Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティのお仕事: インターネット屋さん編 / LOCAL DEVELOPER DAY '...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
Yasunari Momoi
September 07, 2019
Technology
0
260
セキュリティのお仕事: インターネット屋さん編 / LOCAL DEVELOPER DAY '19 Security
LOCAL DEVELOPER DAY '19 / Security での資料です。
https://local.connpass.com/event/140890/
Yasunari Momoi
September 07, 2019
Tweet
Share
Other Decks in Technology
See All in Technology
Introduction to Bill One Development Engineer
sansan33
PRO
0
360
生成AI時代にこそ求められるSRE / SRE for Gen AI era
ymotongpoo
5
3.1k
セキュリティについて学ぶ会 / 2026 01 25 Takamatsu WordPress Meetup
rocketmartue
1
300
Red Hat OpenStack Services on OpenShift
tamemiya
0
100
Cosmos World Foundation Model Platform for Physical AI
takmin
0
870
Amazon S3 Vectorsを使って資格勉強用AIエージェントを構築してみた
usanchuu
3
450
顧客の言葉を、そのまま信じない勇気
yamatai1212
1
350
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
340
Introduction to Sansan, inc / Sansan Global Development Center, Inc.
sansan33
PRO
0
3k
制約が導く迷わない設計 〜 信頼性と運用性を両立するマイナンバー管理システムの実践 〜
bwkw
3
920
茨城の思い出を振り返る ~CDKのセキュリティを添えて~ / 20260201 Mitsutoshi Matsuo
shift_evolve
PRO
1
250
Azure Durable Functions で作った NL2SQL Agent の精度向上に取り組んだ話/jat08
thara0402
0
180
Featured
See All Featured
It's Worth the Effort
3n
188
29k
YesSQL, Process and Tooling at Scale
rocio
174
15k
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
38
2.7k
The Spectacular Lies of Maps
axbom
PRO
1
520
Taking LLMs out of the black box: A practical guide to human-in-the-loop distillation
