A.8.33
    Technological Controls

    Test information

    Test information should be appropriately selected, protected and managed.

    Purpose

    To ensure test data does not contain production data that could be exposed.

    Implementation Guidance

    Avoid using production data in test environments

    Sanitize or mask production data if used for testing

    Protect test data with appropriate controls

    Delete test data after use

    Document test data management procedures

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.33 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.33 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.33 Test information. Built for compliance professionals.

    Try ISMS Copilot free