ã¯ããã«
2026幎çŸåšãã©ã³ãµã ãŠã§ã¢ã¯å€ãã®äŒæ¥ã®é¢å¿äºãšãªã£ãŠããŸãã
AWS ã¯ãå€ãã®äŒæ¥ã®ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãšããŠå€ãå©çšãããŠããŸãã
AWS ã§ã¯ãã©ã®ãããªæ¹æ³ã§ã©ã³ãµã ãŠã§ã¢å¯Ÿçãã§ããã®ã§ããããïŒ
æ¬èšäºã§ã¯ãAWS ã®æ©èœã掻çšããã©ã³ãµã ãŠã§ã¢å¯Ÿçãããé²åŸ¡ã»æ€ç¥ã»å埩ãã®3ã€ã®ãã§ãŒãºã«åããçãããèªåã®ç°å¢ã«é©çšã§ããã¬ãã«ãŸã§å
·äœçã«è§£èª¬ããŸãã
ã©ã³ãµã ãŠã§ã¢ã«å¯ŸããŠã¯ã©ãŠãå šäœã§ã©ã®ããã«åããŠããããšããäžäœã¬ã€ã€ãŒåãã®ææ¡èšäºã«ã€ããŠã¯ãå¥éå ¬éããã ããããããã®ãã2026å¹Žææ°ãã©ã³ãµã ãŠã§ã¢å¯Ÿçã«å¯Ÿããæèšããã確èªãã ããã
1. ãé²åŸ¡ãåæäŸµå ¥ã鮿ããæ°Žé察çãšæš©éã®éã蟌ã
åæã®äŸµå ¥ãã§ãŒãºã«ãããŠãæ»æè ãçãã®ã¯ GitHub ã®ãªããžããªãéçºè ã®ç«¯æ«ã«æ®åãããéçãªã¢ã¯ã»ã¹ããŒãã§ããAWS ã§ã¯ãé·æçãªã¢ã¯ã»ã¹ããŒã廿¢ããŠãäžæçã«ç®¡çãããã¢ã¯ã»ã¹ããŒã®å©çšãæšå¥šããŠããŸãã
SCPã«ããã¬ãŒãã¬ãŒã«ãšã¢ã¯ã»ã¹ããŒçºè¡çŠæ¢ã®ä»çµã¿
2026幎ã®ãã¹ããã©ã¯ãã£ã¹ã«ãããŠããã¢ã¯ã»ã¹ããŒã®ããŒããŒã·ã§ã³ãã¯ããã¯ãéå»ã®å¯Ÿçã§ããé·æã¢ã¯ã»ã¹ããŒãã®ãã®ã廿¢ããã»ãã·ã§ã³ããŒã¹ã®çãæå¹æéã®ã¯ã¬ãã³ã·ã£ã«ã«ç§»è¡ããããšãéèŠã§ãã
ããããåã«ã䜿ããªãã§ãã ããããšåšç¥ããã ãã§ã¯äžååã§ããAWS Organizations ã® SCPïŒãµãŒãã¹ã³ã³ãããŒã«ããªã·ãŒïŒ ã䜿ããç©ççã«ã¢ã¯ã»ã¹ããŒãäœæã§ããªãç°å¢ïŒã¬ãŒãã¬ãŒã«ïŒãæ§ç¯ããŸãã
æ»æè ã®åã:
é·æã¢ã¯ã»ã¹ããŒã奪åããèªç±ã«IAMãŠãŒã¶ãŒãããŒã«ãäœæã»å€æŽããŠç°å¢ãä¹ã£åãããšããŸãã
ã察çã
- å¢çããªã·ãŒïŒPermission BoundaryïŒã®äœæ: ãã¢ã¯ã»ã¹ããŒã®äœæïŒ
iam:CreateAccessKeyïŒããæç€ºçã«æåŠããããªã·ãŒïŒäŸïŒCoreSecurityBoundaryïŒããããããäœæããŠãããŸãã - SCPã«ãã匷å¶: ãšã³ãžãã¢ãæ°ããIAMããŒã«ããŠãŒã¶ãŒãäœæããéãå¿ ãäžèšã®å¢çããªã·ãŒãã¢ã¿ããããªããã°ãªããªãããã«å¶éããŸãã
以äžã®ããªã·ãŒãé©çšããããšã§ãã»ãã¥ãªãã£åºæºãæºãããªãIAMãšã³ãã£ãã£ã®äœæãæåŠããçµæãšããŠçµç¹å ã§ã®åæãªã¢ã¯ã»ã¹ããŒçºè¡ãå°ã蟌ããŸãã
å®è£ ããããªã·ãŒïŒ
