Test information
Purpose
Select, protect and manage test information appropriately to keep tests reliable and safeguard operational data.
How to meet this control
In short: Select, protect and manage test data appropriately.
- Step 01Choose test data that produces reliable results without exposing real sensitive or personal data
- Step 02Generate synthetic or masked datasets for development and test rather than copying raw production data
- Step 03Apply the same access controls to test environments as to production when operational data must be used
- Step 04Require separate, recorded authorisation each time operational data is copied into a test environment
- Step 05Log the copying and use of operational test information to create an audit trail
- Step 06Delete operational data from test environments promptly once testing is complete
Tip: Use synthetic or masked data in test environments.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Choose test information that produces reliable results while protecting operational data
- ›Avoid copying sensitive or personally identifiable information into dev and test environments
- ›Apply the same access controls to test environments as to operational ones
- ›Require separate authorisation each time operational information is copied into a test environment
- ›Log the copying and use of operational information to create an audit trail
- ›Remove or mask sensitive information when it must be used for testing
- ›Delete operational information from test environments promptly once testing is finished
- ›Store test information securely and use it only for testing
Audit evidence to keep
- - Evidence test environments use synthetic or masked data
- - Authorisation records for copying operational data into test
- - Access control configuration on test environments
- - Audit log of operational data copied for testing
- - Records of test data deletion after testing
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.33. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.