PEN / PEN-05
モバイルアプリケーションセキュリティテスト
AndroidまたはiOSアプリケーション、およびその通信に対する評価。これにより、露出しているデータや不十分なセキュリティコントロールを特定します。.

役立つとき
的確な回答
定義されたニーズに対して.
Mobile software vendor or CTO; store release, field application or personal-data processing.
適用範囲と成果物
このエンゲージメントの対象範囲.
スコープ
- Local storage and secrets
- authentication and communications
- permissions, release settings and interaction with in-scope APIs
成果物
- Platform-specific report
- 証拠を最小限に抑える
- separate application-side and server-side remediation
検収証拠
Findings reference a specific version and test scenario; server-side dependencies are identified.
配達
仕事の進め方.
アプローチ
承認と交戦規定を得て、アカウントとバックアップを準備し、管理されたテストを実施し、デリーフ(報告・検討)、クリーンアップを行い、再テストを手配する。.
前提条件と責任
顧客:書面による承認、資産の所有権、第三者の許可、接触の停止、およびスコープ。プロバイダー:限定されたテスト、最小限の証拠、および重大な発見の通知。.
スコープ要因
アプリケーション、ロール、API、ネットワーク、ビジネスの複雑性、提供されるアクセス、テストの深度、承認された実施時間。ブラック・グレー・ホワイトボックスおよび再テストは工数に影響し、価格はスコーピング後に決定します。.
確認のための質問
Which platforms and versions? Is a test build available? Is the API included in the engagement?
重要な境界線
Device protections do not replace API controls; specify devices, versions and permitted testing techniques.
明示的な許可なしに、サービス妨害、破壊、実際の情報流出、またはソーシャルエンジニアリングを行ってはならない。第三者は、顧客の依頼のみに基づいてテストされるわけではない。テストされていない範囲は未評価のままとなる。.
実際には
具体例.
これらの例は、想定される関与と目標とする成果について説明したものであり、顧客の事例や達成された実績ではありません。.
シナリオ01
A field-service app stores customer documents on phones. Project: examine storage and logout behaviour. Target outcome: stronger local protection and cleanup rules, verified on test devices.
シナリオ 02
A loyalty app embeds a shared secret in its binary. Project: assess its use and server controls. Target outcome: remove the distributed secret and implement appropriate access controls; obfuscation alone is not presented as a sufficient fix.
技術と参照コンテキスト
OWASP MASVS/MASTG; dedicated devices and synthetic data.
最終的なテクノロジーセットは、相互運用性、ライセンス、アクセス権、および運用要件に基づき、スコープ設定の段階で合意されます。.
コネクテッドサービス
次のステップを構築する。.
これらのサービスはエンゲージメントを補完するものであり、自動的には含まれません。.
会話を始めましょう。
スコープを明確にする。.
このサービスの目的、依存関係、および責任範囲を明確にした上で、納品を提案いたします。.
