Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / ...
Search
kenryooo
February 09, 2021
Technology
6
5.5k
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / AWS multi-account approach in Classi
2021/02/09開催「第二回 AWSマルチアカウント事例祭り」での発表資料です。
kenryooo
February 09, 2021
Tweet
Share
Other Decks in Technology
See All in Technology
Lambda management with ecspresso and Terraform
ijin
2
130
Kiroから考える AIコーディングツールの潮流
s4yuba
4
660
Claude Codeから我々が学ぶべきこと
s4yuba
6
1.8k
dipにおけるSRE変革の軌跡
dip_tech
PRO
1
230
SRE新規立ち上げ! Hubbleインフラのこれまでと展望
katsuya0515
0
160
Claude CodeでKiroの仕様駆動開発を実現させるには...
gotalab555
3
880
Foundation Model × VisionKit で実現するローカル OCR
sansantech
PRO
0
290
Jamf Connect ZTNAとMDMで実現! 金融ベンチャーにおける「デバイストラスト」実例と軌跡 / Kyash Device Trust
rela1470
0
120
MCP認可の現在地と自律型エージェント対応に向けた課題 / MCP Authorization Today and Challenges to Support Autonomous Agents
yokawasa
5
1.7k
反脆弱性(アンチフラジャイル)とデータ基盤構築
cuebic9bic
2
160
AI関数が早くなったので試してみよう
kumakura
0
120
Agent Development Kitで始める生成 AI エージェント実践開発
danishi
0
120
Featured
See All Featured
Measuring & Analyzing Core Web Vitals
bluesmoon
7
540
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
30
2.2k
Building a Scalable Design System with Sketch
lauravandoore
462
33k
Designing for humans not robots
tammielis
253
25k
Building a Modern Day E-commerce SEO Strategy
aleyda
43
7.4k
YesSQL, Process and Tooling at Scale
rocio
173
14k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
139
34k
A Tale of Four Properties
chriscoyier
160
23k
RailsConf 2023
tenderlove
30
1.2k
Why You Should Never Use an ORM
jnunemaker
PRO
58
9.5k
Fashionably flexible responsive web design (full day workshop)
malarkey
407
66k
How To Stay Up To Date on Web Technology
chriscoyier
790
250k
Transcript
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ୈೋճ"84ϚϧνΞΧϯτࣄྫࡇΓ ηΩϡϦςΟΠϯγσϯτΛΓӽ͑ΔͨΊʹߦͬͨ ϚϧνΞΧϯτͰͷऔΓΈʹ͍ͭͯ $MBTTJ$PSQ,FOSZP0NJOBNJ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE $ whoami • ,FOSZP0NJOBNJ !LFOSZPPP • ۙ͘Β͍#$αʔϏεΛத৺ʹ%#"ɺαʔό αΠυΤϯδχΞɺ43&Λܦݧɻ
• $MBTTJʹ43&ͱͯ͠δϣΠϯɻ • ͜͜ΠϯϑϥηΩϡϦςΟྖҬΛத৺ʹۀΛ ߦ͍ͬͯΔɻ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE About Classi ʮ$MBTTJʯڭҭݱΛࢧԉ͢Δ ΫϥυαʔϏε • શࠃͷߴߍͷˋ͕ಋೖ • ߴߍੜͷਓʹਓ͕ར༻ •
ར༻ऀສਓ • ઌੜɺੜెɺอޢऀ͕ܨ͕Δ ֶशࢧԉϓϥοτϑΥʔϜ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͞ͳ͍͜ͱ • ݄ɺ݄ͷߴෛՙʹΑΔΞΫηεোঢ়ଶʹؔ͢ΔऔΓΈʹ͍ͭͯ • ͪ͜Βʹ͍ͭͯԼهΛ͝ཡ͍ͩ͘͞ • $MBTTJ։ൃऀϒϩά IUUQTUFDIDMBTTJKQ
