CAN/CSA-ISO/IEC 17960:16
the methodology needed to support the signing of software source code, to enable it to be uniquely
identified, and to enable roll-back to signed previous versions. It is intended to be used by originators
of software source code and the recipients of their signed source code. This International Standard is
designed for transfers of source code among disparate entities.
The following areas are outside the scope of this International Standard:
— Determination of the trust level of a certification authority;
— Format used to track revisions of source code files;
— Digital signing of object or binary code;
— System configuration and resource availability;
— Metadata
— This is partially addressed by ISO/IEC 19770-2;
— Transmission and representation issues
— Though this could be an issue in implementation, there are techniques such as Portable
Document Format (PDF)1) that can be used to mitigate these issues. This applies in particular
to the transmission of digital signatures.
SDO:
CSA
Language:
English
ICS Codes:
35.060
Status:
Standard
Publish date:
2012-11-30
Standard Number:
CAN/CSA-ISO/IEC 17960:16