International standards on system and software integrity

ACM Stand. Pub Date : 1996-09-01 DOI:10.1145/240819.240827
L. Tripp
{"title":"International standards on system and software integrity","authors":"L. Tripp","doi":"10.1145/240819.240827","DOIUrl":null,"url":null,"abstract":"m In recent years, the increased use of software in critical applications such as nuclear power plants, medical systems, transportation systems, financial systems, and environmental systems has necessitated the development of guidelines to ensure that this software meets certain criteria for prudent performance. Each of these applications carries some form of risk, with welldefined consequences. A standard developed jointly by IEC TC 56/WG10 and ISO/IEC JTC1/WG9 has the concept of integrity level as its unifying theme. The integrity level is a “negotiated” containment of risk based on an integrity target established by the parties concerned. Risk cannot be contained in the software alone, as software operates in a system as one of its functions. Risk must be addressed from a system perspective to determine its magnitude and the means to contain it. For the standard under discussion, TC 56/WG10 provides the system perspective, while ISO/IEC JTC1/WG9 provides the software perspective. This article describes the requirements for the standard, the concept of operations for integrity-level process, the key features of the standard, and the means to produce the systems and software integrity-level standard. The article also describes a proposed program of work, based on the integrity-level concept, being pursued jointly by the two working groups. he purpose of this article is to describe how integrity-level standards are used; describe the system and software-level program; describe how a set of integrity-level standards is being developed; and describe the key features of the basic standard in the joint system and software integrity-level program.","PeriodicalId":270594,"journal":{"name":"ACM Stand.","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1996-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM Stand.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/240819.240827","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

m In recent years, the increased use of software in critical applications such as nuclear power plants, medical systems, transportation systems, financial systems, and environmental systems has necessitated the development of guidelines to ensure that this software meets certain criteria for prudent performance. Each of these applications carries some form of risk, with welldefined consequences. A standard developed jointly by IEC TC 56/WG10 and ISO/IEC JTC1/WG9 has the concept of integrity level as its unifying theme. The integrity level is a “negotiated” containment of risk based on an integrity target established by the parties concerned. Risk cannot be contained in the software alone, as software operates in a system as one of its functions. Risk must be addressed from a system perspective to determine its magnitude and the means to contain it. For the standard under discussion, TC 56/WG10 provides the system perspective, while ISO/IEC JTC1/WG9 provides the software perspective. This article describes the requirements for the standard, the concept of operations for integrity-level process, the key features of the standard, and the means to produce the systems and software integrity-level standard. The article also describes a proposed program of work, based on the integrity-level concept, being pursued jointly by the two working groups. he purpose of this article is to describe how integrity-level standards are used; describe the system and software-level program; describe how a set of integrity-level standards is being developed; and describe the key features of the basic standard in the joint system and software integrity-level program.
关于系统和软件完整性的国际标准
近年来,在诸如核电站、医疗系统、运输系统、金融系统和环境系统等关键应用中越来越多地使用软件,因此有必要制定指导方针,以确保该软件符合谨慎性能的某些标准。这些应用程序中的每一个都带有某种形式的风险,并具有明确的后果。由IEC TC 56/WG10和ISO/IEC JTC1/WG9联合制定的标准将完整性级别的概念作为其统一主题。诚信水平是基于有关各方建立的诚信目标对风险的“协商”遏制。风险不能单独包含在软件中,因为软件作为其功能之一在系统中运行。必须从系统的角度来处理风险,以确定其大小和控制风险的手段。对于正在讨论的标准,TC 56/WG10提供了系统视角,而ISO/IEC JTC1/WG9提供了软件视角。本文描述了该标准的需求、完整性级过程的操作概念、该标准的主要特征以及制定系统和软件完整性级标准的方法。文章还描述了两个工作组正在共同执行的基于诚信级别概念的拟议工作方案。本文的目的是描述如何使用完整性级别的标准;描述系统和软件级程序;描述如何开发一套完整性级别的标准;并描述了该基本标准在联合系统和软件完整性级方案中的主要特点。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信