{"id":2282,"date":"2022-01-07T10:07:45","date_gmt":"2022-01-07T01:07:45","guid":{"rendered":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/?p=2282"},"modified":"2022-01-07T10:07:45","modified_gmt":"2022-01-07T01:07:45","slug":"least-privilege-with-iam-access-analyzer","status":"publish","type":"post","link":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2022\/01\/07\/least-privilege-with-iam-access-analyzer\/","title":{"rendered":"\u300cPatch Manager\u306e\u305f\u3081\u306b\u5fc5\u8981\u306a\u6700\u4f4e\u9650\u306e\u6a29\u9650\u3063\u3066\u3069\u308c\u306a\u3093\u3060\u308d\u3046\u300d\u301c IAM Access Analyzer \u3067\u672c\u5f53\u306b\u5fc5\u8981\u306a\u6700\u5c0f\u6a29\u9650\u3092\u5b9f\u73fe\u3059\u308b\u301c"},"content":{"rendered":"\n
\u897f\u85e4\u3067\u3059\u3002<\/p>\n\n\n
\u60c5\u5831\u30b7\u30b9\u30c6\u30e0\u4e0a\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u9650\u306e\u904b\u7528\u306b\u304a\u3044\u3066\u5ea6\u3005\u76ee\u306b\u3059\u308b\u8a00\u8449\u3068\u3057\u3066\u300c\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u300d\u3068\u3044\u3046\u3082\u306e\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u300c\u6a29\u9650\u306e\u4ed8\u4e0e\u306f\u6700\u5c0f\u9650\u306e\u3082\u306e\u304b\u3089\u4ed8\u4e0e\u3057\u3066\u3044\u304d\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u8ffd\u52a0\u3057\u3066\u3044\u304f\u3002\u305d\u3057\u3066\u4e0d\u8981\u306a\u6642\u306b\u306f\u6a29\u9650\u3092\u7834\u68c4\u3059\u308b\u300d\u3068\u3044\u3046\u3053\u3068\u304c\u8a00\u308f\u308c\u3066\u304a\u308a\u3001\u60c5\u5831\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306b\u304a\u3044\u3066\u306f\u91cd\u8981\u306a\u539f\u5247\u3067\u3059\u3002<\/p>\n\n\n
\u305f\u3060\u3057\u3001\u3053\u306e\u539f\u5247\u306b\u3057\u305f\u304c\u3063\u3066\u3044\u304d\u307e\u3059\u3068\u30b7\u30b9\u30c6\u30e0\u306e\u7acb\u3061\u4e0a\u3052\u6bb5\u968e\u306b\u304a\u3044\u3066\u306f<\/p>\n\n\n
\u306f\u3058\u3081\u306bA\u304c\u52d5\u4f5c\u3067\u304d\u306a\u304b\u3063\u305f\u304b\u3089\u6a29\u9650\u3092\u8db3\u3057\u3066\u3001<\/p>\n
\u6b21\u306bB\u3082\u5fc5\u8981\u3060\u304b\u3089\u6a29\u9650\u3092\u8db3\u3057\u3066\u3001<\/p>\n
\u305d\u3057\u305f\u3089\u3001C\u3082\u3046\u307e\u304f\u3044\u304b\u306a\u304b\u3063\u305f\u304b\u3089\u6a29\u9650\u3092\u8db3\u3057\u3066\u30fb\u30fb\u30fb\u30fb<\/p><\/blockquote>\n\n\n
\u3068\u3044\u3046\u5177\u5408\u306b\u3001\u5e0c\u671b\u306e\u52d5\u4f5c\u304c\u3067\u304d\u308b\u6a29\u9650\u69cb\u6210\u306b\u306a\u308b\u307e\u3067\u306b\u6642\u9593\u3092\u8981\u3057\u3066\u3057\u307e\u3046\u3053\u3068\u304c\u591a\u3005\u3042\u308a\u5f97\u307e\u3059\u3002<\/p>\n\n\n
\u3082\u3061\u308d\u3093\u3001\u9806\u6b21\u8db3\u3057\u3066\u3044\u304f\u3053\u3068\u304c\u3082\u3063\u3068\u3082\u63a8\u5968\u3055\u308c\u308b\u3084\u308a\u65b9\u3067\u306f\u3042\u308a\u307e\u3059\u304c\u3001\u958b\u767a\u9032\u884c\u306b\u304a\u3051\u308b\u969c\u58c1\u3068\u306a\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u305d\u3053\u3067\u53c2\u8003\u306b\u3057\u305f\u3044\u306e\u304cAWS\u306e\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u304a\u3051\u308bIAM\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u3067\u306e\u8a18\u8f09\u3067<\/p>\n\n\n
