12.01.2013 Views

Source Code Analysis Laboratory (SCALe) for Energy ... - CERT

Source Code Analysis Laboratory (SCALe) for Energy ... - CERT

Source Code Analysis Laboratory (SCALe) for Energy ... - CERT

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3.5 Transition<br />

Transition of <strong>SCALe</strong> to practice will follow the SEI’s transition strategy to grow the concept<br />

through engagement with external organizations or SEI partners via a series of deliberate steps.<br />

The proof-of-concept phase will occur with a piloting program of <strong>SCALe</strong> that engages a small<br />

number of clients. During this phase, <strong>CERT</strong> will test and refine processes, procedures, systems,<br />

and outputs.<br />

After the pilot phase, <strong>CERT</strong> will engage a small number of additional organizations that will be<br />

licensed to sponsor <strong>SCALe</strong> laboratories within themselves. Each organization will be licensed to<br />

per<strong>for</strong>m the assessment, issue the con<strong>for</strong>mance assessment report, report results to <strong>CERT</strong>, and be<br />

subject to annual quality audits of all processes, procedures, hardware, and software.<br />

3.6 Con<strong>for</strong>mance Test Results<br />

As of the publication of this report, <strong>CERT</strong> has completed the analysis of one energy delivery system<br />

and begun analyzing a second.<br />

3.6.1 <strong>Energy</strong> Delivery System A<br />

Table 6 shows the flagged noncon<strong>for</strong>mities reported from analysis of the first energy delivery system.<br />

The analysis was per<strong>for</strong>med using four static analysis tools supplemented by manual code<br />

inspection. Dynamic analysis was not used.<br />

CMU/SEI-2010-TR-021 | 32

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!