[{"data":1,"prerenderedAt":1628},["ShallowReactive",2],{"/ja-jp/blog/guide-to-fulfilling-soc-2-security-requirements-with-gitlab":3,"navigation-ja-jp":848,"banner-ja-jp":1276,"footer-ja-jp":1284,"blog-post-authors-ja-jp-Fernando Diaz":1525,"blog-related-posts-ja-jp-guide-to-fulfilling-soc-2-security-requirements-with-gitlab":1540,"blog-promotions-ja-jp":1566,"next-steps-ja-jp":1619},{"id":4,"title":5,"authors":6,"body":8,"category":825,"date":826,"description":827,"extension":828,"externalUrl":829,"faq":829,"featured":523,"heroImage":830,"meta":831,"navigation":523,"path":832,"seo":833,"slug":838,"stem":839,"tags":840,"template":846,"updatedDate":829,"__hash__":847},"blogPosts/ja-jp/blog/guide-to-fulfilling-soc-2-security-requirements-with-gitlab.md","GitLabでSOC2セキュリティ要件に対応するためのガイド",[7],"Fernando Diaz",{"type":9,"value":10,"toc":805},"minimark",[11,15,20,23,115,118,122,125,199,209,212,221,249,252,261,275,287,301,304,307,324,330,333,344,347,350,358,361,368,385,387,395,401,404,415,426,429,432,458,460,463,486,559,562,594,600,619,630,633,646,648,660,662,665,685,691,693,704,707,714,716,727,731,734,745,749,766,769,772,801],[12,13,14],"p",{},"機密性の高い顧客情報を扱う企業にとって、SOC（システムおよび組織管理）2コンプライアンスの達成は単なる推奨事項ではなく、多くの場合、必要不可欠です。SOC2は、米国公認会計士協会（AICPA）が策定した厳格な監査基準であり、サービス組織のセキュリティ、可用性、処理の完全性、機密性、プライバシーに関する管理体制を評価します。\nSOC2は法的義務ではありませんが、ニュースで頻繁に報じられる情報漏洩事件の影響もあり、重要性が高まっています。SOC2コンプライアンスを達成することで、顧客データを適切に保管し、第三者によるセキュリティ管理の評価を受けていることが伝わり、顧客からの信頼を得られます。\n本ガイドでは、SOC2コンプライアンスの要件を解説し、GitLabがどのように組織のアプリケーションセキュリティの最高水準の達成に役立つかをご紹介します。",[16,17,19],"h2",{"id":18},"soc-2で定められている要件","SOC 2で定められている要件",[12,21,22],{},"SOC2コンプライアンスを達成するには、独立した監査担当者による監査が必要となります。監査では、組織の管理体制の設計および運用の有効性を評価します。監査プロセスは非常にコストがかかることが多く、多くの組織は監査前の準備を十分に行えていないのが現状です。通常、SOC2監査は約1年を要するため、効率的な事前監査プロセスを確立することが重要です。\nSOC2コンプライアンスを達成するには、組織は以下のトラストサービス規準に基づく要件を満たす必要があります。",[24,25,26,40],"table",{},[27,28,29],"thead",{},[30,31,32,37],"tr",{},[33,34,36],"th",{"align":35},"left","規準",[33,38,39],{"align":35},"要件",[41,42,43,59,73,87,101],"tbody",{},[30,44,45,49],{},[46,47,48],"td",{"align":35},"セキュリティ",[46,50,51,52,55,56,58],{"align":35},"- 不正アクセスを防ぐための管理策を実施 ",[53,54],"br",{}," - リスクの特定と軽減のための手順を確立",[53,57],{}," - セキュリティインシデントを検知および対応するためのシステムを構築",[30,60,61,64],{},[46,62,63],{"align":35},"可用性",[46,65,66,67,69,70,72],{"align":35},"- 合意されたとおりにシステムの稼働を保証",[53,68],{}," - 現在の使用状況と容量をモニタリング ",[53,71],{}," - システム可用性に影響を与えうる環境リスクを特定・対処",[30,74,75,78],{},[46,76,77],{"align":35},"処理の完全性",[46,79,80,81,83,84,86],{"align":35},"- システムの入力・出力の正確な記録を維持 ",[53,82],{}," - システムエラーを迅速に特定し修正する手順を実施 ",[53,85],{}," - 製品・サービスが仕様を満たすよう処理作業を定義",[30,88,89,92],{},[46,90,91],{"align":35},"機密性",[46,93,94,95,97,98,100],{"align":35},"- 機密情報を特定し保護 ",[53,96],{}," - データ保持期間のポリシーを策定 ",[53,99],{}," - 保持期間終了後、機密データを安全に破棄する方法を確保",[30,102,103,106],{},[46,104,105],{"align":35},"プライバシー",[46,107,108,109,111,112,114],{"align":35},"- 機密個人情報を収集する前に同意を取得 ",[53,110],{}," - プライバシーポリシーを明確かつわかりやすく伝達 ",[53,113],{}," - 法的手段を通じて信頼できる情報源からのみデータを収集",[12,116,117],{},"なお、これらの要件は一度達成すれば終わりではなく、継続的に準拠する必要があります。監査担当者は一定期間にわたる管理策の有効性の有無を評価します。",[16,119,121],{"id":120},"セキュリティ要件を満たし維持する方法","セキュリティ要件を満たし、維持する方法",[12,123,124],{},"GitLabには、SOC2のセキュリティ要件を満たすためにすぐに活用できる機能が数多く用意されています。",[24,126,127,137],{},[27,128,129],{},[30,130,131,134],{},[33,132,133],{"align":35},"セキュリティ要件",[33,135,136],{"align":35},"対応機能",[41,138,139,165,191],{},[30,140,141,144],{},[46,142,143],{"align":35},"不正アクセスを防ぐための管理策を実施",[46,145,146,147,149,150,152,153,155,156,158,159,161,162,164],{"align":35},"- 非公開のイシュー／マージリクエスト ",[53,148],{}," -  カスタムロールときめ細かい権限設定 ",[53,151],{}," - セキュリティポリシー ",[53,154],{}," - 検証済みコミット ",[53,157],{}," - コンテナイメージの署名 ",[53,160],{}," - CodeOwners ",[53,163],{}," - 保護ブランチ",[30,166,167,170],{},[46,168,169],{"align":35},"セキュリティインシデントを検知および対応するためのシステムを構築",[46,171,172,173,175,176,178,179,181,182,184,185,187,188,190],{"align":35},"- 脆弱性スキャン ",[53,174],{}," - マージリクエスト内セキュリティウィジェット ",[53,177],{}," -  脆弱性インサイトコンプライアンスセンター ",[53,180],{}," - 監査イベント ",[53,183],{}," -脆弱性レポート依存関係リスト ",[53,186],{}," - AIによる脆弱性の説明 ",[53,189],{}," - AIによる脆弱性の修正",[30,192,193,196],{},[46,194,195],{"align":35},"リスクの特定と軽減のための手順を確立",[46,197,198],{"align":35},"上記すべてのツールを活用して、セキュリティチームが脆弱性発見時の対応および軽減手順を確立できます",[12,200,201,202,208],{},"それでは、各要件に対応するセキュリティ機能についてさらに詳しく解説しましょう。なお、上記のほとんどの機能は、",[203,204,207],"a",{"href":205,"rel":206},"https://about.gitlab.com/ja-jp/free-trial/",[],"GitLab Ultimateプランのサブスクリプション","および適切なロールと権限設定が必要となります。詳細については、該当するドキュメントをご確認ください。",[16,210,211],{"id":211},"不正アクセスから保護するための制御の実装",[12,213,214,215,220],{},"組織の資産を保護して、規制遵守を達成し、業務の継続性を維持し、信頼を築くためには、強固なアクセス制御の実装が不可欠です。GitLabでは、",[203,216,219],{"href":217,"rel":218},"https://about.gitlab.com/blog/the-ultimate-guide-to-least-privilege-access-with-gitlab/",[],"最小権限の原則","に従ったアクセス制御を実装でき、不正アクセスからの保護を実現します。ここでは以下の項目について簡単に紹介します。",[222,223,224,231,237,243],"ul",{},[225,226,227],"li",{},[203,228,230],{"href":229},"#security-policies","セキュリティポリシー",[225,232,233],{},[203,234,236],{"href":235},"#custom-roles-and-granular-permissions","カスタムロールときめ細かい権限設定",[225,238,239],{},[203,240,242],{"href":241},"#branch-protections-and-codeowners","ブランチ保護とCodeOwners",[225,244,245],{},[203,246,248],{"href":247},"#verified-commits","検証済みコミット",[250,251,230],"h3",{"id":230},[12,253,254,255,260],{},"GitLabのセキュリティポリシー（いわゆるガードレール）を使用すると、セキュリティおよびコンプライアンスチームは組織全体で一貫した制御を実装できます。これにより、セキュリティインシデントの予防、コンプライアンス基準の維持、一括でのベストプラクティスの自動適用によるリスクの低減が可能になります。