A.8.26
    Technological Controls

    Application security requirements

    Information security requirements should be identified, specified and approved when developing or acquiring applications.

    Purpose

    To ensure security is built into applications from requirements through implementation.

    Implementation Guidance

    Define security requirements early in project lifecycle

    Include input validation, authentication, and authorization requirements

    Specify encryption and data protection requirements

    Define logging and monitoring requirements

    Validate security requirements are implemented

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.26 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.26 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.26 Application security requirements. Built for compliance professionals.

    Try ISMS Copilot free