• %FWFMPQFST4VNNJU
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE [PR] Developers Summit 2021 IUUQTFWFOUTIPFJTIBKQEFWTVNJTFTTJPO
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ηΩϡϦςΟΠϯγσϯτʹ͍ͭͯ 4VO 4BU ֎෦ͷ߈ܸऀ͔Βෆਖ਼ΞΫηεΛड͚αʔϏεఀࢭ αʔϏε࣌ؒޙʹ෮چͰ͖ͨͷͷϢʔβʔใྲྀग़ͷՄೳੑΛ֬ೝ ͯ͢ͷϢʔβʔͷύεϫʔυมߋ͕ྃ
֎෦αΠτʹͯɺྲྀग़ͨ͠ݸਓใͷ࿙ӮΛ֬ೝ ΠϯϑϥɺΞϓϦέʔγϣϯͱʹൈຊతͳηΩϡϦςΟͷݟ͠Λ࣮ࢪ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ઓུͱධՁ • શମͷઓུ • "848FMM"SDIJUFDUFE'SBNFXPSL4FDVSJUZ1JMMBS • "84ΞΧϯτཧͷઓུ • #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT
• ηΩϡϦςΟධՁ • "84ϓϩϑΣογϣφϧαʔϏεͷηΩϡϦςΟධՁ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ
։ൃ༻ΞΧϯτ ࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 064$1Λར༻͍ͯ͠ͳ͍ • 1SPEVDUJPOΞΧϯτ͕0SHBOJ[BUJPOͷཧΞΧϯτͱͯ͠ઃఆ • ࠷ݫີʹཧ͍ͨͣ͠ͷΞΧϯτ͕ཧͰ͖ͳ͍ • #BTUJPOΞΧϯτɺ։ൃऀ͕4BOECPYڥͱͯ͠ར༻
• 1SPEVDUJPOΞΧϯτϩάΠϯ͢ΔݩͷΞΧϯτ͕ηΩϡΞͰͳ͍
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ཧΞΧϯτͷΓସ͑ • ཧΞΧϯτΛ৽ن࡞ • طଘΞΧϯτچ৫Λɺ՝ۚपΓͷઃఆΛՃ͠৽৫Ҡಈ େมʜ
• 0SHBOJ[BUJPOTಋೖ࣌৽نʹཧΞΧϯτΛ࡞Γ·͠ΐ͏ʂ • 06ઃܭͱஔ • ʮ#FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOTʯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -After- 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06
.BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT IUUQTBXTBNB[PODPNKQCMPHTNUCFTUQSBDUJDFTGPSPSHBOJ[BUJPOBMVOJUTXJUIBXTPSHBOJ[BUJPOT
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organiztional Units 06 ༻్ 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 1SPE@06
ຊ൪ΞΧϯτͷΈΛแ͢Δ06 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ ։ൃ༻ΞΧϯτ
࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O Ϛωδϝϯτίϯιʔϧར༻ ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- • ։ൃऀ͚ʹҎԼͷ௨ΓͰΞΫηεํ๏Λఏڙ • ϚωδϝϯτίϯιʔϧͰͷར༻ • ϩάΠϯํ๏(4VJUFͱ4".-࿈ܞ •
#BTUJPOΞΧϯτΛܦͯɺ࡞ۀ͍ͨ͠ΞΧϯτʹ4XJUDI3PMF͢Δ • ϓϩάϥϜΞΫηεͰͷར༻ • ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 3PMFͱΞΫηεΩʔͷཧ • ผʑʹཧΛߦ͏ඞཁ͕͋Γࡶ • ΞΫηεΩʔཧ • ӬଓతͳΞΫηεΩʔͷཧ͕ར༻ऀͤ
• 4XJUDI3PMFͷηΩϡϦςΟ • աڈɺεΠονઌ3PMFͷ1SJODJQBMઃఆϛεʹΑΓఆͯ͠ͳ͍ݖݶͰೖΓ์ʹ ͳ͍ͬͯͨ͜ͱ͕͋ͬͨ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ϩʔΧϧϚγϯͷରࡦ • BXTMBCTHJUTFDSFUTಋೖ • ΞΫηεΩʔͳͲͷػີใͷ(JUϦϙδτϦͷίϛοτΛ͙
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • "84ଆͷରࡦ • "84440ͷҠߦ • ݄ʹ5PLZP3FHJPOͰϩʔϯνͨ͠λΠϛϯάͰҠߦ • "[VSF"%ͱ࿈ܞ͢Δ͜ͱͰΞΧϯτཧ͕γϯϓϧʹ
• ΞΫηεΩʔͷཧෆཁʹ ˞4BB4͚ͷͷআ͘
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06 .BJOUFOBODF@06