\n",[256,257],"img",{"alt":258,"src":259},"マージリクエスト承認ポリシーの活用例","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/merge_request_approval_policy_aHR0cHM6_1750099596925.png","\nマージリクエスト承認ポリシーの活用例\n以下のようなポリシーを利用できます。",[222,262,263,266,269,272],{},[225,264,265],{},"スキャン実行ポリシー：パイプラインの一部として、または指定したスケジュールに応じてセキュリティスキャンの実行を強制",[225,267,268],{},"マージリクエスト承認ポリシー：スキャン結果に基づいて、プロジェクトレベルの設定や承認ルールを適用",[225,270,271],{},"パイプライン実行ポリシー：プロジェクトパイプライン内でCI/CDジョブの実行を強制",[225,273,274],{},"脆弱性管理ポリシー：脆弱性の対応ワークフローを自動化\n以下に、パイプライン実行ポリシーを活用してコンプライアンスを確保する例をご紹介します。",[276,277,278,281,284],"ol",{},[225,279,280],{},"複数のコンプライアンスジョブをまとめたプロジェクトを作成します。たとえば、デプロイされるファイルの権限を確認するジョブを含めます。これらのジョブは、複数のアプリケーションで再利用できるように汎用的な内容にしておきます。",[225,282,283],{},"このプロジェクトへの権限はセキュリティ／コンプライアンス担当者に限定し、デベロッパーがジョブを削除できないようにします。これにより職務分離が実現します。",[225,285,286],{},"対象のプロジェクトにこれらのコンプライアンスジョブを一括で挿入します。ジョブが必ず実行されるよう強制しつつ、開発の妨げにならないようにチームリーダーが実行を承認できるようにします。これにより、コンプライアンスジョブが常に実行され、デベロッパーによって削除されることがなくなり、ご利用の環境にて常にコンプライアンスが確保されるようになります。",[288,289,290],"blockquote",{},[291,292,294,295,300],"h5",{"id":293},"セキュリティポリシーの作成方法についてはgitlabのセキュリティポリシーに関するページをご覧ください","セキュリティポリシーの作成方法については、GitLabの",[203,296,299],{"href":297,"rel":298},"https://docs.gitlab.com/ja-jp/user/application_security/policies/",[],"セキュリティポリシーに関するページ","をご覧ください。",[250,302,303],{"id":303},"カスタムロールと詳細な権限",[12,305,306],{},"GitLabのカスタム権限を使用すると、標準のロールベースの権限ではできないきめ細かいアクセス制御を実装できます。これにより、以下のような利点が得られます。",[222,308,309,312,315,318,321],{},[225,310,311],{},"より正確なアクセス制御",[225,313,314],{},"セキュリティコンプライアンスの向上",[225,316,317],{},"誤ったアクセスのリスク軽減",[225,319,320],{},"ユーザー管理の効率化",[225,322,323],{},"複雑な組織構造への対応",[12,325,326],{},[256,327],{"alt":328,"src":329},"GitLabカスタムロール","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/custom_roles_aHR0cHM6_1750099596926.png",[12,331,332],{},"ロールと権限の設定（カスタムロールを含む）",[288,334,335],{},[291,336,338,343],{"id":337},"カスタムロールに関するページを参照してきめ細かな権限を設定できるカスタムロールの作成方法をご確認ください",[203,339,342],{"href":340,"rel":341},"https://docs.gitlab.com/ja-jp/user/custom_roles/",[],"カスタムロールに関するページ","を参照して、きめ細かな権限を設定できるカスタムロールの作成方法をご確認ください。",[250,345,242],{"id":346},"ブランチ保護とcodeowners",[12,348,349],{},"GitLabでは、次の2つの主要な機能により、コードに変更を加えられるユーザーをさらに厳密に管理できます。",[222,351,352,355],{},[225,353,354],{},"ブランチ保護：変更をマージする前に承認を必須とするなど、特定のブランチを変更できるユーザーに関するルールを設定できます。",[225,356,357],{},"CodeOwners：各ファイルを指定された所有者に関連付け、該当ファイルが変更された際に自動的に適切なレビュアーを指定します。",[12,359,360],{},"これらの機能を組み合わせることで、適切な担当者がレビュー・承認を行う体制を構築でき、コードのセキュリティと品質を高い水準で維持できます。",[12,362,363,367],{},[256,364],{"alt":365,"src":366},"保護ブランチ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/protected_branches_aHR0cHM6_1750099596928.png","\n保護ブランチの設定",[288,369,370],{},[291,371,373,374,378,379,384],{"id":372},"保護ブランチとcodeownersの設定方法については保護ブランチおよびcodeownerのページをご参照ください","保護ブランチとCodeOwnersの設定方法については、",[203,375,365],{"href":376,"rel":377},"https://docs.gitlab.com/ja-jp/user/project/repository/branches/protected/",[],"および",[203,380,383],{"href":381,"rel":382},"https://docs.gitlab.com/ja-jp/user/project/codeowners/",[],"CodeOwner","のページをご参照ください。",[250,386,248],{"id":248},[12,388,389,390,394],{},"コミットにデジタル署名を追加することで、なりすましではなく、本当に自分が作成したものであることを証明できます。デジタル署名は、自分だけが発行できる「電子印鑑」のようなものです。GitLabに公開GPG鍵を登録すれば、署名が正しいかを確認でき、マッチすればそのコミットには",[391,392,393],"code",{},"Verified","（検証済み）のマークが付きます。さらに、未署名のコミットを拒否したり、本人確認ができていないユーザーのコミットをブロックしたりするルールも設定可能です。",[12,396,397],{},[256,398],{"alt":399,"src":400},"検証済み署名付きコミット","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/signed_commit_aHR0cHM6_1750099596929.png",[12,402,403],{},"検証済み署名付きコミット\nコミットには以下の方法で署名できます。",[222,405,406,409,412],{},[225,407,408],{},"SSH鍵",[225,410,411],{},"GPG鍵",[225,413,414],{},"個人用x.509証明書",[288,416,417],{},[291,418,420,421,300],{"id":419},"検証済みコミットの詳細は署名付きコミットに関するページをご覧ください","検証済みコミットの詳細は、",[203,422,425],{"href":423,"rel":424},"https://docs.gitlab.com/ja-jp/user/project/repository/signed_commits/",[],"署名付きコミットに関するページ",[16,427,428],{"id":428},"セキュリティインシデントの検出と対応のためのシステムの構築",[12,430,431],{},"強固なセキュリティ対策状況の維持、規制遵守の確保、被害の最小化、変化し続ける脅威への迅速な対応には、セキュリティインシデントを検知し対応するシステムの構築が不可欠です。\nGitLabには、アプリケーションのライフサイクル全体を対象とするセキュリティスキャンと脆弱性管理機能が備わっています。以下の機能について簡単に説明します。",[222,433,434,440,446,452],{},[225,435,436],{},[203,437,439],{"href":438},"#security-scanning-and-vulnerability-management","セキュリティスキャンと脆弱性管理",[225,441,442],{},[203,443,445],{"href":444},"#software-bill-of-materials","ソフトウェア部品表（SBOM）",[225,447,448],{},[203,449,451],{"href":450},"#system-auditing-and-security-posture-review","システム監査とセキュリティ対策状況のレビュー",[225,453,454],{},[203,455,457],{"href":456},"#compliance-and-security-posture-oversight","コンプライアンスおよびセキュリティ対策状況の監視",[250,459,439],{"id":439},[12,461,462],{},"GitLabには以下のような多様なセキュリティスキャナーが備わっており、アプリケーションのライフサイクル全体をカバーします。",[222,464,465,468,471,474,477,480,483],{},[225,466,467],{},"静的アプリケーションセキュリティテスト（SAST）",[225,469,470],{},"動的アプリケーションセキュリティテスト（DAST）",[225,472,473],{},"コンテナスキャン",[225,475,476],{},"依存関係スキャン",[225,478,479],{},"Infrastructure as Code（IaC）スキャン",[225,481,482],{},"カバレッジガイドファジング",[225,484,485],{},"Web APIファジング\nこれらのスキャナーはテンプレートを利用すれば、パイプラインに追加できます。