æ©å¯æ§ã®é«ã顧客æ
å ±ãæ±ãäŒæ¥ã«ãšã£ãŠãSOCïŒã·ã¹ãã ããã³çµç¹ç®¡çïŒ2ã³ã³ãã©ã€ã¢ã³ã¹ã®éæã¯åãªãæšå¥šäºé
ã§ã¯ãªããå€ãã®å Žåãå¿
èŠäžå¯æ¬ ã§ããSOC2ã¯ãç±³åœå
¬èªäŒèšå£«åäŒïŒAICPAïŒãçå®ãã峿 Œãªç£æ»åºæºã§ããããµãŒãã¹çµç¹ã®ã»ãã¥ãªãã£ãå¯çšæ§ãåŠçã®å®å
šæ§ãæ©å¯æ§ããã©ã€ãã·ãŒã«é¢ãã管çäœå¶ãè©äŸ¡ããŸãã
SOC2ã¯æ³ç矩åã§ã¯ãããŸãããããã¥ãŒã¹ã§é »ç¹ã«å ±ããããæ
å ±æŒæŽ©äºä»¶ã®åœ±é¿ããããéèŠæ§ãé«ãŸã£ãŠããŸããSOC2ã³ã³ãã©ã€ã¢ã³ã¹ãéæããããšã§ã顧客ããŒã¿ãé©åã«ä¿ç®¡ãã第äžè
ã«ããã»ãã¥ãªãã£ç®¡çã®è©äŸ¡ãåããŠããããšãäŒããã顧客ããã®ä¿¡é ŒãåŸãããŸãã
æ¬ã¬ã€ãã§ã¯ãSOC2ã³ã³ãã©ã€ã¢ã³ã¹ã®èŠä»¶ã解説ããGitLabãã©ã®ããã«çµç¹ã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®æé«æ°Žæºã®éæã«åœ¹ç«ã€ããã玹ä»ããŸãã
SOC 2ã§å®ããããŠããèŠä»¶
SOC2ã³ã³ãã©ã€ã¢ã³ã¹ãéæããã«ã¯ãç¬ç«ããç£æ»æ
åœè
ã«ããç£æ»ãå¿
èŠãšãªããŸããç£æ»ã§ã¯ãçµç¹ã®ç®¡çäœå¶ã®èšèšããã³éçšã®æå¹æ§ãè©äŸ¡ããŸããç£æ»ããã»ã¹ã¯éåžžã«ã³ã¹ãããããããšãå€ããå€ãã®çµç¹ã¯ç£æ»åã®æºåãååã«è¡ããŠããªãã®ãçŸç¶ã§ããéåžžãSOC2ç£æ»ã¯çŽ1幎ãèŠãããããå¹ççãªäºåç£æ»ããã»ã¹ã確ç«ããããšãéèŠã§ãã
SOC2ã³ã³ãã©ã€ã¢ã³ã¹ãéæããã«ã¯ãçµç¹ã¯ä»¥äžã®ãã©ã¹ããµãŒãã¹èŠæºã«åºã¥ãèŠä»¶ãæºããå¿
èŠããããŸãã
| èŠæº |
èŠä»¶ |
| ã»ãã¥ãªã㣠|
- äžæ£ã¢ã¯ã»ã¹ãé²ãããã®ç®¡ççã宿œ - ãªã¹ã¯ã®ç¹å®ãšè»œæžã®ããã®æé ãç¢ºç« - ã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€ç¥ããã³å¯Ÿå¿ããããã®ã·ã¹ãã ãæ§ç¯ |
| å¯çšæ§ |
- åæããããšããã«ã·ã¹ãã ã®çšŒåãä¿èšŒ - çŸåšã®äœ¿çšç¶æ³ãšå®¹éãã¢ãã¿ãªã³ã° - ã·ã¹ãã å¯çšæ§ã«åœ±é¿ãäžãããç°å¢ãªã¹ã¯ãç¹å®ã»å¯ŸåŠ |
| åŠçã®å®å
šæ§ |
- ã·ã¹ãã ã®å
¥åã»åºåã®æ£ç¢ºãªèšé²ãç¶æ - ã·ã¹ãã ãšã©ãŒãè¿
éã«ç¹å®ãä¿®æ£ããæé ã宿œ - 補åã»ãµãŒãã¹ã仿§ãæºããããåŠçäœæ¥ãå®çŸ© |
| æ©å¯æ§ |
- æ©å¯æ
å ±ãç¹å®ãä¿è· - ããŒã¿ä¿ææéã®ããªã·ãŒãçå® - ä¿ææéçµäºåŸãæ©å¯ããŒã¿ãå®å
šã«ç Žæ£ããæ¹æ³ãç¢ºä¿ |
| ãã©ã€ãã·ãŒ |
- æ©å¯å人æ
å ±ãåéããåã«åæãååŸ - ãã©ã€ãã·ãŒããªã·ãŒãæç¢ºãã€ããããããäŒé - æ³çææ®µãéããŠä¿¡é Œã§ããæ
