ISO 27002:2022 8.29: Security testing in development and acceptance
Requires security testing processes to be defined and implemented within the development life cycle.
What else in your programme already covers this
This control maps to 100 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.2.1 Bespoke and custom software are developed securely, as follows: • Based on industry standards and/or best practices for secure development. • In accordance with PCI DSS (for example, secure authentication and logging). • Incorporating
6.2.3 Custom software reviewed prior to production
6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
6.4.3 All payment page scripts that are loaded and executed in the consumer's browser are managed as follows: • A method is implemented to confirm that each script is authorized. • A method is implemented
6.5.3 Pre-production environments are separated from production environments and the separation is enforced with access controls
CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components
CA-8(2) Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
CM-3(2) Testing, Validation, and Documentation of Changes
SA-11(1) Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of
SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing
SA-15 Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the
SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system
CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components
CA-8(2) Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
CM-3(2) Testing, Validation, and Documentation of Changes
SA-11(1) Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of
SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing
SA-15 Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the
SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system
NIST800-PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
NIST800-SA-15 Development process, standards, and tools
NIST800-SC-38 Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]
NIST800-SI-6 Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defined]; Alert [organization-defined] to failed security and privacy verification tests; and [organization-defined] when anomalies
NIST800-SI-7 Software, firmware, and information integrity
SA-15 Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the
SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system
SA-15 Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.29 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.