💡ソフトウェアをシンプルに保ち、ビジネス上の様々な要求に応えやすくするためには、開発者の活動を支援する様々な自動化やアーキテクチャ設計への投資が必要不可欠です。
ですが、目に見える機能と異なり、ソフトウェアの中身に宿る品質への投資は経営者やエンジニアでないものには理解されにくいものです。
目に見えない投資について、「見える化」をしながら改善がなされていることが重要な視点です。
1.バージョン管理
なぜ重要か
ソースコードのバージョン管理は、最も基礎的な開発者の習慣です。
このような習慣がない場合、共同でソフトウェアを開発すること自体が困難になり、属人化したノウハウや暗黙的なルールの温床になりえます。また、GitHubなどのサービスはさまざまな開発者向けツールの起点となる重要な基盤でもあります。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-1-1メトリクスの計測Measurement of metricsバージョン管理システムの履歴情報(Code Churn)の分析をもとにバグ予測や品質上の問題を指摘するツールを導入し、継続的に改善しているか。Do you introduce tools for predicting bugs and pointing out quality problems based on the analysis of historical information of the version control system (Code Churn), and continuously improve?
- SYSTEM-1-2学習と改善Learning and improvement明文化されたブランチ戦略が存在するか。そして、それは守られているか。Is there any documentation for branch strategy, which is obeyed strictly?
- SYSTEM-1-3プラクティスPracticeすべてのアプリケーションコードをGit/GitHubなどのバージョン管理システムで自社管理しているか。(権利を有する全てのソースコードについて、自社がアカウントを管理する統一のバージョン管理システムで扱っているか)Are all the application codes managed by version management system like Git/GitHub in-house? (Are all the code that you have rights handled by by a unified version control system, which have the accounts managed in-house?)
- SYSTEM-1-4プラクティスPracticeインフラ構成とシステム要素のプロビジョニングをソースコードとして実行可能な形式にした上で、バージョン管理システムで管理しているか。(Infrastructure as Code)Is the infrastructure configuration and system element provisioning in a format that can be executed as source code and then managed by a version control system? (Infrastructure as Code)
- SYSTEM-1-5プラクティスPractice統合テスト/デプロイメントの自動化に関わるソースコードをアプリケーションコードと同一のバージョン管理システムで管理しているか。Is the source code involved in the automation of integration testing/deployment managed in the same version control system as the application code?
- SYSTEM-1-6アンチパターンAnti-patternソースコード自体のセキュリティレベルを高く設定しており、開発支援系SaaSの利用を禁止している。The security level of the source code itself is set high, and the usage of development support SaaS is prohibited.
- SYSTEM-1-7アンチパターンAnti-patternバージョン管理システムが複数存在していたり、1つのツールからすべての履歴を閲覧できないなど、中途半端な状態のままになっていないか。You are using more than one version control system, or unable to view all the history from one tool, leading you in a half-baked state.
- SYSTEM-1-8アンチパターンAnti-patternシステムのソースコードの閲覧を関連するエンジニアのみに限定している。(別チームのエンジニアや他のステークホルダーが閲覧できない。)The source code of the system is restricted to the relevant engineers only. (Engineers from different teams and other stakeholders cannot view it.)
2.ソースコードの明確さ
なぜ重要か
複雑なソースコードは、それだけで自動的なテストを難しくしバグや障害を生み出しやすいだけでなく、開発者のモチベーションや生産性に悪影響を与えます。
ソフトウェアの内部的な品質は経営から不可視であるため軽視される傾向があります。だからこそ、十分な注意をはらい続けなければなりません。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-2-1メトリクスの計測Measurement of metricsアプリケーションコードの循環的複雑度などのメトリクスを、ツール/サービスを用いて継続的に計測しているか。Are metrics such as cyclical complexity of application code continuously measured by tools/services?
- SYSTEM-2-2学習と改善Learning and improvementデッドコードを四半期以上のサイクルで定期的に棚卸しし、削除や分解をしているか。Is the dead code regularly reviewed, removed or splitted on a quarterly or shorter cycle?
- SYSTEM-2-3プラクティスPracticeコードレビューをする習慣や規則があり、本番用ブランチ(master / mainなど)へのマージはコードレビューを必須としているか。Do you have code review habits and rules, and do you require code review for merging into production branches (master / main, etc.)?
