ISO/IEC 27034-7:2018
Information technology — Application security — Part 7: Assurance prediction framework
Information technology — Application security — Part 7: Assurance prediction framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 29
- Дата публикации:
- 22 мая 2018 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
This document describes the minimum requirements when the required activities specified by an Application Security Control (ASC) are replaced with a Prediction Application Security Rationale (PASR). The ASC mapped to a PASR define the Expected Level of Trust for a subsequent application. In the context of an Expected Level of Trust, there is always an original application where the project team performed the activities of the indicated ASC to achieve an Actual Level of Trust. The use of Prediction Application Security Rationales (PASRs), defined by this document, is applicable to project teams which have a defined Application Normative Framework (ANF) and an original application with an Actual Level of Trust. Predictions relative to aggregation of multiple components or the history of the developer in relation to other applications is outside the scope of this document.
Abstract
Overview
ISO/IEC 27034-7:2018 - “Information technology - Application security - Part 7: Assurance prediction framework” defines a structured, auditable approach for making security predictions when a project team reuses evidence from a previous application version instead of repeating all Application Security Controls (ASCs). The standard codifies minimum requirements for creating a Prediction Application Security Rationale (PASR) that maps to ASCs and establishes an Expected Level of Trust for a subsequent application. It applies when an organization has an Application Normative Framework (ANF) and an original application with an Actual Level of Trust. Predictions across aggregated components or based on a developer’s history are out of scope.
Key topics and technical requirements
ISO/IEC 27034-7 focuses on practical, risk-based requirements for secure prediction and assurance:
- Prediction concepts: definitions of Expected Level of Trust, Actual Level of Trust, and the prediction framework.
- PASR creation: requirements for content, format, identifiers, actors, rationale, and linkage to ASCs in the ANF.
- Mapping ASCs to PASRs: show how omitted activities are justified and what evidence is reused.
- Prediction authorization and accountability: roles, ONF committee approval, and forced authorization controls.
- Substantial changes risk analysis: guidance for assessing code changes, architecture reviews, and test deprecation risks.
- Confidence building: measures and building blocks for expressing degrees of confidence in a prediction.
- Verification, validation and audit: processes for PASR verification, PASR auditability, and Expected Level of Trust reports.
- Implementation guidance: steps for integrating PASR into an organization’s Application Normative Framework and governance processes.
Practical applications
ISO/IEC 27034-7 is designed to help organizations:
- Reuse security evidence between application versions without losing assurance.
- Reduce redundant security effort where justified by risk analysis and documented rationale.
- Provide auditable, repeatable rationale for security claims when ASC activities are not repeated.
- Support risk-based release decisions, change management, and security governance for application lifecycles.
Use cases include version updates, minor functional changes, and maintenance releases where previous security evidence may still be valid.
Who should use this standard
- Application security teams and developers
- Security architects and risk analysts
- QA and testing managers
- ONF/ANF governance committees
- Auditors and compliance officers
Related standards
- ISO/IEC 27034 series (application security framework) - see ISO/IEC 27034-1 for principles and terminology. Using ISO/IEC 27034-7 alongside other parts of the 27034 family helps integrate prediction practices into a mature application security program.
Keywords: ISO/IEC 27034-7, application security, PASR, ASC, Expected Level of Trust, assurance prediction framework, ANF, ONF, Actual Level of Trust.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-7:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 27034-7:2018
ДействующийInformation technology. Application security. Assurance prediction framework.
BS ISO/IEC 27034-3:2018
ДействующийInformation technology. Application security. Application security management process.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…