Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティ系アップデート全体像と AWS Organizations 新ポリシー「宣言型ポリ...
Search
MasahiroKawahara
December 11, 2024
Technology
1.3k
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
セキュリティ系アップデート全体像と AWS Organizations 新ポリシー「宣言型ポリシー」を紹介 / reGrowth 2024 Security
MasahiroKawahara
December 11, 2024
More Decks by MasahiroKawahara
See All by MasahiroKawahara
Claude Code で使える DuckDB Skills を試してみた / DuckDB Skills and Claude Code
masahirokawahara
2
2.4k
Claude Code を安全に使おう勉強会 / Claude Code Security Basics
masahirokawahara
19
46k
Claude Code Skills 勉強会 (DevelersIO向けに調整済み) / claude code skills for devio
masahirokawahara
1
32k
新 Security HubがついにGA!仕組みや料金を深堀り #AWSreInvent #regrowth / AWS Security Hub Advanced GA
masahirokawahara
1
3.9k
AWS環境のリソース調査を Claude Code で効率化 / aws investigate with cc devio2025
masahirokawahara
2
2.1k
ここ一年のCCoEとしてのAWSコスト最適化を振り返る / CCoE AWS Cost Optimization devio2025
masahirokawahara
1
2.5k
生まれ変わった AWS Security Hub (Preview) を紹介 #reInforce_osaka / reInforce New Security Hub
masahirokawahara
0
1.6k
Amazon DevOps Guru のベースラインを整備して1ヶ月ほど運用してみた #jawsug_asa / Amazon DevOps Guru trial
masahirokawahara
3
830
DuckDB MCPサーバーを使ってAWSコストを分析させてみた / AWS cost analysis with DuckDB MCP server
masahirokawahara
0
2.9k
Other Decks in Technology
See All in Technology
AWSシリコン最前線 〜AI時代のチップ選択を読み解く〜
htokoyo
1
240
美味しいスイスチーズを作ろう🧀🐭
taigamikami
1
260
LLMと共に進化するプロセスを目指して
ymatsuwitter
12
3.7k
AIを「創る」と「使う」の循環 — HRテックが実践するリアルなAI組織実装
taketo957
0
1.8k
マーケットプレイス版Oracle WebCenter Content For OCI
oracle4engineer
PRO
5
1.8k
作って終わりにしない タイミーのセマンティックレイヤー育成の現在地
chanyou0311
1
860
AI Adaptable なテストを整える工夫 / Ways to Make Your Tests AI-Adaptable
bitkey
PRO
3
230
個人の発見を、組織の知恵に 〜生成AI活用を"探索"から"組織の仕組み"へ〜
kintotechdev
3
1.1k
AgentGatewayを試してみたかった
tkikuchi
0
130
Rancherの紹介&Update情報(RancherJP Online Meetup #09)
yoshiyuki_kono
0
130
あなたの AI ワークスペースに、 専門コーダーを連れてくる - Amazon Quick Desktop 最新情報
kawaji_scratch
1
110
Mastering Ruby Box
