ãã®ã€ãã³ãã®èæ¯ã«ç §ãããŠãPCI DSSãšã¯äœããåºæºãžã®æºæ ã確èªããåºæºãããã³ç¬èªã®èšŒææžããªããŠããªã³ã©ã€ã³ã¹ãã¢ããŠãŒã¶ãŒã®è²¡åããŒã¿ã®å®å šæ§ã確ä¿ããæ¹æ³ã«ã€ããŠè©³ãã説æããããšæããŸãã
Googleã§PCI DSSã®ç¥èªãæ¡ç¹ããããHabréã§æ€çŽ¢ããããããšããã®æšæºã説æããèšäºãããªããããŸãã ããããã¹ãŠã®è³æã®å¯Ÿè±¡èªè ã¯ãé»ååååŒã«äœããã®åœ¢ã§é¢ä¿ããŠãã人ã ã§ããããšãããã«æããã«ãªããŸãã ãããã¯äž»ã«æ¯æãã¢ã°ãªã²ãŒã¿ãŒãšåŠçã»ã³ã¿ãŒã§ããããªã³ã©ã€ã³ã¹ãã¢ã®éçºè ã®ã¿ã§ãã
ã©ã®ãããªçš®é¡ã®é»ååååŒããäœããã®æ¹æ³ã§ã補åãè³Œå ¥ãããè³Œå ¥è ããã®è£œåã®ä»£éãæ¯æããªããã°ãªããªããšããäºå®ã«åºã¥ããŠããŸãã ïŒäŒè°ã§å® é 䟿æ¥è ã«ãéãäžããããã«ïŒå€é¢šãªæ¹æ³ã§æ¯æãèœåããã·ã¢ã§æã人æ°ããããšããäºå®ã«ãããããããè²·ãæã圌ã®æ¯æãã«ãŒãã䜿çšããããšã奜ãå¯èœæ§ãé«ãã§ãã ããã§ãã¹ãã¢ã®éçºè ã¯ã財åã«ãé¢é£ä»ããããŠãããŠãŒã¶ãŒã®å人ããŒã¿ãªã©ã®ããªã±ãŒããªåé¡ã«å¯ŸåŠããå¿ èŠããããŸãã åºèã®é¡§å®¢ã®èª°ãããããå ¬éããããšã¯æããªãã®ã§ãããã§ããªãã¯ææ ®æ·±ãç¹°ãè¿ããã¹ãããããœãªã¥ãŒã·ã§ã³ã«é Œããªããã°ãªããŸããã
ãªã³ã©ã€ã³ã¹ãã¢å šäœããŒãããäœæããããšã¯ãç°¡åã«èšãã°ãé£ããäœæ¥ã§ãã ãããã£ãŠãåžå Žã«ã¯éçºè ãæ¯æŽãããã¬ãŒã ã¯ãŒã¯ãããªããããŸãïŒããšãã°ãMagentoãèããããšããã人ã¯èª°ã§ãïŒã æãéèŠãªãã®ã®1ã€ã§ããæ¯æããåãå ¥ããã¿ã¹ã¯ã¯ããéã«é¢é£ããŠããããããã¹ãŠã®eã³ããŒã¹ãœãªã¥ãŒã·ã§ã³ãå«ãŸããŸãã ããã«å¯ŸåŠããéçºè ã¯ããããããªãåçŽãªäžé£ã®æé ã§ããããšãç¥ã£ãŠããŸããããã¯ããXYZæ¯æãã²ãŒããŠã§ã€ã®ã©ã€ãã©ãªã³ãŒããããŠã³ããŒããããããæ§æãããããã«èŠããŸãïŒéåžžã¯ãã²ãŒããŠã§ã€ã圌ã¯åºãæ±ããŸãïŒããå°ãã ãä»äžããŸããããçç£ã«ã¢ããããŒããããã
ååãšããŠãããã¯é倧ãªåé¡ãåŒãèµ·ãããŸããã ãã ããã¹ãã¢ã®ãŠãŒã¶ãŒãéžæããæ¯æãã²ãŒããŠã§ã€ã®æ¯æãããŒãžã«ç§»åããæ¯æãã«ãŒãã®è©³çŽ°ãå ¥åããŠãæ¯æãããã¿ã³ãã¯ãªãã¯ããåŸãããã»ã¹ã«ä»å ¥ããããšã¯ã§ããŸãããæè¬ïŒãã¹ãŠãããŸããã£ãå ŽåïŒãŸãã¯è¬çœªïŒäœããããŸããããªãã£ãå ŽåïŒã
