resources violates one of the policies, and the user receives notification of the resolution from a terminal used by the user, the storage unit includes a rewrite unit that rewrites the violation to a resolution, The inspection apparatus according to claim 3, further comprising:
5. If the user fails to resolve that one resource violates one policy, and the user receives a notification from a terminal used by the user indicating that the matter has not been resolved, the storage unit includes a rewrite unit that rewrites the information about the violation to indicate that the matter is unresolved, The inspection apparatus according to claim 3, further comprising:
6. When the rewriting unit receives the reason for the unresolved status from the terminal used by the user, in addition to rewriting the statement that the status is unresolved in the storage unit, it also adds the reason for the unresolved status. The inspection apparatus according to claim 5.
7. Computers An acquisition step of acquiring environment information from a public cloud used by a user, which provides a managed service having multiple resources, and which lists the status of the managed service, including the multiple resources within the public cloud and the multiple parameters that each resource has, and storing this information in a storage unit. A determination step of determining whether one of the multiple resources violates one of the multiple policies by comparing the environmental information stored in the storage unit with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy, When it is determined that one of the resources violates one of the policies, a notification step is made to notify the user of the violation, according to the severity of the policy being violated. A testing method that performs this task.
8. On the computer, A user-accessible public cloud that provides a managed service with multiple resources, and an acquisition step of environment information which lists the multiple resources within the public cloud and the multiple parameters of those resources as the status of the managed service, A determination step of determining whether one of the multiple resources violates one of the multiple policies by comparing the acquired environmental information with the contents of multiple policies which are conditions that the multiple parameters of the multiple resources listed in the environmental information must satisfy, When it is determined that one of the resources violates one of the policies, a notification step is made to notify the user of the violation, according to the severity of the policy being violated. A program to be executed.
Citation Information
Patent Citations
Cloud monitoring / restoration method, cloud monitoring / restoration system and program
JP2021121886A