ISO 27001 Secure Development Policy

0% found this document useful (0 votes)
192 views4 pages
This document outlines ABC Ventures Ltd's secure development policy. The policy applies to all internal and external engineers and developers working on ABC's business critical and confident…

Uploaded by

Adaa Jarso
  • Secure Development Policy Introduction
  • Technical and Security Controls
  • Test Data and Third-Party Acquisitions

Secure Development Policy

Version 1.0

Policy Owner: Compliance


Effective Date: Jan 31, 2022

1. Purpose
To ensure that information security is designed and implemented within the development
lifecycle for applications and information systems.

2. Scope
All ABC Ventures Ltd, (dba ABC ) applications and information systems that are business
critical and/or process, store, or transmit Confidential data. This policy applies to all internal and
external engineers and developers of ABC software and infrastructure.

3. Policy
This policy describes the rules for the acquisition and development of software and systems that
shall be applied to developments within the ABC organization.

4. System Change Control Procedures


Changes to systems within the development lifecycle shall be controlled by the use of formal
change control procedures. Change control procedures and requirements are described in the
ABC Operations Security Policy.
Significant code changes must be reviewed and approved by the Head of Engineering before
being merged into any production branch in accordance with the Check In Process found here:
[Link]

6. Software Version Control


All ABC software is version controlled and synced between contributors (developers). Access to
the central repository is restricted based on an employee’s role. All code is written, tested, and
saved in a local repository before being synced to the origin repository.

7. Technical Review of Applications after Operating


Platform Changes
When operating platforms are changed, business critical applications shall be reviewed and
tested to ensure that there is no adverse impact on organizational operations or security.

8. Restrictions on Changes to Software Packages


Modifications to third-party business application packages shall be discouraged, limited to
necessary changes and all changes shall be strictly controlled.

9. Secure System Engineering Principles


Principles for engineering secure systems shall be established, documented, maintained and
applied to any information system implementation efforts.
Engineering style guides and technical references can be found in the Development Process
pages here: [Link] and
[Link]
Software developers are expected to adhere to ABC ’ coding standards throughout the
development cycle, including standards for quality, commenting, and security.

10. Secure Development Environment


ABC shall establish and appropriately protect secure development environments for system
development and integration efforts that cover the entire system development life cycle.

11. System Security Testing


Testing of security functionality shall be carried out during development. No code shall be
deployed to ABC production systems without documented, successful test results.

12. System Acceptance Testing


Acceptance testing programs and related criteria shall be established for new information
systems, upgrades and new versions.
Prior to deploying code, a Release Checklist MUST be completed which includes a checklist of
all Test Plans which show the completion of all associated tests.

13. Protection of Test Data


Test data shall be selected carefully, protected and controlled. Confidential customer data shall be
protected in accordance with all contracts and commitments. Customer data shall not be used for
testing purposes without the explicit permission of the data owner and the Head of Engineering.

14. Acquisition of Third-Party Systems and Software


The acquisition of third-party systems and software shall be done in accordance with the
requirements of the ABC Third-Party Management Policy.

15. Exceptions
Requests for an exception to this Policy must be submitted to the Head of Engineering for
approval.

16. Violations & Enforcement


Any known violations of this policy should be reported to the Head of Engineering. Violations
of this policy can result in immediate withdrawal or suspension of system and network privileges
and/or disciplinary action in accordance with company procedures up to and including
termination of employment.

Version
Date
Description
Author
Approved by
1.0
31-Jan-2022
First Version
SVP, Compliance
Chief Compliance Officer

Common questions

Powered by AI

Acceptance testing ensures that new information systems, upgrades, and versions meet specified criteria before deployment. The policy mandates a Release Checklist, which includes test plans showing the completion of all associated tests, as a formal procedure to ensure all functional and security requirements are met, preventing potential failures post-deployment .

The policy requires that the acquisition of third-party systems and software adhere to the ABC Third-Party Management Policy. This underscores the necessity of evaluating third-party solutions to ensure they meet security and compliance standards, thereby reducing risks associated with third-party integrations .

System security testing involves verifying the security functionality during development. The policy specifies that no code can be deployed to production systems without documented successful test results. This is crucial to ensure that security vulnerabilities are identified and mitigated before software deployment, thus protecting sensitive data and maintaining system integrity .

The policy mandates the use of formal change control procedures to manage system changes within the development lifecycle. These processes are necessary to maintain the security and stability of systems by ensuring that all changes are reviewed, approved, and documented to prevent unauthorized alterations and potential security breaches .

The Secure Development Policy integrates information security by establishing a set of rules and procedures that must be followed throughout the development lifecycle of applications at ABC Ventures Ltd. These include the use of formal change control procedures to manage changes to systems, ensuring that software is version controlled and synced between contributors, and enforcing the review and testing of applications after operating platform changes to assess their impact on operations and security .

The Secure Development Policy requires that test data be carefully selected, protected, and controlled. Specifically, confidential customer data must be safeguarded according to all contracts and commitments, and cannot be used for testing without the explicit permission of the data owner and the Head of Engineering .

The policy discourages modifications to third-party business application packages, allowing them only when necessary and ensuring all changes are strictly controlled. This restriction is significant as it helps maintain the integrity and security of software, minimizing risks associated with unauthorized or poorly managed changes that could introduce vulnerabilities .

The policy enforces access restrictions on the central code repository based on an employee’s role, ensuring that only authorized personnel have access to sensitive codebases. This is a key measure to prevent unauthorized access and potential security breaches .

Violations of the policy can lead to immediate withdrawal or suspension of system and network privileges and/or disciplinary actions up to termination of employment. This underscores the policy’s importance and the necessity of compliance to prevent security breaches and maintain organizational integrity .

The policy establishes that secure system engineering principles must be documented, maintained, and applied to all information system implementations at ABC Ventures Ltd. These principles include adherence to coding standards, quality assurance, commenting, and maintaining security throughout the development cycle .

Secure Development Policy
Version 1.0
 
Policy Owner: Compliance
Effective Date:  Jan 31, 2022
1. Purpose 
To ensure that inf
Significant code changes must be reviewed and approved by the Head of Engineering before 
being merged into any production br
Acceptance testing programs and related criteria shall be established for new information 
systems, upgrades and new versions

You might also like