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "EnforceSecurityBoundaryOnIAMCreation",
"Effect": "Deny",
"Action": [
"iam:CreateUser",
"iam:CreateRole",
"iam:PutUserPermissionsBoundary",
"iam:PutRolePermissionsBoundary"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"iam:PermissionsBoundary": "arn:aws:iam::${aws:PrincipalAccount}:policy/CoreSecurityBoundary"
}
}
},
{
"Sid": "PreventBoundaryDeletion",
"Effect": "Deny",
"Action": [
"iam:DeleteUserPermissionsBoundary",
"iam:DeleteRolePermissionsBoundary"
],
"Resource": "*"
}
]
}
ãã®SCPåäœã§ã¢ã¯ã»ã¹ããŒãæ¶ããããã§ã¯ãªããäºåã« CoreSecurityBoundary ããªã·ãŒå
ã«ã以äžã®èšè¿°ãå«ããŠããããšãæ¡ä»¶ã§ãã
iam:CreateAccessKeyã Deny ããèšå®- ãã®ä»ã®ã»ãã¥ãªãã£çŠæ¢äºé
ããã«ãããéçºè ãäœæ¥çšã«æš©éã®åŒ·ãããŒã«ãäœãããšããéãå¿ ãã¢ã¯ã»ã¹ããŒäœæäžå¯ãšããå¶çŽãã»ããã§ä»äžãããããšã«ãªããé·æã¯ã¬ãã³ã·ã£ã«ãçãŸããäœå°ãç¡ããããšãã§ããŸãã
ABAC (屿§ããŒã¹ã¢ã¯ã»ã¹å¶åŸ¡) ã§æšªå±éãé²ã
åæäŸµå ¥ã«æåããæ»æè ãæ¬¡ã«è¡ãã®ã¯ã奪ã£ãã¯ã¬ãã³ã·ã£ã«ã䜿ã£ãŠæš©éã®ç¯å²ãåºãã ã©ãã©ã«ã ãŒãã¡ã³ã ã§ãããã®åããæ¢ããããšãéèŠã§ãã
æ»æè ã®åã:
çªåãããŠãŒã¶ãŒã®ã¯ã¬ãã³ã·ã£ã«ã§ãã¢ã¯ã»ã¹æš©ããããã«é¢ããããçµç¹å ã®ä»ã®ãªãœãŒã¹ïŒS3ãã±ãããEC2ãªã©ïŒãžã®ã¢ã¯ã»ã¹ã詊ã¿ãŸãã
ã察çã
ABAC ãå°å ¥ããIAMåŽãšãªãœãŒã¹åŽã§ä»äžãããã¿ã°ãäžèŽããªãéããæäœãèš±å¯ããŸãããããã«ãããæš©éããããžã§ã¯ãåäœã§è«ççã«ãéã蟌ãããããšãå¯èœã§ãã
ââã¿ã°ã®çŽä»ãæé
- IAM (ã¢ã€ãã³ãã£ãã£åŽ) ãžã®ã¿ã°ä»äž:
IdP飿ºæããŠãŒã¶ãŒã®å±æ§ïŒäŸ: éšéåProject: A-ProjectïŒã ã»ãã·ã§ã³ã¿ã° ãšããŠAWSã«æž¡ãããã«èšå®ããŸãã - AWSãªãœãŒã¹åŽãžã®ã¿ã°ä»äž:
S3ãã±ãããEC2ã€ã³ã¹ã¿ã³ã¹ãªã©ãä¿è·å¯Ÿè±¡ã®å šãŠã®ãªãœãŒã¹ã«åãããŒïŒäŸ:ProjectïŒã§ã¿ã°ãä»äžããŸãã - IAMããªã·ãŒ (èš±å¯ã»ãã) ã®èšå®:
