Back to all 93 controls
    Annex A 8.25
    Technological

    A.8.25 Secure development life cycle

    Follow a secure development lifecycle.

    What good looks like

    Security requirements, threat modelling, secure coding, security testing at gates.

    Evidence an auditor will ask for

    SDLC policy, threat models, pipeline scans.

    Document template for this control

    The Secure Development Policy template gives you auditor-ready wording that fulfils Annex A 8.25. Preview the full document before you download the editable version.