- SYSTEM-2-4プラクティスPractice静的解析だけでは発見できないレビュー観点を生成AIを用いたツールやサービスによってレビュー・修正提案を自動化しているか。Does the team use generative AI tools or services to automate reviews and generate modification proposals for review points that cannot be discovered by static analysis alone?
- SYSTEM-2-5プラクティスPracticeリポジトリ共通のコードルールに準拠したコードにするため、指摘点を自動的に検出・補正するLinterやフォーマッタなどのツール群を整備しているか。Does the team have a set of tools, such as linters and formatters, that automatically detect and correct issues to ensure code complies with the repository's common coding standards?
- SYSTEM-2-6アンチパターンAnti-patternコードレビューをできる人物がチームの中におらず、レビュー待ちに1、2営業日がかかる。There is no one on the team who can do code reviews, and it takes one or two business days to wait for a review.
- SYSTEM-2-7アンチパターンAnti-patternコードレビューガイドラインが些細な記述上のルールにとどまり、品質特性(保守性や拡張性など)に資する項目が十分に書かれていない。The code review guidelines are limited to trivial rules of notation, and items contributing to quality characteristics such as maintainability and extensibility are not sufficiently written.
- SYSTEM-2-8アンチパターンAnti-patternコードレビューガイドラインの多くの項目が、自動的なフォーマッタなどで統一・解決可能な些末な事柄である。Many of the items in the code review guidelines are trivial matters that can be unified and resolved by automatic formatters.
3.継続的インテグレーション
なぜ重要か
継続的インテグレーションとは、自動的で定期的に実施される結合テスト環境のことです。
この環境が簡単でかつ信頼できるほど、開発者は誰かの手作業によるテストを待つ必要がなくなり、自分の手元でソースコードの改善を繰り返しやすくなります。これは生産性と品質向上に寄与します。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-3-1メトリクスの計測Measurement of metricsすべてのインテグレーションテストにかかる時間が計測されており、それは30分以内に完了するか。Is the time taken for all integration tests measured, and are those tests completed within 30 minutes?
- SYSTEM-3-2学習と改善Learning and improvementテストカバレッジ基準や自動テストガイドラインを用意し、これらを継続的に改善するための工数がチームで割かれているか。Are test coverage criteria and automated test guidelines prepared, and are the team allocating man-hours to continuously improve these?
- SYSTEM-3-3プラクティスPracticeプロダクトの半分以上のモジュール/クラスファイルに対して、ユニットテストが存在しているか。Do unit tests cover for more than half of the modules/class files in the product?
- SYSTEM-3-4プラクティスPracticeテスト用データやスタブ/モックなどを整備し、テストを書きやすくするための環境整備をしているか。Do you have test data, stubs/mocks, etc., and prepare the environment to make it easier to write tests?
- SYSTEM-3-5プラクティスPractice継続的インテグレーション環境が存在し、開発者は開発ブランチの全テストをリソース調整することなく、自由に行うことができるか。Does a continuous integration environment exist, allowing developers to freely test all development branches without having to coordinate resources?
- SYSTEM-3-6アンチパターンAnti-pattern一部の人だけがテストを書き、一部の人はテストを書かないといったように自動テストを個々人の努力目標などになっている。Only some people write tests and some people don't, making automated testing an individual effort goal.
- SYSTEM-3-7アンチパターンAnti-patternたまに失敗するような不安定な動作をする自動テスト(フレーキーテスト)が増え、自動テストの結果が信頼できなくなっている。The number of automated tests that occasionally fail and behave unstably (flaky tests) has increased, making the results of automated tests unreliable.
- SYSTEM-3-8アンチパターンAnti-patternアイスクリームコーン型のテスト(手動テストやE2Eテストの比重が大きい)になっており、テストの実行時間、保守工数などが増大している。The testing approach has become 'ice-cream cone shaped,' where the proportion of manual and E2E tests is large, leading to increased test execution time and maintenance effort.
4.継続的デプロイ
なぜ、重要か。
継続的デプロイとは、完成したソースコードを自動的かつ簡単・安全にサービスインするための仕組みです。
この環境への投資が整っていない場合、開発者は本番環境のリリースのたびに様々な作業負荷がかかり、仮説検証や継続的な品質改善に対しての足止めになってしまいます。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-4-1メトリクスの計測Measurement of metricsデプロイ頻度とデプロイ成功率を継続的に測定しており、これらを改善することを目標管理しているか。Do you continuously measure deployment frequency and deployment success rate, and do you manage the goals to improve them?