- \u300c\u30a2\u30af\u30bb\u30b9\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u57fa\u3065\u304f\u30dd\u30ea\u30b7\u30fc\u306e\u751f\u6210\u300d1<\/a><\/sup><\/li><\/ul>\n\n\n
\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u5229\u7528\u5c65\u6b74\u306b\u57fa\u3065\u3044\u3066\u30dd\u30ea\u30b7\u30fc\u3092\u751f\u6210\u3057\u3001\u305d\u308c\u3092\u9069\u7528\u3057\u3066\u3044\u304f\u3053\u3068\u3067\u3088\u308a\u5c0f\u3055\u306a\u6a29\u9650\u69cb\u6210\u3092\u5b9f\u73fe\u3057\u3088\u3046\u3002\u3068\u3044\u3046\u30a2\u30d7\u30ed\u30fc\u30c1\u3067\u3059\u3002<\/p>\n\n\n
\u305f\u3068\u3048\u3070\u3001\u300c\u76f4\u8fd130\u65e5\u9593\u904b\u7528\u3057\u3066\u307f\u3066\u3001\u5b9f\u969b\u306b\u5229\u7528\u5c65\u6b74\u306e\u3042\u3063\u305f\u6a29\u9650\u3060\u3051\u306b\u7d5e\u308b\u300d\u3068\u8a00\u3046\u3053\u3068\u304c\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n\n\n
\u3053\u308c\u306f\u3001\u904b\u7528\u306e\u306f\u3058\u3081\u306b\u6bd4\u8f03\u7684\u7de9\u3081\u306e\u6a29\u9650\u3092\u4ed8\u4e0e\u3059\u308b\u3053\u3068\u306b\u306f\u306a\u308a\u307e\u3059\u3002\u3057\u304b\u3057\u300cA\u304c\u3067\u304d\u306a\u304b\u3063\u305f\u6b21\u306f\u3001B\u3082\u3067\u304d\u306a\u304f\u3066\u30fb\u30fb\u30fb\u300d\u3068\u3044\u3046\u5177\u5408\u306b\u3001\u90fd\u5ea6\u90fd\u5ea6\u3001\u6a29\u9650\u3092\u8db3\u3057\u3066\u3044\u304f\u3053\u3068\u3092\u6c42\u3081\u3089\u308c\u308b\u72b6\u6cc1\u3068\u6bd4\u3079\u308b\u3068\u3001\u304b\u306a\u308a\u73fe\u5b9f\u7684\u306a\u30a2\u30d7\u30ed\u30fc\u30c1\u3067\u3059\u3002<\/p>\n\n\n
\u4eca\u56de\u306f\u3001\u300c\u30a2\u30af\u30bb\u30b9\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u57fa\u3065\u304f\u30dd\u30ea\u30b7\u30fc\u306e\u751f\u6210\u300d\u306b\u304a\u3051\u308b\u30c4\u30fc\u30eb\u3068\u3057\u3066AWS\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u8cc7\u6599\u4e0a\u3067\u3082\u8a00\u53ca\u3055\u308c\u3066\u3044\u308b\"IAM Access Analyzer\"\u3092\u4f7f\u3063\u3066\u3001<\/p>\n\n
\nSystems Manager Patch Manager\u3092\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u3082\u542b\u3081\u3066\u904b\u7528\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u6a29\u9650\u3060\u3051\u3092\u4ed8\u4e0e\u3059\u308b<\/p>\n<\/blockquote>\n\n
\u3068\u8a00\u3046\u30b7\u30ca\u30ea\u30aa\u306e\u5b9f\u8df5\u4f8b\u3092\u8a18\u8f09\u3057\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n\n\n
\u672c\u8a18\u4e8b\u304c\u300c\u30a2\u30af\u30bb\u30b9\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u57fa\u3065\u304f\u30dd\u30ea\u30b7\u30fc\u306e\u751f\u6210\u300d\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u3067\u6700\u5c0f\u6a29\u9650\u3092\u5b9f\u73fe\u3057\u3066\u3044\u304f\u305f\u3081\u306e\u65b9\u6cd5\u306e\u53c2\u8003\u306b\u306b\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\u3002<\/p>\n\n\n
\u203b\u306a\u304a\u3001\u300cSystems Manager Patch Manager\u3092\u4f7f\u3063\u305f\u30d1\u30c3\u30c1\u9069\u7528\u306e\u3084\u308a\u65b9\u300d\u81ea\u4f53\u306f\u5272\u611b\u3044\u305f\u3057\u307e\u3059\u3002<\/p>\n\n\n
