MTCS (Singapore)
16: System acquisitions and development – MTCS (Singapore)

MTCS (Singapore) 16.2: Development, acquisition and release management

Development, acquisition and release management, covering acquisition of applications, systems, databases, infrastructure and services as well as in-house development. Level 1 has eleven items (a to k): secure development rules applied; removal of custom and development accounts, IDs and passwords before release; removal of test data and accounts before production goes live; verification of security against industry standards; separation of development, test and operational environments; controlled changes to software packages; security testing during development; security requirements specified for new or changed systems; and three further items (i to k) beyond ISO/IEC 27001 whose text the held reports do not describe (the 2013 edition's corresponding items included input data validation). Levels 2 and 3 each add one requirement not described in the held material.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.25 Secure development life cycle

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 16: System acquisitions and development – MTCS (Singapore)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.