- SYSTEM-4-2学習と改善Learning and improvementデプロイ時に社内のユーザーや開発者のみを対象もしくは、一部のサーバのみにサービスをリリースしてエラーがないかを確かめるカナリアリリースができるか。Is it possible to do a canary release, where the service is released only to internal users and developers or only to some servers at the time of deployment to make sure there are no errors?
- SYSTEM-4-3プラクティスPracticeデプロイ完了時、および構成変更時にインフラ構成に関する自動的なテスト(e2eのスモークテストおよびServerspecなどのインフラ環境テスト)を実行しているか。Are automated tests (e2e smoke tests or infrastructure environment tests such as Serverspec) run on infrastructure configuration when deployments are complete and when configuration changes are made?
- SYSTEM-4-4プラクティスPracticeブルーグリーンデプロイメントができるか。(稼働中のサーバーを切り替えるのではなく、別環境にデプロイ作業をしてから本番の向き先を切り替えるデプロイ手法。)Can blue green deployment be done? (A deployment method that switches the production destination after deploying to a different environment, rather than switching the server in operation.)
- SYSTEM-4-5プラクティスPracticeデプロイ作業を伴わず、一部の機能を安全にオフにしたり、オンにしたりできるか。( Feature Toggle /Soft Launch/ Dark launchなどの仕組みを導入・実装しているか。)Can some features be safely turned off and on without deployment work? (Are mechanisms such as Feature Toggle / Soft Launch / Dark launch introduced and implemented?)
- SYSTEM-4-6アンチパターンAnti-patternデプロイされたコードに問題が発生した際に、前のバージョンへの切り戻しを意思決定してから5分以内に切り戻すことができない。When a problem occurs in the deployed code, it is not possible to roll back to the previous version within five minutes after making the decision.
- SYSTEM-4-7アンチパターンAnti-pattern開発者のメンバー自身が、権限を持つ人物の承認があっても、自分のコードを本番環境にデプロイできない。The developers themselves cannot deploy their own code to the production environment, even with the approval of an authorized person.
- SYSTEM-4-8アンチパターンAnti-patternデプロイ工程が自動化されておらず、本番反映に1時間以上かかっていたり、特定の時間帯しかできないなどの制約事項がかかっている。The deployment process is not automated, and is subject to restrictions such as taking more than an hour to reflect production, or only being able to do so at certain time zones of a day.
5.API駆動開発
なぜ、重要か。
ネットワーク経由のAPIを基準にシステムを開発することで、他のシステムと連携しやすくなります。
またシステムがレガシー化した際に交換したり、改善したりといった手が打ちやすいものになります。
人が使う見た目の作りだけでなく、エンジニアにとっての作りが質を生み出します。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-5-1メトリクスの計測Measurement of metrics社内外のAPIの利用者にとってのユーザビリティについてヒアリング/アンケートを行い継続的な改善が行われているか。Do you conduct hearings/questionnaires on the usability of APIs for internal and external users and make continuous improvements?
- SYSTEM-5-2学習と改善Learning and improvement各APIについて、動作するインタラクティブなドキュメントや管理サービスを持っているか。For each API, does a working interactive documentation or management service exist?
- SYSTEM-5-3プラクティスPracticeプロダクトに対して外部あるいは内部の別のシステムと連携するためのAPIが提供されているか。Are APIs provided for the product to work with other external or internal systems?
- SYSTEM-5-4プラクティスPracticeAPIは何らかのSchema定義言語によって規定され、そこから自動的にクライアントの生成やバリデータの生成が行われているか。Is the API specified by some Schema definition language, from which clients and validators are automatically generated?
- SYSTEM-5-5プラクティスPracticeAPIに関わる要件は、SDD(スキーマ駆動開発)で開発され、直ちにモックアップサーバーが提供できるか。Can the requirements related to the API be developed using SDD (Schema Driven Development) and provide a mockup server immediately?
- SYSTEM-5-6アンチパターンAnti-patternViewやControllerの層に処理が集中しており、機能をAPIに切り出すことが困難な設計になっている。Processing is concentrated in the View and Controller layers, and the design makes it difficult to carve out functions into APIs.
