This was the subject of my 2019 Masters Thesis/Project.
Abstract
The Information Security landscape is ever changing, and faced with new threats, new legislation and decreasing finances it’s imperative that we consider new and novel methods to analyse and document these risks.
This Action Research project report explores the deployment of a number of Agile Techniques and Methods, experimenting with adaptations to current practice in order to reduce the burden of traditional approaches to Information Security.
A background analysis of the current literature related to these methods takes place, which is also supplemented with a survey, considering the attitudes towards Information Security and Agility across the Further Education Sector.
A phased approach to improvements is adopted, splitting the experimentation into three distinct Action Research Cycles. Feedback has been gathered at each stage, both observationally and via the use of Surveys.
A number of conclusions are drawn, revealing that these Methods and Techniques have fulfilled the requirements set out in the initial research questions. The success of the project can also be attributed to the Agile approaches used to manage the project.