inesmontani
PRO
3
2k
Discover your Explorer Soul
emna__ayadi
2
1.1k
brightonSEO & MeasureFest 2025 - Christian Goodrich - Winning strategies for Black Friday CRO & PPC
cargoodrich
3
100
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
The browser strikes back
jonoalderson
0
370
The SEO identity crisis: Don't let AI make you average
varn
0
240
Everyday Curiosity
cassininazir
0
130
My Coaching Mixtape
mlcsv
0
48
Transcript
ηΩϡϦςΟͷ͓ࣄ લઆ
ʮηΩϡϦςΟͷ͓ࣄʯ ͱฉ͍ͯʜ Πϝʔδ͢Δͷʁ
! "
ʮηΩϡϦςΟͷ͓ࣄʯ Πϝʔδྫ ఆ w ϕϯμ ϋʔυ ιϑτ w '8
*14 w 4BOECPY &NBJM w "OUJ7 &%3 w 4*&. w αʔϏεఏڙऀ w ϚωʔδυαʔϏε 40$ w ΫϥυαʔϏεఏڙଆ w "84 "[VSF w ։ൃ 4*FS w ݕࠪ ΞϓϦ w ࠪ w ΠϯςϦδΣϯε w ίϯαϧ ڭҭ
$4*35 γʔαʔτ ͬͱଟ͘ͷ৫ʹඞཁͳ ͯ͢ͷ৫ʹʁ ηΩϡϦςΟରԠͷ͓Ͱ͢
$4*35ͷ؆୯ͳઆ໌ w $PNQVUFS4FDVSJUZ*ODJEFOU3FTQPOTF5FBN w *ODJEFOUॏେࣄނɺॏେࣄނʹͳΓ͏Δࣄଶ w 3FTQPOTF5FBNରԠνʔϜ w ఆΊͨൣғͷΠϯγσϯτରԠΛߦ͏ w
֎ͷ࿈བྷ૭ޱͱͳΓɺదͳରԠΛ͢Δ w ফஂɺࣗܯஂɺ࣏ࣗձͷΑ͏ͳͷ
ηΩϡϦςΟͷ͓ࣄ Πϯλʔωοτ͞Μฤ גࣜձࣾΠϯλʔωοτΠχγΞςΟϒ ηΩϡϦςΟຊ෦ηΩϡϦςΟใ౷ׅࣨ ͍͢ͳΓNPNP!JJKBEKQ
ࣗݾհ w ͍͢ͳΓ w 5XJUUFS!TCH'BDFCPPLZNPNPJ w ։ൃɺηΩϡϦςΟ w Πϯλʔωοτɺαʔό w
ίϛϡχςΟ׆ಈɺษڧձ w ৯ͷɺϔϰΟϝλϧɺͶ͜
*OUFSOFU*OGSBTUSVDUVSF3FWJFX w **+ͷѲͨ͠ηΩϡϦςΟใ؍ଌ݁Ռɺ **+ͷηΩϡϦςΟରࡦ׆ಈΛ·ͱΊͯެද͢ Δ͜ͱͰɺΠϯλʔωοτ্ͷΠϯγσϯτ ൃੜঢ়گΛѲͯ͠Β͏ͨΊͷϨϙʔτɻ ݄ΑΓɺ࢛ظʹҰճൃߦɻ w ࠷৽൛7PM ݄ൃߦ
ɻτϐοΫ ϒϩοΫνΣʔϯٕज़Λϕʔεͱͨ͠ΞΠσ ϯςΟςΟཧɾྲྀ௨ͷಈղઆͱF4*.ɻ w 1%'൛Λ8FC͔ΒແྉͰμϯϩʔυՄೳɻ w ӳޠ൛͋Γ·͢ʂؤுͬͯ·͢ʂ w ʮ**+**3ʯͰݕࡧʂ
**+4FDVSJUZ%JBSZ w **+άϧʔϓͷ$4*35 νʔϜɺ**+4&$5ʹΑ Δใൃ৴αΠτ w ಛఆͷࣄʹؔ͢Δৄ ࡉͳௐࠪݚڀɺϋχʔ ϙοτΫϩʔϥʔͳ Ͳಠࣗͷ؍ଌ݁ՌΛج
ʹͨ͠ใΛఏڙ w IUUQTTFDUJJKBEKQ
