Information technology -- Programming languages, their environments and system software interfaces -- Code signing for source code

Logo
CSA Group
Standards Development Organisation:
Working Program:
Designation Number:
CAN/CSA-ISO/IEC 17960
Standard Type:
National Standard of Canada - Adoption of International Standard
Standard Development Activity:
New Standard
Status:
Proceeding to development
SDO Comment Period Start Date:
SDO Comment Period End Date:
Posted On:

Scope:

Scope

This Standard specifies a language-neutral and environment-neutral description to define the methodology needed to support the signing of software source code, to enable it to be uniquely identified, and to enable roll-back to signed previous versions. It is intended to be used by originators of software source code and the recipients of their signed source code. This International Standard is designed for transfers of source code among disparate entities.

The following areas are outside the scope of this International Standard:

- Determination of the trust level of a certification authority;

- Format used to track revisions of source code files;

- Digital signing of object or binary code;

- System configuration and resource availability;

- Metadata

  • - This is partially addressed by ISO/IEC 19770‑2;

- Transmission and representation issues

  • - Though this could be an issue in implementation, there are techniques such as Portable Document Format (PDF) that can be used to mitigate these issues. This applies in particular to the transmission of digital signatures.

Project need:

Project Need
n/a

Note: The information provided above was obtained by the Standards Council of Canada (SCC) and is provided as part of a centralized, transparent notification system for new standards development. The system allows SCC-accredited Standards Development Organizations (SDOs), and members of the public, to be informed of new work in Canadian standards development, and allows SCC-accredited SDOs to identify and resolve potential duplication of standards and effort.

Individual SDOs are responsible for the content and accuracy of the information presented here. The text is presented in the language in which it was provided to SCC.