Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティチェックシートの話 / Security Check Sheet
Search
mnuma
September 11, 2025
0
9
セキュリティチェックシートの話 / Security Check Sheet
mnuma
September 11, 2025
Tweet
Share
More Decks by mnuma
See All by mnuma
Datadogで始めるユーザー行動分析 / Getting Started with User Behavior Analysis Using Datadog
mnuma
0
56
自動テストについて / Automated Testing
mnuma
0
220
Kubernetesの自動アップグレードについて / Upgrading GKE cluster
mnuma
0
200
AWS Auroraのスロークエリを Datadogで扱うまで / How to handle slow_queries_logs in AWS Aurora with Datadog
mnuma
0
900
Googleに学ぶDesign Docs / Learn from Google on Design Docs
mnuma
0
160
Observabilityを実践する / Pragmatic observability
mnuma
2
220
Kubernetes Case Studies #1@Makuake KubeCon NA 2019 Recap
mnuma
0
160
カオスエンジニアリングについてヤホーで調べてきました / Enter the chaos engineering
mnuma
0
110
Chaos Engineering 現状把握 / History Of Chaos Engineering
mnuma
0
350
Featured
See All Featured
How STYLIGHT went responsive
nonsquared
100
5.9k
How to train your dragon (web standard)
notwaldorf
97
6.3k
Bash Introduction
62gerente
615
210k
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
132
19k
Bootstrapping a Software Product
garrettdimon
PRO
307
110k
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
1.7k
Balancing Empowerment & Direction
lara
5
710
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
658
61k
Building an army of robots
kneath
306
46k
The Psychology of Web Performance [Beyond Tellerrand 2023]
tammyeverts
49
3.2k
Context Engineering - Making Every Token Count
addyosmani
8
330
Statistics for Hackers
jakevdp
799
220k
Transcript
>»½õúö³ñ·ó¿·üø~ û? 2025/09/09 TDU CySec ç«_ LT
¯?}Ï CySec ×o üßn Web ¸ó¸û² / SRE (Site Reliability
Engineering ÿ {ý~ / ÷ýÀ¿ø»½úö³{·¿»sx|[t ÿj_yý²sv¹¿üø²ó÷wÝtvt~y
»½õúö³ñ·ó¿·üø »½õúö³ñ·ó¿·üøx : ÿÕOm|Û±vt»SaaS ´ôüû^/f~±~þ¯~î_y [Excel ´Word _w¯~»½õúö³~þâwþ¯~owr»sx|[t ôüû´SaaS ~Y}f{{|ß
https://smarthr.jp/about/security/
