Does anyone know the potential pitfalls of applying ISO controls to processes?
My organisation is mooting an expansion of our registration to all of our top 40
applications (from 3) based on the approach of applying the 27001 controls to
the ITIL - type processes such as problem management, change and release, help
desk etc. It worries me slightly that if we fail in one process then this will
flow down into a failure across the board and it will appear that our security
has deteriorated. In actuality, it has improved in the past year.