ISO/IEC 27034-1:2011 PDF
Information technology — Security techniques — Application security — Part 1: Overview and concepts
Information technology — Security techniques — Application security — Part 1: Overview and concepts
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 67
- Дата публикации:
- 21 ноября 2011 г.
- Издание:
- ISO/IEC IS 27034 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27034 provides guidance to assist organizations in integrating security into the processes used for managing their applications. ISO/IEC 27034-1:2011 presents an overview of application security. It introduces definitions, concepts, principles and processes involved in application security. ISO/IEC 27034 is applicable to in-house developed applications, applications acquired from third parties, and where the development or the operation of the application is outsourced.
Abstract
Overview
ISO/IEC 27034-1:2011 is the international application security standard that provides an overview of concepts, definitions and principles for integrating security into application life‑cycle processes. Part 1 introduces the vocabulary and high‑level framework used across ISO/IEC 27034, explains how application security fits with an organization’s information security management system (ISMS), and describes context, roles and processes for managing security of in‑house, third‑party or outsourced applications.
Keywords: ISO/IEC 27034-1:2011, application security standard, Application Normative Framework, Organization Normative Framework.
Key topics and technical requirements
- Scope and definitions: Clarifies the difference between application security and software security and defines key terms used in later parts of ISO/IEC 27034.
- Application security requirements: Identifies sources of requirements (business, regulatory, technical) and the need to engineer security requirements into application specifications.
- Risk and controls: Covers application‑level risk assessment, threat/vulnerability considerations, impact analysis and selection of controls appropriate to the application context.
- Organization Normative Framework (ONF): Guidance for establishing organizational policies, libraries and processes that support consistent application security.
- Application Normative Framework (ANF) and Application Security Controls (ASC): Structures for mapping controls to specific application needs and life‑cycle stages.
- Processes: High‑level processes for ONF management, application security management, provisioning/operation and security auditing.
- Integration guidance: Mapping examples showing how to fit existing secure development lifecycles (SDL) and other standards (e.g., mapping ASCs with NIST SP 800‑53) into ISO/IEC 27034.
Practical applications
- Embedding security into requirements, design, implementation, testing and operation of enterprise applications.
- Creating an Application Normative Framework to reuse security patterns, controls and responsibilities across projects.
- Performing targeted application risk assessments and demonstrating application security to auditors or acquirers.
- Guiding procurement, outsourcing and supplier assurance activities for application development and operation.
Who should use this standard
- Security managers and ISMS teams integrating application controls.
- Application owners, development and operations teams responsible for secure delivery.
- Procurement/acquisition teams and vendors evaluating security expectations.
- Auditors and assurance professionals assessing application security maturity.
Related standards
ISO/IEC 27034 is intended to work with other standards such as ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, and mappings to security assurance and system life‑cycle standards (e.g., ISO/IEC 15288, ISO/IEC 12207).
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27034-1:2011
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
SIST EN ISO/IEC 27005:2024
ДействующийInformation security, cybersecurity and privacy protection - Guidance on managing information security risks…
Overview SIST EN ISO/IEC 27005:2024 (adoption of ISO/IEC 27005:2022 as EN ISO/IEC 27005:2024) provides detailed guidance on managing information security risks to support implementation of an Informa…