ISO/IEC 27034-2:2015
Information technology — Security techniques — Application security — Part 2: Organization normative framework
Information technology — Security techniques — Application security — Part 2: Organization normative framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 52
- Дата публикации:
- 28 июля 2015 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27034-2:2015 provides a detailed description of the Organization Normative Framework and provides guidance to organizations for its implementation.
Abstract
Overview
ISO/IEC 27034-2:2015 defines the Organization Normative Framework (ONF) for application security. As Part 2 of the ISO/IEC 27034 series, this standard provides organizations with guidance to create, implement, maintain and audit a formal, organization-wide framework that makes application security components, roles and processes authoritative and reusable. It positions the ONF as the foundation for consistent application security governance, aligning security practices with business, regulatory and technological contexts.
Key Topics and Technical Requirements
ISO/IEC 27034-2 covers the structure and management of the ONF and specifies key technical topics and requirements including:
- ONF Management Process: governance activities such as establishing an ONF committee, design, implementation, monitoring, improvement and auditing of the ONF. The standard recommends use of RACI charts to describe activities, roles and responsibilities.
- ONF Elements: clearly defined components to be included in the ONF, for example:
- Business, regulatory and technological context components
- Application specifications repository and roles/responsibilities repository
- Application Security Control (ASC) definitions and an organization ASC library
- Application Security Life Cycle Reference Model (ASLCRM) and life cycle models
- Application Security Management Process (ASMP), risk analysis and verification processes
- Auditing and Compliance: processes to verify that applications conform to ONF requirements and to validate the ONF itself.
- Alignment and Integration: guidance to align the ONF with enterprise architecture, ISMS requirements and software life-cycle standards.
Practical Applications
ISO/IEC 27034-2 is practical for organizations that need to standardize and scale application security across projects and teams. Typical uses:
- Establishing organizational application security governance and policy
- Creating a reusable library of application security controls (ASC)
- Integrating application security into software development and procurement lifecycles
- Enabling formal audits and verification of application security compliance
- Improving maturity (e.g., aligning with ISO/IEC 15504 or CMMI concepts) and managing security-related risks consistently
Who Should Use This Standard
- Managers and executives responsible for security strategy and resource allocation
- ONF Committees and governance bodies that approve and maintain application security elements
- Security architects and domain experts implementing ONF components and ASCs
- Developers and project teams who must follow organization-approved application security practices
- Auditors and compliance teams validating conformance and effectiveness
Related Standards
ISO/IEC 27034-2 is part of the ISO/IEC 27034 series and references and aligns with other standards such as:
- ISO/IEC 27034-1 (Overview and concepts)
- ISO/IEC 27001 (ISMS) and ISO/IEC 27005 (risk management)
- ISO/IEC 15288, ISO/IEC 12207 and ISO/IEC 15026-4 (life-cycle alignment)
- ISO/IEC 15504 and SEI/CMMI (maturity models)
Keywords: ISO/IEC 27034-2, Organization Normative Framework, ONF, application security, ASMP, Application Security Control, application security lifecycle, security governance, compliance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-2:2015
Похожие стандарты
Стандарты, упомянутые в описании