ããã³ããšã³ã決æžã»ãã¥ãªãã£ãšã³ãžã³ã培åºè§£èª¬ããã²ã«ãŒãããã©ãŒã ãžã£ããã³ã°ãªã©ã®è åšããä¿è·ãã顧客ã®ä¿¡é Œãé«ããæ¹æ³ã説æããŸãã
æåç·ã匷åããïŒããã³ããšã³ã決æžãªã¯ãšã¹ãã»ãã¥ãªãã£ãšã³ãžã³ã®åŸ¹åºè§£èª¬
ã°ããŒãã«ãªããžã¿ã«ããŒã±ãããã¬ã€ã¹ã«ãããŠããã§ãã¯ã¢ãŠãããŒãžã¯åãªãååŒã®ã¹ãããã§ã¯ãããŸãããããã¯æçµçãªæ¡æã§ããã顧客ã®ä¿¡é Œãåºãããããããããã¯æã¡ç ããããã®ç¬éã§ããeã³ããŒã¹ããã¹ãŠã®å€§éžã§é©ç°çãªæé·ãç¶ããã«ã€ããŠããã®éèŠãªå²è·¯ãæšçãšãããµã€ããŒè åšã®å·§åŠããå¢ããŠããŸããåŸæ¥ãäŒæ¥ã¯ãµãŒããŒã匷åããå ç¢ãªãã¡ã€ã¢ãŠã©ãŒã«ãæ§ç¯ããããŒã¿ããŒã¹ãæå·åããŠããŸãããããããããæŠå Žãç§»ã£ãŠããŸã£ããšãããã©ãã§ãããïŒããæãè匱ãªç¹ããé¡§å®¢ã«æãè¿ãå Žæãã€ãŸã圌ãèªèº«ã®ãŠã§ããã©ãŠã¶ã ãšãããïŒ
ãããçŸä»£ã®æ±ºæžã»ãã¥ãªãã£ã®çŸå®ã§ããæªæã®ããæ»æè ã¯ããŠãŒã¶ãŒãæãæ©å¯æ§ã®é«ãæ å ±ãå ¥åããã¯ã©ã€ã¢ã³ããµã€ãç°å¢ã§ããããã³ããšã³ãããŸããŸãæšçã«ããŠããŸããããã«ãããæ°ããäžå¯æ¬ ãªé²åŸ¡ã«ããŽãªãçãŸããŸããããããããã³ããšã³ã決æžãªã¯ãšã¹ãã»ãã¥ãªãã£ãšã³ãžã³ã§ãããã®å æ¬çãªã¬ã€ãã§ã¯ãçŸä»£ã®æ±ºæžä¿è·ç®¡çã«ããããããã®ãšã³ãžã³ã®éèŠãªåœ¹å²ãæ¢ããããããç¡ååããè åšããã®ã³ã¢ã³ã³ããŒãã³ãããããŠããããè§£ãæŸã€è«å€§ãªããžãã¹äŸ¡å€ãåæããŸãã
è åšã®ã©ã³ãã¹ã±ãŒããçè§£ããïŒãªãããã³ããšã³ãã»ãã¥ãªãã£ã¯è²ããªãã®ã
äœå幎ãã®éãã»ãã¥ãªãã£ã®ãã©ãã€ã ã¯ãµãŒããŒäžå¿ã§ãããäž»ãªç®æšã¯ãããã¯ãšã³ãã€ã³ãã©ãäŸµå ¥ããä¿è·ããããšã§ããããããããµã€ããŒç¯çœªè ã¯é©å¿ããŸããã圌ãã¯ã匷åããããµãŒããŒãæ»æããã®ã¯é£ããããå¶åŸ¡ãããŠãããã倿§ã§ããã°ãã°è匱ãªç°å¢ã§ãããŠãŒã¶ãŒã®ãã©ãŠã¶ã䟵害ããæ¹ãã¯ããã«ç°¡åã§ããããšã«æ°ã¥ããŸããããã®ãµãŒããŒãµã€ãããã¯ã©ã€ã¢ã³ããµã€ããžã®æ»æãžã®ã·ããã¯ãå€ãã®çµç¹ã«ãšã£ãŠå±éºãªæ»è§ãçã¿åºããŸããã
äžè¬çãªããã³ããšã³ã決æžã®è åšïŒã³ã³ããŒãžã§ã³ã®éããªããã©ãŒ
