ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.4: Access to source code

Requires managed control over who can read and who can write to source code, and equally over development tools and software libraries.

What else in your programme already covers this

This control maps to 41 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 4 controls

  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:
  • SA-10 Developer Configuration Management

FedRAMP Moderate · 4 controls

  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:
  • SA-10 Developer Configuration Management

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 6.5.1 Changes to all system components in the production environment are made according to established procedures that include: • Reason for, and description of, the change. • Documentation of security impact. • Documented change approval
  • 6.5.3 Pre-production environments are separated from production environments and the separation is enforced with access controls
  • 7.2.5 All application and system accounts and related access privileges are assigned and managed as follows: • Based on the least privileges necessary for the operability of the system or application. • Access is limited
  • 8.6.2 Passwords/passphrases for any application and system accounts that can be used for interactive login are not hard coded in scripts, configuration/property files, or bespoke and custom source code
  • ISM-1422 Unauthorised access to the authoritative source for software is prevented.
  • ISM-1816 Unauthorised modification of the authoritative source for software is prevented.
  • ISM-2029 The authoritative source for software restricts the use and import of third-party librarie
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • SA-10 Developer Configuration Management

SOC 2 · 3 controls

  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC2-CC8.1 Change management processes are in place
  • SEC11-BP05 Centralize services for packages and dependencies
  • SEC11-BP07 Regularly assess security properties of the pipelines

C5 (Germany) · 2 controls

NIST SP 800-218 · 2 controls

  • CM-5 Access Restrictions for Change
  • SA-10 Developer Configuration Management

ISO 27001:2022 · 1 control

  • 8.4 Access to source code
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-172 · 1 control

  • 3.4.1e Authoritative Source for Software and Firmware
  • CM-5 Access Restrictions for Change

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.