A.8.33 Technological
Test information
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CM-2mostlyaligns with — Both controls require that test environments mirror the security posture of production systems and that operational data used for testing be protected, sanitized, and removed when no longer needed.
- AC-3partialaligns with — Applying the same access-control procedures to test environments as to operational environments implements the NIST access-enforcement objective for all system resources.
- AU-2partialaligns with — Logging the copying and use of operational information for testing fulfills the NIST requirement to generate audit records for significant security-relevant events.
- MP-6partialaligns with — The explicit requirement to delete operational information from test environments after use aligns with NIST media-sanitization practices to prevent unauthorized disclosure.
- SI-7partialaligns with — The ISO control’s requirement to protect test data from tampering directly supports the NIST objective of ensuring the integrity of software, firmware, and information used in testing.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — Requiring the same access-control procedures and separate authorization for each copy of operational data into test environments enforces policy-based management of entitlements and authorizations.
- PR.DS-01mostlyaligns with — The control protects the confidentiality of operational data when it is replicated into non-production environments, directly supporting the outcome of safeguarding data-at-rest.
- PR.PS-04mostlyaligns with — Mandating an audit trail for every copy and use of operational information in testing environments produces the log records needed for continuous monitoring.
- ID.RA-07partialaligns with — Tracking the movement of sensitive data into test environments and its subsequent secure deletion provides documented evidence that changes and exceptions are recorded and managed.
- PR.IR-01partialaligns with — Applying operational access controls to test environments reduces the risk of unauthorized logical access to copies of production data.
Related OWASP ASVS 5.0 requirements (9)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.3.2partialaligns with — Enforcing least-privilege access and separate authorization for each copy of operational data into test environments aligns with the ASVS requirement that secret and sensitive assets be accessed under the principle of least privilege.
- V14.1.1partialaligns with — The ISO control's requirement to classify and protect sensitive operational data when copied into test environments directly supports the ASVS mandate to identify and classify all sensitive data processed by the application.
- V14.2.4partialaligns with — Requiring the same access controls, separate authorization, and audit logging for test copies implements the ASVS expectation that sensitive data handling must include documented controls for encryption, access, and logging.
- V14.2.7partialaligns with — Requiring immediate, secure deletion of operational data from test environments once testing ends implements the ASVS rule that sensitive information must be removed according to its retention classification.
- V16.2.1partialaligns with — Mandating an audit trail for every copy and use of operational information in testing satisfies the ASVS need for log entries that capture who, what, when, and where for security-relevant events.
Related weaknesses / CWE (14)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200mostlyprevents — By requiring removal or masking of sensitive operational data before it enters test environments, the control sharply reduces the chance that such data will be exposed to unauthorized actors who have access to those environments.
- CWE-212mostlyprevents — Test-data protection rules require sanitization of production data used in testing.
- CWE-359mostlyprevents — The explicit prohibition on copying personally identifiable information into development and test environments directly lowers the exposure of private personal data to staff or processes that should not see it.
- CWE-531mostlyprevents — Explicit control on test information directly addresses inclusion of sensitive data in test environments.
- CWE-284partialmitigates — Mandating identical access-control rules for test environments as for production prevents weaker protections from being introduced simply because the data is labelled 'test'.
- CWE-312partialmitigates — By insisting that any retained test copies be stored securely and only for testing, the control reduces the likelihood that clear-text operational data will persist on disk or in backups.
- CWE-1258nonenone — Test information protection includes ensuring debug artifacts do not leak sensitive data.
- CWE-215nonenone — Test data handling rules discourage use of real sensitive data in debug contexts.
- CWE-532nonenone — Requiring immediate, secure deletion of operational information once testing finishes limits the window during which sensitive data could be inadvertently left in logs or files inside the test environment.
- CWE-541nonenone — Test data rules discourage use of real credentials in include files used for testing.
- CWE-615nonenone — Test data handling rules can extend to source comments, but the control focuses on test datasets rather than production code comments.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1552partialprevents — Preventing or masking copies of operational information in test systems limits the exposure of credentials stored in files, registries, or other locations that an adversary could harvest.
- T1003nonemitigates — By prohibiting or masking sensitive operational data—including credentials—in test environments, the control reduces the chance that an adversary who later compromises those environments can obtain usable credentials via credential dumping.
- T1005nonemitigates — Strict controls and immediate deletion of operational data after testing reduce the volume of sensitive files an adversary can collect from a compromised test environment.
- T1078nonemitigates — Requiring separate authorization and equivalent access controls for any operational data moved to test environments reduces the likelihood that valid accounts or their secrets will be present and usable for unauthorized access.
- T1087nonemitigates — Masking or removing account-related data from test copies deprives an adversary of the account lists they would otherwise discover by querying test systems that mirror production identity stores.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.