
ãã®è¨äºã¯ãCYBOZU SUMMER BLOG FES '25ã®è¨äºã§ãã
ããã«ã¡ã¯ãkintoneéçºçµç¹ã§ã¨ã³ã¸ãã¢ãªã³ã°ããã¼ã¸ã£ã¼ããã¦ããä¸å²¡ï¼@ueokandeï¼ã§ãã å°ãåã®è©±ã§ãããã°ãã¼ãã«å¸å ´åãkintone1ï¼ä»¥ä¸kintone.comï¼ã«ããã¦ã2023å¹´12æã«SOC2 Type 1ã2024å¹´8æã«SOC2 Type2ã®ä¿è¨¼å ±åæ¸ãåé ãã¾ããã以éãæ¯å¹´å ±åæ¸ã®æ´æ°ãããããã«ãç¶ç¶çãªè©ä¾¡ããã³éç¨æ¹åã«åãçµãã§ãã¾ãã
ãµã¤ãã¦ãºã¯ããã¾ã§ãISMSãISMAPãªã©ã®ã»ãã¥ãªãã£èªè¨¼ãè©ä¾¡ãåå¾ãã¦ãã¾ããã ããããã°ãã¼ãã«å¸å ´ã§ã¯SOC2ã®èªç¥åº¦ãå§åçã«é«ããkintone.comã®ã°ãã¼ãã«å±éã«ããã¦éè¦ãªå½¹å²ãæããã¾ãã
SOCã¯ãã峿 ¼ãªã»ãã¥ãªãã£åºæºãæ±ããããåå¾ã¾ã§ããã2å¹´ãã®æéãè¦ãã¾ããã ãã®è¨äºã§ã¯ãkintone.comãSOC2ä¿è¨¼å ±åæ¸ãåé ããã¾ã§ã®åãçµã¿ãç´¹ä»ãã¾ãã
SOC2ã«ã¤ãã¦
SOC2ã¯AICPAãå®ãããµã¤ãã¼ã»ãã¥ãªãã£ã®ãã¬ã¼ã ã¯ã¼ã¯ã§ããã»ãã¥ãªãã£ããã©ã¤ãã·ã¼ãå¯ç¨æ§ãæ©å¯æ§ãå¦çã®å®å ¨æ§ã®5ã¤ã®é ç®ã§ãã¼ã¿ã»ãã¥ãªãã£ã®åºæºãå®ãã¦ãã¾ãã SOC2ã¯ç¬¬ä¸è ç£æ»æ³äººã伿¥ãè©ä¾¡ãã¦å ±åæ¸ãã¾ã¨ãããã®ã§ããããã®5ã¤ã®é ç®ã«æºæ ããããã«ã¼ã«ãå¶å®ããå®éã®éç¨ãè¡ãå¿ è¦ãããã¾ãã
SOC2ã«ã¯ç£æ»æéã®éãã«ãã£ã¦Type 1ã¨Type 2ãããã¾ããType 1ã¯ç¹å®ã®æ¥ä»æç¹ã§ã®ç£æ»ãType 2ã¯6ã¶æä»¥ä¸ã®æéã«ãããç£æ»ãåãã¾ããé·æçãªéç¨ç¶æ³ãè©ä¾¡ãããType 2ã¯ãType 1ã¨æ¯ã¹ã¦ãã峿 ¼ãªç£æ»ãæ±ãããã¾ãã
å ·ä½çãªåãçµã¿
SOC2ã§ã¯ISMSããã峿 ¼ãªåºæºãæ±ãããã¾ãã SOC2ã®ç£æ»ã§ã¯ä»¥ä¸ã®ãã¤ã³ãã§ç¢ºèªããã¾ããã
- ã»ãã¥ãªãã£ã«ã¼ã«ãååãªæ°´æºãã
- ã»ãã¥ãªãã£ã«ã¼ã«ã«å¾ã£ã¦ãã¡ãã¨ããã»ã¹åããã¦ãããã
- ããã»ã¹ããã¡ãã¨å®æ½ããã¦ãããã
1.ããã³2.ã«ã¤ãã¦ã¯ã社å ã®ã»ãã¥ãªãã£ã«ã¼ã«ãéç¨ããã»ã¹ã®ããã¥ã¡ã³ããç£æ»æ³äººã«æåºãããã£ã¼ãããã¯ãåºã«æ¹åãã¾ããã 3.ã«ã¤ãã¦ã¯è¨¼è·¡ï¼ã¨ããã³ã¹ï¼ãè¨é²ã»æåºãããã¨ã§ãããã»ã¹ã«æ²¿ã£ãéç¨ãã§ãã¦ããã確èªããã¾ããType 2ã§ã¯ç£æ»æéä¸ã®ç¡ä½çºæ½åºã«ããè¨¼è·¡ã®æåºãå¿ è¦ã¨ãªãã¾ãããã®ãããããã»ã¹ã®å¾¹åºã¨èªååã«ãã証跡ã®è¨é²æ¼ã鲿¢ã«æ°ãã¤ããå¿ è¦ãããã¾ããã
