ISO/IEC 27034-3:2018
Information technology — Application security — Part 3: Application security management process
Information technology — Application security — Part 3: Application security management process
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 47
- Дата публикации:
- 22 мая 2018 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
This document provides a detailed description and implementation guidance for the Application Security Management Process.
Abstract
Overview
ISO/IEC 27034-3:2018 - part of the ISO/IEC 27034 application security series - defines the Application Security Management Process (ASMP) and provides implementation guidance for embedding application security into an organization’s projects and lifecycle. The standard describes how to identify application security requirements, assess risks, create and maintain an Application Normative Framework (ANF), provision and operate applications securely, and audit application security. Key concepts include roles and responsibilities, the relationship with the Organizational Normative Framework (ONF), use of approved tools, and defining an application’s targeted and actual level of trust.
Key technical topics and requirements
- Application Security Management Process (ASMP): structured steps for integrating security across an application’s life cycle - from requirements to operation and auditing.
- Application Normative Framework (ANF): a documented set of elements (business, regulatory, technological contexts; specifications; actors and responsibilities; selected security measures; lifecycle and information) that govern application-specific security.
- Risk assessment: assessing application security risks and defining mitigation activities (realization and verification activities are required).
- Roles and responsibilities: explicitly communicating and documenting roles, qualifications and accountability for application security.
- Level of trust: defining a targeted level of trust for an application and measuring its actual level of trust against that target.
- Verification and auditing: systematic verification activities and audits to confirm outcomes and maintain compliance.
- Guidance and tool use: selection and use of approved tools and consistent alignment with organizational policies (ONF).
Practical applications
- Embed ASMP into software development and DevOps pipelines to ensure security requirements are identified, implemented and verified throughout the SDLC.
- Create and maintain an ANF to centralize application-specific security policies, controls and lifecycle rules.
- Use the standard to structure threat and risk assessments, map controls to regulatory requirements, and define audit criteria.
- Support procurement, third-party application evaluation, and secure deployment by documenting targeted levels of trust and verification evidence.
Who should use this standard
- Application security managers and architects
- Security and risk managers
- Development and DevOps teams integrating security into SDLC
- Compliance officers and auditors evaluating application controls
- Product owners and IT governance teams aligning application practices with organizational policies
Related standards
- ISO/IEC 27034 series (other parts covering concepts and controls)
- ISO/IEC 27001 / ISO/IEC 27002 (information security management and controls)
ISO/IEC 27034-3 is practical guidance for organizations that want repeatable, auditable application security management tailored to their business and technology contexts.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-3:2018
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 27034-3:2018
ДействующийInformation technology. Application security. Application security management process.
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…