- SYSTEM-5-7アンチパターンAnti-pattern各APIに対して、ネットワークを経由した死活監視が存在しておらず、サービスの稼働状況をリアルタイムで把握できていない。For each API, network-based health monitoring is lacking (or: is not in place), and as a result, the team is unable to ascertain the real-time operational status of the service.
- SYSTEM-5-8アンチパターンAnti-patternAPIがバージョン管理されていないため、並行開発や段階的なリリースが困難な状態になっている。The APIs are not version-controlled, making parallel development and phased releases difficult.
6.疎結合アーキテクチャ
なぜ、重要か。
システムの役割は単純であればあるほど、高速に改善しやすくなります。
複雑な問題を解くときに単純な問題の組み合わせにするというのは重要な設計技術です
疎結合なアーキテクチャとは、このように改善する単位を単純に保つための技術です。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-6-1メトリクスの計測Measurement of metrics目指すべきアーキテクチャに対してそぐわない点を洗い出すための仕組みが存在しており、それらの情報をもとに改善を進めているか。(アーキテクチャ適応度関数)Is there a mechanism to identify the unsuitable points in the architecture that should be aimed for,and are improvements being made based on this information? (Architecture fitness function)
- SYSTEM-6-2学習と改善Learning and improvementシステムアーキテクチャの決定・変更・改善に関するドキュメントを管理し継続的な学習機会を設けているか。Do you maintain documentation on system architecture decisions, changes, and improvements to provide continous learning opportunities?
- SYSTEM-6-3プラクティスPracticeドメインイベントの発火に伴いPublish/Subscribeモデルを利用した仕組みで、関連サービスとの連携が可能か。またその履歴データが保存管理され、これらのイベントリプレイから再突合や監査の自動化が可能か。Is it possible to link related services using a Publish/Subscribe model when a domain event is fired? Also, can the historical data be stored and managed, and can these event replays be used to automate reconciliation and auditing?
- SYSTEM-6-4プラクティスPractice結果整合性を考慮したサービスレベルの合意が要件のガイドラインの中に組み込まれているか。Are service level agreements for eventual consistency incorporated into the requirements guidelines?
- SYSTEM-6-5プラクティスPracticeバッチ、ジョブ、プロシージャに対する冪等な設計ガイドラインが存在しており、再送によって整合性が担保できるようなシステムになっているか。Are there design guidelines to ensure idempotency for batches, jobs, and procedures, and can the system ensure consistency in case of retransmission?
- SYSTEM-6-6アンチパターンAnti-pattern1つのデータベースに対して複数のシステムからの直接的な参照または書き込みがなされていて、それらの依存性が簡単には追跡できない状況になっている。There are direct references or writes to a database from multiple systems, and their dependencies are not easily traceable.
- SYSTEM-6-7アンチパターンAnti-pattern疎結合なシステムであるが、分散トレーシングの仕組みがなく、問題発生時の原因特定に時間がかかる。Although it is a loosely coupled system, there is no distributed tracing mechanism, and it takes time to identify the cause when a problem occurs.
- SYSTEM-6-8アンチパターンAnti-pattern自動テストとスキーマ定義の存在しない外部システムとの依存関係が10ケース以上存在しており、機能開発の影響範囲を特定できない。There are more than 10 cases of dependencies on an external system that does not have automated tests or schema definitions, making it impossible to identify the scope of impact of functional development.
7.システムモニタリング
なぜ、重要か。
システムの品質は、エラーや障害などから学び改善していくことで生まれます。
そのためには、エラーや障害について検知し、復旧するためのモニタリングとその改善を支援するための文化と技術が必要になります。
ミスを許さない懲罰的な文化のもとでは、重大事故が起きやすくなります。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-7-1メトリクスの計測Measurement of metricsSLI/SLO/エラーバジェットがビジネスオーナーとエンジニアが協議して合意の上設定され、計測されているか。Are the SLI/SLO/Error budgets set and measured after consultation and agreement between the business owner and the engineers?
- SYSTEM-7-2学習と改善Learning and improvement開発と SRE が共有する障害報告リストがあり、それぞれに有効な再発防止の仕組みが整うようにリソースを割いているか。Are failure reports shared between development teams and SRE teams, and are enough resouces dedicated from each team to create effective mechanisms to prevent recurrences?
