æšä»ã®ã·ã¹ãã éçºã«ãããŠæ³šç®ãããŠãããDevSecOpsãã補åãããŒã«éžå®ãè«ç¹ã«ãªããã¡ã ããå®éã«ã¯æè¡é¢ã§ã¯ãªãããã以å€ã®èŠå ã§çµç¹ãžã®æµžéãé»å®³ãããŠããŸãã±ãŒã¹ãå€ãã
ã¢ã¯ã»ã³ãã¥ã¢ ãã¯ãããžãŒã³ã³ãµã«ãã£ã³ã°æ¬éš ã»ãã¥ãªãã£ã°ã«ãŒã ãããŒãžã£ãŒ ç°åè乿°ãã7æ13æ¥ã14æ¥ã«éå¬ããããªã³ã©ã€ã³ã»ãããŒãTECH+ãã©ãŒã©ã ã¯ã©ãŠãã€ã³ãã© Days 2023 Jul.ããžãã¹ãæ¯ããã¯ã©ãŠãã®æ¬è³ªãã«ç»å£ããã®èª²é¡ã«å¯Ÿããå®è·µçãªè§£æ±ºçãã¢ã€ãã¢ã«ã€ããŠè§£èª¬ããã
DevSecOpsãšã¯
ã¬ãŒãããŒã®å®çŸ©ã«ãããŠãDevSecOpsã¯ããæ°èã®ã¢ãžã£ã€ã«ITãDevOpsã®éçºã«ã»ãã¥ãªãã£ãã§ããã ãã·ãŒã ã¬ã¹ãã€ééçã«çµ±åããããšããšãããŠããã
çæ³çã«ã¯ãéçºè ã®ã¢ãžãªãã£ãã¹ããŒããäœäžãããããéçºããŒã«ç°å¢ã倿Žãããããããšãªãå®çŸããããšãæãŸããããã ã»ãã¥ãªãã£ãã¹ããè¡ãã®ã§ã¯ãªããã§ããã ãéçºã»éçšã®å¹çæ§ãé»å®³ããªãããšããã€ã³ãã ãå ·äœçã«ã¯ãéçºè ãéçšè ã䜿ãCI/CDãã€ãã©ã€ã³ãIDEã«çµ±åãããããã¡ã§å®è£ ããæ¹éãæ¡ãããšãæšå¥šãããã
ãäŸãã°ãã³ãŒãã£ã³ã°ã®ãã§ãŒãºã§ã¯ãIDEïŒIntegrated Development Environmentãçµ±åéçºç°å¢ïŒã®ãã©ã°ã€ã³ãå ¥ããŠã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã§ããŠããããã§ãã¯ããããã«ãã®ãã§ãŒãºã§ããã°ãéçã³ãŒãè§£æãªã©ã®ããŒã«ãå°å ¥ããŠãœãŒã¹ã³ãŒããåé¡ãªãããã§ãã¯ããæ¹æ³ãæ¡ãããããšããããŸããïŒç°åæ°)
DevSecOpså°å ¥åŸã®åé¡ç¹ã¯ãæè¡ã§ã¯ãªã人æã»ããã»ã¹ã«ãã
ç°åæ°ã«ãããšãDevSecOpså°å ¥åŸã¯ãæè¡é¢ã§ã¯ãªãã人æãããã»ã¹ãèŠå ãšãªã£ãŠçµç¹ãžã®æµžéãé»å®³ãããããšãå€ããšããã
äºäŸãšããŠã¯ãåçš®ã»ãã¥ãªãã£ãã¹ãããŒã«ãCI/CDãã€ãã©ã€ã³ã«çµã¿èŸŒãã§è匱æ§ãå¯èŠåããããã¢ããªãã€ã³ãã©ã®éçºã»éçšäœæ¥ã«å¿ãããè匱æ§ã®æ¯æ£ãè¡ããšãããŸã§æãåããªããªããçµæçã«èª°ã察å¿ããªããªã£ãã±ãŒã¹ãããããã ã
ãŸããè匱æ§ãæ¯æ£ããããã»ã¹ãŸã§ãæŽåããŠå¯Ÿå¿ãå§ãããã®ã®ãã»ãã¥ãªãã£ã®ç¥èŠãããã¡ã³ããŒã«ãã察å¿ã«åããçµç¹å šäœã®äœæ¥å¹çãèœã¡ãŠããŸã£ãã±ãŒã¹ãæããããã
ããã«ãããã»ã¹ã®æŽåã圹å²åæ ã®æç¢ºåãŸã§è¡ã£ãŠããŠãã倧éã«æ€åºãããè匱æ§ã«å¯ŸããŠã©ããŸã§å¯Ÿå¿ãã¹ããåãããçŸå Žãæ··ä¹±ããŠããŸã£ããšããäºäŸãããã
