Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / ...
Search
kenryooo
February 09, 2021
Technology
6
5.6k
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / AWS multi-account approach in Classi
2021/02/09開催「第二回 AWSマルチアカウント事例祭り」での発表資料です。
kenryooo
February 09, 2021
Tweet
Share
Other Decks in Technology
See All in Technology
今から間に合う re:Invent 準備グッズと現地の地図、その他ラスベガスを周る際の Tips/reinvent-preparation-guide
emiki
1
280
20251029_Cursor Meetup Tokyo #02_MK_「あなたのAI、私のシェル」 - プロンプトインジェクションによるエージェントのハイジャック
mk0721
PRO
6
2.4k
Amazon Athena で JSON・Parquet・Iceberg のデータを検索し、性能を比較してみた
shigeruoda
1
300
Playwrightで始めるUI自動テスト入門
devops_vtj
0
140
AIの個性を理解し、指揮する
shoota
3
630
書籍『実践 Apache Iceberg』の歩き方
ishikawa_satoru
0
470
設計に疎いエンジニアでも始めやすいアーキテクチャドキュメント
phaya72
27
18k
NOT A HOTEL SOFTWARE DECK (2025/11/06)
notahotel
0
3k
AIエージェントを導入する [ 社内ナレッジ活用編 ] / Implement AI agents
glidenote
1
210
なぜ新機能リリース翌日にモニタリング可能なのか? 〜リードタイム短縮とリソース問題を「自走」で改善した話〜 / data_summit_findy_Session_2
sansan_randd
1
120
サブドメインテイクオーバー事例紹介と対策について
mikit
15
7.3k
LLM APIを2年間本番運用して苦労した話
ivry_presentationmaterials
10
7.9k
Featured
See All Featured
Documentation Writing (for coders)
carmenintech
76
5.1k
Facilitating Awesome Meetings
lara
57
6.6k
Fireside Chat
paigeccino
41
3.7k
Site-Speed That Sticks
csswizardry
13
940
How STYLIGHT went responsive
nonsquared
100
5.9k
Rails Girls Zürich Keynote
gr2m
95
14k
4 Signs Your Business is Dying
shpigford
186
22k
Visualization
eitanlees
150
16k
Reflections from 52 weeks, 52 projects
jeffersonlam
355
21k
Embracing the Ebb and Flow
colly
88
4.9k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
253
22k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.7k
Transcript
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ୈೋճ"84ϚϧνΞΧϯτࣄྫࡇΓ ηΩϡϦςΟΠϯγσϯτΛΓӽ͑ΔͨΊʹߦͬͨ ϚϧνΞΧϯτͰͷऔΓΈʹ͍ͭͯ $MBTTJ$PSQ,FOSZP0NJOBNJ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE $ whoami • ,FOSZP0NJOBNJ !LFOSZPPP • ۙ͘Β͍#$αʔϏεΛத৺ʹ%#"ɺαʔό αΠυΤϯδχΞɺ43&Λܦݧɻ
• $MBTTJʹ43&ͱͯ͠δϣΠϯɻ • ͜͜ΠϯϑϥηΩϡϦςΟྖҬΛத৺ʹۀΛ ߦ͍ͬͯΔɻ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE About Classi ʮ$MBTTJʯڭҭݱΛࢧԉ͢Δ ΫϥυαʔϏε • શࠃͷߴߍͷˋ͕ಋೖ • ߴߍੜͷਓʹਓ͕ར༻ •
ར༻ऀສਓ • ઌੜɺੜెɺอޢऀ͕ܨ͕Δ ֶशࢧԉϓϥοτϑΥʔϜ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͞ͳ͍͜ͱ • ݄ɺ݄ͷߴෛՙʹΑΔΞΫηεোঢ়ଶʹؔ͢ΔऔΓΈʹ͍ͭͯ • ͪ͜Βʹ͍ͭͯԼهΛ͝ཡ͍ͩ͘͞ • $MBTTJ։ൃऀϒϩά IUUQTUFDIDMBTTJKQ
• %FWFMPQFST4VNNJU
