ISO 27001A.8 — Separation of development, test and production environments
A.8.31
Separation of development, test and production environments
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Separate development, testing, and production environments and control the interaction between them.
Points of focus
- Environment separation
- Control promotion paths
- Protect prod credentials
- Prevent prod data leakage into lower envs
Implementation notes
Use separate AWS accounts/GCP projects. CI roles deploy; humans break-glass only. Mask data in non-prod (A.8.11). Block network paths from dev to prod data stores. Assign a named owner in the SoA, tie operating evidence to environment architecture doc, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Prove account separation and that normal developer roles cannot change production.
Evidence auditors typically request:
- Environment architecture doc
- Separate cloud accounts/projects
- CI/CD promotion config
- Data handling rules for lower environments
Common gaps
- Shared credentials across envs
- Developers admin on prod
- Prod dumps in staging
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.31 | This control |
| SOC 2 | CC8.1 | Related SOC 2 themes (CC8.1) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.31)
Frequently Asked Questions
Prefer hard account boundaries for production.
If so, treat it closer to prod for access and data rules.
A.8.33 covers test information content; A.8.31 is environment separation.
Even without owned data centers, separation of development, test and production environments still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with environment architecture doc, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.