- SYSTEM-7-3プラクティスPracticeシステムに起こった障害や異変などを再現できるための情報がアプリケーションのログ、メトリクス、トレースを通じて出力され分析できるようになっている。(オブザーバビリティ)Information necessary to reproduce system failures or anomalies is output and analyzable through application logs, metrics, and traces. (Observability)
- SYSTEM-7-4プラクティスPracticeプロアクティブな本番系への負荷テストやフォルトインジェクションテスト、リカバリテストなどのシステムの不確定要因への耐障害性を上げていく試みをおこなっているか。Are attempts being made to increase the system's resilience to uncertainties, such as proactive load testing on production systems, fault injection testing, and recovery testing?
- SYSTEM-7-5プラクティスPracticeオートスケールなどの仕組みにより、開発者やSREが介在しなくても、適切なキャパシティコントロールができているか。Is capacity control possible by mechanisms such as autoscale without the intervention of developers or SREs?
- SYSTEM-7-6アンチパターンAnti-pattern障害の発生に対しての罰則や謝罪などの、開発者が萎縮したり障害を隠蔽する方向につながるような慣習が存在する。There are any practices, such as penalties or apologies for failures, that can lead developers towards attrition or covering up failures?
- SYSTEM-7-7アンチパターンAnti-pattern定常的に発生しているサービス上の警告を問題ないものとして無視したり、ログを意図的に出力しないようにする慣習が存在する。Practices exist of ignoring regular service warnings as non-issues, or intentionally not outputting logs.
- SYSTEM-7-8アンチパターンAnti-patternシステム構成要素の構築方法や運用方法が属人化しており、同じインスタンスを構築できない。The construction and operation method of system components are personalized, and it is not possible to recreate the same environment
8.セキュリティシフトレフト
なぜ、重要か。
ソフトウェアが完成したあとにセキュリティの課題が見つかると、そのための対応に追われたり、リリースが遅れたりと良いことがありません。
できる限り早い工程でセキュリティの課題を見つけ出す技術と文化を、DevSecOpsあるいはセキュリティのシフトレフトと言います。
DX Criteria v202506 · 8項目8 criteria
- SYSTEM-8-1メトリクスの計測Measurement of metricsCI/CDのパイプラインにソースコードの自動的なセキュリティチェック(静的解析または動的解析)が組み込まれていて、一定の基準を達さないとリリースされない仕組みになっているか。Does the CI / CD pipeline have automatic source code security checks (static or dynamic analysis) built in so that a release will not happen until certain criteria are met?
- SYSTEM-8-2学習と改善Learning and improvementセキュアコーディングについて、開発者を対象とした教育カリキュラムや研修を実施しているか。Does the company have a course or training for developers about secure coding?
- SYSTEM-8-3プラクティスPractice専門的なアプリケーションセキュリティの知識を持つメンバーが、専任でセキュリティチームにおり、動向や最新情報をもとに自社サービスをレビュー・改善できているか。Is there a dedicated security team, with experts in application security, who can review and improve your service based on latest trends and information?
- SYSTEM-8-4プラクティスPracticeOSSのライブラリやミドルウェアを使用する際、それらの脆弱性情報を自動的モニタリング・警告・パッチ適用するための仕組みまたはサービス等を利用しているか。When using OSS libraries and middleware, do you use a system or service for automatically monitoring, warning, and patching vulnerabilities?
- SYSTEM-8-5プラクティスPractice4半期から1年の間で定期的に、全体的なアプリケーションとインフラの脆弱性診断を受けているか。Are quaterly and yearly application and infrastructure vulnerability assessments performed?
- SYSTEM-8-6アンチパターンAnti-pattern開発速度(デプロイ頻度)を低下させるようなセキュリティルールが、施行されていて現況に合わせたアップデートが行われていない。Security rules that reduce the development speed (deployment frequency) are enforced and not updated according to the current situation.
- SYSTEM-8-7アンチパターンAnti-patternソースコード中に、漏洩してはならない情報がハードコーディングされている。(それらを分離かつ暗号化して管理するようなツールまたは仕組みを導入していない)Sensitive information that should not be leaked is hard-coded in the source code. (Tools or mechanisms to manage and encrypt this information separately have not been introduced / are not in place.)
- SYSTEM-8-8アンチパターンAnti-pattern開発企画要件の段階で、設計レベルのセキュリティレビューが実施されていない。(Security by Designの未実施)No design-level security review are conducted at the development planning stage. (Security by Design not implemented)