å ±æºããã®ã¿ããŒã¿ãåé |
ãªãããããã®èŠä»¶ã¯äžåºŠéæããã°çµããã§ã¯ãªããç¶ç¶çã«æºæ ããå¿
èŠããããŸããç£æ»æ
åœè
ã¯äžå®æéã«ããã管ççã®æå¹æ§ã®æç¡ãè©äŸ¡ããŸãã
## ã»ãã¥ãªãã£èŠä»¶ãæºãããç¶æããæ¹æ³
GitLabã«ã¯ãSOC2ã®ã»ãã¥ãªãã£èŠä»¶ãæºããããã«ããã«æŽ»çšã§ããæ©èœãæ°å€ãçšæãããŠããŸãã
| ã»ãã¥ãªãã£èŠä»¶ | å¯Ÿå¿æ©èœ | | :---- | :---- | | äžæ£ã¢ã¯ã»ã¹ãé²ãããã®ç®¡ççã宿œ | - éå
¬éã®ã€ã·ã¥ãŒïŒããŒãžãªã¯ãšã¹ã
- ã«ã¹ã¿ã ããŒã«ãšãã现ããæš©éèšå®
- ã»ãã¥ãªãã£ããªã·ãŒ
- æ€èšŒæžã¿ã³ããã
- ã³ã³ããã€ã¡ãŒãžã®çœ²å
- CodeOwners
- ä¿è·ãã©ã³ã | | ã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€ç¥ããã³å¯Ÿå¿ããããã®ã·ã¹ãã ãæ§ç¯ | - è匱æ§ã¹ãã£ã³
- ããŒãžãªã¯ãšã¹ãå
ã»ãã¥ãªãã£ãŠã£ãžã§ãã
- è匱æ§ã€ã³ãµã€ãã³ã³ãã©ã€ã¢ã³ã¹ã»ã³ã¿ãŒ
- ç£æ»ã€ãã³ã
-è匱æ§ã¬ããŒãäŸåé¢ä¿ãªã¹ã
- AIã«ããè匱æ§ã®èª¬æ
- AIã«ããè匱æ§ã®ä¿®æ£ | | ãªã¹ã¯ã®ç¹å®ãšè»œæžã®ããã®æé ãç¢ºç« | äžèšãã¹ãŠã®ããŒã«ã掻çšããŠãã»ãã¥ãªãã£ããŒã ãè匱æ§çºèŠæã®å¯Ÿå¿ããã³è»œæžæé ã確ç«ã§ããŸã |
ããã§ã¯ãåèŠä»¶ã«å¯Ÿå¿ããã»ãã¥ãªãã£æ©èœã«ã€ããŠããã«è©³ãã解説ããŸãããããªããäžèšã®ã»ãšãã©ã®æ©èœã¯ã[GitLab Ultimateãã©ã³ã®ãµãã¹ã¯ãªãã·ã§ã³](https://about.gitlab.com/ja-jp/free-trial/)ããã³é©åãªããŒã«ãšæš©éèšå®ãå¿
èŠãšãªããŸãã詳现ã«ã€ããŠã¯ã該åœããããã¥ã¡ã³ããã確èªãã ããã
## äžæ£ã¢ã¯ã»ã¹ããä¿è·ããããã®å¶åŸ¡ã®å®è£
çµç¹ã®è³ç£ãä¿è·ããŠãèŠå¶éµå®ãéæããæ¥åã®ç¶ç¶æ§ãç¶æããä¿¡é Œãç¯ãããã«ã¯ã匷åºãªã¢ã¯ã»ã¹å¶åŸ¡ã®å®è£
ãäžå¯æ¬ ã§ããGitLabã§ã¯ã[æå°æš©éã®åå](https://about.gitlab.com/blog/the-ultimate-guide-to-least-privilege-access-with-gitlab/)ã«åŸã£ãã¢ã¯ã»ã¹å¶åŸ¡ãå®è£
ã§ããäžæ£ã¢ã¯ã»ã¹ããã®ä¿è·ãå®çŸããŸããããã§ã¯ä»¥äžã®é
ç®ã«ã€ããŠç°¡åã«ç޹ä»ããŸãã
* [ã»ãã¥ãªãã£ããªã·ãŒ](#security-policies)
* [ã«ã¹ã¿ã ããŒã«ãšãã现ããæš©éèšå®](#custom-roles-and-granular-permissions)
* [ãã©ã³ãä¿è·ãšCodeOwners](#branch-protections-and-codeowners)
