• There are no items in your cart

PD ISO/IEC TS 17961:2013

Current
Current

The latest, up-to-date edition.

Information technology. Programming languages, their environments and system software interfaces. C secure coding rules
Available format(s)

Hardcopy , PDF

Language(s)

English

Published date

09-30-2016

Foreword
Introduction
1 Scope
2 Conformance
3 Normative references
4 Terms and definitions
5 Rules
Annex A (informative) - Intra- to Interprocedural
        Transformations
Annex B (informative) - Undefined Behavior
Annex C (informative) - Related Guidelines and References
Annex D (informative) - Decidability of Rules
Bibliography

Describes: - rules for secure coding in the C programming language, and - code examples.

This Technical Specification specifies rules for secure coding in the C programming language and code examples. This Technical Specification does not specify the mechanism by which these rules are enforced or any particular coding style to be enforced. (It has been impossible to develop a consensus on appropriate style guidelines. Programmers should define style guidelines and apply these guidelines consistently. The easiest way to consistently apply a coding style is with the use of a code formatting tool. Many interactive development environments provide such capabilities.) Each rule in this Technical Specification is accompanied by code examples. Code examples are informative only and serve to clarify the requirements outlined in the normative portion of the rule. Examples impose no normative requirements. Each rule in this Technical Specification that is based on undefined behavior defined in the C Standard identifies the undefined behavior by a numeric code. The numeric codes for undefined behaviors can be found in Annex B, Undefined Behavior. Two distinct kinds of examples are provided: noncompliant examples demonstrating language constructs that have weaknesses with potentially exploitable security implications; such examples are expected to elicit a diagnostic from a conforming analyzer for the affected language construct; and compliant examples are expected not to elicit a diagnostic. Examples are not intended to be complete programs. For brevity, they typically omit #include directives of C Standard Library headers that would otherwise be necessary to provide declarations of referenced symbols. Code examples may also declare symbols without providing their definitions if the definitions are not essential for demonstrating a specific weakness. Some rules in this Technical Specification have exceptions. Exceptions are part of the specification of these rules and are normative.

Committee
IST/5
DocumentType
Standard
Pages
96
PublisherName
British Standards Institution
Status
Current

Standards Relationship
ISO/IEC TS 17961:2013/Cor 1:2016 Identical
ISO/IEC TS 17961:2013 Identical

ISO/IEC 2382-1:1993 Information technology Vocabulary Part 1: Fundamental terms
ISO/IEC 11889-1:2015 Information technology Trusted platform module library Part 1: Architecture
ISO/IEC TR 24772:2013 Information technology Programming languages Guidance to avoiding vulnerabilities in programming languages through language selection and use
ISO 80000-2:2009 Quantities and units Part 2: Mathematical signs and symbols to be used in the natural sciences and technology
ISO/IEC 9899:2011 Information technology Programming languages C
ISO/IEC/IEEE 9945:2009 Information technology — Portable Operating System Interface (POSIX®) Base Specifications, Issue 7
ISO/IEC TR 24731-2:2010 Information technology Programming languages, their environments and system software interfaces Extensions to the C library Part 2: Dynamic Allocation Functions
IEEE/Open Group 1003.1, 2013 Edition IEEE Standard for Information Technology—Portable Operating System Interface (POSIX(TM)) Base Specifications, Issue 7

View more information
US$356.96
Excluding Tax where applicable

Access your standards online with a subscription

Features

  • Simple online access to standards, technical information and regulations.

  • Critical updates of standards and customisable alerts and notifications.

  • Multi-user online standards collection: secure, flexible and cost effective.