PCI DSSã§å¦ã¶AWSã»ãã¥ãªãã£â£ ï½Amazon EKSï¼ããã¼ã¸ãã³ã³ãããµã¼ãã¹ï¼ã®è¨è¨ï½
ååï¼https://www.intellilink.co.jp/column/security/2021/102200.aspxï¼ã¾ã§ã«ã¯ã¬ã¸ããã«ã¼ãæ¥çã®ã»ãã¥ãªãã£åºæºã§ããPCI DSSããã¼ã¹ã«AWSãã©ãããã©ã¼ã ä¸ã§ã»ãã¥ã¢ã«ã·ã¹ãã ãæ§æããéã®çæç¹ã«ã¤ãã¦ãã»ã°ã¡ã³ãã¼ã·ã§ã³ã«ããç°å¢åé¢ã責任å
±æã¢ãã«ã«åºã¥ããå©ç¨è
ã®è²¬ä»»ç¯å²ã®ç解ãåè¦ä»¶ã«æ²¿ã£ãã»ãã¥ãªãã£å¯¾çã®ãã¤ã³ãã«ã¤ãã¦ç´¹ä»ãã¦ãã¾ããã
ä»åã¯ãã³ã³ãããµã¼ãã¹ã管çããããã®ãã©ãããã©ã¼ã ã§ããKubernetesãããã¼ã¸ããµã¼ãã¹ã¨ãã¦æä¾ããAmazon Elastic Kubernetes Serviceï¼Amazon EKSï¼ãã»ãã¥ã¢ã«æ§æããããã®çæç¹ã«ã¤ãã¦AWSããå
¬éããã¦ããã¬ã¤ãã³ã¹ææ¸ãArchitecting Amazon EKS for PCI DSS Complianceã[1]ããã¨ã«æ¦èª¬ãã¾ããã³ã³ãããã¼ã¹ã®ãµã¼ãã¹ã¯OSããããã¯ã¼ã¯ãå
±ç¨ããããããåä¸ã®ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã§è¤æ°ã³ã³ãããå®è¡ãããããªå ´åããã¹ã¦ã®ã³ã³ããã«ã¢ã¯ã»ã¹å¯è½ãªå
±éã®æ»æãã¤ã³ããæ»æè
ã«æä¾ãããã¨ã«ãªãããã¾ãããããã§ããã®ãããªã»ãã¥ãªãã£ãªã¹ã¯ãä½æ¸ããããã®å¯¾çã«ã¤ãã¦AWSãµã¼ãã¹ãä¸å¿ã¨ããæ§æä¾ãã¿ã¦ããã¾ãããã
ãã¹ãOSã¨ã³ã³ããã¤ã¡ã¼ã¸ã®å¼·å
Amazon EKSã§ã¯ãã³ã³ããã®å®è¡ç°å¢ã¨ãªãWorker Nodeã®ãã¹ãOSä¸ã§ãè¤æ°ã®é¢é£ããã³ã³ãããå«ãPODã¨ããåä½ã§å¦çãå®è¡ããã¾ããã¾ãPODå ã§ç¨¼åããã³ã³ããã¯ãã¢ããªã±ã¼ã·ã§ã³å®è¡ã«å¿ è¦ãªãã®ããã¹ã¦å«ãã ã½ããã¦ã§ã¢ããã±ã¼ã¸ã§ããã³ã³ããã¤ã¡ã¼ã¸ããããã¤ãããã¨ã§ç¨¼åããã¾ãããã®ãããWorker Nodeã®ãã¹ãOSã«å ãã¦ãã³ã³ããã¤ã¡ã¼ã¸ãã»ãã¥ã¢ã«æ§æãããã¨ãå¿ è¦ã§ããã¬ã¤ãã³ã¹ã§ã¯ä¸è¨ã®ãããªå¯¾çãæ¨å¥¨ããã¦ãã¾ãã
- âWorker Nodeä¸ã®ãã¹ãOSï¼å³1ï¼â åç
§ï¼
- ã»ã»ãã¥ãªãã£ãããã®é©ç¨ããã«ã¦ã§ã¢å¯¾çãªã©ã·ã¹ãã ã®å ç¢å
- ã»Amazon Inspectorãªã©ãæ´»ç¨ããèå¼±æ§è©ä¾¡ã¨å¯¾å¦
