

# 文档历史记录
<a name="document-history-for-the-aws-security-incident-response-user-guide"></a>

下表介绍了自 2026 年 1 月 1 日以来对 AWS 安全事件响应文档的重要补充。如需有关此文档的更新通知，您可以订阅 RSS 源。

| 变更 | 说明 | 日期 | 
| --- |--- |--- |
| [使用检测服务和集成指南更新了载入先决条件](https://docs.aws.amazon.com/security-ir/latest/userguide/onboarding-prerequisites.html) | 重写了载入先决条件页面，扩展了关于检测服务（Amazon GuardDuty、AWS Security Hub CSPM、AWS CloudTrail）的指南、通过 Security Hub CSPM 集成第三方 EDR 的指南，并注明在载入前创建的调查发现不会被追溯摄取。 | 2026 年 7 月 2 日 | 
| [重写了“什么是 AWS 安全事件响应”页面](https://docs.aws.amazon.com/security-ir/latest/userguide/what-is.html) | 重写了“什么”页面，更新了内容，涵盖服务概述、调查发现重复数据删除、日志访问权限、抑制规则、自动和人工调查、主动和被动案例、遏制、集成和服务边界。 | 2026 年 7 月 2 日 | 
| [扩展了“检测和分析”页面上的“更新调查发现”部分](https://docs.aws.amazon.com/security-ir/latest/userguide/detect-and-analyze.html) | 重组了“检测和分析”页面，记录了 Amazon GuardDuty 调查发现的完整分级结果分类法，包括已存档的调查发现和未存档的调查发现的类别。将调查发现归档内容从“检测”部分移至“更新调查发现”部分。 | 2026 年 7 月 2 日 | 
| [合并了载入文档](https://docs.aws.amazon.com/security-ir/latest/userguide/deploy-configure.html) | 将“启用 AWS 安全事件响应”页面重写为一个简化的指南，涵盖先决条件、成员账户选择、账户范围配置、服务权限和遏制操作。合并了“选择成员账户”、“设置成员资格详细信息”和“将账户与 AWS Organizations 关联”页面中的内容，这些页面现已重定向到更新后的页面。 | 2026 年 7 月 2 日 | 
| [添加了配置验证指南](https://docs.aws.amazon.com/security-ir/latest/userguide/config-validation.html) | 添加了一个新主题，其中包含验证 AWS 安全事件响应配置的分步程序，包括注册验证、检测源验证、自动管道测试、通知测试、遏制准备情况检查和故障排除指南。 | 2026 年 7 月 2 日 | 
| [已修正“使用 API/CLI 启用安全事件响应”中的 CLI 示例](https://docs.aws.amazon.com/security-ir/latest/userguide/enable-sir-using-cli.html) | 更正了 `create-membership` CLI 示例，在 `--incident-response-team` 数组中的 JSON 对象之间添加了一个缺失的逗号分隔符，并将 `communicationPreferences` 中的无效 `email` 枚举值替换为有效值。 | 2026 年 7 月 1 日 | 
| [修改了遏制文档](https://docs.aws.amazon.com/security-ir/latest/userguide/contain.html) | 整合了“遏制”页面，更新了关于支持的遏制措施、遏制决策、策略制定、分阶段遏制方法以及遏制与事件生命周期的关系等内容的描述。 | 2026 年 6 月 26 日 | 
| [在《入门指南》中添加了“部署遏制”和“EC2 Triage”角色](https://docs.aws.amazon.com/security-ir/latest/userguide/working-with-stacksets.html) | 将 AWS CloudFormation StackSet 文档迁移并重新编写，作为新的入门步骤。添加了创建具有服务托管权限的 StackSet 的分步操作指南，并更新了“仅遏制”和“带有 EC2 Triage 的遏制”选项的模板说明。 | 2026 年 6 月 26 日 | 
| [为委托管理员增加了启用过程中的 IAM 权限要求](https://docs.aws.amazon.com/security-ir/latest/userguide/onboarding-prerequisites.html) | 添加了一项先决条件，规定用于登录委托管理员账户的 IAM 主体必须具备 `AdministratorAccess` 权限。在启用流程的登录步骤中添加了一条说明，明确指出权限不足会导致该步骤失败。 | 2026 年 6 月 19 日 | 
| [合并了载入文档](https://docs.aws.amazon.com/security-ir/latest/userguide/deploy-configure.html) | 将“启用 AWS 安全事件响应”页面重写为一个简化的指南，涵盖先决条件、成员账户选择、账户范围配置、服务权限和遏制操作。合并了“选择成员账户”、“设置成员资格详细信息”和“将账户与 AWS Organizations 关联”页面中的内容，这些页面现已重定向到更新后的页面。 | 2026 年 6 月 17 日 | 
