Test environments are essential.
Using real data in them, without control, is one of the fastest ways to create a breach.
Annex A 8.33 exists to ensure organisations select, protect, use, and dispose of test information appropriately, reducing the risk of unauthorised access, data leakage, and misuse while still enabling effective testing.
This control is about protecting information outside production, where discipline often slips.

Annex A 8.33 focuses on test information used in development, testing, and acceptance environments.
In practice, this includes:
The control does not prevent testing.
It ensures test data does not become an unmanaged security liability.
Test environments often have:
When real or sensitive information is introduced into these environments:
Annex A 8.33 ensures organisations apply the same level of thought to test data as they do to live data, even if the controls differ.
This control replaces ISO 27001:2013 Annex A 14.3.1, with clearer emphasis on data masking and removal.
Organisations should consider what information is genuinely required to achieve reliable test results.
Where possible:
More data does not equal better testing.
Live or production data should not automatically be used for testing.
Where production data is proposed:
Uncontrolled copying of live data is a common compliance failure.
When sensitive information is used in test environments, organisations should consider controls such as:
The objective is to retain test value while reducing exposure.
Test environments should not be treated as open systems.
Access should be:
Default credentials and shared accounts increase risk significantly.
Where sensitive information is used:
Visibility supports accountability and investigation if issues arise.
Test information handling should be:
This reduces accidental crossover between environments and controls.
Test data should be:
Lower criticality does not justify poor protection.
Once testing is complete:
Old test data is often forgotten — and later discovered during incidents.
Annex A 8.33 applies equally where:
Suppliers should:
External testing does not reduce internal responsibility.
Where test data includes personal information:
Test environments are not exempt from regulation.
Most test data incidents are caused by convenience over control.
Annex A 8.33 is about preventing non-production environments from becoming high-risk blind spots.
When test information is managed effectively:
Test environments are essential.
Uncontrolled test data is not.
Annex A 8.33 ensures organisations test safely, not carelessly.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today