Skip to content
arrow_back
search
Annex A 8.27 verified ISO/IEC 27001:2022

Secure system architecture and engineering principles

Create and use guidelines for building secure systems in all development projects.

record_voice_over

Plain language

This control is about making sure that when we build or update our information systems, we follow clear guidelines to keep them secure. If we skip this step, our systems might be vulnerable to attacks, leading to data breaches or interruptions in service.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Principles for engineering secure systems shall be established, docu- mented, maintained and applied to any information system development activities.
verified ISO/IEC 27001:2022 Annex A 8.27
priority_high

Why it matters

Without documented secure architecture and engineering principles, systems are designed inconsistently, increasing exploitable flaws, breaches and service disruption.

settings

Operational notes

Define and maintain secure architecture/engineering principles (e.g., least privilege, defence-in-depth), and require their use via design reviews and threat modelling.

Mapping detail

Mapping

Direction

Controls