ISO/IEC JTC1/SC7 /N3040

Similar documents
ISO/IEC JTC1/SC7 /N3945

ISO/IEC JTC1/SC7 /N3016

ISO/IEC JTC1/SC7 /N4314

ISO/IEC JTC1/SC7 /N3287

ISO/IEC JTC1/SC7 /N3037

ISO/IEC JTC1/SC7 /N3647

ISO/IEC JTC1/SC7 3810

ISO/IEC JTC1/SC7 /N2667

International Software & Systems Engineering Standards

ISO/IEC JTC1/SC7 /N3614

ISO/IEC JTC1/SC7 /N3848

ISO/IEC JTC1/SC7 /N2736

ISO/IEC JTC1/SC7 /N3209

ISO/IEC JTC1/SC7 N3640

Summary of Contents LIST OF FIGURES LIST OF TABLES

Seminar themes (1 of 3) IEEE/EIA 12207:1995 Software Life Cycle Processes. Seminar themes (3 of 3) Seminar themes (2 of 3)

Engineering for System Assurance Legacy, Life Cycle, Leadership

Security Standardization

ISO/IEC JTC1/SC7 /N3652

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology

ISO/IEC JTC 1 N 13145

INTERNATIONAL STANDARD

ISO/IEC/ IEEE Systems and software engineering Content of life-cycle information items (documentation)

ISO/IEC JTC 1/SC 27 N7769

ISO/IEC ISO/IEC

ISO/IEC JTC1/SC7 N4379

ISO/IEC INTERNATIONAL STANDARD. Systems and software engineering Measurement process. Ingénierie des systèmes et du logiciel Processus de mesure

ISO/IEC JTC1/SC7 /N2975

ISO/IEC JTC 1 N 13538

Frequently Asked Questions

Engineering Practices for System Assurance

Reported by Jim Moore, The MITRE Corporation, ,

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

Report on ISO/IEC/JTC1/SC27 Activities in Digital Identities

ISO/IEC JTC 1 Study Group on Smart Cities

Information technology Process assessment Concepts and terminology

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques A framework for IT security assurance Part 2: Assurance methods

ISO/IEC JTC1/SC7 N2830,

ISO/IEC JTC 1 Update. April 2018 Phil Wennblom, Chair

Information technology Process assessment Process measurement framework for assessment of process capability

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management systems Overview and vocabulary

Agenda. New ISO/IEC developments in Process Assessment standards for IT Services. Antonio Coletta DNV IT Global Services

ISO/IEC TR TECHNICAL REPORT. Systems and software engineering Life cycle management Part 1: Guide for life cycle management

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology

Information technology Service management. Part 10: Concepts and vocabulary

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

ISO/IEC INTERNATIONAL STANDARD. Identification cards Machine readable travel documents Part 3: Machine readable official travel documents

Information technology Service management. Part 10: Concepts and terminology

INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management. Frequently Asked Questions

IEEE RS Standards Status and Descriptions, and Collaboration Efforts. Lou Gullo June 9, 2010

Introduction to Conformity Assessment and ISO/CASCO Tool Box

Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems

Synergies of the Common Criteria with Other Standards

ISO/IEC TR TECHNICAL REPORT

ISO/IEC INTERNATIONAL STANDARD

Integration Technologies Group, Inc. Uncompromising Performance

ISO/IEC JTC 1 N 11326

ISO/IEC INTERNATIONAL STANDARD

Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC :2011

The Analysis and Proposed Modifications to ISO/IEC Software Engineering Software Quality Requirements and Evaluation Quality Requirements

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Requirements for bodies certifying products, processes and services

ISO/IEC INTERNATIONAL STANDARD. Information technology Cloud computing Overview and vocabulary

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

Software engineering Guidelines for the application of ISO 9001:2008 to computer software

ISO/IEC TR TECHNICAL REPORT. Software engineering Product quality Part 4: Quality in use metrics

ISO/IEC INTERNATIONAL STANDARD. Software engineering Software measurement process. Ingénierie du logiciel Méthode de mesure des logiciels

