ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.29: Security testing in development and acceptance

Security testing processes are to be defined and carried out within the development life cycle. Purpose (stated in ISO/IEC 27002:2022): checks that code and applications satisfy security requirements before they reach production. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.29.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 11 controls

  • CA-8 Penetration Testing
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • SA-11 Developer Testing and Evaluation
  • SA-11(1) Developer Testing and Evaluation | Static Code Analysis (SA-11(1))
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SA-3 System Development Life Cycle
  • SI-11 Error Handling
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks

FedRAMP Moderate · 11 controls

  • CA-8 Penetration Testing
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • SA-11 Developer Testing and Evaluation
  • SA-11(1) Developer Testing and Evaluation | Static Code Analysis (SA-11(1))
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SA-3 System Development Life Cycle
  • SI-11 Error Handling
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks

PCI DSS 4.0 · 10 controls

  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.3 6.2.3 Code review before release
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.5.3 6.5.3 Separate pre-production from production

CIS Controls v8 · 9 controls

  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.12 Implement Code-Level Security Checks
  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-16.14 Conduct Threat Modeling
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests

NIST SP 800-218 · 7 controls

NIST SP 800-53 Rev 5 · 7 controls

ISO 27002:2022 · 6 controls

  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.31 Separation of development, test and production environments
  • 8.33 Test information
  • ASBv3-DS-4 Integrate static application security testing into DevOps pipeline
  • ASBv3-DS-5 Integrate dynamic application security testing into DevOps pipeline
  • ASBv3-PV-7 Conduct regular red team operations

C5 (Germany) · 3 controls

  • C5-DEV-06 Testing changes
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service

COBIT 2019 · 3 controls

  • BAI03.07 BAI03.07 Prepare for solution testing
  • BAI03.08 BAI03.08 Execute solution testing
  • BAI07.03 BAI07.03 Plan acceptance tests

EU AI Act · 3 controls

ISO 27701:2019 · 3 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 7.2.5 Privacy impact assessment
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP03 Perform regular penetration testing

CMMC 2.0 · 2 controls

DORA · 2 controls

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.25 Testing of ICT tools and systems

HIPAA Security Rule · 2 controls

ISO 27001:2013 · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-172 · 2 controls

  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • CFTC-SS-5 Systems Development and Quality Assurance Category

ISO/IEC 42001:2023 · 1 control

  • A.6.2.4 AI system verification and validation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.29 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.