\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\"AmazonSSMManagedInstanceCore\"\u306b\u3064\u3044\u3066<\/h2>\n\n\n
\u307e\u305a\u59cb\u3081\u306b\u3001\u9069\u5207\u306a\u6a29\u9650\u306e\u4ed8\u4e0e\u3092\u3057\u3066\u3044\u304f\u4e0a\u3067\u691c\u8a0e\u3057\u305f\u3044\u306e\u304c\u3001\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\u3067\u3059\u3002<\/p>\n\n\n
Systems Manager\u3092\u4f7f\u3046\u305f\u3081\u306e\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\u3068\u3057\u3066
AmazonSSMManagedInstanceCore<\/code>\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n
\u3053\u308c\u306fAWS\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3067\u306e\u89e3\u8aac\u306b\u3066<\/p>\n\n\n
\u3053\u306e AWS \u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\u306b\u3088\u308a\u3001\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306f Systems Manager \u30b5\u30fc\u30d3\u30b9\u30b3\u30a2\u6a5f\u80fd\u3092\u4f7f\u7528\u3067\u304d\u307e\u3059\u30022<\/a><\/sup><\/p><\/blockquote>\n\n\n
\u3068\u3042\u308b\u3088\u3046\u306b\u3001Systems Manager\u3092\u4f7f\u3046\u4e0a\u3067\u306e\u6700\u4f4e\u9650\u306e\u6a29\u9650\u30bb\u30c3\u30c8\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u308b\u306e\u3067\u30011\u304b\u3089\u30dd\u30ea\u30b7\u30fc\u8a2d\u8a08\u3092\u3059\u308b\u624b\u9593\u3092\u7701\u304f\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n
\u3053\u308c\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u3053\u306e\u3088\u3046\u306a\u6a29\u9650\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u3053\u308c\u3060\u3051\u3067\u3082Systems Manager\u306e\u52d5\u4f5c\u306f\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u3001\u30d1\u30c3\u30c1\u9069\u7528\u306f\u884c\u3048\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u52d5\u4f5c\u78ba\u8a8d\u3057\u3066\u307f\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n
\"AmazonSSMManagedInstanceCore\"\u3060\u3051\u306e\u72b6\u614b\u306e\u52d5\u4f5c\u78ba\u8a8d<\/h2>\n\n\n
\u30d1\u30c3\u30c1\u9069\u7528\u306e\u3084\u308a\u65b9\u81ea\u4f53\u306f\u5272\u611b\u3057\u307e\u3059\u304c\u3001<\/p>\n\n\n
- Amazon Linux 2\u306e\u53e4\u3044\u30de\u30b7\u30f3\u30a4\u30e1\u30fc\u30b8\u3092\u4f7f\u3063\u3066EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u7acb\u3061\u4e0a\u3052\u308b\uff08\u3064\u307e\u308a\u30d1\u30c3\u30c1\u9069\u7528\u5bfe\u8c61\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u304c\u591a\u304f\u3042\u308b\uff09<\/li>
- \u305d\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u5bfe\u3057\u3066Patch Manager\u3067\u306e\u5b9f\u65bd\u7d50\u679c\u306e\u78ba\u8a8d\uff08\u914d\u4fe1\u3055\u308c\u3066\u3044\u308b\u3059\u3079\u3066\u306e\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b\uff09<\/li><\/ul>\n\n\n
\u3092\u884c\u306a\u3063\u305f\u7d50\u679c\u304c\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n\n\n
Systems Manager\u3067\u306e\u8868\u793a\uff1a<\/p>\n\n
<\/a><\/p>\n\n
\u2192\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u304c\u6210\u529f\u3057\u3066\u3044\u308b<\/p>\n\n\n
\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u5185\uff1a<\/p>\n\n
<\/a><\/p>\n\n
