Mapping Principles
The application security requirements on this site have been split into the 8 different principles from the UK Government’s Code of practice for app store operators and app developers.
App stores operators must be vigilant in communicating and upholding the security/privacy requirements of the app store. This includes:
- Clearly setting out the requirements in a publicly accessible location
- Vetting and rejecting apps that don’t adhere
- Clearly communicating the verification process and any reasons an app was rejected
- Having a way for people to report malicious apps and taking the necessary actions to remove any malicious apps, including reviewing other apps from the same developer
Principle 2: Ensure apps adhere to baseline security and privacy requirements
Developers must follow the security/privacy requirements, for example:
- Using industry standard encryption
- Requesting and using permissions only necessary for an apps functionality
- Having a simple uninstallation process
- Allowing users to request the deletion of their data
Principle 3: Implement a vulnerability disclosure process
Apps must have a way for users and security researchers to disclose vulnerabilities. App store operators must also verify this is the case and additionally pass on any disclosures to the developer.
Principle 4: Keep apps updated to protect users
Developers should provide updates to fix security/privacy vulnerabilities in their app as well as update any libraries or SDKs used in their app when those receive security/privacy updates. App store operators should encourage users to update to the latest version and shouldn’t reject standalone security updates. App store operators should also check up on developers if an app hasn’t been updated for 2 years and consider removing the app from the store.
Principle 5: Provide important security and privacy information to users in an accessible way
App store operators should notify users if an app they use is removed from the app store and how to remove the app from their device. App developers should supply privacy information which should be displayed by the app store, for example:
- The jurisdictions where a user’s data is stored and processed
- Who is given access to a user’s data and why
- When the app was last updated
- The permissions required for an app and reasoning for each
Principle 6: Provide security and privacy guidance to Developers
App store operators should provide any additional best practice guidance to developers for security/privacy in addition to the baseline requirements. This includes signposting this Code of Practice to developers. App store operators should also support developers implementing supply chain management such as monitoring third party libraries.
Principle 7: Provide clear feedback to developers
If an app store operator rejects and app, they should provide clear consistent and actionable feedback, justifying the rejection and making it clear what elements need to be changed. If they remove an app from the app store for security/privacy reasons, they should notify the developer and provide reasoning.
Principle 8: Ensure appropriate steps are taken when a personal data breach arises
App store operators should notify developers of any data breaches. Developers should also notify app store operators and any other relevant stakeholders. When app store operators find out about a breach they should consider removing the app from the app store.
Outliers
This is a list of items that didn’t map to any of the above categories.
