A.8.33 Technological
Test information
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CM-2mostlyaligns with — Both controls require that test environments mirror the security posture of production systems and that operational data used for testing be protected, sanitized, and removed when no longer needed.
- AC-3partialaligns with — Applying the same access-control procedures to test environments as to operational environments implements the NIST access-enforcement objective for all system resources.
- AU-2partialaligns with — Logging the copying and use of operational information for testing fulfills the NIST requirement to generate audit records for significant security-relevant events.
- MP-6partialaligns with — The explicit requirement to delete operational information from test environments after use aligns with NIST media-sanitization practices to prevent unauthorized disclosure.
- SI-7partialaligns with — The ISO control’s requirement to protect test data from tampering directly supports the NIST objective of ensuring the integrity of software, firmware, and information used in testing.
- AC-3covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- CM-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SI-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (18)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — Requiring the same access-control procedures and separate authorization for each copy of operational data into test environments enforces policy-based management of entitlements and authorizations.
- PR.DS-01mostlyaligns with — The control protects the confidentiality of operational data when it is replicated into non-production environments, directly supporting the outcome of safeguarding data-at-rest.
- PR.PS-04mostlyaligns with — Mandating an audit trail for every copy and use of operational information in testing environments produces the log records needed for continuous monitoring.
- ID.RA-07partialaligns with — Tracking the movement of sensitive data into test environments and its subsequent secure deletion provides documented evidence that changes and exceptions are recorded and managed.
- PR.IR-01partialaligns with — Applying operational access controls to test environments reduces the risk of unauthorized logical access to copies of production data.
- ID.RA-07implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (9)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.3.2partialaligns with — Enforcing least-privilege access and separate authorization for each copy of operational data into test environments aligns with the ASVS requirement that secret and sensitive assets be accessed under the principle of least privilege.
- V14.1.1partialaligns with — The ISO control's requirement to classify and protect sensitive operational data when copied into test environments directly supports the ASVS mandate to identify and classify all sensitive data processed by the application.
- V14.2.4partialaligns with — Requiring the same access controls, separate authorization, and audit logging for test copies implements the ASVS expectation that sensitive data handling must include documented controls for encryption, access, and logging.
- V14.2.7partialaligns with — Requiring immediate, secure deletion of operational data from test environments once testing ends implements the ASVS rule that sensitive information must be removed according to its retention classification.
- V16.2.1partialaligns with — Mandating an audit trail for every copy and use of operational information in testing satisfies the ASVS need for log entries that capture who, what, when, and where for security-relevant events.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — By requiring removal or masking of sensitive operational data before it enters test environments, the control sharply reduces the chance that such data will be exposed to unauthorized actors who have access to those environments.
- CWE-212prevents — Test-data protection rules require sanitization of production data used in testing.
- CWE-284mitigates — Mandating identical access-control rules for test environments as for production prevents weaker protections from being introduced simply because the data is labelled 'test'.
- CWE-312mitigates — By insisting that any retained test copies be stored securely and only for testing, the control reduces the likelihood that clear-text operational data will persist on disk or in backups.
- CWE-359prevents — The explicit prohibition on copying personally identifiable information into development and test environments directly lowers the exposure of private personal data to staff or processes that should not see it.
- CWE-531prevents — Explicit control on test information directly addresses inclusion of sensitive data in test environments.
Mitigated MITRE ATT&CK techniques (104)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1213.001prevents — A.8.33's rules on not copying sensitive operational data (or masking/deleting it) and applying equivalent access controls to test environments directly stop adversaries from mining valuable information like credentials, diagrams, and internal links that would otherwise be present in a Confluence repository in a development/test environment.
- T1530prevents — A.8.33's rules on not copying sensitive operational data (or masking/deleting it) and applying equivalent access controls to test environments directly stop the technique for any sensitive data that would otherwise be duplicated into cloud test storage, but leave the bulk of production cloud storage untouched.
- T1552prevents — Preventing or masking copies of operational information in test systems limits the exposure of credentials stored in files, registries, or other locations that an adversary could harvest.
- T1552.001prevents — A.8.33's rules on not copying sensitive operational data (incl. credentials) into test environments, masking when used, separate authorizations, and immediate secure deletion after testing directly stop insecure credential files from being created or left in test/dev copies that adversaries could search, but this is only a slice of the technique's scope (production configs, backups, container logs, source code, etc.).
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.8.33's access-control, masking, deletion and secure-storage rules for test data limit the blast radius and downstream impact of a realized broken-access-control flaw (e.g. by preventing real PII from being exfiltrated via an IDOR in test), but do not reduce the authorization-decision defect itself.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.