たとえば、テストステージでSASTと依存関係スキャンのジョブを実行するには、.gitlab-ci.ymlに以下を追加します。",[487,488,493],"pre",{"className":489,"code":490,"language":491,"meta":492,"style":492},"language-yaml shiki shiki-themes github-light","stages:\n  - test\n\ninclude:\n  - template: Jobs/Dependency-Scanning.gitlab-ci.yml\n  - template: Jobs/SAST.gitlab-ci.yml   \n","yaml","",[391,494,495,508,518,525,533,547],{"__ignoreMap":492},[496,497,500,504],"span",{"class":498,"line":499},"line",1,[496,501,503],{"class":502},"shJU0","stages",[496,505,507],{"class":506},"sgsFI",":\n",[496,509,511,514],{"class":498,"line":510},2,[496,512,513],{"class":506},"  - ",[496,515,517],{"class":516},"sYBdl","test\n",[496,519,521],{"class":498,"line":520},3,[496,522,524],{"emptyLinePlaceholder":523},true,"\n",[496,526,528,531],{"class":498,"line":527},4,[496,529,530],{"class":502},"include",[496,532,507],{"class":506},[496,534,536,538,541,544],{"class":498,"line":535},5,[496,537,513],{"class":506},[496,539,540],{"class":502},"template",[496,542,543],{"class":506},": ",[496,545,546],{"class":516},"Jobs/Dependency-Scanning.gitlab-ci.yml\n",[496,548,550,552,554,556],{"class":498,"line":549},6,[496,551,513],{"class":506},[496,553,540],{"class":502},[496,555,543],{"class":506},[496,557,558],{"class":516},"Jobs/SAST.gitlab-ci.yml\n",[12,560,561],{},"これらのジョブは環境変数やGitLabジョブ構文を使ってすべて設定可能です。パイプラインが起動すると、セキュリティスキャナーが動作し、現在のブランチとターゲットブランチの差分から脆弱性を検出します。検出された脆弱性はマージリクエスト（MR）内で確認でき、コードがターゲットブランチにマージされる前に細部まで監視する必要があります。MRには脆弱性に関して以下の情報が表示されます。",[222,563,564,567,570,573,576,579,582,585,588,591],{},[225,565,566],{},"説明",[225,568,569],{},"ステータス",[225,571,572],{},"重大度",[225,574,575],{},"証拠",[225,577,578],{},"識別子",[225,580,581],{},"URL（該当する場合）",[225,583,584],{},"リクエスト／レスポンス（該当する場合）",[225,586,587],{},"再現用資産（該当する場合）",[225,589,590],{},"トレーニング情報（該当する場合）",[225,592,593],{},"コードフロー（高度なSAST使用時）",[12,595,596],{},[256,597],{"alt":598,"src":599},"脆弱性を紹介するMRの表示画面","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/no_sql_injection_vulnerability_mr_view_aHR0cHM6_1750099596931.png",[12,601,598,602,604,605,609,610,612,613,618],{},[53,603],{},"\nデベロッパーはこれらの情報を活用して、セキュリティチームのワークフローを妨げることなく脆弱性を修正できます。デベロッパーは、レビュープロセスにかかる時間を短縮するために、理由を添えて脆弱性を無視したり、もしくは脆弱性を追跡するための非公開イシューを作成したりすることが可能です。\nマージリクエストのコードがデフォルトブランチ（通常は本番環境レベル）にマージされると、脆弱性レポートにセキュリティスキャナーの結果が反映されます。セキュリティチームはこれらの結果をもとに、本番環境で見つかった脆弱性の管理・トリアージを行います。\n",[256,606],{"alt":607,"src":608},"バッチステータス設定が表示された脆弱性レポート","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/vulnerability_report_aHR0cHM6_1750099596936.png","\nバッチステータス設定が表示された脆弱性レポート",[53,611],{},"\n脆弱性レポート内の脆弱性の説明をクリックすると、MRと同じ脆弱性データが表示される脆弱性ページに移動します。これらの情報は、影響評価や修正作業の際に信頼できる唯一の情報源として活用できます。脆弱性ページでは、",[203,614,617],{"href":615,"rel":616},"https://about.gitlab.com/ja-jp/gitlab-duo-agent-platform/",[],"GitLab Duo","のAI機能を使って脆弱性の説明を生成したり、修正のためのMRを作成したりして、解決までの時間を短縮できます。",[288,620,621],{},[291,622,624,625,300],{"id":623},"gitlabに含まれるセキュリティスキャナーや脆弱性管理の詳細はアプリケーションセキュリティに関するページをご覧ください","GitLabに含まれるセキュリティスキャナーや脆弱性管理の詳細は、",[203,626,629],{"href":627,"rel":628},"https://docs.gitlab.com/ja-jp/user/application_security/",[],"アプリケーションセキュリティに関するページ",[250,631,632],{"id":632},"ソフトウェア部品表",[12,634,635,636,641,642],{},"GitLabはソフトウェアで使用されているコンポーネント（部品）の詳細をリスト化できます。これはコードの「材料表」のようなもので、ソフトウェア部品表（",[203,637,640],{"href":638,"rel":639},"https://about.gitlab.com/ja-jp/blog/the-ultimate-guide-to-sboms/",[],"SBOM","）と呼ばれます。プロジェクトで使われている外部コードに関して、直接使われているコードやそれらが依存するコードも含め、すべてを把握できます。各項目について、使用バージョンやライセンス情報、既知のセキュリティ問題の有無も表示されます。これにより、自社のソフトウェアの構成を把握し、潜在的なリスクを見つけやすくなります。\n",[256,643],{"alt":644,"src":645},"グループレベルの依存関係リスト（SBOM）","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/sbom_aHR0cHM6_1750099596937.png",[12,647,644],{},[288,649,650],{},[291,651,653,654,659],{"id":652},"依存関係リストのアクセス方法と活用法は依存関係リストに関するページをご参照ください","依存関係リストのアクセス方法と活用法は、",[203,655,658],{"href":656,"rel":657},"https://docs.gitlab.com/ja-jp/user/application_security/dependency_list/",[],"依存関係リストに関するページ","をご参照ください。",[250,661,451],{"id":451},[12,663,664],{},"GitLabは、誰がいつ何を変更したかなど、システム内のすべての動きを記録します。コードを監視するセキュリティカメラのようなものだと考えてください。これにより、以下が可能になります。",[222,666,667,670,673,676,679,682],{},[225,668,669],{},"不審な動きを発見する",[225,671,672],{},"規制当局にルール遵守を証明する",[225,674,675],{},"問題が発生した際に状況を把握する",[225,677,678],{},"GitLabの利用状況を把握する\nこれらの情報は一元管理されているため、必要に応じて容易に確認・調査できます。たとえば、監査イベントを使うと以下の情報を追跡できます。",[225,680,681],{},"GitLabプロジェクトにおいて、誰がいつ特定ユーザーの権限レベルを変更したか",[225,683,684],{},"誰がいつ新しいユーザーを追加または削除したか",[12,686,687],{},[256,688],{"alt":689,"src":690},"プロジェクトレベルの監査イベント","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/audit_events_aHR0cHM6_1750099596938.png",[12,692,689],{},[288,694,695],{},[291,696,698,699,300],{"id":697},"監査イベントの詳細については監査イベントに関するページをご覧ください","監査イベントの詳細については、",[203,700,703],{"href":701,"rel":702},"https://docs.gitlab.com/ja-jp/user/compliance/audit_events/",[],"監査イベントに関するページ",[16,705,706],{"id":706},"コンプライアンスとセキュリティ対策状況の監視",[12,708,709,710],{},"GitLabのセキュリティダッシュボードは、すべてのセキュリティリスクを1か所で表示する「コントロールルーム」のような機能です。複数のセキュリティツールを個別に確認する必要はなく、全プロジェクトの調査情報を1つの画面でまとめて把握できます。これにより、プロジェクトに潜む問題の早期発見と迅速な対応が可能になります。\n",[256,711],{"alt":712,"src":713},"グループレベルのセキュリティダッシュボード","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099597/Blog/Content%20Images/Blog/Content%20Images/security_dashboard_aHR0cHM6_1750099596939.png",[12,715,712],{},[288,717,718],{},[291,719,721,722,300],{"id":720},"セキュリティダッシュボードの詳細についてはセキュリティダッシュボードに関するページをご覧ください","セキュリティダッシュボードの詳細については、",[203,723,726],{"href":724,"rel":725},"https://docs.gitlab.com/ja-jp/user/application_security/security_dashboard/",[],"セキュリティダッシュボードに関するページ",[16,728,730],{"id":729},"リスクを特定し軽減するための手順の確立","リスクを特定し、軽減するための手順の確立",[12,732,733],{},"脆弱性には特定のライフサイクルがあります。たとえば、セキュリティポリシーを使って、脆弱なコードを保護ブランチにマージするには承認が必要という手続きを設けることができます。さらに、本番環境で脆弱なコードが検出された場合、優先的に対応し、評価・修正・検証を行うという流れを定めることも可能です。",[222,735,736,739,742],{},[225,737,738],{},"優先順位は、GitLabのスキャナーによって提供される脆弱性の重大度に基づいて決められます。",[225,740,741],{},"評価は、AIによる脆弱性の説明機能が提供する悪用の詳細情報を使って行えます。",[225,743,744],{},"修正後は、GitLabに組み込まれた回帰テストやスキャナーを使用して検証できます。