ISO/IEC TR 24772-3:2020 PDF
Programming languages — Guidance to avoiding vulnerabilities in programming languages — Part 3: C
Programming languages — Guidance to avoiding vulnerabilities in programming languages — Part 3: C
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 42
- Дата публикации:
- 20 мая 2020 г.
- Издание:
- ISO/IEC TR 24772 edition 1 version 1
- ICS:
- 35.060
This document specifies software programming language vulnerabilities to be avoided in the development of systems where assured behaviour is required for security, safety, mission-critical and business-critical software. In general, this guidance is applicable to the software developed, reviewed, or maintained for any application. This document describes the way that the vulnerabilities listed in ISO/IEC TR 24772-1 are manifested or avoided in the C language.
Abstract
Overview
ISO/IEC TR 24772-3:2020 - Programming languages - Guidance to avoiding vulnerabilities in programming languages - Part 3: C - is a technical report that identifies common software programming language vulnerabilities and describes how they are manifested or avoided in the C language. The document targets development of systems requiring assured behaviour for security, safety, mission-critical, and business‑critical software, and is applicable to software developed, reviewed, or maintained for any application.
Key topics
The standard organizes practical guidance by language concept and specific classes of vulnerability. Major topics covered include:
- Language concepts and applicability of vulnerabilities to C
- Type system, bit representations, and floating‑point concerns
- Common errors: conversion errors, string termination, buffer boundary violations (buffer overflows), unchecked array indexing/copying
- Pointer issues: pointer type conversions, pointer arithmetic, null pointer dereference, dangling heap/stack references
- Arithmetic and operator pitfalls: wrap‑around errors, improper use of shift operations, operator precedence, and side‑effects/order of evaluation
- Code quality and maintainability: dead stores, unused variables, identifier reuse, namespace issues, initialization of variables, dead/deactivated code
- Control flow and structure: switch statements and static analysis, loop control variables, off‑by‑one errors, demarcation of control flow, passing parameters and return values, subprogram signature mismatch
Each topic includes an assessment of applicability to C and guidance to language users, enabling targeted mitigation strategies.
Applications and who should use it
ISO/IEC TR 24772-3:2020 is practical for:
- C developers building secure, safety‑critical or high‑assurance software
- Software architects designing systems with strict reliability requirements
- Code reviewers and auditors creating secure coding checklists
- Static analysis and tool vendors mapping checker rules to recognized vulnerabilities
- Systems integrators and procurement teams specifying secure‑coding expectations
- Trainers and educators teaching secure C programming and defensive coding practices
Use cases include integrating the guidance into secure coding standards, code review templates, static analysis rule sets, and training curricula to reduce vulnerabilities in C codebases.
Related standards
- ISO/IEC TR 24772-1 (reference list of vulnerabilities) - the part that enumerates the vulnerability classes the C-specific guidance addresses.
- Other language‑specific parts of the ISO/IEC TR 24772 series provide analogous guidance for other programming languages.
Keywords: ISO/IEC TR 24772-3:2020, secure C programming, programming language vulnerabilities, buffer overflow, null pointer dereference, static analysis, safety-critical software, secure coding guidance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 22 - Programming languages, their environments and system software interfaces
- SKU
- ISO/IEC TR 24772-3:2020
Похожие стандарты
Другие стандарты ISO
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…
ISO/ASTM52901-17(2023)
ДействующийStandard Guide for Additive Manufacturing – General Principles – Requirements for Purchased AM Parts
Scope 1.1 This document defines and specifies requirements for purchased parts made by additive manufacturing. 1.2 It gives guidelines for the elements to be exchanged between the customer and the pa…