What is ISO/IEC TR 24772-3 about?
ISO/IEC TR 24772-3 is an International Standard on programming languages, their environments, and system software interfaces that convert strings, or graphical program elements in the case of visual programming languages, to various kinds of machine code output. ISO/IEC TR 24772-3 is the third part in a multi-series of documents that specifies software programming language vulnerabilities to be avoided in the development of systems where assured behaviour is required for security, safety, mission-critical and business-critical software.
ISO/IEC TR 24772-3 is applicable to the software developed, reviewed, or maintained for any application. ISO/IEC TR 24772-3 describes the way that the vulnerabilities listed in ISO/IEC TR 24772-1 are manifested or avoided in the C language.
Who is ISO/IEC TR 24772-3 for?
ISO/IEC TR 24772-3 on programming languages is relevant to:
- IT Industry
- Software developers
- Programmers
Why should you use ISO/IEC TR 24772-3?
C is a procedural programming language. ISO/IEC TR 24772-3 provides guidance for the programming language C so that application developers using C can better avoid the programming constructs that lead to vulnerabilities and their attendant consequences.
ISO/IEC TR 24772-3 can be used by developers to select source code evaluation tools that can discover and eliminate such constructs in their software, or the developers of such tools. Adopting ISO/IEC TR 24772-3 can help you identify and mitigate vulnerabilities such as buffer overflows and string manipulation, that can maintain security information systems’ integrity.
Secure programming can ultimately prevent damage of the running flow of a software and contribute to the development of more confident software.