ISO/IEC 27034-5:2017
Information technology — Security techniques — Application security — Part 5: Protocols and application security controls data structure
Information technology — Security techniques — Application security — Part 5: Protocols and application security controls data structure
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 33
- Дата публикации:
- 9 октября 2017 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27034-5 outlines and explains the minimal set of essential attributes of ASCs and details the activities and roles of the Application Security Life Cycle Reference Model (ASLCRM).
Abstract
Overview
ISO/IEC 27034-5:2017 is part of the ISO/IEC 27034 series on application security. It documents the minimal set of essential attributes and a standardized data structure for Application Security Controls (ASCs) and describes the Application Security Life Cycle Reference Model (ASLCRM) - its activities, roles and processes. The standard promotes consistent creation, exchange, protection and reuse of ASCs to reduce cost and improve application-level security governance.
Key topics and technical requirements
- ASC information requirements - a defined, minimal set of essential attributes that should accompany an ASC to ensure it is usable, verifiable and reusable across projects and tools.
- Integrity assurance - guidance that ASC data must support integrity mechanisms (for example, recognized signing or verification methods) so controls can be trusted.
- Multilingual / multiregional data representation - support for representing ASC metadata in multiple languages or regions to enable global reuse.
- ASC data structure recommendations - principles for structuring ASC content to facilitate exchange (interoperability between tools/suppliers) and self-containedness (packaged controls include required metadata and context).
- Application Security Life Cycle Reference Model (ASLCRM) - detailed activities and roles across layers such as Application Management, Provisioning & Operation, Infrastructure Management and Application Audit. This includes processes for initiating, planning, executing, monitoring, transitioning, utilization, archival and destruction of application assets.
- Roles and ASC package - responsibilities for managers, ONF (Organization Normative Framework) committees, domain experts, suppliers and acquirers; and guidance on packaging ASCs for distribution and lifecycle mapping.
- Normative linkage - aligns with ISO/IEC 27034-1 (overview and concepts) and other parts of the 27034 suite.
Practical applications
- Standardizing how application security controls are described, stored and exchanged across organizations and vendors.
- Building an ASC library or repository where approved controls are discoverable and reusable across projects.
- Selecting or developing security tooling that interoperates using a common ASC data structure and exchange protocol.
- Supporting audits, provisioning and lifecycle activities by mapping ASC responsibilities into organizational processes.
- Reducing duplication and implementation cost by reusing verified, integrity-protected controls.
Who should use it
- Managers responsible for enterprise application security governance.
- ONF committees that manage organizational ASC libraries and approval processes.
- Domain experts who develop and validate ASCs.
- Tool vendors and ASC suppliers creating, signing and distributing controls.
- Acquirers integrating third‑party ASCs and mapping them to internal lifecycles.
Related standards
- ISO/IEC 27034-1 (Overview and concepts) - foundational concepts referenced normatively by ISO/IEC 27034-5.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-5:2017
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 27034-3:2018
ДействующийInformation technology. Application security. Application security management process.
BS ISO/IEC 27034-5:2017
ДействующийInformation technology. Security techniques. Application security. Protocols and application security control…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…