4 ms·
imo this sounds like one of those situations where you learn to say, "No." Unless there is a compelling reason to be ISO-compliant with the majority of your cus
by devmonk 16y ago
imo this sounds like one of those situations where you learn to say, "No." Unless there is a compelling reason to be ISO-compliant with the majority of your customers, you will end up wasting so much time on getting compliant, you won't be able to do the things the rest of your customers need. That goes for pretty much any kind of standards compliance. Only do what is required to be legal to get and retain the business you need.
To answer the question at hand though, I think you'd need to grow enough where you can take the risk at persuing certifications.
Good luck.
- gbog 16y agoWell, we can not afford to loose our main client, and the renewal of their contract is tied to ISO 27001 compliance. Moreover, a very big company just bought a part of our shares and require us to comply to their own security policies. Both go in the same direction, and we have to go this way, whatever painful the process is. But we tech team still want to be happy go to work every morning. So I'm wondering if there is a less painful way to go there.
- deleted 16y ago[deleted]
- brudgers 16y agoIs the big company going to require you to follow their existing procedures, or are you free to develop your own?
- gbog 16y agoWe agreed we will "eventually" follow all their existing procedures, but it is really annoying because we would have to switch many of our secure Linux solutions to their required Windows environment, so this "eventually" may mean "in a very far future" for some requirements. Some other procedures are very interesting and we are happy to learn from them.