A.8.27
    Technological Controls

    Secure system architecture and engineering principles

    Principles for engineering secure systems should be established, documented and maintained and applied to information system development activities.

    Purpose

    To ensure systems are designed with security in mind using established security principles.

    Implementation Guidance

    Apply security design principles (defense in depth, least privilege, fail secure)

    Document system architecture and security controls

    Review architecture for security weaknesses

    Separate security-critical components

    Design for resilience and recovery

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.27 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.27 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.27 Secure system architecture and engineering principles. Built for compliance professionals.

    Try ISMS Copilot free