Ok, just a bit of information.
I have seen several people comment that security shouldn't be a part of
the file format specification.
They might need to re-assess that position:
ISO & IEC have a committee called JTC1 (or Joint Technical Committee 1)
that has many subcommittees and working groups assigned with
standardizing systems, process, workflows, etc, as they related to
computers and networks. The following 3 standards were published by
JTC1/SC 27:
ISO/IEC 15408-1:1999 “Information technology -- Security techniques --
Evaluation criteria for IT security -- Part 1: Introduction and general
model
ISO/IEC 15408-1:1999 “Information technology -- Security techniques --
Evaluation criteria for IT security -- Part 2 : Security functional
requirements
ISO/IEC 15408-1:1999 “Information technology -- Security techniques --
Evaluation criteria for IT security – Part 3: Security assurance
requirements
I doubt that the ISO and IEC would bother creating a software security
specification, for operating systems specifically, if there wasn't a
place for security in a specification.
I could be wrong in that, but it is something to think about.
Jaqui