25 min

Raising the Bar - Mainstreaming CERT C Secure Coding Rules Software Engineering Institute (SEI) Podcast Series

    • Technology

An essential element of secure coding in the C programming language is a set of well-documented and enforceable coding rules. The rules specified in this Technical Specification apply to analyzers, including static analysis tools, and C language compiler vendors that wish to diagnose insecure code beyond the requirements of the language standard. All rules are meant to be enforceable by static analysis. The application of static analysis to security has been done in an ad hoc manner by different vendors, resulting in nonuniform coverage of significant security issues. This specification enumerates secure coding rules and requires analysis engines to diagnose violations of these rules as a matter of conformance to this specification. In this podcast, Robert Seacord, the leader of CERT's Secure Coding Initiative, discusses the 7-year journey resulting in the selection of 46 coding rules, derived from the CERT C Secure Coding Standard, for this new technical specification.   Listen on Apple Podcasts.

An essential element of secure coding in the C programming language is a set of well-documented and enforceable coding rules. The rules specified in this Technical Specification apply to analyzers, including static analysis tools, and C language compiler vendors that wish to diagnose insecure code beyond the requirements of the language standard. All rules are meant to be enforceable by static analysis. The application of static analysis to security has been done in an ad hoc manner by different vendors, resulting in nonuniform coverage of significant security issues. This specification enumerates secure coding rules and requires analysis engines to diagnose violations of these rules as a matter of conformance to this specification. In this podcast, Robert Seacord, the leader of CERT's Secure Coding Initiative, discusses the 7-year journey resulting in the selection of 46 coding rules, derived from the CERT C Secure Coding Standard, for this new technical specification.   Listen on Apple Podcasts.

25 min

Top Podcasts In Technology

Lex Fridman Podcast
Lex Fridman
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Acquired
Ben Gilbert and David Rosenthal
Deep Questions with Cal Newport
Cal Newport
In Her Ellement
Boston Consulting Group BCG
Hard Fork
The New York Times

More by Carnegie Mellon University

Software Engineering Institute (SEI) Podcast Series
Members of Technical Staff at the Software Engineering Institute
SEI Shorts
Members of Technical Staff at the Software Engineering Institute
Make It Real
CMU Engineering
Software Engineering Institute (SEI) Webcast Series
SEI Members of Technical Staff
SEI Cyber Talks
Members of Technical Staff