Crown Jewels Analysis
Crown Jewels Analysis とは何ですか?
Crown Jewels AnalysisA MITRE-popularized methodology that identifies the small set of mission-critical assets whose loss would unacceptably harm the organization, then concentrates protection, monitoring, and IR investment there.
Crown Jewels Analysis (CJA) is a methodology formalized by MITRE in the mid-2010s and incorporated into the U.S. DoD's mission-assurance practice. The premise: most organizations cannot harden everything to the same level, and most adversaries don't care about everything either. CJA produces a ranked, justified list of the assets — datasets, systems, applications, identities, processes — whose compromise or loss would produce unacceptable mission, business, regulatory, or reputational impact, and the dependencies (network paths, credentials, supporting services) that lead to them. The output drives where to concentrate defense-in-depth controls (segmentation, monitoring tier, IR tabletop priority, cyber-insurance scoping, recovery RTO/RPO), what threat models to take most seriously, and which paths in attack-graph terms to disrupt first. CJA is often a precursor to attack-path analysis, MITRE ATT&CK technique prioritization, and adversary-emulation scoping. It is also a common requirement of cyber-insurance underwriting and of regulator-led resilience reviews (DORA, NIS2, U.S. DOD CMMC).
● 例
- 01
A bank's CJA identifies the payments-clearing system, the customer-master database, and the production HSM as crown jewels and routes their telemetry to a dedicated SOC tier.
- 02
After a CJA, the IR tabletop scenarios for the next year focus on ransomware against the crown-jewel ERP rather than a generic phishing breach.
● よくある質問
Crown Jewels Analysis とは何ですか?
A MITRE-popularized methodology that identifies the small set of mission-critical assets whose loss would unacceptably harm the organization, then concentrates protection, monitoring, and IR investment there. サイバーセキュリティの 防御と運用 カテゴリに属します。
Crown Jewels Analysis とはどういう意味ですか?
A MITRE-popularized methodology that identifies the small set of mission-critical assets whose loss would unacceptably harm the organization, then concentrates protection, monitoring, and IR investment there.
Crown Jewels Analysis はどのように機能しますか?
Crown Jewels Analysis (CJA) is a methodology formalized by MITRE in the mid-2010s and incorporated into the U.S. DoD's mission-assurance practice. The premise: most organizations cannot harden everything to the same level, and most adversaries don't care about everything either. CJA produces a ranked, justified list of the assets — datasets, systems, applications, identities, processes — whose compromise or loss would produce unacceptable mission, business, regulatory, or reputational impact, and the dependencies (network paths, credentials, supporting services) that lead to them. The output drives where to concentrate defense-in-depth controls (segmentation, monitoring tier, IR tabletop priority, cyber-insurance scoping, recovery RTO/RPO), what threat models to take most seriously, and which paths in attack-graph terms to disrupt first. CJA is often a precursor to attack-path analysis, MITRE ATT&CK technique prioritization, and adversary-emulation scoping. It is also a common requirement of cyber-insurance underwriting and of regulator-led resilience reviews (DORA, NIS2, U.S. DOD CMMC).
Crown Jewels Analysis からどのように防御しますか?
Crown Jewels Analysis に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Crown Jewels Analysis の別名は何ですか?
一般的な別名: CJA, Mission-critical asset analysis。
● 関連用語
- compliance№ 1042
リスクアセスメント
特定の資産に対する脅威・脆弱性・影響を洗い出し、結果として生じるリスクを評価して対応判断につなげる、リスクマネジメント内の体系的な活動。
- defense-ops№ 153
BIA(ビジネスインパクト分析)
重要な業務プロセスとその依存関係、ならびに中断時の運用・財務・レピュテーション上の影響を体系的に分析する手法。
- defense-ops№ 084
アタックサーフェスマネジメント(ASM)
組織をサイバー攻撃にさらすあらゆる資産を継続的に発見・棚卸し・分類・監視する取り組み。
- compliance№ 330
多層防御(Defense in Depth)
独立した対策を層状に重ね、単一の対策が破られても他の層が予防・検知・封じ込めを続けられるようにするセキュリティ戦略。
- appsec№ 1270
脅威モデリング
資産・脅威・脆弱性・対策を体系的に分析し、セキュリティを後付けではなく設計段階から組み込むための構造化された手法。
- network-security№ 809
ネットワークセグメンテーション
ネットワークを複数のゾーンに分割し、ゾーン間の通信を制御することで侵害を封じ込め、最小権限を強制する設計手法。