Artica ST has successfully completed the last phase of the certification process, and obtained the ISO 27001 Management System Information Security certification with number SI-0101/2009.
ISO/IEC 27001 is an official certification given by the Estate to any management system intended to bring information security under explicit management control. Being a formal specification means that it requires rigorous and specific guarantees. Organizations that claim to have adopted ISO/IEC 27001 can therefore be formally audited and certified in compliance with those standards.
ISO/IEC 27001 requires that the company:
- Systematically examines the organization's information security risks, taking account of its threats, vulnerabilities and impacts;
- Designs and implements a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address those risks that it deems unacceptable.
- Adopts an overarching management process to ensure that the information security controls continue to meet the organization's information security requirements on an ongoing basis.
