Skip to content
compliancebase
ISO 27001A.8 — Separation of development, test and production environments

A.8.31

Separation of development, test and production environments

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Separate development, testing, and production environments and control the interaction between them.

Points of focus

  • Environment separation
  • Control promotion paths
  • Protect prod credentials
  • Prevent prod data leakage into lower envs

Implementation notes

Use separate AWS accounts/GCP projects. CI roles deploy; humans break-glass only. Mask data in non-prod (A.8.11). Block network paths from dev to prod data stores. Assign a named owner in the SoA, tie operating evidence to environment architecture doc, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Prove account separation and that normal developer roles cannot change production.

Evidence auditors typically request:

  • Environment architecture doc
  • Separate cloud accounts/projects
  • CI/CD promotion config
  • Data handling rules for lower environments

Common gaps

  • Shared credentials across envs
  • Developers admin on prod
  • Prod dumps in staging

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.31This control
SOC 2CC8.1Related SOC 2 themes (CC8.1) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Prefer hard account boundaries for production.

If so, treat it closer to prod for access and data rules.

A.8.33 covers test information content; A.8.31 is environment separation.

Even without owned data centers, separation of development, test and production environments still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with environment architecture doc, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above