{"id":42288,"date":"2024-09-02T06:45:32","date_gmt":"2024-09-02T06:45:32","guid":{"rendered":"https:\/\/www.carmatec.com\/?p=42288"},"modified":"2025-12-31T09:52:30","modified_gmt":"2025-12-31T09:52:30","slug":"aws%e3%81%ae%e3%83%88%e3%83%83%e3%83%97%e3%83%bb%e3%82%a8%e3%82%af%e3%82%b9%e3%83%97%e3%83%ad%e3%82%a4%e3%83%88%e3%81%a8%e3%82%af%e3%83%a9%e3%82%a6%e3%83%89%e7%92%b0%e5%a2%83%e3%82%92%e4%bf%9d","status":"publish","type":"post","link":"https:\/\/www.carmatec.com\/ja\/blog\/top-aws-exploits-and-how-to-secure-your-cloud-environment\/","title":{"rendered":"AWS\u306e\u60aa\u7528\u30c8\u30c3\u30d7\u3068\u30af\u30e9\u30a6\u30c9\u74b0\u5883\u3092\u4fdd\u8b77\u3059\u308b\u65b9\u6cd5"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"42288\" class=\"elementor elementor-42288\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3adb0f6 e-flex e-con-boxed e-con e-parent\" data-id=\"3adb0f6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c4d4e6c elementor-widget elementor-widget-text-editor\" data-id=\"c4d4e6c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2><b>AWS\u3068\u306f\uff1f<\/b><\/h2><p><span style=\"font-weight: 400;\">Amazon Web Services\uff08AWS\uff09\u306f\u3001\u6700\u3082\u4eba\u6c17\u306e\u3042\u308b\u30af\u30e9\u30a6\u30c9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306e1\u3064\u3067\u3042\u308a\u3001\u4e16\u754c\u4e2d\u3067\u4f55\u767e\u4e07\u3082\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u96fb\u529b\u3092\u4f9b\u7d66\u3057\u3066\u3044\u307e\u3059\u3002AWS\u306f\u5805\u7262\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u8cac\u4efb\u5171\u6709\u30e2\u30c7\u30eb\u306b\u3088\u308a\u3001\u30af\u30e9\u30a6\u30c9\u74b0\u5883\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u78ba\u4fdd\u306fAWS\u3068\u30e6\u30fc\u30b6\u30fc\u306e\u5171\u540c\u4f5c\u696d\u3068\u306a\u308a\u307e\u3059\u3002AWS\u306f\u30a4\u30f3\u30d5\u30e9\u3092\u4fdd\u8b77\u3057\u307e\u3059\u304c\u3001\u30c7\u30fc\u30bf\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3001\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u3092\u4fdd\u8b77\u3059\u308b\u306e\u306f\u30e6\u30fc\u30b6\u30fc\u6b21\u7b2c\u3067\u3059\u3002\u3053\u306e\u30d6\u30ed\u30b0\u3067\u306f\u3001\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u304c\u3088\u304f\u4f7f\u7528\u3059\u308bAWS\u306e\u60aa\u7528\u306e\u30c8\u30c3\u30d7\u306b\u3064\u3044\u3066\u63a2\u308a\u3001\u30af\u30e9\u30a6\u30c9\u74b0\u5883\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u5b9f\u7528\u7684\u306a\u30b9\u30c6\u30c3\u30d7\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002.<\/span><\/p><h3><b>AWS\u306e\u4e3b\u306a\u7279\u5fb4\u3068\u306f\uff1f<\/b><\/h3><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u6f14\u7b97\u80fd\u529b<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u4eee\u60f3\u30b5\u30fc\u30d0\u30fc\uff08\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\uff09\u3092\u8d77\u52d5\u3067\u304d\u308bAmazon EC2\uff08Elastic Compute Cloud\uff09\u306a\u3069\u3001\u3044\u304f\u3064\u304b\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30c8\u30b5\u30fc\u30d3\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002\u305d\u306e\u4ed6\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30c8\u30fb\u30b5\u30fc\u30d3\u30b9\u306b\u306f\u3001\u4ee5\u4e0b\u306eAWS Lambda\u304c\u3042\u308b\u3002 <a href=\"https:\/\/www.carmatec.com\/ja\/%e3%83%96%e3%83%ad%e3%82%b0\/aws%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e3%83%ac%e3%82%b9%e3%82%b5%e3%83%bc%e3%83%93%e3%82%b9%e3%81%ae%e3%81%99%e3%81%b9%e3%81%a6\/\">\u30b5\u30fc\u30d0\u30fc\u30ec\u30b9\u30fb\u30b3\u30f3\u30d4\u30e5\u30fc\u30c6\u30a3\u30f3\u30b0<\/a>\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30c7\u30d7\u30ed\u30a4\u3068\u7ba1\u7406\u306e\u305f\u3081\u306eElastic Beanstalk\u3001\u30b3\u30f3\u30c6\u30ca\u5316\u3055\u308c\u305f\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u306e\u305f\u3081\u306eAmazon ECS\uff08Elastic Container Service\uff09\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30b9\u30c8\u30ec\u30fc\u30b8\u30fb\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u30fb\u30b9\u30c8\u30ec\u30fc\u30b8\u7528\u306eAmazon S3\uff08Simple Storage Service\uff09\u3001\u30d6\u30ed\u30c3\u30af\u30fb\u30b9\u30c8\u30ec\u30fc\u30b8\u7528\u306eAmazon EBS\uff08Elastic Block Store\uff09\u3001\u9577\u671f\u30a2\u30fc\u30ab\u30a4\u30d6\u30fb\u30b9\u30c8\u30ec\u30fc\u30b8\u7528\u306eAmazon Glacier\u3001\u30cf\u30a4\u30d6\u30ea\u30c3\u30c9\u30fb\u30af\u30e9\u30a6\u30c9\u30fb\u30b9\u30c8\u30ec\u30fc\u30b8\u7528\u306eAWS Storage Gateway\u306a\u3069\u3001\u62e1\u5f35\u53ef\u80fd\u306a\u69d8\u3005\u306a\u30b9\u30c8\u30ec\u30fc\u30b8\u30fb\u30aa\u30d7\u30b7\u30e7\u30f3\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d3\u30b9<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u30ea\u30ec\u30fc\u30b7\u30e7\u30ca\u30eb\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u7528\u306eAmazon RDS\uff08Relational Database Service\uff09\u3001NoSQL\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u7528\u306eAmazon DynamoDB\u3001\u30c7\u30fc\u30bf\u30a6\u30a7\u30a2\u30cf\u30a6\u30b9\u7528\u306eAmazon Redshift\u3001\u9ad8\u6027\u80fd\u30ea\u30ec\u30fc\u30b7\u30e7\u30ca\u30eb\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u7528\u306eAmazon Aurora\u306a\u3069\u306e\u30de\u30cd\u30fc\u30b8\u30c9\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d3\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30cd\u30c3\u30c8\u30ef\u30fc\u30ad\u30f3\u30b0\u3068\u30b3\u30f3\u30c6\u30f3\u30c4\u914d\u4fe1<\/b><span style=\"font-weight: 400;\">:AWS\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30ad\u30f3\u30b0\u30fb\u30b5\u30fc\u30d3\u30b9\u306b\u306f\u3001\u5206\u96e2\u3055\u308c\u305f\u30af\u30e9\u30a6\u30c9\u30fb\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3092\u69cb\u7bc9\u3059\u308b\u305f\u3081\u306eAmazon