CI/CD ãã€ãã©ã€ã³ã®æ¹èš: NIST ããœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³ã®ã»ãã¥ãªãã£ã匷åããããã®ãã¬ãŒã ã¯ãŒã¯èæ¡ãçºè¡š
æè¿ã®ãœãããŠã§ã¢æ»æã«å¯Ÿå¿ããŠãåœç«æšæºæè¡ç ç©¶æ (NIST) ã¯ãã»ãã¥ãªãã£å¯Ÿçã CI/CD ãœãããŠã§ã¢ ãã€ãã©ã€ã³ã«çµ±åããæŠç¥ã®æŠèŠããŸãšããèæ¡ãçºè¡šããŸããã

National Institute of Standards and Technology (NIST)ç»æçãªææžèæ¡ãçºè¡šããããšã§ããµã€ããŒã»ãã¥ãªãã£ã®å®è·µåŒ·åã«åããéèŠãªäžæ©ãèžã¿åºããŸããããã®å é§çãªã¬ã€ãã¯ããœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³ã®ã»ãã¥ãªãã£ä¿è·ææ®µãç¶ç¶çã€ã³ãã°ã¬ãŒã·ã§ã³/ç¶ç¶çãããã€ã¡ã³ã (CI/CD) ãã€ãã©ã€ã³ã«çµ±åããããšã«éç¹ã眮ããŠããŸããããã¯ãçŸåšã®ããžã¿ã«ç°å¢ã«ãããŠãŸããŸãéèŠã«ãªã£ãŠããŸãã
ã¯ã©ãŠã ãã€ãã£ã ã¢ããªã±ãŒã·ã§ã³ã®éçšã®äžå¿ãšãªãã®ã¯ãã€ã¯ããµãŒãã¹ ã¢ãŒããã¯ãã£ã§ãããå€ãã®å ŽåããµãŒãã¹ ã¡ãã·ã¥ãªã©ã®éäžãµãŒãã¹ ã€ã³ãã©ã¹ãã©ã¯ãã£ãšçµã¿åãããããŸãã NISTã«ããæ°ããèæ¡ææžã¯ããããã®ã¢ããªã±ãŒã·ã§ã³ã®éçºã«ããã DevSecOps ã®éèŠæ§ã匷調ããŠãããCI/CD ãã€ãã©ã€ã³ã¯ããœãããŠã§ã¢ã®ãµãã©ã€ ãã§ãŒã³ãåæ ããããã»ã¹ã§ããããã«ãããã¹ããããã±ãŒãžãå±éãªã©ã®æ®µéãéããŠãœãããŠã§ã¢ãæäœããäžã§æ¥µããŠéèŠã§ãã
Endor Labs ã®ã»ãã¥ãªãã£ç ç©¶è ã§ãã Henrik Plate æ°ã¯ãæè¡ãšã³ã·ã¹ãã ã«ãããèæ¡ææžã®äŸ¡å€ã«ã€ããŠããããéçºçµç¹ã«ã©ã®ããã«æéãæäŸãããã匷調ããŸããã Plate ã«ãšã£ãŠç®ç«ã£ãã®ã¯ãæå°ç¹æš©ãšç¥ãå¿ èŠãããååã«åºå·ããCI/CD ãã€ãã©ã€ã³å ã®ãŠãŒã¶ãŒãšãµãŒãã¹ ã¢ã«ãŠã³ãã®åœ¹å²ãšæ¿èªã決å®ããã¢ã¯ã»ã¹å¶åŸ¡ææ®µãææžã§åŒ·èª¿ããŠããããšã§ãããã€ãã©ã€ã³ã®å®è¡äžã«ã·ã¹ãã ããµãŒãã¹å šäœã§ãããã®å€æ°ã®æ¿èªã管çããããã»ã¹ã¯å°é£ãããããŸãããã NISTãæäŸãããã¬ãŒã ã¯ãŒã¯ã¯éåžžã«åœ¹ç«ã€ããšãæåŸ ãããŠããŸãã
NISTã®æ°ããèæ¡ã¯ããœãããŠã§ã¢ã®è匱æ§ã𿻿ã«é¢ããæè¿ã®ããã€ãã®è©äŸ¡ã«å¯Ÿå¿ãããã®ã§ããœãããŠã§ã¢ã®éçºãå°å ¥ãçµ±åã«ç©æ¥µçã«åãçµãã§ãã宿°åæ¹ã®çµç¹ãããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã« (SDLC) å šäœã«ããã£ãŠã»ãã¥ãªãã£ãåªå ããããä¿ããŠããŸãã
