首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 CSA/ANSI T200:22
到馆提醒
收藏跟踪
购买正版
Evaluation of software development and cybersecurity programs 软件开发和网络安全计划的评估
发布日期: 2022-04-26
前言这是CSA/ANSI T200《软件开发和网络安全计划评估》的第一版。本标准由运营安全技术委员会和信息和通信技术战略指导委员会管辖下的网络安全验证小组委员会编制,并已由技术委员会正式批准。本标准是根据加拿大标准委员会对加拿大国家标准的要求制定的。 CSA集团已将其发布为加拿大国家标准。本标准已被美国国家标准协会(ANSI)批准为美国国家标准。范围1.1本标准描述了评估组织的产品软件和网络安全控制成熟度的方法。本标准为评估人员和供应商提供了一种方法,以确定组织和正在开发的产品/解决方案的控制成熟度,而不考虑解决方案的垂直性。它涵盖了整个产品系统生命周期,从概念到全面调试,直到生命结束。 它支持有效的执行业务决策,为网络安全建立全面的成熟度模型方法。1.2本标准适用于所有物联网和相关产品/解决方案。1.3在本标准中,“应”用于表示要求,即用户为遵守本标准而有义务满足的规定;“宜”用于表示建议或建议但不需要的建议;“may”用于表示一个选项或在标准范围内允许的选项。 注释随附条款不包括要求或替代要求;随附条款的注释旨在与文本中的解释性或信息性材料分开。表和图的注释被视为表或图的一部分,可以作为要求编写。附录被指定为规范性(强制性)或信息性(非强制性)以定义其预期应用。
PrefaceThis is the first edition of CSA/ANSI T200, Evaluation of software development and cybersecurity programs. This Standard was prepared by the Subcommittee on Cybersecurity Verification, under the jurisdiction of the Technical Committee on Operational Security and the Strategic Steering Committee on Information and Communication Technology, and has been formally approved by the Technical Committee. This Standard has been developed in compliance with Standards Council of Canada requirements for National Standards of Canada. It has been published as a National Standard of Canada by CSA Group. This Standard has been approved by the American National Standards Institute (ANSI) as an American National Standard.Scope1.1 This Standard describes a methodology for assessing the product software and cybersecurity control maturity of an organization. This Standard provides the evaluators and vendors a method to determine the control maturity of the organization and products/solutions being developed regardless of solution vertical. It covers the entire product system life cycle from conception to full commissioning and until the end of life. It supports effective executive business decisions that establish a comprehensive maturity model approach to cybersecurity.1.2 This Standard is applicable to all IoT and related products/solutions.1.3 In this Standard, "shall" is used to express a requirement, i.e., a provision that the user is obliged to satisfy in order to comply with the Standard; "should" is used to express a recommendation or that which is advised but not required; and "may" is used to express an option or that which is permissible within the limits of the Standard. Notes accompanying clauses do not include requirements or alternative requirements; the purpose of a note accompanying a clause is to separate from the text explanatory or informative material. Notes to tables and figures are considered part of the table or figure and may be written as requirements. Annexes are designated normative (mandatory) or informative (non-mandatory) to define their intended application.