| [在“取消成员资格”中添加了与服务相关的角色清除指南](https://docs.aws.amazon.com/security-ir/latest/userguide/cancel-membership.html) | 添加了一条重要说明，明确指出在取消成员资格后，`AWSServiceRoleForSecurityIncidentResponse` 和 `AWSServiceRoleForSecurityIncidentResponse_Triage` 服务关联角色不会被自动删除。您必须手动从所有处于适用范围内的账户中删除这些角色。 | 2026 年 6 月 17 日 | 
| [将“事件后报告”重命名为“月度报告”](https://docs.aws.amazon.com/security-ir/latest/userguide/monthly-report.html) | 将“事件后报告”部分重命名为“月度报告”。更新了该部分，以明确报告将发送给事件响应团队的所有联系人，包括送达时间，并记录电子邮件主题行格式。 | 2026 年 5 月 13 日 | 
| [更新了接入文档](https://docs.aws.amazon.com/security-ir/latest/userguide/deploy-configure.html) | 更新了“启用 AWS 安全事件响应”主题，以阐明使用控制台时，AWS 安全事件响应会自动在 AWS Organizations 管理账户中创建 `AWSServiceRoleForSecurityIncidentResponse_Triage` 服务相关角色。增加了一个链接，指向使用 API/CLI 启用安全事件响应的说明。 | 2026 年 5 月 7 日 | 
| [增加了使用 API/CLI 启用安全事件响应的主题](https://docs.aws.amazon.com/security-ir/latest/userguide/enable-sir-cli.html) | 增加了一个新主题，其中包含使用委派管理员注册和管理账户注册方法启用 AWS 安全事件响应的 CLI 分步说明。 | 2026 年 5 月 7 日 | 
| [澄清了对 Amazon GuardDuty 和第三方调查发现的主动响应要求](https://docs.aws.amazon.com/security-ir/latest/userguide/setup-monitoring-and-investigation-workflows.html) | 澄清了 Amazon GuardDuty 不需要使用主动响应。AWS安全事件响应还可以使用 Security Hub CSPM 集成来监控并调查来自第三方威胁检测工具的威胁警报。更新了该部分，以准确描述检测服务要求和配置调查发现摄取的价值。 | 2026 年 5 月 5 日 | 
| [添加了 EC2 Triage 支持的操作系统](https://docs.aws.amazon.com/security-ir/latest/userguide/detect-and-analyze.html) | 添加了 EC2 Triage 功能支持的操作系统列表，包括 Linux 发行版（Amazon Linux 2、Amazon Linux 2023、Ubuntu、RHEL、CentOS、SLES 和 Debian）和 Windows Server 版本。 | 2026 年 4 月 29 日 | 
| [更新了 `AWSSecurityIncidentResponseReadOnlyAccess` 的策略描述](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html) | 更新了策略以添加 `security-ir:ListInvestigations` 操作。 | 2026 年 4 月 22 日 | 
| [更新了 `AWSSecurityIncidentResponseFullAccess` 的策略描述](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html) | 更新了策略以添加 AWS Organizations 权限，并删除了 MFA 条件。 | 2026 年 4 月 22 日 | 
| [更新了 `AWSSecurityIncidentResponseCaseFullAccess` 的策略描述](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html) | 更新了策略以添加 `security-ir:ListInvestigations` 和 `security-ir:SendFeedback` 操作，并删除了 MFA 条件。 | 2026 年 4 月 22 日 | 
| [用于 AWS 安全事件响应的 EC2 Triage 功能](https://docs.aws.amazon.com/security-ir/latest/userguide/detect-and-analyze.html) | 添加了 EC2 Triage 功能，使 AWS 安全事件响应能够在安全调查期间使用 AWS Systems Manager Run Command 从 Amazon Elastic Compute Cloud 实例收集调查信息。更新了“检测和分析”页面，以记录 EC2 Triage 先决条件和功能。 | 2026 年 4 月 20 日 | 
| [用于 AWS 安全事件响应的 EC2 Triage 功能](https://docs.aws.amazon.com/security-ir/latest/userguide/working-with-stacksets.html) | 更新了 CloudFormation StackSets 文档以提供两个模板选项：“仅遏制”和“带有 EC2 Triage 的遏制”。“带有 EC2 Triage 的遏制”模板包括从 Amazon EC2 实例收集调查数据的额外权限。 | 2026 年 4 月 20 日 | 
| [受监管客户的数据收集、区域行为和合规性指导](https://docs.aws.amazon.com/security-ir/latest/userguide/data-collection-and-usage.html) | 添加了有关数据收集和使用、数据驻留和区域行为以及数据访问和权限的新章节。扩展了合规性验证部分，为受监管行业的客户提供了责任共担和元数据分类指导。 | 2026 年 4 月 17 日 | 
| [更新了入门指南](https://docs.aws.amazon.com/security-ir/latest/userguide/onboarding-guide.html) | 使用新的分步结构更新了入门指南，包括事件响应团队的准备步骤、先决条件和简化的配置工作流、案例类型和工具集成。 | 2026 年 4 月 7 日 | 
| [更新了 AWS 安全事件响应分级服务角色策略的策略描述](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html) | 更新了 AWS 安全事件响应分级服务角色策略的策略描述，以反映允许该服务改进服务调整并收集信息以调查潜在事件的更改。 | 2026 年 3 月 27 日 | 
| [提交元数据](#document-history-for-the-aws-security-incident-response-user-guide) | 添加了通过 AWS 支持 案例提交元数据的说明。 | 2026 年 3 月 27 日 | 
| [提交遏制偏好](https://docs.aws.amazon.com/security-ir/latest/userguide/submit-containment-preferences.html) | 添加了通过 AWS 支持 案例提交遏制偏好的说明。 | 2026 年 3 月 27 日 | 
| [遏制堆栈集模板](https://docs.aws.amazon.com/security-ir/latest/userguide/working-with-stacksets.html) | 更新了遏制堆栈集 CloudFormation 模板。 | 2026 年 3 月 27 日 | 
| [阐明了委派管理员账户的 AWS 区域 注意事项](https://docs.aws.amazon.com/security-ir/latest/userguide/considerations_important.html) | 阐明如下事实：虽然您于初始设置期间在一个 AWS 区域 中指定委托的 AWS 安全事件响应管理员账户，但该服务在所有支持的 AWS 区域 中提供组织范围的覆盖。 | 2026 年 3 月 20 日 | 
| [定义遏制措施偏好](https://docs.aws.amazon.com/security-ir/latest/userguide/define-containment-preferences.html) | 更新了遏制措施偏好部分以匹配当前选项。 | 2026 年 3 月 19 日 | 
| [主动响应和警报分级](https://docs.aws.amazon.com/security-ir/latest/userguide/setup-monitoring-and-investigation-workflows.html) | 删除有关主动响应和警报分级工作流属于可选功能的表述。 | 2026 年 3 月 3 日 | 
| [响应时限](https://docs.aws.amazon.com/security-ir/latest/userguide/what-to-expect-from-aws-sir-engineers.html) | 更新了响应时限，将案例确认的 SLO 指定为 15 分钟，案例关闭前的客户响应时限为 5 个工作日。 | 2026 年 2 月 24 日 | 
| [沟通最佳实践](https://docs.aws.amazon.com/security-ir/latest/userguide/communication-best-practices.html) | 更新了案例关闭时限，规定客户响应关键信息请求的时限为 5 个工作日。 | 2026 年 2 月 24 日 | 
| [在“使用 AWS CloudShell 与安全事件响应进行交互”部分增加了 AWS CLI 参考](https://docs.aws.amazon.com/security-ir/latest/userguide/cshell-examples.html) | 添加了指向“AWS 安全事件响应的 AWS Command Line Interface 参考”链接。 | 2026 年 2 月 24 日 | 
| [RACI 矩阵](https://docs.aws.amazon.com/security-ir/latest/userguide/raci-matrix.html) | 将 RACI 矩阵中的“授权 CIRT 遏制措施”更新为“授权遏制措施”。 | 2026 年 2 月 13 日 | 
| [遏制偏好](https://docs.aws.amazon.com/security-ir/latest/userguide/define-containment-preferences.html) | 将遏制偏好选项从“无遏制措施”、“经批准后遏制”和“自动遏制”更新为“需要审批”、“遏制已确认”和“遏制疑似”，并修改了描述。 | 2026 年 2 月 13 日 | 
| [安全事件响应部署后](https://docs.aws.amazon.com/security-ir/latest/userguide/post-deploy.html) | 添加了指向“AWS 安全事件响应：新集成与 OU 级别订阅”演示的链接。 | 2026 年 2 月 4 日 | 