8J[4BGF4FDVSJUZ4JHOBM w **+͕ఏڙ͢ΔηΩϡϦςΟ ࣄۀʮXJ[4BGFʯʹ͓͚Δ ࣮ࡍͷ߈ܸࣄҊͷ؍ଌ ใɺͦΕΒͷੳ݁ՌΛ جʹͨ͠ใൃ৴αΠτ w ηΩϡϦςΟΦϖϨʔγϣ ϯηϯλʔͷൣͰཏత
ͳใΛجʹੳͨ͠༰ ΛλΠϜϦʔʹൃ৴ w IUUQTXJ[TBGFJJKBEKQ
ຊͷ͓ ηΩϡϦςΟ૯߹֨ಆٕ
ηΩϡϦςΟͷ͓ࣄ
ηΩϡϦςΟ෯͍ w ηΩϡϦςΟؔͷࣄͱ͍͏ͱʁ w ಄ʹʮαΠόʔʯ͕͍ͭͨΒͲ͏͔ʁ w ࠓ$4*35 γʔαʔτ ʹযΛͯ·͢ w
40$ΛؚΜͰ͍ͨΓ͠·͢ w ηΩϡϦςΟରԠ৫
$4*35ͷ׆ಈ w $4*35ͷ׆ಈશൠ w ʮඇৗ࣌ʯͱʮฏ࣌ʯ +1$&35$$ʮ$4*35ΨΠυʯΑΓ
$4*35͕ఏڙ͢Δػೳ ηΩϡϦςΟରԠ৫ͷػೳʹΑΔྨ (ISOG-JʮηΩϡϦςΟରԠ৫ͷڭՊॻ v2.1ʯ) ηΩϡϦςΟରԠ৫ӡӦ ϦΞϧλΠϜΞφϦγε (ଈ࣌ੳ) σΟʔϓΞφϦγε (ਂ۷ੳ) ΠϯγσϯτରԠ
ηΩϡϦςΟରԠঢ়گͷஅͱධՁ ڴҖใͷऩू͓ΑͼੳͱධՁ ηΩϡϦςΟରԠγεςϜӡ༻ɾ։ൃ ෦౷੍ɾ෦ෆਖ਼ରԠࢧԉ ֎෦৫ͱͷੵۃత࿈ܞ
$4*35ʹؔΘΔਓʑ
$4*35৫ʹਖ਼ղͳ͍ w $4*35ػೳͷ࣮ํ๏༷ʑ w ࣮มԽ͢Δ w ৫ͷঢ়گɺਓࡐɺ༧ࢉ w $4*35ͷߏஙϑΣʔζ ن
w ੈؒͷ +1$&35$$ʮ$4*35ΨΠυʯΑΓ
ηΩϡϦςΟରԠͷׂҰཡ
$4*35ਓࡐͷఆٛͱ֬อ w $4*35ʹٻΊΒΕΔׂͱਓࡐʹΑΔྨ /$"ʮ$4*35ਓࡐͷఆٛͱ֬อ7FSʯ w 1P$ 1PJOUPG$POUBDU w
ϦʔΨϧΞυόΠβʔ w ϊʔςΟϑΟέʔγϣϯ୲ w Ϧαʔνϟʔ w ΩϡϨʔλʔ w ੬ऑੑஅ࢜ w ηϧϑΞηεϝϯτ୲ w ιϦϡʔγϣϯΞφϦετ w ίϚϯμʔ w ΠϯγσϯτϚωʔδϟʔ w Πϯγσϯτϋϯυϥʔ w ΠϯϕεςΟήʔλʔ w τϦΞʔδ୲ w ϑΥϨϯδοΫ୲ w ڭҭ୲
None
None
None
None
ׂ୲ w ΈΜͳͰࣄʹ͋ͨΔɺׂ୲ w εʔύʔϚϯ͍ͳ͍ w Ծʹ͍ͨͱͯ࣌ؒ͠ʹݶΓ͕͋Δ w ୭͔͕ൈ͚͚ͨͩͰ่յͯ͠ࠔΔ
࣮ࡍʹ͍Ζ͍Ζͳਓ͕͍·͢ w ֎͔Βݟ͍͑͢ਓͨͪ w 1P$ɺϦαʔνϟʔɺτϨʔφʔ w Τʔε ΞφϦετɺΤόϯδΣϦετ w ݟ͑ʹ͍͘ਓͨͪ
w ΞφϦετɺௐࠪνʔϜ w ΦϖϨʔλʔɺج൫։ൃɺӡ༻ɺνʔϜӡӦ w ใγεςϜɺཧɺࠪ
ηΩϡϦςΟͷ͓ࣄΛ͢Δ
ηΩϡϦςΟͷࣄʹͭ͘ʁ w ෯ׂ͍ͷͲΕ͔Λ୲͑Δ w ઐεΩϧΛຏ͘ ྖҬ*** *7 w ྖҬ*
**ʜʁ
*5ܕਓࡐ w ͋ΔઐʹಛԽͨ͠ਓ*ܕਓࡐ w ηΩϡϦςΟۀքɺઈରগͳ͍ w ҰൠاۀͰϚον͠ͳ͍ʁ w *5ܕਓࡐ w
ݱۀͷεΩϧΛϕʔεʹ͢Δ w ηΩϡϦςΟΛֶ͘Ϳ w ηΩϡϦςΟͷΛ۷ΓԼ͛Δ ISOG-JʮηΩϡϦςΟରԠ৫ͷڭՊॻ v2.1ʯ
νʔϜϝϯόʔͷεΩϧηοτྫ
ࢲ͕৮Ε͖ͯͨ͜ͱ
ܭࢉػՊֶʹ৮ΕΔ w جૅతͳֶ w σʔλߏͱΞϧΰϦζϜ w ܭࢉྔͱ͔ w ௨৴ωοτϫʔΫͷཧ
Πϯλʔωοτͱ5$1*1 w ωοτϫʔΫΛ͏ w ෳͷϚγϯͰࢄॲཧ w 04*֊ͱ͔ w &NBJM /FU/FXT
w 8FCग़ݱ
04αʔόʹ৮ΕΔ w ϑϦʔιϑτ w Φʔϓϯιʔε w #4% .*/*9 -JOVY w
98JOEPX w 4IFMM 1FSM 5DM5L
