ISO27001:2022 – A8.33
Test Information
Want to fast track your ISO 27001 journey?
Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).
Introduction to ISO 27001 – A8.33
The purpose of ISO 27001 – A8.33 control is ensure that information used in testing is first of all relevant, and secondly that it is protected. The importance of testing systems was established earlier, when discussing the ISO27001 Annex A control A8.29 (Security testing in development and acceptance), but in this control the need is to establish controls around the test information itself.
What does the standard require?
The standard states that “Test information shall be appropriately selected, protected and managed.” (A8.33 – Test information)
Nore here that the ISO27001 control expects that test information is appropriately;
- Selected – i.e. Where is the information coming from?
- Protected – i.e. – What security controls do you apply to the information?
- Managed – e.g. – Identify who is responsible for the management of the information.
Why is this required?
Testing applications and systems is an important part of your software development lifecycle, which was established when you looked at ISO27001 Annex A control A8.25 (Secure development lifecycle) and Annex A control A8.29 (Security testing in development and acceptance).
As discussed in ISO27001 Annex A control A8.31 (Separation of development, test and production environments), test environments should be separate from development and production environments. But when this happens, controls surrounding test environments are often less stringently applied, which can lead to data breaches, compliance issues and cyber attack.
From controlling access to the test environment to ensuring the data is erased before test environments are decommissioned the risk of having data in two places at once, means you are increasing the risk of a breach.
It is also important to note that from a General Data Protection Regulation (GDPR) and UK Data Protection perspective, you can’t use live data in a test environment without letting people know that is what you’re doing. Therefore, if you do use live data for these reasons, then you need to let people know, and you should ensure you have good security controls in place to protect it.
Testing systems is essential for the development of high-quality products and services. Ensuring you’re using reliable test data ensures you can trust the system to operate as expected in the live environment. But the selection and protection of that test data must be as carefully applied, as it is for the live environment.
What the auditor is looking for
For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;
- Data Classification (of the test data) (A5.12 – Classification of information)
- Steps within the software development lifecycle for testing (A8.25 – Secure development lifecycle)
- How testing is carried out A8.29 (Security testing in development and acceptance)
- Management Review Team (MRT) meeting minutes.
- Risk Register.
What do you need to do?
First, take a look at your Data Classification scheme and ensure ‘Test Data’ is included. You need to establish how test data has been categorised, and ensure it is at the correct level. The best way to do this is to consider…
- What test data is used?
- How is it selected?
- How much test data is there?
- How often it is refreshed?
- When is it deleted?
Review your approach to software development by carefully applying the ISO27001 Annex A control, A8.25 (Secure development lifecycle). Pay careful attention to what it says in the areas which details the testing phase.
Speak to your development team in order to answer the questions above, as this will help you identify any risks to the data you’re using. Remembering that the significance of the risks will be determined by the criticality of the data used in testing. For example, if you use personal data in the test environment, this raises additional risks and issues, and perhaps you will need to implement a process to ensure data is pseudonymised (see below).
Keep in mind that the control is expecting you to determine how test information is;
- Selected – Relevant and appropriate data should be collected.
- Protected – Appropriate security controls need to be applied.
- Managed – Someone is responsible for test data and any associated risks.
Answer these questions and you won’t go far wrong. But remember, implement any additional security controls you think are needed for the test environment. However, it is more likely that you will simply need to ensure that you consider the test environment in all other ISO27001 controls. For example, ensuring test environments hardware is configured securely as it would be for live environments. Ensure the data classification considers test environments(s). And ensure that access controls, and data retention processes are followed for all assets.
Difficulty rating
We rate this a 1.5 out of 5 difficulty rating. The difficulty in this control is that you will need to review a range of other ISO27001 Annex A controls and ensure that ‘test information’ is carefully considered.
Q&A
What is Pseudonymised Data?
Pseudonymisation of data is something which the GDPR determines is a way for organisations to reduce the risks to the data subjects concerned and help controllers and processors to meet their data-protection obligations.
Article 4(5) of the GDPR states that pseudonymisation’ means the “processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.”
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.
Fastback your journey to ISO27001 and buy our Policies to get started TODAY!
Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!