VPC\uff08\u4eee\u60f3\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8\u30fb\u30af\u30e9\u30a6\u30c9\uff09\u3001\u5c02\u7528\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u63a5\u7d9a\u306e\u305f\u3081\u306eAWS Direct Connect\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u914d\u4fe1\u3068\u30ad\u30e3\u30c3\u30b7\u30f3\u30b0\u306e\u305f\u3081\u306eAmazon CloudFront\u306a\u3069\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u6a5f\u68b0\u5b66\u7fd2\u3068AI<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u6a5f\u68b0\u5b66\u7fd2\u30e2\u30c7\u30eb\u306e\u69cb\u7bc9\u3068\u30c7\u30d7\u30ed\u30a4\u306e\u305f\u3081\u306eAmazon SageMaker\u3001\u753b\u50cf\u3068\u30d3\u30c7\u30aa\u89e3\u6790\u306e\u305f\u3081\u306eAWS Rekognition\u3001\u81ea\u7136\u8a00\u8a9e\u51e6\u7406\u306e\u305f\u3081\u306eAmazon Comprehend\u3001\u30c1\u30e3\u30c3\u30c8\u30dc\u30c3\u30c8\u69cb\u7bc9\u306e\u305f\u3081\u306eAWS Lex\u306a\u3069\u3001\u4e00\u9023\u306e\u6a5f\u68b0\u5b66\u7fd2\u30b5\u30fc\u30d3\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3068\u30a2\u30a4\u30c7\u30f3\u30c6\u30a3\u30c6\u30a3\u7ba1\u7406<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u306e\u305f\u3081\u306eAWS IAM\uff08Identity and Access Management\uff09\u3001\u6697\u53f7\u5316\u306e\u305f\u3081\u306eAWS KMS\uff08Key Management Service\uff09\u3001DDoS\u9632\u5fa1\u306e\u305f\u3081\u306eAWS Shield\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30fb\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u305f\u3081\u306eAWS WAF\uff08Web Application Firewall\uff09\u306a\u3069\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3001\u30a2\u30a4\u30c7\u30f3\u30c6\u30a3\u30c6\u30a3\u3001\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u3092\u7ba1\u7406\u3059\u308b\u305f\u3081\u306e\u3055\u307e\u3056\u307e\u306a\u30c4\u30fc\u30eb\u3084\u30b5\u30fc\u30d3\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u958b\u767a\u8005\u30c4\u30fc\u30eb\u3068DevOps<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u4ee5\u4e0b\u3092\u63d0\u4f9b\u3059\u308b\u3002<a href=\"https:\/\/www.carmatec.com\/ja\/%e3%83%96%e3%83%ad%e3%82%b0\/aws-devops%e3%83%84%e3%83%bc%e3%83%ab%e3%83%aa%e3%82%b9%e3%83%88%e3%81%a8%e4%bd%bf%e7%94%a8%e4%be%8b%e8%a9%b3%e7%b4%b0%e3%82%ac%e3%82%a4%e3%83%89\/\"> \u958b\u767a\u8005\u3068DevOps\u30c1\u30fc\u30e0\u306e\u305f\u3081\u306e\u30c4\u30fc\u30eb<\/a>\u7d99\u7d9a\u7684\u30a4\u30f3\u30c6\u30b0\u30ec\u30fc\u30b7\u30e7\u30f3\u3068\u30c7\u30ea\u30d0\u30ea\u30fc\uff08CI\/CD\uff09\u306e\u305f\u3081\u306eAWS CodePipeline\u3001\u30d3\u30eb\u30c9\u81ea\u52d5\u5316\u306e\u305f\u3081\u306eAWS CodeBuild\u3001\u30c7\u30d7\u30ed\u30a4\u81ea\u52d5\u5316\u306e\u305f\u3081\u306eAWS CodeDeploy\u3001Infrastructure as Code\u306e\u305f\u3081\u306eAWS CloudFormation\u306a\u3069\u3067\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a2\u30ca\u30ea\u30c6\u30a3\u30af\u30b9\u3068\u30d3\u30c3\u30b0\u30c7\u30fc\u30bf<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u30d3\u30c3\u30b0\u30c7\u30fc\u30bf\u51e6\u7406\u306e\u305f\u3081\u306eAmazon EMR\uff08Elastic MapReduce\uff09\u3001SQL\u3092\u4f7f\u7528\u3057\u3066S3\u306b\u4fdd\u5b58\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u30af\u30a8\u30ea\u3059\u308b\u305f\u3081\u306eAmazon Athena\u3001\u30ea\u30a2\u30eb\u30bf\u30a4\u30e0\u30c7\u30fc\u30bf\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u306e\u305f\u3081\u306eAmazon Kinesis\u3001ETL\uff08\u62bd\u51fa\u3001\u5909\u63db\u3001\u30ed\u30fc\u30c9\uff09\u30d7\u30ed\u30bb\u30b9\u306e\u305f\u3081\u306eAWS Glue\u306a\u3069\u3001\u3044\u304f\u3064\u304b\u306e\u5206\u6790\u30b5\u30fc\u30d3\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/li><\/ol><h3><b>AWS\u3092\u4f7f\u3046\u30e1\u30ea\u30c3\u30c8\u306f\uff1f<\/b><\/h3><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30b9\u30b1\u30fc\u30e9\u30d3\u30ea\u30c6\u30a3<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u3001\u4f01\u696d\u304c\u9700\u8981\u306b\u5fdc\u3058\u3066\u30ea\u30bd\u30fc\u30b9\u3092\u5897\u6e1b\u3055\u305b\u3001\u30b3\u30b9\u30c8\u52b9\u7387\u3068\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u306e\u6700\u9069\u5316\u3092\u5b9f\u73fe\u3057\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30b0\u30ed\u30fc\u30d0\u30eb\u30fb\u30ea\u30fc\u30c1<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u30c7\u30fc\u30bf\u30bb\u30f3\u30bf\u30fc\u306e\u30b0\u30ed\u30fc\u30d0\u30eb\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\uff08\u30a2\u30d9\u30a4\u30e9\u30d3\u30ea\u30c6\u30a3\u30be\u30fc\u30f3\u3068\u30ea\u30fc\u30b8\u30e7\u30f3\uff09\u3092\u6301\u3061\u3001\u4e16\u754c\u4e2d\u306e\u9867\u5ba2\u306b\u4f4e\u30ec\u30a4\u30c6\u30f3\u30b7\u30fc\u3068\u9ad8\u53ef\u7528\u6027\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u4fe1\u983c\u6027<\/b><span style=\"font-weight: 400;\">:\u7d44\u307f\u8fbc\u307f\u306e\u5197\u9577\u6027\u3068\u30d5\u30a7\u30a4\u30eb\u30aa\u30fc\u30d0\u30fc\u6a5f\u69cb\u306b\u3088\u308a\u3001AWS\u306f\u91cd\u8981\u306a\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u30b5\u30fc\u30d3\u30b9\u306b\u9ad8\u30ec\u30d9\u30eb\u306e\u4fe1\u983c\u6027\u3068\u30a2\u30c3\u30d7\u30bf\u30a4\u30e0\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30b3\u30b9\u30c8\u52b9\u7387<\/b><span style=\"font-weight: 400;\">:AWS\u306e\u5f93\u91cf\u8ab2\u91d1\u30e2\u30c7\u30eb\u306b\u3088\u308a\u3001\u5148\u884c\u6295\u8cc7\u8cbb\u7528\u304c\u4e0d\u8981\u3068\u306a\u308a\u3001\u4f01\u696d\u306f\u6d88\u8cbb\u3057\u305f\u30ea\u30bd\u30fc\u30b9\u306b\u5bfe\u3057\u3066\u306e\u307f\u6599\u91d1\u3092\u652f\u6255\u3046\u3053\u3068\u304c\u3067\u304d\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u5305\u62ec\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3<\/b><span style=\"font-weight: 