Software Development in Development Environments
Software development should only be done in dedicated development environments.
Plain language
This control means that any work on creating or changing software should happen in a special, separate area designed just for developing software. It's important because if you make changes in the wrong place, you might accidentally break something important or expose sensitive information.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
Development and modification of software only take place in development environments.
Why it matters
Without a separate development space, there's a risk of disrupting operations or accidentally exposing sensitive information by untested changes.
Operational notes
Regularly verify development is happening in designated spaces to prevent any accidental cross-over to operational systems, keeping business activities stable.
Implementation tips
- IT team should set up dedicated development areas: Ensure that there are specific computers or systems designated for developing or modifying software, separate from those used for day-to-day business operations.
- Managers should communicate policy: Make sure everyone involved in software creation knows where they should do their development work to keep it separate from live environments.
- Developers should validate the environment: Regularly check that development is only happening in the designated areas by confirming the computers or servers being used match the approved list.
- System owners should review access: Periodically check who has access to the development environments to confirm that only authorised developers can make changes.
- IT team should monitor environments: Use logs to track any changes made in development environments and ensure that those environments don't accidentally get used for everyday business tasks.
Audit / evidence tips
- Asklogs of software changes: Request a document or report showing recent changes made in the development environmentLook atwhich environments the changes were made inGoodChanges are only logged in dedicated development environments
- Askthe list of authorised development systems: Check the list against actual usage recordsLook atwhether the usage records match the systems and environments approved for developmentGoodUsage records match authorised systems
- Askaccess control lists: Review who has the ability to modify software within the development environmentLook atwhether all users have a defined role justifying accessGoodAll access is justified by a clear need and is regularly reviewed
- Aska policy document: Request the policy that mandates software development occur only in authorised environmentsLook atwhether the policy clearly defines where development is allowedGoodThe policy is clear, up-to-date, and communicated to all relevant staff
- Askincident records: Request any records of incidents where development was done outside the approved environmentsLook athow such incidents were identified and resolvedGoodAny breaches are documented with corrective actions taken immediately
Cross-framework mappings
How ISM-1419 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 8.25 | ISM-1419 requires that development and modification of software only occurs in development environments to avoid uncontrolled changes in ... | |
| Annex A 8.32 | ISM-1419 requires that software development and modification occur only in development environments, preventing ad-hoc production changes | |
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.19 | ISM-1419 requires that software changes are performed in development environments rather than on operational systems | |
handshakeSupports(3)expand_less | ||
| Annex A 8.4 | ISM-1419 requires software changes to occur only in development environments, reducing the likelihood of unauthorised or uncontrolled pro... | |
| Annex A 8.9 | ISM-1419 requires that development and modification of software only occurs in development environments, limiting configuration drift and... | |
| Annex A 8.29 | ISM-1419 requires software changes to be performed only in development environments rather than directly in production | |
linkRelated(1)expand_less | ||
| Annex A 8.31 | ISM-1419 requires development and modification of software to occur only in development environments, to protect production integrity | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.