Cyber Resilience

← ISO 27001 Annex A

A.8.25 Technological

Secure development life cycle

AttributesPreventiveC·I·AProtectApplication securitySystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (15)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (11)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (14)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (915)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

CWE-1007←PCWE-102←P →PCWE-1022←P →PCWE-1024←P →PCWE-1025←P →PCWE-1037←P →PCWE-1038←P →PCWE-1039←P →PCWE-1049←P →PCWE-1050→PCWE-1051←P →PCWE-1055←P →PCWE-1057←P →PCWE-1058←P →PCWE-1059←P →PCWE-1066←P →PCWE-1067←P →PCWE-1068←P →PCWE-1072→PCWE-1076←P →PCWE-1078→PCWE-1083←P →PCWE-1088←P →PCWE-1091←P →PCWE-11←P →PCWE-1100→PCWE-1102←P →PCWE-1103←PCWE-1106→PCWE-1107←P →PCWE-1108←P →PCWE-111←P →PCWE-1112←PCWE-1113→PCWE-1116←P →PCWE-1118←P →PCWE-1119→PCWE-112←P →PCWE-1124←P →PCWE-1125←P →PCWE-113←P →PCWE-114←P →PCWE-115←P →PCWE-116←P →PCWE-1164←P →PCWE-117→PCWE-1173←P →PCWE-1174←P →PCWE-1176←PCWE-118←P →PCWE-119←P →PCWE-1191→PCWE-12←P →PCWE-120←P →PCWE-1204→PCWE-121←P →PCWE-122←P →PCWE-1221←P →PCWE-1223←P →PCWE-1224←P →PCWE-123←P →PCWE-1231←P →PCWE-1236←P →PCWE-124←P →PCWE-1240←P →PCWE-1241→PCWE-1242←P →PCWE-1244←P →PCWE-1245←P →PCWE-1246←P →PCWE-125←P →PCWE-1250←P →PCWE-1254←P →PCWE-126←P →PCWE-1264←P →PCWE-1265←P →PCWE-1269←P →PCWE-127←P →PCWE-1270←P →PCWE-1272→PCWE-128←P →PCWE-1281←P →PCWE-1282←P →PCWE-1284←P →PCWE-1285←P →PCWE-1286←P →PCWE-1287←P →PCWE-1288←P →PCWE-129←P →PCWE-1291←P →PCWE-1298←P →PCWE-130←P →PCWE-131←P →PCWE-1310→PCWE-1320←P →PCWE-1321←P →PCWE-1322←P →PCWE-1325←P →PCWE-1328→PCWE-1329←P →PCWE-1333←P →PCWE-1335←P →PCWE-1336←P →PCWE-134←P →PCWE-1341←P →PCWE-135←P →PCWE-1357→PCWE-138←P →PCWE-1386←P →PCWE-1389←P →PCWE-1391←P →PCWE-14→PCWE-140→PCWE-141←P →PCWE-142←P →PCWE-143←P →PCWE-144←P →PCWE-145←P →PCWE-146←P →PCWE-147←P →PCWE-148←P →PCWE-149←P →PCWE-150←P →PCWE-153←P →PCWE-154←P →PCWE-155←P →PCWE-156←P →PCWE-157←P →PCWE-158←P →PCWE-159←P →PCWE-160←P →PCWE-162←P →PCWE-164←P →PCWE-166←P →PCWE-167←P →PCWE-168←P →PCWE-170←P →PCWE-172←P →PCWE-176←P →PCWE-177→PCWE-178←P →PCWE-179←P →PCWE-180←P →PCWE-182←P →PCWE-185←P →PCWE-186←P →PCWE-187←P →PCWE-188←P →PCWE-190←P →PCWE-191←P →PCWE-192←P →PCWE-193←P →PCWE-194←P →PCWE-195←P →PCWE-196←P →PCWE-197←P →PCWE-198←P →PCWE-20→PCWE-200→PCWE-201←P →PCWE-204←P →PCWE-205←P →PCWE-207→PCWE-209←P →PCWE-210←PCWE-212←P →PCWE-215←P →PCWE-219←P →PCWE-22←P →PCWE-226→PCWE-228←P →PCWE-229←P →PCWE-23←P →PCWE-231←P →PCWE-232←P →PCWE-233←P →PCWE-234←P →PCWE-235←P →PCWE-236←P →PCWE-237←P →PCWE-239←P →PCWE-24←P →PCWE-240←P →PCWE-241←P →PCWE-242←P →PCWE-244→PCWE-248←P →PCWE-25←P →PCWE-252←P →PCWE-253←P →PCWE-257←P →PCWE-258→PCWE-26←P →PCWE-267→PCWE-27←P →PCWE-270←P →PCWE-271→PCWE-274→PCWE-277←P →PCWE-278←P →PCWE-28←P →PCWE-280→PCWE-284→PCWE-287→PCWE-288→PCWE-290←P →PCWE-30←P →PCWE-302←P →PCWE-303←P →PCWE-304→PCWE-305→PCWE-31←P →PCWE-316→PCWE-318→PCWE-32←P →PCWE-325→PCWE-329→PCWE-330→PCWE-331→PCWE-332→PCWE-336←P →PCWE-337←P →PCWE-338→PCWE-34←P →PCWE-340→PCWE-341→PCWE-342→PCWE-343→PCWE-344←P →PCWE-345→PCWE-349←P →PCWE-35←P →PCWE-351←P →PCWE-356←P →PCWE-357←P →PCWE-358←P →PCWE-36←P →PCWE-362←P →PCWE-363←P →PCWE-364←P →PCWE-366←P →PCWE-368←P →PCWE-369←P →PCWE-372←P →PCWE-374←P →PCWE-377←P →PCWE-378←P →PCWE-38←P →PCWE-384→PCWE-386←P →PCWE-390←P →PCWE-391←P →PCWE-392←P →PCWE-393←P →PCWE-394←P →PCWE-396→PCWE-401←P →PCWE-403←P →PCWE-407←P →PCWE-409→PCWE-41←P →PCWE-412→PCWE-413←P →PCWE-414←P →PCWE-415←P →PCWE-416←P →PCWE-421←P →PCWE-422←P →PCWE-424←P →PCWE-425→PCWE-428←P →PCWE-43←P →PCWE-430←P →PCWE-431←P →PCWE-433←P →PCWE-434→PCWE-435←P →PCWE-436←P →PCWE-437←P →PCWE-440←P →PCWE-441←P →PCWE-444←P →PCWE-446←P →PCWE-447←P →PCWE-448←P →PCWE-449←P →PCWE-450←P →PCWE-451←P →PCWE-453←P →PCWE-454←P →PCWE-455←P →PCWE-456←P →PCWE-457←P →PCWE-459←P →PCWE-460←P →PCWE-462←P →PCWE-463←P →PCWE-466←P →PCWE-467→PCWE-468←P →PCWE-469←P →PCWE-470←P →PCWE-471→PCWE-472←P →PCWE-473←P →PCWE-474←P →PCWE-475←P →PCWE-476←P →PCWE-477←P →PCWE-478→PCWE-479←P →PCWE-482→PCWE-484→PCWE-488←P →PCWE-489←P →PCWE-491←P →PCWE-495←P →PCWE-499←P →PCWE-50←P →PCWE-501←P →PCWE-507←P →PCWE-511←P →PCWE-520→PCWE-526←P →PCWE-531←P →PCWE-535←P →PCWE-539←P →PCWE-540←P →PCWE-541←P →PCWE-544←P →PCWE-547←P →PCWE-548←P →PCWE-550←P →PCWE-551←P →PCWE-553←P →PCWE-561←P →PCWE-562←P →PCWE-564←P →PCWE-567←P →PCWE-57←P →PCWE-570←P →PCWE-571←P →PCWE-573←P →PCWE-587←P →PCWE-588←P →PCWE-59←P →PCWE-590←P →PCWE-597←P →PCWE-6→PCWE-600←P →PCWE-602←P →PCWE-606←P →PCWE-610←P →PCWE-611←P →PCWE-615←P →PCWE-616←P →PCWE-617←P →PCWE-618←P →PCWE-621←P →PCWE-622←P →PCWE-623←P →PCWE-624←P →PCWE-625←P →PCWE-626←P →PCWE-627←P →PCWE-628←P →PCWE-637←P →PCWE-639→PCWE-640→PCWE-641←P →PCWE-642→PCWE-643←P →PCWE-644←P →PCWE-646←P →PCWE-648←P →PCWE-652←P →PCWE-657←M →PCWE-66←P →PCWE-662←P →PCWE-663←P →PCWE-664←P →PCWE-665←P →PCWE-667←P →PCWE-669←P →PCWE-67→PCWE-670←P →PCWE-674←P →PCWE-675←P →PCWE-676←P →PCWE-680←P →PCWE-681←P →PCWE-682←P →PCWE-683→PCWE-684←P →PCWE-686←P →PCWE-687←P →PCWE-688←P →PCWE-689←P →PCWE-690←P →PCWE-691←P →PCWE-692→PCWE-694→PCWE-695←P →PCWE-696←P →PCWE-697←P →PCWE-698←P →PCWE-704←P →PCWE-705←P →PCWE-706←P →PCWE-707←P →PCWE-710←P →PCWE-73←P →PCWE-733←P →PCWE-74←P →PCWE-749←P →PCWE-75←P →PCWE-754←P →PCWE-755←P →PCWE-756←P →PCWE-757→PCWE-758←P →PCWE-759→PCWE-76←P →PCWE-760→PCWE-761→PCWE-762←P →PCWE-763←P →PCWE-764←P →PCWE-765←P →PCWE-767←P →PCWE-768←P →PCWE-77←P →PCWE-771←P →PCWE-772←P →PCWE-774←P →PCWE-775←P →PCWE-776←P →PCWE-782→PCWE-783←P →PCWE-786←P →PCWE-787←P →PCWE-788←P →PCWE-789←P →PCWE-79→PCWE-790←P →PCWE-791→PCWE-792←P →PCWE-794←P →PCWE-80←P →PCWE-805←P →PCWE-81←P →PCWE-820←P →PCWE-821←P →PCWE-822←P →PCWE-823←P →PCWE-824←P →PCWE-825←P →PCWE-826←P →PCWE-827←P →PCWE-828←P →PCWE-83←P →PCWE-832←P →PCWE-833←P →PCWE-834←P →PCWE-835←P →PCWE-837←P →PCWE-838←P →PCWE-839←P →PCWE-84→PCWE-841←P →PCWE-843←P →PCWE-86←P →PCWE-862→PCWE-87←P →PCWE-88←P →PCWE-89→PCWE-90←P →PCWE-908←P →PCWE-909←P →PCWE-91←P →PCWE-910←P →PCWE-911←P →PCWE-912←P →PCWE-913←P →PCWE-914←P →PCWE-915←P →PCWE-917←P →PCWE-93←P →PCWE-941→PCWE-943←P →PCWE-95←P →PCWE-96←P →PCWE-97←P →PCWE-98←P →PCWE-99←P →P
Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (7)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (6)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.