We have been certified to ISO/IEC 27001, covering product development, project delivery and technical support.
What the certification covers
Product development, project delivery and technical support — in other words, every step a customer touches. It certifies that our process is repeatable and auditable, not that one particular system passed a test.
- An inventory of information assets, each with a named owner
- Access requests, approvals and revocation
- Change and release records
- Incident response and post-mortems
What it means for customers
Data handling, access control and incident response all follow an auditable process rather than depending on individual experience. When something goes wrong we can say who did what, on what basis, at which step.
What we still have to do
Certification is a starting point. The next two items are reducing the manual steps left in the process, and bringing supplier assessment (third-party components and contracted services) into the same system.
