← ISO 27001 · A.8 — Technological

A.8.28 — Secure coding

high secure-developmentapi-security

Requirement

Secure coding principles shall be applied to software development.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
secure codinginput validationoutput encodingowaspparameterisedparameterized
Supporting terms — specificity signals
injectionxsscsrflinterpeer reviewdependency pinningsecrets scanning

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
PCI DSS 4.0.1 6.2 Bespoke and custom software is developed securely secure-development
PCI DSS 4.0.1 6.4.1-6.4.2 Public-facing web applications are protected against attacks api-security
PCI DSS 4.0.1 6.4.3 Payment page scripts are authorised, inventoried and integrity-checked secure-development
GLBA 314.4(c)(4) Secure development and assessment of applications secure-development
NIST CSF 2.0 PR.PS-06 Secure software development practices are integrated secure-development