• Lucas@jlai.lu
    link
    fedilink
    English
    arrow-up
    2
    ·
    14 days ago

    From wikipedia for those, like me, that don’t know about ISO27001 :

    ISO/IEC 27001 requires that management:

    Systematically examine the organization’s information security risks, taking account of the threats, vulnerabilities, and impacts;

    Design and implement a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address those risks that are deemed unacceptable; and

    Adopt an overarching management process to ensure that the information security controls continue to meet the organization’s information security needs on an ongoing basis.

      • fraksken@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 days ago

        I passed my first audit last week. I know exactly what it entails.

        I would have expected Proton to have had this certificate a while ago.

        kudos on them passing the audit though.

        • HaleHirsute@infosec.pub
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          Awesome congrats! Maybe they didn’t need it if they are mostly business to consumer focused and average users don’t ask for it?

          • fraksken@infosec.pub
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 days ago

            Thanks 😊

            It’s true that 27001 is more valued in the industry. The lack of the certificate also doesn’t imply they have no information security management system.

            I was surprised they weren’t certified yet.