- ã»ããã¼ã¸ããµã¼ãã¹ã§ããAWS Fargateã«ãããããé©ç¨ãªã©ã®ç®¡çè² æ ã軽æ¸
- âã³ã³ããã¤ã¡ã¼ã¸ï¼å³1ï¼â¡åç
§ï¼
- ã»ä¿¡é ¼ã§ããã³ã³ããã¤ã¡ã¼ã¸ã使ç¨
- ã»Amazon ECRãªã©ä¿¡é ¼ã§ããã³ã³ããã¬ã¸ã¹ããªã使ç¨
- ã»Amazon Inspectorã«ããAmazon ECRã§ã®ã³ã³ããã¹ãã£ã³ããã³å¯¾å¦
å³1ï¼ãã¹ãOSã¨ã³ã³ããã¤ã¡ã¼ã¸ã®å¼·åãã¤ã³ã
ãããã¯ã¼ã¯ã»ãã¥ãªãã£
AWSã¢ã«ã¦ã³ããVPCãããã¯ã¼ã¯ãåãã¦ä»ã®ç°å¢ããåé¢ãããï¼å³2ï¼â åç §ï¼ãInternetãªã©ä»ã®ãããã¯ã¼ã¯ããã®éä¿¡ãAWS Network FirewallãVPCã»ãã¥ãªãã£ã°ã«ã¼ããç¨ãã¦å¿ è¦æå°éã«å¶éãããï¼å³2ï¼â¡åç §ï¼ãããã¨ãåºæ¬ã®å¯¾çã§ããå ãã¦ãAmazon EKSãå©ç¨ããã³ã³ãããã¼ã¹ã®ãµã¼ãã¹ãæä¾ããã«ããã£ã¦ã¯ã以ä¸ã®ãããªåã¬ã¤ã¤ã¼ã§ã®å¯¾çãèãããã¾ãããPODééä¿¡ãç´°ããå¶å¾¡ããã®ãããããã¯è¤éåãé¿ããããã«ã»ãã¥ãªãã£ã¬ãã«ã«å¿ãããã¼ãåå²ã«ãããã¼ãéã§ãããã¯ã¼ã¯ã¢ã¯ã»ã¹å¶å¾¡ãå®ç¾ããã®ããªã©ãã·ã¹ãã ã®ç¹å¾´ã«å¿ãã¦æé©ãªèãæ¹ãæ¡ç¨ãããã¨ãéè¦ã§ãã
- âã³ã³ããã¼ã«ãã¬ã¼ã³ã¨ã®éä¿¡ï¼å³2ï¼â¢åç
§ï¼
- ã»VPCã»ãã¥ãªãã£ã°ã«ã¼ãã«ããã³ã³ããã¼ã«ãã¬ã¼ã³ã¨ãã¼ãééä¿¡ãå¶é
- âãã¼ãééä¿¡ï¼å³2ï¼â£åç
§ï¼
- ã»ã»ãã¥ãªãã£ã¬ãã«ã«å¿ãã¦ãã¼ããåãã¦ãããããå°ç¨ã®VPCã»ãã¥ãªãã£ã°ã«ã¼ãã使ç¨ãã¦åé¢
- âPODééä¿¡ï¼PODã¨å¤é¨ãµã¼ãã¹ééä¿¡ï¼å³2ï¼â¤åç
§ï¼
- ã»ããã©ã«ãã§ã¯ãã¹ã¦ã®ãããééä¿¡ãã¯ã©ã¹ã¿ã¼å ã§è¨±å¯ããããããå¿ è¦ãªå ´åãKubernetesãããã¯ã¼ã¯ããªã·ã¼ãªã©ãç¨ãã¦ãããééä¿¡ãå¶é
- ã»PODã®ã»ãã¥ãªãã£ã°ã«ã¼ããªã©ã«ããã¯ã©ã¹ã¿ã¼å¤ã®ãµã¼ãã¹ã¨ãããéã®éä¿¡ãå¶é
å³2ï¼ãããã¯ã¼ã¯ã»ãã¥ãªãã£ã®æ§æä¾
ãã¼ã¿ä¿è·