Identity Centerã§å©çšè ã«å²ãåœãŠãèš±å¯ã»ããïŒã»ãã·ã§ã³ã«åŒãç¶ãããããªã·ãŒïŒã«ã以äžã®æ¡ä»¶ã远å ããŸãã
å®è£ ããããªã·ãŒïŒ
<br />{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject"
],
"Resource": "arn:aws:s3:::*",
"Condition": {
"StringEquals": {
"aws:ResourceTag/Project": "${aws:PrincipalTag/Project}"
}
}
}
]
}
ãã®ããªã·ãŒã¯ããªãœãŒã¹ã¿ã° (aws:ResourceTag/Project) ãšãæäœãè¡ãããªã³ã·ãã«ïŒãŠãŒã¶ãŒ/ããŒã«ïŒã®ã¿ã° (aws:PrincipalTag/Project) ãå®å
šã«äžèŽããªãéããS3æäœãèš±å¯ããŸãããæ»æè
ãã¯ã¬ãã³ã·ã£ã«ãçªåããŠããã¿ã°ãç°ãªããªãœãŒã¹ã«ã¯äžåæåºãã§ããªããªããŸãã
â»å®è£ åã®éèŠäºé
ãã®ããªã·ãŒã¯ãIAM Identity CenterïŒæ§AWS SSOïŒã§ã屿§ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ããæå¹ã«ãããã€IdPåŽããé©åã«å±æ§ãæž¡ãããŠããå Žåã«åäœããŸãããŸãæå¹ã«æ©èœãããããã«ãããªã·ãŒã®èšå®ã ãã§ãªãä¿è·å¯Ÿè±¡ãšãªãå
šãŠã® S3 ãã±ããã EC2 ã€ã³ã¹ã¿ã³ã¹çã«å¯ŸããŠãæ£ç¢ºã«ã¿ã°ïŒProjectã¿ã°çïŒãä»äžãããŠããããšãæ¡ä»¶ãšãªããŸãã
ã¿ã°ä»ãã«æŒãããããšãæ£èŠã®å©çšè
ã§ãã£ãŠãã¢ã¯ã»ã¹ã§ããªããªããããå°å
¥åã®ãªãœãŒã¹æ£åžããéèŠã§ãã
SCP ã«ãã蚌跡ã®è»¢é忢ã黿¢
æ»æè ã®èšŒæ é æ» ã®åããSCP (ãµãŒãã¹ã³ã³ãããŒã«ããªã·ãŒ)ã䜿çšããŠé»æ¢ããã
æ»æè ã®åã:
æ»æè ã¯ã管çè æš©éã奪ååŸã«èšŒæ é æ» ã®ããã«CloudTrailã®ãã°èšé²ã忢ãããããã°å°çšã¢ã«ãŠã³ããžã®è»¢éèšå®ãåé€ããããšããŸãã
ã察çã
AWS Organizationsã® SCP ã䜿çšããCloudTrailã®åæ¢ãèšå®å€æŽãçµç¹å šäœã§æåŠããŸãã
å®è£ ããããªã·ãŒïŒ
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ProtectCloudTrailSettings",
"Effect": "Deny",
"Action": [
"cloudtrail:DeleteTrail",
"cloudtrail:StopLogging",
"cloudtrail:UpdateTrail"
],
"Resource": "*"
}
]
}
ãã®SCPãå šã¡ã³ããŒã¢ã«ãŠã³ãã«é©çšããããšã§ãæ¬çªã¢ã«ãŠã³ããä¹ã£åãããŠãããã°ã®è»¢éãæ¢ããæš©éãæ»æè ããç©ççã«å¥å¥ªã§ããŸãã