ãã®ææžã§ã¯ããœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³ (SSC) ã®ã»ãã¥ãªãã£ã¯ããã«ãããã¹ããããã±ãŒãžåãå±éãªã©ã®æ®µéã®æŽåæ§ã«äŸåããŠãããšèª¬æãããŠããŸãããã®çµæãè匱æ§ã¯æªæã®ããæ»æè ã ãã§ãªããSDLC äžã®äžæ³šæãèŠèœãšãã«ãã£ãŠãçºçããå¯èœæ§ããããŸãã
èæ¡ææžã§ã¯ãSDLC ã§ SSC ã»ãã¥ãªãã£ã«å¿ èŠãªèšå€§ãªæé ãå®è£ ããéã«çºçããå¯èœæ§ã®ãã課é¡ãèªããããŠããŸãããã¬ãŒãæ°ãææããŠããããã«ããã®ææžã§ã¯ãæ ¹åºã«ããããžãã¹ããã»ã¹ãšéçšã³ã¹ãã«éå€§ãªæ··ä¹±ãçããå¯èœæ§ããããšåŒ·èª¿ããŠããŸãã
NISTã®èæ¡ã¯Secure Software Development Framework (SSDF)ã®éèŠæ§ã匷調ããŠããŸããSSDF ã¯ãåºæ¬çã«ãBSAãOWASPãSAFECode ãªã©ã®ä¿¡é Œã§ããçµç¹ããã®å®å šãªãœãããŠã§ã¢éçºææžã«åºã¥ãããäžé£ã®å åºã§å®å šãªãœãããŠã§ã¢éçºå®è·µã§ãã
è峿·±ãããšã«ããã®èæ¡ã¯ããœãããŠã§ã¢ ãããã€ããŒã« SSDF ã®å®å šãªéçºæ £è¡ã®é å®ã蚌æãããä»åŸã®èªå·±èšŒæèŠä»¶ã«å¯ŸåŠããŠããŸããããã¯ãDevSecOpsãCI/CD ãã€ãã©ã€ã³ã®ã³ã³ããã¹ãã«ç¹ã«é¢é£ããŠãããã»ãã¥ãªãã£ã®èгç¹ããå¿ èŠãšã¿ãªããããã®ãå®çŸ©ããŸãã
Plate ãæèµ·ããéå€§ãªæžå¿µã® 1 ã€ã¯ãSigstore ã in-toto ãªã©ããœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³ã匷åããããã«èšèšãããããŒã«ã®å°å ¥ãæ¯èŒçéãããšã§ãã
ãã®èæ¡ã¯ãçµç¹ãæ¬ é¥æ€åºã ãã«çŠç¹ãåœãŠãã®ã§ã¯ãªãããªãŒãã³ãœãŒã¹ã®ãªã¹ã¯ç®¡çã«ç·åçã«ã¢ãããŒãããããšã奚å±ããŠããŸããã³ãŒãå質ããã®ä»ã®ãããžã§ã¯ã掻åãã»ãã¥ãªãã£ãšéçšã®äž¡æ¹ã®ãªã¹ã¯ã軜æžããã®ã«åœ¹ç«ã€ãªã¹ã¯ææšãªã©ã®èæ ®äºé ãèæ ®ããå¿ èŠããããŸãã
NISTã«ããèæ¡ã¯å¹ åºãèªè ã察象ãšããŠããããœãããŠã§ã¢æ¥çã®å®åè ã察象ãšããŠããŸããããã«ã¯ãã»ãã¥ãªã㣠ã¢ãŒããã¯ãããšã³ãžãã¢ã«å ããŠããœãããŠã§ã¢ ãšã³ãžãã¢ããµã€ãä¿¡é Œæ§ãšã³ãžãã¢ã補åãŸãã¯ãããžã§ã¯ã ãããŒãžã£ãŒãå«ãŸããŸããäžè¬ã®ã¡ã³ããŒã¯ã2023 幎 10 æ 13 æ¥ãŸã§ã«èæ¡ã«ã€ããŠã³ã¡ã³ããæåºããå¿ èŠããããŸãã
AppMasterã®ãããªno-codeãã©ãããã©ãŒã ãæŽ»çšããããšã§ãäŒæ¥ã¯ CI/CD ãã€ãã©ã€ã³å ã®ããŒã¿ ã»ãã¥ãªãã£ã匷åããå®å šãªãœãããŠã§ã¢ãæäŸãããœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³å šäœã®åŒ·åã«è²¢ç®ã§ããŸãã 2023 幎 4 æãŸã§ã« 60,000 人ãè¶ ãããŠãŒã¶ãŒãããAppMasterãã©ãããã©ãŒã ã¯ãããŸããŸãªèŠæš¡ã®ããŸããŸãªããžãã¹ã®ã»ãã¥ãªã㣠ã€ããŒãã©ãŒãšããŠå¹ççã«æ©èœã§ããŸããããã¯ã NISTã®èæ¡ææžã®å ¬éã«é¢é£ããŠç¹ã«éèŠã§ãã


