Overview
ISO/IEC 23643:2020 - "Software and systems engineering - Capabilities of software safety and security verification tools" defines capabilities, vendor requirements and user/developer guidance for tools that verify software safety and security. The standard focuses on verification of software artefacts (specifications, models, pseudo-code) via analysis and animation rather than execution testing. It is domain‑independent, excludes hardware, and is intended to improve the quality and transparency of software safety and security verification tools.
Key topics and technical scope
- Purpose and scope
- Requirements for verification tool vendors and guidance for users and developers.
- Clarifies differences between verification and validation; testing tools are excluded (see ISO/IEC 30130).
- Models and use cases
- Introduces models, use cases and an entity‑relationship chart to help match tools to verification workflows.
- Tool categories covered
- Specification and refinement tools
- Model checking tools
- Program analysis tools (static and dynamic program analysis is defined)
- Proof tools (formal verification)
- Monitoring tools
- Programming rules checkers
- Security categories: vulnerability analysis, security modeling, threat modeling
- Capabilities and requirements
- Defines capabilities expected of safety and security verification tools and category‑specific guidance and requirements for vendors and developers.
- Addresses common concerns such as false positives/false negatives, evaluator roles, and assurance levels.
- Operational context
- Encourages continuous verification aligned with agile and continuous delivery practices.
- Distinguishes software verification from system-level safety/security.
Practical applications and who uses it
ISO/IEC 23643:2020 is useful for:
- Verification tool vendors - to design, document and market tools that meet recognized capability and quality expectations.
- Software developers and V&V teams - to select and apply appropriate verification tools for safety‑critical and security‑sensitive software.
- Independent evaluators and certification bodies - to assess tool claims, capability, and fit for purpose.
- Safety/security engineers - to integrate model checking, formal verification, static analysis, runtime monitoring and threat/vulnerability modeling into development lifecycles.
Typical applications include verification of software in transportation, energy, IoT, medical devices and other safety‑critical systems where software defects or security vulnerabilities have high impact.
Related standards
Keywords: ISO/IEC 23643:2020, software safety, security verification tools, model checking, program analysis, formal verification, vulnerability analysis, threat modeling, verification tool vendors.