Mercari Advent Calendar 2020 ã®15æ¥ç®ã¯ãã¡ã«ã«ãª Product Security ãã¼ã ã® Gloria Chow ããéããã¾ãã
ããã«ã¡ã¯ãProduct Securityãã¼ã ã®@gloriaã§ãã以åããªã¼ãã³ã½ã¼ã¹ã¨ãã¦å ¬éãã¦ããTestdeckã¨ããããã¤ã¯ããµã¼ãã¹ã®èªååãã¹ãã®ããã®ç¤¾å ãã¼ã«ã«ã¤ãã¦è¨äºãæ¸ãã¾ããã
ä»åã¯ã2020å¹´ã®Advent Calendarã®è¨äºã¨ãã¦ãDevSecOpsã«ã¤ãã¦ã話ããããã¨æãã¾ããè¿å¹´ãè³ã«ããæ©ä¼ã®å¤ã話é¡ã®ä¸ã¤ãªã®ã§æ¢ã«ãåãã®æ¹ãããã£ãããããããã¾ããããDevSecOpsã®åºæ¬çãªã³ã³ã»ããã注ç®ããã¦ããçç±ããããããã£ã¬ã³ã¸ã¨ã¡ã«ã«ãªã«ãããDevSecOpsã®å®è·µäºä¾ãç´¹ä»ãããã¨æãã¾ãã
DevSecOpsã¨ã¯?
ã¾ãã以åããæå±ããã¦ããDevOpsã«ã¤ãã¦æ¯ãè¿ãããã¨æãã¾ããDevOpsã¯Developmentï¼éçºã¨ãã¹ãï¼ã¨Operationsï¼ãããã¤ã¡ã³ãã¨ã¢ãã¿ãªã³ã°ï¼ãçµã¿åãããçµç¹æåã§ã4ã¤ã®ã³ã³ã»ããã§æ§æããã¦ãã¾ããContinuous Integrationï¼ç¶ç¶çã¤ã³ãã°ã¬ã¼ã·ã§ã³ï¼ã Continuous Testingï¼ç¶ç¶çãã¹ãï¼ãContinuous Deliveryï¼ç¶ç¶çããªããªï¼ãã¨Continuous Monitoringï¼ç¶ç¶çã¢ãã¿ãªã³ã°ï¼ã§ãã
å¾æ¥ãéçºè ã¯ä¸ããããè¦ä»¶ã«æ²¿ã£ã¦æ©è½ãéçºãããã¨ã«è²¬ä»»ãæã¡ããã¹ãã¯QAãæ®ãã¯Operationsï¼éç¨é¨éï¼ã«ä»»ããã¨ãã£ãããã¼ãã¨ã£ã¦ãã¾ãããããããªãããDevOpsçµç¹ã§ã¯ãéçºè ã¯éçºã ãã§ã¯ãªãããã¹ãããããã¤ã¡ã³ãã¨ã¢ãã¿ãªã³ã°ã«ã責任ãæã¡ã¾ãã
DevOpsçµç¹ãªãã§ã¯ã®ç¹å¾´ããShift-Left Testingï¼ã·ããã¬ããã»ãã¹ãï¼ãã§ããéçºè ã¯ãåä½ãã¹ããªã©ã®èªåãã¹ããéãã¦ãèªåãã¡ã®æ¸ããã³ã¼ãã®ãã¹ãã«å¯¾ãã¦è²¬ä»»ãæã¤ããã«ãªãã¾ãããã®çµæãDevOps以åã®ããã«éçºã¨ãã¹ãï¼QAï¼ãã§ã¼ãºãåããããã¨ãªããã½ããã¦ã§ã¢éçºãµã¤ã¯ã«ï¼SDLCï¼ã®éçºãã§ã¼ãºã®ä¸ã«ãå¤ãã®ãã¹ããçµã¿è¾¼ã¾ãããã¨ã«ãªãã¾ããããããã¨ããã°ãããæ©ã段éã§è¦ã¤ãããç´ããããããã¨ãã§ãããªãªã¼ã¹ã®ç´åã«ãã¹ããå§ããããå¹ççã ã¨è¨ããã¦ãã¾ãã
