Back to all 93 controls
Annex A 8.25
Technological
A.8.25 Secure development life cycle
Follow a secure development lifecycle.
What good looks like
Security requirements, threat modelling, secure coding, security testing at gates.
Evidence an auditor will ask for
SDLC policy, threat models, pipeline scans.
Document template for this control
The Secure Development Policy template gives you auditor-ready wording that fulfils Annex A 8.25. Preview the full document before you download the editable version.
