SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Aspects in A 14.2.5

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Aspects in A 14.2.5

Secure system engineering principles)Can you help me to understand some aspects in the A 14.2.5 of ISO 27002:2013   1. Does the mentioned clause refer to just software development or to the large information system design?   2. What are the main aspects of the clause and how the organization should implement the requirements of this chapter?   3. How the implementation of above mentioned clause can be checked by an auditor and what will be the evidence of implementation of requirements?   Thanks, Aram Arekhtsyan IT Security Specialist
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 12, 2016

1.- You can read in the "Implementation guidance" of the control 14.2.5 the following: "Security should be designed into all architecture layers (business, data, applications and technology) balancing the need for information security with the need for accessibility". So, this control is related to the large information system design, which also include the development of software.

2.- You can use our template to implement this control in your organization (you can see a free version if you click on ³Free Demo² tab) "Secure Development Policy": https://advisera.com/27001academy/documentation/secure-development-policy/. And also you can use this template related to IT procedures "Operating Procedures for Information and Communication Technology" : https://advisera.com/27001academy/documentation/security-procedures-for-it-department/
3.- The auditors will search the documents mentioned above and their records as evidence of implementation.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016