* [æ€èšŒæžã¿ã³ããã](#verified-commits)
### ã»ãã¥ãªãã£ããªã·ãŒ
GitLabã®ã»ãã¥ãªãã£ããªã·ãŒïŒããããã¬ãŒãã¬ãŒã«ïŒã䜿çšãããšãã»ãã¥ãªãã£ããã³ã³ã³ãã©ã€ã¢ã³ã¹ããŒã ã¯çµç¹å
šäœã§äžè²«ããå¶åŸ¡ãå®è£
ã§ããŸããããã«ãããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®äºé²ãã³ã³ãã©ã€ã¢ã³ã¹åºæºã®ç¶æãäžæ¬ã§ã®ãã¹ããã©ã¯ãã£ã¹ã®èªåé©çšã«ãããªã¹ã¯ã®äœæžãå¯èœã«ãªããŸãã

ããŒãžãªã¯ãšã¹ãæ¿èªããªã·ãŒã®æŽ»çšäŸ
以äžã®ãããªããªã·ãŒãå©çšã§ããŸãã
* ã¹ãã£ã³å®è¡ããªã·ãŒïŒãã€ãã©ã€ã³ã®äžéšãšããŠããŸãã¯æå®ããã¹ã±ãžã¥ãŒã«ã«å¿ããŠã»ãã¥ãªãã£ã¹ãã£ã³ã®å®è¡ã匷å¶
* ããŒãžãªã¯ãšã¹ãæ¿èªããªã·ãŒïŒã¹ãã£ã³çµæã«åºã¥ããŠããããžã§ã¯ãã¬ãã«ã®èšå®ãæ¿èªã«ãŒã«ãé©çš
* ãã€ãã©ã€ã³å®è¡ããªã·ãŒïŒãããžã§ã¯ããã€ãã©ã€ã³å
ã§CI/CDãžã§ãã®å®è¡ã匷å¶
* è匱æ§ç®¡çããªã·ãŒïŒè匱æ§ã®å¯Ÿå¿ã¯ãŒã¯ãããŒãèªåå
以äžã«ããã€ãã©ã€ã³å®è¡ããªã·ãŒã掻çšããŠã³ã³ãã©ã€ã¢ã³ã¹ã確ä¿ããäŸãã玹ä»ããŸãã
1. è€æ°ã®ã³ã³ãã©ã€ã¢ã³ã¹ãžã§ãããŸãšãããããžã§ã¯ããäœæããŸããããšãã°ããããã€ããããã¡ã€ã«ã®æš©éã確èªãããžã§ããå«ããŸãããããã®ãžã§ãã¯ãè€æ°ã®ã¢ããªã±ãŒã·ã§ã³ã§åå©çšã§ããããã«æ±çšçãªå
容ã«ããŠãããŸãã
2. ãã®ãããžã§ã¯ããžã®æš©éã¯ã»ãã¥ãªãã£ïŒã³ã³ãã©ã€ã¢ã³ã¹æ
åœè
ã«éå®ããããããããŒããžã§ããåé€ã§ããªãããã«ããŸããããã«ããè·ååé¢ãå®çŸããŸãã
3. 察象ã®ãããžã§ã¯ãã«ãããã®ã³ã³ãã©ã€ã¢ã³ã¹ãžã§ããäžæ¬ã§æ¿å
¥ããŸãããžã§ããå¿
ãå®è¡ããããã匷å¶ãã€ã€ãéçºã®åŠšãã«ãªããªãããã«ããŒã ãªãŒããŒãå®è¡ãæ¿èªã§ããããã«ããŸããããã«ãããã³ã³ãã©ã€ã¢ã³ã¹ãžã§ããåžžã«å®è¡ãããããããããŒã«ãã£ãŠåé€ãããããšããªããªãããå©çšã®ç°å¢ã«ãŠåžžã«ã³ã³ãã©ã€ã¢ã³ã¹ã確ä¿ãããããã«ãªããŸãã
> ##### ã»ãã¥ãªãã£ããªã·ãŒã®äœææ¹æ³ã«ã€ããŠã¯ãGitLabã®[ã»ãã¥ãªãã£ããªã·ãŒã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/application_security/policies/)ãã芧ãã ããã
### ã«ã¹ã¿ã ããŒã«ãšè©³çŽ°ãªæš©é
GitLabã®ã«ã¹ã¿ã æš©éã䜿çšãããšãæšæºã®ããŒã«ããŒã¹ã®æš©éã§ã¯ã§ããªããã现ããã¢ã¯ã»ã¹å¶åŸ¡ãå®è£
ã§ããŸããããã«ããã以äžã®ãããªå©ç¹ãåŸãããŸãã