αʔόߏஙӡ༻Λͯ͠ΈΔ w ֶੜڞ༻ͷιϑτΣΞΛཧ w ֶੜ༻αʔόʹྖҬͱݖݶΛΒͬͨ w ݚڀࣨωοτϫʔΫΛߏஙɺӡ༻ w %/4 &NBJM
8FCͳͲΛߏஙɺӡ༻
ϓϩάϥϜͷษڧΛ͢Δ w େ͖ͳϓϩάϥϜΛॻͨ͘Ίͷཧ۶ΛֶͿ w ߏԽɺΦϒδΣΫτࢦ w όάΛ͋·Γग़͞ͳ͍ͨΊͷํ๏ w 5SBQT1JUGBMMT w
੬ऑੑʹͭͳ͕Δ
ݚڀͱ͍͏ͷͱग़ձ͏ w 8*%&ݚڀձ w ଞେֶاۀͷ͍͢͝ਓͨͪʹձ͏ w ݚڀͷ·Ͷ͝ͱΛ͢Δ
$"%ͷ։ൃձࣾʹब৬ w ۀࣝ ͋ͨΓ·͑ w $"%ͷσʔλߏΛཧղ͢Δ w ܗঢ়σʔλ τϙϩδʔ
w ΠϯλʔωοτΛͭͳ͙ w ωοτϫʔΫҕһձΛ࡞Δ
Πϯλʔωοτͷձࣾʹब৬ w ηΩϡϦςΟͷ෦ॺͰ͍Ζ͍Ζ࡞Δ w αʔϏεͷόοΫΤϯυɺ*%4 w ෆ۩߹ٻͰ͍Ζ͍ΖֶͿ w ৽͘͠ग़͖ͯͨͷΛ͏ௐΔ w
ษڧձ׆ಈͷࢧԉ
ηΩϡϦςΟʹؔΘΔ
։ൃͰֶΜͩ͜ͱ w ۀੳɺཁ݅ఆٛɺઃܭ w ͷղɺ୯७ԽɺఆࣜԽ w ਓֶؒɺ৺ཧֶͳͲͷॳา w ωοτϫʔΫ04ͷ͘͠Έ w
τϥϒϧγϡʔτେࣄ w ఔཧɺνʔϜӡӦ
ηΩϡϦςΟʜ͍ w ใཧɺ҉߸ w ౷ܭֶɺࣾձֶ w ۓٸରԠɺࡂରԠɺࡂ w ๏ɺӴ w
ֶशɺڭҭɺ৺ཧֶ w ҆શֶɺࣦഊֶ
։ൃऀͳΒͰ͖Δ͜ͱ w ৽͍͠ڥπʔϧͷςετɺಋೖ w σόοάɺτϥϒϧγϡʔτ w ϓϩτλΠϐϯά w ࣗಈԽ w
੬ऑੑใΛಡΈղ͘ w ݪཧɺ1P$
ಛʹࠔ͍ͬͯΔ͜ͱ
ӳޠͱֶ
ֶཧֶͷجૅ w ใཧʹͨ͘͞Μֶ͕ʜ w ৽͍͠Λཧղ͢Δʹֶ͕ʜ w ػցֶश %FFQ-FBSOJOH "* w
#MPDL$IBJO #JUDPJO w ҉߸·ΘΓ
'*345"OOVBM$POGFSFODF
'*345࣍૯ձʹߦͬͯ·ͨ͠ w '*345ͱʁ w '*345JTUIFHMPCBM'PSVNPG *ODJEFOU3FTQPOTFBOE 4FDVSJUZ5FBNT w ੈքதͷηΩϡϦςΟʹؔΘΔ ৫͕ू·ΔϑΥʔϥϜ
w ʹҰɺେنͳΧϯϑΝϨϯ ε͕։࠵͞ΕΔ ࠓճ https://www.first.org
'*345"OOVBM$POGFSFODF հ
'*345"OOVBM$POGFSFODF #BORVFU *DF#SFBLFS /FUXPSLJOH w *DF#SFBLFS w ॳͷॳࢀՃऀ͚ձ߹ޙ w $POGFSFODF#BORVFU
w ఔਅΜதΜͷ w /FUXPSLJOH#SFBL w ྑ͘ͳΔͨΊͷ࣌ؒ
'*345"OOVBM$POGFSFODF "OOVBM(FOFSBM.FFUJOH w 'PSVNͷ࣍૯ձ w һબग़ w ׆ಈใࠂ w ձܭใࠂ
w نมߋ
'*345"OOVBM$POGFSFODF &WFOUT w '*345'PPUCBMM$VQ w 1IPUP8BML w #:# #SJOH:PVS#PUUMF
None
ͦͷଞηΩϡϦςΟؔͷ৫ ࢲ͕͍ؔͯ͠Δͷ w /$" ຊγʔαʔτڠٞձ w *4"$ ผͷຽؒ৫ͷू·Γ
w *40(+ ࣄۀऀͷू·Γ w ଞɺͱͯͨ͘͞Μ͋Γ·͢
ຊͷ͓ ηΩϡϦςΟ૯߹֨ಆٕ
·ͱΊ ηΩϡϦςΟ͍ ࣄଶৗʹมԽ͢Δ มԽʹڧ͍ࣗΛ࡞Δ جૅେࣄ
2"
࣭ٙ w શମΛ௨ͯ͠ɺͳΜͰฉ͍͍ͯͩ͘͞ w ग़ͯ͜ͳ͔ͬͨͰେৎͰ͢ ଟ͘ͷࣸਅఏڙ: ͨʹ͌͞Μ