ããšãã°ãè³æ Œã®ãããŠãŒã¶ãŒã¯ãhttpsãhttpãããåªããŠããããšãç¥ã£ãŠãããå€ãã®ãã©ãŠã¶ãŒãã¢ãã¬ã¹ããŒã«ãµã€ã蚌ææžæ å ±ã衚瀺ããããšã確èªããŸãã ãã ããæ¯æãã²ãŒããŠã§ã€ãçºè¡éè¡ïŒã«ãŒããçºè¡ããéè¡ïŒããã³ååŸéè¡ïŒæ¯æããåãåãå¿ èŠã®ããéè¡ïŒãšã®ãå éšããã©ã³ã¶ã¯ã·ã§ã³ãéå§ãããšãå®å šã«è«ççãªçåãçããå¯èœæ§ããããŸãã çµå±ã®ãšãããhttpsãããã³ã«ãä»ããããŒã¿ã®è»¢éã¯ãŸã ã»ãã¥ãªãã£ã®ä¿èšŒã§ã¯ãªããæ å ±ã®ä¿è·ãä¿èšŒããæ°çŸã®ãã©ã¡ãŒã¿ãŒã®1ã€ã«ãããŸããã
ãã¶ãããã®ã²ãŒããŠã§ã€ã®äººãã¡ã¯èªåã§httpsãèšå®ãã蚌ææžãè³Œå ¥ãããŠã§ããµã€ãã«ãã¹ãŠãéåžžã«ããããã¹ãŠãéåžžã«ä¿è·ãããŠããããšã倧æåã§æžãããããããŸããã ãããããããæ€èšŒããå¯äžã®çã«ä¿¡é Œã§ããæ¹æ³ã¯ãæ¯æãã²ãŒããŠã§ã€ã®å éšã³ãŒãã®ã»ãã¥ãªãã£ã蚌æããããã€ãã®æé ãå®è¡ããããšã§ãã ãããŠããã¡ããããã®ãããªãã¹ãã«åæ Œããããšã¯ããµã€ãã«å°ãçŸããHTMLãæžããããé£ããã§ããã-ã100ïŒ ã»ãã¥ãªãã£ä¿èšŒãã
ãã®ãããªæé ã説æãããããé»ååååŒæ¥çã®æšæºã§ããçç±ãç解ããããšããŸãã ããã¯ãã¹ãŠPCI DSSã®ç¥èªã®äžã«é ããŠãããæ¯æãã²ãŒããŠã§ã€ã«ãã®èšŒææžãååšããããšã§ãæ¯æãã«ãŒãã®ããŒã¿ïŒã€ãŸããæ¯æ人ã®ãéïŒãåé¡ãªãå®å ã«å±ãããšãæå³ããŸãã
PCI DSSãšã¯äœã§ããïŒ
PCI DSSïŒãã€ã¡ã³ãã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£æšæºïŒã¯ããã€ã¡ã³ãã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£æšæºã§ãã èšãæããã°ãããã¯ã«ãŒãçªå·ãæå¹æéãCVVã³ãŒããªã©ãäœããã®åœ¢ã§ç®¡çããå Žåã«ãµãŒãã¹ãæºããã¹ãåºæºã®ãªã¹ããåããããã¥ã¡ã³ãã§ãã
