Cyber Resilience

← ISO 27001 Annex A

A.8.29 Technological

Security testing in development and acceptance

AttributesPreventiveC·I·AIdentifyApplication securityInformation security assuranceSystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (11)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (12)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (13)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (776)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

CWE-1004→MCWE-1007←P →PCWE-102←P →MCWE-1021→MCWE-1022←P →MCWE-1023←P →MCWE-1024←P →MCWE-1025←P →MCWE-1037←P →MCWE-1038←P →MCWE-1039←P →MCWE-1049←P →MCWE-1050→MCWE-1056→MCWE-1057→MCWE-1066←P →MCWE-1067←P →PCWE-1068→MCWE-1077→MCWE-1083→MCWE-1088←P →MCWE-1091←P →MCWE-11→MCWE-1102→MCWE-1103←P →PCWE-111←P →MCWE-1119→MCWE-112→MCWE-1124→PCWE-113→MCWE-114←P →MCWE-115→MCWE-116→MCWE-1164→PCWE-117→MCWE-1173→MCWE-1174→MCWE-1176←PCWE-118←P →MCWE-1189→MCWE-119←P →MCWE-1190→MCWE-1191→MCWE-12→MCWE-120←P →MCWE-1204→MCWE-121←P →MCWE-122←P →MCWE-1221←P →MCWE-1223←P →MCWE-1224←P →MCWE-123←P →MCWE-1231←P →MCWE-1233→MCWE-1234→MCWE-1236→MCWE-124←P →MCWE-1240←P →MCWE-1241→MCWE-1242←P →MCWE-1244←P →MCWE-1245→MCWE-1246→MCWE-1247←P →PCWE-125←P →MCWE-1253→MCWE-1254←P →MCWE-1255←P →MCWE-1256←P →MCWE-1257→MCWE-1258←P →MCWE-1259→MCWE-126←P →MCWE-1260→MCWE-1262→MCWE-1264→MCWE-1265←P →MCWE-1269←P →MCWE-127←P →MCWE-1270←P →MCWE-1275→MCWE-1278←P →PCWE-1279←P →MCWE-128←P →MCWE-1281←P →MCWE-1283→MCWE-1284→MCWE-1285←P →MCWE-1286→MCWE-1287→MCWE-1288→MCWE-1289←P →MCWE-129→MCWE-1291←P →PCWE-1295←P →MCWE-1298→MCWE-1299→MCWE-130←P →MCWE-1300→PCWE-1303→PCWE-131←P →MCWE-1312→MCWE-1313←P →MCWE-1316←P →MCWE-1319→MCWE-1320←P →MCWE-1321→MCWE-1322→MCWE-1325→MCWE-1332←P →PCWE-1333→MCWE-1335←P →MCWE-1336→MCWE-134←P →MCWE-1341←P →MCWE-1342→PCWE-135←P →MCWE-138→MCWE-1385←P →MCWE-1386←P →MCWE-1389→MCWE-1391←P →MCWE-14→MCWE-140→MCWE-141→MCWE-142←P →MCWE-143→MCWE-144→MCWE-145→MCWE-146→MCWE-147→MCWE-148←P →MCWE-149→MCWE-150→MCWE-153→MCWE-154→MCWE-155→MCWE-156→MCWE-157→MCWE-158→MCWE-159→MCWE-160→MCWE-162→MCWE-164→MCWE-166→MCWE-167←P →MCWE-168→MCWE-170←P →MCWE-172←P →MCWE-173→MCWE-176←P →MCWE-177→MCWE-179→MCWE-180→MCWE-182→MCWE-183←P →MCWE-184→MCWE-185←P →MCWE-186←P →MCWE-187←P →MCWE-188←P →MCWE-190←P →MCWE-191←P →MCWE-192←P →MCWE-193←P →MCWE-194←P →MCWE-195←P →MCWE-196←P →MCWE-197←P →MCWE-198←P →MCWE-20→MCWE-200→MCWE-202←P →PCWE-204←P →MCWE-205←P →MCWE-207→MCWE-209→MCWE-210→MCWE-215←P →MCWE-22←P →MCWE-226→MCWE-228→MCWE-229→MCWE-23→MCWE-230→MCWE-231→MCWE-232←P →MCWE-233→MCWE-234←P →MCWE-235→MCWE-236→MCWE-237←P →MCWE-239→MCWE-24→MCWE-240←P →MCWE-241→MCWE-242→MCWE-248←P →MCWE-25→MCWE-252←P →MCWE-253←P →MCWE-26→MCWE-27→MCWE-273→MCWE-277→MCWE-28←P →MCWE-280→MCWE-284→MCWE-288→MCWE-29→MCWE-290←P →MCWE-296→MCWE-297←P →MCWE-298→MCWE-299→MCWE-30→MCWE-301→MCWE-302←P →MCWE-303←P →MCWE-305→MCWE-31→MCWE-316→MCWE-318→MCWE-32→MCWE-322→MCWE-323→MCWE-325→MCWE-328→MCWE-329→MCWE-330→MCWE-331→MCWE-332→MCWE-333→MCWE-334→MCWE-335→MCWE-336→MCWE-337→MCWE-338→MCWE-339→MCWE-34→MCWE-340→MCWE-341→MCWE-342→MCWE-343→MCWE-345→MCWE-348→MCWE-349→MCWE-35←P →MCWE-351←P →MCWE-354→MCWE-356→MCWE-357←P →MCWE-358←P →MCWE-36←P →MCWE-362←P →MCWE-363→MCWE-364←P →MCWE-366←P →MCWE-368←P →MCWE-369←P →MCWE-37→MCWE-372←P →MCWE-377→MCWE-378→MCWE-38→MCWE-384→MCWE-385→PCWE-39→MCWE-390←P →MCWE-391←P →MCWE-392←P →MCWE-393←P →MCWE-394←P →MCWE-395→MCWE-396←P →MCWE-40←P →MCWE-401←P →MCWE-403→MCWE-407←P →MCWE-409→MCWE-41←P →MCWE-410→PCWE-413→MCWE-414→MCWE-415→MCWE-416←P →MCWE-42←P →MCWE-421←P →MCWE-422→MCWE-424←P →MCWE-425→MCWE-426→MCWE-427→MCWE-428←P →MCWE-43←P →MCWE-430←P →MCWE-431←P →MCWE-433→MCWE-434→MCWE-435←P →MCWE-436←P →MCWE-437←P →MCWE-44→MCWE-440←P →MCWE-444←P →MCWE-446←P →MCWE-447←P →MCWE-448←P →PCWE-449←P →MCWE-450←P →MCWE-451←P →MCWE-453→MCWE-454→MCWE-455←P →MCWE-456←P →MCWE-457→MCWE-46←P →MCWE-460←P →MCWE-462←P →MCWE-463→MCWE-466←P →MCWE-467→MCWE-468→MCWE-469←P →MCWE-470←P →MCWE-471→MCWE-472→MCWE-473→MCWE-474→MCWE-475←P →MCWE-476←P →MCWE-478←P →MCWE-479←P →MCWE-480←P →MCWE-482→MCWE-484→MCWE-488→MCWE-489←P →MCWE-491←P →MCWE-495→MCWE-499←P →MCWE-50←P →MCWE-502→MCWE-507←P →MCWE-511←P →MCWE-514→PCWE-515←P →MCWE-531←P →MCWE-535→MCWE-539←P →MCWE-541→MCWE-544←P →MCWE-548←P →MCWE-550←P →MCWE-551→MCWE-553→MCWE-561→MCWE-562←P →MCWE-564→MCWE-565→MCWE-566→MCWE-567→MCWE-57→MCWE-570→MCWE-571→MCWE-573→MCWE-587→MCWE-588←P →MCWE-59←P →MCWE-590←P →MCWE-591→MCWE-597→MCWE-598→MCWE-599→MCWE-6→MCWE-600←P →MCWE-602→MCWE-603←P →MCWE-606←P →MCWE-61←P →MCWE-610→MCWE-611→MCWE-615→MCWE-616→MCWE-617←P →MCWE-618→MCWE-62→MCWE-621→MCWE-622←P →MCWE-623→MCWE-624←P →MCWE-625→MCWE-626←P →MCWE-627→MCWE-628→MCWE-639→MCWE-64→MCWE-641→MCWE-643→MCWE-644→MCWE-646←P →MCWE-647→MCWE-648→MCWE-649←P →MCWE-65←P →MCWE-650←P →MCWE-652→MCWE-657←P →MCWE-66←P →MCWE-662→MCWE-663→MCWE-665→MCWE-667←P →MCWE-67→MCWE-670←P →MCWE-672→MCWE-674→MCWE-675←P →MCWE-676→MCWE-680←P →MCWE-681←P →MCWE-682←P →MCWE-683←P →MCWE-684←P →MCWE-686←P →MCWE-687←P →MCWE-688→MCWE-690←P →MCWE-691→MCWE-692→MCWE-694→MCWE-695→MCWE-696←P →MCWE-697←P →MCWE-698←P →MCWE-704←P →MCWE-705→MCWE-706←P →MCWE-707→MCWE-710→MCWE-73→MCWE-733→MCWE-74→MCWE-749←P →MCWE-75→MCWE-754←P →MCWE-755←P →MCWE-756←P →MCWE-757→MCWE-758→MCWE-759→MCWE-76→MCWE-760→MCWE-761→MCWE-762←P →MCWE-763←P →MCWE-764←P →MCWE-765←P →MCWE-767→MCWE-768←P →MCWE-77→MCWE-771←P →MCWE-774←P →MCWE-775→MCWE-776→MCWE-777→MCWE-78→MCWE-780→MCWE-782→MCWE-783→MCWE-784→MCWE-786←P →MCWE-787←P →MCWE-788←P →MCWE-789←P →MCWE-79→MCWE-790→MCWE-791→MCWE-792→MCWE-794→MCWE-80→MCWE-804←P →MCWE-805←P →MCWE-807←P →MCWE-81→MCWE-82←P →MCWE-820←P →MCWE-821←P →MCWE-822←P →MCWE-823←P →MCWE-824←P →MCWE-825→MCWE-826←P →MCWE-827←P →MCWE-828→MCWE-83→MCWE-830→MCWE-832→MCWE-833←P →MCWE-834←P →MCWE-835→MCWE-838←P →MCWE-839←P →MCWE-84→MCWE-841→MCWE-843←P →MCWE-85←P →MCWE-86→MCWE-87→MCWE-88→MCWE-89→MCWE-90→MCWE-908←P →MCWE-909→MCWE-91→MCWE-910←P →MCWE-911←P →MCWE-912←P →MCWE-913→MCWE-914←P →MCWE-915→MCWE-917→MCWE-925→MCWE-926→MCWE-927→MCWE-93→MCWE-939→MCWE-941→MCWE-942←P →MCWE-943→MCWE-95→MCWE-96→MCWE-97→MCWE-98→MCWE-99→M
Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (9)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (7)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.