ãã¦ãDevSecOpsã®è©±ã«æ»ãã¾ããDevSecOpsã§ã¯ãååã®éãDevOpsã«ã»ãã¥ãªãã£ãèåããã5ã¤ç®ã®ã³ã³ã»ããã§ããContinuous Securityï¼ç¶ç¶çã»ãã¥ãªãã£ï¼ã追å ããã¾ããã¤ã¾ãã以åã®ããã«ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãå ¨éçºãçµãã¦ããã»ãã¥ãªãã£ãã¹ããªã©ãè¡ãã¨ããããã»ã¹ãåãããéçºããã»ã¹ã®å ¨ã¦ã®æ®µéã§è¡ãããããã§ããã»ãã¥ãªãã£ã¯SDLCã®å ¨ã¦ã®æ®µéã¨ãã¢ããªã±ã¼ã·ã§ã³ããã¤ã³ãã©ã¹ãã©ã¯ãã£ï¼ã³ã³ããããµã¼ãã¼ããããã¯ã¼ã¯ï¼ã¾ã§ãå ¨ã¦ã«é¢ããã¾ãã
DevOpsã¨åãããã«ãDevSecOpsãã¼ã ã®éçºè ã¯ãèªåã®æ¸ããã³ã¼ãã®ã»ãã¥ãªãã£å質ã«è²¬ä»»ãæã¡ãã»ãã¥ã¢ã³ã¼ãã£ã³ã°ãã»ãã¥ãªãã£ãã¹ããªã©ã®ä¸è¬çãªã»ãã¥ãªãã£æ´»åãç©æ¥µçã«ããªãã¾ããDevOpsã®ããã»ã¹ã«ã»ãã¥ãªãã£ãã¼ã«ãçµ±åãããã¨ã¯ãSecurity as Code (SaC)ãã¨å¼ã°ãã¦ãã¦ãéçºããã»ã¹ã«æªå½±é¿ãåã°ããã«èªåçãªã»ãã¥ãªãã£ãã§ãã¯ãã»ãã¥ãªãã£ãã¹ããããã³ã»ãã¥ãªãã£ã¹ãã£ã³ã追å ããç®çã§è¡ããã¾ããèªååã«ãã£ã¦ãSDLCã®ä¸ã«å¸¸ã«åå¨ããæ©è½ã¨ãã¦ãç¶ç¶çãã¤å®¹æã«ã»ãã¥ãªãã£ã®å¼·åãå®æ½ãããã¨ãã§ãã¾ãã
ãªãDevSecOpsã¯æ³¨ç®ããã¦ããã®ãï¼
以ä¸ã§ã¯è¿å¹´DevSecOpsãå¿åããçµç¹ãå¢ãã¦ãã3ã¤ã®çç±ã説æãã¾ãã
ããçããªãªã¼ã¹ãµã¤ã¯ã«ã¨ãªãªã¼ã¹ã®é«éå
DevOpsãã¼ã ã®ãã¹ãã¯éçºãã§ã¼ãºã«å®æ½ãããã®ã§ããã°ãæ©ã段éã§è¦ã¤ããã¾ãããã¹ãã¯ãªãªã¼ã¹ã®ç´åã«ä¸æ°ã«è¡ãããã®ã§ã¯ãªããSDLCã®åãã§ã¼ãºã§è¡ããã¾ããã»ãã¥ãªãã£ãåãããã«ãå¾æ¥ã¯ãããã¬ã¼ã·ã§ã³ãã¹ããªã©ã®ã»ãã¥ãªãã£æ´»åã¯æå¾ã®ãã§ã¼ãºã§è¡ããã¦ãã¾ããããDevSecOpsã§ã¯åãã§ã¼ãºã§è¡ãããããã«ãªãã¾ããã
DevSecOpsã«ãããQAã¨ã»ãã¥ãªãã£ã®ããã«ããã¯ãæé¤ã§ãã2ã¤ã®çç±ãããã¾ãï¼
