The worlds of information access and information security are inextricably joined, and as such, data must be readily available and accessible to all who need it, yet its confidentiality and integrity simultaneously maintained. As project managers, we have all managed technical change, but the current pace of technological advancements, coupled with an influx of increasingly sophisticated security threats and attacks, as well as the need to comply with a myriad of privacy laws and security protection standards, all but guarantee heightened interaction and benefits to partnering with our local information security group... Saving Changes...
Hi, information security is getting more and more important and ISO 27001 becomes more wide spread. ISO 27001 control A.6.1.5 is mandatory therefore no discussion it must be included in the organization's project methodology.
However, I think it does not qualify for a new knowledge area for the PMBOK, because ISO 27001 is about establishing an Information Security Management System (ISMS) which is effectively part of the organization's risk management. I support adding some best practice to PMBOK's risk management knowledge area.