Upgrade to Pro — share decks privately, control downloads, hide ads and more …

セキュリティ系アップデートの全体像とSecurity Hub深掘り #AWSreInvent ...

セキュリティ系アップデートの全体像とSecurity Hub深掘り #AWSreInvent #cmregrowth

MasahiroKawahara

December 11, 2023
Tweet

More Decks by MasahiroKawahara

Other Decks in Technology

Transcript

  1. ࣗݾ঺հ ઒ݪ੐େ LBXBIBSBNBTBIJSP ˔ Ϋϥεϝιου ˔ "84ࣄۀຊ෦ίϯαϧςΟϯά෦ॴଐ ˔ "1/"845PQ&OHJOFFST 4FSWJDF

    ˔ +BQBO"845PQ&OHJOFFST 4FDVSJUZ ˔ ޷͖ͳ"84αʔϏε*". $-* ˔ SF*OWFOUόʔνϟϧࢀՃ੎ https://dev.classmethod.jp/author/kawahara-masahiro/
  2. ηΩϡϦςΟαʔϏε l৽ػೳͷ݅਺z ϥϯΩϯά ˔ ݅4FDVSJUZ)VC %FUFDUJWF ˔ ݅*OTQFDUPS ˔ ݅(VBSE%VUZ

    *"."DDFTT"OBMZ[FS $POGJH $POUSPM5PXFS ˔ ݅*".*EFOUJUZ$FOUFS $MPVE5SBJM 4FDSFUT.BOBHFS
  3. ৽ػೳҰཡ  ൃදͰ͸ׂѪ 4FDVSJUZ)VC "844FDVSJUZ)VCͷ৽͍͠ൃݟͷڧԽΛൃද IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXOFXGJOEJOHFOSJDINFOUBXTTFDVSJUZ IVC "844FDVSJUZ)VCͷओཁͳμογϡϘʔυͷػೳڧԽΛൃ දIUUQTBXTBNB[PODPNBCPVUBXTXIBUT

    OFXEBTICPBSEFOIBODFNFOUTBXTTFDVSJUZ IVC "844FDVSJUZ)VCͷ৽͍͠தԝઃఆػೳͷൃද IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBXTTFDVSJUZIVCDFOUSBMDPOGJHVSBUJPO "844FDVSJUZ)VCͰηΩϡϦςΟ੍ޚΛΧελϚΠζͰ͖ ΔΑ͏ʹͳΓ·ͨ͠IUUQTBXTBNB[PODPNBCPVU BXTXIBUTOFXDVTUPNJ[FTFDVSJUZDPOUSPMT BXTTFDVSJUZIVC %FUFDUJWF "NB[PO%FUFDUJWF͕ *".ͷௐࠪΛൃද IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POEFUFDUJWFJOWFTUJHBUJPOTJBN "NB[PO%FUFDUJWF͸ɺ"NB[PO(VBSE%VUZ&$4ϥϯλΠϜ؂ࢹ ͷηΩϡϦςΟௐࠪΛαϙʔτ͠·͢ IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POEFUFDUJWFTFDVSJUZHVBSEEVUZFDT NPOJUPSJOH "NB[PO%FUFDUJWF͕ɺੜ੒ "*Λ࢖༻ͨ͠άϧʔϓͷ֓ཁͷݕࡧ ΛಋೖIUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POEFUFDUJWFHSPVQTVNNBSJFT HFOFSBUJWFBJ "NB[PO%FUFDUJWF͕ "NB[PO4FDVSJUZ-BLF͔ΒͷϩάऔಘΛα ϙʔτ͢ΔΑ͏ʹͳΓ·ͨ͠IUUQTBXTBNB[PODPNBCPVU BXTXIBUTOFXBNB[POEFUFDUJWFMPHSFUSJFWBM TFDVSJUZMBLF
  4. ৽ػೳҰཡ  ൃදͰ͸ׂѪ *OTQFDUPS "NB[PO*OTQFDUPS͸։ൃऀπʔϧͱ౷߹͢Δ͜ͱͰίϯςφΠϝ ʔδͷηΩϡϦςΟΛڧԽ͠·͢ IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POJOTQFDUPSJNBHFTFDVSJUZEFWFMPQFS UPPMT "NB[PO*OTQFDUPSͷ

