标准编号:ISO/IEC 17960:2015
中文名称:信息技术 程序设计语言及其环境和系统软件接口 源代码的代码签名
英文名称:Information technology — Programming languages, their environments and system software interfaces — Code signing for source code
发布日期:2015-09
标准范围
This International Standard specifies a language-neutral and environment-neutral description to definethe methodology needed to support the signing of software source code, to enable it to be uniquelyidentified, and to enable roll-back to signed previous versions. It is intended to be used by originatorsof software source code and the recipients of their signed source code. This International Standard isdesigned for transfers of source code among disparate entities.The following areas are outside the scope of this International Standard:— Determination of the trust level of a certification authority;— Format used to track revisions of source code files;— Digital signing of object or binary code;— System configuration and resource availability;— Metadata— This is partially addressed by ISO/IEC 19770-2;— Transmission and representation issues— Though this could be an issue in implementation, there are techniques such as PortableDocument Format (PDF)1) that can be used to mitigate these issues. This applies in particularto the transmission of digital signatures.