ã³ã³ããã§åæ±ãæ©å¯ãã¼ã¿ã¯ãå®å ¨ãªãã¡ã¤ã«ã¹ãã¢ããã¼ã¿ãã¼ã¹ã«ã®ã¿ä¿åãã¦ãã¡ã¤ã«ã·ã¹ãã ã®ããªã¥ã¼ã ãã¦ã³ããªã©ã«ãã£ã¦ãã¹ãOSä¸ã«æå³ããä¿åãã¦ãã¾ããªããã注æãå¿ è¦ã§ãï¼å³3ï¼â åç §ï¼ãã¾ããã³ã³ããã®ã¤ã¡ã¼ã¸ããã«ããã¡ã¤ã«ã«å«ã¾ãããã¼ã¿ãã¼ã¹æ¥ç¶èªè¨¼æ å ±ãªã©ã®ãã¹ã¯ã¼ãæååãç°å¢å¤æ°ã¯AWS KMSãªã©ãç¨ãã¦æå·åä¿åãããã¨ã§ãå¹³æã®ã¾ã¾ã®ãã¹ã¯ã¼ãæååãå«ããã¡ã¤ã«ãGitHubãä»ãã¦æµåºãã¦ãã¾ããããªäºæ ã®äºé²ã«ã¤ãªããã¾ãï¼å³3ï¼â¡åç §ï¼ãããã«ã転éä¸ã®æ©å¯ãã¼ã¿ãä¿è·ãããã¨ã§æ©å¯ãã¼ã¿ã®æµåºãã¤ã³ããæå°åã§ãã¾ããALBãä»ããå¤é¨ã¨ã®ãã¼ã¿è»¢éãããã¼ã¿ãã¼ã¹ãªã©éè¦ãªãªã½ã¼ã¹ã¨ã®æ¥ç¶æã®httpsãå¼·åãªæå·åæ§æã§ä¿è·ããã ãã§ãªããå¯è½ãªéããããééä¿¡ã«ã¤ãã¦ãmTLSãªã©ã®ãããã³ã«ãæå¹åãã¦æå·åãããã¨ãæ¨å¥¨ããã¾ãï¼å³3ï¼â¢åç §ï¼ã
å³3ï¼ãã¼ã¿ä¿è·ã®ãã¤ã³ã
ã¢ã¯ã»ã¹å¶å¾¡
å種ãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãæ¥åä¸å¿ è¦ãªæå°éã®ã¢ã¯ã»ã¹ã«å¶éãããã¨ãå¿ è¦ã§ããã³ã³ãããã¼ã¹ã®ãµã¼ãã¹ã§ã¯åè¿°ã®ãããã¯ã¼ã¯ã»ãã¥ãªãã£åæ§ã«ä»¥ä¸ã®ãããªè¤æ°ã®ã¬ã¤ã¤ã¼ã§é©åãªã¢ã¯ã»ã¹å¶å¾¡ãè¬ãããã¨ã対çã®ãã¤ã³ãã§ãã
- âã³ã³ããï¼ãã¹ãOSï¼ã¬ã¸ã¹ããª
- ã»root以å¤ã®ã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã§ã³ã³ãããå®è¡ï¼å³4ï¼â åç §ï¼
- ã»EC2èµ·åã¿ã¤ãã®ãã¹ãOSã¸ã®sshã§ã®ç´æ¥ã¢ã¯ã»ã¹ã¯ç¡å¹åããAWS Systems Manager Run Commandãªã©ã§ä»£æ¿ï¼å³ï¼ï¼â¡åç §ï¼
- ã»AWS Identity and Access Managementï¼IAMï¼ã«ããECRãªã©ã³ã³ããã¬ã¸ã¹ããªã®ã¢ã¯ã»ã¹å¶éï¼å³4ï¼â¢åç §ï¼
- âAmazon EKSï¼IAMï¼Kubernetes RBACï¼
- ã»å°ç¨IAMãã¼ã«ã使ç¨ãã¦ã¯ã©ã¹ã¿ã¼ãä½æããååé常æ¥åã«ã¯ä½¿ç¨ããã使ç¨ç¶æ³ãå®æçã«ç£æ»ï¼å³4ï¼â£åç §ï¼
- ã»aws-auth ConfigMapãä»ãã¦è¿½å ã¦ã¼ã¶ã¼ã«ã¯ã©ã¹ã¿ã¼ã¸ã®ã¢ã¯ã»ã¹ã許å¯ããRoles/RoleBindingsï¼åå空éï¼ã¨ClusterRole/ClusterRoleBindingsï¼ã¯ã©ã¹ã¿ã¼ï¼ãä½æãã¦æå°éã®æ¨©éãä»ä¸ï¼å³4ï¼â¤åç §ï¼
- ã»å¯è½ãªå ´åãIRSAï¼IAM Roles for ServiceAccoutï¼ã使ç¨ãã¦PODåä½ã§IAMãã¼ã«ãå²å½ã¦ï¼å³4ï¼â¥åç §ï¼
å³4ï¼ã¢ã¯ã»ã¹å¶å¾¡ã®æ§æä¾
