The ultimate audit guide to ISO 27001 Annex A 8.33 Test Information
Table of contents
- 1. Check there is a Test Data Selection Policy
- 2. Confirm there is no PII in Test Environments
- 3. Validate the Data Masking and Obfuscation Integrity
- 4. Ensure there is Authorisation for Operational Data Usage
- 5. Check Test Data Access Control Segregation
- 6. Review Independent Audit Logging of Test Data Access
- 7. Confirm Secure Deletion of Test Information
- 8. Confirm System Hardening Matches Production
- 9. Check the Cloud Storage Privacy of Test Data
- 10. Evidence Periodic Test Data Compliance Reviews
1. Check there is a Test Data Selection Policy
Verification Criteria: A documented policy exists defining the requirements for selecting, protecting, and deleting test data, specifically addressing the use of operational data.
Required Evidence: Approved “Test Data Management Policy” or “Secure Development Standard” with explicit rules on data de-identification.
Pass/Fail Test: If the organisation cannot produce a formal standard specifying how test information must be secured, mark as Non-Compliant.
2. Confirm there is no PII in Test Environments
Verification Criteria: Personal Identifiable Information (PII) or sensitive production data is not present in development or test environments without an approved business justification.
Required Evidence: Database scan results from staging/test environments showing the absence of legitimate production records (e.g., real names, emails, or credit card numbers).
Pass/Fail Test: If a manual query of the test database reveals unmasked production PII, mark as Non-Compliant.
3. Validate the Data Masking and Obfuscation Integrity
Verification Criteria: Technical mechanisms (masking, pseudonymisation, or anonymisation) are applied to operational data before it is ingested into test environments.
Required Evidence: Data masking logs or script configurations showing the transformation of production data into synthetic variants.
Pass/Fail Test: If “masked” data can be easily re-identified or reversed using available keys or mapping tables in the test environment, mark as Non-Compliant.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Ensure there is Authorisation for Operational Data Usage
Verification Criteria: Every instance where operational data is copied to a test environment is supported by a documented and approved business justification.
Required Evidence: Approved Change Request (CR) or Data Transfer Request form signed by the Data Asset Owner.
Pass/Fail Test: If production data has been migrated to a test environment without formal sign-off from the Data Owner, mark as Non-Compliant.
5. Check Test Data Access Control Segregation
Verification Criteria: Access to test data is restricted to authorised developers and testers, following the principle of least privilege.
Required Evidence: Access Control Lists (ACLs) or Identity and Access Management (IAM) reports for the test database showing restricted user groups.
Pass/Fail Test: If all members of the IT department have unrestricted administrative access to the test data repository, mark as Non-Compliant.
6. Review Independent Audit Logging of Test Data Access
Verification Criteria: All access to and modifications of test information are recorded in an immutable audit log, specifically for environments containing operational data copies.
Required Evidence: System logs or SIEM reports showing “read/write” events on the test data repository with associated User IDs.
Pass/Fail Test: If test data can be modified or exported without a corresponding entry in a central audit trail, mark as Non-Compliant.
7. Confirm Secure Deletion of Test Information
Verification Criteria: Test data is securely removed from environments immediately after the testing phase is complete to prevent “data remanence” or “scope creep”.
Required Evidence: Decommissioning logs or automated cleanup script execution records for temporary test databases.
Pass/Fail Test: If “temporary” test data sets from projects completed over six months ago remain active on testing servers, mark as Non-Compliant.
8. Confirm System Hardening Matches Production
Verification Criteria: The environments where test information resides are hardened to the same technical standard as production environments to prevent unauthorised exfiltration.
Required Evidence: Configuration audit reports or IaC (Infrastructure as Code) templates showing parity in security settings between environments.
Pass/Fail Test: If the test environment has security controls (e.g., firewalls or antivirus) disabled to “improve performance,” mark as Non-Compliant.
9. Check the Cloud Storage Privacy of Test Data
Verification Criteria: Test data stored in cloud repositories (e.g., S3 buckets, Azure Blobs) is not publicly accessible and is protected by encryption.
Required Evidence: Cloud Security Posture Management (CSPM) reports showing no “Public” access for test data volumes and active encryption-at-rest.
Pass/Fail Test: If a cloud-hosted test database is accessible via the public internet without a VPN or authenticated gateway, mark as Non-Compliant.
10. Evidence Periodic Test Data Compliance Reviews
Verification Criteria: Management or Security teams perform regular scans or audits to ensure that no unauthorised production data has “leaked” into test zones.
Required Evidence: Quarterly Internal Audit reports or automated Data Discovery tool logs specifically targeting non-production environments.
Pass/Fail Test: If the organisation has no record of verifying its test environments for unauthorised data presence in the last 12 months, mark as Non-Compliant.