\nすべての組織に共通の対応策はありませんが、GitLabのような統合プラットフォームを活用することで、複数の異なるツールを使う場合と比べて、リスクをすばやく把握・対処でき、リスク全体を低減することが可能です。",[250,746,748],{"id":747},"soc-2コンプライアンスに関するベストプラクティス","SOC 2コンプライアンスに関するベストプラクティス",[222,750,751,754,757,760,763],{},[225,752,753],{},"強固なセキュリティ文化を確立する：組織全体でセキュリティへの意識と責任感を高めましょう。",[225,755,756],{},"すべてを文書化する：ポリシー、手順、コントロールの詳細なドキュメントを維持しましょう。",[225,758,759],{},"自動化できる部分は自動化する：自動化ツールを使用してコンプライアンスプロセスを効率化し、エラーを削減しましょう。",[225,761,762],{},"効果的に情報を共有する：関係者に対し、コンプライアンスの取り組みについて情報を伝えましょう。",[225,764,765],{},"専門家の助言を求める：SOC2準拠の取り組みにおいて、信頼できるコンサルタントとの連携を検討しましょう。\nSOC2コンプライアンスは大きな取り組みですが、その価値は計り知れません。アプリケーションセキュリティと運用上の卓越性への取り組みを示すことで、顧客からの信頼を築き、企業としての評判を高め、市場における競争力を強化できます。",[16,767,768],{"id":768},"詳細はこちら",[12,770,771],{},"GitLabの詳細、またGitLabがSOC2コンプライアンスの達成とセキュリティ対策状況の強化にどのように役立つかについては、以下のリソースをご覧ください。",[222,773,774,781,788,794],{},[225,775,776],{},[203,777,780],{"href":778,"rel":779},"https://about.gitlab.com/ja-jp/pricing/ultimate/",[],"GitLab Ultimate",[225,782,783],{},[203,784,787],{"href":785,"rel":786},"https://about.gitlab.com/ja-jp/solutions/application-security-testing/",[],"GitLabのセキュリティおよびコンプライアンスソリューション",[225,789,790],{},[203,791,793],{"href":627,"rel":792},[],"GitLabアプリケーションセキュリティに関するページ",[225,795,796],{},[203,797,800],{"href":798,"rel":799},"https://gitlab.com/gitlab-da/tutorials/security-and-governance/devsecops/simply-vulnerable-notes",[],"GitLab DevSecOpsチュートリアルプロジェクト",[802,803,804],"style",{},"html pre.shiki code .shJU0, html code.shiki .shJU0{--shiki-default:#22863A}html pre.shiki code .sgsFI, html code.shiki .sgsFI{--shiki-default:#24292E}html pre.shiki code .sYBdl, html code.shiki .sYBdl{--shiki-default:#032F62}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":492,"searchDepth":510,"depth":510,"links":806},[807,808,809,815,820,821,824],{"id":18,"depth":510,"text":19},{"id":120,"depth":510,"text":121},{"id":211,"depth":510,"text":211,"children":810},[811,812,813,814],{"id":230,"depth":520,"text":230},{"id":303,"depth":520,"text":303},{"id":346,"depth":520,"text":242},{"id":248,"depth":520,"text":248},{"id":428,"depth":510,"text":428,"children":816},[817,818,819],{"id":439,"depth":520,"text":439},{"id":632,"depth":520,"text":632},{"id":451,"depth":520,"text":451},{"id":706,"depth":510,"text":706},{"id":729,"depth":510,"text":730,"children":822},[823],{"id":747,"depth":520,"text":748},{"id":768,"depth":510,"text":768},"security","2025-01-22","SOC2セキュリティ要件に対応する、GitLab DevSecOpsプラットフォームのアプリケーションセキュリティ機能について解説します。","md",null,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1750099576/Blog/Hero%20Images/Blog/Hero%20Images/AdobeStock_1172300481_IGPi3TS4VzFgcqhvEdBlR_1750099575518.jpg",{},"/ja-jp/blog/guide-to-fulfilling-soc-2-security-requirements-with-gitlab",{"title":5,"description":827,"ogTitle":5,"ogDescription":827,"noIndex":834,"ogImage":830,"ogUrl":835,"ogSiteName":836,"ogType":837,"canonicalUrls":835},false,"https://about.gitlab.com/blog/guide-to-fulfilling-soc-2-security-requirements-with-gitlab","https://about.gitlab.com","記事","guide-to-fulfilling-soc-2-security-requirements-with-gitlab","ja-jp/blog/guide-to-fulfilling-soc-2-security-requirements-with-gitlab",[841,842,843,844,845],"Tutorial","Security","DevSecOps platform","Features","Product","BlogPost","20plu5nfDdMVXgZE2quw7oGN3evpAcZ-CcBOUqWUVKU",{"logo":849,"freeTrial":854,"sales":859,"login":864,"items":869,"search":1196,"minimal":1229,"duo":1246,"switchNav":1255,"pricingDeployment":1266},{"config":850},{"href":851,"dataGaName":852,"dataGaLocation":853},"/ja-jp/","gitlab logo","header",{"text":855,"config":856},"無料トライアルを開始",{"href":857,"dataGaName":858,"dataGaLocation":853},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/ja-jp&glm_content=default-saas-trial/","free trial",{"text":860,"config":861},"デモをリクエスト",{"href":862,"dataGaName":863,"dataGaLocation":853},"/ja-jp/sales/?contact-topic=request-demo","sales",{"text":865,"config":866},"サインイン",{"href":867,"dataGaName":868,"dataGaLocation":853},"https://gitlab.com/users/sign_in/","sign in",[870,898,999,1004,1118,1174],{"text":871,"config":872,"menu":874},"プラットフォーム",{"dataNavLevelOne":873},"platform",{"type":875,"columns":876},"cards",[877,883,891],{"title":871,"description":878,"link":879},"DevSecOpsに特化したインテリジェントオーケストレーションプラットフォーム",{"text":880,"config":881},"プラットフォームの詳細はこちら",{"href":882,"dataGaName":873,"dataGaLocation":853},"/ja-jp/platform/",{"title":884,"description":885,"link":886},"GitLab Duo Agent Platform","ソフトウェアライフサイクル全体を支えるエージェント型AI",{"text":887,"config":888},"GitLab Duoのご紹介",{"href":889,"dataGaName":890,"dataGaLocation":853},"/ja-jp/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":892,"description":893,"link":894},"GitLabが選ばれる理由","エンタープライズがGitLabを選ぶ主な理由をご覧ください",{"text":768,"config":895},{"href":896,"dataGaName":897,"dataGaLocation":853},"/ja-jp/why-gitlab/","why gitlab",{"text":899,"left":523,"config":900,"menu":902},"製品",{"dataNavLevelOne":901},"solutions",{"type":903,"link":904,"columns":908,"feature":978},"lists",{"text":905,"config":906},"すべてのソリューションを表示",{"href":907,"dataGaName":901,"dataGaLocation":853},"/ja-jp/solutions/",[909,934,956],{"title":910,"description":911,"link":912,"items":917},"自動化","CI/CDと自動化でデプロイを加速",{"config":913},{"icon":914,"href":915,"dataGaName":916,"dataGaLocation":853},"AutomatedCodeAlt","/ja-jp/solutions/delivery-automation/","automated software delivery",[918,922,925,930],{"text":919,"config":920},"CI/CD",{"href":921,"dataGaLocation":853,"dataGaName":919},"/ja-jp/solutions/continuous-integration/",{"text":884,"config":923},{"href":889,"dataGaLocation":853,"dataGaName":924},"gitlab