| [监控与调查](https://docs.aws.amazon.com/security-ir/latest/userguide/monitoring-and-investigation.html) | 在此页面的介绍及子章节中添加了修改后的内容。 | 2026 年 2 月 4 日 | 
| [检测与分析](https://docs.aws.amazon.com/security-ir/latest/userguide/detect-and-analyze.html) | 在此页面的介绍及子章节中添加了修改后的内容。 | 2026 年 2 月 4 日 | 
| [遏制](https://docs.aws.amazon.com/security-ir/latest/userguide/contain.html) | 在此页面中添加了修改后的内容。 | 2026 年 2 月 4 日 | 
| [人工智能调查代理](https://docs.aws.amazon.com/security-ir/latest/userguide/ai-investigative-agent.html) | 在此页面中增加了客户数据的使用免责声明。免责声明：人工智能调查代理不使用客户数据进行模型训练，也不会与第三方共享客户数据。 | 2026 年 2 月 4 日 | 

**Topics**


|  更改  |  描述  |  日期  | 
| --- | --- | --- | 
| 取消会员资格 | 更新了[取消成员资格页面，说明成员资格和服务将在取消后立即终止，而不是在账单周期结束时才终止。](https://docs.aws.amazon.com//security-ir/latest/userguide/cancel-membership.html) | 2025 年 11 月 20 日 | 
| AWS 托管式策略 | [在服务提供的操作列表中增加了“更新案例”、“创建案例备注”、“列出案例”、“列出案例备注”等操作。](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html#AWSSecurityIncidentResponseServiceRolePolicy) | 2025 年 11 月 19 日 | 
| 使用服务关联角色 | [在服务提供的操作列表中增加了“更新案例”、“创建案例备注”、“列出案例”、“列出案例备注”等操作。](https://docs.aws.amazon.com/security-ir/latest/userguide/using-service-linked-roles.html) | 2025 年 11 月 19 日 | 
| 通信首选项 | 创建并更新了[为新功能文档添加了“通信首选项”部分。](https://docs.aws.amazon.com/security-ir/latest/userguide/communication-preferences.html) | 2025 年 11 月 12 日 | 
| 信息载入指南新增内容与更新 | 创建并更新了[添加了信息载入指南，包括以下部分](https://docs.aws.amazon.com/security-ir/latest/userguide/onboarding-guide.html)<br />增加了[启用安全事件响应](https://docs.aws.amazon.com/security-ir/latest/userguide/deploy-configure.html)章节。<br />增加了[授权安全事件响应工程师执行威胁遏制措施](https://docs.aws.amazon.com/security-ir/latest/userguide/authorize-security-incident-response.html)章节。<br />增加了[安全事件响应部署后](https://docs.aws.amazon.com/security-ir/latest/userguide/post-deploy.html)章节。<br />添加了[更新事件响应团队](https://docs.aws.amazon.com/security-ir/latest/userguide/support-case.html)部分。<br />添加了 [GuardDuty 调查发现和禁止规则](https://docs.aws.amazon.com/security-ir/latest/userguide/guard-duty.html)部分。<br />添加了 [Amazon EventBridge](https://docs.aws.amazon.com/security-ir/latest/userguide/amazon-eventbridge.html) 部分。<br />添加了[集成和外部工具工作流程](https://docs.aws.amazon.com/security-ir/latest/userguide/integrations-external-tooling.html)部分。<br />添加了[外部工具工作流程](https://docs.aws.amazon.com/security-ir/latest/userguide/external-tooling.html)部分。 | 2025 年 11 月 12 日 | 
| 合规和账单语言更新 | 更新了[已删除AWS任何框架均未涵盖安全事件响应AWS的声明。HITRUST 现在涵盖了安全事件响应，将来还会有更多内容。](https://docs.aws.amazon.com/security-ir/latest/userguide/compliance-validation.html)<br />更新了[可见性和控制](https://docs.aws.amazon.com/security-ir/latest/userguide/visibility-and-alerting.html)以添加AWS安全事件响应<br />更新了[取消会员资格](https://docs.aws.amazon.com/security-ir/latest/userguide/cancel-membership.html)，以明确服务账单周期。<br />在[入门](https://docs.aws.amazon.com/security-ir/latest/userguide/getting-started.html)中添加了一段视频，为开始使用 AWS 安全事件响应的典型任务提供了额外的背景信息。 | 2025 年 8 月 15 日 | 
