4 ms·
Some months ago my company got certified with the ISO 27001 thing about information security management. It was a horrible process to be part of and in charge f
by mns 3y ago
Some months ago my company got certified with the ISO 27001 thing about information security management. It was a horrible process to be part of and in charge for for the IT side and the consultants and auditors where the types of people that take themselves too seriously, haven't worked in a real environment in 20 years and come and suggest things just because it's in the standard, but with no context as to how companies operate. Anyhow, apparently this certification is somehow important for a lot corporate clients, I always said that's it's mostly security theatre. Now I see that both Atlassian and Trello are ISO 27001 certified and they leak the data like this... How do they even get away with this in an audit, maybe because it's just a worthless certification.
- klysm 3y agoI think it’s fundamentally just ass covering. Executives want some kind of certification to be able to say they did due diligence. The quality of the certification doesn’t really matter as long as it’s standard enough