duo agent platform - product menu",{"text":926,"config":927},"ソースコード管理",{"href":928,"dataGaLocation":853,"dataGaName":929},"/ja-jp/solutions/source-code-management/","Source Code Management",{"text":931,"config":932},"自動化されたソフトウェアデリバリー",{"href":915,"dataGaLocation":853,"dataGaName":933},"Automated software delivery",{"title":48,"description":935,"link":936,"items":941},"セキュリティを犠牲にすることなくコード作成を高速化",{"config":937},{"href":938,"dataGaName":939,"dataGaLocation":853,"icon":940},"/ja-jp/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[942,946,951],{"text":943,"config":944},"アプリケーションセキュリティテスト",{"href":938,"dataGaName":945,"dataGaLocation":853},"Application security testing",{"text":947,"config":948},"ソフトウェアサプライチェーンセキュリティ",{"href":949,"dataGaLocation":853,"dataGaName":950},"/ja-jp/solutions/supply-chain/","Software supply chain security",{"text":952,"config":953},"ソフトウェアコンプライアンス",{"href":954,"dataGaName":955,"dataGaLocation":853},"/ja-jp/solutions/software-compliance/","software compliance",{"title":957,"link":958,"items":963},"測定",{"config":959},{"icon":960,"href":961,"dataGaName":962,"dataGaLocation":853},"DigitalTransformation","/ja-jp/solutions/visibility-measurement/","visibility and measurement",[964,968,973],{"text":965,"config":966},"可視性と測定",{"href":961,"dataGaLocation":853,"dataGaName":967},"Visibility and Measurement",{"text":969,"config":970},"バリューストリーム管理",{"href":971,"dataGaLocation":853,"dataGaName":972},"/ja-jp/solutions/value-stream-management/","Value Stream Management",{"text":974,"config":975},"分析とインサイト",{"href":976,"dataGaLocation":853,"dataGaName":977},"/ja-jp/solutions/analytics-and-insights/","Analytics and insights",{"title":979,"type":903,"items":980},"GitLabが活躍する場所",[981,987,993],{"text":982,"config":983},"大企業",{"icon":984,"href":985,"dataGaLocation":853,"dataGaName":986},"Building","/ja-jp/enterprise/","enterprise",{"text":988,"config":989},"スモールビジネス",{"icon":990,"href":991,"dataGaLocation":853,"dataGaName":992},"Work","/ja-jp/small-business/","small business",{"text":994,"config":995},"公共部門",{"icon":996,"href":997,"dataGaLocation":853,"dataGaName":998},"Organization","/ja-jp/solutions/public-sector/","public sector",{"text":1000,"config":1001},"価格",{"href":1002,"dataGaName":1003,"dataGaLocation":853,"dataNavLevelOne":1003},"/ja-jp/pricing/","pricing",{"text":1005,"config":1006,"menu":1008},"関連リソース",{"dataNavLevelOne":1007},"resources",{"type":903,"link":1009,"columns":1013,"feature":1107},{"text":1010,"config":1011},"すべてのリソースを表示",{"href":1012,"dataGaName":1007,"dataGaLocation":853},"/ja-jp/resources/",[1014,1047,1074],{"title":1015,"items":1016},"はじめに",[1017,1022,1027,1032,1037,1042],{"text":1018,"config":1019},"インストール",{"href":1020,"dataGaName":1021,"dataGaLocation":853},"/ja-jp/install/","install",{"text":1023,"config":1024},"クイックスタートガイド",{"href":1025,"dataGaName":1026,"dataGaLocation":853},"/ja-jp/get-started/","quick setup checklists",{"text":1028,"config":1029},"学ぶ",{"href":1030,"dataGaLocation":853,"dataGaName":1031},"https://university.gitlab.com/","learn",{"text":1033,"config":1034},"製品ドキュメント",{"href":1035,"dataGaName":1036,"dataGaLocation":853},"https://docs.gitlab.com/ja-jp/","product documentation",{"text":1038,"config":1039},"ベストプラクティスビデオ",{"href":1040,"dataGaName":1041,"dataGaLocation":853},"/ja-jp/getting-started-videos/","best practice videos",{"text":1043,"config":1044},"インテグレーション",{"href":1045,"dataGaName":1046,"dataGaLocation":853},"/ja-jp/integrations/","integrations",{"title":1048,"items":1049},"検索する",[1050,1055,1060,1065,1069],{"text":1051,"config":1052},"お客様成功事例",{"href":1053,"dataGaName":1054,"dataGaLocation":853},"/ja-jp/customers/","customer success stories",{"text":1056,"config":1057},"ブログ",{"href":1058,"dataGaName":1059,"dataGaLocation":853},"/ja-jp/blog/","blog",{"text":1061,"config":1062},"Demo Hub",{"href":1063,"dataGaName":1064,"dataGaLocation":853},"/ja-jp/demo-hub/","demo hub",{"text":1066,"config":1067},"The Source",{"href":1068,"dataGaName":1059,"dataGaLocation":853},"/ja-jp/the-source/",{"text":1070,"config":1071},"リモート",{"href":1072,"dataGaName":1073,"dataGaLocation":853},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":1075,"items":1076},"つなげる",[1077,1082,1087,1092,1097,1102],{"text":1078,"config":1079},"GitLabサービス",{"href":1080,"dataGaName":1081,"dataGaLocation":853},"/ja-jp/services/","services",{"text":1083,"config":1084},"コントリビュート",{"href":1085,"dataGaName":1086,"dataGaLocation":853},"https://contributors.gitlab.com","contribute",{"text":1088,"config":1089},"コミュニティ",{"href":1090,"dataGaName":1091,"dataGaLocation":853},"/community/","community",{"text":1093,"config":1094},"フォーラム",{"href":1095,"dataGaName":1096,"dataGaLocation":853},"https://forum.gitlab.com/","forum",{"text":1098,"config":1099},"イベント",{"href":1100,"dataGaName":1101,"dataGaLocation":853},"/events/","events",{"text":1103,"config":1104},"パートナー",{"href":1105,"dataGaName":1106,"dataGaLocation":853},"/ja-jp/partners/","partners",{"config":1108,"title":1111,"text":1112,"link":1113},{"background":1109,"textColor":1110},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","GitLabの最新情報","最新の機能と改善点に関する情報をお届けします。",{"text":1114,"config":1115},"最新情報を読む",{"href":1116,"dataGaName":1117,"dataGaLocation":853},"/ja-jp/whats-new/","whats