isms.coach
← All controls

A.8.29 · Technological

Security testing in development and acceptance

Why it matters

Catches vulnerabilities before they reach production, where they're far more expensive to fix.

How a self-led small team implements it

Automated dependency/vulnerability scanning in your CI pipeline is a proportionate starting point before manual pen testing.

What auditors expect to see

CI scan results, penetration test reports if applicable.

Track A.8.29 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More technological controls