Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
やはりタグ。タグは全てを解決する
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
Kengo Suzuki
November 04, 2021
Technology
9.7k
2
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
やはりタグ。タグは全てを解決する
Kengo Suzuki
November 04, 2021
More Decks by Kengo Suzuki
See All by Kengo Suzuki
男(監査)はつらいよ - Policy as CodeからAIエージェントへ
ken5scal
5
1.1k
AI時代の大規模データ活用とセキュリティ戦略
ken5scal
1
520
Pwned Labsのすゝめ
ken5scal
2
1.2k
信頼性に挑む中で拡張できる・得られる1人のスキルセットとは?
ken5scal
3
1.3k
Eventual Detection Engineering
ken5scal
0
2.9k
脆弱性対応をこの先生きのこるには
ken5scal
0
1.7k
LayerXとMDMのリスク評価と年次対応の実例(公開版)
ken5scal
2
1.5k
AWSだ! Google Cloudだ! Azureだ! 認証連携だ!
ken5scal
9
2.6k
適応し続けるプロダクトとセキュリティ
ken5scal
5
2.5k
Other Decks in Technology
See All in Technology
AIっぽい文章を採点して人間らしく直すアプリを作ってみた
yama3133
2
200
Claude Code の Sandbox 機能を Anthropic Sandbox Runtime(srt) で試そう!/lets-play-anthropic-sandbox-runtime
tomoki10
1
630
なぜ Platform Engineering の土台に Kubernetes を選ぶのか
r4ynode
2
650
Kiroで書いた 設計書 が AI レビューの 採点基準 になる
ezaki
0
120
Claude Codeをどのように キャッチアップしているか
oikon48
13
8.3k
RAG を使わないという選択肢
tatsutaka
1
250
LayerXにおけるセキュリティ管理の現在地と次の一手
tosho
0
220
Lightning近況報告
kozy4324
0
120
機械学習を「社会実装」するということ 2026年夏版 / Social Implementation of Machine Learning June 2026 Version
moepy_stats
6
2.4k
脆弱性対応、どこで線を引くか
rymiyamoto
1
410
Bucharest Tech Week 2026 - Guardians of the Cloud-Native Galaxy
edeandrea
PRO
0
100
あなたの知らないPDFのアクセシビリティ
lycorptech_jp
PRO
0
200
Featured
See All Featured
How to Ace a Technical Interview
jacobian
281
24k
The browser strikes back
jonoalderson
0
1.3k
Building Flexible Design Systems
yeseniaperezcruz
330
40k
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