* ããæ£ç¢ºãªã¢ã¯ã»ã¹å¶åŸ¡
* ã»ãã¥ãªãã£ã³ã³ãã©ã€ã¢ã³ã¹ã®åäž
* 誀ã£ãã¢ã¯ã»ã¹ã®ãªã¹ã¯è»œæž
* ãŠãŒã¶ãŒç®¡çã®å¹çå
* è€éãªçµç¹æ§é ãžã®å¯Ÿå¿

ããŒã«ãšæš©éã®èšå®ïŒã«ã¹ã¿ã ããŒã«ãå«ãïŒ
> ##### [ã«ã¹ã¿ã ããŒã«ã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/custom_roles.html)ãåç
§ããŠããã现ããªæš©éãèšå®ã§ããã«ã¹ã¿ã ããŒã«ã®äœææ¹æ³ãã確èªãã ããã
### ãã©ã³ãä¿è·ãšCodeOwners
GitLabã§ã¯ã次ã®2ã€ã®äž»èŠãªæ©èœã«ãããã³ãŒãã«å€æŽãå ãããããŠãŒã¶ãŒãããã«å³å¯ã«ç®¡çã§ããŸãã
* ãã©ã³ãä¿è·ïŒå€æŽãããŒãžããåã«æ¿èªãå¿
é ãšãããªã©ãç¹å®ã®ãã©ã³ãã倿Žã§ãããŠãŒã¶ãŒã«é¢ããã«ãŒã«ãèšå®ã§ããŸãã
* CodeOwnersïŒåãã¡ã€ã«ãæå®ãããææè
ã«é¢é£ä»ãã該åœãã¡ã€ã«ã倿Žãããéã«èªåçã«é©åãªã¬ãã¥ã¢ãŒãæå®ããŸãã
ãããã®æ©èœãçµã¿åãããããšã§ãé©åãªæ
åœè
ãã¬ãã¥ãŒã»æ¿èªãè¡ãäœå¶ãæ§ç¯ã§ããã³ãŒãã®ã»ãã¥ãªãã£ãšå質ãé«ãæ°Žæºã§ç¶æã§ããŸãã

ä¿è·ãã©ã³ãã®èšå®
> ##### ä¿è·ãã©ã³ããšCodeOwnersã®èšå®æ¹æ³ã«ã€ããŠã¯ã[ä¿è·ãã©ã³ã](https://docs.gitlab.com/ee/user/project/repository/branches/protected.html)ããã³[CodeOwner](https://docs.gitlab.com/ee/user/project/codeowners/)ã®ããŒãžããåç
§ãã ããã
### æ€èšŒæžã¿ã³ããã
ã³ãããã«ããžã¿ã«çœ²åã远å ããããšã§ããªãããŸãã§ã¯ãªããæ¬åœã«èªåãäœæãããã®ã§ããããšã蚌æã§ããŸããããžã¿ã«çœ²åã¯ãèªåã ããçºè¡ã§ãããé»åå°éãã®ãããªãã®ã§ããGitLabã«å
¬éGPGéµãç»é²ããã°ã眲åãæ£ãããã確èªã§ãããããããã°ãã®ã³ãããã«ã¯`Verified`ïŒæ€èšŒæžã¿ïŒã®ããŒã¯ãä»ããŸããããã«ãæªçœ²åã®ã³ããããæåŠããããæ¬äººç¢ºèªãã§ããŠããªããŠãŒã¶ãŒã®ã³ãããããããã¯ãããããã«ãŒã«ãèšå®å¯èœã§ãã

æ€èšŒæžã¿çœ²åä»ãã³ããã
ã³ãããã«ã¯ä»¥äžã®æ¹æ³ã§çœ²åã§ããŸãã
* SSHéµ
* GPGéµ
* å人çšx.509èšŒææž
> ##### æ€èšŒæžã¿ã³ãããã®è©³çްã¯ã[眲åä»ãã³ãããã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/project/repository/signed_commits/)ãã芧ãã ããã
## ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®æ€åºãšå¯Ÿå¿ã®ããã®ã·ã¹ãã ã®æ§ç¯
匷åºãªã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®ç¶æãèŠå¶éµå®ã®ç¢ºä¿ãè¢«å®³ã®æå°åãå€åãç¶ããè
åšãžã®è¿
éãªå¯Ÿå¿ã«ã¯ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€ç¥ã察å¿ããã·ã¹ãã ã®æ§ç¯ãäžå¯æ¬ ã§ãã
GitLabã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã©ã€ããµã€ã¯ã«å
šäœã察象ãšããã»ãã¥ãªãã£ã¹ãã£ã³ãšè匱æ§ç®¡çæ©èœãåãã£ãŠããŸãã以äžã®æ©èœã«ã€ããŠç°¡åã«èª¬æããŸãã
* [ã»ãã¥ãªãã£ã¹ãã£ã³ãšè匱æ§ç®¡ç](#security-scanning-and-vulnerability-management)
* [ãœãããŠã§ã¢éšå衚ïŒSBOMïŒ](#software-bill-of-materials)
* [ã·ã¹ãã ç£æ»ãšã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®ã¬ãã¥ãŒ](#system-auditing-and-security-posture-review)
* [ã³ã³ãã©ã€ã¢ã³ã¹ããã³ã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®ç£èŠ](#compliance-and-security-posture-oversight)
### ã»ãã¥ãªãã£ã¹ãã£ã³ãšè匱æ§ç®¡ç
GitLabã«ã¯ä»¥äžã®ãããªå€æ§ãªã»ãã¥ãªãã£ã¹ãã£ããŒãåãã£ãŠãããã¢ããªã±ãŒã·ã§ã³ã®ã©ã€ããµã€ã¯ã«å
šäœãã«ããŒããŸãã
* éçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒSASTïŒ
* åçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒDASTïŒ
* ã³ã³ããã¹ãã£ã³
* äŸåé¢ä¿ã¹ãã£ã³
* Infrastructure as CodeïŒIaCïŒã¹ãã£ã³
* ã«ãã¬ããžã¬ã€ããã¡ãžã³ã°
* Web APIãã¡ãžã³ã°
ãããã®ã¹ãã£ããŒã¯ãã³ãã¬ãŒããå©çšããã°ããã€ãã©ã€ã³ã«è¿œå ã§ããŸããããšãã°ããã¹ãã¹ããŒãžã§SASTãšäŸåé¢ä¿ã¹ãã£ã³ã®ãžã§ããå®è¡ããã«ã¯ã.gitlab-ci.ymlã«ä»¥äžã远å ããŸãã
```yaml
stages: - test
include: - template: Jobs/Dependency-Scanning.gitlab-ci.yml - template: Jobs/SAST.gitlab-ci.yml ```
ãããã®ãžã§ãã¯ç°å¢å€æ°ãGitLabãžã§ãæ§æã䜿ã£ãŠãã¹ãŠèšå®å¯èœã§ãããã€ãã©ã€ã³ãèµ·åãããšãã»ãã¥ãªãã£ã¹ãã£ããŒãåäœããçŸåšã®ãã©ã³ããšã¿ãŒã²ãããã©ã³ãã®å·®åããè匱æ§ãæ€åºããŸããæ€åºãããè匱æ§ã¯ããŒãžãªã¯ãšã¹ãïŒMRïŒå
ã§ç¢ºèªã§ããã³ãŒããã¿ãŒã²ãããã©ã³ãã«ããŒãžãããåã«çްéšãŸã§ç£èŠããå¿
