Controls

Terug naar overzicht
Version

SB.14.002 Testing Data

Medium
Medium
nvt
Secure Development
System Owner
v2.0 (Q1 2024)

No production information is exposed or reused in environments other than for acceptance testing. This includes production data (also not pseudonymised), API keys, credentials and production server hostnames.

Specification

On sufficiently large datasets, removing names and randomly scrambling records can be a way to generate realistic testing data, maintaining a realistic distribution of values and edge cases, without being able to point at which data belongs to what individual.

ISO 27001 & 27002:2022

8.1,
A8.4,
A8.29,
A8.31,
A8.33

SURF toetsingskader informatiebeveiliging (NBA-volwassenheidsmodel)

CH.04 Test environment
CH.05 Testing of changes