Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティチェックシートの話 / Security Check Sheet
Search
mnuma
September 11, 2025
0
7
セキュリティチェックシートの話 / Security Check Sheet
mnuma
September 11, 2025
Tweet
Share
More Decks by mnuma
See All by mnuma
Datadogで始めるユーザー行動分析 / Getting Started with User Behavior Analysis Using Datadog
mnuma
0
51
自動テストについて / Automated Testing
mnuma
0
220
Kubernetesの自動アップグレードについて / Upgrading GKE cluster
mnuma
0
200
AWS Auroraのスロークエリを Datadogで扱うまで / How to handle slow_queries_logs in AWS Aurora with Datadog
mnuma
0
880
Googleに学ぶDesign Docs / Learn from Google on Design Docs
mnuma
0
160
Observabilityを実践する / Pragmatic observability
mnuma
2
220
Kubernetes Case Studies #1@Makuake KubeCon NA 2019 Recap
mnuma
0
150
カオスエンジニアリングについてヤホーで調べてきました / Enter the chaos engineering
mnuma
0
100
Chaos Engineering 現状把握 / History Of Chaos Engineering
mnuma
0
350
Featured
See All Featured
No one is an island. Learnings from fostering a developers community.
thoeni
21
3.4k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
285
14k
Optimising Largest Contentful Paint
csswizardry
37
3.4k
The Cost Of JavaScript in 2023
addyosmani
53
8.9k
For a Future-Friendly Web
brad_frost
180
9.9k
RailsConf 2023
tenderlove
30
1.2k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
31
2.2k
Java REST API Framework Comparison - PWX 2021
mraible
33
8.8k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
18
1.1k
Product Roadmaps are Hard
iamctodd
PRO
54
11k
Designing for humans not robots
tammielis
253
25k
Being A Developer After 40
akosma
90
590k
Transcript
>»½õúö³ñ·ó¿·üø~ û? 2025/09/09 TDU CySec ç«_ LT
¯?}Ï CySec ×o üßn Web ¸ó¸û² / SRE (Site Reliability
Engineering ÿ {ý~ / ÷ýÀ¿ø»½úö³{·¿»sx|[t ÿj_yý²sv¹¿üø²ó÷wÝtvt~y
»½õúö³ñ·ó¿·üø »½õúö³ñ·ó¿·üøx : ÿÕOm|Û±vt»SaaS ´ôüû^/f~±~þ¯~î_y [Excel ´Word _w¯~»½õúö³~þâwþ¯~owr»sx|[t ôüû´SaaS ~Y}f{{|ß
https://smarthr.jp/about/security/