400;\">:AWS\u306f\u9ad8\u5ea6\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3068\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u8a8d\u8a3c\u3092\u63d0\u4f9b\u3057\u3001\u4f01\u696d\u304c\u898f\u5236\u8981\u4ef6\u3092\u6e80\u305f\u3057\u3001\u30c7\u30fc\u30bf\u3092\u4fdd\u8b77\u3067\u304d\u308b\u3088\u3046\u652f\u63f4\u3059\u308b\u3002<\/span><\/li><\/ul><h2><b>\u8cac\u4efb\u5171\u6709\u30e2\u30c7\u30eb\u3092\u7406\u89e3\u3059\u308b<\/b><\/h2><p><span style=\"font-weight: 400;\">\u5177\u4f53\u7684\u306a\u60aa\u7528\u3084\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306b\u8e0f\u307f\u8fbc\u3080\u524d\u306b\u3001AWS\u306e\u8cac\u4efb\u5171\u6709\u30e2\u30c7\u30eb\u3092\u7406\u89e3\u3059\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3060\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>AWS\u306e\u8cac\u4efb\uff1a<\/b><span style=\"font-weight: 400;\"> AWS\u306f\u3001\u7269\u7406\u7684\u306a\u30c7\u30fc\u30bf\u30bb\u30f3\u30bf\u30fc\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3001\u30cf\u30fc\u30c9\u30a6\u30a7\u30a2\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3092\u542b\u3080\u30af\u30e9\u30a6\u30c9\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u5b89\u5168\u78ba\u4fdd\u306b\u8cac\u4efb\u3092\u8ca0\u3046\u3002 <a href=\"https:\/\/www.carmatec.com\/ja\/aws%e3%83%9e%e3%83%8d%e3%83%bc%e3%82%b8%e3%83%89%e3%82%b5%e3%83%bc%e3%83%93%e3%82%b9\/\">AWS\u306e\u30b5\u30fc\u30d3\u30b9<\/a>.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30e6\u30fc\u30b6\u30fc\u306e\u8cac\u4efb\uff1a<\/b><span style=\"font-weight: 400;\"> \u3059\u3079\u3066\u306e\u5b89\u5168\u78ba\u4fdd\u306f\u30e6\u30fc\u30b6\u30fc\u306e\u8cac\u4efb <\/span><i><span style=\"font-weight: 400;\">\u3067<\/span><\/i><span style=\"font-weight: 400;\"> \u30c7\u30fc\u30bf\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3001\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u69cb\u6210\u3001IAM\uff08Identity and Access Management\uff09\u3001\u6697\u53f7\u5316\u3092\u542b\u3080\u30af\u30e9\u30a6\u30c9\u3002<\/span><\/li><\/ul><h2><b>\u30c8\u30c3\u30d7AWS\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3068\u306f\uff1f<\/b><\/h2><p><b style=\"background-color: transparent; text-align: var(--text-align);\">1.S3\u30d0\u30b1\u30c3\u30c8\u306e\u8a2d\u5b9a\u30df\u30b9<\/b><b style=\"background-color: transparent; text-align: var(--text-align);\"><br \/><\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> Amazon Simple Storage Service\uff08S3\uff09\u30d0\u30b1\u30c3\u30c8\u306f\u3001\u305d\u306e\u5e83\u7bc4\u306a\u4f7f\u7528\u3068\u983b\u7e41\u306a\u8aa4\u8a2d\u5b9a\u306b\u3088\u308a\u3001\u653b\u6483\u8005\u306b\u3068\u3063\u3066\u4eba\u6c17\u306e\u30bf\u30fc\u30b2\u30c3\u30c8\u3067\u3059\u3002\u3088\u304f\u3042\u308b\u9593\u9055\u3044\u306b\u306f\u3001S3\u30d0\u30b1\u30c3\u30c8\u3092\u4e00\u822c\u306b\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306b\u3059\u308b\u3053\u3068\u3001\u6697\u53f7\u5316\u3092\u5b9f\u65bd\u3057\u306a\u3044\u3053\u3068\u3001\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u304c\u4e0d\u5341\u5206\u306a\u3053\u3068\u306a\u3069\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u8a2d\u5b9a\u30df\u30b9\u306f\u3001\u30c7\u30fc\u30bf\u4fb5\u5bb3\u3001\u30c7\u30fc\u30bf\u6f0f\u6d29\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u306b\u3064\u306a\u304c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u4e00\u822c\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u7d76\u5bfe\u306b\u5fc5\u8981\u306a\u5834\u5408\u3092\u9664\u304d\u3001S3\u30d0\u30b1\u30c3\u30c8\u304c\u4e00\u822c\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u306a\u3044\u3088\u3046\u306b\u3059\u308b\u3002\u30d0\u30b1\u30c3\u30c8\u30ec\u30d9\u30eb\u3068\u30a2\u30ab\u30a6\u30f3\u30c8\u30ec\u30d9\u30eb\u306e\u4e21\u65b9\u3067 \"Block Public Access \"\u8a2d\u5b9a\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u6700\u5c0f\u7279\u6a29\u3092\u5c0e\u5165\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS Identity and Access Management (IAM) \u30dd\u30ea\u30b7\u30fc\u3092\u4f7f\u7528\u3057\u3066\u6700\u5c0f\u7279\u6a29\u306e\u539f\u5247\u3092\u5b9f\u65bd\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u5fc5\u8981\u306a\u6a29\u9650\u306e\u307f\u3092\u8a31\u53ef\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30d0\u30b1\u30c3\u30c8\u306e\u30d0\u30fc\u30b8\u30e7\u30cb\u30f3\u30b0\u3068\u30ed\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u5076\u767a\u7684\u306a\u30c7\u30fc\u30bf\u524a\u9664\u304b\u3089\u56de\u5fa9\u3059\u308b\u305f\u3081\u306b\u30d0\u30fc\u30b8\u30e7\u30cb\u30f3\u30b0\u3092\u6709\u52b9\u306b\u3057\u3001\u30a2\u30af\u30bb\u30b9\u3092\u76e3\u8996\u3057\u3001\u4e0d\u5be9\u306a\u6d3b\u52d5\u3092\u691c\u51fa\u3059\u308b\u305f\u3081\u306b\u30ed\u30ae\u30f3\u30b0\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u9759\u6b62\u6642\u3068\u8ee2\u9001\u6642\u306e\u30c7\u30fc\u30bf\u3092\u6697\u53f7\u5316\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u9759\u6b62\u72b6\u614b\u306e\u30c7\u30fc\u30bf\u306b\u306f\u30b5\u30fc\u30d0\u30fc\u5074\u3067\u6697\u53f7\u5316\uff08SSE\uff09\u3092\u4f7f\u7528\u3057\u3001\u8ee2\u9001\u4e2d\u306e\u30c7\u30fc\u30bf\u306b\u306f HTTPS \u3092\u5f37\u5236\u3059\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">2.IAM\u7279\u6a29\u306e\u30a8\u30b9\u30ab\u30ec\u30fc\u30b7\u30e7\u30f3<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> \u653b\u6483\u8005\u306f\u3001\u904e\u5ea6\u306b\u5bdb\u5bb9\u306a IAM \u30ed\u30fc\u30eb\u3068\u30dd\u30ea\u30b7\u30fc\u3092\u60aa\u7528\u3057\u3066\u3001\u6607\u683c\u3057\u305f\u7279\u6a29\u3092\u5f97\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30dd\u30ea\u30b7\u30fc\u306e\u9023\u9396\u300d\u3084\u8aa4\u3063\u305f\u8a2d\u5b9a\u306e\u4fe1\u983c\u95a2\u4fc2\u3092\u60aa\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u7279\u6a29\u3092\u6607\u683c\u3055\u305b\u3066\u7ba1\u7406\u8005\u30a2\u30af\u30bb\u30b9\u6a29\u3092\u7372\u5f97\u3057\u3001AWS\u74b0\u5883\u5168\u4f53\u3092\u5371\u967a\u306b\u3055\u3089\u3059\u3053\u3068\u304c\u3067\u304d\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u6700\u5c0f\u7279\u6a29\u306e\u539f\u5247\u306b\u5f93\u3046\uff1a<\/b><span