分类信息
发布单位或类别: 加拿大-加拿大标准协会
关联关系
研制信息
相似标准/计划/法规
现行
CAN/CSA Q396.1.1-89(R1997)
Quality Assurance Program for the Development of Software Used in Critical Applications
关键应用软件开发的质量保证计划
2000-06-05
现行
CAN/CSA Q396.2.1-89(R1997)
Quality Assurance Program for the Development of Software Used in Noncritical Applications
非关键应用软件开发的质量保证计划
2000-05-29
现行
GB/T 43848-2024
网络安全技术 软件产品开源代码安全评价方法
Cybersecurity technology—Evaluation method for open source code security of software products
2024-04-25
现行
AS/NZS ISO/IEC 25041-2013
Systems and software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Evaluation guide for developers, acquirers and independent evaluators
系统和软件工程.系统和软件质量要求和评估(SQuaRE).开发者、收购者和独立评估者评估指南
2013-05-24
现行
BS ISO/IEC 25041-2012
Systems and software engineering. Systems and software Quality Requirements and Evaluation (SQuaRE). Evaluation guide for developers, acquirers and independent evaluators
系统和软件工程 系统和软件质量要求与评估(SQuaRE) 开发商、收购方和独立评估方评估指南
2013-01-31
现行
ISO/IEC 25041-2012
Systems and software engineering — Systems and software Quality Requirements and Evaluation (SQuaRE) — Evaluation guide for developers, acquirers and independent evaluators
系统与软件工程——系统和软件质量要求与评估(SQuaRE)——开发商、收购方和独立评估方评估指南
2012-10-09
现行
CAN/CSA Q396.1.2-89(R1997)
Quality Assurance Program for Previously Developed Software Used in Critical Applications
用于关键应用程序的先前开发软件的质量保证计划
2000-05-25
现行
CAN/CSA Q396.2.2-89(R1997)
Quality Assurance Program for Previously Developed Software Used in Noncritical Applications
用于非关键应用的先前开发软件的质量保证计划
2000-04-25
现行
UNE-ISO/IEC 14598-3-2005
Software engineering -- Product evaluation -- Part 3: Process for developers
软件工程产品评估第3部分:开发人员的过程
2005-07-27
现行
SY/T 6177-2020
气田开发方案及调整方案经济评价技术要求
Economic evaluation requirements of overall development program and adjusting program for gas field
2020-10-23
现行
GOST R ISO/IEC 25041-2014
Информационные технологии. Системная и программная инженерия. Требования и оценка качества систем и программного обеспечения (SQuaRE). Руководство по оценке для разработчиков, приобретателей и независимых оценщиков
信息技术 系统和软件工程 系统和软件质量要求和评估(SQuaRE) 开发商 收购方和独立评估者的评估指南
现行
GB/T 25000.41-2018
系统与软件工程 系统与软件质量要求和评价(SQuaRE) 第41部分:开发方、需方和独立评价方评价指南
Systems and software engineering—Systems and software Quality Requirements and Evaluation (SQuaRE)—Part 41: Evaluation guide for developers, acquirers and independent evaluators
2018-12-28
现行
BS 11/30242229 DC
BS ISO/IEC 25041. Systems and software engineering. Systems and software Quality Requirements and Evaluation (SQuaRE). Evaluation guide for developers, acquirers and independent evaluators
BS ISO/IEC 25041 系统和软件工程 系统和软件质量要求与评估(SQuaRE) 开发商、收购方和独立评估方评估指南
2011-06-29
现行
JJF 1245.2-2019
安装式交流电能表型式评价大纲 软件要求
Program of Pattern Evaluation of Fixed AC Electricity Meters—Software Requirements
2019-12-31
现行
AWWA ACE61746
Teamwork for Process Evaluation and Decision-Making in Developing an Upgrade Program Roadmap
在制定升级计划路线图时 团队合作进行过程评估和决策
2005-06-17
现行
FIPS FIPS-PUB-99 Notice 1-Withdrawn
GUIDELINE: A FRAMEWORK FOR THE EVALUATION AND COMPARISON OF SOFTWARE DEVELOPMENT TOOLS(NO S/S DOCUMENT)
指南:软件开发工具的评估和比较框架(无S/S文档)
1997-07-29
现行
CH-99-16-2
A Simple Software Program for Evaluating Energy Consumption and Operating Costs for Water Heaters
用于评估热水器能耗和运行成本的简单软件程序
现行
AWWA ACE58177
On-Line UV Transmittance: Developing Monitoring Programs and Evaluating Commercially Available Monitors
在线紫外线透射率:开发监测程序和评估商用监测器
2003-06-15
现行
DOD DODI-2015.4
DEFENSE RESEARCH, DEVELOPMENT, TEST AND EVALUATION (RDT&E) INFORMATION EXCHANGE PROGRAM (IEP)
国防研究、开发、测试和评估(RDT&E)信息交换计划(IEP)
2002-02-07
现行
BS ISO/IEC 13817-1-1996
Information technology. Programming languages, their environments and system software interfaces. Vienna Development Method. Specification language-Base language
信息技术 编程语言及其环境和系统软件接口 维也纳开发方法 规范语言 基础语言
1997-04-15