まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

興味を持った記事(2020年04月23日)

セキュリティ

Zoom

いくつかのプロダクトを利用して安全なリモートアクセスを実現していますが、その中でも特にコアになっているプロダクトはIdentity-Aware Proxyです。

Changes to existing features

  • Prevent private chatting with channel members outside of Zoom account or organization
  • Users will no longer be able to privately chat with other members of the same channel if they are not on the same Zoom account or organization. To -continue chatting with contacts outside of their Zoom account, they can add them as external contacts.

New and enhanced features

  • Meeting features
    • Report a user during a meeting
    • The meeting host can now report a user during a meeting by clicking on the Security icon, then Report. This feature will generate a report which will be sent to the Zoom Trust and Safety team to evaluate any misuse of the platform and block a user if necessary.
  • Additional feedback options at the end of a meeting
    • Users will now have the ability to provide additional feedback if the setting Post meeting feedback survey is enabled. This feedback can also be viewed in Dashboard and can be downloaded as a spreadsheet. This setting was previously named Display end of meeting feedback survey.
  • Enhancements to meeting end/leave flow
    The host will now be required to assign a new host when leaving the meeting. Additionally, the pop-up message asking if the host would like to leave or end the meeting will now be displayed by the Leave button.
  • Chat features
    • Indication of an external user
      Users will have the label “External” next to their name if they are not part of your Zoom account. This label will be displayed in one on one messages, group messages, and channels. This label will also be displayed in the user’s profile details when you hover over their profile picture and in the channel members list.
  • Phone features
    • Enhanced encryption
      Zoom Phone SIP signaling communications from client to server occur over TLS v1.2 with AES-256 bit encryption. Zoom Phone call media is transported and protected by SRTP with AES-256 bit encryption for latest Zoom clients, and with AES-128 bit encryption for SIP devices.
  • Resolved issues
    • Minor bug fixes

iOS Mail.app

IPA Remote work

また、いずれの勤務者も、以下の「日常における情報セキュリティ対策」の実施を呼びかけている。
1:修正プログラムの適用
2:セキュリティソフトの導入および定義ファイルの最新化
3:パスワードの適切な設定と管理
4:不審なメールに注意
5:USBメモリ等の取り扱いの注意
6:社内ネットワークへの機器接続ルールの遵守
7:ソフトウェアをインストールする際の注意
8:パソコン等の画面ロック機能の設定