Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / ...
Search
kenryooo
February 09, 2021
Technology
6
5.3k
セキュリティインシデントを乗り越えるために行ったマルチアカウントでの取り組みについて / AWS multi-account approach in Classi
2021/02/09開催「第二回 AWSマルチアカウント事例祭り」での発表資料です。
kenryooo
February 09, 2021
Tweet
Share
Other Decks in Technology
See All in Technology
AWS re:Invent 2024で発表された コードを書く開発者向け機能について
maruto
0
190
Turing × atmaCup #18 - 1st Place Solution
hakubishin3
0
470
サービスでLLMを採用したばっかりに振り回され続けたこの一年のあれやこれや
segavvy
2
390
AI時代のデータセンターネットワーク
lycorptech_jp
PRO
1
280
レンジャーシステムズ | 会社紹介(採用ピッチ)
rssytems
0
150
Amazon SageMaker Unified Studio(Preview)、Lakehouse と Amazon S3 Tables
ishikawa_satoru
0
150
10個のフィルタをAXI4-Streamでつなげてみた
marsee101
0
160
社外コミュニティで学び社内に活かす共に学ぶプロジェクトの実践/backlogworld2024
nishiuma
0
260
ゼロから創る横断SREチーム 挑戦と進化の軌跡
rvirus0817
2
260
コンテナセキュリティのためのLandlock入門
nullpo_head
2
320
Snowflake女子会#3 Snowpipeの良さを5分で語るよ
lana2548
0
230
複雑性の高いオブジェクト編集に向き合う: プラガブルなReactフォーム設計
righttouch
PRO
0
110
Featured
See All Featured
Statistics for Hackers
jakevdp
796
220k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
507
140k
Build The Right Thing And Hit Your Dates
maggiecrowley
33
2.4k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
232
17k
Building Better People: How to give real-time feedback that sticks.
wjessup
365
19k
実際に使うSQLの書き方 徹底解説 / pgcon21j-tutorial
soudai
169
50k
Why Our Code Smells
bkeepers
PRO
335
57k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
28
2.1k
Music & Morning Musume
bryan
46
6.2k
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
656
59k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
48
2.2k
Principles of Awesome APIs and How to Build Them.
keavy
126
17k
Transcript
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ୈೋճ"84ϚϧνΞΧϯτࣄྫࡇΓ ηΩϡϦςΟΠϯγσϯτΛΓӽ͑ΔͨΊʹߦͬͨ ϚϧνΞΧϯτͰͷऔΓΈʹ͍ͭͯ $MBTTJ$PSQ,FOSZP0NJOBNJ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE $ whoami • ,FOSZP0NJOBNJ !LFOSZPPP • ۙ͘Β͍#$αʔϏεΛத৺ʹ%#"ɺαʔό αΠυΤϯδχΞɺ43&Λܦݧɻ
