ISO27001:2022 – A8.30

Outsourced development

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.30

If you’re in total control of your development team, and the way they operate then you can rest assured that security principles are contained within your software development lifecycle.

But what do you do if you discover that development has been outsourced to a third party? That’s what this ISO27001 control is focused on.  You need to ensure you have processes in place to control an important aspect of your business. One which may be shrouded in mystery to you.

What does the standard require?

The standard states that “The organisation shall direct, monitor and review the activities related to outsourced system development.” (A8.30 – Outsourced development)

Notice here that this control requires that you;

  • Direct – provide clear instructions and expectations for the service (including security)
  • Monitor – ensuring that this is continually assessed for suitability and effectiveness
  • Review – the service is reviewed to ensure it meets your original expectations

Why is this required?

We spoke to a business who were looking to achieve ISO27001 certification for their products and services, which included a sophisticated Mobile App.

During the review of their development lifecycle, they declared “Oh we don’t have to worry about any of that. We’ve outsourced development to [X] company in [country]. So it’s out of scope.”

Firstly, no it’s not out of scope, because you can’t ‘outsource’ risk.  As this ISO27001 control states, you must direct, monitor and review any activities related to outsourced system development.

Failing to do this means you are trusting an organisation to follow all the principles of security and privacy that are required by a business.  Failure to do this could leave you at risk of data breaches or cyber attacks.  It leaves you at risk of compliance issues, as data and systems are stored in locations that you are unaware of.

We worked with a client who, when asked where the data for their application was stored, responded by saying “Oh that’s down to the outsourced development team in [country].” To put it simply, they didn’t know where their data was.

It’s important to note that if you have been working through the ISO27001 Annex A controls you will have already identified the need for security in earlier controls, such as A5.19 (Information security in supplier relationships). You will also have implemented some form of review process in A5.22 (Monitoring, review and change management of supplier services). And before you began working with them, you will (hopefully) have outlined your expectations in contracts and agreements (as required by A5.20 (Addressing information security within supplier agreements)).

Keep in mind this final point, that by not having clear contracts and agreements in place you could put your entire business at risk.  Imagine the scenario that you outsource the development of a new kind of Artificial Intelligence App that predicts moods, based on the weather.  Without a defined contract in place, who actually owns the intellectual property for this application? What about the code? Who owns that? What happens when the project is over? Have they agreed to hand it over to you and destroy all copies of it? What happens if things go wrong? Could they hold your code to ransom, until the dispute has been settled? Or what happens if they go out of business, mid-way through the project?

We have seen these scenarios playout in real life, and it’s never pleasant, and often leads to business disruption, reputational impact and significant emotional distress. Don’t leave this to chance, just because someone’s website says they are “The best Developer of Mobile Apps in [country]”!

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

When reviewing the contracts in place with the outsourced development business, the auditor will be looking for a number of things, including clauses related to confidentiality and ownership of intellectual property. They might also expect to see some form of statement of work which outlines what work is carried out.

They will also want to see some evidence that they have committed to some form of security and privcy principles and processes.  This might be part of the agreement or statement of work, or part of the project management documentation where you defined the requirements of the engagement.

What do you need to do?

If development has been outsourced then you should arrange a meeting with the relationship owner, and the outsourced delivery team.  Keep in mind that you are not only looking to satisfy the needs of this ISO27001 control, but also other development related controls, such as;

If someone says that the above is not relevant/applicable because you outsource development, then remind them that the above are being addressed by the outsourced provider, but you are still accountable for their implementation.

When you speak to the development team, you’re going to need to satisfy yourself that all the above is in place. If they are a reputable business, they will have been asked these questions a thousand times before so don’t be afraid to ask for evidence of their secure development lifecycle, or how they conduct code reviews.

Take a close look at the contract, agreement and statements of work to establish;

  • Clauses related to confidentiality and non-disclosure
  • Ownership of code and intellectual property
  • Details related to the software development process (including testing processes)
  • Security and data protection principles followed

Review each of the ISO27001 controls, from A8.25 to A8.31 before you arrange your meeting with the developers so that you have a good understanding of what you need to ask.

Remember that the principles of Privacy by Design and Default and Security by Design are not new concepts, and you need to be confident that someone you are trusting to build a platform that you will put YOUR name to, is built well.

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. This control brings us back to supplier management, and is about establishing clear rules of engagement and setting expectations. It’s only a technical control because you need to establish the truth behind what you’re being told. Look for evidence of the controls outlined above being in place.

Q&A

What if we’re using a contractor?

It makes no difference if this is a large outsourced development team, or a single contractor.  In fact, if it is a contractor, then you might look for additional assurances that they are competent for doing the work, or evidence of Professional Indemnity (PI) insurance.  Consider what might happen if they develop an app that exposes thousands of users personal details? Do you think those people, and the Information Commissioners Office (ICO) will be interested in talking to your contractor, or you?

More questions?

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.30 –  Outsourced development