A.5.8
    Organizational Controls

    Information security in project management

    Information security should be integrated in project management.

    Purpose

    To ensure information security requirements are identified and addressed throughout the project lifecycle.

    Implementation Guidance

    Include security requirements in project initiation and planning phases

    Conduct security risk assessments for new projects

    Ensure security reviews are part of project milestones and approvals

    Involve information security team in relevant projects

    Document security decisions and requirements in project documentation

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.8 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.8 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.8 Information security in project management. Built for compliance professionals.

    Try ISMS Copilot free