• $MBTTJʹ43&ͱͯ͠δϣΠϯɻ • ͜͜ΠϯϑϥηΩϡϦςΟྖҬΛத৺ʹۀΛ ߦ͍ͬͯΔɻ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE About Classi ʮ$MBTTJʯڭҭݱΛࢧԉ͢Δ ΫϥυαʔϏε • શࠃͷߴߍͷˋ͕ಋೖ • ߴߍੜͷਓʹਓ͕ར༻ •
ར༻ऀສਓ • ઌੜɺੜెɺอޢऀ͕ܨ͕Δ ֶशࢧԉϓϥοτϑΥʔϜ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͞ͳ͍͜ͱ • ݄ɺ݄ͷߴෛՙʹΑΔΞΫηεোঢ়ଶʹؔ͢ΔऔΓΈʹ͍ͭͯ • ͪ͜Βʹ͍ͭͯԼهΛ͝ཡ͍ͩ͘͞ • $MBTTJ։ൃऀϒϩά IUUQTUFDIDMBTTJKQ
• %FWFMPQFST4VNNJU
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE [PR] Developers Summit 2021 IUUQTFWFOUTIPFJTIBKQEFWTVNJTFTTJPO
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ηΩϡϦςΟΠϯγσϯτʹ͍ͭͯ 4VO 4BU ֎෦ͷ߈ܸऀ͔Βෆਖ਼ΞΫηεΛड͚αʔϏεఀࢭ αʔϏε࣌ؒޙʹ෮چͰ͖ͨͷͷϢʔβʔใྲྀग़ͷՄೳੑΛ֬ೝ ͯ͢ͷϢʔβʔͷύεϫʔυมߋ͕ྃ
֎෦αΠτʹͯɺྲྀग़ͨ͠ݸਓใͷ࿙ӮΛ֬ೝ ΠϯϑϥɺΞϓϦέʔγϣϯͱʹൈຊతͳηΩϡϦςΟͷݟ͠Λ࣮ࢪ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ઓུͱධՁ • શମͷઓུ • "848FMM"SDIJUFDUFE'SBNFXPSL4FDVSJUZ1JMMBS • "84ΞΧϯτཧͷઓུ • #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT
• ηΩϡϦςΟධՁ • "84ϓϩϑΣογϣφϧαʔϏεͷηΩϡϦςΟධՁ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ
։ൃ༻ΞΧϯτ ࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 064$1Λར༻͍ͯ͠ͳ͍ • 1SPEVDUJPOΞΧϯτ͕0SHBOJ[BUJPOͷཧΞΧϯτͱͯ͠ઃఆ • ࠷ݫີʹཧ͍ͨͣ͠ͷΞΧϯτ͕ཧͰ͖ͳ͍ • #BTUJPOΞΧϯτɺ։ൃऀ͕4BOECPYڥͱͯ͠ར༻
• 1SPEVDUJPOΞΧϯτϩάΠϯ͢ΔݩͷΞΧϯτ͕ηΩϡΞͰͳ͍
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ཧΞΧϯτͷΓସ͑ • ཧΞΧϯτΛ৽ن࡞ • طଘΞΧϯτچ৫Λɺ՝ۚपΓͷઃఆΛՃ͠৽৫Ҡಈ େมʜ
• 0SHBOJ[BUJPOTಋೖ࣌৽نʹཧΞΧϯτΛ࡞Γ·͠ΐ͏ʂ • 06ઃܭͱஔ • ʮ#FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOTʯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Classi Organizations -After- 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06
.BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY #FTU1SBDUJDFTGPS0SHBOJ[BUJPOBM6OJUTXJUI"840SHBOJ[BUJPOT IUUQTBXTBNB[PODPNKQCMPHTNUCFTUQSBDUJDFTGPSPSHBOJ[BUJPOBMVOJUTXJUIBXTPSHBOJ[BUJPOT
