ISO 27001 Annex : A.14.3 Test data
ISO 27001 Annex : A.14.3 Test data its objective is to ensure that data used for research are secured. A.14.3.1 Protection of test data Control – Careful collection, security, and review of test data should be performed. Implementation Guidance – It should be avoided the use of operational information containing personal information or any other confidential information for test purposes. Where personal information or otherwise confidential information for testing purposes is used, all sensitive information and content should be protected either by deletion or modification. When used for testing purposes, the following guidelines should be used for the protection of operational data: The access management protocols applicable to the running application systems should also refer to the application control systems; Every time operational information is copied to the test setting, separate authorization should be granted; Operatio...