å€ãã®ãã€ã¡ã³ãã«ãŒããã«ãŠã³ãã§ããŸãïŒèª°ããVisaãšMasterCardãç¥ã£ãŠããŸãïŒãããã¯æ¥çæšæºã§ããããããã¹ãŠã®äŒæ¥ãå®å šãšèŠãªããã®ã«ã€ããŠåæããããšã¯æçã§ãã ãããè¡ãããã«ãPCI SSCïŒPayment Card Industry Security Standards CouncilïŒããããŸããããã¯ã5ã€ã®æ倧ã®æ±ºæžã·ã¹ãã ã«ãã£ãŠåœ¢æããããPayment Card Industry Security Standardsã®è©è°äŒã§ãã ãå®å šãªéã³ãã®ã«ãŒã«ãäœæããã®ã¯åœŒã§ãããåæãããŠããPCI-DSSèªå®ã©ãã«ãåãåãããäŒæ¥ã¯åŸããªããã°ãªããªãã®ã¯åœŒã®ã«ãŒã«ã§ãã æ¯å¹Žèªå®ã«åæ Œããå¿ èŠããããŸãã
äœãæ£ç¢ºã«ãã§ãã¯ãããŠããŸããïŒ
å®éãæ€èšŒã®ãã¹ãŠã®åºæºãèšè¿°ããããšã¯å°é£ã§ã-288ãããŸããå€ãã®è€éãªæè¡çåé¡ããã§ãã¯ããå¿ èŠããããããéåžžã«é·ãæé ããããŸãã 12ã®ã°ã«ãŒãã«åããããåºæºã®å®å šãªãªã¹ãã¯æ¬¡ã®ãšããã§ãã
- ã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯ã®ä¿è·ã
- æ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ããŒãã³ãã®æ§æã
- ä¿åãããã«ãŒãäŒå¡ããŒã¿ã®ä¿è·ã
- ã«ãŒãææè ã®éä¿¡ããŒã¿ã®ä¿è·ã
- æ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãŠã€ã«ã¹å¯Ÿçä¿è·ã
- æ å ±ã·ã¹ãã ã®éçºãšãµããŒãã
- ã«ãŒãäŒå¡ããŒã¿ãžã®ã¢ã¯ã»ã¹ã管çããŸãã
- èªèšŒã¡ã«ããºã
- æ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç©ççä¿è·ã
- ã€ãã³ããšã¢ã¯ã·ã§ã³ã®ãã°ã
- æ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ãç£èŠããŸãã
- æ å ±ã»ãã¥ãªãã£ç®¡çã
ããã§ã¯ããœãããŠã§ã¢éšåãšãç©çã³ã³ããŒãã³ããã«ã€ããŠè©±ããŠããããšãã¯ã£ãããšããããŸããã€ãŸãããã¹ãŠããã§ãã¯ãããŠããŸãã ããã«ããæ€èšŒããšããèšèã¯ãæ€èšŒãããŠããäŒç€Ÿã®ãªãã£ã¹ã§ãã®æ€èšŒãå®è¡ãã人ã®æåéãã®ååšãæå³ããŸãã QSAïŒèªå®ã»ãã¥ãªãã£è©äŸ¡è -ãã®æ³ä»€ã¯PCI SSCã«ãã£ãŠç¢ºèªæžã¿ïŒã®ã¹ããŒã¿ã¹ãæã€èªå®ç£æ»äººã¯ãæ¯æãã²ãŒããŠã§ã€ã®åŸæ¥å¡ãšè©±ãåãïŒãã®ããã®ç¹å¥ãªã€ã³ã¿ãã¥ãŒæé ããããŸãïŒãã·ã¹ãã ã³ã³ããŒãã³ãã®èšå®ã調ã¹ãã¹ã¯ãªãŒã³ã·ã§ãããæ®ãããä»çµã¿ãã確èªããæš©å©ããããŸãã PayOnlineã¯ãè¿å¹ŽDeiteriyã«ãã£ãŠç£æ»ãããŠããŸãã 圌女ã®çµè«ã¯ãåœé決æžã·ã¹ãã VisaãMasterCardãMIRãAmerican ExpressãDiscoverãJCBã§èªããããŠããŸãã
