<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Other technical information on Documentation - V2</title><link>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/</link><description>Recent content in Other technical information on Documentation - V2</description><generator>Hugo</generator><language>en</language><atom:link href="https://doc.castsoftware.com/export-v2/sizing/other-technical-information/index.xml" rel="self" type="application/rss+xml"/><item><title>Java SE 8 - Java SE 11 - OpenJDK support for CAST AIP</title><link>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/java-se-8-java-se-11-openjdk-support-for-cast-aip/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/java-se-8-java-se-11-openjdk-support-for-cast-aip/</guid><description>&lt;p&gt;CAST AIP relies on the use of the Java Runtime Environment (JRE) or the Java Development Kit (JDK) to function and CAST therefore fully understands that the change in &lt;strong&gt;&lt;a href="https://www.oracle.com/technetwork/java/java-se-support-roadmap.html"&gt;Oracle&amp;rsquo;s licensing policy&lt;/a&gt;&lt;/strong&gt;, will have a significant impact on you, our customers. In short, CAST will continue to support the use of &lt;strong&gt;Oracle Java SE 8&lt;/strong&gt; for CAST AIP, but CAST will also offer you the option to use &lt;strong&gt;Java SE 11&lt;/strong&gt; either through &lt;strong&gt;Oracle&lt;/strong&gt; or an &lt;strong&gt;OpenJDK provider&lt;/strong&gt;. In detail:&lt;/p&gt;</description></item><item><title>Supported character sets for all AIP products and tools</title><link>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/supported-character-sets-for-all-aip-products-and-tools/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/supported-character-sets-for-all-aip-products-and-tools/</guid><description>&lt;h2 id="supported-languages-with-unicode-for-analysis"&gt;Supported languages with Unicode for analysis&lt;/h2&gt;
&lt;p&gt;The supported languages with Unicode are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Albanian&lt;/li&gt;
&lt;li&gt;Belarusian&lt;/li&gt;
&lt;li&gt;Bosnian&lt;/li&gt;
&lt;li&gt;Bulgarian&lt;/li&gt;
&lt;li&gt;Catalan&lt;/li&gt;
&lt;li&gt;Chinese&lt;/li&gt;
&lt;li&gt;Croatian&lt;/li&gt;
&lt;li&gt;Czech&lt;/li&gt;
&lt;li&gt;Danish&lt;/li&gt;
&lt;li&gt;Dutch&lt;/li&gt;
&lt;li&gt;Estonian&lt;/li&gt;
&lt;li&gt;Faroese&lt;/li&gt;
&lt;li&gt;Finnish&lt;/li&gt;
&lt;li&gt;French&lt;/li&gt;
&lt;li&gt;German&lt;/li&gt;
&lt;li&gt;English&lt;/li&gt;
&lt;li&gt;Greek&lt;/li&gt;
&lt;li&gt;Greenlandic Inuktitut&lt;/li&gt;
&lt;li&gt;Hungarian&lt;/li&gt;
&lt;li&gt;Icelandic&lt;/li&gt;
&lt;li&gt;Japanese - note that we do not support:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://en.wikipedia.org/wiki/Extended_Unix_Code"&gt;EUC-JP&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;ISO_2022_JP_3&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Irish&lt;/li&gt;
&lt;li&gt;Italian&lt;/li&gt;
&lt;li&gt;Latvian&lt;/li&gt;
&lt;li&gt;Lithuanian&lt;/li&gt;
&lt;li&gt;Luxembourgish&lt;/li&gt;
&lt;li&gt;Macedonian&lt;/li&gt;
&lt;li&gt;Maltese&lt;/li&gt;
&lt;li&gt;Moldovan&lt;/li&gt;
&lt;li&gt;Norwegian&lt;/li&gt;
&lt;li&gt;Polish&lt;/li&gt;
&lt;li&gt;Portuguese&lt;/li&gt;
&lt;li&gt;Romanian&lt;/li&gt;
&lt;li&gt;Russian&lt;/li&gt;
&lt;li&gt;Serbian&lt;/li&gt;
&lt;li&gt;Slovak&lt;/li&gt;
&lt;li&gt;Slovenian&lt;/li&gt;
&lt;li&gt;Spanish&lt;/li&gt;
&lt;li&gt;Swedish&lt;/li&gt;
&lt;li&gt;Turkish&lt;/li&gt;
&lt;li&gt;Ukrainian&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Any non-supported character that is present in the source code file encoded with one of the supported encodings, will be converted to an arbitrary supported character by CAST. The impact on the analysis result of this conversion depends on the situation in which the conversion occurs and on the character to which the conversion occurred. Therefore, the impact is unpredictable in a general way as for example:&lt;/p&gt;</description></item><item><title>Supported Security Standards</title><link>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/supported-security-standards/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://doc.castsoftware.com/export-v2/sizing/other-technical-information/supported-security-standards/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Info&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;: this page describes the security standards that CAST supports via the standard CAST AIP Quality Model.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;
&lt;p&gt;CAST AIP provides support for a wide range of security rules that are established by leading industry research and standards on security vulnerabilities. These security rules are originated from established standards such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Open Web Application Security Project (OWASP) Top 10&lt;/strong&gt; - &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project"&gt;OWASP Top 10&lt;/a&gt;&lt;/strong&gt; provides a list of the 10 most critical web application security risks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Common Weakness Enumeration (CWE) Top 25&lt;/strong&gt; – &lt;strong&gt;&lt;a href="http://cwe.mitre.org/top25/"&gt;CWE/SANS Top 25 Most Dangerous Software Errors&lt;/a&gt;&lt;/strong&gt; is a list of the most widespread and critical errors that can lead to serious vulnerabilities in software.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Payment Card Industry Data Security Standard (PCI DSS)&lt;/strong&gt; - &lt;strong&gt;&lt;a href="https://www.pcisecuritystandards.org/security_standards/index.php"&gt;PCI DSS&lt;/a&gt;&lt;/strong&gt; provides an actionable framework for developing a robust payment card data security process.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consortium for IT Software Quality (CISQ) / OMG Automated Source Code Security Measure Standard&lt;/strong&gt; -MITRE has participated in the CISQ initiative to specify an automated source code security measurement standard, derived from the CWE Top 25 by focusing on automatable measurements. Please also refer to MITRE own communication about their work with the CISQ:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="http://cwe.mitre.org/news/index.html#september172015_CWE_Mentioned_in_CISQ_Press_Release_Announcing_New_Specifications_for_Measuring_Structural_Quality_of_Software"&gt;http://cwe.mitre.org/news/index.html#september172015_CWE_Mentioned_in_CISQ_Press_Release_Announcing_New_Specifications_for_Measuring_Structural_Quality_of_Software&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="http://cwe.mitre.org/documents/advances_in_information_assuarance_standards.pdf"&gt;http://cwe.mitre.org/documents/advances_in_information_assuarance_standards.pdf&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;International Organization for Standardization - ISO-5055&lt;/strong&gt; - &lt;strong&gt;&lt;a href="https://www.iso.org/standard/80623.html"&gt;https://www.iso.org/standard/80623.html&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CAST documents its rule sets in the &lt;strong&gt;&lt;a href="https://technologies.castsoftware.com/rules"&gt;structural rule portal&lt;/a&gt;&lt;/strong&gt;. Rules can be browsed according to the standard they meet:&lt;/p&gt;</description></item></channel></rss>