DEC 10, 2018
We take threats to the availability, integrity, and confidentiality of our client's information seriously. As such, we are pleased to announce that Bevy is an ISO/IEC 27001:2013 certified provider whose Information Security Management System (ISMS) has received third-party accreditation from the International Standards Organization. We invested significantly in this effort and are proud of this accomplishment.
The standard
ISO/IEC 27001:2013 is meant to be usable for virtually any type of organization and requires active maintenance to ensure the ISMS remains relevant and fits the organizational context, as it changes over time.
Key features include:
- Active management involvement
- Risk management processes
- Continuous improvement
- Internal and external auditing
It is possible to have a ISO/IEC 27001 compliant ISMS without being certified. Of course, it lends a lot more assurance to undergo external auditing by an ANAB-accredited certification body to achieve independent certification of such compliance. The latter is the path we chose; surveillance audits in subsequent years will help assure our continued compliance with the standard.
It matters
Management of organizational security should not occur by accident. ISO/IEC 27001, describes a framework for an ISMS that (among other things) requires active leadership involvement. At Bevy security is part of the conversation, from top to bottom. We determined that ISO/IEC 27001 provides useful formalism appropriate for our organization and we subject ourselves to external auditing to ensure we continue to conform.
As a client, you should expect this.
Further information
Please visit the
security/compliance page for additional information or reach out to
security with further questions and/or feedback you might have.
--
Alex Bendig, CTO and Co-Founder at Bevy