-
ãªãªã¼ã¹ç´åã«å¤§ãããã°ãèå¼±æ§ãè¦ã¤ãããæ©æ¥ã«ç´ããªãã¨ãããªãäºæ ã«é¥ãå¯è½æ§ãæ¸ãããã¨ãã§ãã¾ããä¼çµ±çãªã¦ã©ã¼ã¿ã¼ãã©ã¼ã«ã¨ã¢ã¸ã£ã¤ã«ã«ããéçºã¹ã¿ã¤ã«ã§ã¯ãQAã¨ã»ãã¥ãªãã£ããªãªã¼ã¹ã®ç´åã«å¤§ããªãã°ãèå¼±æ§ãè¦ã¤ããããããªãªã¼ã¹ã®ãããã«ã¼ã«è¦ãããã¡ã§ãããDevSecOpsã§ã¯æ©ã段éã§åé¡ãè¦ã¤ãã¦ä¿®æ£ãããã¨ãã§ãã¾ãã
-
éçºè ã¯QAã¨ã»ãã¥ãªãã£ã®ä½æ¥ãçµããã¾ã§å¾ ããªãã¦ãè¯ããªãã¾ããã³ã¼ããæãç解ãã¦ãã人ã¯éçºè ã®ã¯ããªã®ã§ãã³ã¼ããæ¸ããªãããã¹ããæ¸ãï¼ãããã¯ããã¹ãé§åéçºï¼TDDï¼ã§æåã«ãã¹ããæ¸ãï¼ã¨ããã®ã¯ãå®æããå¾ã«QAã«ãã¹ããä¾é ¼ããããå¹ççã ã¨è¨ããã¦ãã¾ããã»ãã¥ãªãã£ãåãããèå¼±ãªã½ããã¦ã§ã¢ããã¨ããã»ãã¥ã¢ã«ãããããæåããã»ãã¥ãªãã£ãéè¦ãã¦ä½ãæ¹ãå¹ççã§ãã
DevSecOpsãã¼ã ã®ããä¸ã¤ã®ç¹å¾´ã¯ãèªååãç©æ¥µçã«æ´»ç¨ãã¦ãããã¨ã§ããã³ã¼ããã³ãããããããã³ã«ãQAã¨ã»ãã¥ãªãã£ãã¹ããå®è¡ããã½ããã¦ã§ã¢ã®å質ã¨ã»ãã¥ãªãã£ã確ä¿ãã¦ãã¾ãããããããã¨ã§ãDevSecOpsãã¼ã ã¯èªååã使ç¨ããªãã¦ã©ã¼ã¿ã¼ãã©ã¼ã«ãã¢ã¸ã£ã¤ã«ã®éçºã¹ã¿ã¤ã«ã§éçºããçµç¹ããéããã«ãªãªã¼ã¹ãããã¨ãã§ãã¾ãã
ã½ããã¦ã§ã¢ã®å質ã¨ã»ãã¥ãªãã£ã®åä¸
DevSecOpsã¯ã½ããã¦ã§ã¢å質ã¨ã»ãã¥ãªãã£ãåªå ãããã¹ãã¨ã»ãã¥ãªãã£ã®æ´»åãæ©ã段éã§éå§ããã½ããã¦ã§ã¢ã®ãã¶ã¤ã³ã¨ã¢ã¼ããã¯ãã£ã«å½±é¿ãä¸ããããããã«ãã¦ãã¾ãããããããã¨ã§ããã¸ãã¯ãã¢ã¼ããã¯ãã£ã®æ ¹æ¬çãªåé¡ãããæ©ãè¦ã¤ãã¦ä¿®æ£ããæ¬çªç°å¢ã§çºçããã¤ã³ã·ãã³ããæ¸å°ã§ãã¾ãã
ãSecurity as Code (SaC)ãã¨ãInfrastructure as Code (IaC)ããªã©ã®DevSecOpsã®èãæ¹ã¯ãæ¬çªç°å¢ã«æªå½±é¿ãä¸ãããã¥ã¼ãã³ã¨ã©ã¼ã®ãªã¹ã¯ãåæ¸ã§ãã¾ããSaCã¨IaCã§ã¯ãã»ãã¥ãªãã£ã®æ´»åããããã¤ã¡ã³ããªã©ã®éè¦ãªãªãã¬ã¼ã·ã§ã³ã¯å ¨ã¦èªåã§è¡ãããã®ã§ãæ¯åã®ãªãªã¼ã¹ããã»ã¹ã«ããã¦ä¸è²«æ§ã確ä¿ã§ãã¾ãã