ããã³ããšã³ãã§åäœããè åšã¯ããŠãŒã¶ãŒãšããŒãã£ã³ãã®ããã¯ãšã³ãã·ã¹ãã ã®äž¡æ¹ã«ãšã£ãŠç®ã«èŠããªãããšãå€ããããé°æ¹¿ã§ãããµãŒããŒäžã§ã¯ååŒãå®å šã«æ£åœã«èŠãããããããŸãããããã®éã«é¡§å®¢ã®ããŒã¿ã¯ãã§ã«çãŸããŠããŸãã
- ããžã¿ã«ã¹ããã³ã°ïŒãã²ã«ãŒãåæ»æïŒïŒããã¯æãèå»¶ããŠããè åšã®äžã€ã§ããæ»æè ã¯ããã°ãã°äŸµå®³ããããµãŒãããŒãã£ã®ã¹ã¯ãªããïŒãã£ããããããåæããŒã«ãåºåãããã¯ãŒã¯ãªã©ïŒãä»ããŠããŠã§ããµã€ãã«æªæã®ããJavaScriptã³ãŒããæ³šå ¥ããŸãããã®ã³ãŒãã¯ããŠãŒã¶ãŒããã§ãã¯ã¢ãŠããã©ãŒã ã«å ¥åããæ¯æãã«ãŒãæ å ±ãéãã«çã¿åããæ»æè ã管çãããµãŒããŒã«éä¿¡ããŸãã
- ãã©ãŒã ãžã£ããã³ã°ïŒããžã¿ã«ã¹ããã³ã°ã®äžçš®ã§ã決æžãã©ãŒã ã®éä¿¡åäœãæ¹ããããŸããæªæã®ããã¹ã¯ãªããã¯ãéä¿¡ããã¿ã³ãä¹ã£åããæ£åœãªæ±ºæžåŠçæ¥è ãšæ»æè ã®ãµãŒããŒã®äž¡æ¹ã«ããŒã¿ãåæã«éä¿¡ããããšãã§ããŸãã
- ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒïŒãŠã§ããµã€ãã«XSSã®è匱æ§ãããå Žåãæ»æè ã¯ãŠãŒã¶ãŒã®ãã©ãŠã¶ã§å®è¡ãããæªæã®ããã¹ã¯ãªãããæ³šå ¥ã§ããŸããæ±ºæžã®æèã§ã¯ããããå©çšããŠæ±ºæžããŒãžãæ¹ããããããåœã®ãã£ãŒã«ãã远å ããŠè¿œå ããŒã¿ïŒPINãªã©ïŒãåéããããã»ãã·ã§ã³ã¯ãããŒãçãã§ãŠãŒã¶ãŒã«ãªãããŸãããããããšãã§ããŸãã
- ã¯ãªãã¯ãžã£ããã³ã°ïŒãã®ææ³ã§ã¯ãæ¬ç©ã®æ±ºæžãã¿ã³ã®äžã«ãèŠãç®ã¯æ£åœã ãéæãªiframeãéããŠè¡šç€ºããŸãããŠãŒã¶ãŒã¯ãè³Œå ¥ã確å®ããã¯ãªãã¯ããŠããã€ããã§ããå®éã«ã¯éæãªã¬ã€ã€ãŒäžã®ãã¿ã³ãã¯ãªãã¯ããŠãããããã«ãã£ãŠäžæ£ãªååŒãæ¿èªãããããæªæã®ããããŠã³ããŒããããªã¬ãŒããããããå¯èœæ§ããããŸãã
- Man-in-the-Browser (MitB) æ»æïŒä»ãããé«åºŠãªãã®æ»æã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã«ãã§ã«ååšãããã«ãŠã§ã¢ã䌎ããŸãããã®ãã«ãŠã§ã¢ã¯ãããŒã¿ãæå·åãããŠéä¿¡ãããçŽåã«ãéè¡æ¯èŸŒãã©ãŒã ã®åå人å£åº§çªå·ã倿Žãããªã©ããã©ãŠã¶èªäœã®äžã§ããŒã¿ãååããæ¹ããããããšãã§ããŸãã
