Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

3
  • It should be "The ability to make modifications to the source code for the binary shall be restricted"
    – user163495
    Commented Nov 21, 2019 at 16:25
  • I don't think this is applicable to FOSS. I think it is applicable to source code owned by the organization. All controls implicitly apply to the scope and to nothing else. If you don't own it, you can't control the risks. Commented Dec 20, 2021 at 12:03
  • GitLab (gitlab.com) is an open source project that recently went through ISO 27001 certification. Their blogs and compliance pages do a great job describing their journey through ISO 27000 / SOC 2 certification. Commented Feb 9, 2022 at 16:39