ã¾ã¨ã
ä»åã¯ãAWSã®ããã¼ã¸ãã³ã³ãããµã¼ãã¹ã§ããAmazon EKSãã»ãã¥ã¢ã«æ§æããããã®çæç¹ã«ã¤ãã¦ã¬ã¤ãã³ã¹ææ¸ãããã¤ã³ããæç²ãã¦ç´¹ä»ãã¾ãããä»åç´¹ä»ãã対ç以å¤ã«ããã°ã®ä¿å ¨ãã¢ãã¿ãªã³ã°ãå®æçãªã»ãã¥ãªãã£ãã¹ãå®æ½ãªã©PCI DSSã®åè¦ä»¶ã«æ²¿ã£ãå¤å±¤çãªã»ãã¥ãªãã£å¯¾çãå¿ è¦ã¨ãªãç¹ã¯ã³ã³ãããµã¼ãã¹ãå©ç¨ããå ´åãåæ§ã§ããå ãã¦ãèå¼±ãªç¶æ ã®ã³ã³ããã¤ã¡ã¼ã¸ãæ¬çªç°å¢ã«ãããã¤ããã¦æ»æè ã®ä¾µå ¥ã許ãã¦ãã¾ããªã©ã³ã³ããåºæã®ãªã¹ã¯ãèªèããä¸ã§ãä¸é£ã®ã³ã³ããã®ãããã¤ã¡ã³ããµã¤ã¯ã«å ¨ä½ã«ããã£ã¦ã¤ã¡ã¼ã¸ãã¬ã¸ã¹ããªããã¹ãOSãã³ã³ããã¼ã«ãã¬ã¼ã³ãªã©åã¬ã¤ã¤ã¼ã§ã®å¯¾çãè¬ãããã¨ãéè¦ã¨ãªãã¾ããä»åç´¹ä»ãã¾ãããã¤ã³ããåèã«ãPCI DSSãªã©ã®ã³ã³ãã©ã¤ã¢ã³ã¹è¦ä»¶ã¸ã®éµå®ãã³ã³ããç°å¢ã®ã»ãã¥ãªãã£åä¸ã«ã¤ãªãããããç¶ç¶çãªå¯¾çã«åãçµãã§ããã ãã¾ããã幸ãã§ãã
åèãªã½ã¼ã¹
- [1]Architecting Amazon EKS for PCI DSS Compliance
https://d1.awsstatic.com/whitepapers/architecting-amazon-eks-for-pci-dss-compliance.pdf
ãåãåãã
AWSãªã©ã®ãããªãã¯ã¯ã©ã¦ãç°å¢ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ã¾ãã¯ç¾ç¶ææ¡ãéè¦ã§ããã»ãã¥ãªãã£åºæºã«åºã¥ããã¢ã»ã¹ã¡ã³ããµã¼ãã¹ãå種ã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãªã©ã§ã®ãæ¯æ´ãå¯è½ã§ããã¾ããææ°ã®PCI DSS Version4.0ã«å¯¾å¿ã§ãããµã¼ãã¹ãæä¾ãã¦ããã¾ãããæ°è»½ã«ãåãåãããã ããã
â»ãPCI DSSãã¼ã¿ã«ãµã¼ãã¹ããå·æ° | NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾ (intellilink.co.jp)
â»ãåãåãããã©ã¼ã ãhttps://www.intellilink.co.jp/contact-us.aspx
â»Amazon Web ServicesããPowered by Amazon Web Servicesããã´ãããã³ãããè³æã§ä½¿ç¨ããããã®ä»ã®AWSåæ¨ã¯ãç±³å½ããã³/ã¾ãã¯ãã®ä»ã®è«¸å½ã«ããããAmazon.com, Inc.ã¾ãã¯ãã®é¢é£ä¼ç¤¾ã®åæ¨ã§ãã