ãã°ã¯å®å šå°åž¯ã§ãããã°å°çšã¢ã«ãŠã³ãïŒLog ArchiveïŒãžè»¢éããç¶ããŸãã
2. ãæ€ç¥ããµããŸãããèŠæããæ£èŠæš©éãæªçšãã䟵æ»ã
è¿å¹Žã®ã©ã³ãµã ãŠã§ã¢æ»æã¯ããã«ãŠã§ã¢ãéã蟌ãã ãã§ãªããçªåããæ£èŠã®æš©éãæªçšããAWSã®æšæºæ©èœãä»ããŠããŒã¿ãç Žå£ããåŸåã«ãããŸããããã§ã¯ãAIã«ããäžå¯©ãªæ¯ãèãã®æ€ç¥ãšããã®åŸã®èªåçãªå°ã蟌ãïŒã¬ã¹ãã³ã¹ïŒã«èžã¿èŸŒã¿ãŸãã
GuardDuty \à Lambdaã«ããèªåå°ã蟌ã( Auto-Remediation )
GuardDutyãç°åžžãæ€ç¥ããéãLambdaã§å¯Ÿè±¡ã®æš©éãå³åº§ã«ç¡å¹åãããããŒãçµãããšãæ»æã«æå¹ã§ãã
æ»æè ã®åã:
äŸµå ¥ã«æååŸãS3ãã±ãããžã®å€§éã¢ã¯ã»ã¹ããæ®æ®µãšç°ãªããªãŒãžã§ã³ããã®äžå¯©ãªAPIã³ãŒã«ãšãã£ããäžå¯©ãªãµããŸãããè¡ããŸãã
ã察çã
Amazon GuardDuty ãAIã»æ©æ¢°åŠç¿ã§äžå¯©ãªæ¯ãèãïŒFindingïŒãæ€ç¥ããéãAmazon EventBridge ãš AWS Lambda ã飿ºãããå¯Ÿè±¡ã®æš©éãå³åº§ã«ç¡å¹åããèªåå°ã蟌ããå®è£ ããŸãã
Lambdaã³ãŒãã®ããžãã¯
1. ããªã¬ãŒ: EventBridgeãGuardDutyã®High SeverityïŒé倧床7.0以äžïŒã®Findingãæ€ç¥ããéã«Lambdaãèµ·åã
2. ã¿ãŒã²ããç¹å®: Findingã® detail.user.name ããã䟵害ãããIAMãŠãŒã¶ãŒ/ããŒã«åãç¹å®ã
3. Denyããªã·ãŒã®äœæã»ã¢ã¿ãã: 以äžã®å
容ãæã€IAMããªã·ãŒãåçã«äœæããç¹å®ããããŠãŒã¶ãŒ/ããŒã«ã«åŒ·å¶çã«ã¢ã¿ããããŸãã
4. aws:TokenIssueTime ã䜿ã£ãŠãæ€ç¥æå»ä»¥åã«çºè¡ãããå
šããŒã¯ã³ãç©ççã«ãç¡å¹ãåããŸãã
Denyããªã·ãŒã®äŸ (Policy Name: Deny-All-On-Breach)
// IAMããŒã«ã«ã¢ã¿ãããã匷å¶å€±å¹ããªã·ãŒã®äŸ
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "*",
"Resource": "*",
"Condition": {
"DateLessThan": {
ãããããã //ããªã·ãŒå
ã® 2026-02-12T21:00:00Z ã®éšåã¯ãGuardDutyã®Findingãããªã¬ãŒã«Lambdaãèµ·åããå®è¡æå»ïŒäŸµå®³æ€ç¥æå»ïŒãåçã«èšå®ããå¿
èŠããã
"aws:TokenIssueTime": "2026-02-12T21:00:00Z"
}
}
}
]
}
ãã®Denyããªã·ãŒãã¢ã¿ããããããšã§ãããšããŠãŒã¶ãŒ/ããŒã«ãããšããšæã£ãŠããAllowããªã·ãŒãããåªå