ã©ã€ãã©ãªèªäœã®ããã°ã©ã ã³ãŒãã¯éžæçã«ãã§ãã¯ãããæ¯æãã«ãŒãããŒã¿ãçŽæ¥åŠçããã³ã¢ã«æã泚æãæãããŸãããã³ãŒãã®è匱æ§ãæ€çŽ¢ããŠæé€ããããã®åºæ¬èŠä»¶ã説æããå€éšã»ãã¥ãªãã£æšæºOWASPãžã®æºæ ã«æ³šæãæãããŸãã ãŸããéçºããžãã¹ããã»ã¹ã«ã¯ã³ãŒãã¬ãã¥ãŒãªã³ã¯ããããå®éã«ã¯ãã³ãŒãã®äœæã«é¢äžããŠããªãå¥ã®éçºè ã«ããè¿œå æ€èšŒãè¡ãããŸãã
ãµãŒãã¹ãããã€ããŒéãããªãã¡åŠçã»ã³ã¿ãŒãšããŒã¿ã»ã³ã¿ãŒéãããã³è²·åéè¡éã®PCI DSSèŠä»¶ã®ãã¬ãŒã ã¯ãŒã¯å ã®ãã¹ãŠã®é¢ä¿ãšè²¬ä»»ã¯ãããããè² åµãããªãã¯ã¹ã«èšé²ãããŸãã PCI DSSèŠæ Œã®ããŒãžã§ã³3.1以éããµãŒãã¹ãããã€ããŒéã®çœ²åæžã¿è²¬ä»»ãããªãã¯ã¹ã®ååšã¯å¿ é èŠä»¶ã«ãªã£ãŠããŸãã ãã¡ãããããŒã¿ã»ã³ã¿ãŒã«ã¯ãåŠçã»ã³ã¿ãŒãæ¥åã§äœ¿çšããã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ããŒãã³ãïŒä»®æ³åããµãŒãã¹ãç©çæ©åšãªã©ïŒã®ææ°ã®PCI DSSã³ã³ãã©ã€ã¢ã³ã¹èšŒææžãå¿ èŠã§ãã
ãµãŒããŒèªäœãããã³ä»ã®ãã¹ãŠã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ããŒãã³ãïŒãããã¯ãŒã¯æ©åšãªã©ïŒããå¿ é ã®æ€èšŒã®å¯Ÿè±¡ãšãªããŸãã ããã§ã®äž»ãªèŠä»¶ã¯ãPCI-DSSã®ã¹ããŒã¿ã¹ã®é¢é£æ§ã§ããããã¯ããœãããŠã§ã¢å€æŽã®é »åºŠãããŒããŠã§ã¢æ§æãä»®æ³ãã·ã³ãããã³åæ§ã«éèŠãªæªåé«ãHeartBleedãªã©ã®æ¢ç¥ã®è匱æ§ã«çŽæ¥äŸåããŸãã ã€ã³ãã©ã¹ãã©ã¯ãã£ç®¡çè ã¯ãã·ã¹ãã ã®å éš/å€éšã®è匱æ§ãç£æ»ããã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ããŒãã³ããPCI DSSæšæºã«æºæ ãããå¿ èŠããããŸãã
ã»ãã¥ãªãã£ç£æ»ã¯2åå®è¡ãããŸãã åããŠãæ¢ç¥ã®è匱æ§ã®èªåã¹ãã£ããŒã䜿çšãããŸããããã¯ãèªèšŒãããçµç¹ASVïŒæ¿èªæžã¿ã¹ãã£ã³ãã³ããŒïŒã«ãã£ãŠæäŸãããŸãã ãã®ãã¹ãã«åæ Œããå Žåãã·ã¹ãã ã¯ãå ¬åŒã®æèŠã§ãæåã§èšãããã«ãå°é家ã«ãã£ãŠããäžåºŠå®å šæ§ããã§ãã¯ãããŸãã