style=\"font-weight: 400;\"> \u7c92\u5ea6\u306e\u7d30\u304b\u3044IAM\u30dd\u30ea\u30b7\u30fc\u3092\u5b9a\u7fa9\u3057\u3001\u6b21\u306e\u3088\u3046\u306a\u904e\u5ea6\u306b\u5bdb\u5bb9\u306a\u30dd\u30ea\u30b7\u30fc\u306e\u4f7f\u7528\u3092\u907f\u3051\u308b\u3002 <\/span><span style=\"font-weight: 400;\">\u7ba1\u7406\u8005\u30a2\u30af\u30bb\u30b9<\/span><span style=\"font-weight: 400;\"> \u3069\u3046\u3057\u3066\u3082\u5fc5\u8981\u306a\u5834\u5408\u3092\u9664\u304d\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u591a\u8981\u7d20\u8a8d\u8a3c\uff08MFA\uff09\u3092\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u30ec\u30a4\u30e4\u30fc\u3092\u5897\u3084\u3059\u305f\u3081\u306b\u3001\u3059\u3079\u3066\u306e\u7279\u6a29\u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u30e6\u30fc\u30b6\u30fc\u306bMFA\u3092\u8981\u6c42\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>IAM \u30dd\u30ea\u30b7\u30fc\u3068\u5f79\u5272\u3092\u5b9a\u671f\u7684\u306b\u898b\u76f4\u3059\uff1a<\/b><span style=\"font-weight: 400;\"> IAM\u306e\u5f79\u5272\u3001\u30dd\u30ea\u30b7\u30fc\u3001\u6a29\u9650\u3092\u5b9a\u671f\u7684\u306b\u898b\u76f4\u3057\u3001\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u306b\u5408\u81f4\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>IAM\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u76e3\u8996\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS CloudTrail\u3068Amazon CloudWatch\u3092\u4f7f\u7528\u3057\u3066\u3001IAM\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u76e3\u8996\u3057\u3001\u4e0d\u5be9\u306a\u52d5\u4f5c\u3092\u691c\u51fa\u3059\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">3.EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u306e\u643e\u53d6<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u30b5\u30fc\u30d3\u30b9\u306f\u3001IAM\u30ed\u30fc\u30eb\u306e\u8a8d\u8a3c\u60c5\u5831\u3092\u542b\u3080\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u63d0\u4f9b\u3059\u308b\u3002\u653b\u6483\u8005\u306f\u3001EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u4e0a\u3067\u52d5\u4f5c\u3059\u308b\u5b89\u5168\u3067\u306a\u3044\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u60aa\u7528\u3057\u3066\u3001\u30e1\u30bf\u30c7\u30fc\u30bf\u30b5\u30fc\u30d3\u30b9(<\/span><span style=\"font-weight: 400;\">http:\/\/169.254.169.254<\/span><span style=\"font-weight: 400;\">)\u3092\u53d6\u5f97\u3057\u3001IAM\u30ed\u30fc\u30eb\u306e\u8cc7\u683c\u60c5\u5831\u3092\u53d6\u5f97\u3059\u308b\u3053\u3068\u3067\u3001\u6a2a\u65b9\u5411\u306e\u79fb\u52d5\u3084\u6a29\u9650\u306e\u6607\u683c\u3092\u53ef\u80fd\u306b\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>IAM \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306f\u63a7\u3048\u3081\u306b\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u5fc5\u8981\u306a\u5834\u5408\u306b\u306e\u307fEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306bIAM\u30ed\u30fc\u30eb\u3092\u5272\u308a\u5f53\u3066\u3001\u30ed\u30fc\u30eb\u306b\u95a2\u9023\u3059\u308b\u6a29\u9650\u3092\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30e1\u30bf\u30c7\u30fc\u30bf\u30fb\u30d0\u30fc\u30b8\u30e7\u30f31\uff08IMDSv1\uff09\u3092\u7121\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30c3\u30b7\u30e7\u30f3\u30d9\u30fc\u30b9\u306e\u30c8\u30fc\u30af\u30f3\u3092\u5fc5\u8981\u3068\u3057\u3001SSRF\uff08Server-Side Request Forgery\uff09\u653b\u6483\u306e\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3059\u308bIMDSv2\uff08Instance Metadata Service Version 2\uff09\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3078\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30afACL\u3092\u4f7f\u7528\u3057\u3066\u3001EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u4fe1\u983c\u3067\u304d\u308bIP\u30a2\u30c9\u30ec\u30b9\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u307f\u306b\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>IAM \u30ed\u30fc\u30eb\u306e\u8cc7\u683c\u60c5\u5831\u3092\u5b9a\u671f\u7684\u306b\u30ed\u30fc\u30c6\u30fc\u30b7\u30e7\u30f3\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305fIAM\u30ed\u30fc\u30eb\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u3092\u5b9a\u671f\u7684\u306b\u30ed\u30fc\u30c6\u30fc\u30b7\u30e7\u30f3\u3057\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u76d7\u96e3\u306e\u30ea\u30b9\u30af\u3092\u6700\u5c0f\u9650\u306b\u6291\u3048\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">4.\u4fdd\u8b77\u3055\u308c\u3066\u3044\u306a\u3044AWS Lambda\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> AWS Lambda\u95a2\u6570\u306f\u3001\u9069\u5207\u306b\u4fdd\u8b77\u3055\u308c\u3066\u3044\u306a\u3044\u5834\u5408\u3001\u6a5f\u5bc6\u30c7\u30fc\u30bf\u3001\u74b0\u5883\u5909\u6570\u3001\u30a2\u30af\u30bb\u30b9\u30ad\u30fc\u3092\u516c\u958b\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001Lambda\u306e\u30b3\u30fc\u30c9\u3084\u6a29\u9650\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u3066\u3001\u4ed6\u306eAWS\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3057\u305f\u308a\u3001\u4e0d\u6b63\u306a\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u305f\u308a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u74b0\u5883\u5909\u6570\u3092\u5b89\u5168\u306b\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> Lambda\u306e\u74b0\u5883\u5909\u6570\u306b\u6a5f\u5bc6\u60c5\u5831\u3092\u4fdd\u5b58\u3057\u306a\u3044\u3088\u3046\u306b\u3057\u307e\u3057\u3087\u3046\u3002\u6a5f\u5bc6\u30c7\u30fc\u30bf\u306e\u4fdd\u5b58\u306b\u306fAWS Secrets Manager\u307e\u305f\u306fAWS Systems Manager Parameter Store\u3092\u4f7f\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u7d30\u304b\u3044 IAM \u30dd\u30ea\u30b7\u30fc\u3092\u5b9a\u7fa9\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> Lambda\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\u306b\u6700\u5c0f\u7279\u6a29IAM\u30dd\u30ea\u30b7\u30fc\u3092\u4f5c\u6210\u3057\u3001\u5fc5\u8981\u306a\u30ea\u30bd\u30fc\u30b9\u306e\u307f\u306b\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30ed\u30b0\u3068\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS CloudTrail\u3068Amazon CloudWatch Logs\u3092\u6709\u52b9\u306b\u3057\u3066\u3001Lambda\u95a2\u6570\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u76e3\u8996\u3057\u3001\u7570\u5e38\u3092\u691c\u51fa\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30e9\u30e0\u30c0\u306e\u4f9d\u5b58\u95a2\u4fc2\u3092\u5b9a\u671f\u7684\u306b\u66f4\u65b0\u3057\u3001\u30d1\u30c3\u30c1\u3092\u5f53\u3066\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u65e2\u77e5\u306e\u8106\u5f31\u6027\u306e\u60aa\u7528\u3092\u9632\u3050\u305f\u3081\u3001\u30e9\u30e0\u30c0\u95a2\u6570\u306e\u30e9\u30a4\u30d6\u30e9\u30ea\u3068\u4f9d\u5b58\u95a2\u4fc2\u3092\u5e38\u306b\u6700\u65b0\u306e\u72b6\u614b\u306b\u4fdd\u3064\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">5.\u516c\u958bRDS\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> Amazon Relational Database Service\uff08RDS\uff09\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306f\u3001\u4e0d\u9069\u5207\u306b\u8a2d\u5b9a\u3055\u308c\u308b\u3068\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u516c\u958b\u3055\u308c\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3084\u30c7\u30fc\u30bf\u6f0f\u6d29\u306e\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u8a2d\u5b9a\u3001\u8106\u5f31\u306a\u30d1\u30b9\u30ef\u30fc\u30c9\u3001\u8aa4\u3063\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u3092\u60aa\u7528\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30d1\u30d6\u30ea\u30c3\u30af\u30fb\u30a2\u30af\u30bb\u30b7\u30d3\u30ea\u30c6\u30a3\u3092\u7121\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u7d76\u5bfe\u306b\u5fc5\u8981\u306a\u5834\u5408\u3092\u9664\u304d\u3001RDS\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u304c\u4e00\u822c\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u306a\u3044\u3088\u3046\u306b\u3059\u308b\u3002\u4eee\u60f3\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8\u30af\u30e9\u30a6\u30c9\uff08VPC\uff09\u3092\u4f7f\u7528\u3057\u3066RDS\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u5206\u96e2\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u6697\u53f7\u5316\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u6a5f\u5bc6\u30c7\u30fc\u30bf\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001\u9759\u6b62\u6642\u306e\u30c7\u30fc\u30bf\uff08AWS KMS\uff09\u3068\u8ee2\u9001\u6642\u306e\u30c7\u30fc\u30bf\uff08SSL\/TLS\uff09\u306b\u6697\u53f7\u5316\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u5f37\u529b\u306a\u8a8d\u8a3c\u3092\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u5316\u3059\u308b\u305f\u3081\u306b\u3001\u5f37\u529b\u306a\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u5f37\u5236\u3057\u3001IAM\u8a8d\u8a3c\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u5b9a\u671f\u7684\u306a\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3068\u30b9\u30ca\u30c3\u30d7\u30b7\u30e7\u30c3\u30c8\uff1a<\/b><span style=\"font-weight: 400;\"> \u5b9a\u671f\u7684\u306b\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3092\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3057\u3001\u30b9\u30ca\u30c3\u30d7\u30b7\u30e7\u30c3\u30c8\u3092\u4f5c\u6210\u3059\u308b\u3053\u3068\u3067\u3001\u30c7\u30fc\u30bf\u640d\u5931\u3084\u7834\u640d\u6642\u306e\u5fa9\u65e7\u306b\u5099\u3048\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">6.\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306e\u8a2d\u5b9a\u30df\u30b9<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306f\u3001EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u4eee\u60f3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3068\u3057\u3066\u6a5f\u80fd\u3059\u308b\u3002\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9\u3084\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u306e\u30eb\u30fc\u30eb\u304c\u904e\u5ea6\u306b\u5bdb\u5bb9\u3067\u3042\u308b\u306a\u3069\u3001\u8a2d\u5b9a\u3092\u8aa4\u308b\u3068\u3001AWS\u30ea\u30bd\u30fc\u30b9\u304c\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u516c\u958b\u3055\u308c\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u3057\u3066\u3057\u307e\u3046\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u6700\u5c0f\u7279\u6a29\u3092\u5c0e\u5165\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30a4\u30f3\u30d0\u30a6\u30f3\u30c9\u3068\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3084\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u306b\u5fc5\u8981\u306a\u3082\u306e\u3060\u3051\u306b\u5236\u9650\u3057\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>IP\u30a2\u30c9\u30ec\u30b9\u306b\u3088\u308b\u30a2\u30af\u30bb\u30b9\u5236\u9650\uff1a<\/b><span style=\"font-weight: 400;\"> IP\u30db\u30ef\u30a4\u30c8\u30ea\u30b9\u30c8\u3092\u4f7f\u7528\u3057\u3066\u3001\u7279\u5b9a\u306e\u4fe1\u983c\u3067\u304d\u308bIP\u30a2\u30c9\u30ec\u30b9\u307e\u305f\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u3092\u5b9a\u671f\u7684\u306b\u898b\u76f4\u3057\u3001\u76e3\u67fb\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u69cb\u6210\u306e\u5b9a\u671f\u7684\u306a\u30ec\u30d3\u30e5\u30fc\u3092\u5b9f\u65bd\u3057\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306b\u6e96\u62e0\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>VPC\u30d5\u30ed\u30fc\u30ed\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> VPC\u30d5\u30ed\u30fc\u30ed\u30b0\u3092\u4f7f\u7528\u3057\u3066\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u30d1\u30bf\u30fc\u30f3\u3092\u76e3\u8996\u304a\u3088\u3073\u5206\u6790\u3057\u3001\u6f5c\u5728\u7684\u306a\u8a2d\u5b9a\u30df\u30b9\u3084\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u691c\u51fa\u3057\u307e\u3059\u3002<br \/><br \/><\/span><\/li><\/ul><\/li><\/ul><p><b