| 更新了 – [AWSSecurityIncidentResponseServiceRolePolicy](aws-managed-policies.md#AWSSecurityIncidentResponseServiceRolePolicy) | 该政策现在包括以下两个新操作 `"organizations:DescribeAccount"`、`"organizations:ListDelegatedAdministrators"` 和一个新条件：<pre><br />"Condition": {<br />      "StringEquals": {<br />        "aws:ResourceAccount": "${aws:PrincipalAccount}"<br />      }<br />    }<br />            </pre> | 待定 | 
| 功能更新：订阅特定组织单元（OU）或整个 AWS 组织 | 用户界面中的帮助面板已更新，以反映订阅特定组织单元（OU）或整个 AWS 组织的更新。<br />创建用于[管理组织单元（OU）成员资格](https://docs.aws.amazon.com/security-ir/latest/userguide/managing-membership-with-ou.html)的新页面<br />与 AWS Organizations 相关的页面已更新，以反映新的 OU 管理功能。 | 2025 年 8 月 7 日 | 
| 更新了服务限额 | 服务配额页面已更新，引导用户查看《AWS 一般参考指南》中的 [AWS 安全事件响应端点和配额](https://docs.aws.amazon.com/general/latest/gr/securityir.html) | 2025 年 8 月 7 日 | 
| 用户反馈更新 | 为该服务添加了 [AWS 安全事件响应案例](https://docs.aws.amazon.com/security-ir/latest/userguide/cases.html)的超链接<br />更新以反映[《安全技术指南》](https://docs.aws.amazon.com/security-ir/latest/userguide/introduction.html)的《计算机安全事件处理指南》SP 800-61 r3 | 2025 年 8 月 7 日 | 
| 添加 Amazon EventBridge 与 AWS 安全事件响应集成的页面。 | 新的内容章节，介绍 Amazon EventBridge 如何集成到 AWS 安全事件响应中。 | 2025 年 6 月 26 日 | 
| SLR 更新，增加了获得支持服务权利的权限。 | [AWSSecurityIncidentResponseTriageServiceRolePolicy](aws-managed-policies.md#AWSSecurityIncidentResponseTriageServiceRolePolicy) 已更新，添加了 security-ir:GetMembership、security-ir:ListMemberships、security-ir:UpdateCase、guardduty:ListFilters、guarduty:UpdateFilter、guardduty:DeleteFilter，以及 guardduty:GetAdministratorAccount 权限。添加的 guardduty:GetAdministratorAccount 权限有助于在委托账户中实现 GuardDuty 自动存档筛选条件管理。 | 2025 年 6 月 2 日 | 
| 资源更新。 | 更新了 https://docs.aws.amazon.com/security-ir/latest/userguide/appendix-b-incident-response-resources.html\#playbook-resources 以反映可供客户参加的活动讲习会。 | 2025 年 5 月 23 日 | 
| 服务现在支持日语。 | 更新了支持的配置，以识别日语支持（日本当地时间）。全球都支持英语。 | 2025 年 5 月 13 日 | 
| 内容更新和客户反馈。 |  在 https://docs.aws.amazon.com/security-ir/latest/userguide/select-a-membership-account.html 中添加了说明，以反映在设置过程中使用委托管理员账户时需完成的额外任务。<br /> 更新了[服务生成的案例](https://docs.aws.amazon.com/security-ir/latest/userguide/responding-to-an-aws-generated-case.html)和[检测和分析](https://docs.aws.amazon.com/security-ir/latest/userguide/detect-and-analyze.html)功能的客户使用体验。<br /> 更新了账户取消详情，以便更清晰地说明[取消会员资格](https://docs.aws.amazon.com/security-ir/latest/userguide/cancel-membership.html)的计费影响。 | 2025 年 5 月 9 日 | 
