标准编号:ISO/IEC TR 24772:2013
中文名称:信息技术 编程语言 通过语言选择与使用规避编程语言脆弱性的指南
英文名称:Information technology — Programming languages — Guidance to avoiding vulnerabilities in programming languages through language selection and use
发布日期:2013-03
标准范围
This Technical Report specifies software programming language vulnerabilities to be avoided in the development of systems where assured behaviour is required for security, safety, mission-critical and business-critical software. In general, this guidance is applicable to the software developed, reviewed, or maintained for any application.Vulnerabilities are described in a generic manner that is applicable to a broad range of programming languages.