← ISO 27001 · A.8 — Technological
A.8.29 — Security testing in development and acceptance
high
security-testingpen-test
Requirement
Security testing processes shall be defined and implemented in the development life cycle.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
security testingpenetration testpen testsastdastvulnerability assessment
Supporting terms — specificity signals
annualthird partyreportretestfindingsacceptance criteriaci pipeline
Contradiction markers
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
no penetration testing
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| PCI DSS 4.0.1 | 11.4 | Penetration testing at least every 12 months | pen-test security-testing |
| GLBA | 314.4(d) | Continuous monitoring, or annual penetration tests and six-monthly vulnerability assessments | pen-test security-testing |
| CCPA/CPRA | Regs (cybersecurity audits) | Annual independent cybersecurity audit | security-testing |