PR.DS-P7: The development and testing environment(s) are separate from the production environment
CSF v1.1 References:
Threats Addressed:
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]
Note: This Privacy Framework Subcategory is identical to the Cybersecurity Framework Subcategory.
Related Controls
Cloud Controls Matrix v4.0
AIS-04: Secure Application Design and Development
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-06: Automated Secure Application Deployment
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
DSP-15: Limitation of Production Data Use
Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.
IVS-05: Production and Non-Production Environments
Separate production and non-production environments.
Critical Security Controls Version 8.1
16: Application Software Security
Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise.
16.8: Separate Production and Non-Production Systems
Maintain separate environments for production and non-production systems.
Cloud Controls Matrix v3.0.1
CCC-03: Quality Testing
Organizations shall follow a defined quality change control and testing process (e.g., ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services.
CCC-05: Production Changes
Policies and procedures shall be established for managing the risks associated with applying changes to: Business-critical or customer (tenant)-impacting (physical and virtual) applications and system-system interface (API) designs and configurations. Infrastructure network and systems components. Technical measures shall be implemented to provide assurance that all changes directly correspond to a registered change request, business-critical or…
DSI-05: Non-Production Data
Production data shall not be replicated or used in non-production environments. Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements.
Critical Security Controls Version 7.1
20: Penetration Tests and Red Team Exercises
Test the overall strength of an organization’s defense (the technology, the processes, and the people) by simulating the objectives and actions of an attacker.
20.5: Create Test Bed for Elements Not Typically Tested in Production
Create a test bed that mimics a production environment for specific penetration tests and Red Team attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems.