2 ms·
ISO 27001 is actually quite flexible. The implementation details can be as 'heavy' ( or not ) as you make them. For instance change controls implies all kinds o
by jdee 16y ago
ISO 27001 is actually quite flexible. The implementation details can be as 'heavy' ( or not ) as you make them. For instance change controls implies all kinds of non-agile processes that inhibit you from building software the way you do today. Change control from an ISO 27001 point of view can be as simple as stating 'when a request for a new feature comes in, we put it on a list, and discuss the impact of it'. I'm sure you would recognize this process as a SCRUM product backlog.
You can be 27001 and still be agile - we are. The biggest problem of all is training your staff to be ISO-aware (data classification, password policies etc) and making them stick to it so that you pass the audits.