Information Security in Project Management - ISO 27001 Annex A Control

ISO 27001 Annex A 5.8

Build security in at project start - bolting on later is more expensive.

ISO 27001 Annex A 5.8 - Information Security in Project Management

Projects create change. New systems, new processes, new data flows, new suppliers. Each of those creates new information security risk if it is not considered as the project is scoped, designed and delivered. The control is about catching that risk early enough to do something about it.

In practice the control means information security is part of the project initiation - someone considers the security implications and any controls that need building in. It means information security is reviewed at key project milestones, not just at the end. And it means residual risks at go-live are documented and accepted by the right person.

The control applies to projects of all sizes, not just major IT projects. A change to a business process, a new supplier integration, or a move to a different cloud provider all count. The depth of the security review scales to the project, but the principle that security is considered up front applies to all of them.

The most common mistake is leaving information security until just before go-live. By then the architecture, the contracts and the data flows are decided, and changing them is expensive. The cheaper place to consider information security is at the start, when there is still room to choose a different supplier or design.

Practical Compliance Guidance

The expectation that information security forms part of project management is described in the IMS1 Manual Section 8.5 alongside the secure development policy. Information security is reviewed and assessed for each project with actions taken based on the risks identified.

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit, including the IMS1 Manual, information security risks register, policy-procedures, forms, registers and audit checklists. 
ER15 Information Security Risks The risk register. Project-related information security risks should be added here when identified, with the project owner accountable for treatment or acceptance.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

No. Any project that affects the way the organisation handles information falls within scope. Business process changes, supplier changes, premises moves and reorganisations can all create information security implications even when no new IT system is involved.
It does not need to be elaborate. A short structured review that covers what data the project will handle, what new systems or suppliers are involved, what access changes will be needed, and any obvious threats. The output is either a list of controls that need building into the project or an entry in the risk register for residual risk.
The Information Security Lead should review and confirm the security position before go-live, with any unaccepted residual risk escalated to senior management for explicit acceptance. The project sponsor or owner usually carries the residual risk.

Further Resources

payment logos