ISO/IEC 27034-6:2016
Information technology — Security techniques — Application security — Part 6: Case studies
Information technology — Security techniques — Application security — Part 6: Case studies
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 70
- Дата публикации:
- 5 октября 2016 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27034-6:2016 provides usage examples of ASCs for specific applications. NOTE Herein specified ASCs are provided for explanation purposes only and the audience is encouraged to create their own ASCs to assure the application security.
Abstract
Overview
ISO/IEC 27034-6:2016 - part of the ISO/IEC 27034 series on application security - delivers practical case studies and usage examples of Application Security Controls (ASCs). Rather than normative prescriptions, this part provides realistic ASC examples (for instance, a Java mobile application code-review ASC), XML representation examples, and guidance on adapting ASCs to an organization’s context. The standard helps organizations implement the Application Security Framework and Organizational Normative Framework (ONF) described across ISO/IEC 27034.
Key topics and technical highlights
- Application Security Controls (ASCs): focused examples showing how to define, structure and use ASCs to address application-level threats.
- ASC representation: examples use the XML data structure recommended in ISO/IEC 27034-5-1 to enable consistent ASC exchange and implementation.
- Case studies included: Java code revision for mobile apps; privacy requirements spanning two countries; integration and implementation of third‑party ASCs; use of the Application Security Life Cycle Reference Model (ASLCRM); and integrating ASCs into a secure development life cycle (SDLC).
- Application levels of trust and information classification: practical categorization examples (e.g., baseline → private) and how ASC selection maps to those tiers.
- Secure development life cycle phases: mapped ASC activities across preparation, requirements, design, implementation, verification, release and sustainment phases.
- Annex A: informative XML examples supporting the case studies and demonstrating ASC encoding for tool or process integration.
- Audience and role guidance: targeted at domain experts, application security teams, developers, auditors and organizational ONF committees responsible for ASC creation, validation and maintenance.
Practical applications - who uses this standard
- Application security teams and developers: adopt the ASC examples (e.g., code review ASC for Java mobile apps) as starting points for project-level controls.
- Security architects and ONF committees: adapt case-study patterns to build an organizational ASC library and policy mapping.
- Tool vendors and integrators: use the XML examples to support ASC import/export and automation across SDLC tools.
- Auditors and compliance teams: validate that ASCs have been defined and implemented consistently across application lifecycles.
Related standards (if applicable)
- ISO/IEC 27034 series (general framework and other parts) - ISO/IEC 27034-1 (concepts/definitions) and ISO/IEC 27034-5-1 (ASC XML data structure) are specifically referenced in the case-study context.
By providing concrete ASC templates, XML examples and SDLC mappings, ISO/IEC 27034-6:2016 helps organizations translate application-security principles into implementable controls and repeatable processes.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-6:2016
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 27034-3:2018
ДействующийInformation technology. Application security. Application security management process.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…