ISO27001:2022 – A8.26

Application security requirements

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.26

This ISO27001 control requires you to identify the security requirements within applications that you are developing or that you have acquired.

The purpose is to ensure that you identify and address all information security requirements so that you do not place your business or other interested parties at risk. 

What does the standard require?

The standard states that “Information security requirements shall be identified, specified and approved when developing or acquiring applications.” (A8.26 – Application security requirements)

 Note here that there are three aspects to this control, where you shall… 

  • Identify requirements – i.e. what security requirements are needed.
  • Specified – i.e. what security controls you will implement.
  • Approved – i.e. who will sign-off on these controls.

It’s also important to note that this control specifically asks you to consider the above when developing or acquiring applications. This is important because you may believe that because this ISO27001 control sits within the controls related to development, that it is only concerned with the development process. But this is not the case. 

Why is this required?

Imagine your business has decided to purchase a new HR platform to manage all your people data. It will allow managers to store 1-2-1 meetings, sickness and absence information, policies and procedures can easily be shared and it’s all in one easy platform that has a plethora of reports for easy consumption.

 This is a system that may be rich in features and benefits, but weak security. How is the data separated? What are the access controls? Where is the data stored? How is it backed-up? We discussed the use of Cloud services in ISO27001 Annex A control A5.23 (Information Security for use of Cloud Services). So were you involved in the discussion when you identified, specified, and approved the application’s security requirements?

 Of course, this is just as important when you are the ones developing the system. When developing the application, it is important to identify the security requirements from the outset, as neglecting to do so could increase the cost of development and implementation. It could lead to security breaches at later point, which could affect your reputation and cost you more money.

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

What do you need to do?

You need to understand how new applications are developed or selected, and ensure that part of the process includes the identification, specification and approval of security requirements.

 Speak to the team responsible for implementing new systems to understand how this currently happens, and then develop a simple process which includes the key steps in this control. 

 

Identification

Where in the process of identifying the need for an application are the security requirements outlined? Place this step at the start of the process, as early as possible so that people are thinking about security from the outset (keep in mind the principle privacy by design and default).

 

Specification

Once you have identified the need for security, you need to be specific about what the control looks like. For example you may identify the need for passwords to be used to access a system, but here you will specify how complex the passwords need to be, if they will expire, and how passwords will be stored.

 

Approval

At the end of the process you need to see that these specific requirements have been implemented, and there must be some form of approval and sign-off. This might be before or after the testing phase, but it should still pass a security approval stage, not simply a functionality testing step.

  

Difficulty rating

We rate this a 2 out of 5 difficulty rating. This control is about formalising something that most likely already happens instinctively in your business. Although specification of the requirements can be technical, this is actually a control that is concerned with the process of identifying, specifying and approving security requirements that meet the needs of the business and interested parties.  This is a fine balance, and that is the technical difficulty in this control.

 

Q&A

Do I need a policy?

No there is no need for a policy, or even a documented process. Of course, it is always helpful to have a documented process flow which you can follow, as this helps communicate to new team members what is needed when applications are selected or developed.  But a documented process or policy is not mandatory.

 

How can I evidence this control is in place?

The auditor is going to need to see that application security requirements are identified and this might be evidenced through formal project initiation documents (PIDs) or minuted project meetings and workshops.  You need to demonstrate that security requirements have been identified during the process of selecting or developing the application. This could include a list of security requirements that you provide to the development team, which is their ‘pick list’. 

 

Finally, the auditor is going to need to see some form of approval process, where someone is held accountable for agreeing the use of an application or deployment of a new system. MRT members could be responsible for approving security requirements, or it could be the function that will use the system.  Dependent upon the size and complexity of your business, this can be as informal as an email which approves the security requirements or a formal Change Advisory Board (CAB).

 

As with all ISO27001 controls we simply ask you to consider what is appropriate for your business, and what is acceptable. Don’t over complicate this, because no one will follow it, and no one will thank you for it.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.26 – Application security requirements