ISO 27034

  • Who it's for

    Software developers and organizations that manage application systems.

  • Problems we solve

    Difficulty proving application security to customers, and security not built into the SDLC.

  • Benefits

    Establish an application-security management mechanism that improves the credibility and auditability of software security.

ISO 27034 Application Security

For software vendors, proving to customers and users that the systems they develop are secure has become a key issue — trust must be created and evidence-based. On this premise, organizations need to understand: whether indicators show things are under control, whether third-party components can be trusted, whether they meet the customer's specified security requirements, and whether records and evidence exist when a security incident occurs.

ISO published ISO 27034 in 2011 to create management mechanisms and methods for application-system security. It applies not only to development units but also to organizations that manage applications, and demonstrates application security through basic principles, verification and auditing.

ISO 27034 uses information-protection principles as the basis for developing applications, using an Application Security Life Cycle guidance model to build the security needed throughout the life cycle. The goal is for every information and communication system to have its own security plan — demonstrating, within limited resources, exactly what security efforts have been made, so that security does not become empty talk. The organizational normative framework maps components to the PDCA cycle to manage application security.

Through in-depth study of the ISO 27034 series, IngSafe consultants have developed a compliant management system that helps organizations demonstrate and manage application security.

Interested in adoption and consulting? Contact us and a specialist will assist you.