# Parisa Tabriz ## 概要 Parisa Tabriz は Google Chrome のセキュリティチームを率いたセキュリティエンジニアであり、*Building Secure and Reliable Systems* 第19章「Case Study: Chrome Security Team」の著者(協力者: Susanne Landers, Paul Blankinship)である。本ページは同章が語るチーム運営の視点に限定して記録する。(Source: [[@2020__OReilly__Building Secure and Reliable Systems - Chapter 19 Case Study - Chrome Security Team]]) ## Chromeセキュリティチームでの役割 第19章によれば、Chromeのセキュリティチームは2006年のプロジェクト発足時には専任チームを持たず、2009年に専任チーム(v1.0)として発足した後、2010年のVulnerability Reward Program発足を機にハイブリッドエンジニアリングチームとしての性格を確立し(v2.0)、2012〜2013年にコアセキュリティ原則・ミッション・5つの重点領域(セキュリティレビュー、バグの発見と修正、アーキテクチャとエクスプロイト緩和、ユーザブルセキュリティ、ウェブプラットフォームセキュリティ)を確立した(v3.0)。著者はこの一連の組織化を「2012年に書かれたコア原則は2020年時点でも変わらず有効である」と振り返っている。(Source: [[@2020__OReilly__Building Secure and Reliable Systems - Chapter 19 Case Study - Chrome Security Team]] ch.19 §Background and Team Evolution) チーム運営上の具体的な判断として、前例のなかったリサーチサイエンティスト職からの人材をユーザブルセキュリティ領域の立ち上げのために説得して採用したこと、Site Isolationのように見積もりを大幅に超過するもののユーザーから見えにくい多層防御プロジェクトを経営層に説明し続けて擁護したこと、脆弱性の扱いを公開し四半期報告や外部メーリングリストで透明性を保ったことなどが記録されている。(Source: [[@2020__OReilly__Building Secure and Reliable Systems - Chapter 19 Case Study - Chrome Security Team]] ch.19 §Help Users Safely Navigate the Web, §Design for Defense in Depth, §Be Transparent and Engage the Community) ## 関連 - source: [[@2020__OReilly__Building Secure and Reliable Systems - Chapter 19 Case Study - Chrome Security Team]] - 実体: [[Google Chrome]] - 概念: [[セキュリティエンジニアリングチームの管理と組織的リスク]] ## 出典 - Heather Adkins et al. (eds.), *Building Secure and Reliable Systems*, O'Reilly Media, 2020, Chapter 19 (Written by Parisa Tabriz, with Susanne Landers and Paul Blankinship).