\u2192\"No packages marked for update\"\u306e\u8868\u793a\u3068\u306a\u3063\u3066\u304a\u308a\u3001\u3059\u3079\u3066\u306e\u30d1\u30c3\u30c1\u304c\u9069\u7528\u3055\u308c\u3066\u3044\u308b\u72b6\u614b\u3002<\/p>\n\n\n
\u4ee5\u4e0a\u306e\u901a\u308a\u3001\u30d1\u30c3\u30c1\u9069\u7528\u306e\u5b9f\u65bd\u3060\u3051\u3067\u3042\u308c\u3070\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc
AmazonSSMManagedInstanceCore<\/code>\u3092\u4f7f\u3046\u3060\u3051\u3067\u5b9f\u73fe\u3067\u304d\u308b\u3068\u8a00\u3046\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u3057\u304b\u3057\u3001\u3053\u306e\u6a29\u9650\u69cb\u6210\u3060\u3051\u3067\u3059\u3068\u6a29\u9650\u306e\u4e0d\u8db3\u306b\u3088\u308aSystems Manager\u306b\u3088\u308b\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u306e\u30ed\u30b0\u3092CloudWatch Logs\u306b\u66f8\u304d\u51fa\u305b\u305a\u5c65\u6b74\u3092\u898b\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u305b\u3093\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u300c\u30ed\u30b0\u3092\u3053\u3053\u304b\u3089\u898b\u308b\u300d\u65e8\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u304c\u30fb\u30fb\u30fb<\/p>\n\n
<\/a><\/p>\n\n
\u2192\u300c\u8a72\u5f53\u306e\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u304c\u5b58\u5728\u3057\u306a\u3044\u300d\u3068\u306e\u30a8\u30e9\u30fc\u306b\u306a\u308b\u3002<\/p>\n\n\n
\u3053\u306e\u72b6\u614b\u304b\u3089CloudWatch Logs\u306b\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u3092\u3067\u304d\u308b\u3088\u3046\u306b\u6a29\u9650\u8a2d\u5b9a\u3092\u9032\u3081\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n\n\n
\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\"CloudWatchLogsFullAccess\"\u3092\u4ed8\u4e0e<\/h2>\n\n\n
\u307e\u305a\u306f\u6b63\u5e38\u306b\u52d5\u4f5c\u3059\u308b\u305f\u3081\u306b\u5236\u7d04\u306e\u3086\u308b\u3044\u5f62\u3067\u6a29\u9650\u3092\u4ed8\u4e0e\u3057\u307e\u3059\u3002<\/p>\n\n\n
\u5177\u4f53\u7684\u306b\u306f\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\u306e
CloudWatchLogsFullAccess<\/code>\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u3067\u306f\u3001\u3053\u306e\u3088\u3046\u306b\u6a29\u9650\u3092\u4ed8\u4e0e\u3057\u305f\u4e0a\u3067Systems Manager\u306ePatch Manager\u3092\u4f7f\u3046\u3068\u3069\u3046\u306a\u308b\u304b\u3002\u7d50\u679c\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002\uff08\u4e0a\u8a18\u3068\u307e\u3063\u305f\u304f\u540c\u3058\u69cb\u6210\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u65b0\u8a2d\u3057\u3066\u3001\u5b9f\u884c\u3057\u307e\u3057\u305f\u3002\uff09<\/p>\n\n\n
Systems Manager\u3067\u306e\u8868\u793a\uff1a<\/p>\n\n
<\/a><\/p>\n\n
\u2192\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u304c\u6210\u529f\u3057\u3066\u3044\u308b<\/p>\n\n\n
\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u5185\uff1a<\/p>\n\n
<\/a><\/p>\n\n
\u2192\"No packages marked for update\"\u306e\u8868\u793a\u3068\u306a\u3063\u3066\u304a\u308a\u3001\u3059\u3079\u3066\u306e\u30d1\u30c3\u30c1\u304c\u9069\u7528\u3055\u308c\u3066\u3044\u308b\u72b6\u614b\u3002<\/p>\n\n\n
CloudWatch Logs\uff1a<\/p>\n\n
<\/a><\/p>\n\n
\u2192\u8a72\u5f53\u306e\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u4e0a\u306b\u30ed\u30b0\u304c\u66f8\u304d\u8fbc\u307e\u308c\u3066\u3044\u308b\u3002<\/p>\n\n\n