以ä¸ã§ã¯kintone.comã«ãããå ·ä½çãªåãçµã¿ãããã¤ãç´¹ä»ãã¾ãã
æ¬çªç°å¢ã®å®æãã§ãã¯
kintone.comã¯AWSä¸ã§éç¨ãã¦ãããAWS GuardDutyã«ããã¢ã¯ãã£ããã£ç£è¦ãAWS Trusted Advisorã«ããã¯ã©ã¦ãæé©åãAWS Bulletinã«ããèå¼±æ§ã®ç¢ºèªããã¦ãã¾ãã SOC2ç£æ»ããåããæ¥æ¬¡ã§ãã§ãã¯ãã¦ãã¾ããããããã証跡ã¨ãã¦åºããå½¢ã«æ¥åãæ´çãã¾ããã
ãã®è¨é²å ã¨ãã¦kintoneã¢ããªã使ããæ¥æ¬¡ã§ãã§ãã¯ã®è¨é²ãæ®ããç£æ»æã«è¨¼è·¡ã¨ãã¦æåºã§ããããã«ãã¾ããã

第ä¸è ãã§ãã¯ã®ã«ã¼ã«å
SOC2ç£æ»ã§ã¯ãéçºæ¥åãå人ã®å¤æã§ã¯ãªã第ä¸è ãã§ãã¯ã®ãã¨ã§å®æ½ããã¦ããããæ±ãããã¾ããã ãã¡ãã徿¥ãããã³ã¼ãã¬ãã¥ã¼ãQAã¨ã³ã¸ãã¢ã«ãããã§ãã¯ã宿½ãã¦ãã¾ããã SOC2ç£æ»ã«åãã¦ãããã®éç¨ãã«ã¼ã«åããè¨¼è·¡ãæ®ããå½¢ã«æ´åãã¾ããã ãã®ããã«ã«ã¼ã«ã¨ãã¦æ¹ãã¦æ´åããç¹ãããã¤ãç´¹ä»ãã¾ãã
- æ©è½éçºãé©åãªããã»ã¹ã§æ¿èªãå¾ã¦ãããã
- ãããã¯ãããã¼ã¸ã£ã¼ã«ããææç©ã®ç¢ºèª
- ä»ã®éçºè ã«ããã³ã¼ãã¬ãã¥ã¼
- QAã¨ã³ã¸ãã¢ã«ããæ©è½è©¦é¨ã¨è©¦é¨çµæã®æ·»ä»
- çµå¶é£ã«ããkintoneéçºè¨ç»ã®æ¿èª
- ã¤ã³ãã©ã®å¤æ´ãé©åãªããã»ã¹ã§æ¿èªãå¾ã¦ãããã
- ä»ã®éçºè ã«ããPull Requestã®ã³ã¼ãã¬ãã¥ã¼
- ä»ã®éçºè ã«ããæåãªãã¬ã¼ã·ã§ã³ã®æé ã¬ãã¥ã¼
ãããã®ã«ã¼ã«ãå³å®ã§ããããã«ãã¬ãã¸ããªã®ãã©ã³ãä¿è·ã«ã¼ã«ã®è¦ç´ãããããã¯ãããã¯ãã°ã¢ã¤ãã ã®ç®¡çã®æ´åããªãã¬ã¼ã·ã§ã³è¨é²ã®æ´åããã¾ããã
以ä¸ã¯ç¾å¨ã®ãªãã¬ã¼ã·ã§ã³ç®¡çã¢ããªã®ç¶æ é·ç§»å³ï¼kintoneã¢ããªã®ããã»ã¹ç®¡çæ©è½ï¼ã§ãã

æ¬çªç°å¢ã¢ã«ã¦ã³ãã®ä»ä¸ã«ã¼ã«ã¨æ£å¸ã
kintone.comã®æ¬çªç°å¢ã¸ã®ã¢ã¯ã»ã¹ã¯éãããä¸é¨ç¤¾å¡ã®ã¿ã«è¨±å¯ãã¦ãã¾ããæ¬çªç°å¢ã¸ã®ã¢ã¯ã»ã¹æ¨©éã®ä»ä¸ã¯éçºãã¼ã å´ã§å¤æããç°åãéè·æã«é½åº¦ã¢ã«ã¦ã³ããåé¤ãã¦ãã¾ãããSOC2ç£æ»ã«åãã¦ãã¢ã«ã¦ã³ãä»ä¸ã«ã¼ã«ã®æç¢ºåã¨ãæ°ãã«ææ¬¡ã®æ£å¸ãããã»ã¹ãæ´åãã¾ããã
