A.8.30
    Technological Controls

    Outsourced development

    The organization should direct, monitor and review the activities related to outsourced system development.

    Purpose

    To ensure outsourced development meets security requirements and follows secure practices.

    Implementation Guidance

    Include security requirements in development contracts

    Assess security capabilities of development vendors

    Review code and deliverables for security

    Ensure intellectual property protection

    Monitor vendor compliance with security requirements

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.30 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.30 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.30 Outsourced development. Built for compliance professionals.

    Try ISMS Copilot free