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE [PR] Developers Summit 2021 IUUQTFWFOUTIPFJTIBKQEFWTVNJTFTTJPO
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ηΩϡϦςΟΠϯγσϯτʹ͍ͭͯ 4VO 4BU ֎෦ͷ߈ܸऀ͔Βෆਖ਼ΞΫηεΛड͚αʔϏεఀࢭ αʔϏε࣌ؒޙʹ෮چͰ͖ͨͷͷϢʔβʔใྲྀग़ͷՄೳੑΛ֬ೝ ͯ͢ͷϢʔβʔͷύεϫʔυมߋ͕ྃ
֎෦αΠτʹͯɺྲྀग़ͨ͠ݸਓใͷ࿙ӮΛ֬ೝ ΠϯϑϥɺΞϓϦέʔγϣϯͱʹൈຊతͳηΩϡϦςΟͷݟ͠Λ࣮ࢪ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ઓུͱධՁ • શମͷઓུ • "848FMM"SDIJUFDUFE'SBNFXPSL4FDVSJUZ1JMMBS • "84ΞΧϯτཧͷઓུ • #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT
• ηΩϡϦςΟධՁ • "84ϓϩϑΣογϣφϧαʔϏεͷηΩϡϦςΟධՁ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ
։ൃ༻ΞΧϯτ ࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 064$1Λར༻͍ͯ͠ͳ͍ • 1SPEVDUJPOΞΧϯτ͕0SHBOJ[BUJPOͷཧΞΧϯτͱͯ͠ઃఆ • ࠷ݫີʹཧ͍ͨͣ͠ͷΞΧϯτ͕ཧͰ͖ͳ͍ • #BTUJPOΞΧϯτɺ։ൃऀ͕4BOECPYڥͱͯ͠ར༻
• 1SPEVDUJPOΞΧϯτϩάΠϯ͢ΔݩͷΞΧϯτ͕ηΩϡΞͰͳ͍
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ཧΞΧϯτͷΓସ͑ • ཧΞΧϯτΛ৽ن࡞ • طଘΞΧϯτچ৫Λɺ՝ۚपΓͷઃఆΛՃ͠৽৫Ҡಈ େมʜ
• 0SHBOJ[BUJPOTಋೖ࣌৽نʹཧΞΧϯτΛ࡞Γ·͠ΐ͏ʂ • 06ઃܭͱஔ • ʮ#FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOTʯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -After- 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06
.BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT IUUQTBXTBNB[PODPNKQCMPHTNUCFTUQSBDUJDFTGPSPSHBOJ[BUJPOBMVOJUTXJUIBXTPSHBOJ[BUJPOT
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organiztional Units 06 ༻్ 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 1SPE@06
ຊ൪ΞΧϯτͷΈΛแ͢Δ06 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ ։ൃ༻ΞΧϯτ
࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O Ϛωδϝϯτίϯιʔϧར༻ ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- • ։ൃऀ͚ʹҎԼͷ௨ΓͰΞΫηεํ๏Λఏڙ • ϚωδϝϯτίϯιʔϧͰͷར༻ • ϩάΠϯํ๏(4VJUFͱ4".-࿈ܞ •
#BTUJPOΞΧϯτΛܦͯɺ࡞ۀ͍ͨ͠ΞΧϯτʹ4XJUDI3PMF͢Δ • ϓϩάϥϜΞΫηεͰͷར༻ • ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 3PMFͱΞΫηεΩʔͷཧ • ผʑʹཧΛߦ͏ඞཁ͕͋Γࡶ • ΞΫηεΩʔཧ • ӬଓతͳΞΫηεΩʔͷཧ͕ར༻ऀͤ
• 4XJUDI3PMFͷηΩϡϦςΟ • աڈɺεΠονઌ3PMFͷ1SJODJQBMઃఆϛεʹΑΓఆͯ͠ͳ͍ݖݶͰೖΓ์ʹ ͳ͍ͬͯͨ͜ͱ͕͋ͬͨ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ϩʔΧϧϚγϯͷରࡦ • BXTMBCTHJUTFDSFUTಋೖ • ΞΫηεΩʔͳͲͷػີใͷ(JUϦϙδτϦͷίϛοτΛ͙
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • "84ଆͷରࡦ • "84440ͷҠߦ • ݄ʹ5PLZP3FHJPOͰϩʔϯνͨ͠λΠϛϯάͰҠߦ • "[VSF"%ͱ࿈ܞ͢Δ͜ͱͰΞΧϯτཧ͕γϯϓϧʹ
• ΞΫηεΩʔͷཧෆཁʹ ˞4BB4͚ͷͷআ͘
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06 .BJOUFOBODF@06
