Android and iOS

ISO/IEC 27001 and managing mobile security controls

OWASP, secure development and the evidence behind controls.

Standards and evidence1 min readEditorial methods

Control ownership, implementation and evidence matter in an ISO/IEC 27001 context. Buying a protection product does not complete a management system.

Evaluation approach

Link the control's rationale, assets, owner and monitoring to risk assessment. Record exceptions and changes. Reassess risk and effectiveness when the product changes.

Application example

A control record for mobile transaction integrity should include false-positive review, policy-change authority and pre-release test ownership alongside the product name.

Limits and considerations

A supplier's certification does not automatically certify a customer's application or processes. Organization, scope and validity matter.

Checks and decisions

  • Link controls to risk records
  • Assign owners and measures
  • Verify certification scope

Keep management-system evidence consistent with daily operations. Product ownership cannot compensate for a process that does not operate in practice.

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.