new",{"text":1119,"config":1120,"menu":1122},"企業情報",{"dataNavLevelOne":1121},"company",{"type":903,"columns":1123},[1124],{"items":1125},[1126,1131,1137,1139,1144,1149,1154,1159,1164,1169],{"text":1127,"config":1128},"GitLabについて",{"href":1129,"dataGaName":1130,"dataGaLocation":853},"/ja-jp/company/","about",{"text":1132,"config":1133,"footerGa":1136},"採用情報",{"href":1134,"dataGaName":1135,"dataGaLocation":853},"/jobs/","jobs",{"dataGaName":1135},{"text":1098,"config":1138},{"href":1100,"dataGaName":1101,"dataGaLocation":853},{"text":1140,"config":1141},"経営陣",{"href":1142,"dataGaName":1143,"dataGaLocation":853},"/company/team/e-group/","leadership",{"text":1145,"config":1146},"ハンドブック",{"href":1147,"dataGaName":1148,"dataGaLocation":853},"https://handbook.gitlab.com/","handbook",{"text":1150,"config":1151},"投資家向け情報",{"href":1152,"dataGaName":1153,"dataGaLocation":853},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":1155,"config":1156},"トラストセンター",{"href":1157,"dataGaName":1158,"dataGaLocation":853},"/ja-jp/security/","trust center",{"text":1160,"config":1161},"AI Transparency Center",{"href":1162,"dataGaName":1163,"dataGaLocation":853},"/ja-jp/ai-transparency-center/","ai transparency center",{"text":1165,"config":1166},"ニュースレター",{"href":1167,"dataGaName":1168,"dataGaLocation":853},"/company/contact/#contact-forms","newsletter",{"text":1170,"config":1171},"プレス",{"href":1172,"dataGaName":1173,"dataGaLocation":853},"/press/","press",{"text":1175,"config":1176,"menu":1177},"お問い合わせ",{"dataNavLevelOne":1121},{"type":903,"columns":1178},[1179],{"items":1180},[1181,1186,1191],{"text":1182,"config":1183},"お問い合わせはこちら",{"href":1184,"dataGaName":1185,"dataGaLocation":853},"/ja-jp/sales/","talk to sales",{"text":1187,"config":1188},"サポートを受ける",{"href":1189,"dataGaName":1190,"dataGaLocation":853},"https://support.gitlab.com/hc/en-us","support portal",{"text":1192,"config":1193},"カスタマーポータル",{"href":1194,"dataGaName":1195,"dataGaLocation":853},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":1197,"login":1198,"suggestions":1205},"閉じる",{"text":1199,"link":1200},"リポジトリとプロジェクトを検索するには、次にログインします",{"text":1201,"config":1202},"GitLab.com",{"href":867,"dataGaName":1203,"dataGaLocation":1204},"search login","search",{"text":1206,"default":1207},"提案",[1208,1210,1215,1217,1221,1225],{"text":884,"config":1209},{"href":889,"dataGaName":884,"dataGaLocation":1204},{"text":1211,"config":1212},"コード提案（AI）",{"href":1213,"dataGaName":1214,"dataGaLocation":1204},"/ja-jp/solutions/code-suggestions/","Code Suggestions (AI)",{"text":919,"config":1216},{"href":921,"dataGaName":919,"dataGaLocation":1204},{"text":1218,"config":1219},"GitLab on AWS",{"href":1220,"dataGaName":1218,"dataGaLocation":1204},"/ja-jp/partners/technology-partners/aws/",{"text":1222,"config":1223},"GitLab on Google Cloud",{"href":1224,"dataGaName":1222,"dataGaLocation":1204},"/ja-jp/partners/technology-partners/google-cloud-platform/",{"text":1226,"config":1227},"GitLabを選ぶ理由",{"href":896,"dataGaName":1228,"dataGaLocation":1204},"Why GitLab?",{"freeTrial":1230,"mobileIcon":1234,"desktopIcon":1239,"secondaryButton":1242},{"text":855,"config":1231},{"href":1232,"dataGaName":858,"dataGaLocation":1233},"https://gitlab.com/-/trials/new/","nav",{"altText":1235,"config":1236},"GitLabアイコン",{"src":1237,"dataGaName":1238,"dataGaLocation":1233},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":1235,"config":1240},{"src":1241,"dataGaName":1238,"dataGaLocation":1233},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":1015,"config":1243},{"href":1244,"dataGaName":1245,"dataGaLocation":1233},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/ja-jp/get-started/","get started",{"freeTrial":1247,"mobileIcon":1251,"desktopIcon":1253},{"text":1248,"config":1249},"GitLab Duoの詳細について",{"href":889,"dataGaName":1250,"dataGaLocation":1233},"gitlab duo",{"altText":1235,"config":1252},{"src":1237,"dataGaName":1238,"dataGaLocation":1233},{"altText":1235,"config":1254},{"src":1241,"dataGaName":1238,"dataGaLocation":1233},{"button":1256,"mobileIcon":1261,"desktopIcon":1263},{"text":1257,"config":1258},"/switch",{"href":1259,"dataGaName":1260,"dataGaLocation":1233},"#contact","switch",{"altText":1235,"config":1262},{"src":1237,"dataGaName":1238,"dataGaLocation":1233},{"altText":1235,"config":1264},{"src":1265,"dataGaName":1238,"dataGaLocation":1233},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":1267,"mobileIcon":1272,"desktopIcon":1274},{"text":1268,"config":1269},"料金ページに戻る",{"href":1002,"dataGaName":1270,"dataGaLocation":1233,"icon":1271},"back to pricing","GoBack",{"altText":1235,"config":1273},{"src":1237,"dataGaName":1238,"dataGaLocation":1233},{"altText":1235,"config":1275},{"src":1241,"dataGaName":1238,"dataGaLocation":1233},{"title":1277,"button":1278,"config":1282},"GitLab Orbitが登場: AIエージェントのためのコンテキストレイヤー",{"text":768,"config":1279},{"href":1280,"dataGaName":1281,"dataGaLocation":853},"/ja-jp/gitlab-orbit/","orbit",{"layout":1283,"disabled":834},"release",{"data":1285},{"text":1286,"source":1287,"edit":1293,"contribute":1298,"config":1303,"items":1308,"minimal":1516},"GitはSoftware Freedom Conservancyの商標です。