    "NB[PO&$޲͚ΤʔδΣϯτϨε੬ऑੑ ධՁ͕ϓϨϏϡʔதIUUQTBXTBNB[PODPNBCPVU BXTXIBUTOFXBNB[POJOTQFDUPSBHFOUMFTT BTTFTTNFOUTFDQSFWJFX "NB[PO*OTQFDUPS͸ɺੜ੒ "*Λར༻ͨ͠म෮ʹΑΓ "84 -BNCEBίʔυεΩϟϯΛ֦ு͠·͢ IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POJOTQFDUPSBXTMBNCEBDPEF TDBOOJOH (VBSE%VUZ "84'BSHBUFΛؚΉ "NB[PO(VBSE%VUZ&$4ϥϯλΠϜϞχλϦϯάͷ ঺հIUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBNB[POHVBSEEVUZFDTSVOUJNFNPOJUPSJOHGBSHBUF "NB[PO(VBSE%VUZ͕ "NB[PO&$ͷϥϯλΠϜ؂ࢹΛαϙʔτ͢ΔΑ ͏ʹͳΓ·ͨ͠ ϓϨϏϡʔ IUUQTBXTBNB[PODPNBCPVU BXTXIBUTOFXBNB[POHVBSEEVUZSVOUJNFNPOJUPSJOH BNB[POFDQSFWJFX *"."DDFTT"OBMZ[FS *"."DDFTT"OBMZ[FS͸ɺࣗಈԽ͞Εͨਪ࿦Λར༻ͨ͠ΧελϜ ϙϦγʔ νΣοΫΛಋೖ͠·͢IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXJBNBDDFTTBOBMZ[FSDVTUPNQPMJDZDIFDL *"."DDFTT"OBMZ[FS͸ɺະ࢖༻ͷΞΫηεͷݕࠪΛ؆ૉԽ͠ɺ࠷খݶͷಛ ݖʹಋ͘Α͏ʹͳΓ·ͨ͠IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXJBNBDDFTTBOBMZ[FSJOTQFDUJOHVOVTFEBDDFTT
  5. ৽ػೳҰཡ  ൃදͰ͸ׂѪ $POGJH "84$POGJH͕ఆظతͳه࿥Λαϙʔτ͢ΔΑ͏ʹͳΓ·ͨ͠ IUUQTBXTBNB[PODPNBCPVUBXTXIBUTOFXBXTDPOGJH QFSJPEJDSFDPSEJOH "84$POGJH͕ "*Λ׆༻ͨ͠ੜ੒తͳࣗવݴޠΫΤϦΛ։࢝ ϓϨϏϡʔ

     IUUQTBXTBNB[PODPNBCPVUBXTXIBUTOFXBXTDPOGJH HFOFSBUJWFBJQPXFSFEOBUVSBMMBOHVBHFRVFSZJOHQSFWJFX $POUSPM5PXFS "84$POUSPM5PXFS͕σδλϧओݖཁ݅Λຬͨͨ͢Ίͷ ͷίϯτϩʔ ϧΛൃදIUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBXTDPOUSPMUPXFSDPOUSPMTEJHJUBMTPWFSFJHOUZ SFRVJSFNFOUT "1*Λ࢖༻ͯ͠ "84$POUSPM5PXFSϥϯσΟϯά κʔϯͷૢ࡞ΛࣗಈԽ ͢ΔIUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBVUPNBUFBXTDPOUSPMUPXFS[POFPQFSBUJPOTBQJT *".*EFOUJUZ$FOUFS "84"OBMZUJDT͸ɺ*".*EFOUJUZ$FOUFSΛ࢖༻ͯ͠αʔϏεؒͰͷϢʔβ ʔͷσʔλ ΞΫηεΛ؆ૉԽ͠·͢IUUQTBXTBNB[PODPNBCPVU BXTXIBUTOFXBXTBOBMZUJDTVTFSTEBUBBDDFTTJBN JEFOUJUZDFOUFS $MPVE5SBJM "84$MPVE5SBJM-BLFσʔλ͕ "NB[PO"UIFOBͰͷθϩ &5-෼ੳʹར༻ ՄೳʹIUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBXTDMPVEUSBJMMBLF[FSPFUMBOMZTJTBUIFOB 4FDSFUT.BOBHFS "844FDSFUT.BOBHFS͕γʔΫϨοτͷόονऔಘΛαϙʔτ͢ΔΑ͏ʹ ͳΓ·ͨ͠IUUQTBXTBNB[PODPNBCPVUBXTXIBUT OFXBXTTFDSFUTNBOBHFSCBUDISFUSJFWBMTFDSFUT
  6. ࢥͬͨ͜ͱͭ ˔ ηΩϡϦςΟ º ੜ੒"* ͕Ξπ͍ ˓ ΫΤϦΛੜ੒"*Ͱ࡞੒ $POGJH ɺ-BNCEBίʔυमਖ਼Λੜ੒"*ͰΞγετ

    *OTQFDUPS ͳͲ ˔ (VBSE%VUZ *OTQFDUPS৽ػೳ͋ͨΓ͸ఆ൪ ˓ (VBSE%VUZ&$4 'BSHBUF &$ϥϯλΠϜϞχλϦϯά ˞&$ϥϯλΠϜϞχλϦϯά͸ϓϨϏϡʔ ˓ *OTQFDUPS&$ΤʔδΣϯτϨε਍அ ϓϨϏϡʔ ɺ$*$%ύΠϓϥΠϯ૊ΈࠐΈ ˔ ΞΫηε؅ཧ͸ *".*EFOUJUZ$FOUFSਪ͠ ˓ ෼ੳܥαʔϏε΍4ͷΞΫηεΛ *".*EFOUJUZ$FOUFSͰ؅ཧ ˓ SF*OWFOU༧બམͪΞοϓσʔτ͕ଟ͔ͬͨ
  7. ৽͍͠தԝઃఆػೳ ˔ ϚϧνΞΧ΢ϯτ؀ڥͷ 4FDVSJUZ)VC౷੍͕௒ઈڧԽ͞Ε·ͨ͠ ˓ ίϯτϩʔϧແޮԽͷूத؅ཧ ˓ ΦϓτΠϯܗࣜͰίϯτϩʔϧ༗ޮԽ ˓ 06୯Ґͷίϯτϩʔϧ੍ޚ

    ຊ౰ʹཉ͔ͬͨ͠΋ͷ౓˒˒˒˒˒˒˒˒˒˒˒˒˒ [アップデート]AWS Security Hubの組織への展開がセキュリティ標準やコントロールなどを カスタマイズして設定できるようになりました! #AWSreInvent | DevelopersIO