ISO/IEC 27000 Security Testing in Development and Acceptance, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to security testing in development and acceptance.
Assessment Step
|
1
Security Testing in Development and Acceptance (SecurityTestinginDevelopmentandAcceptance)
Are security testing processes defined and implemented in the development life cycle?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
|
Security Testing in Development and Acceptance
Security testing processes shall be defined and implemented in the development life cycle.
Citations
27001
Annex A, Control 8.29
27002
Section 8.29
|