ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.33: Test information

Information used for testing is to be chosen, protected and managed appropriately. Purpose: keep testing meaningful while protecting the operational information used in it. Guidance: choose test information that makes results reliable while keeping the related operational information confidential, and do not copy sensitive information, including PII, into development and test environments (8.31). When copies of operational information are used for testing, whether in-house or in a cloud service, control access to test environments exactly as for operational ones; require a separate authorization every time operational information is copied into a test environment; log the copying and use to create an audit trail; remove or mask sensitive information used in tests (8.11); and delete operational information from the test environment properly (8.10) as soon as testing ends so it cannot be misused. Store test information securely to prevent tampering that could invalidate results, and use it only for testing. Other information: system and acceptance testing may need large volumes of test data that resemble operational data as closely as possible.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 32 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 6 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications

PCI DSS 4.0 · 5 controls

  • 10.3.2 10.3.2 Audit log files protected from modification
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 6.5.6 6.5.6 Remove test data and accounts before production
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts

ISO/IEC 42001:2023 · 3 controls

  • 7.5.3 Control of documented information
  • A.6.2.4 AI system verification and validation
  • A.7.2 Data for development and enhancement of AI system

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
  • NIST800-SA-11 SA-11 Developer Testing and Evaluation
  • NIST800-SI-14 SI-14 Non-persistence
  • ISM-1274 Production database contents in non-production environments
  • ISM-1420 Production data in non-production environments

ISO 27001:2022 · 2 controls

  • 8.29 Security testing in development and acceptance
  • 8.33 Test information
  • SEC07-BP04 Define scalable data lifecycle management
  • AUCDR-IS-3 Securely manage information assets over their lifecycle

C5 (Germany) · 1 control

GDPR · 1 control

ISO 19011:2018 · 1 control

  • 6.3.1 Performing review of documented information

ISO 27701:2019 · 1 control

ISO/IEC 38500:2024 · 1 control

  • 5.3 Value generation

MTCS (Singapore) · 1 control

  • 161R1-PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.33 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.