èŠããããŸããMRã«ã¯è匱æ§ã«é¢ããŠä»¥äžã®æ
å ±ã衚瀺ãããŸãã
* 説æ
* ã¹ããŒã¿ã¹
* é倧床
* 蚌æ
* èå¥å
* URLïŒè©²åœããå ŽåïŒ
* ãªã¯ãšã¹ãïŒã¬ã¹ãã³ã¹ïŒè©²åœããå ŽåïŒ
* åçŸçšè³ç£ïŒè©²åœããå ŽåïŒ
* ãã¬ãŒãã³ã°æ
å ±ïŒè©²åœããå ŽåïŒ
* ã³ãŒããããŒïŒé«åºŠãªSASTäœ¿çšæïŒ

è匱æ§ã玹ä»ããMRã®è¡šç€ºç»é¢
ããããããŒã¯ãããã®æ
å ±ãæŽ»çšããŠãã»ãã¥ãªãã£ããŒã ã®ã¯ãŒã¯ãããŒã劚ããããšãªãè匱æ§ãä¿®æ£ã§ããŸããããããããŒã¯ãã¬ãã¥ãŒããã»ã¹ã«ãããæéãççž®ããããã«ãçç±ãæ·»ããŠè匱æ§ãç¡èŠãããããããã¯è匱æ§ã远跡ããããã®éå
¬éã€ã·ã¥ãŒãäœæãããããããšãå¯èœã§ãã
ããŒãžãªã¯ãšã¹ãã®ã³ãŒããããã©ã«ããã©ã³ãïŒéåžžã¯æ¬çªç°å¢ã¬ãã«ïŒã«ããŒãžããããšãè匱æ§ã¬ããŒãã«ã»ãã¥ãªãã£ã¹ãã£ããŒã®çµæãåæ ãããŸããã»ãã¥ãªãã£ããŒã ã¯ãããã®çµæãããšã«ãæ¬çªç°å¢ã§èŠã€ãã£ãè匱æ§ã®ç®¡çã»ããªã¢ãŒãžãè¡ããŸãã

ãããã¹ããŒã¿ã¹èšå®ã衚瀺ãããè匱æ§ã¬ããŒã
è匱æ§ã¬ããŒãå
ã®è匱æ§ã®èª¬æãã¯ãªãã¯ãããšãMRãšåãè匱æ§ããŒã¿ã衚瀺ãããè匱æ§ããŒãžã«ç§»åããŸãããããã®æ
å ±ã¯ã圱é¿è©äŸ¡ãä¿®æ£äœæ¥ã®éã«ä¿¡é Œã§ããå¯äžã®æ
å ±æºãšããŠæŽ»çšã§ããŸããè匱æ§ããŒãžã§ã¯ã[GitLab Duo](https://about.gitlab.com/ja-jp/gitlab-duo/)ã®AIæ©èœã䜿ã£ãŠè匱æ§ã®èª¬æãçæããããä¿®æ£ã®ããã®MRãäœæãããããŠã解決ãŸã§ã®æéãççž®ã§ããŸãã
> ##### GitLabã«å«ãŸããã»ãã¥ãªãã£ã¹ãã£ããŒãè匱æ§ç®¡çã®è©³çްã¯ã[ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/application_security/)ãã芧ãã ããã
### ãœãããŠã§ã¢éšå衚
GitLabã¯ãœãããŠã§ã¢ã§äœ¿çšãããŠããã³ã³ããŒãã³ãïŒéšåïŒã®è©³çްããªã¹ãåã§ããŸããããã¯ã³ãŒãã®ãææè¡šãã®ãããªãã®ã§ããœãããŠã§ã¢éšå衚ïŒ[SBOM](https://about.gitlab.com/ja-jp/blog/the-ultimate-guide-to-sboms/)ïŒãšåŒã°ããŸãããããžã§ã¯ãã§äœ¿ãããŠããå€éšã³ãŒãã«é¢ããŠãçŽæ¥äœ¿ãããŠããã³ãŒããããããäŸåããã³ãŒããå«ãããã¹ãŠãææ¡ã§ããŸããåé
ç®ã«ã€ããŠã䜿çšããŒãžã§ã³ãã©ã€ã»ã³ã¹æ
å ±ãæ¢ç¥ã®ã»ãã¥ãªãã£åé¡ã®æç¡ã衚瀺ãããŸããããã«ãããèªç€Ÿã®ãœãããŠã§ã¢ã®æ§æãææ¡ããæœåšçãªãªã¹ã¯ãèŠã€ãããããªããŸãã

ã°ã«ãŒãã¬ãã«ã®äŸåé¢ä¿ãªã¹ãïŒSBOMïŒ
