ISO27001:2022 – A5.8 Information security in project management

Annex 5.8 Information Security in Project Management

ISO27001 is a risk-based management system, and any change within a business can introduce new risks. That’s why ISO 27001 – A5.8 emphasises the importance of including information security considerations within your project management practices.

Information security risks associated with projects and their deliverables should be effectively managed from start to finish.

What does ISO 27001 – A5.8 require?

The standard states that:

“Information security shall be integrated in project management.” (A5.8 Information Security in Project Management)

The key word here is integrated — security must be embedded within your project management methodology, not treated as an afterthought. Concepts like “Security by Design” and “Privacy by Design and Default” should be foundational to your approach.

Why is this required?

Projects often introduce changes to business processes, IT systems, data handling, or physical environments. If not properly assessed, these changes can lead to new information security risks.

For example, one client’s office relocation project involved over 150 desks, PCs, and personal belongings. By performing a risk review at the start, we identified and managed several risks — to both the business and clients — ensuring a smooth and secure transition.

Integrating security into your project management approach ensures that confidentiality, integrity, and availability of information are preserved throughout the project lifecycle.

What the auditor is looking for

The auditor won’t necessarily look for a dedicated policy on this topic, but they will want to see evidence that your projects account for information security risks. Even if you don’t have a formalised project methodology, you should be able to provide:

  • Project documentation: Including project plans, risk assessments, security requirements, and impact assessments.
  • Meeting minutes: Records of discussions and agreed mitigation actions.
  • Email chains: Showing that security has been addressed in project communications.
  • Change management procedures: Evidence that system/process changes are assessed for security impacts.

Not every project needs exhaustive security oversight — use your judgement. The starting point is a simple question: “Will this change introduce risks to our business?”

Q & A

Is this a mandatory control?

No control in ISO27001 is strictly “mandatory,” but it would be difficult to justify this one as “not applicable.” Most organisations undergo change — and significant change constitutes a project that must include security considerations.

How do we start identifying information security risks in projects?

Use a risk assessment methodology during project planning and delivery. Ask:

  • What security risks are associated with this project before it begins?
  • What risks might arise during delivery?
  • What risks might emerge after the project ends?

Log risks in a spreadsheet, assign owners, and ensure mitigation strategies are in place and tracked through to project completion.

Is it possible to get this wrong?

Yes. If you completely ignore information security within your projects, this will likely be flagged as a non-conformity. Make sure information security is covered in deliverables, timelines, and risk assessments.

Difficulty rating

We rate this a 1 out of 5. No technical skills are needed, just a practical approach to managing projects. Small businesses may have informal processes — that’s okay. Just ensure you consider and document security risks where applicable.

More questions?

ISO27001 controls are interconnected. Check our FAQ for further guidance. If you’re still unsure how to apply this control or align your project management with security best practices, get in touch and we’ll be happy to help.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book.. The Real Easy Guide to ISO27001, available on Amazon.

ISO 27001 – A5.8