Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Protection and minimisation of test data

Critical
High
Normal
Low

The data and other materials used for testing should be carefully selected and protected.

Production information that contains personal or other confidential information should not be used for testing purposes.

Connected other frameworks and requirements:
14.3: Test data
ISO 27001
14.3.1: Protection of test data
ISO 27001
8.33: Test information
ISO 27001

Specific safeguards for production data used for testing

Critical
High
Normal
Low

The use of production data for testing purposes should be avoided. If confidential information is used in testing, the following security measures should be used:

  • all sensitive details should be either deleted or made secure (e.g. anonymisation of personal data)
  • testing environments are subject to the same strict access control as production
  • copying production data to the test environment is done only with a separate authorization
  • production data is removed from the test environment immediately upon completion of testing
Connected other frameworks and requirements:
14.3: Test data
ISO 27001
14.3.1: Protection of test data
ISO 27001
8.33: Test information
ISO 27001
No items found.