A.8.33A.8 Technological controls

Test information

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.33 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Select, protect and manage test information appropriately to keep tests reliable and safeguard operational data.

How to meet this control

In short: Select, protect and manage test data appropriately.

  1. Step 01Choose test data that produces reliable results without exposing real sensitive or personal data
  2. Step 02Generate synthetic or masked datasets for development and test rather than copying raw production data
  3. Step 03Apply the same access controls to test environments as to production when operational data must be used
  4. Step 04Require separate, recorded authorisation each time operational data is copied into a test environment
  5. Step 05Log the copying and use of operational test information to create an audit trail
  6. Step 06Delete operational data from test environments promptly once testing is complete

Tip: Use synthetic or masked data in test environments.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Choose test information that produces reliable results while protecting operational data
  • ›Avoid copying sensitive or personally identifiable information into dev and test environments
  • ›Apply the same access controls to test environments as to operational ones
  • ›Require separate authorisation each time operational information is copied into a test environment
  • ›Log the copying and use of operational information to create an audit trail
  • ›Remove or mask sensitive information when it must be used for testing
  • ›Delete operational information from test environments promptly once testing is finished
  • ›Store test information securely and use it only for testing

Audit evidence to keep

  • - Evidence test environments use synthetic or masked data
  • - Authorisation records for copying operational data into test
  • - Access control configuration on test environments
  • - Audit log of operational data copied for testing
  • - Records of test data deletion after testing

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.8.33. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.