»½õúö³ñ·ó¿·üø Qiita »½õúö³üñ·ó¿·üøxtv×x~¶ÛÛ - Qiita How do you like »½õúö³üñ·ó¿·üø
? ³ü³³³³³³¹¹¹ü³1³ ¹¹ü1³ü³1³¹¹¹ü ÿºü÷ûóÀö1__ïu¿º »½õúö³üñ·ó¿& Qiita u³»½õúö³ñ·ó¿·üø²þtvtvÿº|q}vz~wo}Þ²þt& »½õúö³ñ·ó¿·üøsv/Ywy¸} <Y}ý}o_w1Îo²¹sñ·ó¿·üø²3 oß~w{û{p~~ºwyÿ= <s¼NG xY}w}zt³wyqyz³x{z¹ztwy&
»½õúö³ñ·ó¿·üø~ºÜ e~wÞn±¹¼» _|ù5 ©/z¯_u
»½õúö³ñ·ó¿·üø~ºÜ e~wÞn±¹¼» WÏ~÷ý»¹{ztv1Y}ý}_~ÿw~Þ|ßxz»±ü¹|[t2 WÏ~\þ²¶'ï¼sß~oww²ÏzÞß{zsv»2 WÏõýü : úüù ò²úó° þú'÷ò7PoC sº
óh'¿ó »½õúö³ñ·ó¿·üøÞ û'ü¿ Y}ý} ^/'ÛoÛ
»½õúö³ñ·ó¿·üø~ºÜ _´Õû|ù5 ÿû{¸sv_´Õû|ù5 _ /_ Excel ´ Word gßw^oôüû|ßxv}vt» SecureNavi
(ISMS o÷µüó¹) Assured ( »½õúö³ßï÷ùóøõ¹üð) ³ Þß{ãù|¯¿¼»~wÛßözví{¿¼»±ü¹ Õû²ù5
»½õúö³ñ·ó¿·üø~º Ü ©/z¯_u 50 <u~~Þu2ðú¸ü·÷ó²[t2 ¯~»½õúö³{þ²SaaS {n±v»sx|[t
¹¿üø²ó÷~ºÜ ^ÿ~O : CISO ²^ÿ»½õúö³ø¯|r»¿qwzt /¯gºÜ : Þ~þþ´èÿ|}/u¼z1üóõü'Ýïk|~ow´yt û}zn :
ÿoö{¾í´Ûo?~û}z®n~wn±¹¼»±ü¹|[t ¿u³¹ø : }÷'ýÛ'~|·¿»Õûz~w1Õ¿u{f|{{»
yvÿßwvt{ÿ BtoB SaaS ´svtNwÿûv»ºÜ2 Ïzÿß_vuxvzsx|Ý2
Þû÷W Google NotebookLM ²o Þß~²Ö}wv Google NotebookLM wÓwy»ß} Þ_{wp¹¼z1r»{þºw²/¯wÞ|ÿý ¸ó¸û²´÷ýð¿øñüð{{{¿¹z1»üû¹´CS
w/kÞ|ÿý{
ñ·ó¿·üø²}wvt׺} AWS ~¸vz¿ù¶ùùóÀü|³ó÷ù´²ó¹åy²Ï_}y»m¼2 T~¾'÷ÿüýüøÿISO 1SOC 1PCI DSS zy²À¶óýüùw}»ýü¿û|}u¼vt»2
ñ·ó¿·üø²}wvt׺} AWS ~¸vz¿ù¶ùùóðü|³ó÷ù´²ó¹åy²Ï_}y»m¼2 https://smarthr.jp/about/security/
}ñ·ó¿·üø~ßÖ [/ö{}ñ·ó¿·üø²ßÖy»×²Û https://github.com/mnuma/awesome-public-check-sheet
¸Ówu¼»ñ·ó¿ú¹ø T~}»½õúö³·üøwïO{þâu¼vt»sx|[t2 IPA þ¯ý/ <Ûyz¶·öµ´ø~_ºo= ¶·ö²÷ú±ü·÷ó~»½õúö³ßÍ ñ·ó¿ú¹ø Web çx~ÿ|zu¼vt»{ 2021
~3 o31 o}7 z4 w} }nwmw (METI) <¿ù¶ùµüó¹üùû~ñ·ó¿ú¹ø= ÿog1ï¼g1gýþzy|ùü¹ 2010 ~8 o } ;ÿ}u¼vzt|xv²¸¿¼vt» xtx}/özõ¹üþóø{zsvgvtzt }~þ|rx÷t2ßogx^öy»±ü¹ûv}vt»~{zx}v2 ¯~»½õúö³{þ²/¼¿°±}\þ¯{zº|q2
O Û? ÿ{þzÛ?2 <SOC 2 zy~}|zt|\ñ·ó¿·üø~Þxz»±ü¹|~~r»= ISMS ÿISO/IEC 27001 ISO/IEC
27017 SOC Type2 / SOC Type1 »½õúö³ñ·ó¿·üøÞ~/uZ{²ö}w~y2 rtv×_Yx~´º×º²û÷Ww1þ\{Og~úß{tz|º~y2
~x± : CĞSpc w³psx²{wvt »½õúö³ñ·ó¿·üøxBtoB SaaS ²ßÛ~»ù{¹uvw~w2 _özÿßwz1zûù{xsv²ï¼g{tz|»sx|g²Ý Cysec w³÷¿²{w1ýÿö{»½õúö³²¿±vt}t