Slide 1

Slide 1 text

@ken5scal, 2022/09/30 ͳͥLayerXͷηΩϡϦςΟͰ Softwareࢦ޲͕ॏࢹ͞Ε͍ͯΔ͔ LayerX CTOࣨ, Fintechࣄۀຊ෦

Slide 2

Slide 2 text

ࣗݾ঺հ • @ken5scal • LayerX: 2020/02 ~ • CTOࣨ / Fintechࣄۀ෦ • CTOࣨ: CTO഑ԼͰશࣾԣஅతͳηΩϡϦςΟɾγεςϜͷ։ ൃɾӡ༻ • Fintechࣄۀ෦: ෆಈ࢈ূ݊ͷখޱԽ • ݸਓ׆ಈʮSecureཱྀஂʯ • ΄΅िץʮ๩͍͠ਓͷͨΊͷηΩϡϦςΟɾΠϯςϦδΣϯεʯ • PodCastʮSecure Liaisonʯ

Slide 3

Slide 3 text

ࠓ೔ͷ͓࿩ • ͜ΕͷηΩϡϦςΟαΠυ https://tech.layerx.co.jp/entry/2022/07/27/090609 https://tech.layerx.co.jp/entry/2022/07/27/090609

Slide 4

Slide 4 text

No content

Slide 5

Slide 5 text

No content

Slide 6

Slide 6 text

45min/ਓ * Nਓ -> 10min

Slide 7

Slide 7 text

஥ؒΛ૿΍͢ ಉ͡ߟ͑ํ΋ͬͯ͘ΕΔ஥͕ؒ૿͑Δͱ͏Ε͍͠ͳ˒ ࠓ೔ͷΰʔϧ

Slide 8

Slide 8 text

CTOࣨͷ໾ׂͱืूཁ߲ • ໾ׂ • σδλϧܦࡁ׆ಈΛݎ࿚Խ͢Δ • શࣾతͳLayerXͷϓϩμΫτͷϙςϯγϟϧΛ࠷େԽ͢Δ • ืूཁ߲

Slide 9

Slide 9 text

CTOࣨͷ໾ׂͱืूཁ߲ • ໾ׂ • σδλϧܦࡁ׆ಈΛݎ࿚Խ͢Δ • શࣾతͳLayerXͷϓϩμΫτͷϙςϯγϟϧΛ࠷େԽ͢Δ • ืूཁ߲ɹʢڧ͘ιϑτ΢ΣΞͳϓϩμΫτ։ൃܦݧΛཁٻʣ

Slide 10

Slide 10 text

CTOࣨͷ࣮੷ • ্ྲྀʁܥ • վఆݸਓ৘ใอޢͳͲͷํରԠ • ֤छγεςϜؔ࿈ͷنఔ࡞੒ɾӡ༻ • ֤छݚम • γεςϜӡ༻ • ΦϯϘʔσΟϯάؔ܎࡞ۀͷࣗಈԽ • ΦϑϘʔσΟϯάͷࣗಈԽ • ॏཁΠϯϑϥͷશମߏ੒ɾ؂ࢹج൫ • ࣾ಺޲͚γεςϜͷೝূήʔτ΢ΣΠ • ࢖͏ݴޠ • ݴޠ: Golang, TypeScript • Iac: Terraform, CDK • IaaS: جຊAWS, ͨ·ʹGCP

Slide 11

Slide 11 text

Why?

Slide 12

Slide 12 text

ηΩϡϦςΟରԠΛSWԽ͢Δཧ༝͸৭ʑ͋Δ • SoftwareԽͷఆٛͬͯͳΜͩͱ͍͏ͷ͸ޙ೔ʹɻɻɻ • ࠶ݱੑ͕ڧ·Δ • ΤϏσϯεͷऔಘ͕༰қʹͳΔ • ࡞ۀՄೳͳ࣌ؒͷറΓ͕ͳ͘ͳΔ • ࿑ಇࢢ৔ͷڱ͍ݴޠʢ೔ຊޠʣʹґଘ͠ͳͯ͘Α͘ͳΔ • ࡉ͔͍৚݅ࣜΛӡ༻͠΍͘͢ͳΔ • ͳͲͳͲ https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/

Slide 13

Slide 13 text

ηΩϡϦςΟରԠΛSWԽ͢Δཧ༝͸৭ʑ͋Δ • SoftwareԽͷఆٛͬͯͳΜͩͱ͍͏ͷ͸ޙ೔ʹɻɻɻ • ࠶ݱੑ͕ڧ·Δ • ΤϏσϯεͷऔಘ͕༰қʹͳΔ • ࡞ۀՄೳͳ࣌ؒͷറΓ͕ͳ͘ͳΔ • ࿑ಇࢢ৔ͷڱ͍ݴޠʢ೔ຊޠʣʹґଘ͠ͳͯ͘Α͘ͳΔ • ࡉ͔͍৚݅ࣜΛӡ༻͠΍͘͢ͳΔ • ͳͲͳͲ https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/ ࡢࠓͷϓϩμΫτ։ൃ͔Βɺ Ͳ͏ͯ͠ιϑτ΢ΣΞԽΛਐΊͯΔ͔

