Overview
ISO/IEC 27034-7:2018 - “Information technology - Application security - Part 7: Assurance prediction framework” defines a structured, auditable approach for making security predictions when a project team reuses evidence from a previous application version instead of repeating all Application Security Controls (ASCs). The standard codifies minimum requirements for creating a Prediction Application Security Rationale (PASR) that maps to ASCs and establishes an Expected Level of Trust for a subsequent application. It applies when an organization has an Application Normative Framework (ANF) and an original application with an Actual Level of Trust. Predictions across aggregated components or based on a developer’s history are out of scope.
Key topics and technical requirements
ISO/IEC 27034-7 focuses on practical, risk-based requirements for secure prediction and assurance:
- Prediction concepts: definitions of Expected Level of Trust, Actual Level of Trust, and the prediction framework.
- PASR creation: requirements for content, format, identifiers, actors, rationale, and linkage to ASCs in the ANF.
- Mapping ASCs to PASRs: show how omitted activities are justified and what evidence is reused.
- Prediction authorization and accountability: roles, ONF committee approval, and forced authorization controls.
- Substantial changes risk analysis: guidance for assessing code changes, architecture reviews, and test deprecation risks.
- Confidence building: measures and building blocks for expressing degrees of confidence in a prediction.
- Verification, validation and audit: processes for PASR verification, PASR auditability, and Expected Level of Trust reports.
- Implementation guidance: steps for integrating PASR into an organization’s Application Normative Framework and governance processes.
Practical applications
ISO/IEC 27034-7 is designed to help organizations:
- Reuse security evidence between application versions without losing assurance.
- Reduce redundant security effort where justified by risk analysis and documented rationale.
- Provide auditable, repeatable rationale for security claims when ASC activities are not repeated.
- Support risk-based release decisions, change management, and security governance for application lifecycles.
Use cases include version updates, minor functional changes, and maintenance releases where previous security evidence may still be valid.
Who should use this standard
- Application security teams and developers
- Security architects and risk analysts
- QA and testing managers
- ONF/ANF governance committees
- Auditors and compliance officers
Related standards
- ISO/IEC 27034 series (application security framework) - see ISO/IEC 27034-1 for principles and terminology.
Using ISO/IEC 27034-7 alongside other parts of the 27034 family helps integrate prediction practices into a mature application security program.
Keywords: ISO/IEC 27034-7, application security, PASR, ASC, Expected Level of Trust, assurance prediction framework, ANF, ONF, Actual Level of Trust.