当社は「GitLab」をライセンスに基づいて使用しています",{"text":1288,"config":1289},"ページのソースを表示",{"href":1290,"dataGaName":1291,"dataGaLocation":1292},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":1294,"config":1295},"このページを編集",{"href":1296,"dataGaName":1297,"dataGaLocation":1292},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":1299,"config":1300},"ご協力をお願いします",{"href":1301,"dataGaName":1302,"dataGaLocation":1292},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":1304,"facebook":1305,"youtube":1306,"linkedin":1307},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[1309,1353,1406,1449,1483],{"title":1000,"links":1310,"subMenu":1325},[1311,1315,1320],{"text":1312,"config":1313},"プランの表示",{"href":1002,"dataGaName":1314,"dataGaLocation":1292},"view plans",{"text":1316,"config":1317},"Premiumを選ぶ理由",{"href":1318,"dataGaName":1319,"dataGaLocation":1292},"/ja-jp/pricing/premium/","why premium",{"text":1321,"config":1322},"Ultimateを選ぶ理由",{"href":1323,"dataGaName":1324,"dataGaLocation":1292},"/ja-jp/pricing/ultimate/","why ultimate",[1326],{"title":1175,"links":1327},[1328,1330,1332,1334,1338,1343,1348],{"text":1175,"config":1329},{"href":1184,"dataGaName":863,"dataGaLocation":1292},{"text":1187,"config":1331},{"href":1189,"dataGaName":1190,"dataGaLocation":1292},{"text":1192,"config":1333},{"href":1194,"dataGaName":1195,"dataGaLocation":1292},{"text":569,"config":1335},{"href":1336,"dataGaName":1337,"dataGaLocation":1292},"https://status.gitlab.com/","status",{"text":1339,"config":1340},"利用規約",{"href":1341,"dataGaName":1342,"dataGaLocation":1292},"/terms/","terms of use",{"text":1344,"config":1345},"プライバシーに関する声明",{"href":1346,"dataGaName":1347,"dataGaLocation":1292},"/ja-jp/privacy/","privacy statement",{"text":1349,"config":1350},"Cookie 優先設定",{"dataGaName":1351,"dataGaLocation":1292,"id":1352,"isOneTrustButton":523},"cookie preferences","ot-sdk-btn",{"title":899,"links":1354,"subMenu":1363},[1355,1359],{"text":1356,"config":1357},"DevSecOpsプラットフォーム",{"href":882,"dataGaName":1358,"dataGaLocation":1292},"devsecops platform",{"text":1360,"config":1361},"AI支援開発",{"href":889,"dataGaName":1362,"dataGaLocation":1292},"ai-assisted development",[1364],{"title":1365,"links":1366},"トピック",[1367,1371,1376,1381,1386,1391,1396,1401],{"text":919,"config":1368},{"href":1369,"dataGaName":1370,"dataGaLocation":1292},"/ja-jp/topics/ci-cd/","cicd",{"text":1372,"config":1373},"GitOps",{"href":1374,"dataGaName":1375,"dataGaLocation":1292},"/ja-jp/topics/gitops/","gitops",{"text":1377,"config":1378},"DevOps",{"href":1379,"dataGaName":1380,"dataGaLocation":1292},"/ja-jp/topics/devops/","devops",{"text":1382,"config":1383},"バージョン管理",{"href":1384,"dataGaName":1385,"dataGaLocation":1292},"/ja-jp/topics/version-control/","version control",{"text":1387,"config":1388},"DevSecOps",{"href":1389,"dataGaName":1390,"dataGaLocation":1292},"/ja-jp/topics/devsecops/","devsecops",{"text":1392,"config":1393},"クラウドネイティブ",{"href":1394,"dataGaName":1395,"dataGaLocation":1292},"/ja-jp/topics/cloud-native/","cloud native",{"text":1397,"config":1398},"コーディングのためのAI",{"href":1399,"dataGaName":1400,"dataGaLocation":1292},"/ja-jp/topics/devops/ai-for-coding/","ai for coding",{"text":1402,"config":1403},"エージェント型AI",{"href":1404,"dataGaName":1405,"dataGaLocation":1292},"/ja-jp/topics/agentic-ai/","agentic ai",{"title":1407,"links":1408},"ソリューション",[1409,1412,1414,1419,1423,1426,1429,1432,1434,1436,1439,1444],{"text":943,"config":1410},{"href":938,"dataGaName":1411,"dataGaLocation":1292},"Application Security Testing",{"text":931,"config":1413},{"href":915,"dataGaName":916,"dataGaLocation":1292},{"text":1415,"config":1416},"アジャイル開発",{"href":1417,"dataGaName":1418,"dataGaLocation":1292},"/ja-jp/solutions/agile-delivery/","agile delivery",{"text":1420,"config":1421},"SCM",{"href":928,"dataGaName":1422,"dataGaLocation":1292},"source code management",{"text":919,"config":1424},{"href":921,"dataGaName":1425,"dataGaLocation":1292},"continuous integration & delivery",{"text":969,"config":1427},{"href":971,"dataGaName":1428,"dataGaLocation":1292},"value stream management",{"text":1372,"config":1430},{"href":1431,"dataGaName":1375,"dataGaLocation":1292},"/ja-jp/solutions/gitops/",{"text":982,"config":1433},{"href":985,"dataGaName":986,"dataGaLocation":1292},{"text":988,"config":1435},{"href":991,"dataGaName":992,"dataGaLocation":1292},{"text":1437,"config":1438},"公共機関",{"href":997,"dataGaName":998,"dataGaLocation":1292},{"text":1440,"config":1441},"教育",{"href":1442,"dataGaName":1443,"dataGaLocation":1292},"/ja-jp/solutions/education/","education",{"text":1445,"config":1446},"金融サービス",{"href":1447,"dataGaName":1448,"dataGaLocation":1292},"/ja-jp/solutions/finance/","financial services",{"title":1450,"links":1451},"リソース",[1452,1454,1456,1458,1462,1464,1467,1469,1471,1473,1475,1477,1479,1481],{"text":1018,"config":1453},{"href":1020,"dataGaName":1021,"dataGaLocation":1292},{"text":1023,"config":1455},{"href":1025,"dataGaName":1026,"dataGaLocation":1292},{"text":1028,"config":1457},{"href":1030,"dataGaName":1031,"dataGaLocation":1292},{"text":1033,"config":1459},{"href":1460,"dataGaName":1461,"dataGaLocation":1292},"https://docs.gitlab.com/ja-jp","docs",{"text":1056,"config":1463},{"href":1058,"dataGaName":1059,"dataGaLocation":1292},{"text":1465,"config":1466},"最新リリース",{"href":1116,"dataGaName":1117,"dataGaLocation":1292},{"text":1051,"config":1468},{"href":1053,"dataGaName":1054,"dataGaLocation":1292},{"text":1070,"config":1470},{"href":1072,"dataGaName":1073,"dataGaLocation":1292},{"text":1078,"config":1472},{"href":1080,"dataGaName":1081,"dataGaLocation":1292},{"text":1083,"config":1474},{"href":1085,"dataGaName":1086,"dataGaLocation":1292},{"text":1088,"config":1476},{"href":1090,"dataGaName":1091,"dataGaLocation":1292},{"text":1093,"config":1478},{"href":1095,"dataGaName":1096,"dataGaLocation":1292},{"text":1098,"config":1480},{"href":1100,"dataGaName":1101,"dataGaLocation":1292},