èµ·ããããå°é£
ããã§ç§ã¯å人çãªçµéšããäŸãæããããšæããŸãã ææ°ã®PCI-DSSèªèšŒäžã«ãåœç€Ÿã®å°é家ãç¹å¥ãªç£èŠãµãŒãã¹ãçµç¹ããããŒã¿ã»ã³ã¿ãŒãšéè¡éã®ååŒãç¶ç¶çã«è¡ãããããã«ããŸããã æœåšçãªåé¡ã®åå ã¯ãäžéšã®éè¡ãTLS 1.0蚌ææžãäºåŸããŒãžã§ã³1.2ã«æŽæ°ããããšå ±åããããšã§ãã å€ã蚌ææžãææããŠããéè¡ãšéä¿¡ããããšããŠããäžæ¹ã§ããã§ã«æŽæ°ãããŠããå¯èœæ§ããããŸãã çŸåšãåå¥ã®ãã©ã³ã¶ã¯ã·ã§ã³ç¶ç¶æ§ç£èŠãµãŒãã¹ãæäŸãããŠããããããã®åé¡ã¯çºçããªããªããŸããã
äžè¬ã«ãæ€èšŒã®ä»çµã¿ãšãã€ã³ãã©ã¹ãã©ã¯ãã£ãèŠä»¶ã«åãããæ¹æ³ã®äŸãããã€ã瀺ãããšãã§ããŸãã ãåãã®ããã«ãPCI-DSSã«ããã°ãæ¯æãã·ã¹ãã ã¯ãããšãã°CVVãŸãã¯PINã³ãŒãïŒåŸè ã¯éåžžãã¹ãŒããŒããŒã±ããã®POS端æ«ããæ¥ãŸãïŒãå«ããããããã¯ãªãã£ã«ã«èªèšŒããŒã¿ïŒCADïŒãä¿åããã¹ãã§ã¯ãããŸããã 次ã®ããã«å®è£ ãããŸãã
ãã©ã³ã¶ã¯ã·ã§ã³ãåŠçã»ã³ã¿ãŒããç¹å¥ãªã¹ããŒã¿ã¹ãåä¿¡ãããšãå®äºããããšã瀺ããŸãïŒæåãããã©ããã«é¢ä¿ãªãïŒã2ã€ã®åé¡ã解決ããç¹å¥ãªããã°ã©ã ã³ãŒããã·ã¹ãã ã§éå§ãããŸãã äœããã®çç±ã§ãã©ã³ã¶ã¯ã·ã§ã³äžã«ããŒã¿ããã£ã¹ã¯ã«æžã蟌ãŸããå Žåããã®ã¬ã³ãŒããåé€ããç¹å¥ãªæäœãæé«ã®åªå 床ãååŸããç¹å¥ãªã¯ãŒã«ãŒã«ãã£ãŠå®è¡ãããŸãã ãã£ã¹ã¯ãžã®ã¢ã¯ã»ã¹ããªãã£ãå Žåã¯ãããã«ç°¡åã§ãããã©ã³ã¶ã¯ã·ã§ã³ããã»ã¹ã¯ãµãŒããŒã®ã¡ã¢ãªããåé€ããããããCADã®åºå®ã¯è¡ãããŸããã ä¿åã§ããããŒã¿ã¯ãPANïŒãã©ã€ããªã¢ã«ãŠã³ãçªå·ïŒã«ãŒãçªå·ã®ã¿ã§ãããæä»çã«æå·åãããŸãã
å¥ã®äŸã¯ããªã³ã©ã€ã³ã¹ãã¢ã§ååãè³Œå ¥ãããŠãŒã¶ãŒã®1人ã«çŽæ¥é¢ä¿ããŠããŸãïŒå®éããã®ãããªã¹ããŒãªãŒã¯å€æ°ãããŸãããããã¯ãŸãã«ææ°ã®ãã®ã§ãïŒã äœããééã£ããåŸã圌ã¯ååã«è©³çŽ°ãªãšã©ãŒã¡ãã»ãŒãžãèªã¿ãŸããã§ããããåã«äž¡åŽã§æ¯æãã«ãŒãã®åçãæ®ããŸããïŒãããããæåŸã®3æ¡ãå ¥åããå¿ èŠãããããšãæ¯æãã®åœ¢ã§èª¬æããããã§ãïŒèé¢ã®ç£æ°ã¹ããªããã®åŸïŒããµããŒãããŒã ã«éä¿¡ããŸãã ãã€ã€ãŒã«ãããšãããã¯åœŒã®æ¯æãã®ã¹ããŒã¿ã¹ã調ã¹ãã®ã«åœ¹ç«ã€ã¯ãã ã£ã-ããéãåŒãåºãããããã©ããã PCI-DSSèŠæ Œã§ã¯ããã®ãããªå¥œå¥å¿ã匷ããšåæã«æ²ããã±ãŒã¹ãèŠå®ãããŠãããšèšããããåŸãŸããã