床ã®é«ãDenyãé©çšããããã®ã»ãã·ã§ã³ã¯å³åº§ã«ç¡ååãããŸãããŸãæ€ç¥ä»¥åã«çºè¡ãããå
šããŒã¯ã³ãç¡å¹åããæ»æè
ã®æå
ã®éµã¯ãã ã®ã¬ã©ã¯ã¿ã«å€ãããŸãã
â»å°å ¥æã®æ³šæç¹ïŒFalse Positiveãªã¹ã¯ïŒ
èªå鮿ã¯åŒ·åã§ãããæ£èŠã®ãããåŠçããããã€äœæ¥ããæ»æããšèª€æ€ç¥ïŒFalse PositiveïŒããã·ã¹ãã ã忢ããããªã¹ã¯ããããŸãã
æšå¥šéçš:
æåã¯ãæ€ç¥æã¯ç®¡çè
ã®ãã£ããããŒã«ïŒSlackçïŒãžå³æéç¥ããããã§ãŒãºããéå§ããæ€ç¥ç²ŸåºŠã®ãã¥ãŒãã³ã°ãååã«è¡ããŸãããã
èªå鮿ãé©çšããã®ã¯ãéèŠåºŠ (Severity) ãæ¥µããŠé«ãïŒ8.0以äžãªã©ïŒç¹å®ã®è
åšã¿ã€ãã«éå®ãããªã©ãæ
éãªæ€èšãå¿
èŠã§ãã
Amazon Inspectorã«ãããµãã¬ãã·ã§ã³ã«ãŒã«ã§ãã€ãºãæ¶ã
æ»æè ã®åã:
éå»ã«æ§ç¯ããæ€èšŒçšãµãŒãã®ãããé©çšæŒããã塩挬ãã«ãªã£ãã³ã³ããã€ã¡ãŒãžãšãã£ããããã¯ãã¢ããšãªãåŸãè匱æ§ãäŸµå ¥çµè·¯ãšããŸãã
ã察çã
Amazon Inspector ãæå¹åããè匱æ§ç®¡çãèªååããŸããç¹ã«éèŠãªã®ã¯ãéçšè² è·ãæžããããã«ããã€ãºãæ¶ããããšã§ãã
å®åçãªãã£ã«ã¿ãªã³ã°æ¡ä»¶ïŒãµãã¬ãã·ã§ã³ã«ãŒã«ïŒ
Inspectorãå°å ¥ãããšãæ°åä»¶ã®èŠåãçºçããã¡ã§ããä¿®æ£äžèŠãªãã®ãèªåã§æå¶ïŒãµãã¬ã¹ïŒããããã®å®åçãªãã£ã«ã¿æ¡ä»¶ã¯ä»¥äžã®éãã§ãã
| ãã£ã«ã¿æ¡ä»¶ | ç®ç |
|---|---|
| Vulnerability \> Fix available : NO | ä¿®æ£ããããååšããªãè匱æ§ãé€å€ïŒå¯Ÿå¿äžèŠãªããïŒ |
| Severity : LOW | 圱é¿åºŠãäœãããŸãã¯ç·æ¥æ§ã®äœãèŠåãé€å€ |
| Resource Tags : Environment : staging or dev | æ¬çªç°å¢ä»¥å€ã®ã圱é¿ç¯å²ãéå®çãªç°å¢ã®èŠåãé€å€ |
| Network Reachability : Internet : NO | ã€ã³ã¿ãŒãããã«é²åºããŠããªããªãœãŒã¹ã®èŠåã®åªå 床ãäžããïŒãããã¯é€å€ïŒ |
èšå®æé ïŒ
Amazon Inspectorã®ãçµæ (Findings)ãç»é¢ãéãã
- ãã£ã«ã¿ãŒããŒã§äžèšæ¡ä»¶ãå ¥åãã察象ãçµã蟌ãã
- çµã蟌ãã ç¶æ ã§ãæå¶ã«ãŒã«ãäœæ (Create suppression rule)ããã¯ãªãã¯ããã¢ã¯ã·ã§ã³ãšããŠãæå¶ (Suppress)ããéžæã
éèŠãªã¢ã©ãŒãããã€ãºã«åãããã®ãé²ãã管çè ãä»ãã察åŠãã¹ãæ¬åœã«ã¯ãªãã£ã«ã«ãªè匱æ§ã«éäžã§ããç°å¢ãæ§ç¯ããŸãã