| 添加三个新的支持区域。 |  在 https://docs.aws.amazon.com/security-ir/latest/userguide/supported-configs.html 中添加了三个新区域。孟买、巴黎和圣保罗。 | 2025 年 5 月 7 日 | 
|  更新：根据客户评论对文档进行了更新。 | 多个页面上的拼写和语法错误都已更正。<br /> 更新了 https://docs.aws.amazon.com/en\_us/security-ir/latest/userguide/organizations\_permissions.html 以准确反映 security-ir 是服务前缀。<br /> 在 https://docs.aws.amazon.com/security-ir/latest/userguide/source-containment.html 中添加了一条关于 Route53 和 DNS 的说明。 |  2025 年 2 月 7 日  | 
|  更新：根据客户评论对文档进行了更新。 | 更新了 https://docs.aws.amazon.com/security-ir/latest/userguide/setup-monitoring-and-investigation-workflows.html 中的 StackSet 模板。<br /> 将 triage.security-ir.com 条目更正为 triage.security-ir.amazonaws.com <br /> 在 https://docs.aws.amazon.com/security-ir/latest/userguide/contain.html 中添加了对 AWSSupport-ContainEC2Reversible 的跟踪连接说明。<br /> 修复了 https://docs.aws.amazon.com/security-ir/latest/userguide/managing-associated-accounts.html 中的失效链接。<br /> 在 https://docs.aws.amazon.com/security-ir/latest/userguide/select-a-membership-account.html 中添加了会员账户定义。<br /> 在 https://docs.aws.amazon.com/en\_us/security-ir/latest/userguide/using-service-linked-roles.html 中添加了针对 AWS Organizations 管理账户的澄清说明。 |  2024 年 12 月 20 日  | 
|  更新：根据客户评论对文档进行了更新。 | 删除了文中多个重复的 AWS AWS。<br />修复了 https://docs.aws.amazon.com/security-ir/latest/userguide/sir\_tagging.html 和 https://docs.aws.amazon.com/security-ir/latest/userguide/service-name-info-in-cloudtrail.html 中的失效链接。<br />https://docs.aws.amazon.com/security-ir/latest/userguide/contain.html 更新。删除了第一段中的 >。将 AWSSupport-ContainEC2Reversible 替换为 AWSSupport-ContainEC2Instance。将 AWSSupport-ContainIAMReversible 替换为 AWSSupport-ContainIAMPrincipal。将 AWSSupport-ContainS3Reversible 替换为 AWSSupport-ContainS3Resource。<br />更新了 https://docs.aws.amazon.com/en\_us/security-ir/latest/userguide/issues.html 中的格式<br />在告诉客户通过支持票证联系安全事件响应时，https://docs.aws.amazon.com/security-ir/latest/userguide/understand-response-teams-and-support.html 现在提供了若干可在支持表单中选择的选项。<br />删除了 https://docs.aws.amazon.com/security-ir/latest/userguide/logging-and-events.html 中的 CloudWatch Events，将其替换为 EventBridge。<br />更新了 https://docs.aws.amazon.com/security-ir/latest/userguide/technique-access-containment.html 中的语法。<br />删除了 https://docs.aws.amazon.com/security-ir/latest/userguide/security-incident-response-guide.html 中的发布日期，替换为此表中的更新日期。 |  2024 年 12 月 10 日  | 
|  更新：AWS 托管策略和服务相关角色。 |  [托管策略和服务相关角色更新。](https://docs.aws.amazon.com/security-ir/latest/userguide/aws-managed-policies.html#managed-policy-updates) |  2024 年 12 月 1 日  | 
|  服务启动  |  re:Invent 2024 服务发布的初始文档  |  2024 年 12 月 1 日  | 