A.8.31
    Technological Controls

    Separation of development, test and production environments

    Development, testing and production environments should be separated and secured.

    Purpose

    To reduce the risks of unauthorized access or changes to the production environment.

    Implementation Guidance

    Implement separate environments for development, testing, and production

    Control promotion of code between environments

    Use non-production data in test environments

    Restrict access to production environments

    Document environment separation architecture

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.31 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.31 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.31 Separation of development, test and production environments. Built for compliance professionals.

    Try ISMS Copilot free