A.12.5.4
Information leakage
Control
Opportunities for information leakage shall be prevented.
A.12.5.5 Outsourced software development
Control
Outsourced software development shall be supervised and monitored by the organization. 18
A.12.6 Technical Vulnerability Management
Objective: To reduce risks resulting from exploitation of published technical
vulnerabilities.
A.12.6.1 Control of technical vulnerabilities
Control
Timely information about technical vulnerabilities of information systems being used
shall be obtained, the organization's exposure to such vulnerabilities evaluated, and
appropriate measures taken to address the associated risk.