170
Side Projects
sachag
455
43k
The Curse of the Amulet
leimatthew05
1
13k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
254
22k
Leading Effective Engineering Teams in the AI Era
addyosmani
9
2.1k
Documentation Writing (for coders)
carmenintech
77
5.4k
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
200
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
25
2k
A Soul's Torment
seathinner
6
2.9k
Transcript
ΓλάɹλάશͯΛղܾ͢Δ 1 BXTEFWEBZ
໊લླݚޗ !LFOTDBM ॴଐ -BZFS9גࣜձࣾ$50ࣨ ࡾҪ࢈σδλϧΞηοτɾϚωδϝϯτग़
དྷྺ ূ͚݊.BOBHFE4FDVSJUZ4FSWJDFɺՈܭɾΫϥυձܭɺূ݊ձࣾ ݸਓͷ׆ಈ ಉਓʮ4FDVSFཱྀஂʯʹͯ1PEDBTUʮ4FDVSF-JBJTPOʯಉਓࢽ࡞ िץʮ͍͠ਓͷͨΊͷηΩϡϦςΟɾΠϯςϦδΣϯεʯൃߦ 1PE$BTUʮ4FDVSF-JBJTPOʯΛʢ΄΅ʣ8FFLMZͰϦϦʔε ॻ੶ 0`3FJMMZʮ;FSP5SVTU/FUXPSLʯ༁ ΠϯϓϨε3%ʮΞΠσϯςΟςΟͩΕͷͷʁ)ZQFSMFEHFS*OEZ"SJFTͰ࣮ݱ͢ΔࢄΞΠσϯςΟςΟʯஶ࡞ ॴଐઌհࣗݾհ 2
Ϧετ Ϧετ Ϧετ Ϧετͷڧௐจࣈ Ϧετ
ݟग़͠ 3
ϒϩοΫνΣʔϯͷձࣾ Ͱͳ͍Ͱ͢ 4 IUUQTOPUFDPNGVLLZZOOGFECD
ॴଐઌͦͷᶃ 5
Ϧετ Ϧετ Ϧετ Ϧετͷڧௐจࣈ Ϧετ
ݟग़͠ 6
Ϧετ Ϧετ Ϧετ Ϧετͷڧௐจࣈ Ϧετ
ݟग़͠ 7
ॴଐઌͦͷᶄ 8
ॴଐઌͦͷᶄ 9
ॴଐઌͦͷᶄ 10
ॴଐઌͦͷᶄ 11
ຊͷ͓ 12 $50ࣨࠎΤϯδχΞ
ຊͷ͓ 13 $50ࣨࠎΤϯδχΞ ࢿ࢈ཧ
ຊͷ͓ 14 $50ࣨࠎΤϯδχΞ ࢿ࢈ཧ "84
ຊͷ͓ 15 $50ࣨࠎΤϯδχΞ ࢿ࢈ཧ "84 λά
ຊͷ͓ 16 $50ࣨࠎΤϯδχΞ ࢿ࢈ཧ "84 λά
ຊͷ͓ 17 $50ࣨࠎΤϯδχΞ ࢿ࢈ཧ "84 λά
͢͜ͱ ࣾͷλάཧͷมભ ͞ͳ͍͜ͱ ࣾͷλάΛ׆༻ͨ͠ӡ༻ ͞ͳ͍͜ͱ 18
8IZλάཧ ࣾͷλάཧ 5BHWFS 5BHWFS 5BHWFS
5BHWFS ະདྷͷʣ ΞδΣϯμ 19
8IZλάཧ 20
ʢ͍͖ͳΓઢʣθϩτϥετ 21
ୈࡾͷࢦɺθϩτϥετͷ֓೦ ɺอޢରͷγεςϜͱσʔλͷ ৫తՁʹ͋Θͤͯద༻͢Δඞཁ͕͋ Δͱ͍͏͜ͱͰ͢ 22 θϩτϥετΞʔΩςΫνϟ"84ͷࢹ
ୈࡾͷࢦɺθϩτϥετͷ֓೦ ɺอޢରͷγεςϜͱσʔλͷ ৫తՁʹ͋Θͤͯద༻͢Δඞཁ͕͋ Δͱ͍͏͜ͱͰ͢ 23 θϩτϥετΞʔΩςΫνϟ"84ͷࢹ อޢରͷ γεςϜͱσʔλʹ͍ͭͯ ԿΘ͔ΒΜ߹ʁ
ࢿ࢈ཧ ༧࣮ཧ ΞΫηεཧ ʢฏ࣌ͷʣϦεΫཧ ΠϯγσϯτରԠ
ࣗಈԽ ର͕طͰͳ͍ͱͰ͖ͳ͍͜ͱ 24
UPNPWFUP;5" BOFOUFSQSJTFNVTUIBWFB TZTUFNUPEJTDPWFSBOESFDPSEQIZTJDBMBOE WJSUVBMBTTFUTUPDSFBUFBVTBCMFJOWFOUPSZ /*4541ʮθϩτϥετɾΞʔΩςΫνϟʯ 25
֤Ϧιʔεʹ༩͞Εͨϝλσʔ λ ֤छӡ༻ʹ͓͚ΔඞཁෆՄܽͳࢀ রઌσʔλ ৫ಛ༗ͷϦιʔε*EFOUJUZΛߏ ங͢Δ$MBJN "84ͷλάͱʁ