Slide 14

Slide 14 text

ηΩϡΞͳϓϩμΫτͱݴ͑͹γϑτϨϑτ • ϏδωεతͳγϑτϨϑτ • ʮϦϦʔεͷεέδϡʔϧΛ๦͛ͳ͍Α͏ʹɺηΩϡϦ ςΟʹؔΘΔ޻ఔΛલ౗࣮ͯ͠͠ࢪ͢Δͱ͍͏֓೦ʯby NRIηΩϡΞ • ʮ։ൃϓϩηεͷՄೳͳݶΓૣظͷஈ֊ʹηΩϡϦςΟର ࡦΛҠಈͤ͞Δ͜ͱʯ by PaloAlto https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/

Slide 15

Slide 15 text

ηΩϡΞͳϓϩμΫτͱݴ͑͹γϑτϨϑτ • ϏδωεతͳγϑτϨϑτ • ʮϦϦʔεͷεέδϡʔϧΛ๦͛ͳ͍Α͏ʹɺηΩϡϦ ςΟʹؔΘΔ޻ఔΛલ౗࣮ͯ͠͠ࢪ͢Δͱ͍͏֓೦ʯby NRIηΩϡΞ • ʮ։ൃϓϩηεͷՄೳͳݶΓૣظͷஈ֊ʹηΩϡϦςΟର ࡦΛҠಈͤ͞Δ͜ͱʯ by PaloAlto https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left

Slide 16

Slide 16 text

ηΩϡΞͳϓϩμΫτͱݴ͑͹γϑτϨϑτ • ϏδωεతͳγϑτϨϑτ • ʮϦϦʔεͷεέδϡʔϧΛ๦͛ͳ͍Α͏ʹɺηΩϡϦςΟʹؔΘΔ޻ ఔΛલ౗࣮ͯ͠͠ࢪ͢Δͱ͍͏֓೦ʯby NRIηΩϡΞ • ʮ։ൃϓϩηεͷՄೳͳݶΓૣظͷஈ֊ʹηΩϡϦςΟରࡦΛҠಈͤ͞ Δ͜ͱʯ by PaloAlto • DevOpsతͳγϑτϨϑτ • ”he e ff orts of a DevOps team to guarantee application security at the earliest stages in the development lifecycle, as part of an organizational pattern known as DevSecOps” by aquasec https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/

Slide 17

Slide 17 text

ηΩϡΞͳϓϩμΫτͱݴ͑͹γϑτϨϑτ • ϏδωεతͳγϑτϨϑτ <- 2015೥ʹ͸͋ͬͨ • ʮϦϦʔεͷεέδϡʔϧΛ๦͛ͳ͍Α͏ʹɺηΩϡϦςΟʹؔΘΔ޻ఔΛલ౗ ࣮ͯ͠͠ࢪ͢Δͱ͍͏֓೦ʯby NRIηΩϡΞ • ʮ։ൃϓϩηεͷՄೳͳݶΓૣظͷஈ֊ʹηΩϡϦςΟରࡦΛҠಈͤ͞Δ͜ͱʯ by PaloAlto • DevOpsతͳγϑτϨϑτ<- ࠷ۙͷSWαϓϥΠνΣʔϯؔ܎ • ”he e ff orts of a DevOps team to guarantee application security at the earliest stages in the development lifecycle, as part of an organizational pattern known as DevSecOps” by auasec https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/

Slide 18

Slide 18 text

ηΩϡΞͳϓϩμΫτͱݴ͑͹γϑτϨϑτ • ϏδωεతͳγϑτϨϑτ <- 2015೥ʹ͸͋ͬͨ • ʮϦϦʔεͷεέδϡʔϧΛ๦͛ͳ͍Α͏ʹɺηΩϡϦςΟʹؔΘΔ޻ఔΛલ౗ ࣮ͯ͠͠ࢪ͢Δͱ͍͏֓೦ʯby NRIηΩϡΞ • ʮ։ൃϓϩηεͷՄೳͳݶΓૣظͷஈ֊ʹηΩϡϦςΟରࡦΛҠಈͤ͞Δ͜ͱʯ by PaloAlto • DevOpsతͳγϑτϨϑτ <- ࠷ۙͷSWαϓϥΠνΣʔϯؔ܎ • ”he e ff orts of a DevOps team to guarantee application security at the earliest stages in the development lifecycle, as part of an organizational pattern known as DevSecOps” by auasec https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/ ͭ·Γࠓ೔Ͱ͸ɺ ϓϩμΫτͷ Ϗδωεͱ࢓༷ͱ։ൃͱӡ༻શମͰ ʮγϑτϨϑτʯ͕ ཁٻ͞Ε͍ͯΔ