tagomoris
3
150
Featured
See All Featured
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
600
Amusing Abliteration
ianozsvald
1
200
We Have a Design System, Now What?
morganepeng
55
8.2k
Lightning Talk: Beautiful Slides for Beginners
inesmontani
PRO
2
570
We Are The Robots
honzajavorek
0
240
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
231
23k
Mobile First: as difficult as doing things right
swwweet
225
10k
Paper Plane
katiecoart
PRO
1
51k
Deep Space Network (abreviated)
tonyrice
0
170
Bash Introduction
62gerente
615
210k
[SF Ruby Conf 2025] Rails X
palkan
2
1.1k
New Earth Scene 8
popppiees
3
2.3k
Transcript
ηΩϡϦςΟܥΞοϓσʔτͷશମ૾ 0SHBOJ[BUJPOTͷ৽ϙϦγʔΛհ
SFHSPXUI@PTBLB ࣗݾհ ݪେ LBXBIBSBNBTBIJSP ˔ $MBTTNFUIPE"84ࣄۀຊ෦ ίϯαϧςΟϯά෦ ˔ d"845PQ&OHJOFFST ˔
SF*OWFOUݱࢀՃ ˓ ,3BDF͕շͰͨ͠
SFHSPXUI@PTBLB ࠓ͢͜ͱ ˔ ηΩϡϦςΟܥΞοϓσʔτΛ͓͞Β͍ ˔ "840SHBOJ[BUJPOTͷΞϓσΛհ ˔ ↳ એݴܕϙϦγʔΛਂງΓ ˔
↳ ͜Ε͔Βͷ༧తΨʔυϨʔϧ
ηΩϡϦςΟܥΞοϓσʔτ ͬ͘͟Γͱ͓͞Β͍
SFHSPXUI@PTBLB ߋ৽ͷ͋ͬͨ"84αʔϏε ˞༧બམؚͪΉ
SFHSPXUI@PTBLB ߋ৽ͷ͋ͬͨ"84αʔϏε ˞༧બམؚͪΉ <"843FTPVSDF&YQMPSFS> ɾػೳ֦ॆɻηΩϡϦςΟίετͷใΛҰݩతʹݕࡧɾཧՄೳʹ <"844ZTUFNT.BOBHFS> ɾϚϧνΞΧϯτϚϧνϦʔδϣϯͷϊʔυѲɺཧ͕ҰݩԽ <"844FDVSJUZ-BLF> ɾ৽͍͠ύʔτφʔೝఆ "NB[PO4FDVSJUZ-BLF3FBEZ4QFDJBMJ[BUJPO͕ൃද
ɾ0QFO4FBSDI4FSWJDFͱͷ [FSP&5-౷߹Λαϙʔτ <"84$MPVE5SBJM> ɾػೳڧԽɻแׅతͳμογϡϘʔυՃͱΫϩεΞΧϯτͰͷσʔλετΞڞ༗ ɾ"*ػೳΛՃɻࣗવݴޠͰͷΫΤϦੜͱΫΤϦ݁Ռͷཁػೳ <*"."DDFTT"OBMZ[FS> ɾະ༻ΞΫηεੳʹͯɺΞΧϯτ*%ϩʔϧλάʹΑΔείʔϓબ͕Մೳʹ
SFHSPXUI@PTBLB ߋ৽ͷ͋ͬͨ"84αʔϏε ˞༧બམؚͪΉ <"84*".> ɾ0SHBOJ[BUJPOTͷϝϯόʔΞΧϯτͷϧʔτΞΫηε ΛҰݩཧՄೳʹ <"840SHBOJ[BUJPOT> ɾએݴܕϙϦγʔ %FDMBSBUJWFQPMJDZ ͕Ճ
ɾ3$1 3FTPVSDFDPOUSPMQPMJDZ ͕Ճ <"84$POUSPM5PXFS> ɾએݴܕϙϦγʔΛ༻ͨ͠༧ίϯτϩʔϧ͕Ճ ɾ3$1Λ༻ͨ͠༧ίϯτϩʔϧ͕Ճ ɾ"84#BDLVQͱ౷߹ɻਪόοΫΞοϓઃఆΛҰׅద ༻Մೳʹ
SFHSPXUI@PTBLB ߋ৽ͷ͋ͬͨ"84αʔϏε ˞༧બམؚͪΉ <"NB[PO71$> ɾ71$ͷϒϩοΫύϒϦοΫΞΫηε #1" Λൃද ɾ$MPVE'SPOU͕71$ΦϦδϯʹରԠ <"84/FUXPSL'JSFXBMM> ɾ)551ɺ26*$ɺ1PTUHSF42-ͳͲͷ৽ϓϩτίϧݕ
ग़ʹରԠ <"847FSJGJFE"DDFTT> ɾ5$144)ɺ3%1ͳͲͷඇ)551 4 Ϧιʔεͷθϩ τϥετΞΫηε͕Մೳʹ
SFHSPXUI@PTBLB ߋ৽ͷ͋ͬͨ"84αʔϏε ˞༧બམؚͪΉ <"NB[PO(VBSE%VUZ> ɾߴͳڴҖݕग़ػೳ͕Ճɻෳεςʔδͷ߈ܸΛࣗಈݕग़ <"844FDVSJUZ*ODJEFOU3FTQPOTF> ɾ༗ਓͰηΩϡϦςΟΠϯγσϯτʹରԠͯ͘͠ΔαʔϏε͕(" ˞࠷ֹ݄ྉۚ υϧ͔Β ɾ"844FDVSJUZ*ODJEFOU3FTQPOTFͷ৽͍͠ύʔτφʔϓϩάϥϜ