ãããã«å¯Ÿãç°åæ°ã¯ããããã ããã£ãŠããã°ãã®åé¡ã¯èµ·ããªãããšããååãªå¯Ÿçãããããã§ã¯ãªããã»ãã¥ãªãã£ç¥èãæã€äººæããªã¹ã¯ãšå¯Ÿå¿å·¥æ°ãéã¿ã察å¿å€æã®ããã»ã¹ã®æŽåãå¿ èŠãã ãšè§£èª¬ããããã®ããã§çµç¹ãšããŠDevSecOpsãæµžéãããã«ã¯ã人æããã³ããã»ã¹ãšããåå°ãæŽããããšã®éèŠæ§ãææããã
çµç¹ã«ãããDevSecOpså°å ¥ã®ãã€ã³ãïŒäººææè²ãšäœå¶ã¥ãã
人æã®æŽåã«ããã£ãŠã¯ãé¢ä¿è 1人1人ã®ã»ãã¥ãªãã£ç¥èãåäžããããã®æè²ããããŠãèªçµç¹ã®ã»ãã¥ãªãã£å°éå®¶ãæŽ»ããããã®äœå¶ã¥ããããã€ã³ããšãªãã ã»ãã¥ãªãã£ã¯åéãå¹ åºããããã©ãããç¥èã身ã«ã€ããŠããã¹ããã®å€æãé£ãããç°åæ°ã«ãããšãéçºãéçšãæ åœããã¡ã³ããŒã«å¯ŸããŠã¯ãçãçµã£ãåŠç¿ãå¹ççã ãšãããå ·äœçã«ã¯ãäžèšã®3ã€ã«åããããã
1.èªèº«ã®æ
åœé åããçæãããã¿ãŒã³
èªèº«ã®æ
åœé åããçæããå Žåãããã°ã©ããŒã§ããã°ãåèšèªã»ãã¬ãŒã ã¯ãŒã¯ã®ã»ãã¥ã¢ã³ãŒãã£ã³ã°ã¬ã€ããã¯ã©ãŠããšã³ãžãã¢ã§ããã°ãåãããªãã¯ã¯ã©ãŠããã³ããŒã®ã»ãã¥ãªãã£ãã¯ã€ãããŒããŒããªãã¡ã¬ã³ã¹ã¢ãŒããã¯ãã£ã掻çšããŠãæ
åœé åãã»ãã¥ãªãã£èгç¹ããæ·±æãããŠããæ¹æ³ãæå¹ãšãªãã
2.äœç³»çã«åŠã¶ãã¿ãŒã³
äžæ¹ãå
šäœåããéç®ããŠåŠç¿ãé²ãã人ãå°ãªããªãã¯ãããã®å Žåãã»ãã¥ãªãã£è³æ Œå¯Ÿçã³ã³ãã³ãã䜿ã£ãŠãäœç³»çãªåŠç¿ãå¯èœã ãç°åæ°ã¯ãäŸãã°ãæ
å ±åŠçå®å
šç¢ºä¿æ¯æŽå£«ã¯åºç¯å²ã®ã»ãã¥ãªãã£ç¥èãæ±ãããããããè³æ Œå¯Ÿçæ¬ã«ç®ãéãããšã§äœç³»çã«ã»ãã¥ãªãã£ã®å
šäœåãæŽçã§ããããšèª¬æããã
3.ã»ãã¥ãªãã£ãã¬ã³ãã俯ç°ããŠå匷ããŠãããã¿ãŒã³
俯ç°çãªç®ã§èŠãŠã»ãã¥ãªãã£ãã¬ã³ããæŒãããããšããå¹ççãªåŠç¿æ³ã®1ã€ã ãIPAãåºããæ
å ±ã»ãã¥ãªãã£10倧è
åšãããOWASP Top10ããªã©ã®è§£èª¬ã«ç®ãéããèªãã®çµç¹ãæ
åœã·ã¹ãã ã®è
åšãšããŠçœ®ãæããŠçŸç¶ã®å¯ŸçãèŠçŽãæ¹éãšãªãã
ç°åæ°ã¯ãæ¥æ¬ã«ãããŠã¯ã»ãã¥ãªãã£äººæã倧ããäžè¶³ããŠããäºå®ãæèãã¹ãã ãšèšãããäžè¶³ããã»ãã¥ãªãã£äººæã掻ããã«ã¯ã宿œé »åºŠãé«ãã¿ã¹ã¯ã¯ã»ãã¥ãªãã£ããŒã ã§ã¯ãªãåæ åœé åã®ããŒã ãåãæã€ãããåæ ã«é æ ®ããããšãéèŠããšäœå¶é¢ã§ã®èæ ®ãå¿ èŠã§ãããšããã
