• BS ISO/IEC 17960:2015

    Current The latest, up-to-date edition.

    Information technology. Programming languages, their environments and system software interfaces. Code signing for source code

    Available format(s):  Hardcopy, PDF

    Language(s):  English

    Published date:  30-09-2015

    Publisher:  British Standards Institution

    Add To Cart

    Table of Contents - (Show below) - (Hide below)

    Foreword
    Introduction
    1 Scope
    2 Conformance
    3 Normative references
    4 Terms and definitions
    5 Concepts
    6 Requirements
    Annex A (informative) - Notional code signing process
    Bibliography

    Abstract - (Show below) - (Hide below)

    Describes a language-neutral and environment-neutral description to define the methodology needed to support the signing of software source code, to enable it to be uniquely identified, and to enable roll-back to signed previous versions.

    Scope - (Show below) - (Hide below)

    This International Standard specifies a language-neutral and environment-neutral description to define the methodology needed to support the signing of software source code, to enable it to be uniquely identified, and to enable roll-back to signed previous versions. It is intended to be used by originators of software source code and the recipients of their signed source code. This International Standard is designed for transfers of source code among disparate entities.

    The following areas are outside the scope of this International Standard:

    • Determination of the trust level of a certification authority;

    • Format used to track revisions of source code files;

    • Digital signing of object or binary code;

    • System configuration and resource availability;

    • Metadata

      • This is partially addressed by ISO/IEC19770-2;

    • Transmission and representation issues

      • Though this could be an issue in implementation, there are techniques such as Portable Document Format (PDF)1) that can be used to mitigate these issues. This applies in particular to the transmission of digital signatures.

    General Product Information - (Show below) - (Hide below)

    Committee IST/5
    Document Type Standard
    Publisher British Standards Institution
    Status Current

    Standards Referencing This Book - (Show below) - (Hide below)

    ISO/IEC 14888-3:2016 Information technology — Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms
    ISO/IEC 9796-3:2006 Information technology — Security techniques — Digital signature schemes giving message recovery — Part 3: Discrete logarithm based mechanisms
    ISO/IEC 19770-2:2015 Information technology IT asset management Part 2: Software identification tag
    ISO/IEC 9594-8:2017 Information technology Open Systems Interconnection The Directory Part 8: Public-key and attribute certificate frameworks
    ISO/IEC 14888-1:2008 Information technology Security techniques Digital signatures with appendix Part 1: General
    ISO/IEC 13888-1:2009 Information technology Security techniques Non-repudiation Part 1: General
    ISO/IEC 9899:2011 Information technology Programming languages C
    ISO/IEC 9796-2:2010 Information technology Security techniques Digital signature schemes giving message recovery Part 2: Integer factorization based mechanisms
    ISO/IEC 10118-3:2004 Information technology Security techniques Hash-functions Part 3: Dedicated hash-functions
    ISO/IEC 14750:1999 Information technology Open Distributed Processing Interface Definition Language
    ISO/IEC 14888-2:2008 Information technology Security techniques Digital signatures with appendix Part 2: Integer factorization based mechanisms
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective