ISO/IEC TR 24772-1 is the first part of the multi series standard that specifies software programming language vulnerabilities to be avoided in the development of systems where assured behaviour is required for security, safety, mission-critical and business-critical software.
ISO/IEC TR 24772-1 does not address software engineering and management issues such as how to design and implement programs, use configuration management tools, use managerial processes, and perform process improvement. Furthermore, the specification of properties and applications to be assured are not treated.
ISO/IEC TR 24772-1 is applicable to the software developed, reviewed, or maintained for any application.
ISO/IEC TR 24772-1 on Information technology is relevant to:
ISO/IEC TR 24772-1 provides users of programming languages with a language-independent overview of potential vulnerabilities in their usage and ways to avoid or mitigate them.
It is intended to provide guidance spanning multiple programming languages, so that application developers will be better able to avoid the programming constructs that lead to vulnerabilities in software written in their chosen language and their attendant consequences.
ISO/IEC TR 24772-1 provide guidance that can be used by developers to select source code evaluation tools that can discover and eliminate some constructs that could lead to vulnerabilities in their software or to select a programming language that avoids anticipated problems.
It specifies descriptions of programming language vulnerabilities, as well as selected application vulnerabilities, which have occurred in the past and are likely to occur again.
ISO/IEC TR 24772-1:2019