åŸæ¥ã®ã»ãã¥ãªãã£å¯Ÿçã®éç
ãªãæšæºçãªã»ãã¥ãªãã£ããŒã«ã¯ãããã®æ»æã黿¢ã§ããªãã®ã§ããããïŒãã®çãã¯ããããã®çŠç¹ã«ãããŸããWeb Application Firewall (WAF) ã¯æªæã®ãããµãŒããŒãªã¯ãšã¹ãããã£ã«ã¿ãªã³ã°ããã®ã«åªããŠããŸããããŠãŒã¶ãŒã®ãã©ãŠã¶å ã§å®è¡ãããŠããJavaScriptãå¯èŠåããããšã¯ã§ããŸããããµãŒããŒãµã€ãã®ããªããŒã·ã§ã³ã¯ã¯ã¬ãžããã«ãŒãçªå·ã®åœ¢åŒãæ£ãããã確èªã§ããŸããããã®çªå·ãã¹ããã³ã°ã¹ã¯ãªããã«ãã£ãŠãåžãäžãããããã©ããã¯ããããŸãããTLS/SSLæå·åã¯è»¢éäžã®ããŒã¿ãä¿è·ããŸãããéä¿¡åãã€ãŸããã©ãŠã¶ã®ãã©ãŒã ã«å ¥åãããŠããæäžã®ããŒã¿ã¯ä¿è·ããŸããã
ããã³ããšã³ã決æžãªã¯ãšã¹ãã»ãã¥ãªãã£ãšã³ãžã³ã®ç޹ä»
ããã³ããšã³ã決æžãªã¯ãšã¹ãã»ãã¥ãªãã£ãšã³ãžã³ã¯ããŠãŒã¶ãŒããã§ãã¯ã¢ãŠãããŒãžã«ã¢ã¯ã»ã¹ããç¬éãããããŒã¿ãå®å šã«éä¿¡ããããŸã§ã決æžãžã£ãŒããŒå šäœãä¿è·ããããã«èšèšããããå°éçãªã¯ã©ã€ã¢ã³ããµã€ãã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§ããããã¯ãŠãŒã¶ãŒã®ãã©ãŠã¶å ã§çŽæ¥åäœããæ±ºæžãã©ãŒã ã®å°ä»»ã®ãªã¢ã«ã¿ã€ã ã»ãã¥ãªãã£ã¬ãŒããšããŠæ©èœããŸãã
ã»ãã¥ãªãã£ãšã³ãžã³ãšã¯äœãïŒ
ã¯ã©ã€ã¢ã³ããµã€ãã§æ±ºæžããã»ã¹ãå²ããå®å šã§éé¢ãããããã«ã®ãããªãã®ã ãšèããŠãã ãããããã¯ã¢ã³ããŠã€ã«ã¹ããã°ã©ã ããã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãããŸããã代ããã«ã決æžååŒã®æèãç¹ç°çã«çè§£ãããæŽç·ŽãããJavaScriptããŒã¹ã®å¶åŸ¡ããã³ç£èŠããŒã«ã®ã»ããã§ãããã®äž»ãªäœ¿åœã¯ã決æžããŒãžã®å®å šæ§ãšãããã«å ¥åãããããŒã¿ã®æ©å¯æ§ã確ä¿ããããšã§ãã
çŸä»£ã®ã»ãã¥ãªãã£ãšã³ãžã³ã®æ žå¿çãªæ±
å ç¢ãªãšã³ãžã³ã¯ãéå±€çãªé²åŸ¡ãæäŸããããã«é£æºããŠæ©èœãããããã€ãã®åºæ¬ååã®äžã«æ§ç¯ãããŠããŸãã
- ãªã¢ã«ã¿ã€ã ã®è åšæ€åºïŒéå»ã®ã·ã°ããã£ã«äŸåããŸãããäžæ£ãªã¹ã¯ãªããã®èªã¿èŸŒã¿ãããŒãžæ§é ã®å€æŽè©Šè¡ãªã©ãçãããæ¯ãèããã©ã³ã¿ã€ã ç°å¢ã§ç©æ¥µçã«ç£èŠããŸãã