\u4ee5\u4e0a\u306e\u901a\u308a\u3001\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\"CloudWatchLogsFullAccess\"\u3092\u4ed8\u4e0e\u3059\u308b\u3053\u3068\u3067\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u304c\u5b9f\u73fe\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n\n\n
\u3057\u304b\u3057\u3001\u3053\u306e\u30de\u30cd\u30fc\u30b8\u30c9\u30dd\u30ea\u30b7\u30fc\u306f\u3001\"FullAccess\"\u306e\u540d\u306e\u901a\u308a\u3001\"CloudWatch Logs\"\u306e\u30b5\u30fc\u30d3\u30b9\u306b\u7d5e\u308a\u8fbc\u307e\u308c\u3066\u306f\u3044\u307e\u3059\u304c\u3001\u305d\u306e\u4e2d\u3067\u306e\u5168\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u8a31\u53ef\u3055\u308c\u3066\u3044\u308b\u69cb\u6210\u3067\u3059\u3002<\/p>\n\n\n
\u305d\u306e\u305f\u3081\u3001\u4f5c\u6210\u6e08\u307f\u306e\u30ed\u30b0\u3084\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u3092\u524a\u9664\u3067\u304d\u308b\u6a29\u9650\u3082\u542b\u307e\u308c\u3066\u3044\u308b\u306e\u3067\u3001\u300c\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u305f\u3044\u300d\u3068\u8a00\u3046\u76ee\u7684\u304b\u3089\u3059\u308b\u3068\u904e\u5270\u306b\u6a29\u9650\u3092\u4e0e\u3048\u3066\u3057\u307e\u3063\u3066\u304a\u308a\u3001\u300c\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u300d\u304b\u3089\u306f\u9038\u8131\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n
\u3053\u306e\u72b6\u614b\u304b\u3089\u300c\u5229\u7528\u5b9f\u614b\u306e\u3042\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u3060\u3051\u300d\u3092\u8a31\u53ef\u3059\u308b\u3088\u3046\u306b\u3059\u308b\u305f\u3081\u3001IAM Access Analyzer\u3092\u4f7f\u3063\u3066\u30dd\u30ea\u30b7\u30fc\u751f\u6210\u3092\u3057\u307e\u3059\u3002<\/p>\n\n\n
IAM Access Analyzer\u3067\u30dd\u30ea\u30b7\u30fc\u751f\u6210<\/h2>\n\n\n
IAM Access Analyzer\u3067\u306e\u30dd\u30ea\u30b7\u30fc\u751f\u6210\u3092\u884c\u3046\u305f\u3081\u306b\u306f\u3001\u8a72\u5f53\u306eIAM\u30ed\u30fc\u30eb\u306e\u753b\u9762\u3067\u300cCloudTrail\u30a4\u30d9\u30f3\u30c8\u306b\u57fa\u3065\u3044\u3066\u30dd\u30ea\u30b7\u30fc\u3092\u751f\u6210\u300d\u306e\u6b04\u306b\u3042\u308b\u30dc\u30bf\u30f3\u304b\u3089\u958b\u59cb\u3067\u304d\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u5229\u7528\u5b9f\u614b\u3092\u5206\u6790\u3059\u308b\u305f\u3081\u306eCloudTrail\u306etrail\u3068\u3001\u305d\u306e\u5206\u6790\u671f\u9593\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u300c\u30dd\u30ea\u30b7\u30fc\u3092\u4f5c\u6210\u300d\u3092\u62bc\u3057\u3066\u3001\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u884c\u3046\u3068\u5206\u6790\u304c\u958b\u59cb\u3055\u308c\u305f\u65e8\u306e\u8868\u793a\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u751f\u6210\u304c\u5b8c\u4e86\u3059\u308b\u3068\u300c\u6210\u529f\u300d\u306e\u8868\u793a\u3068\u306a\u308b\u306e\u3067\u3001\u300c\u751f\u6210\u3055\u308c\u305f\u30dd\u30ea\u30b7\u30fc\u3092\u8868\u793a\u300d\u3092\u958b\u304f<\/p>\n\n
<\/a><\/p>\n\n
