Annex A Controls
Annex A Controls
The top 3 mistakes people make for ISO 27001 Annex A 8.4 are
1. Allowing everyone to access code
Depending on the size of teams, complexity and mix of internal and
external resource the requirements for access restrictions on code can
often get over looked. Be sure to understand and document the
requirements, put in place processes and lock the access down based
on organisation need and business risk.
2. Your code is on laptops
This common mistake actually relates to copies of your code being all
over the place. It can be hard to manage code and developers and
teams to maintain a single source of truth in a controlled way that
protects your intellectual property and the integrity of the code base.
Some people use check in and check out solutions but be aware of
rogue copies of your code out in the real world and the risk it poses to
you, usually in terms of that code being taken and used some where
else for commercial gain without your approval or knowledge.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that
version numbers match where used, having a review evidenced in the
last 12 months, having documents that have no comments in are all
good practices.