"840SHBOJ[BUJPOTͷ ΞοϓσʔτΛհ
"840SHBOJ[BUJPOTΛ ͞Βͬͱ͓͞Β͍
SFHSPXUI@PTBLB 0SHBOJ[BUJPOTϚϧνΞΧϯτཧͰཱͭαʔϏε <ओͳಛ> ˔ શ"84ΞΧϯτͷٻΛू ˔ "84ΞΧϯτΛ֊Խͯ͠ཧɺ੍ޚ ˔ ͞·͟·ͳ"84αʔϏεͱ࿈ܞ ը૾Ҿ༻"840SHBOJ[BUJPOTͷ֓೦ͱ༻ޠ
"840SHBOJ[BUJPOT
SFHSPXUI@PTBLB ֤छ ϙϦγʔΛͬͯෳΞΧϯτΛ੍ޚͰ͖Δ ˔ 4$1 4FSWJDFDPOUSPMQPMJDZ ˔ λάϙϦγʔ ˔ όοΫΞοϓϙϦγʔ
˔ ͑ΔϙϦγʔͷৄࡉҎԼΛࢀর ˠ5FSNJOPMPHZBOEDPODFQUTGPS"840SHBOJ[BUJPOT "840SHBOJ[BUJPOT
"840SHBOJ[BUJPOTͷ SF*OWFOUΞοϓσʔτ
SFHSPXUI@PTBLB SF*OWFOUʹͯɺͭͷ৽ϙϦγʔ͕ొʂ ˔ <OFX>3$1 3FTPVSDFDPOUSPMQPMJDZ ˔ <OFX>એݴܕϙϦγʔ %FDMBSBUJWFQPMJDZ
એݴܕϙϦγʔ %FDMBSBUJWF1PMJDZ
SFHSPXUI@PTBLB αʔϏεϨϕϧͰ l·͍͠ઃఆz Λఆٛద༻Ͱ͖Δ ˔ એݴܕϙϦγʔ৽͍͠ʮαʔϏεϨϕϧ ͷϙϦγʔʯ ˔ ৫ͷ"84ΞΧϯτʹ͓͍ͯɺಛఆ αʔϏεଐੑΛඪ४ԽͰ͖Δ
˔ ΤϥʔϝοηʔδΛΧελϚΠζՄೳ <ݱࡏαϙʔτ͍ͯ͠Δଐੑ> ˔ 71$ ˓ 71$ϒϩοΫύϒϦοΫΞΫηε ˔ &$ ˓ γϦΞϧίϯιʔϧΞΫηε ˓ ".*ϒϩοΫύϒϦοΫΞΫηε ˓ ڐՄ͞Εͨ".*ͷར༻ ˓ *.%4ͷσϑΥϧτઃఆ ˔  ˓ εφοϓγϣοτͷϒϩοΫύϒϦοΫΞΫηε
SFHSPXUI@PTBLB ΫϦοΫͰ؆୯ʹઃఆͰ͖Δ ը૾Ҿ༻ʲΞοϓσʔτʳ৽ͨʹൃද͞ΕͨEFDMBSBUJWFQPMJDJFTʢએݴܕϙϦγʔʣΛͨΊͯ͠Έͨ "84SF*OWFOUc%FWFMPQFST*0
ͦͦએݴతͬͯͳΜͩΖ͏ʁ
SFHSPXUI@PTBLB ʮ݁ہԿ͕͍ͨ͠ͷ͔ʯͱ͍͏త͚ͩΛઆ໌͢Δ͜ͱ Ҿ༻એݴతʁ %FDMBSBUJWF Ͳ͏͍͏͜ͱʁ !)JSPZVLJ@04",* 2JJUB
SFHSPXUI@PTBLB lεφοϓγϣοτͷϒϩοΫύϒϦοΫΞΫηεz Λྫʹߟ͑ͯΈΔ εφοϓγϣοτΛύϒϦοΫʹͨ͘͠ͳ͍Μʂ త
SFHSPXUI@PTBLB ʙએݴܕϙϦγʔ͕ͳ͍ͱ͖ʙ εφοϓγϣοτΛύϒϦοΫʹͨ͘͠ͳ͍Μʂ త ˞ͳ͍Ͱ͢ తͷୡํ๏
SFHSPXUI@PTBLB ʙએݴܕϙϦγʔ͕͋Δͱ͖ʙ εφοϓγϣοτΛύϒϦοΫʹͨ͘͠ͳ͍Μʂ త తͷୡํ๏
͜Ε͔Βͷ༧తΨʔυϨʔϧ
SFHSPXUI@PTBLB ࠓɺओཁͳ༧తΨʔυϨʔϧ͕Ұؾʹ૿͑ͨʂ ͜Ε·Ͱͷ<"84ͷ༧తΨʔυϨʔϧͱ͍͑> ˔ 4$1 4FSWJDFDPOUSPMQPMJDZ ͜Ε͔Βͷ<"84ͷ༧తΨʔυϨʔϧͱ͍͑> ˔ 4$1 4FSWJDFDPOUSPMQPMJDZ
˔ 3$1 3FTPVSDFDPOUSPMQPMJDZ ˔ એݴܕϙϦγʔ %FDMBSBUJWFQPMJDZ
SFHSPXUI@PTBLB <Πϝʔδ>͜Ε·Ͱͷ༧తΨʔυϨʔϧ
SFHSPXUI@PTBLB <Πϝʔδ>༧తΨʔυϨʔϧͷ͜Ε͔Β
SFHSPXUI@PTBLB <Πϝʔδ>༧తΨʔυϨʔϧͷ͜Ε͔Β ˞3$1͕αϙʔτ͍ͯ͠ΔαʔϏε ɾ4 ɾ454 ɾ,.4 ɾ424 ɾ4FDSFUT.BOBHFS ˞એݴܕϙϦγʔͷαϙʔτൣғ ɾ71$ϒϩοΫύϒϦοΫΞΫηε
ɾ&$γϦΞϧίϯιʔϧΞΫηε ɾ&$".*ϒϩοΫύϒϦοΫΞΫηε ɾ&$ڐՄ͞Εͨ".*ͷར༻ ɾ&$*.%4ͷσϑΥϧτઃఆ ɾεφοϓγϣοτͷϒϩοΫύϒϦοΫΞΫηε
͓ΘΓʹ
SFHSPXUI@PTBLB ͨ͜͠ͱ ˔ ηΩϡϦςΟܥΞοϓσʔτΛ͓͞Β͍ ˔ "840SHBOJ[BUJPOTͷΞϓσΛհ ˔ ↳ એݴܕϙϦγʔΛਂງΓ ˓
αʔϏεϨϕϧͰʮ·͍͠ઃఆʯΛఆٛద༻ ˓ ΫϦοΫͰ؆୯ʹઃఆͰ͖Δ ˔ ↳ ͜Ε͔Βͷ༧తΨʔυϨʔϧ ˓ ·ͣ એݴܕϙϦγʔ<OFX>Λద༻Ͱ͖ͳ͍͔ ˓ ࣍ʹैདྷ௨Γ 4$1Λ͏ ˓ ิతʹ 3$1<OFX>Λ͏