3.ãååŸ©ãæ»æè ã«ãæ¶ããªããããã¯ã¢ããã®äœæãšåŸ©æ§
ã©ã³ãµã ãŠã§ã¢æ»æã«ãããææªã®ã·ããªãªã¯ããããŒã¿ã®æå·ååŸããã¹ãŠã®ããã¯ã¢ãããåé€ããã身代éãèŠæ±ãããããšãã§ãã確å®ãªããã¯ã¢ãããããã°ãæ»æè ã®è è¿«ã«å±ããå¿ èŠã¯ãããŸããã
AWS Backup Vault Lockã«ãããäžå€æ§ïŒWORMïŒãã®åŒ·å¶
æ»æè ã AdministratorAccess ã奪åããå Žåã圌ããæåã«è¡ãã®ã¯ããã¯ã¢ããã®åé€ã§ãã
æ»æè ã®åã:
ã«ãŒããŠãŒã¶ãŒãšåçãªç®¡çè
æš©é (AdministratorAccess) ã奪ååŸãæãæåã«è¡ãã®ã¯ããã¯ã¢ããããŒã¿ãä¿åãããŠããS3ãã±ãããAWS Backup Vaultã®åé€ã§ãã
ã察çã
AWS Backup Vault Lock ã® ã³ã³ãã©ã€ã¢ã³ã¹ã¢ãŒã ãé©çšããããã¯ã¢ãããã«ãïŒä¿ç®¡åº«ïŒã« WORMïŒWrite Once Read ManyïŒèšå®ã匷å¶ããŸããããã«ãããã«ãŒããŠãŒã¶ãŒã§ãã£ãŠãåé€ã»å€æŽãã§ããªã匷åãªä¿è·å±€ãæ§ç¯ããŸãã
èšå®ãã¹ã®é«ã³ã¹ãã®ãªã¹ã¯ãšãå·åŽæéãã®éçšæ¡
aws backup put-backup-vault-lock-configuration \
--backup-vault-name MyCriticalVault \
--min-retention-days 30 \
--changeable-for-days 3
min-retention-days` (æå°ä¿ææé) ã誀ã£ãŠé·ãèšå®ãããããšãäžèŠã«ãªã£ãããã¯ã¢ããã§ãã£ãŠãæå®æéïŒäŸã§ã¯30æ¥ïŒã¯èª°ã«ãåé€ã§ããªããªããäºæãã¬ã¹ãã¬ãŒãžã³ã¹ããæ°žä¹ ã«çºçãç¶ãããªã¹ã¯ããããŸãã
å®å šãªå°å ¥ã®ããã®ãå·åŽæéãéçšæ¡:
--changeable-for-daysã« 3æ¥ ãªã©çãæéãèšå®ããïŒ= å·åŽæéïŒã- ãã®å·åŽæéäžã«ãããã¯ã¢ãããžã§ããæ£åžžã«åäœããä¿ææéèšå® (
--min-retention-days) ã«åé¡ããªããã培åºçã«æ€èšŒããã - å·åŽæéãéãããšã
Vault Lockèšå®èªäœãåé€ã»å€æŽã§ããªããªããŸããæ¬çªç°å¢ãžã®é©çšåã«å¿ ãå°èŠæš¡ãªèšå®ã§æ€èšŒããŠãã ããã
ã¯ãã¹ã¢ã«ãŠã³ãããã¯ã¢ãããšKMSã«ããè«ççãªéé¢
æ»æè ã®åã:
åäžã®AWSã¢ã«ãŠã³ããå®å šã«äŸµå®³ãããå ŽåãVault Lockãé©çšããŠããŠãããã®ã¢ã«ãŠã³ãå ã®ãªãœãŒã¹å šãŠã«æ»æè ãã¢ã¯ã»ã¹äžå¯ç¶æ³ãåãŒããŸãã
ã察çã
AWS OrganizationsãæŽ»çšããããã¯ã¢ããå°çšã®éé¢ã¢ã«ãŠã³ãïŒéé¢ç°å¢ããšã¢ã®ã£ããïŒãäœæããŸãã