4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY "[VSF"% Ϛωδϝϯτίϯιʔϧ ΞΫηεΩʔ "844JOHMF4JHO0O ֤ΞΧϯτϩάΠϯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ࣄ • 4XJUDI3PMF࣌ͷཧऀ༻3PMFΛআͨ͠ͱ͜ΖɺαʔϏεͰར༻͍ͯ͠ Δ$.,͕ӾཡɺมߋෆՄೳʹͳͬͯ͠·ͬͨ •
"ENJOJTUSBUPSݖݶϢʔβʔͰSPPUͰͲ͏ʹͰ͖ͳ͍ • ݪҼ • আͨ͠ཧऀ3PMFͷΈ͕ΩʔϙϦγʔͱͯ͠ࢦఆ͞Ε͍ͯͨͨΊɺআ͠ ͨ࣌ͰཧऀෆࡏͷΩʔʹͳΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ରԠ • "84ͷαϙʔτ͍߹ΘͤɺҰ࣌తͳϢʔβʔΛ࡞ɺ1VU,FZ1PMJDZݖݶ Λ༩ͯ͠Β͍ݩͷΩʔϙϦγʔΛ෮׆ͤ͞Δ͜ͱͰ෮چͨ͠ •
ͨͩ͠ɺ࡞ۀλΠϛϯάͳͲίϯτϩʔϧͰ͖ͳ͍ཁૉ͋ΔͷͰɺΩʔϙϦ γʔͷཧऀͱͯ͠ෳͷ6TFS͘͠3PMFΛ༩͓ͯ͘͠ͷ͕Φεεϝ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ༧తΨʔυϨʔϧ • 4$1ͷྫ • ෆ༻Ϧʔδϣϯͷ੍ݶ • ࠪܥૢ࡞ͷ੍ݶ • ڥಛ༗ͷ੍ݶ
ॏཁૢ࡞ͳͲ • શૢ࡞ͷېࢭ • FUD
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 06 ༻్ 4$1 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06
Ϧʔδϣϯ੍ݶɺࠪܥૢ࡞ͷ੍ݶ 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 ։ൃऀ͚ͷ੍ݶ 1SPE@06 ຊ൪ΞΧϯτͷΈΛแ͢Δ06 ڥಛ༗ͷ੍ݶ 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 ڥಛ༗ͷ੍ݶ *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 ڥಛ༗ͷ੍ݶ 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 ݕূ༰ʹΑͬͯมߋ .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 ϝϯς༰ʹΑͬͯมߋ 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06 શૢ࡞Λېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06
*OGSB@06 .BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY Ϧʔδϣϯ੍ݶ ࠪܥૢ࡞ͷ੍ݶ ։ൃऀ͚ͷ੍ݶ 1SPEʹ͓͚Δ ॏཁૢ࡞ͷ੍ݶ ڞ௨ج൫ಛ༗ͷ੍ݶ มߋ มߋ શૢ࡞ͷېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ • $MPVE5SBJMΑΔಛఆૢ࡞ͷࢹ • $POpH • (VBSE%VUZ • 4FDVSJUZ)VC
• 5SVTUFE"EWJTPS ݕͨ͠༰ͷϑΟϧλϦϯάʹؔͯ͠ɺνϡʔχϯάΛਐΊ͍ͯΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ αʔϏε໊ 0SHBOJ[BUJPOTରԠ ϝϯόʔͷҕ ϝϯόʔͷࣗಈ༗ޮԽ ิ $POpH ˓ ˓
✕ $MPVE'PSNBUJPO4UBDL4FUTΛར༻ͯ͠ɺ ϝϯόʔΞΧϯτͷ༗ޮԽΛࣗಈͰ࣮ࢪ (VBSE%VUZ ˓ ˓ ˓ 4FDVSJUZ)VC ˓ ˓ ˓ ·ͨɺൃݟతΨʔυϨʔϧͰར༻͢ΔҎԼͷαʔϏεʹؔͯ͠ɺ $POpH͚ͩࣗಈ༗ޮԽ͕Ͱ͖ͳ͔ͬͨͨΊ$'O4UBDL4FUTΛར༻͍ͯ͠Δ ૣ͘0SHBOJ[BUJPOTͱͷεϜʔζͳ౷߹͕࣮ݱͯ͠΄͍͠
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ࠓޙ • ൃݟతΨʔυϨʔϧͷνϡʔχϯά • $POpH3VMFTͷνϡʔχϯά • (VBSE%VUZ4FDVSJUZ)VCͷݕ༰ͷਫ਼ࠪ • ϩΪϯάͱϞχλϦϯάͷڧԽ
• 4*&.ͷಋೖ 4*&.PO"NB[PO&4Λݕ౼த • ΠϯγσϯτϨεϙϯεͷڧԽ • )BSEFOJOHΠϕϯτͷࢀՃɺݚम
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ·ͱΊ • ΠϯγσϯτҎ߱ɺϚϧνΞΧϯτߏΛ׆͔ͨ͠ܗͰରࡦΛ͢͢Ί͖ͯͨ • "84440Λར༻͢Δ͜ͱͰΞΧϯτཧίετ͕Լ͕ΓηΩϡΞʹͳͬͨ • ༧తɺൃݟతΨʔυϨʔϧͷಋೖͰΑΓηΩϡΞʹͳͬͨ ϚϧνΞΧϯτΛಋೖͯ͠ηΩϡΞͳڥΛखʹೖΕΑ͏
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ʘɹ8F"SF)JSJOHɹʗ IUUQTDPSQDMBTTJKQDBSFFST
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͓ΘΓ