Slide 19

Slide 19 text

ϓϩμΫτͷαΠΫϧ Ϧαʔν + Ծઆ ༏ઌ౓ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ܁Γฦ͠ ܁Γฦ͠

Slide 20

Slide 20 text

ηΩϡϦςΟͷαΠΫϧ ϙϦγʔ ֬ೝɾ࡞੒ ϦεΫ ෼ੳ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ܁Γฦ͠

Slide 21

Slide 21 text

αΠΫϧ Ϧαʔν + Ծઆ ༏ઌ౓ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ܁Γฦ͠ ϙϦγʔ ֬ೝɾ࡞੒ ϦεΫ ෼ੳ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ܁Γฦ͠

Slide 22

Slide 22 text

αΠΫϧ Ϧαʔν + Ծઆ ༏ઌ౓ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ௒ߴස౓ ܁Γฦ͠ ϙϦγʔ ֬ೝɾ࡞੒ ϦεΫ ෼ੳ ઃܭ ࣮૷ ϦϦʔε ؍ଌɾܭଌ ܁Γฦ͠ ϞμϯͳCICDͳͲʹΑΓ ϓϩμΫτ։ൃ͸γεςϜԽ͞Ε ࠶ݱੑ͕ڧԽ -> ΑΓߴස౓ͳ มߋ͕Մೳʹͳͬͨɻ

Slide 23

Slide 23 text

ηΩϡϦςΟϚϯͷ൵ئ: ϓϩμΫτͷϦεΫʹ ϦΞϧλΠϜରԠ

Slide 24

Slide 24 text

(࠶ܝʣηΩϡϦςΟରԠΛSWԽ͢Δཧ༝͸৭ʑ͋Δ • SoftwareԽͷఆٛͬͯͳΜͩͱ͍͏ͷ͸ޙ೔ʹɻɻɻ • ࠶ݱੑ͕ڧ·Δ • ΤϏσϯεͷऔಘ͕༰қʹͳΔ • ࡞ۀՄೳͳ࣌ؒͷറΓ͕ͳ͘ͳΔ • ࿑ಇࢢ৔ͷڱ͍ݴޠʢ೔ຊޠʣʹґଘ͠ͳͯ͘Α͘ͳΔ • ࡉ͔͍৚݅ࣜΛӡ༻͠΍͘͢ͳΔ • ͳͲͳͲ https://www.paloaltonetworks.com/blog/2019/08/4-practical-steps-shift-left-security/?lang=ja https://www.nri-secure.co.jp/glossary/shift-left https://www.aquasec.com/cloud-native-academy/devsecops/shift-left-devops/ ͜ΕΒ͕ɺϓϩμΫτଆͰՄೳͰ͋ΔҎ্ɺ ηΩϡϦςΟଆ΋ಉ͡౔ඨʹ͕͋Βͳ͚Ε͹ Ӭଓతʹޙ௥͍ʹͳΔ

Slide 25

Slide 25 text

ʢ࠶ܝʣCTOࣨͷ໾ׂͱืूཁ߲ • ໾ׂ • σδλϧܦࡁ׆ಈΛݎ࿚Խ͢Δ • શࣾతͳLayerXͷϓϩμΫτͷϙςϯγϟϧΛ࠷େԽ͢Δ • ืूཁ߲ɹʢڧ͘ιϑτ΢ΣΞͳϓϩμΫτ։ൃܦݧΛཁٻʣ

Slide 26

Slide 26 text

ʢGoogleͷʣશηΩϡϦςΟΤϯδχΞ͸ίʔυԽΛ ஌͍ͬͯͳ͚Ε͹ͳΒͳ͍ɺྫ֎͸ͳ͍ɻ

Slide 27

Slide 27 text

஥ؒΛ૿΍͢ ಉ͡ߟ͑ํ΋ͬͯ͘ΕΔ஥͕ؒ૿͑Δͱ͏Ε͍͠ͳ˒ ͜͏͍ͬͨྖҬͷΠϕϯτɺษڧձɺΧϯϑΝϨϯε΁֤ ࣾ΋ͬͱηΩϡϦςΟਓࡐ࠾༻͠ʹ͍͖·ͤΜ͔ʁ

Slide 28

Slide 28 text

No content

Slide 29

Slide 29 text

ੋඇɺMeetyͰ ଓ͖Λ https://meety.net/matches/ SunJOdvBKMrT