Skip to content
compliancebase
ISO 27001A.8 — Test information

A.8.33

Test information

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Select, protect, and manage test information appropriately for the testing purpose and classification.

Points of focus

  • Prefer synthetic/masked data
  • Authorize any prod copies
  • Protect test datasets
  • Delete when finished

Implementation notes

Default to synthetic fixtures. Automate masking for staging refreshes. Require ticket approval for any prod snapshot to non-prod with expiry. Scrub secrets from fixtures. Assign a named owner in the SoA, tie operating evidence to test data procedure, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show masking pipeline and that staging does not contain raw customer credentials.

Evidence auditors typically request:

  • Test data procedure
  • Masked refresh job
  • Approval tickets for prod data use
  • Deletion records

Common gaps

  • Unmasked prod DB in shared staging
  • Test data retained indefinitely
  • Contractors with full prod clones

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.33This control
SOC 2CC6.1Related SOC 2 themes (CC6.1) — map in your crosswalk; not identical requirements.
GDPRArticle 5, Article 32Related GDPR themes (Article 5, Article 32) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Aim for it; when realism requires prod-like data, mask aggressively.

Using real personal data for testing needs lawful basis and minimization — prefer anonymization.

Masking techniques implement this control in practice.

Even without owned data centers, test information still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with test data procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above