ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.8: Information security in project management

Information security is to be built into the way projects are managed. Purpose: make sure security risks tied to projects and their deliverables are handled effectively through every stage of the project. Guidance: this applies to every kind of project whatever its size, length, complexity or subject, whether a core business process, ICT, facilities or a support function. The project method should require that security risks are assessed and treated early and at intervals as part of project risk; that security requirements, such as application security (8.26) and intellectual property compliance (5.32), are dealt with early; that risks arising from running the project itself, such as internal and external communications, are handled throughout; and that progress on risk treatment is reviewed and its effectiveness evaluated and tested. Suitable people or bodies, such as a steering committee, check the security work at set stages, and project security responsibilities and authorities are assigned to named roles. Requirements for the product or service are derived from policies and regulation and from threat modelling, incident reviews, vulnerability thresholds and contingency planning, so the design resists known threats. For all project types consider: which information is involved, its classification (5.12) and the business impact of weak security; the confidentiality, integrity and availability needs of the assets; the assurance needed about identities, to set authentication requirements; access provisioning for customers, business users and privileged or technical users including project staff, operators and suppliers; telling users their duties; process-driven needs such as transaction logging, monitoring and non-repudiation; requirements imposed by other controls such as logging or leakage detection interfaces; legal, regulatory and contractual obligations; and the assurance needed that third parties meet the organization's policies, including contract clauses. Other information: waterfall or agile approaches should both support security in a structured way scaled to risk; ISO 21500, ISO 21502 and ISO/IEC 27005 give related guidance.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 53 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 42001:2023 · 6 controls

  • 6.1.4 AI system impact assessment
  • 8.3 AI risk treatment
  • A.5.2 AI system impact assessment process
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.6 AI system life cycle
  • A.6.2.2 AI system requirements and specification

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

FedRAMP High · 4 controls

  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • SA-15 Development Process, Standards, and Tools (SA-15)
  • SA-3 System Development Life Cycle

FedRAMP Moderate · 4 controls

  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • SA-15 Development Process, Standards, and Tools (SA-15)
  • SA-3 System Development Life Cycle

ISO 22301:2019 · 3 controls

  • 6.2 Business continuity objectives and planning to achieve them
  • 8.1 Operational planning and control
  • 8.3.5 Implementation of solutions

ISO 27701:2019 · 3 controls

  • 5.4 Planning
  • 7.4 Privacy by design and privacy by default
  • 8.4 Privacy by design and privacy by default
  • 13.1.10.C.01 13.1.10.C.01 Proportionate risk assessment before migration or decommissioning
  • 13.1.10.C.02 13.1.10.C.02 Required elements of the migration risk assessment
  • 3.3.6.C.04 3.3.6.C.04 Integrate risk assessment into system architectures
  • ISM-0027 Authorisation to operate from authorising officer
  • ISM-1739 Approval of security architecture before development
  • CCM-AIS-04 Secure Application Design and Development
  • CCM-DSP-07 Data Protection by Design and Default

ISO 27001:2022 · 2 controls

  • 5.8 Information security in project management
  • 8.26 Application security requirements
  • CPS230-P26 Assessment of Business and Strategic Decisions on the Risk Profile
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model

C5 (Germany) · 1 control

  • C5-DEV-01 Policies for the development/procurement of information systems
  • CFTC-SS-5 Systems Development and Quality Assurance Category

GDPR · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • 03.16.01 Security Engineering Principles

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

NIST SP 800-218 · 1 control

PCI DSS 4.0 · 1 control

  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.