NAVEX > 实例探究 > Enterprise Software Developer Earns ISO 27001 Certification

Enterprise Software Developer Earns ISO 27001 Certification

NAVEX Logo
公司规模
11-200
产品
  • NAVEX IRM
技术栈
  • Integrated Risk Management
实施规模
  • Enterprise-wide Deployment
影响指标
  • Brand Awareness
  • Customer Satisfaction
技术
  • 分析与建模 - 实时分析
  • 应用基础设施与中间件 - 数据交换与集成
适用行业
  • Software
适用功能
  • 商业运营
用例
  • 网络安全
  • 监管合规监控
服务
  • 软件设计与工程服务
  • 系统集成
关于客户
The customer is a small enterprise software development company with about 85 employees. The company was seeking to achieve ISO 27001 certification, a globally recognized standard for information security. The certification would require the company to establish a sustainable information security management system (ISMS) that could comply with all seven ISO 27001 categories. The company's Chief Technology Officer (CTO) was leading the project.
挑战
The enterprise software developer, a small company with about 85 employees, set a goal to achieve ISO 27001 certification. This certification sets the standard for information security and requires a sustainable information security management system (ISMS) that can comply with all seven ISO 27001 categories. The company knew that using spreadsheets for compliance would not be sufficient due to the rigorous requirements of the certification. The Chief Technology Officer (CTO) was leading the project and needed a technology solution to build an ISMS capable of earning ISO certification.
解决方案
The company selected NAVEX's solution, NAVEX IRM, for its capabilities in integrated risk management (IRM). NAVEX IRM enables organizations to gain a comprehensive view of their business and operations from a risk perspective, connecting individual risk disciplines and managing them in one centralized program. The solution streamlines compliance with multiple regulations and standards, including ISO. The CTO documented ISO 27001’s seven categories of requirements in NAVEX IRM and then leveraged the solution’s functionality to meet requirements, satisfy auditors and earn certification. During the ISMS design phase, the CTO documented objectives, policies, procedures and macro roles, and developed the ISMS manual to govern the entire program, all in NAVEX IRM.
运营影响
  • The company achieved ISO 27001 certification, giving it tremendous credibility with securely managing customer data.
  • The marketplace took notice of the company's achievement, influencing the views of current customers, competitors, prospective companies, and industry analysis firms.
  • The CTO was able to answer all questions from ISO auditors with a show-and-tell in NAVEX IRM, making the audit process smoother and more efficient.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。