How Stacc passed their ISO27001 audit without disruption or paperwork
-
Challenges
- How to get certified without adopting a rigid âoff the shelfâ process
- How to avoid gates, checklists and change board meetings
- How to pass an audit without manual evidence gathering
-
Solutions
- Integration with all of their different processes and toolsÂ
- Automated evidence gathering in their pipelines and environmentsÂ
- Provable compliance without paperwork, meetings or delays
Stacc
FTE 190
We didnât spend any extra time gathering evidence manually because all of it had already been recorded in Kosli.
Ăyvind Fanebust, Partner @Stacc
We have a strong culture of autonomy across our teams and we wanted to keep that. The big question for us was - how can we keep doing DevOps in our teams and standardize compliance across them? Also, as a developer, the change management part of the ISO certification worried me. I thought it would mean meetings and checklists.
We started with a proof of concept in two teams with Github and Bitbucket. The teams chose the types of evidence that they wanted to record in Kosli - pull requests, code reviews, and so on.Â
When it comes to the change management part of the audit, all the auditor needs to know is that you have a process and that youâre following it. All we had to do was show them the Kosli dashboard.Â
We were delivering our software according to our process, but until Kosli we didnât have an easy way to prove we were compliant
We could bring up any change and display the evidence that it had been through code review, had a deployment approval done by a certain person on a certain date, and that it was running in production.Â
We didnât spend any extra time gathering evidence manually because all of it had been recorded in Kosli. We were delivering software according to our process, but until Kosli we didnât have an easy way to prove that we were compliant.Â
When it came to the change management part of the ISO27001 audit we passed with flying colors.
Ready to ship with more confidence?
Got a question about Kosli?
Weâre here to help, our customers range from larges fintechs, medtechs and regulated business all looking to streamline their DevOps audit trails
Contact us