ISO/IEC 27001:2022 COMPLIANCE CUSTOMER STATEMENT
1. What is ISO/IEC 27001:2022 and how does it apply to ITogether?
ISO/IEC 27001:2022 is an internationally recognised best practice framework that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). An ISMS is a systematic approach to managing policies and procedures that includes all legal, physical, environmental, and technical controls involved in an organisation’s information risk management processes. The ISMS also ensures the confidentiality, integrity, and availability of information, as well as providing assurance to interested parties that risks are effectively managed. The standard has four domains that we ensure compliance with, and they fall into the categories below. Please refer to ITogether’s ISO/IEC 27001:2022 Statement of Applicability (SOA) for details.
- Organisational controls
- People controls
- Physical controls
- Technological controls
The scope of ISO/IEC 27001:2022 for ITogether covers the information security framework for the activities relating to the global provision, maintenance, and operation of our 24×7 Cyber and Network Services.
2. How does ITogether comply to the applicable clauses under ISO/IEC 27001:2022?
The ISO/IEC 27001:2022 standard includes five main clauses that ITogether will be compliant with on an annual basis.
Context of the Organisation
ITogether has an ISMS with the following global scope statement:
“The Information Security Management System (ISMS) provides the information security framework for the activities relating to the provision, maintenance, and operations of our Cyber Security and Networks businesses” ITogether prides itself on continuous improvement by understanding the needs and expectations of all relevant stakeholders (internal and external). This is achieved through numerous channels including customer surveys, internal and external audits, account manager catch-ups, and various process improvement initiatives.
Leadership
ITogether has an Information Security Management team, comprising directors from cross-functional departments demonstrating we are committed to the development and implementation of the Information Security Management System.
The team is continuously improving the effectiveness and efficiency of the ISMS by maintaining the Global ISMS Manual, ensuring the information security objectives are updated and aligned with the strategic direction of the company, providing sufficient resources to establish, implement, operate, monitor, review, maintain and improve the ISMS, and communicating to all ITogether employees the importance of effective information security management and conformity to ISMS requirements.