- ããŒã¿ãšã³ãŒãã®å®å šæ§ïŒãŠãŒã¶ãŒãèŠãŠæäœããæ±ºæžãã©ãŒã ãéçºè ã®æå³éãã§ãããéä¿¡ãããããŒã¿ããŠãŒã¶ãŒãå®éã«å ¥åãããã®ã§ãããæ¹ãããããŠããªãããšãä¿èšŒããŸãã
- ç°å¢ã®å ç¢åïŒå±éºãªæ©èœãå¶éããæ¢ç¥ã®è匱æ§ãšã¯ã¹ããã€ããç£èŠããããšã§ããã©ãŠã¶ãæ»æè ã«ãšã£ãŠããæµå¯Ÿçãªç°å¢ã«ããŸãã
- è¡ååæïŒäººéç¹æã®ã€ã³ã¿ã©ã¯ã·ã§ã³ãã¿ãŒã³ãåæããããšã§ãæ£åœãªäººéã®ãŠãŒã¶ãŒãšèªååãããããããã¹ã¯ãªããã«ããæ»æãåºå¥ããŸãã
決æžä¿è·ç®¡çã®äž»èŠã³ã³ããŒãã³ããšã¡ã«ããºã
çã«å¹æçãªã»ãã¥ãªãã£ãšã³ãžã³ã¯åäžã®ããŒã«ã§ã¯ãªããçµ±åãããæè¡ã®ã¹ã€ãŒãã§ããå æ¬çãªä¿è·ãæäŸããéèŠãªã³ã³ããŒãã³ããåè§£ããŠã¿ãŸãããã
1. ã³ãŒãã®å®å šæ§ãšã¹ã¯ãªããç£èŠ
ã»ãšãã©ã®ããã³ããšã³ãæ»æã¯æªæã®ããJavaScriptãä»ããŠé ä¿¡ããããããæ±ºæžããŒãžã§å®è¡ãããã¹ã¯ãªãããå¶åŸ¡ããããšã第äžã®é²åŸ¡ç·ãšãªããŸãã
- ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ãŒïŒCSPïŒïŒCSPã¯ãã¹ã¯ãªãããã¹ã¿ã€ã«ããã®ä»ã®ãªãœãŒã¹ãèªã¿èŸŒãããšãã§ãããœãŒã¹ããã¯ã€ããªã¹ãã«ç»é²ã§ãããã©ãŠã¶ã®ã»ãã¥ãªãã£æšæºã§ããäžå¯æ¬ ã§ãããæ±ºæã®åºãæ»æè ã¯éçãªCSPãåé¿ããæ¹æ³ãèŠã€ããããšããããŸãã
- ãµããªãœãŒã¹å®å šæ§ïŒSRIïŒïŒSRIã«ããããã©ãŠã¶ã¯ãã§ãããããµãŒãããŒãã£ã®ã¹ã¯ãªããïŒäŸïŒCDNããïŒãæ¹ãããããŠããªãããšãæ€èšŒã§ããŸããããã¯ãscriptã¿ã°ã«æå·åŠçããã·ã¥ã远å ããããšã§æ©èœããŸãããã§ããããããã¡ã€ã«ãããã·ã¥ãšäžèŽããªãå Žåããã©ãŠã¶ã¯ãã®å®è¡ãæåŠããŸãã
- åçã¹ã¯ãªããç£æ»ïŒãããããã»ãã¥ãªãã£ãšã³ãžã³ãåºæ¬ãè¶ ããç¹ã§ããããŒãžã®åæã®æ¿èªãããèªã¿èŸŒã¿ã®äžéšã§ã¯ãªãã£ãæ°ããã¹ã¯ãªãããã³ãŒãå®è¡ããªãããããŒãžã®ã©ã³ã¿ã€ã ç°å¢ãç©æ¥µçã«ç£èŠããŸããä»ã®äŸµå®³ãããã¹ã¯ãªããã«ãã£ãŠåçã«æ³šå ¥ãããã¹ã¯ãªãããæ€åºãããããã¯ããããšãã§ããŸããããã¯ãã²ã«ãŒãæ»æã§ããèŠãããæŠè¡ã§ãã
2. DOMæ¹ããæ€åº