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organiztional Units 06 ༻్ 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 1SPE@06
ຊ൪ΞΧϯτͷΈΛแ͢Δ06 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- 0SHBOJ[BUJPOT 3PPU 1SPEVDUJPOΞΧϯτ ཧΞΧϯτ "[VSF"% #BTUJPOΞΧϯτ ։ൃ༻ΞΧϯτ
࿈ܞαʔϏε༻ 1SPEVDUJPOΞΧϯτ 4XJUDI3PMF -PH*O Ϛωδϝϯτίϯιʔϧར༻ ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE IDͱΞΫηεཧ -Before- • ։ൃऀ͚ʹҎԼͷ௨ΓͰΞΫηεํ๏Λఏڙ • ϚωδϝϯτίϯιʔϧͰͷར༻ • ϩάΠϯํ๏(4VJUFͱ4".-࿈ܞ •
#BTUJPOΞΧϯτΛܦͯɺ࡞ۀ͍ͨ͠ΞΧϯτʹ4XJUDI3PMF͢Δ • ϓϩάϥϜΞΫηεͰͷར༻ • ֤"84ΞΧϯτͰݸผʹΞΫηεΩʔΛൃߦ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE • 3PMFͱΞΫηεΩʔͷཧ • ผʑʹཧΛߦ͏ඞཁ͕͋Γࡶ • ΞΫηεΩʔཧ • ӬଓతͳΞΫηεΩʔͷཧ͕ར༻ऀͤ
• 4XJUDI3PMFͷηΩϡϦςΟ • աڈɺεΠονઌ3PMFͷ1SJODJQBMઃఆϛεʹΑΓఆͯ͠ͳ͍ݖݶͰೖΓ์ʹ ͳ͍ͬͯͨ͜ͱ͕͋ͬͨ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • ϩʔΧϧϚγϯͷରࡦ • BXTMBCTHJUTFDSFUTಋೖ • ΞΫηεΩʔͳͲͷػີใͷ(JUϦϙδτϦͷίϛοτΛ͙
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͬͨ͜ͱ • "84ଆͷରࡦ • "84440ͷҠߦ • ݄ʹ5PLZP3FHJPOͰϩʔϯνͨ͠λΠϛϯάͰҠߦ • "[VSF"%ͱ࿈ܞ͢Δ͜ͱͰΞΧϯτཧ͕γϯϓϧʹ
• ΞΫηεΩʔͷཧෆཁʹ ˞4BB4͚ͷͷআ͘
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06 *OGSB@06 .BJOUFOBODF@06
4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY "[VSF"% Ϛωδϝϯτίϯιʔϧ ΞΫηεΩʔ "844JOHMF4JHO0O ֤ΞΧϯτϩάΠϯ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ࣄ • 4XJUDI3PMF࣌ͷཧऀ༻3PMFΛআͨ͠ͱ͜ΖɺαʔϏεͰར༻͍ͯ͠ Δ$.,͕ӾཡɺมߋෆՄೳʹͳͬͯ͠·ͬͨ •
"ENJOJTUSBUPSݖݶϢʔβʔͰSPPUͰͲ͏ʹͰ͖ͳ͍ • ݪҼ • আͨ͠ཧऀ3PMFͷΈ͕ΩʔϙϦγʔͱͯ͠ࢦఆ͞Ε͍ͯͨͨΊɺআ͠ ͨ࣌ͰཧऀෆࡏͷΩʔʹͳΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE AWS SSO Ҡߦ࣌ͷτϥϒϧ • ରԠ • "84ͷαϙʔτ͍߹ΘͤɺҰ࣌తͳϢʔβʔΛ࡞ɺ1VU,FZ1PMJDZݖݶ Λ༩ͯ͠Β͍ݩͷΩʔϙϦγʔΛ෮׆ͤ͞Δ͜ͱͰ෮چͨ͠ •
ͨͩ͠ɺ࡞ۀλΠϛϯάͳͲίϯτϩʔϧͰ͖ͳ͍ཁૉ͋ΔͷͰɺΩʔϙϦ γʔͷཧऀͱͯ͠ෳͷ6TFS͘͠3PMFΛ༩͓ͯ͘͠ͷ͕Φεεϝ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ༧తΨʔυϨʔϧ • 4$1ͷྫ • ෆ༻Ϧʔδϣϯͷ੍ݶ • ࠪܥૢ࡞ͷ੍ݶ • ڥಛ༗ͷ੍ݶ
ॏཁૢ࡞ͳͲ • શૢ࡞ͷېࢭ • FUD