\u3059\u308b\u3068\u30dd\u30ea\u30b7\u30fc\u751f\u6210\u3092\u3059\u308b\u30a6\u30a3\u30b6\u30fc\u30c9\u306b\u5165\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u6307\u5b9a\u671f\u9593\u4e2d\u306b\u691c\u51fa\u3055\u308c\u305f\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u5185\u8a33\u304c\u8868\u793a\u3055\u308c\u308b\u307b\u304b\u3001\u305d\u308c\u4ee5\u5916\u306b\u3082\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u8ffd\u52a0\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n
\u305f\u3068\u3048\u3070\u3001\u300c\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u691c\u51fa\u3055\u308c\u306a\u304b\u3063\u305f\u3051\u3069\u3001\u6a29\u9650\u304c\u5fc5\u8981\u306b\u306a\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u308b\u300d\u3068\u8a00\u3046\u3088\u3046\u306a\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u8ffd\u52a0\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n
\u4eca\u56de\u306f\u300cCloudWatch Logs\u306b\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u3092\u3059\u308b\u3053\u3068\u300d\u304c\u76ee\u7684\u306a\u306e\u306b\u3001\u691c\u51fa\u3055\u308c\u3066\u3044\u306a\u304b\u3063\u305f\"PutLogEvents\"\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u6b21\u306bjson\u5f62\u5f0f\u306e\u30dd\u30ea\u30b7\u30fc\u306e\u7de8\u96c6\u753b\u9762\u306b\u5165\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u76f4\u524d\u306e\u753b\u9762\u3067\u8868\u793a\u3055\u308c\u3066\u3044\u305f\u5404\u30b5\u30fc\u30d3\u30b9\u3054\u3068\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n\n\n
\u307e\u305f\u3001
Resource<\/code>\u306e\u90e8\u5206\u306f
${Region}<\/code>,
${Account}<\/code>\u306a\u3069\u306e\u3088\u3046\u306a\u5f62\u3067\u30d7\u30ec\u30fc\u30b9\u30db\u30eb\u30c0\u30fc\u306b\u306a\u3063\u3066\u304a\u308a\u3001\u305d\u306e\u307e\u307e\u3067\u306f\u4f7f\u3046\u3053\u3068\u304c\u3067\u304d\u307e\u305b\u3093\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u4eca\u56de\u306f\u300cCloudWatch Logs\u306b\u30ed\u30b0\u3092\u66f8\u304d\u8fbc\u3081\u308b\u3088\u3046\u306b\u3057\u305f\u3044\u300d\u3068\u8a00\u3046\u306e\u304c\u76ee\u7684\u3067\u3057\u305f\u306e\u3067\u3001\u6b21\u306e\u7de8\u96c6\u3092\u3057\u307e\u3059<\/p>\n
\n
- CloudWatch Logs\u306e\u4ee5\u5916\u306e\u30b5\u30fc\u30d3\u30b9\u7528\u306e\u30d6\u30ed\u30c3\u30af\u306f\u524a\u9664<\/li>\n
- \u30d7\u30ec\u30fc\u30b9\u30db\u30eb\u30c0\u30fc\u3067\u306e\u8a18\u8ff0\u304c\u5165\u3063\u3066\u3044\u305f
Resource<\/code>\u306e\u90e8\u5206\u3067\u30ea\u30fc\u30b8\u30e7\u30f3\u3092\u6771\u4eac\u30ea\u30fc\u30b8\u30e7\u30f3\u306b\u6307\u5b9a<\/li>\n
- \u30d7\u30ec\u30fc\u30b9\u30db\u30eb\u30c0\u30fc\u3067\u306e\u8a18\u8ff0\u306b\u306a\u3063\u3066\u3044\u305fAWS\u30a2\u30ab\u30a6\u30f3\u30c8ID\u90e8\u5206\u3092\u81ea\u5206\u306eAWS\u30a2\u30ab\u30a6\u30f3\u30c8ID\u306b\u6307\u5b9a<\/li>\n<\/ul>\n\n
<\/a><\/p>\n\n