ããã¥ã¡ã³ããªããžã§ã¯ãã¢ãã«ïŒDOMïŒã¯ãŠã§ãããŒãžã®æ§é ã§ããæ»æè ã¯ãã°ãã°ãããæäœããŠããŒã¿ãçã¿ãŸãã
ã»ãã¥ãªãã£ãšã³ãžã³ã¯ã決æžãã©ãŒã ã®DOMã®å®å šãªããŒã¹ã©ã€ã³ã確ç«ããŸãããããŠãäžæ£ãªå€æŽããªããç¶ç¶çã«ç£èŠããçšå¿æ·±ãçªç¬ãšããŠæ©èœããŸããäŸãã°ã以äžã®ãããªãã®ãæ€åºã»é²æ¢ã§ããŸãã
- ãã£ãŒã«ãã®è¿œå ïŒããŒã¿ããã£ããã£ããŠå€éšã«éä¿¡ããããã«ãã¹ã¯ãªããããã©ãŒã ã«æ°ããé ããã£ãŒã«ãã远å ããããšã
- 屿§ã®å€æŽïŒã¹ã¯ãªããããã©ãŒã ã®`action`屿§ã倿ŽããŠãæ£åœãªãµãŒããŒã«å ããŠæ»æè ã®ãµãŒããŒã«ãããŒã¿ãPOSTããããšã
- ã€ãã³ããªã¹ããŒã®ãã€ãžã£ãã¯ïŒæªæã®ããã¹ã¯ãªãããã¯ã¬ãžããã«ãŒããã£ãŒã«ãã«æ°ããã€ãã³ããªã¹ããŒïŒäŸïŒ`keyup`ã`blur`ã€ãã³ãïŒãã¢ã¿ããããŠãå ¥åäžã®ããŒã¿ãã¹ããã³ã°ããããšã
3. é«åºŠãªããŒã¿æå·åãšããŒã¯ã³å
å¯èœãªéãæ©ãæ®µéã§ããŒã¿ãä¿è·ããããšãæãéèŠã§ãããšã³ãžã³ã¯ããã©ãŠã¶å ã§çŽæ¥ãé«åºŠãªæå·æè¡ãéããŠãããä¿é²ããŸãã
- ã¯ã©ã€ã¢ã³ããµã€ãã»ãã£ãŒã«ãã¬ãã«æå·åïŒCS-FLEïŒïŒããã¯ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã«ãšã£ãŠç»æçãªãã®ã§ãããšã³ãžã³ã¯ããŠãŒã¶ãŒããã©ãŒã ãã£ãŒã«ãã«æ©å¯ããŒã¿ïŒPANãCVVãªã©ïŒãå ¥åããç¬éã«ããã©ãŒã ãéä¿¡ãããåã§ãããããã®ããŒã¿ãæå·åããŸããããã¯ãçã®æ©å¯ããŒã¿ãããŒãã£ã³ãã®ãµãŒããŒã«äžåè§Šããªãããšãæå³ããPCI DSSïŒPayment Card Industry Data Security StandardïŒã®ã¹ã³ãŒããå€§å¹ ã«åæžããŸããæå·åãããããŒã¿ã¯ãµãŒããŒã«éä¿¡ãããæ¿èªãããæ±ºæžåŠçæ¥è ã®ã¿ã埩å·ã§ããŸãã
- 決æžiFrameã®ä¿è·ïŒå€ãã®çŸä»£çãªæ±ºæžãããã€ããŒïŒStripeãAdyenãBraintreeãªã©ïŒã¯ããã¹ãããããã£ãŒã«ããiFrameã䜿çšããŠãããŒãã£ã³ãã®ãµã€ãããã«ãŒãããŒã¿ãéé¢ããŸããããã¯ã»ãã¥ãªãã£äžã®å€§ããªæ¹åã§ãããiFrameããã¹ãããŠãã芪ããŒãžã¯äŸç¶ãšããŠæ»æãããå¯èœæ§ããããŸããã»ãã¥ãªãã£ãšã³ãžã³ã¯ãã®èŠªããŒãžãä¿è·ããã¹ããã³ã°ã¹ã¯ãªãããiFrameã«å°éããåã«ãŠãŒã¶ãŒã®ããŒã¹ãããŒã¯ãèšé²ããããã¯ãªãã¯ãžã£ããã³ã°ã䜿çšããŠãŠãŒã¶ãŒãéšãããããã®ãé²ããŸãã