ISO/IEC INTERNATIONAL STANDARD. Information technology Guideline for the evaluation and selection of CASE tools

An Information Model for Software Quality Measurement with ISO Standards

standards and so the text is not to be used for commercial purposes, gain or as a source of profit. Any changes to the slides or incorporation in

B C ISO/IEC TR TECHNICAL REPORT

ISO/IEC INTERNATIONAL STANDARD. Information technology Systems and software engineering FiSMA 1.1 functional size measurement method

Sýnishorn ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

This document is a preview generated by EVS

ISO/IEC Information technology Security techniques Code of practice for information security controls

SC22/WG20 N677 Date: May 12, 1999

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements

This document is a preview generated by EVS

INTERNATIONAL STANDARD

ISO/IEC Status Report to T10

Information technology Security techniques Application security. Part 5: Protocols and application security controls data structure

INTERNATIONAL STANDARD

ISA99 - Industrial Automation and Controls Systems Security

GUIDE 63. Guide to the development and inclusion of safety aspects in International Standards for medical devices

ISO/IEC INTERNATIONAL STANDARD. Software engineering Product evaluation Part 3: Process for developers

ISO/IEC INTERNATIONAL STANDARD

SC22/WG20 N751 Date: June 29, 2000

COPANT ANNUAL ASSEMBLY XXX PASC MEETING Together towards Standardization. Cartagena de Indias, Colombia April 22 to 27, 2007

ISO/IEC JTC 1 N

ISO/IEC JTC 1 N 11737

ISA99 - Industrial Automation and Controls Systems Security

ISO/IEC TR TECHNICAL REPORT. Software Engineering Guide to the Software Engineering Body of Knowledge (SWEBOK) IEEE

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management

ISO INTERNATIONAL STANDARD. Condition monitoring and diagnostics of machines General guidelines on using performance parameters

Information technology - Security techniques - Privacy framework

Information technology Security techniques Information security controls for the energy utility industry

Transcription:

ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3040 2004-05-12 Document Type Title Source Report ISO/IEC JTC 1/SC7 WG9 Report to the Brisbane Plenary AG Meeting WG9 Covener Project Status Final Reference Action ID FYI or ACT Due Date Distribution AG No. of Pages 16 Note Address reply to: ISO/IEC JTC1/SC7 Secretariat École de technologie supérieure Département de génie électrique 1100 Notre Dame Ouest, Montréal, Québec Canada H3C 1K3 secretariat@jtc1-sc7.org www.jtc1-sc7.org

Paul R. Croll Chair, IEEE Software and Systems Engineering Standards Committee Convener, ISO/IEC JTC1/SC7 WG9 pcroll@csc.com An Overview of Standards Supporting System and Software Assurance and the SC7/WG9 Program of Work

How Does Assurance Fit in the System and Software Life Cycles?

Life Cycle Process Framework Standards System Life Cycle ISO/IEC 15288, Systems engineering System life cycle processes Software Life Cycle ISO/IEC 12207, Standard for Information Technology Software life cycle processes SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 3

Assurance in the ISO/IEC 15288 System Life Cycle Process Framework SYSTEM LIFE CYCLE (25) Safety, Security, Integrity ENTERPRISE(5) AGREEMENT (2) PROJECT (7) SYSTEM LIFE CYCLE MANAGEMENT RESOURCE MANAGEMENT QUALITY MANAGEMENT PROJECT PLANNING TECHNICAL (11) ACQUISITION SUPPLY ENTERPRISE ENVIRONMENT MANAGEMENT INVESTMENT MANAGEMENT PROJECT ASSESSMENT PROJECT CONTROL DECISION MAKING RISK MANAGEMENT CONFIGURATION MANAGEMENT INFORMATION MANAGEMENT STAKEHOLDER REQUIREMENTS DEFINITION REQUIREMENTS ANALYSIS ARCHITECTURAL DESIGN IMPLEMENTATION INTEGRATION VERIFICATION TRANSITION VALIDATION OPERATION MAINTENANCE DISPOSAL SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 4

