ISO 27001 A.8.28 — Secure coding
A.8.28 applies to anyone who writes or commissions software — including a two-developer product team. It asks for secure coding principles that are defined, applied and checked, not a formal AppSec programme.
A.8.28 applies to anyone who writes or commissions software — including a two-developer product team. It asks for secure coding principles that are defined, applied and checked, not a formal AppSec programme.
Secure coding principles shall be applied to software development. That spans planning (standards and training), during coding (review, static analysis, dependency management) and after release (patching, vulnerability handling).
Theme: Technological · New in ISO 27001:2022
If you sell software, this is the control your enterprise buyers read most closely in your Statement of Applicability. It is also where a small team can score well cheaply — most of the expected practice is already in a modern CI pipeline.
Write a one-page secure coding standard, enforce pull-request review in the repository, turn on the dependency and secret scanning your Git host already provides, and keep the evidence those tools generate.
See the full list of all 93 Annex A controls or start from the Statement of Applicability template.
ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.