style=\"background-color: transparent; text-align: var(--text-align);\">7.Elastic Load Balancer (ELB)\u306e\u60aa\u7528<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/b><span style=\"font-weight: 400;\"> AWS Elastic Load Balancers (ELB)\u306f\u3001\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u30b5\u30fc\u30d3\u30b9\u3092\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u3084\u5185\u90e8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u516c\u958b\u3059\u308b\u3088\u3046\u306b\u8aa4\u3063\u3066\u8a2d\u5b9a\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u5b89\u5168\u3067\u306a\u3044\u8a2d\u5b9a\u3092\u60aa\u7528\u3057\u3066\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5236\u5fa1\u3092\u56de\u907f\u3057\u305f\u308a\u3001\u5185\u90e8\u30ea\u30bd\u30fc\u30b9\u306b\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3057\u305f\u308a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u78ba\u4fdd\u3059\u308b\u65b9\u6cd5<\/b><ul><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u3092\u4f7f\u3063\u3066\u30a2\u30af\u30bb\u30b9\u3092\u5236\u5fa1\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> ELB\u304c\u3001\u5fc5\u8981\u306a\u30dd\u30fc\u30c8\u3068IP\u7bc4\u56f2\u306e\u307f\u306b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u5236\u9650\u3059\u308b\u9069\u5207\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>SSL\/TLS Termination\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u30ed\u30fc\u30c9\u30d0\u30e9\u30f3\u30b5\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u6697\u53f7\u5316\u3059\u308b\u305f\u3081\u306b\u3001ELB\u3067SSL\/TLS\u7d42\u7aef\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>ELB\u306e\u30ed\u30b0\u3092\u5b9a\u671f\u7684\u306b\u898b\u76f4\u3059\uff1a<\/b><span style=\"font-weight: 400;\"> ELB\u306e\u30a2\u30af\u30bb\u30b9\u30ed\u30b0\u3092\u6709\u52b9\u306b\u3057\u3066\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3067\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u306e\u8a66\u884c\u3092\u691c\u51fa\u3057\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u30d1\u30bf\u30fc\u30f3\u3092\u5206\u6790\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"2\"><b>\u30ec\u30a4\u30e4\u30fc7\u306e\u4fdd\u8b77\u306b\u306fAWS WAF\u3092\u4f7f\u7528\u3057\u307e\u3059\uff1a<\/b><span style=\"font-weight: 400;\"> AWS Web Application Firewall (WAF)\u306e\u5c0e\u5165\u306b\u3088\u308b\u4fdd\u8b77 <a href=\"https:\/\/www.carmatec.com\/ja\/%e3%82%a6%e3%82%a7%e3%83%96%e3%82%a2%e3%83%97%e3%83%aa%e3%82%b1%e3%83%bc%e3%82%b7%e3%83%a7%e3%83%b3%e9%96%8b%e7%99%ba\/\">\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3<\/a> SQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3084\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff08XSS\uff09\u306a\u3069\u306e\u4e00\u822c\u7684\u306a\u60aa\u7528\u304b\u3089\u3002<\/span><\/li><\/ul><\/li><\/ul><h3><b>AWS\u74b0\u5883\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9<\/b><\/h3><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u6700\u5c0f\u7279\u6a29\u306e\u539f\u5247\u3092\u5b9f\u884c\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30e6\u30fc\u30b6\u30fc\u3001\u30ed\u30fc\u30eb\u3001\u30b5\u30fc\u30d3\u30b9\u306b\u5fc5\u8981\u306a\u6a29\u9650\u306e\u307f\u306b\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30ed\u30b0\u3068\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS CloudTrail\u3001Amazon CloudWatch\u3001VPC Flow Logs\u3092\u4f7f\u7528\u3057\u3066\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u76e3\u8996\u3057\u3001\u7570\u5e38\u3092\u691c\u51fa\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u76e3\u67fb\u3092\u5b9a\u671f\u7684\u306b\u5b9f\u65bd\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u5b9a\u671f\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a55\u4fa1\u3001\u8106\u5f31\u6027\u30b9\u30ad\u30e3\u30f3\u3001\u4fb5\u5165\u30c6\u30b9\u30c8\u3092\u5b9f\u65bd\u3057\u3001\u6f5c\u5728\u7684\u306a\u5f31\u70b9\u3092\u7279\u5b9a\u3057\u3066\u4fee\u6b63\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>AWS Config\u3068GuardDuty\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u81ea\u52d5\u5316\uff1a<\/b><span style=\"font-weight: 400;\"> \u7d99\u7d9a\u7684\u306a\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u30c1\u30a7\u30c3\u30af\u306b\u306fAWS Config\u3092\u3001\u8105\u5a01\u306e\u691c\u77e5\u3068\u30a2\u30e9\u30fc\u30c8\u306b\u306fAWS GuardDuty\u3092\u4f7f\u7528\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u591a\u8981\u7d20\u8a8d\u8a3c\uff08MFA\uff09\u3092\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u3059\u3079\u3066\u306e\u30e6\u30fc\u30b6\u30fc\u3001\u7279\u306b\u7ba1\u7406\u8005\u307e\u305f\u306f\u7279\u6a29\u30a2\u30af\u30bb\u30b9\u3092\u6301\u3064 IAM \u30e6\u30fc\u30b6\u30fc\u306b MFA \u3092\u8981\u6c42\u3059\u308b\u3002<\/span><\/li><\/ul><h2><b>\u7d50\u8ad6<\/b><\/h2><p><span style=\"font-weight: 400;\">AWS\u30af\u30e9\u30a6\u30c9\u74b0\u5883\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u78ba\u4fdd\u3059\u308b\u306b\u306f\u3001\u5805\u7262\u306a\u69cb\u6210\u3001\u7d99\u7d9a\u7684\u306a\u76e3\u8996\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306e\u9075\u5b88\u3092\u7d44\u307f\u5408\u308f\u305b\u305f\u5305\u62ec\u7684\u306a\u30a2\u30d7\u30ed\u30fc\u30c1\u304c\u5fc5\u8981\u3067\u3059\u3002AWS\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u30c8\u30c3\u30d7\u3068\u305d\u306e\u9632\u5fa1\u65b9\u6cd5\u3092\u7406\u89e3\u3059\u308b\u3053\u3068\u3067\u3001\u30af\u30e9\u30a6\u30c9\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4f53\u5236\u3092\u5f37\u5316\u3057\u3001\u6f5c\u5728\u7684\u306a\u8105\u5a01\u304b\u3089\u30d3\u30b8\u30cd\u30b9\u3092\u4fdd\u8b77\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30af\u30e9\u30a6\u30c9\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306f\u5171\u6709\u8cac\u4efb\u3067\u3042\u308a\u3001\u91cd\u8981\u306a\u8cc7\u7523\u3068\u30c7\u30fc\u30bf\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u306f\u4e8b\u524d\u306e\u5bfe\u7b56\u304c\u4e0d\u53ef\u6b20\u3067\u3042\u308b\u3053\u3068\u3092\u5fd8\u308c\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002\u8a73\u3057\u304f\u306f <a href=\"https:\/\/www.carmatec.com\/ja\/\">\u30ab\u30fc\u30de\u30c6\u30c3\u30af<\/a>.