ãŠãŒã¶ãŒã®ããŒã¿ã䟵害ãããå Žåãæ¯æãã·ã¹ãã ã¯ãŠãŒã¶ãŒãšãç §ãããããã«ãŒããçºè¡ããçºè¡éè¡ã«éç¥ãã矩åããããŸãã ããã«ãã¡ãŒã«ãµãŒããŒã ãã§ãªãããµããŒããµãŒãã¹ãªãã¬ãŒã¿ãŒã®ã¯ã©ã€ã¢ã³ãã¡ãŒã«ããã°ã©ã ããæ·»ä»ãã¡ã€ã«ä»ãã®æåãåé€ããå¿ èŠããããŸããã ããã¯ãã¹ãŠãæ¯æãã«ãŒãæ¥çã®ã»ãã¥ãªãã£ã確ä¿ãããšããé»éã®ã«ãŒã«ã«åŸãããã«è¡ãããŸãããããã®æ å ±ãå¿ èŠãªãå Žåã¯ãä¿åããªãã§ãã ãããã
PayOnlineãªã³ã©ã€ã³ã¹ãã¢ã®çµ±å
åè¿°ã®ããã«ãç¹å®ã®ãªã³ã©ã€ã³ã¹ãã¢ãæ¯æãã·ã¹ãã ã«çµ±åããã¿ã¹ã¯ã¯ãé£ãããšã¯èšããŸããã ã€ã³ã¿ãŒãããã§ã¯ãå€ãã®ã²ãŒããŠã§ã€ã®å€ãã®äŸãèŠã€ããããšãã§ããŸãã éåžžããµãŒããŒã«ç¹å¥ã«äœæãããã©ã€ãã©ãªãã€ã³ã¹ããŒã«ãïŒããŸããŸãªãã©ãããã©ãŒã çšã«å€æ°ãããŸãïŒããŠãŒã¶ãŒãã©ãŒã æ å ±ãåéããŠæ¯æãã²ãŒããŠã§ã€ã«éä¿¡ããã¯ã©ã€ã¢ã³ãã³ãŒãã®çš®é¡ãèšè¿°ããŸãã ç§ã泚æãããå¯äžã®ãã€ã³ãã¯ãæ¯æããã©ãŒã èªäœã®å Žæã§ããã¹ãã§ã-ããã¯ãªã³ã©ã€ã³ã¹ãã¢ã®åŽã«ããã®ã§ãããããããã¯PayOnlineã®åŽã§åäœããã®ã§ããããã å€ãã®æ±ºå®ãããªãã®ãŠã§ããµã€ãã§çŽæ¥æ¯æããåãå ¥ããããšãå¯èœã«ãããããããªããšããäºå®ã«ãããããããå人ã圌èªèº«ã®PCI-DSS蚌ææžãæã£ãŠããªãå Žåãæ¯æããæ¯æãã²ãŒããŠã§ã€ã®åŽã§è¡ãããããã«ãã¹ãŠãæé ããå¿ èŠããããŸãã æ£åœåã®çç±ã¯1ã€ã ãã§ããããã¯ããŠãŒã¶ãŒã®è²¡åããŒã¿ã®ã»ãã¥ãªãã£ã§ãã ãã®å Žåãæ¯æããã©ãŒã ã¯äŒç€Ÿã«åãããŠã«ã¹ã¿ãã€ãºã§ããããããšã³ããŠãŒã¶ãŒã®æåŠã¯çºçããŸããã