26 ͜ͷ ڥͰΘΕ·͢ ͷཧऀ 43&νʔϜͰ͢ ܦӦཧ෦ͷ ͓ࡒ͔͍ͭ·͢ ػີใ ͔͍͋ͭ·͢ %9αʔϏεͰ ΘΕ·͢ EFWEYFDͱਃ͠·͢
֤Ϧιʔεʹ༩͞Εͨϝλσʔ λ ֤छӡ༻ʹ͓͚ΔඞཁෆՄܽͳࢀ রઌσʔλ ৫ಛ༗ͷϦιʔε*EFOUJUZΛߏ ங͢Δ$MBJN "84ͷλάͱʁ
27 ͜ͷ ڥͰΘΕ·͢ ͷཧऀ 43&νʔϜͰ͢ ܦӦཧ෦ͷ ͓ࡒ͔͍ͭ·͢ ػີใ ͔͍͋ͭ·͢ %9αʔϏεͰ ΘΕ·͢ EFWEYFDͱਃ͠·͢
αʔόʔʹՍۭͷσʔλΛ༩Ͱ͖ΔΑ͏ʹͳͬͨ ʮໝͱ͍͏໊ͷ૾ྗ͕ϗϞɾαϐΤϯεΛਐԽͤͨ͞ʯ ͨ͘͞Μ͚ͭΒΕΔʢd Ωʔɾͷࣗ༝͕ߴ͍ʢʙ VOJDPEFจࣈɺDBTFTFOTJUJWF
ه߸ར༻Խʣ ϫʔΫϩʔυͷಈ࡞ʹతͳӨڹΛ༩͑Δ͜ͱͳ͘ӡ༻Ͱ͖Δ 71$ͷ/BNFλάʜ Γ·ͤΜͶʜ "1*ཧͰ͖Δ σʔλΛ࣮ࡍͷϦιʔεʹࣄલຒΊࠐΜ্ͩͰɺࢿ࢈ཧ%#ΤΫηϧΛิͰ͖Δ ٯํՄ ཧऀʹΑΔ౷੍Ͱ͖Δ λά͍͢͝ 28
λά͔͠উͨΜ 29
ࣾͷ 30
5BH7FS 31
#$ίϯαϧࣄۀ͕ϝΠϯͩͬͨͨΊɺ۩ମతͳظؒݶఆతͳϫʔ Ϋϩʔυ͔͠ͳ͔ͬͨ 1P$ϓϩδΣΫτʹ͏ظతͳใࢿ࢈͔͠ͳ͔ͬͨʢ"84্ Ͱʣ ΠϯϑϥతඋΛ̎ਓͰ࣮ࢪ ΏΔʙ͘ᯂΑΓ࢝ΊΑ
ʢӨڹͳ͍͠ʣΨϯΨϯ͍͜͏ͥ 5BHWFS 32
ମ੍ ੲ 33
ࢀߟจݙY
ϕεϓϥ $BTFTFOTJUJWF ϦιʔεͷΞΫηείϯτϩʔϧ λάཧͷࣗಈԽ λάগͳ͍ΑΓɺଟ͍ํ͕ϕλʔ
ओʹλάΧςΰϦΛࢀর "845BHHJOH4USBUFHJFT 35 IUUQTEBXTTUBUJDDPNBXTBOTXFST"84@5BHHJOH@4USBUFHJFTQEG
5BHHJOH#FTU1SBDUJDFT "845BHHJOH4USBUFHJFTΛΑ ΓৄࡉԽ IUUQTEPDTBXTBNB[PODPNXIJUFQBQFSTMBUFTUUBHHJOHCFTUQSBDUJDFTJOUSPEVDUJPOUBHHJOHVTFDBTFTIUNM
Ϧετ Ϧετ Ϧετ Ϧετͷڧௐจࣈ Ϧετ
37 ͦΜͳʹλάͷʹͭΊ͜·ΜͰΑ͘ͳ͍ʜ
ࣾಠࣗΧελϚΠζᶃ 38 ݴͬͯΔ͜ͱ͕ҧ͏ͷͰɺ ʮେখΛ݉ͶΔʯͱ͍͏͜ͱͰ ޙ͔Βม͑Δ͜ͱ্Ͱ͚ͭ·͘Δ͜ͱʹͨ͠ɻ λάมߋͰ͋ΕӨڹͳ͘ɼ ͔ͭɺݱࡏͷ༧࣮ཧͰͦ͜·ͰλάΛ׆༻ͯ͠ͳ͍ͨΊ
5BHHJOH#FTU1SBDUJDFT "845BHHJOH4USBUFHJFTΛΑ ΓৄࡉԽ IUUQTEPDTBXTBNB[PODPNXIJUFQBQFSTMBUFTUUBHHJOHCFTUQSBDUJDFTJOUSPEVDUJPOUBHHJOHVTFDBTFTIUNM ϏϛϣʔʹݴͬͯΔ͜ͱ͕ҧ͏ͷͰ 5BHHJOH#FTU1SBDUJDFTͷߟ͑ํΛجʹɺ 5BHHJOH4USBUFHJFTͷ࣮ํ๏ΛϝΠϯʹ࣮
λά໋໊نଇέόϒέʔεεωʔΫέʔε ΠϯϕϯτϦͬͯ%#ͩ͠ɺ͡Ό͋εωʔΫέʔεͩΑͶ 5FSSBGPSNͷϕεϓϥΞϯείͩ͠ɻ Ϧιʔε໊نଇ \FOWJSPONFOU^\TFSWJDF@JE^\Ϧιʔεಛ༗ͷ^
4"-#ʹ͍ͭͯOBNFλάͷΑ͏ͳޠ۟ؒΛ@ͳܗࣜͩ ͱͰ͖ͳ͍ͷͰɺͰͭͳ͛Δɻ ࣾಠࣗΧελϚΠζᶄ 40 IUUQTXXXUFSSBGPSNCFTUQSBDUJDFTDPNOBNJOH
ࣾಠࣗΧελϚΠζᶅ 41 λάཧΛ ड͚࣋ͭ
ࣾಠࣗΧελϚΠζᶆ
43 λά໊ ΧςΰϦ ඞਢ ྫ name Ϧιʔε໊ ◦ ${service_id}.${environment}.${service_role}.$ {name}
