Security is no longer optional - it’s a core pillar of software engineering. ISO 27001 certification is essential for building trust, minimising risks, and ensuring compliance. This talk explores its significance for software companies, focusing on clause A.8 and secure development practices.
We’ll map ISO 27001 controls to a modern SDLC, showing how they align with agile and DevOps. Practical tools like static analysis, dependency scanners, and automated checks will be covered, along with strategies for integrating OWASP SAMM to continuously assess and enhance security. Learn how to embed security seamlessly into your development workflow.