<\/span><\/p><h3><b>\u3088\u304f\u3042\u308b\u8cea\u554f<\/b><\/h3><ol><li><b> \u653b\u6483\u8005\u304c\u4f7f\u7528\u3059\u308b\u6700\u3082\u4e00\u822c\u7684\u306aAWS\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3068\u306f\uff1f<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">\u6700\u3082\u4e00\u822c\u7684\u306aAWS\u306e\u60aa\u7528\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u304c\u3042\u308b\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>S3\u30d0\u30b1\u30c3\u30c8\u306e\u8a2d\u5b9a\u30df\u30b9\uff1a<\/b><span style=\"font-weight: 400;\"> \u4e00\u822c\u306b\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306aS3\u30d0\u30b1\u30c3\u30c8\u306f\u3001\u30c7\u30fc\u30bf\u6f0f\u6d29\u3084\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u306b\u3064\u306a\u304c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>IAM\u7279\u6a29\u306e\u30a8\u30b9\u30ab\u30ec\u30fc\u30b7\u30e7\u30f3\uff1a<\/b><span style=\"font-weight: 400;\"> \u904e\u5ea6\u306b\u5bdb\u5bb9\u306aIAM\u30ed\u30fc\u30eb\u3068\u30dd\u30ea\u30b7\u30fc\u306f\u3001\u7ba1\u7406\u8005\u30a2\u30af\u30bb\u30b9\u3092\u5f97\u308b\u305f\u3081\u306b\u60aa\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u306e\u643e\u53d6\uff1a<\/b><span style=\"font-weight: 400;\"> \u653b\u6483\u8005\u306f\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u3092\u7167\u4f1a\u3057\u3066\u3001IAM\u8a8d\u8a3c\u60c5\u5831\u3092\u76d7\u3080\u3053\u3068\u304c\u3067\u304d\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30bb\u30ad\u30e5\u30a2\u3067\u306a\u3044AWS Lambda\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\uff1a<\/b><span style=\"font-weight: 400;\"> \u5b89\u5168\u3067\u306a\u3044\u30e9\u30e0\u30c0\u95a2\u6570\u306f\u3001\u6a5f\u5bc6\u30c7\u30fc\u30bf\u3092\u516c\u958b\u3057\u305f\u308a\u3001\u4e0d\u6b63\u306a\u30b3\u30fc\u30c9\u5b9f\u884c\u3092\u8a31\u3057\u305f\u308a\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306e\u8a2d\u5b9a\u30df\u30b9\uff1a<\/b><span style=\"font-weight: 400;\"> \u904e\u5ea6\u306b\u5bdb\u5bb9\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30fb\u30b0\u30eb\u30fc\u30d7\u30fb\u30eb\u30fc\u30eb\u306f\u3001\u30ea\u30bd\u30fc\u30b9\u3092\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u306b\u3055\u3089\u3059\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><ol start=\"2\"><li><b> \u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u9632\u3050\u305f\u3081\u306bS3\u30d0\u30b1\u30c3\u30c8\u3092\u4fdd\u8b77\u3059\u308b\u306b\u306f\u3069\u3046\u3059\u308c\u3070\u3044\u3044\u3067\u3059\u304b\uff1f<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">S3\u30d0\u30b1\u30c3\u30c8\u3092\u4fdd\u8b77\u3059\u308b\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u4e00\u822c\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30d0\u30b1\u30c3\u30c8\u30ec\u30d9\u30eb\u3068\u30a2\u30ab\u30a6\u30f3\u30c8\u30ec\u30d9\u30eb\u306e\u4e21\u65b9\u3067\u3001\"Block Public Access \"\u8a2d\u5b9a\u3092\u6709\u52b9\u306b\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u6700\u5c0f\u7279\u6a29\u30a2\u30af\u30bb\u30b9\u30dd\u30ea\u30b7\u30fc\u3092\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> IAM \u30dd\u30ea\u30b7\u30fc\u3092\u8a2d\u5b9a\u3057\u3066\u3001\u7279\u5b9a\u306e\u30e6\u30fc\u30b6\u30fc\u307e\u305f\u306f\u30ed\u30fc\u30eb\u306b\u5fc5\u8981\u306a\u30a2\u30af\u30bb\u30b9\u306e\u307f\u3092\u8a31\u53ef\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Server-Side Encryption (SSE)\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> SSE \u3092\u4f7f\u7528\u3057\u3066\u9759\u6b62\u6642\u306e\u30c7\u30fc\u30bf\u3092\u6697\u53f7\u5316\u3057\u3001\u8ee2\u9001\u4e2d\u306e\u30c7\u30fc\u30bf\u306f HTTPS \u3067\u78ba\u5b9f\u306b\u6697\u53f7\u5316\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a2\u30af\u30bb\u30b9\u30ed\u30b0\u3092\u76e3\u8996\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30d0\u30b1\u30c3\u30c8\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u76e3\u8996\u30fb\u76e3\u67fb\u3059\u308b\u305f\u3081\u306b\u3001S3\u30a2\u30af\u30bb\u30b9\u30ed\u30ae\u30f3\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><ol start=\"3\"><li><b> IAM\u306e\u7279\u6a29\u6607\u683c\u653b\u6483\u3092\u9632\u3050\u306b\u306f\u3001\u3069\u306e\u3088\u3046\u306a\u5bfe\u7b56\u3092\u3068\u308c\u3070\u3088\u3044\u3067\u3057\u3087\u3046\u304b\uff1f<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">IAM \u6a29\u9650\u306e\u6607\u683c\u3092\u9632\u3050\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u6700\u5c0f\u7279\u6a29\u539f\u5247\u3092\u5c0e\u5165\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u304d\u3081\u7d30\u304b\u306aIAM\u30dd\u30ea\u30b7\u30fc\u3092\u5b9a\u7fa9\u3057\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u904e\u5ea6\u306b\u5bdb\u5bb9\u306a\u30ed\u30fc\u30eb\u3092\u907f\u3051\u308b\u3002 <\/span><span style=\"font-weight: 400;\">\u7ba1\u7406\u8005\u30a2\u30af\u30bb\u30b9<\/span><span style=\"font-weight: 400;\">.