Agile delivery and strong IT governance are often treated as opposing forces. On one side, agile frameworks such as SAFe emphasize speed, customer value, and rapid iteration. On the other, established governance and security frameworks - COBIT, ITIL, ISO/IEC 27001/27002, and the CIS Critical Security Controls - focus on risk reduction, resilience, and control.
In practice, this tension frequently leads to a familiar outcome: solutions that deliver business value quickly, but address security, compliance, or control requirements too late .
Bridging Agile Delivery and Control Frameworks
As part of a Design Science research project, I developed an artifact ...