Overview
ISO/IEC 27034-1:2011 is the international application security standard that provides an overview of concepts, definitions and principles for integrating security into application life‑cycle processes. Part 1 introduces the vocabulary and high‑level framework used across ISO/IEC 27034, explains how application security fits with an organization’s information security management system (ISMS), and describes context, roles and processes for managing security of in‑house, third‑party or outsourced applications.
Keywords: ISO/IEC 27034-1:2011, application security standard, Application Normative Framework, Organization Normative Framework.
Key topics and technical requirements
- Scope and definitions: Clarifies the difference between application security and software security and defines key terms used in later parts of ISO/IEC 27034.
- Application security requirements: Identifies sources of requirements (business, regulatory, technical) and the need to engineer security requirements into application specifications.
- Risk and controls: Covers application‑level risk assessment, threat/vulnerability considerations, impact analysis and selection of controls appropriate to the application context.
- Organization Normative Framework (ONF): Guidance for establishing organizational policies, libraries and processes that support consistent application security.
- Application Normative Framework (ANF) and Application Security Controls (ASC): Structures for mapping controls to specific application needs and life‑cycle stages.
- Processes: High‑level processes for ONF management, application security management, provisioning/operation and security auditing.
- Integration guidance: Mapping examples showing how to fit existing secure development lifecycles (SDL) and other standards (e.g., mapping ASCs with NIST SP 800‑53) into ISO/IEC 27034.
Practical applications
- Embedding security into requirements, design, implementation, testing and operation of enterprise applications.
- Creating an Application Normative Framework to reuse security patterns, controls and responsibilities across projects.
- Performing targeted application risk assessments and demonstrating application security to auditors or acquirers.
- Guiding procurement, outsourcing and supplier assurance activities for application development and operation.
Who should use this standard
- Security managers and ISMS teams integrating application controls.
- Application owners, development and operations teams responsible for secure delivery.
- Procurement/acquisition teams and vendors evaluating security expectations.
- Auditors and assurance professionals assessing application security maturity.
Related standards
ISO/IEC 27034 is intended to work with other standards such as ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, and mappings to security assurance and system life‑cycle standards (e.g., ISO/IEC 15288, ISO/IEC 12207).