ããè¯ããã¼ã ã³ã©ãã¬ã¼ã·ã§ã³ã¨äººæã®è²æ
DevSecOpsã¯çµç¹ã®å ±åçãªæåã¨éçºããã»ã¹ã«é¢ãã4ã¤ã®ã°ã«ã¼ãï¼éçºãQAãã»ãã¥ãªãã£ãOperationsï¼éã§ç¥èãå ±æããæèãåä¸ããã¾ãã人æã¯ã¹ãã«ã¢ãããã§ããå°æ¥ã«ãã£ãªã¢ã¢ãããªã©ãå¯è½ã«ãªãã®ã§ãã¨ã¦ãåããããããç°å¢ã ã¨æãã¾ãã以åæ¸ããè¨äºã®éããç¾ä»£ã®ã¨ã³ã¸ãã¢ã¯ãTåãã®ã¹ãã«ï¼å¹ åºãç¥èã«ä¸ã¤ãä¸ã¤ä»¥ä¸ã®å°éç¥èï¼ãå¿ è¦ã§ããDevSecOpsç°å¢ã§åãã¨ã³ã¸ãã¢ã¯ãã¹ãããããã¤ã¡ã³ããã¢ãã¿ãªã³ã°ãã»ãã¥ãªãã£ãªã©ãæ§ã ãªã¹ãã«ã身ã«ä»ããããã®ã§ãèªç¶ã«Tå人æã«æé·ããã§ãããã
éçºè ã§ã¯ãªãæ¹ã¯éçºè ã¨é£æºãããã¨ã§ãæ¸å¿µç¹ãææ¡ãéçºããã»ã¹ã®æ©ã段éã§èãã¦ããããã¨ãã§ãã¾ããå¾æ¥ã®éçºææ³ã§ã¯ããåãã¼ã ã¯èªåãã¡ã®ä½æ¥ã ãã«æ³¨åãã¦ããããã³ã©ãã¬ã¼ã·ã§ã³ãã¨ã¦ãå°ãªããåããããã¯ããä½ã£ã¦ããã®ã«ãµã¤ãåãçºçãã¦ãã¾ããã¨ãããã¾ããããDevSecOpsæåã§ã¯ãããé²ããã¨æã£ã¦ãã¾ãã
ã¡ã«ã«ãªã¨ãã·ããã¬ããã»ã»ãã¥ãªãã£ã
ç¶ç¶çãã¹ãã«ã¯ãã·ããã¬ããã»ãã¹ããã¨ããèãæ¹ããããç¶ç¶çã»ãã¥ãªãã£ã«ããã·ããã¬ããã»ã»ãã¥ãªãã£ãã¨ããèãæ¹ãããã¾ããDevSecOpsã®çµç¹ã§ã¯ãã»ãã¥ãªãã£ã®æ´»åãSDLCã®åæãã§ã¼ãºã«ç§»è¡ãããå段éã§ãè¡ããã¾ãã
ã¡ã«ã«ãªã§ããã·ããã¬ããã»ã»ãã¥ãªãã£ããå°å ¥ãã¦ãã¾ãã以ä¸ã¯èª°ã§ãå°å ¥ã§ãããããããã®ãã·ããã¬ããã»ã»ãã¥ãªãã£ãæ´»åã®ä¾ã§ãã
è¦ä»¶å®ç¾©ã¨è¨è¨ãã§ã¼ãº
-
ãã¶ã¤ã³ã¨è¦ä»¶ã®ã»ãã¥ãªãã£ã¬ãã¥ã¼ï¼ã¡ã«ã«ãªã®Product Securityãã¼ã ã¯æ°ããæ©è½ã®è¦ä»¶å®ç¾©ã¨è¨è¨ã«é¢ãã£ã¦ãããåé¡ã®çºçãããæãç¹å®ããããã«ã¦ã¼ã¶ã¼ããã¼ãã¦ã¼ã¹ã±ã¼ã¹ããã¸ãã¹è¦ä»¶ãªã©ã®ã»ãã¥ãªãã£ã¬ãã¥ã¼ãè¡ãã¾ããããããã¨ãæ©è½ã®éçºãå§ã¾ãåã«ããã¶ã¤ã³æ®µéã§ã»ãã¥ãªãã£åé¡ãæ´ãåºããã»ãã¥ãªãã£å質ã確ä¿ãããã¨ãã§ãã¾ãã
