Standards

Authoritative references from ISO, IEEE, and others, grouped by category and linked to the qualities they back.

45 standards across 13 categories.

General

10

Broad software and systems quality/process standards.

IEEE 2857 IEEE guidelines for engineering privacy into software and systems across the development lifecycle, translating privacy-by-design into technical practice. ISO/IEC 14756 Methods for measuring and rating user-oriented performance of computer-based software systems from the user's perspective: response times and throughput. ISO/IEC 25010 The SQuaRE product quality model defining nine characteristics, from functional suitability and performance to security, maintainability, and safety. ISO/IEC 25019 The SQuaRE quality-in-use model describing the outcome of system use through three characteristics: beneficialness, freedom from risk, and acceptability. ISO/IEC 29100 Privacy framework establishing common terminology, actors, and safeguards for processing personally identifiable information across its lifecycle. ISO/IEC 5055 International standard defining four automated source-code quality measures for reliability, security, performance efficiency, and maintainability. ISO/IEC/IEEE 12207 ISO/IEC/IEEE framework defining software life cycle processes across acquisition, development, operation, maintenance, and disposal of software systems. ISO/IEC/IEEE 29119 International software testing standard series defining test processes, documentation, and techniques from small projects to regulated environments. ISO/IEC/IEEE 42010 Framework for creating, evaluating, and comparing architecture descriptions using stakeholders, concerns, viewpoints, views, and documented decisions. ISO/IEC/IEEE 42030 Framework for systematically evaluating software, systems, and enterprise architectures: evaluation processes, methods, criteria, and quality models.

Accessibility

3

Making digital systems accessible to people with disabilities.

Usability

5

Ease of use, learnability, and overall interaction quality.

AI

8

AI/ML lifecycle governance, risk, transparency, and operational control.

Safety

5

Functional safety where failure can cause harm to people, assets, or environment.

Security

13

Information/cyber security, controls, and resilience practices.

CRA EU regulation mandating cybersecurity requirements for products with digital elements across their lifecycle: secure-by-design, vulnerability handling, updates. ETSI EN 304 223 European standard setting baseline cybersecurity requirements for AI models and systems across their lifecycle, complementing the EU AI Act. GDPR EU regulation governing the processing of personal data: individual rights, accountability, and privacy by design for anyone handling EU residents' data. IEC 62443 Series of standards for cybersecurity of industrial automation and control systems, spanning product development, system integration, and operation. ISO 15408 The Common Criteria framework for evaluating IT product security via protection profiles, security targets, and Evaluation Assurance Levels EAL1 to EAL7. ISO/IEC 27001 International standard specifying requirements for an information security management system (ISMS): risk-based establishment, operation, and improvement. ISO/IEC TR 24028 Technical Report surveying trustworthiness in AI systems, cataloguing properties like reliability, robustness, safety, and fairness, plus AI threats. NIST AI RMF NIST voluntary framework for managing AI risks across the system lifecycle, organized around seven trustworthiness characteristics and four functions. NIST PF NIST voluntary tool for managing privacy risk in personal data processing through enterprise risk management, organized around five core functions. NIST SP 800-53 US catalog of security and privacy controls for information systems, providing a risk-based baseline for compliance and continuous monitoring. OWASP ASVS Open OWASP framework of requirement-level security controls for designing, building, and testing web applications and APIs, with three assurance levels. PCI DSS Payment card industry standard defining twelve baseline security requirements to protect cardholder data wherever it is stored, processed, or transmitted. SOC 2 AICPA auditing framework producing a CPA attestation report on a service organization's controls across five Trust Services Criteria.

Privacy

5

Personal data protection, privacy engineering, and governance controls.

Data

4

Data quality concepts and measurable data characteristics.

Sector

10

Vertical or industry-specific standards and regulations.

DICOM International standard for storing, transmitting, and managing medical imaging data across modalities, PACS, and viewers for cross-vendor interoperability. DO-178C The de facto standard for developing and certifying airborne software, defining objective-based assurance levels (DAL A-E) tied to system safety impact. HL7 / FHIR Family of healthcare interoperability standards (V2, CDA, FHIR) for exchanging, integrating, and retrieving health information across organizations. IEC 62304 International standard defining software life cycle processes for medical device software, including standalone Software as a Medical Device (SaMD). IEC 62443 Series of standards for cybersecurity of industrial automation and control systems, spanning product development, system integration, and operation. IHE Healthcare initiative defining integration profiles that combine HL7 and DICOM to solve interoperability problems, verified through Connectathon testing. ISO 26262 Automotive functional-safety standard for electrical and electronic systems, defining a risk-based safety lifecycle and ASIL A to D risk classification. MISRA-C Guidelines defining a safer subset of the C language for safety- and security-critical embedded systems, reducing undefined behavior for higher assurance. PCI DSS Payment card industry standard defining twelve baseline security requirements to protect cardholder data wherever it is stored, processed, or transmitted. SOX US federal law mandating financial reporting accuracy and internal controls (ICFR) for systems that process, store, or report financial data.

Documentation

5

Architecture, user, and lifecycle documentation standards.


Full standards list grouped by category:

General 10

ISO/IEC/IEEE 29119 - Software Testing

#general, #documentation

Accessibility 3

Usability 5

AI 8

Trustworthiness 2

Safety 5

Security 13

Privacy 5

Data 4

Governance 2

Sector 10

Coding 2

Documentation 5

ISO/IEC/IEEE 29119 - Software Testing

#general, #documentation