11.01.2017 Views

A Technical History of the SEI

ihQTwP

ihQTwP

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

provements in how developers use both languages have propagated to countless s<strong>of</strong>tware products,<br />

including many in <strong>the</strong> DoD supply chain. The <strong>SEI</strong> secure coding experts also participated in<br />

<strong>the</strong> C Secure Coding Rules Study Group, whose work resulted in <strong>the</strong> publication <strong>of</strong> ISO/IEC TS<br />

17961(E), Information Technology—Programming Languages, Their Environments and System<br />

S<strong>of</strong>tware Interfaces—C Secure Coding Rules. The Secure Coding Initiative’s engagement with<br />

such international standards bodies improves <strong>the</strong> initiative’s standards, processes, and influence.<br />

References<br />

[Businesswire 2008] “LDRA Ships New TBsecure Complete with CERT C Secure Coding<br />

Programming Checker.” Businesswire, October 27, 2008. http://www.businesswire.com/news/home/20081027005019/en/LDRA-Ships-TBsecure-TM-Complete-CERT-Secure<br />

[Dobbs 2009] “Secure Coding in C and C++.” Dr. Dobb’s Journal. September 3, 2009.<br />

http://drdobbs.com/cpp/219501214<br />

[ISO 2011] International Standards Organization & International Electrotechnical Commission.<br />

“Programming Languages—C,” International Standard 9899:2011. http://www.openstd.org/jtc1/sc22/wg14/www/docs/n1570.pdf<br />

(2011).<br />

[Keizer 2011] Keizer, Gregg. “Hackers Launch Millions <strong>of</strong> Java Exploits.” Computerworld, November<br />

19, 2011. http://www.infoworld.com/article/2621397/security/micros<strong>of</strong>t--hackers-launchmillions-<strong>of</strong>-java-exploits.html<br />

[Long 2011] Long, Fred; Mohindra, Dhruv; Seacord, Robert C.; Su<strong>the</strong>rland, Dean F.; & Svoboda,<br />

David. The CERT Oracle Secure Coding Standard for Java. Addison-Wesley, 2011 (ISBN<br />

0321803957).<br />

[Long 2013] Long, Fred; Mohindra, Dhruv; Seacord, Robert C.; Su<strong>the</strong>rland, Dean F.; & Svoboda,<br />

David. Java Coding Guidelines: 75 Recommendations for Reliable and Secure Programs. Addison<br />

Wesley Pr<strong>of</strong>essional, 2013 (ISBN 0-321-93315-X).<br />

[Seacord 2008] Seacord, Robert C. The CERT C Secure Coding Standard. Addison Wesley Pr<strong>of</strong>essional,<br />

2008 (ISBN 0321563212).<br />

[Seacord 2013] Seacord, Robert C. Secure Coding in C and C++, 2nd Edition. Addison Wesley<br />

Pr<strong>of</strong>essional, 2013 (ISBN 0321822137).<br />

CMU/<strong>SEI</strong>-2016-SR-027 | SOFTWARE ENGINEERING INSTITUTE | CARNEGIE MELLON UNIVERSITY 180<br />

Distribution Statement A: Approved for Public Release; Distribution is Unlimited.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!