Skip to main content

ISO/IEC 27001:2022 Annex A

ISO/IEC 27001 is the international standard for an information security management system. It is applied to, and certified for, an organization rather than a software product, and its Annex A lists the standard's reference set of controls. This page indexes the Annex A controls that bear on how software is developed.

Requirement groupThemes
5.20 Addressing information security within supplier agreementsT11 Third-party components and supply chain
T13 Vulnerability handling and disclosure
8.8 Management of technical vulnerabilitiesT6 Automated security verification
T13 Vulnerability handling and disclosure
T14 Security updates and supported versions
8.25 Secure development life cycleT1 Documented and applied lifecycle
T2 Requirements and security criteria before implementation
T3 Design and analysis before implementation
8.26 Application security requirementsT2 Requirements and security criteria before implementation
8.27 Secure system architecture and engineering principlesT3 Design and analysis before implementation
8.28 Secure codingT4 Secure coding and code quality
T5 Independent review before a change is accepted
8.29 Security testing in development and acceptanceT6 Automated security verification
T7 Testing and acceptance
8.30 Outsourced developmentT5 Independent review before a change is accepted
T11 Third-party components and supply chain
T15 Accountability for assisted development
8.31 Separation of development, test and production environmentsT10 Separation of development, verification and released code
8.32 Change managementT8 Change control and traceability
8.33 Test informationT7 Testing and acceptance

8.34 Protection of information systems during audit testing is an operator control with no platform-development counterpart.