çµç¹ã«ãããDevSecOpså°å ¥ã®ãã€ã³ãïŒå±äººåãããªãããã»ã¹
DevSecOpsã®ããã»ã¹ã«ãããŠã¯ãèªååããã£ãŒãã£ãŒãããã¡ã ããã²ãŒãåãææžåããã±ããåã«ã€ããŠãåãçµãã§ããå¿ èŠãããã
èªåå
èªååã¯ãã§ã«å°å ¥ããŠããçµç¹ãå€ãããç°åæ°ã¯å®æçã«èŠçŽãããšãå§ãããèªååã¯ã補åã»ããŒã«ã®é²åãéãããªãŒãã³ãœãŒã¹ãœãããŠãšã¢ã«ãããŠãããããªåéã§ãããããããŸã§ã¯åã蟌ããªãã£ããããªåéã§ãã2ïœ3幎ã»ã©ã§èªååããŒã«ãè±å¯ã«ããç¶æ³ã«å€ããããšãããåŸãã(ç°åæ°)ããã ã
èªååã«é¢ããŠãã1ã€èããªããã°ãªããªãã®ã¯ãDevOpsåæ§ãããã«ããã¯ãšãªãããã»ã¹ãæé€ãããã¯è² æ 軜æžããããšã§ãããç³è«ããŒã¹ã§ã®ãã«ãã»ãããã€ã®ããã»ã¹ãååšããŠãããã峿æ§ã®äœãæ¿èªãããŒããã£ãããããšãèªååã®æ©æµãåããããªããªãæããããã
ãã®å¯ŸçãšããŠãç°åæ°ã¯ãåçš®ãããªãã¯ã¯ã©ãŠããã³ããŒãæäŸããã¬ãŒãã¬ãŒã«æ©èœãChatOpsãCI/CDãã€ãã©ã€ã³ã®æ¿èªæ©èœãªã©ã掻çšããæ¹æ³ãæããããŸããæ¿èªãããŒã®æ åœå²åœãèŠçŽãããšãéèŠã ãšããã
ã²ãŒãå
ããã»ã¹ã®ç§»è¡æã«ãã¹ãã宿œãããã§ãã¯ãã€ã³ããèšããã²ãŒãåã«ã€ããŠã¯ãKPIãèšå®ã»æž¬å®ãããã®çµæãåºã«æ¬¡ã®ãã§ãŒãºã«é²ãã¹ããã¯ã©ã€ããªã¢ãèšå®ã倿ããããšãå¿ èŠãšãªããã²ãŒãã®äŸãšããŠã¯ãPre-commit hookãããéçºè ã®ããŒã«ã«ç°å¢ã«ãããŠIDEãã©ã°ã€ã³ã§æ€åºãããã»ãã¥ã¢ã§ã¯ãªãå®è£ ç®æã®æ°ãã«ãŠã³ããããªã©ã®æ¹æ³ãèããããã
ææžå
ææžåã«é¢ããŠã¯ãäŸãã°ããœãŒã¹ã³ãŒãã®éçè§£æã®çµæã«å¯Ÿããçµæã®è§£éæ¹æ³ã誀æ€ç¥ãã³ãŒãä¿®æ£ã®å¿ èŠæç¡ãšãã£ã倿ã«å¯ŸããèåŒ±æ§æ å ±ã®èšäºã»ãœãŒã¹ãå€ææ ¹æ ãã³ãŒãä¿®æ£ã«å¯Ÿããçç±ãåèã«ããæ å ±ãªã©ãææžåããŠããããšãå ·äœçãšããŠèããããã
ãã±ããå
ãŸããä»ã®éçºéçšã¿ã¹ã¯ãšåæ§ã察å¿ãå¿ èŠãªè匱æ§ãæ€åºçµæã«å¯ŸããŠã¯ãã±ãããäœæãã察å¿ç®¡çã培åºããããšãéèŠã ãç°åæ°ã¯ãå¯Ÿå¿ææ¥ãšã¯ããŒãºæ¡ä»¶ãæç¢ºã«ããããã§ã察å¿ãå±äººåããªããããã±ãã管çåºç€ã®ããŒã å ã®èªåæ åœè å²åœæ©èœãå©çšããããšãæšå¥šããã
ããã«ããããè² è·ã忣ãããã ãã§ãªããå®è·µãéããŠã»ãã¥ãªãã£ã®ç¥èŠãã¡ã³ããŒã身ã«ä»ããŠãããããã«ãªãã(ç°åæ°)ãšãDevSecOpsãæŽããããã«å¿ èŠãªäººæè²æã«ã€ããŠããã®ããŠããŠãèªã£ãã





