← Cloud Service
Cloud Engineering Know-how

Security Posture & Threat Management

クラウド環境は継続的に変更されるため、構築時にSecurity Baselineを設定するだけでは、設定不備や新しいThreatを継続的に把握することはできません。

複数のAccount / Project / SubscriptionからSecurity Findingを集約し、Cloud環境のSecurity Postureを継続的に確認するとともに、異常な挙動やThreatを早期に検知・対応できる運用基盤を設計します。

Design Scope

What We Design

01

Continuous Security Posture & Finding Management

  • Continuous Posture Assessment
  • Centralized Finding Management
  • Risk Prioritization & Remediation Flow

Cloud環境の設定不備やPublic Exposureなどを継続的に検知し、複数Environmentで発生するSecurity Findingを集中管理します。

FindingはSeverityだけで判断せず、Production / Non-Production、Internet Exposure、Systemの重要度なども考慮して対応優先度を整理し、担当者への割当、例外管理、対応後の確認まで追跡できる運用Flowを設計します。

02

Threat Detection & Response

  • Threat Detection
  • Suspicious Activity Monitoring
  • Incident Response Integration

Credentialの不正利用、異常なAPI操作、Malware、通常と異なるNetwork Activityなど、Configuration Checkだけでは把握できないThreatを継続的に監視します。

検知したThreatについて、対象Account / Workload、関連するAudit LogやSecurity Findingを確認できる状態を整備し、Security / Opsへの通知から調査・対応までをIncident Responseへつなげます。

Technology Map

Technologies / Keywords

AWS

AWS Security Hub / Amazon GuardDuty / AWS Config / Detective

Azure

Microsoft Defender for Cloud / Microsoft Sentinel / Azure Policy

GCP

Security Command Center / Event Threat Detection / Security Health Analytics