-
è å¨ã¢ããªã³ã°ï¼ çºçãå¾ãè å¨ãèå¼±æ§ãæ´ãåºãããªã¹ã¯è©ä¾¡ãè¡ãããªã¹ã¯ãæ¸å°ãããããã®å¯¾çãææ¡ãã¾ããæ»æè ãè¡ãã§ãããå ¨ã¦ã®ã±ã¼ã¹ãæ´ãåºããã¨ã§ãå æãæã£ã¦ãæ»æè ãæªç¨ããåã«å¯¾çãè¡ããã¨ãã§ããããã«ãªãã¾ãã
-
ã¢ã¼ããã¯ãã£ã¬ãã¥ã¼ï¼ã¡ã«ã«ãªã®Security Engineeringãã¼ã ã¯ã·ã¹ãã ã¤ã³ãã©ã¹ãã©ã¯ãã£ããã¼ã¿ããã¼ãªã©ã®ã¬ãã¥ã¼ãè¡ãããµã¤ãã¼æ»æã®ãªã¹ã¯ã¨ã¤ã³ãã¯ããæå°ã«ããããã«å¯¾çãææ¡ãã¦ãã¾ãã
å®è£ ãã§ã¼ãº
- ã»ãã¥ãªãã£ã³ã¼ãã¬ãã¥ã¼ï¼æ©å¾®æ å ±ã®åãæ±ãã®å®å ¨æ§ã確ä¿ããããã«ãæ©å¾®æ å ±ã«é¢ããã³ã¼ãï¼å人æ å ±ãé ãã£ããããã¤ã¡ã³ããªã©ã«é¢é£ãããããç®æï¼ã®ã»ãã¥ãªãã£ã¬ãã¥ã¼ãè¡ããã»ãã¥ãªãã£å¯¾çãä¸ååãªé¨åãæªç¨ãããããªãã¸ãã¯ãæ´ãåºãã¦ãã¾ããæ©å¾®æ å ±ã«é¢ãããªãã³ã¼ãã«é¢ãã¦ããã»ãã¥ã¢ã³ã¼ãã£ã³ã°ã®ãã¹ããã©ã¯ãã£ã¹ï¼ã¯ã¬ãã³ã·ã£ã«ã®ãã¼ãã³ã¼ãã®ç¦æ¢ãå ç¢ãªæå·åã¢ã«ã´ãªãºã ã®ä½¿ç¨ãªã©ï¼ã«å¾ã£ã¦ãããã©ããã®ç¢ºèªãè¡ã£ã¦ãã¾ãã
ãã¹ãã¨ã¤ã³ãã°ã¬ã¼ã·ã§ã³ãã§ã¼ãº
-
ã»ãã¥ãªãã£ãã¹ãï¼æ©è½ã®ãã¹ããå¯è½ã«ãªã£ãæç¹ã§ï¼QAã®ãã¹ãã¨åæé²è¡ï¼ãèå¼±æ§ã¨æªç¨å¯è½ãªé¨åãæ´ãåºãããã«ãProduct Securityãã¼ã ã¯ã»ãã¥ãªãã£ãã¹ããè¡ã£ã¦ãã¾ãã
-
éçã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ãã¹ãï¼SASTï¼ï¼XSSãSQLiã«ã¤ãªãããèå¼±ãªã©ã¤ãã©ãªã®ä½¿ç¨ãã³ã¼ãã£ã³ã°ã®ãã¹ãªã©ã®ããããåé¡ãæ´ãåºããã¼ã«ã§ããã¡ã«ã«ãªã¯WhiteSourceãMobSFãªã©ã®SASTãã¼ã«ãå°å ¥ããCIã»CDãã¤ãã©ã¤ã³ã§å®è¡ãããã¨ã§ãã³ããããã¨ã«ã»ãã¥ãªãã£å質ã確ä¿ãã¦ãã¾ãã
-
åçã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ãã¹ãï¼DASTï¼ï¼å®éã«ã½ããã¦ã§ã¢ãå®è¡ãã¦ãèå¼±æ§ããããã©ãã解æãããã¼ã«ã§ããã¡ã«ã«ãªãNetsparkerãªã©ã®DASTãã¼ã«ãå°å ¥ãã¦ãã¾ãã
