Skip to content
arrow_back
search
Annex A 5.8 verified ISO/IEC 27001:2022

Information security in project management

Include security checks in all projects to prevent risks from new systems.

record_voice_over

Plain language

This control is about making sure that every project considers information security right from the start. If you overlook security in projects, you might end up with new systems or processes that put your organisation at risk of data breaches or downtime.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Information security shall be integrated into project management.
verified ISO/IEC 27001:2022 Annex A 5.8
priority_high

Why it matters

If security is not built into project plans and stage gates, releases may introduce vulnerabilities and rework, causing delays, cost overruns and incidents.

settings

Operational notes

Define security requirements early, include security deliverables in stage gates (design, build, test, go-live), and track risks/issues in the project register.

Mapping detail

Mapping

Direction

Controls