ISO/IEC/IEEE 32675:2022 PDF
Information technology — DevOps — Building reliable and secure systems including application build, package and deployment
Information technology — DevOps — Building reliable and secure systems including application build, package and deployment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 81
- Дата публикации:
- 30 августа 2022 г.
- Издание:
- ISO/IEC/IEEE IS 32675 edition 1 version 1
- ICS:
- 35.080
This document provides requirements and guidance on the implementation of DevOps to define, control, and improve software life cycle processes. It applies within an organization or a project to build, package, and deploy software and systems in a secure and reliable way. This document specifies practices to collaborate and communicate effectively in groups including development, operations, and other key stakeholders. This document applies a common framework for software life cycle processes, with well-defined terminology. It contains processes, activities, and tasks that are to be applied to the full life cycle of software systems, products, and services, including conception, development, production, utilization, support, and retirement. It also applies to the acquisition and supply of software systems, whether performed internally or externally to an organization. These life cycle processes are accomplished through the involvement of stakeholders, with the ultimate goal of achieving customer satisfaction. The life cycle processes of this document can be applied concurrently, iteratively, and recursively to a software system and incrementally to its elements. This document applies to software systems, products, and services, and the software portion of any system. Software includes the software portion of firmware. Those aspects of system definition needed to provide the context for software systems, products, and services are included. There is a wide variety of software systems in terms of their purpose, domain of application, complexity, size, novelty, adaptability, quantities, locations, life spans, and evolution. This document describes the processes that comprise the life cycle of software systems. It therefore applies to one-of-a-kind software systems, software systems for wide commercial or public distribution, and customized, adaptable software systems. It also applies to a complete stand-alone software system and to software systems that are embedded and integrated into larger, more complex, and complete systems.
Abstract
Overview
ISO/IEC/IEEE 32675:2022 (also published as IEEE Std 2675™‑2021) is an international standard that defines requirements and guidance for implementing DevOps to build, package, and deploy software and systems in a reliable and secure manner. The document frames DevOps as a set of processes, activities, and tasks that span the full software life cycle - from conception and development through production, utilization, support, and retirement - and addresses both internally developed and externally acquired software, including firmware and embedded software components.
Key Topics and Technical Requirements
- DevOps principles: mission first, customer focus, left‑shift (early defect prevention), continuous everything (integration, delivery, deployment), and systems thinking.
- Build, package, deploy: prescriptive practices and technical principles to ensure reproducible application builds, secure packaging, and controlled deployment processes.
- Security and reliability controls: emphasis on establishing effective IT controls, compliance practices, and secure-by-design measures across the pipeline.
- Collaboration and communication: defined practices to improve interaction among development, operations, quality assurance, security, procurement, and other stakeholders.
- Life cycle process model alignment: process outcomes and activities are aligned with ISO/IEC/IEEE 12207:2017 and ISO/IEC/IEEE 15288:2015, enabling integration with existing software and systems engineering processes.
- Applicability and scalability: supports one‑of‑a‑kind systems, commercial distributions, customized/adaptable systems, and systems embedded in larger platforms; processes can be applied concurrently, iteratively, recursively, or incrementally.
Practical Applications
- Implementing continuous integration (CI) and continuous delivery/deployment (CD) pipelines that include security and compliance checkpoints.
- Defining organizational practices for secure build artifacts, tamper‑evident packaging, and controlled release orchestration.
- Integrating DevOps controls into procurement and supplier management for outsourced software and third‑party components.
- Applying “left‑shift” strategies to move testing, vulnerability scanning, and compliance assessments earlier in development.
- Standardizing cross‑team communication and roles to reduce deployment failures and speed time to market.
Who Should Use This Standard
- DevOps engineers, release and deployment managers, site reliability engineers (SREs)
- Software architects, security engineers, QA/test leads
- IT operations, procurement teams, and project managers responsible for system acquisition or supply
- Organizations seeking to standardize secure and reliable build/package/deploy processes across projects and product lines
Related Standards
- ISO/IEC/IEEE 12207:2017 (software life cycle processes)
- ISO/IEC/IEEE 15288:2015 (system life cycle processes)
ISO/IEC/IEEE 32675:2022 is a practical reference for organizations implementing modern DevOps practices with an emphasis on secure, repeatable, and auditable build and deployment processes. Keywords: DevOps, ISO/IEC/IEEE 32675:2022, IEEE 2675, continuous integration, continuous delivery, continuous deployment, left‑shift, secure build, software life cycle.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 7 - Software and systems engineering
- SKU
- ISO/IEC/IEEE 32675:2022
Похожие стандарты
Другие стандарты ISO
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…
ISO/ASTM52901-17(2023)
ДействующийStandard Guide for Additive Manufacturing – General Principles – Requirements for Purchased AM Parts
Scope 1.1 This document defines and specifies requirements for purchased parts made by additive manufacturing. 1.2 It gives guidelines for the elements to be exchanged between the customer and the pa…