ã¡ã³ããã³ã¹ãã§ã¼ãº
- èªååãã¼ã«ã¨ã¢ãã¿ãªã³ã°ï¼ã»ãã¥ãªãã£ã®æ´»åã¯ãªãªã¼ã¹ã§çµããã¨ããããã§ã¯ããã¾ããããªãªã¼ã¹ãçµãã£ã¦ãé »ç¹ã«èå¼±æ§ã¹ãã£ããã»ãã¥ãªãã£ãªã°ã¬ãã·ã§ã³ãã¹ããªã©ãå®æ½ããããã¢ãã¿ãªã³ã°ãã¢ã©ã¼ããç£æ»ãè¡ããã¼ã«ãå°å ¥ãããã¨ã¯ãµã¤ãã¼æ»æãç¸æ¬¡ãã¦ããç¾ä»£ã§ã¯å¿ è¦ä¸å¯æ¬ ã§ããã¡ã«ã«ãªã¯ãSignal SciencesãWeb Application Firewall(WAF)ãSysdigãªã©ã®ã»ãã¥ãªãã£ãã¼ã«ãå©ç¨ãã社å ã§éçºããSOAR (Security Orchestration, Automation and Response)ãªã©ã®ç£è¦ã·ã¹ãã ãéãã¦ãç¶ç¶çãªã¢ãã¿ãªã³ã°ãå®æ½ãã¦ãã¾ãã
ãã£ã¬ã³ã¸
DevSecOpsã®ã¡ãªããã¯ç¢ºãã«å¤ãã§ãããæ£ããå°å ¥ããã®ã¯ç°¡åã§ã¯ããã¾ãããä»ã®éçºææ³ã¨åæ§ã«ããã¼ã ã¯å¤åããå½¹å²ã責任ãããã³åãæ¹ãã«ã«ãã£ã¼ã«é©å¿ããã®ã«æéããããããã移è¡æéä¸ã¯éçºã¹ãã¼ããä¸ããå¯è½æ§ãããã¾ããDevSecOpsã«ç§»è¡ãããã¨ããçµç¹ã¯ãã¡ãªãã享åããã¾ã§ã«çç£æ§ãä¸ããå¯è½æ§ããããã¨ãäºåã«ç解ããåãå ¥ããå¿ è¦ãããã¾ãã
ããä¸ã¤ã®ãã£ã¬ã³ã¸ã¯ãDevSecOpsã®ãã¼ã ã¯äºãã«é£æºããå¿ è¦ãããç¹ã§ããéçºè ãQAãã»ãã¥ãªãã£ãOperationsï¼SREãªã©ï¼ã®4ã¤ã®ãã¼ã ã®ä½æ¥ãSDLCå ¨ã¦ã®æ®µéã«åå¨ãã¦ããããã親å¯ãªé¢ä¿ãç¯ãã¦ååããªããã°ãªãã¾ãããå¾æ¥ã®ã¦ã©ã¼ã¿ã¼ãã©ã¼ã«ã¨ã¢ã¸ã£ã¤ã«ã®çµç¹ã§ã¯ãåãã¼ã ãæå®ãããèªåãã¡ã®SDLC段éã®ä¸ã§ä½æ¥ããã¦ãã¾ããããDevSecOpsã§ã¯ç°ãªãã¾ããã¡ãªã¿ã«ãDevSecOpsã«ã¤ãã¦ããè³ã«ãã誤解ã¯ããã¹ãããããã¤ã¡ã³ããã¢ãã¿ãªã³ã°ã¨ã»ãã¥ãªãã£ã®è²¬ä»»ãéçºè ã«ç§»è²ããããQAã»ã»ãã¥ãªãã£ã»Operationsã®ã¨ã³ã¸ãã¢ãå¿ è¦ãªããªãã¨ããèãã§ããDevSecOpsã®ç®çã¯ãã®3ã¤ã®è·ãæé¤ãããã¨ã§ã¯ãªãããããå½¼ãã«éçºè ããµãã¼ãããå½¹å²ãä¸ãããã¨ã§ããã¤ã¾ããéçºè ã¨å好çã«ååãã¦åãã¨ãããã¨ã§ãã