> ##### äŸåé¢ä¿ãªã¹ãã®ã¢ã¯ã»ã¹æ¹æ³ãšæŽ»çšæ³ã¯ã[äŸåé¢ä¿ãªã¹ãã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/application_security/dependency_list/)ããåç
§ãã ããã
### ã·ã¹ãã ç£æ»ãšã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®ã¬ãã¥ãŒ
GitLabã¯ã誰ããã€äœã倿Žããããªã©ãã·ã¹ãã å
ã®ãã¹ãŠã®åããèšé²ããŸããã³ãŒããç£èŠããã»ãã¥ãªãã£ã«ã¡ã©ã®ãããªãã®ã ãšèããŠãã ãããããã«ããã以äžãå¯èœã«ãªããŸãã
* äžå¯©ãªåããçºèŠãã
* èŠå¶åœå±ã«ã«ãŒã«éµå®ã蚌æãã
* åé¡ãçºçããéã«ç¶æ³ãææ¡ãã
* GitLabã®å©çšç¶æ³ãææ¡ãã
ãããã®æ
å ±ã¯äžå
管çãããŠãããããå¿
èŠã«å¿ããŠå®¹æã«ç¢ºèªã»èª¿æ»ã§ããŸããããšãã°ãç£æ»ã€ãã³ãã䜿ããšä»¥äžã®æ
å ±ã远跡ã§ããŸãã
* GitLabãããžã§ã¯ãã«ãããŠã誰ããã€ç¹å®ãŠãŒã¶ãŒã®æš©éã¬ãã«ã倿Žããã
* 誰ããã€æ°ãããŠãŒã¶ãŒã远å ãŸãã¯åé€ããã

ãããžã§ã¯ãã¬ãã«ã®ç£æ»ã€ãã³ã
> ##### ç£æ»ã€ãã³ãã®è©³çްã«ã€ããŠã¯ã[ç£æ»ã€ãã³ãã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/compliance/audit_events.html)ãã芧ãã ããã
## ã³ã³ãã©ã€ã¢ã³ã¹ãšã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®ç£èŠ
GitLabã®ã»ãã¥ãªãã£ããã·ã¥ããŒãã¯ããã¹ãŠã®ã»ãã¥ãªãã£ãªã¹ã¯ã1ãæã§è¡šç€ºãããã³ã³ãããŒã«ã«ãŒã ãã®ãããªæ©èœã§ããè€æ°ã®ã»ãã¥ãªãã£ããŒã«ãåå¥ã«ç¢ºèªããå¿
èŠã¯ãªããå
šãããžã§ã¯ãã®èª¿æ»æ
å ±ã1ã€ã®ç»é¢ã§ãŸãšããŠææ¡ã§ããŸããããã«ããããããžã§ã¯ãã«æœãåé¡ã®æ©æçºèŠãšè¿
éãªå¯Ÿå¿ãå¯èœã«ãªããŸãã

ã°ã«ãŒãã¬ãã«ã®ã»ãã¥ãªãã£ããã·ã¥ããŒã
> ##### ã»ãã¥ãªãã£ããã·ã¥ããŒãã®è©³çްã«ã€ããŠã¯ã[ã»ãã¥ãªãã£ããã·ã¥ããŒãã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/application_security/security_dashboard/)ãã芧ãã ããã
## ãªã¹ã¯ãç¹å®ãã軜æžããããã®æé ã®ç¢ºç«
è匱æ§ã«ã¯ç¹å®ã®ã©ã€ããµã€ã¯ã«ããããŸããããšãã°ãã»ãã¥ãªãã£ããªã·ãŒã䜿ã£ãŠãè匱ãªã³ãŒããä¿è·ãã©ã³ãã«ããŒãžããã«ã¯æ¿èªãå¿
èŠãšããæç¶ããèšããããšãã§ããŸããããã«ãæ¬çªç°å¢ã§è匱ãªã³ãŒããæ€åºãããå Žåãåªå
çã«å¯Ÿå¿ããè©äŸ¡ã»ä¿®æ£ã»æ€èšŒãè¡ããšããæµããå®ããããšãå¯èœã§ãã
