Cyber Resilience

← ISO 27001 Annex A

A.8.31 Technological

Separation of development, test and production environments

AttributesPreventiveC·I·AProtectApplication securitySystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (16)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (17)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (10)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (25)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (365)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1003.003→PT1003.006→PT1006←MT1021→PT1027.002←MT1027.004←MT1027.010←MT1027.014←MT1027.018←MT1036←MT1036.003←MT1036.005←MT1036.008←MT1037.003→PT1037.004→PT1047→PT1053→PT1053.003→PT1053.005→PT1053.006→PT1053.007→PT1055←MT1055.001←MT1055.002←MT1055.003←M →PT1055.004←MT1055.005←MT1055.008←M →PT1055.009←M →PT1055.011←MT1055.012←MT1055.013←M →PT1055.014←MT1055.015←MT1059→PT1059.004→PT1059.006→PT1059.007→PT1059.008→PT1059.012→PT1059.013→PT1068←MT1071.004←MT1072→PT1078←P →PT1080←P →PT1098→PT1098.003→PT1098.004→PT1098.005←MT1098.006→PT1102←MT1114.003→PT1127←M →PT1127.001←M →PT1127.002→PT1127.003←P →PT1133←MT1134←PT1134.001←PT1134.004←MT1136→PT1137.001→PT1137.002→PT1137.003→PT1137.004→PT1137.005→PT1137.006→PT1176.002←P →PT1195→PT1195.001→PT1195.002←M →PT1202←PT1204.003←MT1204.005←M →PT1207←MT1211←PT1213.001←P →PT1213.003←P →PT1216←M →PT1216.002→PT1218←PT1218.003→PT1218.005←M →PT1218.007←M →PT1218.008←M →PT1218.012→PT1218.013←MT1219.001←M →PT1219.003←PT1220←PT1221←PT1222←PT1222.001←PT1480←PT1480.001←MT1484←M →PT1484.001→PT1484.002←P →PT1491.001→PT1496→PT1496.001→PT1497←MT1497.001←MT1497.002←PT1505←P →PT1505.001→PT1505.002→PT1505.003←M →PT1505.004→PT1505.006←P →PT1525←M →PT1528←P →PT1535←MT1537←MT1542←MT1542.002←MT1542.003←PT1543→PT1543.001→PT1543.002→PT1543.003→PT1543.004→PT1543.005←P →PT1546→PT1546.001→PT1546.002→PT1546.003→PT1546.004→PT1546.005→PT1546.006→PT1546.007→PT1546.009→PT1546.011←M →PT1546.012→PT1546.013→PT1546.014→PT1546.015→PT1546.016→PT1546.017→PT1546.018←P →PT1547.003→PT1547.006→PT1547.012→PT1547.013→PT1547.014→PT1548.001←PT1550←MT1550.001←MT1550.002←MT1550.003←MT1550.004←FT1552.001→PT1553.001←PT1553.002←PT1553.003←M →PT1553.004←PT1553.005←PT1553.006←P →PT1554←P →PT1555.006→PT1556←M →PT1556.001←M →PT1556.003←P →PT1556.007←M →PT1556.008→PT1561.002→MT1563.001→PT1563.002→PT1564.006→PT1565→PT1565.001→PT1565.003→PT1567.001→PT1569→PT1569.003→PT1570←PT1571←PT1572←PT1574←M →PT1574.001←M →PT1574.004→PT1574.005→PT1574.006←M →PT1574.007→PT1574.008→PT1574.009→PT1574.010→PT1574.012→PT1574.013←MT1574.014→PT1578←M →PT1578.001←M →PT1578.002←M →PT1578.003←M →PT1578.004←M →PT1578.005←P →PT1599←MT1599.001←PT1601→PT1601.001←P →PT1601.002←P →PT1606←MT1606.001←MT1606.002←MT1610←P →PT1611←M →PT1612←M →PT1620←PT1651→PT1666←P →PT1677←M →PT1678←PT1684←PT1685←MT1685.002←M →PT1685.003←PT1685.004←M →PT1686←M →PT1686.001←P →PT1687←PT1688←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (11)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.