^

MISRA Myths Busted #2 – Is MISRA C *just* a Safety Standard?

By Andrew Banks - Technical Specialist
7th September 2021
  • Blog
  • MISRA Myths Busted #2 – Is MISRA C *just* a Safety Standard?

The Myth

MISRA C is just a Safety Standard!

The Background

As with earlier editions, in its vision, MISRA C:2012 is linked to the requirement of many safety-related standards for a subset of the C language

Many standards for the development of safety-related software require or recommend the use of a language subset…

This has led some people to conclude, wrongly, that MISRA is only applicable in the safety-domain, but is not applicable in the security-domain.

However, the vision for MISRA C:2012 continues:

… and this can be used to develop any application with high-integrity or high-reliability requirements.

Unfortunately, many people still focus on the safety-related term.

The Reality

At the software level, the non-functional requirements for safety and for security are broadly the same – the software should do what it is supposed to do, without exposing the user or third-parties to vulnerabilities.

Likewise, MISRA C addresses vulnerabilities and undesirable behaviour in C, irrespective of the application.

Subsequent to the publication of MISRA C:2012, the international standards working group responsible for the C language (ISO/IEC JTC1/SC22/WG14) published their own security guidance for users of the C language, ISO/IEC TS 17961.

In a parallel activity, the CERT division of the Software Engineering Institute at Carnegie Mellon University produced the eponymous CERT-C C Secure Coding Standard.

In consequence, MISRA published matrices showing coverage of MISRA C against these two coding standards:

  • Addendum 2 (2016): Coverage of MISRA C:2012 against C Secure (ISO/IEC TS 17961:2013)
  • Addendum 3 (2018): Coverage of MISRA C:2012 against CERT-C

These show that, with few exceptions, MISRA C meets the requirements specified in ISO/IEC TS 17961 and CERT-C.  Additionally, MISRA has also published Amendment 1, adding additional security guidance.

Conclusion

MISRA C … can be used to develop any application with security, high-integrity or high-reliability requirements.

Acknowledgements

The MISRA Logo

The MISRA Consortium

MISRA, MISRA C and the triangle logo are registered trademarks owned by The MISRA Consortium Limited.

Other product or brand names are trademarks or registered trademarks of their respective holders.

Further reading

About the Author
Andrew Banks

Andrew Banks is a Technical Specialist at LDRA with more than 30 years’ experience of high-integrity real-time/embedded software development.

A Chartered Fellow of the British Computer Society, he graduated from the University of Lancaster in 1989, and has spent most of his career within the aerospace, defence and automotive sectors.

Andrew is committed to standards development – he has been involved with MISRA since 2007 and has been Chairman of the MISRA C Working Group since early 2013; he is the Chairman of the BSI “Software Testing” Working Group; and an active participant in other BSI, ISO, IET and SCSC work, including the 2nd Edition of ISO 26262.

FREE 30 Day
TRIAL

Email Us

Email: info@ldra.com

Call Us

EMEA: +44 (0)151 649 9300

USA: +1 (855) 855 5372

INDIA: +91 80 4080 8707

Connect with LDRA