- æ¬çªã¢ã«ãŠã³ãããéé¢ã¢ã«ãŠã³ããžããã¯ã¢ãããèªåã³ããŒããŸãã
- æãéèŠãªã®ã¯ãã³ããŒå ã®éé¢ã¢ã«ãŠã³ãåŽã§ã¯ãæ¬çªã¢ã«ãŠã³ãã®ãšã³ãžãã¢ã§ãã¢ã¯ã»ã¹ã§ããªã峿 Œãªæš©é管çãè¡ãããšã§ãã
KMSããŒããªã·ãŒã«ããããŒã¿ä¿è·ïŒ
ã©ã³ãµã ãŠã§ã¢ãããã¯ã¢ãããæå·åè§£é€ã§ããªãããã«ãããããKMSïŒæå·åéµïŒãã³ããŒå ã®éé¢ã¢ã«ãŠã³ãåŽã®éµã§åæå·åããããã«èšèšããŸãã
éé¢ã¢ã«ãŠã³ãåŽã®KMSããŒããªã·ãŒã®äŸïŒ
以äžã®ããªã·ãŒã«ãããæ¬çªã¢ã«ãŠã³ã (Source Account ID) ããã®æå·åæäœã®ã¿ãèš±å¯ããè€åå (Decrypt) ã¯éé¢ã¢ã«ãŠã³ãå ã®ç¹å®ã®ç®¡çè ããŒã« (Isolated Admin Role) ã®ã¿ã«å¶éããŸãã
{
"Version": "2012-10-17",
"Statement": [
// èš±å¯1: æ¬çªã¢ã«ãŠã³ãããã®ããŒã¿ã®æå·åïŒããã¯ã¢ããã®æžã蟌ã¿ïŒã®ã¿èš±å¯
{
"Sid": "AllowEncryptFromSourceAccount",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::<Source Account ID>:root" // æ¬çªã¢ã«ãŠã³ãã®ARN
},
"Action": "kms:Encrypt",
"Resource": "*"
},
// èš±å¯2: åŸ©æ§æã®è€ååã¯ãéé¢ã¢ã«ãŠã³ãå
ã®ç¹å®ã®ç®¡çè
ããŒã«ã®ã¿ã«å¶é
{
"Sid": "AllowDecryptForIsolatedAdmin",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::<Target Account ID>:role/IsolatedAdminRole"
},
"Action": "kms:Decrypt",
"Resource": "*"
}
]
}
æ»æè ãæ¬çªã¢ã«ãŠã³ããä¹ã£åã£ãŠãããã®æš©éã§éé¢ã¢ã«ãŠã³ãã®KMSããŒã䜿ã£ãŠããã¯ã¢ããããŒã¿ãè€ååïŒèªã¿åãïŒããããšã¯äžå¯èœã«ãªããŸããããã«ãããããã¯ã¢ããã®ããŒã¿ã®äžèº«ãå®ãããŸãã
æ°èŠã§ã¯ãªãŒã³ãªç°å¢ãžã®ãªã¹ãã¢ïŒåŸ©æ§ïŒ
æ»æè ã®åã:
ããã¯ã¢ããããæ¶ãããªãã£ãããšããŠããå ã®æ±æãããAWSã¢ã«ãŠã³ãã«ãã®ãŸãŸæžãæ»ãã®ã¯å±éºã§ãããªããªãæ»æè ã®ããã¯ãã¢ãæ®ã£ãŠããå¯èœæ§ãããããã§ãã
ã察çã
埩æ§ã¯ãæ°èŠã§ã¯ãªãŒã³ãªAWSã¢ã«ãŠã³ãã«å¯ŸããŠè¡ããŸããããã§ãIaCïŒTerraform/CloudFormationïŒãå©çšããããã¯ãŒã¯ããµãŒããŒçŸ€ãæ°èŠã«ç«ã¡äžããããŒã¿ã®åŸ©æ§ã詊ã¿ãŸãã
- ã€ã³ãã©ã®åæ§ç¯ïŒIaCãçšããŠããããã¯ãŒã¯ïŒVPCïŒããµãŒããŒçŸ€ãæ°åã§æ°åã®ç¶æ ã§ç«ã¡äžããŸãã
