Overview
ISO/IEC 27034-3:2018 - part of the ISO/IEC 27034 application security series - defines the Application Security Management Process (ASMP) and provides implementation guidance for embedding application security into an organization’s projects and lifecycle. The standard describes how to identify application security requirements, assess risks, create and maintain an Application Normative Framework (ANF), provision and operate applications securely, and audit application security. Key concepts include roles and responsibilities, the relationship with the Organizational Normative Framework (ONF), use of approved tools, and defining an application’s targeted and actual level of trust.
Key technical topics and requirements
- Application Security Management Process (ASMP): structured steps for integrating security across an application’s life cycle - from requirements to operation and auditing.
- Application Normative Framework (ANF): a documented set of elements (business, regulatory, technological contexts; specifications; actors and responsibilities; selected security measures; lifecycle and information) that govern application-specific security.
- Risk assessment: assessing application security risks and defining mitigation activities (realization and verification activities are required).
- Roles and responsibilities: explicitly communicating and documenting roles, qualifications and accountability for application security.
- Level of trust: defining a targeted level of trust for an application and measuring its actual level of trust against that target.
- Verification and auditing: systematic verification activities and audits to confirm outcomes and maintain compliance.
- Guidance and tool use: selection and use of approved tools and consistent alignment with organizational policies (ONF).
Practical applications
- Embed ASMP into software development and DevOps pipelines to ensure security requirements are identified, implemented and verified throughout the SDLC.
- Create and maintain an ANF to centralize application-specific security policies, controls and lifecycle rules.
- Use the standard to structure threat and risk assessments, map controls to regulatory requirements, and define audit criteria.
- Support procurement, third-party application evaluation, and secure deployment by documenting targeted levels of trust and verification evidence.
Who should use this standard
- Application security managers and architects
- Security and risk managers
- Development and DevOps teams integrating security into SDLC
- Compliance officers and auditors evaluating application controls
- Product owners and IT governance teams aligning application practices with organizational policies
Related standards
ISO/IEC 27034-3 is practical guidance for organizations that want repeatable, auditable application security management tailored to their business and technology contexts.