4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY "[VSF"% Ϛωδϝϯτίϯιʔϧ ΞΫηεΩʔ "844JOHMF4JHO0O ֤ΞΧϯτϩάΠϯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ࣄ • 4XJUDI3PMF࣌ͷཧऀ༻3PMFΛআͨ͠ͱ͜ΖɺαʔϏεͰར༻͍ͯ͠ Δ$.,͕ӾཡɺมߋෆՄೳʹͳͬͯ͠·ͬͨ •
"ENJOJTUSBUPSݖݶϢʔβʔͰSPPUͰͲ͏ʹͰ͖ͳ͍ • ݪҼ • আͨ͠ཧऀ3PMFͷΈ͕ΩʔϙϦγʔͱͯ͠ࢦఆ͞Ε͍ͯͨͨΊɺআ͠ ͨ࣌ͰཧऀෆࡏͷΩʔʹͳΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ରԠ • "84ͷαϙʔτ͍߹ΘͤɺҰ࣌తͳϢʔβʔΛ࡞ɺ1VU,FZ1PMJDZݖݶ Λ༩ͯ͠Β͍ݩͷΩʔϙϦγʔΛ෮׆ͤ͞Δ͜ͱͰ෮چͨ͠ •
ͨͩ͠ɺ࡞ۀλΠϛϯάͳͲίϯτϩʔϧͰ͖ͳ͍ཁૉ͋ΔͷͰɺΩʔϙϦ γʔͷཧऀͱͯ͠ෳͷ6TFS͘͠3PMFΛ༩͓ͯ͘͠ͷ͕Φεεϝ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ༧తΨʔυϨʔϧ • 4$1ͷྫ • ෆ༻Ϧʔδϣϯͷ੍ݶ • ࠪܥૢ࡞ͷ੍ݶ • ڥಛ༗ͷ੍ݶ
ॏཁૢ࡞ͳͲ • શૢ࡞ͷېࢭ • FUD
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 06 ༻్ 4$1 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06
Ϧʔδϣϯ੍ݶɺࠪܥૢ࡞ͷ੍ݶ 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 ։ൃऀ͚ͷ੍ݶ 1SPE@06 ຊ൪ΞΧϯτͷΈΛแ͢Δ06 ڥಛ༗ͷ੍ݶ 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 ڥಛ༗ͷ੍ݶ *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 ڥಛ༗ͷ੍ݶ 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 ݕূ༰ʹΑͬͯมߋ .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 ϝϯς༰ʹΑͬͯมߋ 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06 શૢ࡞Λېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06
*OGSB@06 .BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY Ϧʔδϣϯ੍ݶ ࠪܥૢ࡞ͷ੍ݶ ։ൃऀ͚ͷ੍ݶ 1SPEʹ͓͚Δ ॏཁૢ࡞ͷ੍ݶ ڞ௨ج൫ಛ༗ͷ੍ݶ มߋ มߋ શૢ࡞ͷېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ • $MPVE5SBJMΑΔಛఆૢ࡞ͷࢹ • $POpH • (VBSE%VUZ • 4FDVSJUZ)VC
• 5SVTUFE"EWJTPS ݕͨ͠༰ͷϑΟϧλϦϯάʹؔͯ͠ɺνϡʔχϯάΛਐΊ͍ͯΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ αʔϏε໊ 0SHBOJ[BUJPOTରԠ ϝϯόʔͷҕ ϝϯόʔͷࣗಈ༗ޮԽ ิ $POpH ˓ ˓
✕ $MPVE'PSNBUJPO4UBDL4FUTΛར༻ͯ͠ɺ ϝϯόʔΞΧϯτͷ༗ޮԽΛࣗಈͰ࣮ࢪ (VBSE%VUZ ˓ ˓ ˓ 4FDVSJUZ)VC ˓ ˓ ˓ ·ͨɺൃݟతΨʔυϨʔϧͰར༻͢ΔҎԼͷαʔϏεʹؔͯ͠ɺ $POpH͚ͩࣗಈ༗ޮԽ͕Ͱ͖ͳ͔ͬͨͨΊ$'O4UBDL4FUTΛར༻͍ͯ͠Δ ૣ͘0SHBOJ[BUJPOTͱͷεϜʔζͳ౷߹͕࣮ݱͯ͠΄͍͠
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ࠓޙ • ൃݟతΨʔυϨʔϧͷνϡʔχϯά • $POpH3VMFTͷνϡʔχϯά • (VBSE%VUZ4FDVSJUZ)VCͷݕ༰ͷਫ਼ࠪ • ϩΪϯάͱϞχλϦϯάͷڧԽ
• 4*&.ͷಋೖ 4*&.PO"NB[PO&4Λݕ౼த • ΠϯγσϯτϨεϙϯεͷڧԽ • )BSEFOJOHΠϕϯτͷࢀՃɺݚम
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ·ͱΊ • ΠϯγσϯτҎ߱ɺϚϧνΞΧϯτߏΛ׆͔ͨ͠ܗͰରࡦΛ͢͢Ί͖ͯͨ • "84440Λར༻͢Δ͜ͱͰΞΧϯτཧίετ͕Լ͕ΓηΩϡΞʹͳͬͨ • ༧తɺൃݟతΨʔυϨʔϧͷಋೖͰΑΓηΩϡΞʹͳͬͨ ϚϧνΞΧϯτΛಋೖͯ͠ηΩϡΞͳڥΛखʹೖΕΑ͏
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ʘɹ8F"SF)JSJOHɹʗ IUUQTDPSQDMBTTJKQDBSFFST
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͓ΘΓ