ISO/IEC 27034-7:2018

Information technology — Application security — Part 7: Assurance prediction framework ISO/IEC 27034-7:2018

Publication date:   May 22, 2018

General information

90.93 Standard confirmed   Oct 27, 2023

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

International Standard

35.030   IT Security

Buying

Published

Language in which you want to receive the document.

Scope

This document describes the minimum requirements when the required activities specified by an Application Security Control (ASC) are replaced with a Prediction Application Security Rationale (PASR). The ASC mapped to a PASR define the Expected Level of Trust for a subsequent application. In the context of an Expected Level of Trust, there is always an original application where the project team performed the activities of the indicated ASC to achieve an Actual Level of Trust.
The use of Prediction Application Security Rationales (PASRs), defined by this document, is applicable to project teams which have a defined Application Normative Framework (ANF) and an original application with an Actual Level of Trust.
Predictions relative to aggregation of multiple components or the history of the developer in relation to other applications is outside the scope of this document.

Life cycle

NOW

PUBLISHED
ISO/IEC 27034-7:2018
90.93 Standard confirmed
Oct 27, 2023