Rejected ISO/IEC 27002 control for SDLC
Suggested text for a new ISO/IEC 27002 control on integrating security into the systems lifecycle Back in February 2011, I proposed to incorporate a new information security control statement concerning integrating security into the systems lifecycle into ISO/IEC 27002 which was being revised by the committee at the time. To set the scene, recall that section 12 of ISO/IEC 27002:2005 covered Information systems acquisition, development and maintenance without mentioning development projects or system lifecycles as such. See what you make of the donor text I provided in Standards New Zealand's submission to ISO/IEC JTC1/SC27 ... ---------------------------------- Control objective To take due account of information security throughout the entire IT systems lifecycle. Implementation guidance While the exact naming, nature and sequence of activities may vary according to different development methods and lifecycle models, appropriate information security activ...