ISO/IEC 27001:2022 Annex A · Control 8.27
Secure System Architecture and Engineering Principles: A Practical Implementation Guide
Use documented security principles to guide trustworthy architecture and engineering decisions.
This control concerns establishing, documenting, maintaining and applying principles for engineering secure systems.
What should the control achieve?
- Security engineering principles are approved and current.
- Architecture decisions apply them consistently.
- Trust boundaries and failure assumptions are explicit.
- Exceptions and technical debt are visible.
Step-by-step implementation
Define principles
Include least privilege, defense in depth, secure defaults, isolation, simplicity, resilience and verifiability.
Create architecture method
Require context, assets, trust boundaries, data flows, threats and assumptions.
Review high-risk designs
Use competent multidisciplinary reviewers and documented decisions.
Select patterns
Provide approved reference architectures and reusable controls.
Record exceptions
Capture rationale, risk, safeguards, owner and target resolution.
Learn and update
Use incidents, tests and technology change to improve principles.
What this could look like in practice
A multi-tenant platform uses an approved reference architecture with tenant isolation, separate management plane, centralized identity and immutable audit logs. Deviations require Architecture and Security approval.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Principle | Secure-by-default rule guides service template. | Engineering standard |
| Design review | Threats and trust boundaries are assessed. | Architecture decision |
| Pattern | Approved identity pattern avoids custom authentication. | Reference architecture |
| Exception | Technical debt has owner and expiry. | Exception record |
Implementation evidence
- Engineering principles
- Architecture review process
- Reference patterns
- Threat models
- Decision records
- Exception register
- Design test results
- Review updates
Useful metrics
- High-risk designs reviewed
- Architecture exceptions overdue
- Use of approved patterns
- Incidents linked to design weakness
Common mistakes
- Keeping principles too abstract.
- Reviewing diagrams without data flows.
- Assuming internal networks are trusted.
- Allowing custom security mechanisms by default.
- No owner for architecture debt.
Questions an auditor may ask
- Which principles guide design?
- Show their application in a real system.
- How are exceptions managed?
- How do incidents change architecture guidance?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.