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u591a\u8981\u7d20\u8a8d\u8a3c\uff08MFA\uff09\u3092\u7fa9\u52d9\u4ed8\u3051\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u3059\u3079\u3066\u306e\u7279\u6a29\u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u30e6\u30fc\u30b6\u30fc\u306bMFA\u3092\u5b9f\u65bd\u3057\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u30ec\u30a4\u30e4\u30fc\u3092\u8ffd\u52a0\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>IAM \u30ed\u30fc\u30eb\u3068\u30dd\u30ea\u30b7\u30fc\u3092\u5b9a\u671f\u7684\u306b\u76e3\u67fb\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> IAM \u306e\u5f79\u5272\u3001\u30dd\u30ea\u30b7\u30fc\u3001\u6a29\u9650\u3092\u5b9a\u671f\u7684\u306b\u898b\u76f4\u3057\u3001\u66f4\u65b0\u3057\u3001\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u306b\u5f93\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>IAM\u6d3b\u52d5\u3092\u76e3\u8996\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS CloudTrail\u3068CloudWatch\u3092\u4f7f\u7528\u3057\u3066\u3001IAM\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8ffd\u8de1\u3057\u3001\u6f5c\u5728\u7684\u306a\u60aa\u7528\u3092\u691c\u51fa\u3059\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><ol start=\"4\"><li><b> EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u30e1\u30bf\u30c7\u30fc\u30bf\u306e\u643e\u53d6\u304b\u3089\u4fdd\u8b77\u3059\u308b\u306b\u306f\uff1f<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u30e1\u30bf\u30c7\u30fc\u30bf\u306e\u643e\u53d6\u304b\u3089\u4fdd\u8b77\u3059\u308b\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u30fb\u30e1\u30bf\u30c7\u30fc\u30bf\u30fb\u30b5\u30fc\u30d3\u30b9\u30fb\u30d0\u30fc\u30b8\u30e7\u30f32\uff08IMDSv2\uff09\u3092\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> IMDSv2\u306f\u30bb\u30c3\u30b7\u30e7\u30f3\u30d9\u30fc\u30b9\u306e\u30c8\u30fc\u30af\u30f3\u3092\u5fc5\u8981\u3068\u3057\u3001SSRF\uff08Server-Side Request Forgery\uff09\u653b\u6483\u306e\u30ea\u30b9\u30af\u3092\u4f4e\u6e1b\u3057\u307e\u3059\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306eIAM\u30ed\u30fc\u30eb\u3092\u5236\u9650\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u5fc5\u8981\u306a\u5834\u5408\u306b\u306e\u307fEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306bIAM\u30ed\u30fc\u30eb\u3092\u5272\u308a\u5f53\u3066\u3001\u95a2\u9023\u3059\u308b\u6a29\u9650\u3092\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30bb\u30b9\u3092\u5236\u5fa1\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30afACL\u3092\u4f7f\u7528\u3057\u3066\u3001EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u4fe1\u983c\u3067\u304d\u308bIP\u30a2\u30c9\u30ec\u30b9\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u307f\u306b\u5236\u9650\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>IAM \u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u3092\u5b9a\u671f\u7684\u306b\u30ed\u30fc\u30c6\u30fc\u30b7\u30e7\u30f3\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305fIAM\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u3092\u5b9a\u671f\u7684\u306b\u30ed\u30fc\u30c6\u30fc\u30b7\u30e7\u30f3\u3057\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u76d7\u96e3\u306e\u30ea\u30b9\u30af\u3092\u6700\u5c0f\u9650\u306b\u6291\u3048\u308b\u3002<br \/><br \/><\/span><\/li><\/ul><ol start=\"5\"><li><b> AWS Lambda\u95a2\u6570\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u3068\u306f\uff1f<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">AWS Lambda\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\u3092\u4fdd\u8b77\u3059\u308b\uff1a<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u74b0\u5883\u5909\u6570\u3092\u5b89\u5168\u306b\u4f7f\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u6a5f\u5bc6\u60c5\u5831\u3092\u74b0\u5883\u5909\u6570\u306b\u76f4\u63a5\u4fdd\u5b58\u3059\u308b\u3053\u3068\u306f\u907f\u3051\u3066\u304f\u3060\u3055\u3044\u3002\u6a5f\u5bc6\u30c7\u30fc\u30bf\u306b\u306fAWS Secrets Manager\u307e\u305f\u306fAWS Systems Manager Parameter Store\u3092\u4f7f\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>IAM \u30ed\u30fc\u30eb\u306b\u6700\u5c0f\u7279\u6a29\u3092\u9069\u7528\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> \u304d\u3081\u7d30\u304b\u3044IAM\u30dd\u30ea\u30b7\u30fc\u3092\u4f5c\u6210\u3057\u3001Lambda\u95a2\u6570\u304c\u30a2\u30af\u30bb\u30b9\u3059\u308b\u5fc5\u8981\u306e\u3042\u308b\u30ea\u30bd\u30fc\u30b9\u306e\u307f\u306b\u5236\u9650\u3092\u304b\u3051\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30ed\u30b0\u3068\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0\u3092\u6709\u52b9\u306b\u3059\u308b\uff1a<\/b><span style=\"font-weight: 400;\"> AWS CloudTrail\u3068CloudWatch Logs\u3092\u4f7f\u7528\u3057\u3066\u3001Lambda\u95a2\u6570\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u76e3\u8996\u3057\u3001\u7570\u5e38\u3092\u691c\u51fa\u3059\u308b\u3002<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u30e9\u30e0\u30c0\u306e\u4f9d\u5b58\u95a2\u4fc2\u3092\u66f4\u65b0\u3057\u7d9a\u3051\u308b<\/b><span style=\"font-weight: 400;\"> \u30e9\u30e0\u30c0\u30fb\u30e9\u30a4\u30d6\u30e9\u30ea\u3068\u4f9d\u5b58\u95a2\u4fc2\u3092\u5b9a\u671f\u7684\u306b\u66f4\u65b0\u3057\u3001\u65e2\u77e5\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3055\u308c\u308b\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3059\u308b\u3002<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>What is AWS? Amazon Web Services (AWS) is one of the most popular cloud platforms, powering millions of applications worldwide. While AWS offers robust security features, the shared responsibility model means that securing your cloud environment is a joint effort between\u00a0 AWS and its users. AWS secures the infrastructure, but it\u2019s up to you to [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":42300,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-42288","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/posts\/42288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/comments?post=42288"}],"version-history":[{"count":0,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/posts\/42288\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/media\/42300"}],"wp:attachment":[{"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/media?parent=42288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/categories?post=42288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.carmatec.com\/ja\/wp-json\/wp\/v2\/tags?post=42288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}