æå¾ã«ãæãæ確ãªèª²é¡ã¯ãDevSecOpsãã¼ã ã®ã¨ã³ã¸ãã¢ã¯æ§ã ãªæè¡ã¹ãã«ã¨ç¥èã«ç²¾éãã¦ããå¿ è¦ãããç¹ã§ããéçºè ã¯ã³ã¼ãã£ã³ã°ãåãããã¹ãããããã¤ã¡ã³ããã¢ãã¿ãªã³ã°ãã»ãã¥ãªãã£ãªã©ã®è²¬ä»»ãæã¤ãããèªååãã¹ããã»ãã¥ãªãã£ã®ãã¤ã³ãã»ãããªã©ãæ§ã ãªã¹ãã«ã¨ç¥èã身ã«ä»ããªããã°ãªãã¾ãããDevSecOpsã«ç§»è¡ãããã¨ããçµç¹ã¯éçºè åãã®ãã¬ã¼ãã³ã°ãããã¦QAã»ã»ãã¥ãªãã£ã»Operationsãã¼ã ããã®ç¶ç¶çæ¯æ´ã¨ç¥èãå ±æãã¦ãããæ©ä¼ã確ä¿ããå¿ è¦ãããã¾ããã¡ã«ã«ãªã®ã±ã¼ã¹ãç´¹ä»ããã¨ãã»ãã¥ãªãã£ç¥èãåºããããã«ããã»ãã¥ãªãã£ãã£ã³ããªã³ãã¨ãã社å è²æããã°ã©ã ãä½ãã¾ããã
ãããã«
DevSecOpsã¯æè¿é常ã«æ³¨ç®ããã¦ãã話é¡ã®ä¸ã¤ã§ããæ£ããå°å ¥ããä¸ã§æ§ã ãªãã£ã¬ã³ã¸ãããããããã¾ãããããªãªã¼ã¹ã®é«éåããã°ã¨èå¼±æ§ã®æ¸å°ãããã¦ç¤¾å ã¯ãã¹ãã¼ã ã®ã³ã©ãã¬ã¼ã·ã§ã³ã¨ç¥èå ±æã®ä¿é²ãªã©ã®ã¡ãªãããããã¾ããç¹ã«è¿å¹´ããµã¤ãã¼æ»æã®ç¸æ¬¡ãã¦ããä¸ã§ãã»ãã¥ãªãã£ã¯è£è¶³çãªãã®ã§ã¯ãªããæåããéçºããã»ã¹ã¨ä¸¦è¡ã«è¡ããããä¸å¯æ¬ ãªæ©è½ã®1ã¤ã«ãªãã¾ããããã·ããã¬ããã»ã»ãã¥ãªãã£ããªã©ã®DevSecOpsææ³ãå°å ¥ãããã¨ã§ãã½ããã¦ã§ã¢ã«é«ãã»ãã¥ãªãã£å質ãåãè¾¼ããã¨ãã§ãã¾ãã
æ¬è¨äºã¯DevSecOpsã®åºæ¬çãªã³ã³ã»ããã注ç®ããã¦ããçç±ããããããã£ã¬ã³ã¸ã¨ã¡ã«ã«ãªã®DevSecOpsã®å®è·µäºä¾ãç´¹ä»ãã¾ããããèªã¿ããã ããããã¨ããããã¾ãããææ¥ãå¼ãç¶ãã¡ã«ã«ãª Advent Calendarã®è¨äºãæ稿ãããã®ã§ããæå¾ ãã ããã
ã¡ã«ã«ãªã§ã¯ããã·ã§ã³ã»ããªã¥ã¼ã«å
±æã§ããã¨ã³ã¸ãã¢ãåéãã¦ãã¾ããä¸ç·ã«åãã仲éããå¾
ã¡ãã¦ããã¾ãã
https://careers.mercari.com/jp/job-categories/engineering/
ææ¥ã®Mercari Advent Calendar 2020å·çæ å½ã¯ã Engineering Officeã® afroscript ããã§ããå¼ãç¶ãã楽ãã¿ãã ããã