ISO/IEC 27001:2022 Annex A · Control 8.30
Outsourced Development: A Practical Implementation Guide
Maintain security governance and assurance when external parties develop systems or software.
This control concerns directing, monitoring and reviewing activities related to outsourced system development.
What should the control achieve?
- Supplier capability and risk are assessed.
- Security requirements and ownership are contractual.
- Development access and environments are controlled.
- Deliverables and evidence are independently accepted.
Step-by-step implementation
Assess supplier and model
Consider competence, locations, subcontractors, methods and access.
Specify requirements
Include secure SDLC, coding, testing, vulnerabilities, components and incident duties.
Clarify ownership
Define source code, IP, repositories, artifacts, data and documentation rights.
Control access
Use named accounts, least privilege, expiry and monitored environments.
Monitor delivery
Review metrics, code, findings, personnel changes and subcontractors.
Accept and exit
Verify deliverables, revoke access and transfer knowledge and assets.
What this could look like in practice
An external team develops a mobile application in the customer’s repository. Contractor accounts expire automatically, pull requests follow customer controls and an independent penetration test precedes acceptance.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Selection | Supplier secure-development capability is assessed. | Due diligence |
| Contract | Security, IP and assurance duties are defined. | Agreement |
| Delivery | Customer reviews pipeline and findings. | Governance report |
| Exit | Accounts, code, documentation and secrets transfer. | Exit checklist |
Implementation evidence
- Supplier assessment
- Security schedule
- IP terms
- Access records
- Development reports
- Code review
- Test results
- Exit evidence
Useful metrics
- Supplier findings overdue
- External accounts past expiry
- Deliverables meeting acceptance
- Undisclosed subcontractor changes
Common mistakes
- Assuming fixed-price delivery includes security.
- Supplier-controlled repository only.
- No right to inspect evidence.
- Using production data for development.
- Ending contract without knowledge transfer.
Questions an auditor may ask
- How was the developer assessed?
- Which security requirements are contractual?
- Who owns code and evidence?
- How is access removed at exit?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.