\u300c\u6b21\u3078\u300d\u3092\u62bc\u4e0b\u3057\u3066\u753b\u9762\u3092\u3059\u3059\u3081\u308b\u3068IAM\u30dd\u30ea\u30b7\u30fc\u306e\u4f5c\u6210\u78ba\u5b9a\u753b\u9762\u306b\u306a\u308a\u307e\u3059\u3002\u4f5c\u6210\u3068\u540c\u6642\u306b\u8a72\u5f53\u306eIAM\u30ed\u30fc\u30eb\u306b\u4ed8\u4e0e\u3059\u308b\u30aa\u30d7\u30b7\u30e7\u30f3\u3082\u3042\u308b\u306e\u3067\u305d\u306e\u307e\u307e\u78ba\u5b9a\u3057\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u3053\u306e\u3088\u3046\u306b\u8a72\u5f53\u306e\u30ed\u30fc\u30eb\u306b\u306f\u751f\u6210\u3055\u308c\u305f\u30dd\u30ea\u30b7\u30fc\u304c\u30a2\u30bf\u30c3\u30c1\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u3053\u308c\u306b\u3088\u308a\u3001\"CloudWatch Logs\"\u306b\u95a2\u3059\u308b\u300c\u5fc5\u8981\u6700\u4f4e\u9650\u300d\u306e\u6a29\u9650\u3092\u9069\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u305f\u306e\u3067\u3001\u5143\u3005\u3064\u3051\u3066\u3044\u305f
CloudWatchLogsFullAccess<\/code>\u306e\u30dd\u30ea\u30b7\u30fc\u306f\u5916\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n
\u6700\u7d42\u7248<\/h2>\n\n\n
\u4ee5\u4e0a\u306e\u8a2d\u5b9a\u3092\u8e0f\u307e\u3048\u3066\u3001\u6700\u7d42\u7684\u306b\u8a72\u5f53\u306e\u30ed\u30fc\u30eb\u306b\u3064\u3044\u3066\u3044\u308b\u6a29\u9650\u306f\u6b21\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n
<\/a><\/p>\n\n
\u5143\u3005\u3001FullAccess\u3067\u3064\u3051\u3066\u3044\u305fCloudWatch Logs\u7528\u306e\u6a29\u9650\u304c\u5229\u7528\u5b9f\u7e3e\u306b\u5408\u308f\u305b\u3066\u5fc5\u8981\u6700\u4f4e\u9650\u306e\u6a29\u9650\u306b\u7d5e\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n\n\n
\u8a73\u7d30\u306f\u5272\u611b\u3057\u307e\u3059\u304c\u3001\u3053\u306e\u65b0\u305f\u306a\u6a29\u9650\u69cb\u6210\u3067\u3082\u540c\u3058\u3088\u3046\u306b\u30d1\u30c3\u30c1\u9069\u7528\u3068CloudWatch Logs\u306e\u30ed\u30b0\u66f8\u304d\u8fbc\u307f\u304c\u884c\u308f\u308c\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n\n\n
\u307e\u3068\u3081<\/h2>\n\n\n
\u4ee5\u4e0a\u3001 IAM Access Analyzer\u3092\u4f7f\u3063\u3066\u3001\u300c\u30a2\u30af\u30bb\u30b9\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u57fa\u3065\u304f\u30dd\u30ea\u30b7\u30fc\u306e\u751f\u6210\u300d\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u3067\u6700\u5c0f\u6a29\u9650\u3092\u5b9f\u73fe\u3059\u308b\u65b9\u6cd5\u3092\u7d39\u4ecb\u3057\u307e\u3057\u305f\u3002<\/p>\n\n
\u672c\u6765\u3042\u308b\u3079\u304d\u59ff\u3068\u3057\u3066\u306f\u3001FullAcceess\u3067\u6a29\u9650\u3092\u4ed8\u4e0e\u3057\u3066\u3057\u307e\u3046\u306e\u306f\u597d\u307e\u3057\u304f\u306a\u304f\u3001\u5c0f\u3055\u306a\u6a29\u9650\u304b\u3089\u4ed8\u4e0e\u3057\u3066\u3044\u304f\u306e\u304c\u7406\u60f3\u3067\u3059\u3002<\/p>\n
\u3057\u304b\u3057\u3001\u7a3c\u50cd\u3092\u59cb\u3081\u3066\u3057\u307e\u3063\u3066\u3044\u308b\u30b7\u30b9\u30c6\u30e0\u306b\u3066\u3001\u610f\u56f3\u305b\u305a\u5927\u304d\u306a\u6a29\u9650\u3092\u4ed8\u4e0e\u3057\u3066\u3044\u305f\u3053\u3068\u306b\u6c17\u3065\u304d\u3001\u6a29\u9650\u3092\u7d5e\u308a\u8fbc\u3093\u3067\u3044\u304d\u305f\u3044\u6642\u306a\u3069\u3001AWS\u304c\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3053\u3046\u3044\u3063\u305f\u30c4\u30fc\u30eb\u306f\u7a4d\u6975\u7684\u306b\u6d3b\u7528\u3057\u3066\u3044\u304d\u305f\u3044\u3068\u3053\u308d\u3067\u3059\u3002<\/p>\n\n