4. è¡åãã€ãªã¡ããªã¯ã¹ãšãããæ€åº
é«åºŠãªè©æ¬ºã¯ãã°ãã°èªååã䌎ããŸãã人éãšããããåºå¥ããããšã¯ãã¯ã¬ãã³ã·ã£ã«ã¹ã¿ããã£ã³ã°ãã«ãŒããã¹ãã£ã³ã°ããã®ä»ã®èªåæ»æã黿¢ããããã«äžå¯æ¬ ã§ãã
çŸä»£ã®ã»ãã¥ãªãã£ãšã³ãžã³ã¯ããã©ã€ãã·ãŒãå°éããæ¹æ³ã§ãŠãŒã¶ãŒã®è¡åãååçã«åæããããšã«ãããç ©ãããCAPTCHAãè¶ ããŠããŸãã
- ããŒã¹ãããŒã¯ãã€ããã¯ã¹ïŒãŠãŒã¶ãŒã®ã¿ã€ãã³ã°ã®ãªãºã ãé床ãå§åãåæããŸãã人éã®ã¿ã€ãã³ã°ãã¿ãŒã³ã¯ç¬ç¹ã§ãæ©æ¢°ãå®ç§ã«æš¡å£ããã®ã¯å°é£ã§ãã
- ããŠã¹ã®åããšã¿ããã€ãã³ãïŒããŠã¹ã®åããç»é¢ã¿ããã®çµè·¯ãé床ãå é床ã远跡ããŸãã人éã®åãã¯éåžžãæ²ç·çã§å¯å€ã§ããããããã®åãã¯ãã°ãã°çŽç·çã§ããã°ã©ã çã§ãã
- ããã€ã¹ãšãã©ãŠã¶ã®ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ïŒãŠãŒã¶ãŒã®ããã€ã¹ãšãã©ãŠã¶ã«é¢ããäžé£ã®éå人èå¥å±æ§ïŒç»é¢è§£å床ãã€ã³ã¹ããŒã«ãããŠãããã©ã³ãããã©ãŠã¶ã®ããŒãžã§ã³ãªã©ïŒãåéããŸããããã«ãããåäžã®ããã€ã¹ãç°ãªãã«ãŒãã§äœåãã®ååŒã詊ã¿ããªã©ãç°åžžãæ€åºããããã«äœ¿çšã§ããäžæã®èå¥åãäœæãããŸããããã¯ãGDPRãCCPAãªã©ã®ã°ããŒãã«ãªãã©ã€ãã·ãŒèŠå¶ã峿 Œã«éµå®ããŠå®è£ ããå¿ èŠããããŸãã
ããã³ããšã³ãã»ãã¥ãªãã£ãšã³ãžã³ã®å°å ¥ïŒæŠç¥çã¬ã€ã
ãã®ãããªåŒ·åãªããŒã«ãçµ±åããã«ã¯ãææ ®æ·±ãã¢ãããŒããå¿ èŠã§ããäŒæ¥ã¯éåžžã瀟å ãœãªã¥ãŒã·ã§ã³ãæ§ç¯ããããå°éãã³ããŒãšææºããããšããæ ¹æ¬çãªéžæã«çŽé¢ããŸãã
èªç€Ÿéçºãè³Œå ¥ãïŒéèŠãªæ±ºå®
- èªç€ŸéçºïŒæå€§éã®ã«ã¹ã¿ãã€ãºãå¯èœã§ããããã®éã¯èª²é¡ã«æºã¡ãŠããŸããé«åºŠã«å°éåãããã»ãã¥ãªãã£å°éå®¶ã®å°ä»»ããŒã ãå¿ èŠã§ãããéåžžã«æéãããããçµ¶ãéãªãé²åããè åšã«å¯Ÿå¿ããããã®ç¶ç¶çãªã¡ã³ããã³ã¹ãæ±ããããŸããæå€§æã®ã°ããŒãã«ãã¯ãããžãŒäŒæ¥ãé€ããŠãããã¯ãã°ãã°éçŸå®çã§ãªã¹ã¯ã®é«ã詊ã¿ã§ãã
