View Categories

A8.28 Secure coding

4 min read

Secure coding involves developing software in a way that guards against the introduction of security vulnerabilities. Poor coding practices can lead to flaws such as injection attacks, broken authentication, cross-site scripting (XSS), and insecure data storage—all of which can be exploited by malicious actors.

ISO 27001 A8.28 Secure coding requires organizations to establish, implement, and maintain secure coding guidelines that are aligned with industry standards and tailored to the organization’s specific technology stack. Developers should be trained and equipped to apply these practices consistently across all projects.

Implementation Guide #

Step 1: Define Secure Coding Standards

  • Develop secure coding guidelines based on recognized best practices such as OWASP Secure Coding Practices, SEI CERT Coding Standards, or CWE Top 25.
  • Customize the standards based on programming languages and frameworks used (e.g., Java, .NET, Python).
    → Tool Recommendation: Document using Confluence, SharePoint, or Notion for centralized reference.

Step 2: Train Developers in Secure Coding

  • Conduct mandatory training for developers on secure coding concepts, common vulnerabilities, and how to avoid them.
    → Tool Recommendation: Use platforms like Secure Code Warrior, Pluralsight, or OWASP WebGoat for hands-on training.

Step 3: Enforce Code Quality and Security Reviews

  • Integrate secure coding reviews into the code review process.
  • Include security-focused peer reviews and automated tools to check for vulnerabilities.

→ Tool Recommendation:

  • SonarQube, Checkmarx, Fortify, Snyk for static code analysis
  • GitHub Advanced Security, GitLab Secure, or Veracode for CI-integrated scanning

Step 4: Use Secure Development Tools and Frameworks

  • Favor frameworks and libraries that provide built-in protection (e.g., parameterized queries, CSRF protection).
  • Keep dependencies up to date and vetted for vulnerabilities.

→ Tool Recommendation:

  • Dependabot, Snyk, OWASP Dependency-Check

Step 5: Perform Secure Code Testing

  • Conduct security testing such as static application security testing (SAST), dynamic application security testing (DAST), and fuzz testing.
  • Apply automated tests in your CI/CD pipelines.

→ Tool Recommendation:

  • Burp Suite, OWASP ZAP for DAST
  • SonarQube, Fortify, or CodeQL for SAST

Step 6: Maintain a Secure Coding Knowledge Base

  • Create a secure coding knowledge repository with examples, remediation guides, and FAQs.
  • Update the knowledge base regularly based on threat intelligence and development feedback.

Templates #

  • Secure Coding Standards Document
  • Code Review Checklist with Security Focus
  • Vulnerability Remediation Log
  • Secure Development Training Records
  • Secure Coding Policy

Example #

A fintech company faced a critical SQL injection vulnerability discovered in their customer portal. After a security assessment, they implemented OWASP Secure Coding Guidelines, integrated Checkmarx into their GitLab CI/CD pipeline, and trained all developers using Secure Code Warrior. Within two months, their code quality improved, and post-deployment vulnerabilities dropped by 80%.

How to Comply #

To comply with ISO 27001 A.8.28, organizations should:

  • Define secure coding guidelines tailored to their tech stack.
  • Train developers and review their adherence to these guidelines.
  • Use automated tools and manual reviews to detect and prevent insecure code.
  • Test applications thoroughly before deployment.
  • Maintain documentation and evidence of secure coding practices.

How to Pass an Audit #

Key Documents to Prepare:

  • Secure Coding Policy and Guidelines
  • Secure Development Training Logs
  • Static and Dynamic Testing Reports
  • Code Review Logs Highlighting Security Checks
  • Vulnerability and Patch Management Logs

What the Auditor Will Check:

  • Are secure coding standards established and followed?
  • Are developers trained in secure coding practices?
  • Are tools used to detect insecure code during development?
  • Is there documentation showing security testing of code?

Top 3 Mistakes People Make #

  • Treating security as an afterthought, addressing it only after development.
  • Relying solely on automated tools without human code review.
  • Not keeping third-party libraries and frameworks updated.

ISO 27001 Secure Coding FAQ #

Q1: Do we need secure coding for internal applications too?
Yes, all software—internal or external—should be developed with secure coding principles to prevent insider threats or accidental exposure.

Q2: What if we outsource development?
Ensure that third-party developers are contractually obligated to follow your secure coding standards and submit code for review.

Q3: How often should coding standards be updated?
At least annually, or whenever a major update is released for a framework, language, or security guideline you rely on.

ISO 27001 Controls and Attribute Values #

ControlAttribute Value
A.8.28 Secure CodingPreventive, Risk-Based, Technical
PurposeTo reduce the risk of software vulnerabilities through the application of secure coding practices.
ApplicabilityAll software development activities—internal or outsourced.
ISO 27001 DomainsSystem Acquisition, Development, and Maintenance

By embedding secure coding into your development lifecycle, you build more resilient applications, reduce risk exposure, and ensure compliance with international security standards.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now