SFHSPXUI@PTBLB ࢀߟ ˔ 4JNQMJGZHPWFSOBODFXJUIEFDMBSBUJWFQPMJDJFTc"84/FXT#MPH ˔ <Ξοϓσʔτ>"840SHBOJ[BUJPOTͰએݴܕϙϦγʔ EFDMBSBUJWFQPMJDJFT ͕ར༻Մೳʹͳ Γ·ͨ͠ "84SF*OWFOUc%FWFMPQFST*0
˔ ʲΞοϓσʔτʳ৽ͨʹൃද͞ΕͨEFDMBSBUJWFQPMJDJFTʢએݴܕϙϦγʔʣΛͨΊͯ͠Έͨ "84SF*OWFOUc%FWFMPQFST*0 ˔ એݴతʁ %FDMBSBUJWF Ͳ͏͍͏͜ͱʁ !)JSPZVLJ@04",* 2JJUB
SFHSPXUI@PTBLB ࢀߟ • 識別 ◦ Introducing the Amazon Security Lake
Ready Specialization - AWS ◦ Amazon OpenSearch Service zero-ETL integration with Amazon Security Lake - AWS ◦ Find security, compliance, and operating metrics in AWS Resource Explorer - AWS ◦ AWS CloudTrail Lake launches enhanced analytics and cross-account data access - AWS ◦ AWS CloudTrail Lake enhances log analysis with AI-powered features - AWS ◦ The new AWS Systems Manager experience: Simplifying node management - AWS ◦ Customize scope of IAM Access Analyzer unused access analysis - AWS • 防御 ◦ Centrally manage root access in AWS Identity and Access Management (IAM) - AWS ◦ Amazon Web Services announces declarative policies - AWS ◦ Introducing resource control policies (RCPs) to centrally restrict access to AWS resources - AWS ◦ AWS Control Tower launches managed controls using declarative policies - AWS ◦ AWS Control Tower launches configurable managed controls implemented using resource control policies - AWS ◦ AWS Control Tower adds prescriptive backup plans to landing zone capabilities - AWS ◦ AWS announces Block Public Access for Amazon Virtual Private Cloud - AWS ◦ Amazon CloudFront announces VPC origins - AWS ◦ AWS Network Firewall expands the list of supported protocols and keywords in firewall rules - AWS ◦ AWS Verified Access now supports secure access to resources over non-HTTP(S) protocols (Preview) - AWS • 検知/対応 ◦ AWS announces AWS Security Incident Response for general availability - AWS ◦ Respond and recovery more quickly with AWS Security Incident Response Partners - AWS ◦ Amazon GuardDuty introduces GuardDuty Extended Threat Detection - AWS
None