- ãµãŒãããŒãã£ãœãªã¥ãŒã·ã§ã³ã®è³Œå ¥ïŒå°éãã³ããŒãšã®ææºãæãäžè¬çã§å¹æçãªæŠç¥ã§ãããããã®äŒæ¥ã¯ã¯ã©ã€ã¢ã³ããµã€ãã»ãã¥ãªãã£ãå°éãšããŠããŸãã圌ãã®ãœãªã¥ãŒã·ã§ã³ã¯å®æŠã§ãã¹ããããã»ãã¥ãªãã£ç ç©¶è ã«ãã£ãŠç¶ç¶çã«æŽæ°ãããç°¡åãªçµ±åã®ããã«èšèšãããŠããŸãã䟡å€å®çŸãŸã§ã®æéãå€§å¹ ã«ççž®ãããç¶ç¶çãªéçšè² æ ã¯æå°éã§ãã
ãã³ããŒãœãªã¥ãŒã·ã§ã³ã§æ¢ãã¹ãäž»èŠãªæ©èœ
ãµãŒãããŒãã£ã®ãšã³ãžã³ãè©äŸ¡ããéã«ã¯ã以äžãèæ ®ããŠãã ããã
- çµ±åã®å®¹æãïŒãœãªã¥ãŒã·ã§ã³ã¯ç°¡åã«å°å ¥ã§ããã¹ãã§ãçæ³çã«ã¯æ¢åã®ã³ãŒãããŒã¹ã®å€§èŠæš¡ãªèŠçŽããå¿ èŠãšããªããã·ã³ãã«ãªéåæJavaScriptã¹ãããããä»ããŠå°å ¥ã§ãããã®ãæãŸããã§ãã
- ããã©ãŒãã³ã¹ã®ãªãŒããŒãããïŒã»ãã¥ãªãã£ããŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ãç ç²ã«ããŠã¯ãªããŸããããšã³ãžã³ã¯è»œéã§ãããããŒãžã®èªã¿èŸŒã¿æéãå¿çæ§ã«ç¡èŠã§ããã»ã©ã®åœ±é¿ããäžããªãå¿ èŠããããŸãã
- å æ¬çãªããã·ã¥ããŒããšã¬ããŒãïŒæ€åºã»ãããã¯ãããŠããè åšãæç¢ºã«å¯èŠåããå¿ èŠããããŸããåªãããœãªã¥ãŒã·ã§ã³ã¯ãå®çšçãªæŽå¯ãšè©³çްãªã¬ããŒããæäŸããŸãã
- å¹ åºãäºææ§ïŒäžè¬çãªããã³ããšã³ããã¬ãŒã ã¯ãŒã¯ïŒReact, Angular, Vue.jsïŒãäž»èŠãªæ±ºæžãµãŒãã¹ãããã€ããŒïŒPSPïŒãå«ããæ¢åã®æè¡ã¹ã¿ãã¯ãšã·ãŒã ã¬ã¹ã«é£æºããå¿ èŠããããŸãã
- ã°ããŒãã«ãªã³ã³ãã©ã€ã¢ã³ã¹ïŒãã³ããŒã¯ããŒã¿ãã©ã€ãã·ãŒãžã®åŒ·ãã³ãããã¡ã³ãã瀺ããGDPRãCCPAãªã©ã®åœéçãªèŠå¶ã«æºæ ããŠããå¿ èŠããããŸãã
ã°ããŒãã«ãªåœ±é¿ïŒã»ãã¥ãªãã£ãè¶ ããŠå ·äœçãªããžãã¹äŸ¡å€ãž
ããã³ããšã³ã決æžã»ãã¥ãªãã£ãšã³ãžã³ã¯åãªãã³ã¹ãã»ã³ã¿ãŒã§ã¯ãããŸããã倧ããªãªã¿ãŒã³ãããããæŠç¥çæè³ã§ãã
顧客ã®ä¿¡é Œãšã³ã³ããŒãžã§ã³çã®åäž