Assurance in the IEEE/EIA 12207 Software Life Cycle Process Framework SOFTWARE LIFE CYCLE (17+1) Safety, Security, Integrity SUPPORTING (8) PRIMARY (5) DOCUMENTATION CONFIGURATION MANAGEMENT QUALITY ASSURANCE VERIFICATION VALIDATION ACQUISITION SUPPLY DEVELOPMENT OPERATION MAINTENANCE JOINT REVIEW AUDIT PROBLEM RESOLUTION ISO/IEC 16085 Risk Management Adapted from: Raghu Singh, An Introduction to International Standards ISO/IEC 12207, Software Life Cycle Processes, 1997. ORGANIZATIONAL (4) MANAGEMENT INFRASTRUCTURE IMPROVEMENT TRAINING TAILORING SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 5

What Standards Organizations Support System and Software Assurance?

Standards Organizations Supporting System and Software Assurance ISO IEC TC176 JTC1 TC56 SC65A Quality Information Technology Dependability Functional Safety SC1 SC7 SC22 SC27 Terminology Software Engineering Language, OS IT Security Techniques ISO IEEE CS IEC FISMA Projects IEEE CS S2ESC Software and Systems Engineering IASC Information Assurance SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 7

Dependability Standards IEC 50-191 Dependability vocabulary IEC 300-1 Programme management IEC 300-2 Programme elements & tasks ISO IEC IEC 300-3-6 SW aspects of dependability Risk Analysis IEC 300-3-9 Risk analysis of technological sys Risk Control ISO/IEC 15026 Integrity levels Achieving Confidence ISO/IEC NWI 61720 Tech. & tools for confidence IEC 1025 Fault tree analysis IEC 812 Failure mode and effects analysis ISO/IEC 15288 System life cycle processes ISO/IEC 12207 SW life cycle processes Risk Management Adapted from James W. Moore, Software Engineering Standards: A User's Road Map, IEEE Computer Society Press, Los Alamitos, CA, 1997 ISO/IEC 16085 Risk Management SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 8

Safety and Security Standards IEC 61508 Functional Safety IEEE/EIA 12207 SW life cycle processes IEEE 1228 SW safety plans Safety IEC Sector-Specific Standards IEC 60880 SW in nuclear power safety systems IEC 60601 Programmable electrical medical systems DO 178B SW considerations in airborne equip certification IEEE CS RTCA ISO/IEC 15408 Common Criteria for IT Security Evaluation ISO/IEC 10181 Security frameworks for open systems ISO/IEC 9796 Digital Security Schemes ISO/IEC 21827 Systems Security Engineering CMM Security ISO IEEE/EIA 12207 SW life cycle processes IEEE P1619 Standard Architecture for Encrypted Shared Storage Media IEEE P1700 Security Architecture for Certification and Accreditation of Information IEEE P2200 Baseline Operating System Security IEEE CS SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 9

SC7 WG9 Overview

WG9 Terms of Reference Development of standards and technical reports for system and software assurance. System and software assurance addresses management of risk and assurance of safety, security, and dependability within the context of system and software life cycles. SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 11

Current NB Membership Australia Japan United Kingdom (Secretariat) United States (Convener) SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 12

SC7 WG9 Current Projects

SC7/WG9 Current Projects Revision of ISO/IEC 15026 Revision of ISO/IEC 16085 SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 14

SC7 WG9 Business Objectives

Near Term Objectives Complete the revision of ISO/IEC 15026. Complete the revision of ISO/IEC 16085. Determine the viability of the NWI for 61720 and either provide and editor or cancel the NWI. Establish liaisons with IEC TC56, TC65A, JTC1/SC27 and any other standards bodies whose program of work relates to system and software assurance, for the purposes of harmonization and collaboration on a unified body of work to meet users needs. Establish a Study Group to determine the derived system and software assurance requirements from ISO/IEC 15288, ISO/IEC 12207, and ISO/IEC 15026, and to recommend requirements for the development, modification, adoption, or reference of supporting standards. Expand the membership of WG9 to include participation from additional national bodies. SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 16