* åªå
é äœã¯ãGitLabã®ã¹ãã£ããŒã«ãã£ãŠæäŸãããè匱æ§ã®é倧床ã«åºã¥ããŠæ±ºããããŸãã
* è©äŸ¡ã¯ãAIã«ããè匱æ§ã®èª¬ææ©èœãæäŸããæªçšã®è©³çްæ
å ±ã䜿ã£ãŠè¡ããŸãã
* ä¿®æ£åŸã¯ãGitLabã«çµã¿èŸŒãŸããååž°ãã¹ããã¹ãã£ããŒã䜿çšããŠæ€èšŒã§ããŸãã
ãã¹ãŠã®çµç¹ã«å
±éã®å¯Ÿå¿çã¯ãããŸããããGitLabã®ãããªçµ±åãã©ãããã©ãŒã ãæŽ»çšããããšã§ãè€æ°ã®ç°ãªãããŒã«ã䜿ãå Žåãšæ¯ã¹ãŠããªã¹ã¯ããã°ããææ¡ã»å¯ŸåŠã§ãããªã¹ã¯å
šäœãäœæžããããšãå¯èœã§ãã
### SOC 2ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ãããã¹ããã©ã¯ãã£ã¹
* 匷åºãªã»ãã¥ãªãã£æåã確ç«ããïŒçµç¹å
šäœã§ã»ãã¥ãªãã£ãžã®æèãšè²¬ä»»æãé«ããŸãããã
* ãã¹ãŠãææžåããïŒããªã·ãŒãæé ãã³ã³ãããŒã«ã®è©³çްãªããã¥ã¡ã³ããç¶æããŸãããã
* èªååã§ããéšåã¯èªååããïŒèªååããŒã«ã䜿çšããŠã³ã³ãã©ã€ã¢ã³ã¹ããã»ã¹ãå¹çåãããšã©ãŒãåæžããŸãããã
* 广çã«æ
å ±ãå
±æããïŒé¢ä¿è
ã«å¯Ÿããã³ã³ãã©ã€ã¢ã³ã¹ã®åãçµã¿ã«ã€ããŠæ
å ±ãäŒããŸãããã
* å°éå®¶ã®å©èšãæ±ããïŒSOC2æºæ ã®åãçµã¿ã«ãããŠãä¿¡é Œã§ããã³ã³ãµã«ã¿ã³ããšã®é£æºãæ€èšããŸãããã
SOC2ã³ã³ãã©ã€ã¢ã³ã¹ã¯å€§ããªåãçµã¿ã§ããããã®äŸ¡å€ã¯èšãç¥ããŸãããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãšéçšäžã®åè¶æ§ãžã®åãçµã¿ã瀺ãããšã§ã顧客ããã®ä¿¡é Œãç¯ããäŒæ¥ãšããŠã®è©å€ãé«ããåžå Žã«ãããç«¶äºåã匷åã§ããŸãã
## 詳现ã¯ãã¡ã
GitLabã®è©³çްããŸãGitLabãSOC2ã³ã³ãã©ã€ã¢ã³ã¹ã®éæãšã»ãã¥ãªãã£å¯Ÿçç¶æ³ã®åŒ·åã«ã©ã®ããã«åœ¹ç«ã€ãã«ã€ããŠã¯ã以äžã®ãªãœãŒã¹ãã芧ãã ããã
* [GitLab Ultimate](https://about.gitlab.com/ja-jp/pricing/ultimate/)
* [GitLabã®ã»ãã¥ãªãã£ããã³ã³ã³ãã©ã€ã¢ã³ã¹ãœãªã¥ãŒã·ã§ã³](https://about.gitlab.com/ja-jp/solutions/application-security-testing/)
* [GitLabã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«é¢ããããŒãž](https://docs.gitlab.com/ee/user/application_security/)
* [GitLab DevSecOpsãã¥ãŒããªã¢ã«ãããžã§ã¯ã](https://gitlab.com/gitlab-da/tutorials/security-and-governance/devsecops/simply-vulnerable-notes)