{"text":1103,"config":1482},{"href":1105,"dataGaName":1106,"dataGaLocation":1292},{"title":1484,"links":1485},"会社情報",[1486,1488,1490,1492,1494,1496,1500,1505,1507,1509,1511],{"text":1127,"config":1487},{"href":1129,"dataGaName":1121,"dataGaLocation":1292},{"text":1132,"config":1489},{"href":1134,"dataGaName":1135,"dataGaLocation":1292},{"text":1140,"config":1491},{"href":1142,"dataGaName":1143,"dataGaLocation":1292},{"text":1145,"config":1493},{"href":1147,"dataGaName":1148,"dataGaLocation":1292},{"text":1150,"config":1495},{"href":1152,"dataGaName":1153,"dataGaLocation":1292},{"text":1497,"config":1498},"Sustainability",{"href":1499,"dataGaName":1497,"dataGaLocation":1292},"/sustainability/",{"text":1501,"config":1502},"ダイバーシティ、インクルージョン、ビロンギング（DIB）",{"href":1503,"dataGaName":1504,"dataGaLocation":1292},"/ja-jp/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":1155,"config":1506},{"href":1157,"dataGaName":1158,"dataGaLocation":1292},{"text":1165,"config":1508},{"href":1167,"dataGaName":1168,"dataGaLocation":1292},{"text":1170,"config":1510},{"href":1172,"dataGaName":1173,"dataGaLocation":1292},{"text":1512,"config":1513},"現代奴隷制の透明性に関する声明",{"href":1514,"dataGaName":1515,"dataGaLocation":1292},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1517},[1518,1520,1523],{"text":1339,"config":1519},{"href":1341,"dataGaName":1342,"dataGaLocation":1292},{"text":1521,"config":1522},"Cookieの設定",{"dataGaName":1351,"dataGaLocation":1292,"id":1352,"isOneTrustButton":523},{"text":1344,"config":1524},{"href":1346,"dataGaName":1347,"dataGaLocation":1292},[1526],{"id":1527,"title":7,"body":829,"config":1528,"content":1530,"description":829,"extension":1534,"meta":1535,"navigation":523,"path":1536,"seo":1537,"stem":1538,"__hash__":1539},"blogAuthors/en-us/blog/authors/fernando-diaz.yml",{"template":1529},"BlogAuthor",{"name":7,"config":1531},{"headshot":1532,"ctfId":1533},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749659556/Blog/Author%20Headshots/fern_diaz.png","fjdiaz","yml",{},"/en-us/blog/authors/fernando-diaz",{},"en-us/blog/authors/fernando-diaz","lxRJIOydP4_yzYZvsPcuQevP9AYAKREF7i8QmmdnOWc",[1541,1550,1558],{"title":1542,"description":1543,"heroImage":1544,"category":825,"date":1545,"authors":1546,"slug":1549,"externalUrl":829},"GitLab Secrets ManagerがESO、Terraform、APIに対応","スタック全体の認証情報管理をシンプルに。GitLab Secrets Managerは External Secrets Operator（ESO）、Terraform、Secrets Manager APIに対応し、CI/CD以外の ワークフローからもシークレットを安全に取得できます。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png","2026-08-06",[1547,1548],"Erick Bajao","Joe Randazzo","gitlab-secrets-manager-add-eso-terraform-api-support",{"title":1551,"description":1552,"heroImage":1553,"category":825,"date":1554,"authors":1555,"slug":1557,"externalUrl":829},"Claudeが書き、GitLabがつなぐ：本番環境まで途切れないセキュリティ","Claude Securityはコーディングセッション内で脆弱性を検出します。そこから先はGitLabが引き継ぎ、スキャン、ポリシーの適用、そしてソフトウェアライフサイクル全体の監査エビデンス作成までを担います。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-08-03",[1556],"Alisa Ho","claude-security-and-gitlab",{"title":1559,"description":1560,"heroImage":1561,"category":825,"date":1562,"authors":1563,"slug":1565,"externalUrl":829},"GitLab Duoセキュリティレビューでスキャナーが見逃すロジックの欠陥を検出","AIによるセキュリティ推論で、コードレビューの段階のうちに認可の不備やビジネスロジックのエラー、レース条件を検出します。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1783980535/t3gez0gpayfndrhncunf.png","2026-07-16",[1564],"Mark Settle","gitlab-duo-security-review-flow",{"promotions":1567},[1568,1582,1594,1605],{"id":1569,"categories":1570,"header":1572,"text":1573,"button":1574,"image":1579},"ai-modernization",[1571],"ai","AIの真価、組織全体で発揮できていますか？","所要時間は5分以内です",{"text":1575,"config":1576},"AI成熟度スコアを確認する",{"href":1577,"dataGaName":1578,"dataGaLocation":1059},"/ja-jp/assessments/ai-modernization-assessment/","modernization assessment",{"config":1580},{"src":1581},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":1583,"categories":1584,"header":1586,"text":1573,"button":1587,"image":1591},"devops-modernization",[1585,1390],"product","単にツールを管理するだけでなく、イノベーションを提供していますか？",{"text":1588,"config":1589},"DevOps成熟度スコアを確認しましょう",{"href":1590,"dataGaName":1578,"dataGaLocation":1059},"/ja-jp/assessments/devops-modernization-assessment/",{"config":1592},{"src":1593},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":1595,"categories":1596,"header":1597,"text":1573,"button":1598,"image":1602},"security-modernization",[825],"スピードのためにセキュリティを犠牲にしていませんか？",{"text":1599,"config":1600},"セキュリティ成熟度スコアを確認しましょう",{"href":1601,"dataGaName":1578,"dataGaLocation":1059},"/ja-jp/assessments/security-modernization-assessment/",{"config":1603},{"src":1604},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":1606,"paths":1607,"header":1610,"text":1611,"button":1612,"image":1617},"github-azure-migration",[1608,1609],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","チームはGitHubのAzure移行に対応できていますか？","GitHubはすでにAzureを基盤として再構築を進めています。それがあなたのチームにとって何を意味するのか、ご確認ください。",{"text":1613,"config":1614},"GitLabとGitHubの比較を見る",{"href":1615,"dataGaName":1616,"dataGaLocation":1059},"/ja-jp/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":1618},{"src":1593},{"header":1620,"blurb":1621,"button":1622,"secondaryButton":1626},"今すぐ開発をスピードアップ","DevSecOpsに特化したインテリジェントオーケストレーションプラットフォームで実現できることをご確認ください。\n",{"text":855,"config":1623},{"href":1624,"dataGaName":858,"dataGaLocation":1625},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/ja-jp/","feature",{"text":1175,"config":1627},{"href":1184,"dataGaName":863,"dataGaLocation":1625},1786803771195]