Windows Phoneãå«ããã¹ã¯ãããããã³ã¢ãã€ã«ãœãªã¥ãŒã·ã§ã³ã®æ¯æããæŽçããããã®ã©ã€ãã©ãªããããŸãïŒãã ãããŠãŒã¶ãŒéã®äººæ°ã®ç¹ã§ãã®ãã©ãããã©ãŒã ã®äœçœ®ã¯AndroidãŸãã¯iOSã®äœçœ®ãããã¯ããã«åŒ±ãã§ãïŒã PHPã®ã©ã€ãã©ãªã«ã€ããŠã説æããŸãããããã¯å®éã«ã¯æé»ã®ãã¡ã«æ瀺ãããŠããŸãã .NETãœãªã¥ãŒã·ã§ã³çšã®SDKããããŸãã 人ã ã¯ãã°ãã°ãAndroidã«åŸæ¥ã®ã¢ãããŒãïŒJavaã©ã€ãã©ãªïŒãéžæãããªãã£ãã®ã«ãNode.jsã䜿çšãããçç±ãå°ããŸãã ãã®æ±ºå®ã¯å°ãåã«è¡ãããŸããããã®ãããªã³ãŒãã®çµ±åã¯ãJavaã§æžããããã®ããããããã«ç°¡åã§ãããPCI PA-DSSèŠæ Œã®èŠä»¶ãæºãããŠããŸãã å°æ¥ã®çµ±åã«ã€ããŠã¯ãWebViewãä»ããŠã¢ããªã±ãŒã·ã§ã³ã«çµ±åããããã¹ãŠã®PCI PA-DSSèŠä»¶ãæºãããã€ãã£ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã§æé©ã«æ©èœããé©å¿æ¯æããã©ãŒã ãçšæãããŠããŸãã
ãªã³ã©ã€ã³ã¹ãã¢ãååŸãããã®
PayOnlineé»å決æžã·ã¹ãã ã®äž»ãªå©ç¹ã®äžã§ãæåããæ¯æããžã®å€æãå¢ããããšãç®çãšããåœç€Ÿã®æè¡çèœåãç¹ã«åŒ·èª¿ããããšãã§ããŸãã ãŸã第äžã«ãããã¯3-D Secureã䜿çšããããªã±ãŒããªäœæ¥ã§ãããäžæ£ååŒã«å¯Ÿããé«ãã¬ãã«ã®ä¿è·ãç¶æãããšåæã«æ¯æãã®å€æãå¢ããããšãã§ããŸãã
æè¡ã®é²æ©ã«äŒŽã幎ã å€åããæ¯æè ã®è¡åã泚ææ·±ãç 究ããŠããŸãã ããŒã¿ã®å ¥åãšæ¯æãã®éã«ãæ¯æãããŒãžã§ã®äººã®ã³ã³ããŒãžã§ã³ãšè¡åã枬å®ã§ãããããæè¡çã«ã¯ãã客æ§ã段éçã«ã客æ§ã®é²è·¯ã远跡ãã代ããã«èªå·±çŽ¹ä»ããçµ±èšã«åºã¥ããŠå¯èœãªéããŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ãç°¡çŽ åã§ããŸãã ãã ããæ¯æããè¡ããšãã«ãäœããã®çç±ã§è²·ãæãæ¯æããè¡ããªãå Žåãã¹ãã¢ã¯åŠçã»ã³ã¿ãŒããæåŠã®æ£ç¢ºãªçç±ãåãåããã«ã¹ã¿ãã€ãºããã圢åŒã§æåŠã®çç±ãæ¯æãè ã«ãããŒããã£ã¹ãããŸãã ãããã£ãŠãã¯ã©ã€ã¢ã³ãã¯ãæ¯æãã倱æããçç±ãšã補åãŸãã¯ãµãŒãã¹ãè³Œå ¥ããããã«äœãããå¿ èŠãããããããã«ç解ããŸãã
ãã®æ©äŒã«èå³ãããå Žåã¯ãã«é£çµ¡ããŠãã ãã ãåŒç€Ÿã®ã¹ãã·ã£ãªã¹ããè¿œå æ å ±ãæäŸããå¿ èŠã«å¿ããŠãPCI DSS 3.1æšæºã®èŠä»¶ãæºããã»ãã¥ã¢ã²ãŒããŠã§ã€äžã®Webãµã€ãããã³ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã§æ¯æãã®åè«Ÿãèšå®ããŸãã