service_id ΞϓϦɾαʔϏεID ◦ dx service_role αʔϏεͷׂ ◦ web, db, log_storage cluster ecs Ϋϥελʔͱ͔ environment ڥ ◦ dev, stg, prd version owner ઌ ◦ cost_center ◦ xxx, yyy, layerx (ސ٬໊) project ϓϩδΣΫτ໊ ◦ customer ಛఆͷ͓٬༷͚༻ Τϯϓϥϓϥϯʹ͓٬༷ઐ༻αʔόΛఏڙ ͠·͢...తͳͱ͖ con fi dentiality ػີ߹͍ ◦ managed_by ͲͷIaC͔ ◦ manual(σϑΥϧτ), terraform, cfn compliance ن੍ɾίϯϓϥ PII, [pii, iso27002]
$PNNFSDJBMEBUBDMBTTJ fi DBUJPO 4FOTJUJWF $PO fi EFOUJBM 1SJWBUF
1VCMJD IUUQTEPDTNJDSPTPGUDPNKBKQ TFDVSJUZVQEBUFT QMBOOJOHBOEJNQMFNFOUBUJPOHVJEF $PO fi EFOUJBMJUZʹؔ͢Δิ 44
5BH7FS 45
ࣄۀ෦੍ Ӭଓతͳใࢿ࢈͕ൃੜͨ͠ ΠϯϑϥతඋΛ͢Δ̎ਓࣄۀ෦ʹݣ 5BHWFS 46
ମ੍ /PX 47
ڞ༗ձ 48
DPTU@DFOUFSͷʹ֤ࣄۀ෦͕ೖΔΑ͏ʹ OBNFλάΛഇࢭ λά໊ MBZFSYλά໊ ͷQSF fi YΛഇࢭ
EJGGGSPNWFS 49
5BH7FS 50
5FSSBGPSNQSPWJEFSW $50ަ *4.4औಘ։࢝ 5BHW 51
ମ੍ /PX 52
ڞ༗ձ 53
5FSSBGPSN"841SPWJEFSWͷϦϦʔε 54 provider "aws" { region = var.regio n default_tags
{ tags = var.default_tags } } resource "aws_kms_key" "cloudtrail" { description = "key to encrypt/decrypt cloudtrail " tags = { service_role = var.service_role.km s } } resource "aws_kms_key" "cloudtrail" { description = "key to encrypt/decrypt cloudtrail " tags = { environment = pr d service_role = var.service_role.km s project = guardrai l service_id = guardrai l cost_center = layer X Owner = sr e managed_by = terrafor m github_repository - guardrai l } } EFGBVMU@UBHT͍͜͞ʔ
HJUIVC@SFQPTJUPSZՃ ใ۠ͷݟ͠ લTFOTJUJWF DPO fi EFOUJBM QSJWBUF
QSPQSJFUBSZ QVCMJD ޙDPO fi EFOUJBM QSJWBUF QVCMJD TFSWJDF@SPMFΛ࣮ଶͰ͋ΔϦιʔεͷཻʹ͋ΘͤΔ ྫTFDSFUTNBOBHFSWBVMU EJGGGSPNWFS 55
ࠓޙ 56
λά౷੍ λάFWFSZXIFSF λάཧͷཧ λάͷΞΫηεཧΛ៛ີԽ λάΛͬͨ"#"$ʁ
ਖ਼͋·ΓϝϦοτΛײͯ͡ͳ͍ʜ 5BHW GVUVSF 57
࠾༻ͯ͠·͢ ݸਓΧδϡΞϧ໘ஊ͔ΒͰ 0, 58
59 ࠾༻ͪ͜Β IUUQTIFSQDBSFFSTWMBZFSY ΧδϡΞϧ໘ஊͪ͜Β IUUQTNFFUZOFUBSUJDMFTUXXKK
60 IUUQTNFFUZOFUNBUDIFTK"C ff [W-RK/B IUUQTIFSQDBSFFSTWMBZFSYZSR)(513Y
5IBOLZPV 61