\u6b8b\u5ff5\u306a\u304c\u3089\u3001100%\u30c4\u30fc\u30eb\u306b\u4efb\u305b\u3063\u304d\u308a\u3068\u306f\u3044\u304b\u305a\u3001IAM\u30dd\u30ea\u30b7\u30fc\u306e\u69cb\u6210\u3092\u7406\u89e3\u3057\u306a\u304c\u3089\u81ea\u5206\u3067\u3082\u88dc\u5b8c\u3059\u308b\u5fc5\u8981\u306f\u3042\u308a\u307e\u3057\u305f\u304c\u3001\u4ed8\u4e0e\u6e08\u307f\u306e\u6a29\u9650\u3092\u7d5e\u308a\u8fbc\u3093\u3067\u3044\u304f\u969b\u306b\u4f7f\u3046\u3082\u306e\u3068\u3057\u3066\u306f\u975e\u5e38\u306b\u4fbf\u5229\u306a\u30c4\u30fc\u30eb\u3060\u3068\u611f\u3058\u307e\u3057\u305f\u3002<\/p>\n\n\n
\u6a29\u9650\u7ba1\u7406\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306b\u6e96\u3058\u3066\u3001\u9069\u5207\u306aIAM\u30dd\u30ea\u30b7\u30fc\u306e\u69cb\u6210\u7ba1\u7406\u3092\u3057\u3066\u3044\u304f\u4e0a\u3067\u3001\u672c\u8a18\u4e8b\u304c\u53c2\u8003\u306b\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\u3002<\/p>\n\n
\u53c2\u8003\u8cc7\u6599<\/h2>\n\n
- https:\/\/docs.aws.amazon.com\/ja_jp\/IAM\/latest\/UserGuide\/best-practices.html#grant-least-privilege<\/a>\u21a9<\/a><\/li>
- https:\/\/docs.aws.amazon.com\/ja_jp\/systems-manager\/latest\/userguide\/setup-instance-profile.html#instance-profile-policies-overview<\/a>\u21a9<\/a><\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"
\u306f\u3058\u3081\u306b \u897f\u85e4\u3067\u3059\u3002 \u60c5\u5831\u30b7\u30b9\u30c6\u30e0\u4e0a\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u9650\u306e\u904b\u7528\u306b\u304a\u3044\u3066\u5ea6\u3005\u76ee\u306b\u3059\u308b\u8a00\u8449\u3068\u3057\u3066\u300c\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u300d\u3068\u3044\u3046\u3082\u306e\u304c\u3042\u308a\u307e\u3059\u3002 \u300c\u6a29\u9650\u306e\u4ed8\u4e0e\u306f\u6700\u5c0f\u9650\u306e\u3082\u306e\u304b\u3089\u4ed8\u4e0e\u3057\u3066\u3044\u304d\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u8ffd\u52a0\u3057\u3066\u3044\u304f\u3002\u305d\u3057\u3066\u4e0d\u8981\u306a\u6642\u306b\u306f\u6a29\u9650\u3092\u7834\u68c4\u3059\u308b\u300d\u3068\u3044\u3046\u3053\u3068\u304c\u8a00\u308f\u308c\u3066\u304a\u308a\u3001\u60c5\u5831\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306b\u304a\u3044\u3066\u306f\u91cd\u8981\u306a\u539f\u5247\u3067\u3059\u3002 \u305f\u3060\u3057\u3001\u3053\u306e\u539f\u5247\u306b\u3057\u305f\u304c\u3063\u3066\u3044\u304d\u307e\u3059\u3068\u30b7\u30b9\u30c6\u30e0\u306e\u7acb\u3061\u4e0a\u3052\u6bb5\u968e\u306b\u304a\u3044\u3066\u306f \u306f\u3058\u3081\u306bA\u304c\u52d5\u4f5c\u3067\u304d\u306a\u304b\u3063 […]<\/p>\n","protected":false},"author":6,"featured_media":2309,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[13],"tags":[344,32],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/2282"}],"collection":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/comments?post=2282"}],"version-history":[{"count":27,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/2282\/revisions"}],"predecessor-version":[{"id":2311,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/2282\/revisions\/2311"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media\/2309"}],"wp:attachment":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media?parent=2282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/categories?post=2282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/tags?post=2282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}