- ã¯ãã¹ã¢ã«ãŠã³ãã»ãªã¹ãã¢ã®å®è¡ïŒéé¢ã¢ã«ãŠã³ãã«ä¿ç®¡ãããããã¯ã¢ãããããæ°èŠã¢ã«ãŠã³ããžããŒã¿ã埩å ïŒãªã¹ãã¢ïŒããŸãã
- KMSã«ãã埩å·ïŒéé¢ã¢ã«ãŠã³ãã®ç¹å®ã®ããŒã«ã®ã¿ãæã€ kms:Decrypt æš©éã䜿çšããŠãããŒã¿ã埩å ããŸãã
æš©éã®é転ã«ãã埩æ§ã®å®çŸïŒ
ãªã¹ãã¢æã«ã¯ãæ¬çªã¢ã«ãŠã³ãã§ã¯ãªãéé¢ã¢ã«ãŠã³ãåŽã®åŸ©æ§çšããŒã«ãäž»å°æš©ãæ¡ãããã«èšå®ããŸãã
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowRestoreToCleanAccount",
"Effect": "Allow",
"Action": [
"backup:StartRestoreJob"
],
"Resource": "arn:aws:backup:ap-northeast-1:<Target Account ID>:recovery-point:*",
"Condition": {
"StringEquals": {
"aws:PrincipalAccount": "<Isolated Account ID>"
}
}
}
]
}
察çãã§ãŒãºãšäž»èŠãªãµãŒãã¹
| 察çãã§ãŒãº | AWSãµãŒãã¹ | æ»æè ãžã®å¯ŸæçïŒããžãã¯ïŒ |
|---|---|---|
| äŸµå ¥é²åŸ¡ (Prevent) | SCP, Identity Center, ABAC, | åæäŸµå ¥ã®é®æã é·æã¯ã¬ãã³ã·ã£ã«ã®å»æ¢ãABACã«ããæš©éã®è«ççãªéã蟌ãã |
| æ€ç¥ (Detect) | GuardDuty, Inspector, Security Hub | æœäŒã®æ©æçºèŠã AIæ€ç¥ãšèªåå°ã蟌ã¿ãæ£èŠæš©éã䜿ã£ãäžå¯©ãªæåãèŠæãã |
| å埩 (Recover) | AWS Backup Vault Lock, KMS, IaC | ããŒã¿ã®ä¿è·ãšåŸ©æ§ãæ¶å»ã§ããªãããã¯ã¢ãããæ§æããã¯ãã¹ã¢ã«ãŠã³ãã§è«ççã«éé¢ãã¯ãªãŒã³ãªç°å¢ãžããŒã¿ã埩æ§ã |
ãŸãšã
ã©ã³ãµã ãŠã§ã¢æ»æã¯ãäŸç¶ãšããŠãµã€ããŒè
åšã®äž»æµã§ããã2026幎ããããªãé²åã»é«åºŠåãéããŠæµè¡ããããšãäºæ³ãããŸãã
ã©ã³ãµã ãŠã§ã¢ã®å¯Ÿçã¯ãæ»æã®ãã§ãŒãºã«åãããŠè€æ°ã®å¯Ÿæææ®µã AWS ç°å¢å
ã«æ§ç¯ããããšãéèŠã§ãã
æ¬èšäºã§ç޹ä»ããèšå® ã¯ãæ»æè ã«ãšã£ãŠæãå«ããéå£ãšãªããŸãããããã¯åŒ·åã§ããåé¢ãå°å ¥ã«ã¯æ éãªæ€èšŒæéïŒCooling-off periodïŒã®èšå®ãäžå¯æ¬ ã§ãã
ãã®èšäºãèªãã ä»ããã»ãã¥ãªãã£èšå®ãèŠçŽãæè¯ã®ã¿ã€ãã³ã°ã§ãããŸã㯠AWS ãããžã¡ã³ãã³ã³ãœãŒã«ãéããçŸåšã®èšå®ãå®å šã確èªããŠã¿ãŠãã ããã