Information Security in Project Management - ISO 27001 Annex A Control
ISO 27001 Annex A 5.8
Build security in at project start - bolting on later is more expensive.
ISO 27001 Annex A 5.8 - Information Security in Project Management
Projects create change. New systems, new processes, new data flows, new suppliers. Each of those creates new information security risk if it is not considered as the project is scoped, designed and delivered. The control is about catching that risk early enough to do something about it.
In practice the control means information security is part of the project initiation - someone considers the security implications and any controls that need building in. It means information security is reviewed at key project milestones, not just at the end. And it means residual risks at go-live are documented and accepted by the right person.
The control applies to projects of all sizes, not just major IT projects. A change to a business process, a new supplier integration, or a move to a different cloud provider all count. The depth of the security review scales to the project, but the principle that security is considered up front applies to all of them.
The most common mistake is leaving information security until just before go-live. By then the architecture, the contracts and the data flows are decided, and changing them is expensive. The cheaper place to consider information security is at the start, when there is still room to choose a different supplier or design.
Practical Compliance Guidance
The expectation that information security forms part of project management is described in the IMS1 Manual Section 8.5 alongside the secure development policy. Information security is reviewed and assessed for each project with actions taken based on the risks identified.
| alphaZ document | How to use it |
|---|---|
| ISO 27001 Toolkit | The full alphaZ ISO 27001 toolkit, including the IMS1 Manual, information security risks register, policy-procedures, forms, registers and audit checklists. |
| ER15 Information Security Risks | The risk register. Project-related information security risks should be added here when identified, with the project owner accountable for treatment or acceptance. |
Note - all the above files can be downloaded with an alphaZ subscription.
