PD ISO/IEC TR 24772-3:2020 PDF
Programming languages. Guidance to avoiding vulnerabilities in programming languages - C
Programming languages. Guidance to avoiding vulnerabilities in programming languages - C
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Дата публикации:
- 31 мая 2020 г.
- ICS:
- 35.060
- Технический комитет:
- IEC
- SKU:
- PD ISO/IEC TR 24772-3:2020
Abstract
What is ISO/IEC TR 24772-3 about?
ISO/IEC TR 24772-3 is an International Standard on programming languages, their environments, and system software interfaces that convert strings, or graphical program elements in the case of visual programming languages, to various kinds of machine code output. ISO/IEC TR 24772-3 is the third part in a multi-series of documents that specifies software programming language vulnerabilities to be avoided in the development of systems where assured behaviour is required for security, safety, mission-critical and business-critical software. ISO/IEC TR 24772-3 is applicable to the software developed, reviewed, or maintained for any application. ISO/IEC TR 24772-3 describes the way that the vulnerabilities listed in ISO/IEC TR 24772-1 are manifested or avoided in the C language.
Who is ISO/IEC TR 24772-3 for?
ISO/IEC TR 24772-3 on programming languages is relevant to:
IT Industry Software developers Programmers
Why should you use ISO/IEC TR 24772-3 ?
C is a procedural programming language. ISO/IEC TR 24772-3 provides guidance for the programming language C so that application developers using C can better avoid the programming constructs that lead to vulnerabilities and their attendant consequences. ISO/IEC TR 24772-3 can be used by developers to select source code evaluation tools that can discover and eliminate such constructs in their software, or the developers of such tools. Adopting ISO/IEC TR 24772-3 can help you identify and mitigate vulnerabilities such as buffer overflows and string manipulation, that can maintain security inf...
Похожие стандарты
Другие стандарты PD
PD 6605-2:1998
ОтменёнGuidance on methodology for assessment of stress-rupture data - Computing methods
PD ISO/TS 6226:2025
ДействующийHealth informatics. Reference architecture for syndromic surveillance systems for infectious diseases
1 Scope This document specifies a reference architecture for event-based syndromic surveillance systems for infectious diseases. The system reference architecture addresses architectural components i…
PD ISO/TS 17595:2025
ДействующийSolid biofuels. Characterization of wood chip fuels. Essential information for producers, suppliers and users
1 Scope This document provides guidance on the characterization of wood chips produced from raw materials, as defined in ISO 17225‑4 , for the following aspects: quality classes and specifications; s…
PD ISO/TS 4452:2025
ДействующийSpecification and demonstration of system reliability of single-use drug delivery systems
1 Scope This document addresses the specification and demonstration of capability and system reliability to successfully deliver a medicinal product as part of design verification and manufacture, ut…
PD ISO/TS 25271:2026
ДействующийAutomation systems and integration. Industrial digital twin interface architecture
1 Scope This document specifies the interface architecture of industrial digital twin systems, which is structured around three key elements: the digital twin, the physical twin and the interface tha…