ã¢ã«ã¦ã³ãä»ä¸ã«é¢ãã¦ã¯ç¤¾å ã§ISMSå¾äºè ã®ç®¡çã«ã¼ã«ããããããã«åºã¥ãã¢ããªãéç¨ããã¦ãã¾ããã ãããå ã«éçºãã¼ã å ã§ã¢ã«ã¦ã³ãä»ä¸åºæºãå®ç¾©ãã¾ããã æ£å¸ãã§ã¯ãã¢ããªã®ç»é²å 容ã¨å®éã®æ¨©éãããã¦ã¼ã¶ã¼ãçªåããä¸è¦ãªã¢ã«ã¦ã³ãã宿çã«ãã§ãã¯ãã¦ãã¾ãã
ãã®ä½æ¥ããã¼ã«åãã¦ãææ¬¡ã§ç §åå 容ã¨ä½æ¥å 容ãè¨é²ãããã¨ã«ãã¾ããã

ã¢ã¸ã£ã¤ã«éçºã®å¦¥å½æ§ã®èª¬æ
kintoneéçºçµç¹ã®å¤ãã®ãã¼ã ã¯ã¹ã¯ã©ã éçºãå°å ¥ãã¦ãã¾ããã¹ããªã³ãã¬ãã¥ã¼ã§ã¯éçºææç©ããã¢ã§ç¢ºèªãã¦ãã¾ããããã®å 容ã証跡ã¨ãã¦æ®ããªãã¨ãã課é¡ãããã¾ãããã¾ãä¸é¨ã®ãã¼ã ã§ã¯ã¢ãããã°ã©ãã³ã°ãæ¡ç¨ãã¦ããã夿´ç¹ã®ãã§ãã¯ã¨ã¬ãã¥ã¼ãå£é ã§æ¸ã¾ãããã¨ãã§ãã¾ãããã¡ãã確èªçµæã証跡ã¨ãã¦æ®ããªãã¨ãã課é¡ãããã¾ããããã®èª²é¡ã解決ããããã«ãGitHubã®Branch Protectionè¨å®ã¨Issueãã³ãã¬ã¼ããå°å ¥ãã確èªè¨é²ãæ®ãã¾ããã
以ä¸ã¯åºç¤ã®éç¨ãã¼ã ã®GitHub Issueã®æç²ã§ããã¹ã¯ã©ã ã¤ãã³ãã§ãã§ãã¯ããã¯ã¹ãåãã¦ãã¿ã¹ã¯ãåé¡ãªãå®äºããã確èªãã¦ãã¾ãã

ãããã«
ã»ãã¥ãªãã£ç£æ»ã¨éçºã¹ãã¼ãã®ä¸¡ç«ã¯å¸¸ã«èª²é¡ã¨ãªãã¾ããéçºã¹ãã¼ããç ç²ã«ããªãã»ãã¥ãªãã£ã«ã¼ã«ã»ããã»ã¹ã®æ´åã¯å¸¸ã«é ãæ©ã¾ãã¾ãã éç¨ä¸ã®ï¼éå±ãªï¼æ¥åãæ¸ããããã«ãã¢ã«ã¦ã³ãæ£å¸ãã®ããã«èªååããé¨åãããã¾ããæ¯å¹´SOC2ã®å ±åæ¸ãæ´æ°ããããã«ãç¶ç¶çãªè©ä¾¡ããã³éç¨æ¹åã«åãçµãã§ãã¾ãã
ããããSOC2ã«å¯¾å¿ããããå¼·åºãªéç¨ãå®ç¾ããããã«ã大äºãªéç¨ã§ãã£ããã¨ã¯ééãããã¾ãããçæçã«ã¯éçºé度ãä½ä¸ãããå¯è½æ§ãããã¾ãããä»å¾æé·ããkintoneéçºçµç¹ã«ã¨ã£ã¦ã¯é·æçãªã¡ãªãããæå¾ ãã¦ãã¾ãã
SOC2ç£æ»ã«ããããæ å½ããã ããç£æ»æ³äººã®çãã¾ããã夿°ã®è¨¼è·¡ã®ç¢ºèªããã£ã¼ãããã¯ãã¯ããããã¾ãã¾ãªãå©è¨ãããã ããããããã¾ã§ä¿è¨¼å ±åæ¸ãç¡äºã«å®æããããã¨ãã§ãã¾ãããããã«æ¹ãã¦æè¬ç³ãä¸ãã¾ãã
- cybozu.comä¸ã§æä¾ãã¦ãããå½å å¸å ´åãã®kintoneã¯å¯¾è±¡å¤ã§ãã↩