Overview
ISO/IEC 27034-6:2016 - part of the ISO/IEC 27034 series on application security - delivers practical case studies and usage examples of Application Security Controls (ASCs). Rather than normative prescriptions, this part provides realistic ASC examples (for instance, a Java mobile application code-review ASC), XML representation examples, and guidance on adapting ASCs to an organization’s context. The standard helps organizations implement the Application Security Framework and Organizational Normative Framework (ONF) described across ISO/IEC 27034.
Key topics and technical highlights
- Application Security Controls (ASCs): focused examples showing how to define, structure and use ASCs to address application-level threats.
- ASC representation: examples use the XML data structure recommended in ISO/IEC 27034-5-1 to enable consistent ASC exchange and implementation.
- Case studies included: Java code revision for mobile apps; privacy requirements spanning two countries; integration and implementation of third‑party ASCs; use of the Application Security Life Cycle Reference Model (ASLCRM); and integrating ASCs into a secure development life cycle (SDLC).
- Application levels of trust and information classification: practical categorization examples (e.g., baseline → private) and how ASC selection maps to those tiers.
- Secure development life cycle phases: mapped ASC activities across preparation, requirements, design, implementation, verification, release and sustainment phases.
- Annex A: informative XML examples supporting the case studies and demonstrating ASC encoding for tool or process integration.
- Audience and role guidance: targeted at domain experts, application security teams, developers, auditors and organizational ONF committees responsible for ASC creation, validation and maintenance.
Practical applications - who uses this standard
- Application security teams and developers: adopt the ASC examples (e.g., code review ASC for Java mobile apps) as starting points for project-level controls.
- Security architects and ONF committees: adapt case-study patterns to build an organizational ASC library and policy mapping.
- Tool vendors and integrators: use the XML examples to support ASC import/export and automation across SDLC tools.
- Auditors and compliance teams: validate that ASCs have been defined and implemented consistently across application lifecycles.
Related standards (if applicable)
By providing concrete ASC templates, XML examples and SDLC mappings, ISO/IEC 27034-6:2016 helps organizations translate application-security principles into implementable controls and repeatable processes.