ISO/IEC 17960:2015
Current
The latest, up-to-date edition.
Information technology Programming languages, their environments and system software interfaces Code signing for source code
Hardcopy , PDF , PDF 3 Users , PDF 5 Users , PDF 9 Users
English
09-17-2015
This International Standard specifies a language-neutral and environment-neutral description to define the methodology needed to support the signing of software source code, to enable it to be uniquely identified, and to enable roll-back to signed previous versions. It is intended to be used by originators of software source code and the recipients of their signed source code. This International Standard is designed for transfers of source code among disparate entities.
The following areas are outside the scope of this International Standard:
- Determination of the trust level of a certification authority;
- Format used to track revisions of source code files;
- Digital signing of object or binary code;
- System configuration and resource availability;
- Metadata
- - This is partially addressed by ISO/IEC 197702;
- Transmission and representation issues
- - Though this could be an issue in implementation, there are techniques such as Portable Document Format (PDF)[1] that can be used to mitigate these issues. This applies in particular to the transmission of digital signatures.
[1] ISO 32000-1:2008 Document management ? Portable document format ? Part 1: PDF 1 specifies a digital form for representing electronic documents to enable users to exchange and view electronic documents independent of the environment in which they were created or the environment in which they are viewed or printed.
DocumentType |
Standard
|
Pages |
7
|
PublisherName |
International Organization for Standardization
|
Status |
Current
|
Standards | Relationship |
BS ISO/IEC 17960:2015 | Identical |
CAN/CSA-ISO/IEC 17960:16 | Identical |
NEN ISO/IEC 17960 : 2015 | Identical |
ISO/IEC 14888-3:2016 | Information technology — Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms |
ISO/IEC 9796-3:2006 | Information technology — Security techniques — Digital signature schemes giving message recovery — Part 3: Discrete logarithm based mechanisms |
ISO/IEC 19770-2:2015 | Information technology IT asset management Part 2: Software identification tag |
ISO/IEC 9594-8:2017 | Information technology Open Systems Interconnection The Directory Part 8: Public-key and attribute certificate frameworks |
ISO/IEC 14888-1:2008 | Information technology — Security techniques — Digital signatures with appendix — Part 1: General |
ISO/IEC 13888-1:2009 | Information technology Security techniques Non-repudiation Part 1: General |
ISO/IEC 9899:2011 | Information technology Programming languages C |
ISO/IEC 9796-2:2010 | Information technology Security techniques Digital signature schemes giving message recovery Part 2: Integer factorization based mechanisms |
ISO/IEC 10118-3:2004 | Information technology Security techniques Hash-functions Part 3: Dedicated hash-functions |
ISO/IEC 14750:1999 | Information technology Open Distributed Processing Interface Definition Language |
ISO/IEC 14888-2:2008 | Information technology Security techniques Digital signatures with appendix Part 2: Integer factorization based mechanisms |
Access your standards online with a subscription
Features
-
Simple online access to standards, technical information and regulations.
-
Critical updates of standards and customisable alerts and notifications.
-
Multi-user online standards collection: secure, flexible and cost effective.