ISO/IEC 27000 Security Testing in Development and Acceptance, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to security testing in development and acceptance.
Assessment Step
1
Security Testing in Development and Acceptance (SecurityTestinginDevelopmentandAcceptance)
Are security testing processes defined and implemented in the development life cycle?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Security Testing in Development and Acceptance
Security testing processes shall be defined and implemented in the development life cycle.
Citations
27001
Annex A, Control 8.29
27002
Section 8.29
|