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 06 ༻్ 4$1 'PVOEBUJPOBM@06 1SPE4%-$ͷϫʔΫϩʔυͱڞ௨ج൫Λแ͢Δ06
Ϧʔδϣϯ੍ݶɺࠪܥૢ࡞ͷ੍ݶ 8PSLMPBET@06 1SPE4%-$ͷϫʔΫϩʔυΛแ͢Δ06 ։ൃऀ͚ͷ੍ݶ 1SPE@06 ຊ൪ΞΧϯτͷΈΛแ͢Δ06 ڥಛ༗ͷ੍ݶ 4%-$@06 4UBHJOH%FWɺ4BOECPYͳͲΛแ͢Δ06 ڥಛ༗ͷ੍ݶ *OGSB@06 ڞ௨ج൫ ϩάूΞΧϯτηΩϡϦςΟࠪΞΧϯτ Λแ͢Δ06 ڥಛ༗ͷ੍ݶ 1PMJDZ4UBHJOH@06 ৫ߏͷมߋ4$1ͷมߋͳͲͷݕূͰར༻͢Δ06 ݕূ༰ʹΑͬͯมߋ .BJOUFOBODF@06 ࠪܥػೳͷϝϯςφϯεͳͲɺҰ࣌తʹ4$1Λҳ͢Δ࡞ۀΛߦ͏߹ʹར༻͢Δ06 ϝϯς༰ʹΑͬͯมߋ 4VTQFOEFE@06 ഇغ༧ఆͷ"84ΞΧϯτΛแ͢Δ06 શૢ࡞Λېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Organizational Units and SCP 0SHBOJ[BUJPOT 'PVOEBUJPOBM@06 8PSLMPBET@06 1SPE@06 4%-$@06
*OGSB@06 .BJOUFOBODF@06 4VTQFOEFE@06 3PPU ϚελʔΞΧϯτ ܭըϝϯςφϯε༻ ഇغ༧ఆ 1PMJDZ4UBHJOH@06 ηΩϡϦςΟ ϙϦγʔมߋ༻ ֤छϩά 1SPEVDUJPO 4UBHJOH 4BOECPY Ϧʔδϣϯ੍ݶ ࠪܥૢ࡞ͷ੍ݶ ։ൃऀ͚ͷ੍ݶ 1SPEʹ͓͚Δ ॏཁૢ࡞ͷ੍ݶ ڞ௨ج൫ಛ༗ͷ੍ݶ มߋ มߋ શૢ࡞ͷېࢭ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ • $MPVE5SBJMΑΔಛఆૢ࡞ͷࢹ • $POpH • (VBSE%VUZ • 4FDVSJUZ)VC
• 5SVTUFE"EWJTPS ݕͨ͠༰ͷϑΟϧλϦϯάʹؔͯ͠ɺνϡʔχϯάΛਐΊ͍ͯΔ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ൃݟతΨʔυϨʔϧ αʔϏε໊ 0SHBOJ[BUJPOTରԠ ϝϯόʔͷҕ ϝϯόʔͷࣗಈ༗ޮԽ ิ $POpH ˓ ˓
✕ $MPVE'PSNBUJPO4UBDL4FUTΛར༻ͯ͠ɺ ϝϯόʔΞΧϯτͷ༗ޮԽΛࣗಈͰ࣮ࢪ (VBSE%VUZ ˓ ˓ ˓ 4FDVSJUZ)VC ˓ ˓ ˓ ·ͨɺൃݟతΨʔυϨʔϧͰར༻͢ΔҎԼͷαʔϏεʹؔͯ͠ɺ $POpH͚ͩࣗಈ༗ޮԽ͕Ͱ͖ͳ͔ͬͨͨΊ$'O4UBDL4FUTΛར༻͍ͯ͠Δ ૣ͘0SHBOJ[BUJPOTͱͷεϜʔζͳ౷߹͕࣮ݱͯ͠΄͍͠
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE Agenda • ηΩϡϦςΟΠϯγσϯτ • ઓུͱධՁ • "84ΞΧϯτཧ • *%ͱΞΫηεཧ
• ΨʔυϨʔϧ • ࠓޙ
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ࠓޙ • ൃݟతΨʔυϨʔϧͷνϡʔχϯά • $POpH3VMFTͷνϡʔχϯά • (VBSE%VUZ4FDVSJUZ)VCͷݕ༰ͷਫ਼ࠪ • ϩΪϯάͱϞχλϦϯάͷڧԽ
• 4*&.ͷಋೖ 4*&.PO"NB[PO&4Λݕ౼த • ΠϯγσϯτϨεϙϯεͷڧԽ • )BSEFOJOHΠϕϯτͷࢀՃɺݚम
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ·ͱΊ • ΠϯγσϯτҎ߱ɺϚϧνΞΧϯτߏΛ׆͔ͨ͠ܗͰରࡦΛ͢͢Ί͖ͯͨ • "84440Λར༻͢Δ͜ͱͰΞΧϯτཧίετ͕Լ͕ΓηΩϡΞʹͳͬͨ • ༧తɺൃݟతΨʔυϨʔϧͷಋೖͰΑΓηΩϡΞʹͳͬͨ ϚϧνΞΧϯτΛಋೖͯ͠ηΩϡΞͳڥΛखʹೖΕΑ͏
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ʘɹ8F"SF)JSJOHɹʗ IUUQTDPSQDMBTTJKQDBSFFST
$PQZSJHIU$MBTTJ$PSQ"MMSJHIUTSFTFSWFE ͓ΘΓ