Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.30

Outsourced Development: A Practical Implementation Guide

Maintain security governance and assurance when external parties develop systems or software.

This control concerns directing, monitoring and reviewing activities related to outsourced system development.

Practical interpretation: Outsourcing execution does not outsource accountability. Requirements, access, code ownership, development practice, testing, delivery and exit need active governance.

What should the control achieve?

  • Supplier capability and risk are assessed.
  • Security requirements and ownership are contractual.
  • Development access and environments are controlled.
  • Deliverables and evidence are independently accepted.

Step-by-step implementation

1

Assess supplier and model

Consider competence, locations, subcontractors, methods and access.

2

Specify requirements

Include secure SDLC, coding, testing, vulnerabilities, components and incident duties.

3

Clarify ownership

Define source code, IP, repositories, artifacts, data and documentation rights.

4

Control access

Use named accounts, least privilege, expiry and monitored environments.

5

Monitor delivery

Review metrics, code, findings, personnel changes and subcontractors.

6

Accept and exit

Verify deliverables, revoke access and transfer knowledge and assets.

What this could look like in practice

An external team develops a mobile application in the customer’s repository. Contractor accounts expire automatically, pull requests follow customer controls and an independent penetration test precedes acceptance.

ActivityPractical implementationEvidence
SelectionSupplier secure-development capability is assessed.Due diligence
ContractSecurity, IP and assurance duties are defined.Agreement
DeliveryCustomer reviews pipeline and findings.Governance report
ExitAccounts, code, documentation and secrets transfer.Exit checklist

Implementation evidence

  • Supplier assessment
  • Security schedule
  • IP terms
  • Access records
  • Development reports
  • Code review
  • Test results
  • Exit evidence

Useful metrics

  • Supplier findings overdue
  • External accounts past expiry
  • Deliverables meeting acceptance
  • Undisclosed subcontractor changes

Common mistakes

  • Assuming fixed-price delivery includes security.
  • Supplier-controlled repository only.
  • No right to inspect evidence.
  • Using production data for development.
  • Ending contract without knowledge transfer.

Questions an auditor may ask

  • How was the developer assessed?
  • Which security requirements are contractual?
  • Who owns code and evidence?
  • How is access removed at exit?
Implementation test: Trace one outsourced feature from requirement through supplier access, code review, security test, acceptance and ownership transfer.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.