Published: 2024-03-14 08:00


 一般社団法人日本スマートフォンセキュリティ協会(JSSEC)は3月8日、「スマートフォンアプリケーション開発者実施規範」を発表した。英国「Code of practice for app store operators and app developers」の日本語位置づけとなり、開発者実施すべきことを網羅している。


 この実施規範は、スマートフォンセキュリティを技術面から支援するJSSECの活動一環となるもの。JSSECでは、2023年に英国のDepartment for Science, Innovation & Technologyが発行している「Code of practice for app store operators and app developers」のアプリケーション提供者が実施すべきことに着目し、その日本作成した。

 「Code of practice for app store operators and app developers」は、アプリケーション運営者とアプリケーション提供者がユーザーを保護するための実践的手順明示しており、一般的認識されているセキュリティとプライバシーの慣行にも言及している。これらの原則重要なものであるが、日本国内ではすべて網羅した手順書のような資料存在していなかった。


1:実施規範 2:実装ガイドのスコープ 3:セキュリティとプライバシーの基本要件 4:アプリ公開後のメンテナンス 5:プライバシーの基本要件 6:利用規約基本要件 7:ユーザーサポート 8:セキュリティインシデント対応 9:おわりに




# 言葉 意味
8 じっし (実施) : enforcement; implementation; putting into practice; carrying out; operation; working (e.g. working parameters); enactment
6 きはん (規範) : model; standard; pattern; norm; criterion; example
6 ようけん (要件) : 1. important matter 2. requirement; requisite; necessary condition; sine qua non
5 ていきょう (提供) : 1. offer; tender; providing; supplying; making available; donating (blood, organs, etc.) 2. sponsoring (a TV program)
5 きほん (基本) : basics; fundamentals; basis; foundation
3 はん (版) : 1. edition; version; printing; impression; implementation (e.g. software) 2. plate; block; cast
3 もうら (網羅) : encompassing; covering (exhaustively); including (all of); comprising; comprehending
3 こうかい (公開) : opening to the public; making available to the public; putting on display; exhibiting; showing (play, movie, etc.); holding (interview, etc.); open; public
3 たいおう (対応) : 1. correspondence (to); equivalence 2. suitability; coordination; matching; being appropriate (for)
3 ぜいじゃくせい (脆弱性) : vulnerability; weakness; fragility
2 にほん (日本) : Japan
2 かいはつしゃ (開発者) : developer
2 えいこく (英国) : United Kingdom; Britain; Great Britain
2 にほんご (日本語) : Japanese (language)
2 てじゅん (手順) : process; procedure; sequence; protocol; instruction
2 げんそく (原則) : 1. principle; general rule 2. as a rule; in principle; in general
2 じゅうよう (重要) : important; momentous; essential; principal; major
2 きさい (記載) : mention (in a document); record; entry; statement; listing
2 きわ (際) : 1. edge; brink; verge; side 2. time; moment of
2 ほうしん (方針) : 1. policy; course; plan (of action); principle 2. magnetic needle
2 せいび (整備) : 1. maintenance; servicing 2. putting in place; establishment; development; preparation; provision; outfitting
1 いっぱんしゃだんほうじん (一般社団法人) : general incorporated association
1 きょうかい (協会) : association; society; organization; organisation
1 はっぴょう (発表) : announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
1 いちづけ (位置付け) : placement; fixed position; mapping out; location
1 がぞう (画像) : image; picture; portrait
1 ぜん (全) : 1. all; whole; entire; complete; total; pan- 2. complete (set); in total
1 ぎじゅつめん (技術面) : technical side
1 しえん (支援) : support; backing; aid; assistance
1 かつどう (活動) : 1. activity (of a person, organization, animal, volcano, etc.); action 2. movie (esp. during the silent movie period)
1 いっかん (一環) : 1. link (e.g. in a chain of events); part (of a plan, campaign, activities, etc.) 2. monocyclic
1 はっこう (発行) : 1. publication; issue (of journal, newspaper, etc.) 2. issue (of banknotes, bonds, passport, etc.)
1 ちゃくもく (着目) : attention; giving one's attention; focusing
1 さくせい (作成) : drawing up (e.g. legal document, contract, will, etc.); preparing; writing; framing; making; producing; creating; creation
1 うんえい (運営) : management; administration; operation
1 ほご (保護) : 1. protection; safeguard; guardianship; custody; patronage 2. preservation; conservation
1 じっせんてき (実践的) : practical; pragmatic; hands-on; nuts and bolts
1 めいじ (明示) : elucidation; explicit statement; specification
1 いっぱんてき (一般的) : general; popular; common; typical
1 にんしき (認識) : recognition; awareness; perception; understanding; knowledge; cognition; cognizance; cognisance
1 かんこう (慣行) : customary practice; habit; traditional event
1 げんきゅう (言及) : reference; allusion
1 にほんこくない (日本国内) : Japanese domestic
1 すべて (全て) : 1. everything; all; the whole 2. entirely; completely; wholly; all
1 しりょう (資料) : materials; data; document
1 そんざい (存在) : existence; being
1 さんか (参加) : participation; joining; entry; adherence
1 きぎょう (企業) : enterprise; business; company; corporation
1 ぎじゅつしゃ (技術者) : engineer; technical expert; technician; craftsperson
1 および (及び) : and; as well as
1 ゆうしきしゃ (有識者) : expert; knowledgeable person; authority (on a subject)
1 ぎろん (議論) : argument; discussion; dispute; controversy
1 おこなう (行う) : to perform; to do; to conduct oneself; to carry out
1 かいし (開始) : start; commencement; beginning; initiation
1 けいぞく (継続) : continuation
1 もくてき (目的) : purpose; goal; aim; objective; intention
1 まとめる (纏める) : 1. to collect; to put (it all) together; to integrate; to consolidate; to unify 2. to summarize; to aggregate
1 もくじ (目次) : table of contents; contents
1 とおり (通り) : 1. avenue; street; way; road 2. coming and going; street traffic
1 じっそう (実装) : implementation (e.g. of a feature); installation (of equipment); mounting; packaging
1 りようきやく (利用規約) : terms of service; terms of use; terms and conditions
1 じゅんきょ (準拠) : basis; based on; conformance; conformity; authority (of); standard; reference
1 それぞれ (夫れ夫れ) : each; respectively
1 てき (的) : 1. -ical; -ive; -al; -ic; -y 2. -like; -ish; -sort of; -kind of
1 いえる (言える) : 1. to be possible to say; to be able to say 2. said; have said
1 ていきてき (定期的) : periodic; regular; routine
1 かくにん (確認) : confirmation; verification; validation; review; check; affirmation; identification
1 くわえる (加える) : 1. to add; to add up; to sum up; to append; to annex 2. to increase; to gather (e.g. speed); to pick up
1 じしゃ (自社) : 1. one's company; company one works for 2. in-house; belonging to the company
1 はっけん (発見) : discovery; detection; finding
1 がいぶ (外部) : 1. outside (e.g. of a building); exterior 2. outside (of a group, company, etc.); outside world
1 しんこく (申告) : report; return (e.g. tax); statement; declaration; notification; filing
1 むしょう (無償) : 1. without compensation; without reward; without pay 2. free (of charge)
1 かのう (可能) : possible; potential; practicable; feasible