Upgrade to Pro — share decks privately, control downloads, hide ads and more …

踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08

fnifni
February 24, 2018

踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08

Bastion
Amazon Maice
#secjaws #secjaws08

fnifni

February 24, 2018
Tweet

More Decks by fnifni

Other Decks in Technology

Transcript

  1. Who Am I !?ʢ͓લ୭Αʁʣ • Hirokazu YoshidaˏCloud Native Inc.
 Security

    Engineer • Community
 - Security-JAWS
 - Deep Security User Group • Favorite AWS Service https://qiita.com/fnifni
  2. 20 CIS Controls is Կ • NIST SP800-53 (࿈๜੓෎৘ใγεςϜ ͓Αͼ

    ࿈๜૊৫ͷͨΊͷ ηΩϡϦςΟ؅ཧࡦͱϓϥ Πόγʔ؅ཧࡦ) Λ࣮૷͢Δ্ͰॏཁͱͳΔ20 ͷηΩϡϦςΟίϯτϩʔϧΛ·ͱΊͨจॻ
  3. 6. Maintenance, Monitoring, and Analysis of Audit Logs • ݕग़ɺཧղɺ·ͨ͸߈ܸ͔Βͷճ෮ʹ໾ཱͭ

    Մೳੑͷ͋ΔΠϕϯτͷ؂ࠪϩάΛऩूɺ؅ ཧɺ͓Αͼ෼ੳ • ଟ͘ͷ૊৫Ͱ͸ɺίϯϓϥΠΞϯεͷ໨తͰ ؂ࠪه࿥Λอ͍࣋ͯ͠·͕͢ɺ؂ࠪϩάΛ΄ ͱΜͲࢀর͠ͳ͍ͨΊɺγεςϜ͕৵֐͞Ε ͍ͯΔ͔Ͳ͏͔͸Θ͔Γ·ͤΜɻ
  4. What is Amazon Macie? • ػցֶशʹͯS3಺ͷػີσʔλΛࣗಈతʹݕ ग़ɺ෼ྨɺอޢ͢ΔηΩϡϦςΟαʔϏε • ݸਓ৘ใ (PII)

    ΍஌తࡒ࢈ͳͲͷػີσʔλ͕ೝ ࣝ͞ΕΔɻ • όʔδχΞͱΦϨΰϯͰར༻Մೳ https://docs.aws.amazon.com/ja_jp/macie/latest/userguide/what-is-macie.html
  5. Cause is a misconfiguration of S3 • WWE Leaks 3

    Million Emails
 https://mackeepersecurity.com/post/world-wrestling-entertainment-leaks-3- million-emails • Dow Jones customer data exposed in cloud error
 http://thehill.com/policy/cybersecurity/342333-dow-jones-customer-data-exposed- in-cloud-error • VerizonՃೖऀ1400ສਓͷݸਓ৘ใɺۀ຿ҕୗઌ͕ ʮແ๷උঢ়ଶʯͰΫϥ΢υʹอଘ
 http://www.itmedia.co.jp/enterprise/articles/1707/13/news055.html
  6. Third Party Authentication ~See AWS Artifact~ • ISO 27001:2013 Certification

    • ISO 27017:2015 Certification • ISO 27018:2014 Certification • ISO 9001:2015 Certification • PCIDSSv3.2 • SoC1/2͸ݸผʹௐ΂ͯͶΜ(ཁผ్৘ใೖྗ)