»½õúö³ñ·ó¿·üø Qiita »½õúö³üñ·ó¿·üøxtv×x~¶ÛÛ - Qiita How do you like »½õúö³üñ·ó¿·üø
? ³ü³³³³³³¹¹¹ü³1³ ¹¹ü1³ü³1³¹¹¹ü ÿºü÷ûóÀö1__ïu¿º »½õúö³üñ·ó¿& Qiita u³»½õúö³ñ·ó¿·üø²þtvtvÿº|q}vz~wo}Þ²þt& »½õúö³ñ·ó¿·üøsv/Ywy¸} <Y}ý}o_w1Îo²¹sñ·ó¿·üø²3 oß~w{û{p~~ºwyÿ= <s¼NG xY}w}zt³wyqyz³x{z¹ztwy&
»½õúö³ñ·ó¿·üø~ºÜ e~wÞn±¹¼» _|ù5 ©/z¯_u
»½õúö³ñ·ó¿·üø~ºÜ e~wÞn±¹¼» WÏ~÷ý»¹{ztv1Y}ý}_~ÿw~Þ|ßxz»±ü¹|[t2 WÏ~\þ²¶'ï¼sß~oww²ÏzÞß{zsv»2 WÏõýü : úüù ò²úó° þú'÷ò7PoC sº
óh'¿ó »½õúö³ñ·ó¿·üøÞ û'ü¿ Y}ý} ^/'ÛoÛ
»½õúö³ñ·ó¿·üø~ºÜ _´Õû|ù5 ÿû{¸sv_´Õû|ù5 _ /_ Excel ´ Word gßw^oôüû|ßxv}vt» SecureNavi
(ISMS o÷µüó¹) Assured ( »½õúö³ßï÷ùóøõ¹üð) ³ Þß{ãù|¯¿¼»~wÛßözví{¿¼»±ü¹ Õû²ù5
»½õúö³ñ·ó¿·üø~º Ü ©/z¯_u 50 <u~~Þu2ðú¸ü·÷ó²[t2 ¯~»½õúö³{þ²SaaS {n±v»sx|[t
¹¿üø²ó÷~ºÜ ^ÿ~O : CISO ²^ÿ»½õúö³ø¯|r»¿qwzt /¯gºÜ : Þ~þþ´èÿ|}/u¼z1üóõü'Ýïk|~ow´yt û}zn :
ÿoö{¾í´Ûo?~û}z®n~wn±¹¼»±ü¹|[t ¿u³¹ø : }÷'ýÛ'~|·¿»Õûz~w1Õ¿u{f|{{»
yvÿßwvt{ÿ BtoB SaaS ´svtNwÿûv»ºÜ2 Ïzÿß_vuxvzsx|Ý2
Þû÷W Google NotebookLM ²o Þß~²Ö}wv Google NotebookLM wÓwy»ß} Þ_{wp¹¼z1r»{þºw²/¯wÞ|ÿý ¸ó¸û²´÷ýð¿øñüð{{{¿¹z1»üû¹´CS
w/kÞ|ÿý{
ñ·ó¿·üø²}wvt׺} AWS ~¸vz¿ù¶ùùóÀü|³ó÷ù´²ó¹åy²Ï_}y»m¼2 T~¾'÷ÿüýüøÿISO 1SOC 1PCI DSS zy²À¶óýüùw}»ýü¿û|}u¼vt»2
ñ·ó¿·üø²}wvt׺} AWS ~¸vz¿ù¶ùùóðü|³ó÷ù´²ó¹åy²Ï_}y»m¼2 https://smarthr.jp/about/security/
}ñ·ó¿·üø~ßÖ [/ö{}ñ·ó¿·üø²ßÖy»×²Û https://github.com/mnuma/awesome-public-check-sheet
¸Ówu¼»ñ·ó¿ú¹ø T~}»½õúö³·üøwïO{þâu¼vt»sx|[t2 IPA þ¯ý/ <Ûyz¶·öµ´ø~_ºo= ¶·ö²÷ú±ü·÷ó~»½õúö³ßÍ ñ·ó¿ú¹ø Web çx~ÿ|zu¼vt»{ 2021
~3 o31 o}7 z4 w} }nwmw (METI) <¿ù¶ùµüó¹üùû~ñ·ó¿ú¹ø= ÿog1ï¼g1gýþzy|ùü¹ 2010 ~8 o } ;ÿ}u¼vzt|xv²¸¿¼vt» xtx}/özõ¹üþóø{zsvgvtzt }~þ|rx÷t2ßogx^öy»±ü¹ûv}vt»~{zx}v2 ¯~»½õúö³{þ²/¼¿°±}\þ¯{zº|q2
O Û? ÿ{þzÛ?2 <SOC 2 zy~}|zt|\ñ·ó¿·üø~Þxz»±ü¹|~~r»= ISMS ÿISO/IEC 27001 ISO/IEC
27017 SOC Type2 / SOC Type1 »½õúö³ñ·ó¿·üøÞ~/uZ{²ö}w~y2 rtv×_Yx~´º×º²û÷Ww1þ\{Og~úß{tz|º~y2
~x± : CĞSpc w³psx²{wvt »½õúö³ñ·ó¿·üøxBtoB SaaS ²ßÛ~»ù{¹uvw~w2 _özÿßwz1zûù{xsv²ï¼g{tz|»sx|g²Ý Cysec w³÷¿²{w1ýÿö{»½õúö³²¿±vt}t