Skip to content
compliancebase
ISO 27001A.8 — Secure development life cycle

A.8.25

Secure development life cycle

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Establish and apply rules for the secure development of software and systems.

Points of focus

  • Define scope and requirements for secure development life cycle
  • Assign ownership and operating cadence
  • Integrate with risk treatment and SoA status
  • Retain dated records proving operation

Implementation notes

Embed security into SDLC stages — threat modeling for major features, secure design reviews, and gated releases. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.

Audit tip: Present the SoA line for A.8.25, the current procedure, and one recent dated operating sample with a named owner.

Evidence auditors typically request:

  • System configuration export or IaC policy screenshots
  • Ticket samples with approver, date, and change outcome
  • Monitoring or scan report covering the observation window
  • Runbook or SOP linked from the SoA implementation summary

Common gaps

  • SoA marks secure development life cycle applicable without dated operating samples
  • Procedure exists but interviews describe a different tribal process
  • Owner unclear or last review older than the stated cadence

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.25This control
SOC 2CC8.1Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.
GDPRArticle 25Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.

Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.

Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above