çµ¶ãéãªãããŒã¿äŸµå®³ã®ãããã©ã€ã³ãæµããäžçã§ã¯ã顧客ã¯ãããŸã§ä»¥äžã«ã»ãã¥ãªãã£ãæèããŠããŸããã·ãŒã ã¬ã¹ã§ç®ã«èŠããŠå®å šãªãã§ãã¯ã¢ãŠãããã»ã¹ã¯ä¿¡é Œãç¯ããŸããç Žå£çãªè©æ¬ºãé²ããã¹ã ãŒãºãªãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ã確ä¿ããããšã§ãã»ãã¥ãªãã£ãšã³ãžã³ã¯ã«ãŒãæŸæ£çã®äœäžãšã³ã³ããŒãžã§ã³çã®åäžã«çŽæ¥è²¢ç®ã§ããŸãã
PCI DSSæºæ ã®ã¹ã³ãŒããšã³ã¹ãã®åæž
ã«ãŒãããŒã¿ãæ±ãããããããžãã¹ã«ãšã£ãŠãPCI DSSæºæ ã¯äž»èŠãªéçšäžããã³è²¡åäžã®åãçµã¿ã§ããã¯ã©ã€ã¢ã³ããµã€ãã»ãã£ãŒã«ãã¬ãã«æå·åãå®è£ ããããšã«ãããã»ãã¥ãªãã£ãšã³ãžã³ã¯æ©å¯æ§ã®é«ãã«ãŒãäŒå¡ããŒã¿ããµãŒããŒãééããããšããé²ããPCI DSSç£æ»ã®ã¹ã³ãŒããè€éããã³ã¹ããåçã«åæžã§ããŸãã
財åçããã³è©å€äžã®æå®³ã®é²æ¢
æ å ±æŒæŽ©ã®ã³ã¹ãã¯é©ç°çã§ããããã«ã¯èŠå¶äžã®çœ°éã蚎èšè²»çšã顧客ãžã®è£åãè©æ¬ºã«ããæå€±ãå«ãŸããŸããããããæãé倧ãªã³ã¹ãã¯ããã°ãã°ãã©ã³ãã®è©å€ãžã®é·æçãªæå®³ã§ããäžåºŠã®å€§ããªã¹ããã³ã°äºä»¶ããé·å¹ŽãããŠç¯ãäžãã顧客ã®ä¿¡é Œã䟵é£ããå¯èœæ§ããããŸããç©æ¥µçãªããã³ããšã³ãä¿è·ã¯ããã®å£æ» çãªãªã¹ã¯ã«å¯Ÿããæã广çãªä¿éºã§ãã
çµè«ïŒããžã¿ã«ã³ããŒã¹ã®èŠãããå®è·è
ããžã¿ã«ã®åºå ã«ã¯æœé ãããã¢ããçªãéããããšããããŸããããã®å¢çã¯ããã¹ãŠã®èšªåè ã®ãã©ãŠã¶ã§ãããããã¯åçã§ã倿§ã§ãæ¬è³ªçã«å®å šã§ã¯ãªãç°å¢ã§ãããã®æ°ããã©ã³ãã¹ã±ãŒãã§ããã¯ãšã³ãã®é²åŸ¡ã®ã¿ã«é Œãããšã¯ãèŠå¡ãç¯ããªããæ£é¢çé¢ã倧ããéãæŸããŠãããããªãã®ã§ãã
ããã³ããšã³ã決æžãªã¯ãšã¹ãã»ãã¥ãªãã£ãšã³ãžã³ã¯ãçŸä»£ã®éçªã§ããããã¯æåç·ã§éãã«å¹ççã«åããã«ã¹ã¿ããŒãžã£ãŒããŒã«ãããæãéèŠãªç¬éãä¿è·ããŸãããã§ãã¯ã¢ãŠãããã»ã¹ã®å®å šæ§ã確ä¿ããå ¥åæç¹ã§é¡§å®¢ããŒã¿ãä¿è·ããæ¬ç©ã®ãŠãŒã¶ãŒãšæªæã®ããããããåºå¥ããããšã§ãããã¯åã«è©æ¬ºã黿¢ãã以äžã®ããšãè¡ããŸããä¿¡é Œãç¯ããã³ã³ããŒãžã§ã³ãé«ãããŸããŸãæµå¯Ÿçã«ãªãããžã¿ã«ã¯ãŒã«ãã§ããªãã®ãªã³ã©ã€ã³ããžãã¹ã®æªæ¥ã確ä¿ããŸãããã¹ãŠã®çµç¹ããããã³ããšã³ã決æžä¿è·ãå¿ èŠãã©ãããåãã®ã§ã¯ãªããããã«è¿ éã«ãããå°å ¥ã§ããããåãã¹ãæãæ¥ãŠããŸãã