unified
UC-SDLC-14 — Protect production systems during audit testing
Plan and agree audit and assurance testing of operational systems between the tester and appropriate management before testing begins: define and approve scope, limit testers to read-only access where possible or use isolated copies, schedule tests to minimize disruption, and monitor and log all audit access.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-14
- title
- Protect production systems during audit testing
- statement
- Plan and agree audit and assurance testing of operational systems between the tester and appropriate management before testing begins: define and approve scope, limit testers to read-only access where possible or use isolated copies, schedule tests to minimize disruption, and monitor and log all audit access.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.8.34
- coverage
- full
- relationship
- equal
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-14 — Protect production systems during audit testing maps_to A.8.34 — Protection of information systems during audit testing
- framework
- iso-27001
- control_id
- A.8.34
- coverage
- full
- relationship
- equal
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-14 — Protect production systems during audit testing mitigates Corruption or integrity loss of critical data
- strength
- primary
- rationale
- Restricting audit testers to read-only access or isolated copies prevents accidental or intentional alteration/deletion of production data during testing.
- UC-SDLC-14 — Protect production systems during audit testing mitigates Software and information-system failure
- strength
- primary
- rationale
- Limiting testers to read-only/isolated copies and scheduling tests to minimize disruption prevents audit testing from degrading production availability.
- Technical Security Testing & Pentest Engagement operates UC-SDLC-14 — Protect production systems during audit testing
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-14 — Protect production systems during audit testing