WG 23 addresses programming language vulnerabilities
E697049
WG 23 addresses programming language vulnerabilities is an ISO/IEC working group focused on identifying, analyzing, and providing guidance to mitigate security vulnerabilities in programming languages and their use.
Statements (45)
| Predicate | Object |
|---|---|
| instanceOf |
ISO/IEC working group
ⓘ
standards working group ⓘ |
| activity |
develops international standards
ⓘ
produces guidance documents ⓘ produces technical reports ⓘ |
| collaboratesWith |
academic researchers
ⓘ
industry experts ⓘ national standards bodies ⓘ |
| field |
cybersecurity
ⓘ
programming languages ⓘ software engineering ⓘ software security ⓘ |
| focus |
mitigation of security vulnerabilities in software
ⓘ
programming language vulnerabilities ⓘ secure use of programming languages ⓘ |
| geographicScope | international ⓘ |
| goal |
improve safety and security of software written in standardized languages
ⓘ
reduce security risks in software systems ⓘ |
| governedBy | ISO/IEC directives NERFINISHED ⓘ |
| name | WG 23 addresses programming language vulnerabilities ⓘ |
| output |
catalogs of common programming language vulnerabilities
ⓘ
guidance for safer use of programming languages ⓘ recommendations for language standardization groups ⓘ |
| parentCommittee | ISO/IEC JTC 1 NERFINISHED ⓘ |
| parentOrganization |
International Electrotechnical Commission
NERFINISHED
ⓘ
International Organization for Standardization NERFINISHED ⓘ |
| purpose |
analyze programming language vulnerabilities
ⓘ
identify security vulnerabilities related to programming languages ⓘ provide guidance to mitigate programming language vulnerabilities ⓘ support development of secure software ⓘ |
| scope |
vulnerabilities arising from programming language design
ⓘ
vulnerabilities arising from programming language implementation ⓘ vulnerabilities arising from programming language usage ⓘ |
| shortName | WG 23 NERFINISHED ⓘ |
| stakeholder |
compiler and tool implementers
ⓘ
programming language designers ⓘ security practitioners ⓘ software developers ⓘ |
| standardizationDomain |
information technology
ⓘ
software and systems engineering ⓘ |
| topic |
guidance for language standard committees
ⓘ
language-level security controls ⓘ risk assessment of language features ⓘ secure coding practices ⓘ vulnerability classification in programming languages ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.