ISO/IEC 27001

Information security management

A systematic approach to information protection, security and risk management.

What it is

ISO/IEC 27001 is the standard for information security management systems. It requires systematically identifying risks and putting controls in place that protect the confidentiality, integrity and availability of information.

What it means for you

  • Your data is handled under documented security controls.
  • Risks are assessed regularly, not only after an incident.
  • Easier NIS2 and DORA compliance in your own audits.

How we apply it

Access management, encryption, logging and incident response are part of everyday work. Certification is in progress, and you can follow the status of the controls in the Compliance Live Panel.

Other standards and practices

  • ISO 9001 In progress

    Quality management

    Consistently high quality, clear processes and continuous improvement.

  • ISO/IEC 20000-1 In progress

    IT service management

    Structured, reliable IT service management across the entire service lifecycle.

  • ITIL 4 In practice

    Service management

    Service value system, incident management and SLA delivery 24/7.

  • COBIT In practice

    IT governance and risk

    Strategic alignment of business goals and IT processes, risk management and audit control.

  • Secure SDLC In practice

    Secure development lifecycle

    A DevSecOps approach: continuous security testing and code protection at every CI/CD stage.

  • SRE In practice

    Site reliability engineering

    High-availability engineering (up to 99.99%) with SLO/SLI metrics and error budgets.

  • Zero Trust In practice

    NIST SP 800-207

    Security architecture with no implicit trust: strict identity verification and microsegmentation.