For the fifth time, we have successfully passed the ISO/IEC 27001:2013 audit carried out by the independent body TÜV Rheinland. This confirms not only the effectiveness but also the security of our information security management system. What benefits does this audit bring to our customers?
Information security at i360. ISO 27001:2013 audit. What is ISO/IEC 27001:2013?
ISO/IEC 27001:2013 is the standard for information security and customer personal data management systems. It confirms that the security standards in place ensure that risks are minimised and business continuity is maintained.
In the case of i360, passing the audit is particularly important because we process personal data and also collect information on the structures and budgets of investments as part of incentive schemes and sales support activities for our clients.
An ISO audit is carried out by an independent body, such as TÜV Rheinland. The purpose of the audit is to verify that the company in question complies with procedures that ensure information security in accordance with the international ISO/IEC 27001:2013 standard.
As the last audit coincided with the declaration of the pandemic in Poland, it was also necessary to implement additional precautionary measures during the meeting with the TÜV Rheinland auditors. For this reason, this year’s ISO audit was not the easiest, and it also put our other skills to the test.
What does an ISO 27001:2013 audit involve?
Obtaining ISO certification is always a considerable challenge for a company. It examines a wide range of issues, not only relating to IT processes but to the organisation as a whole. The audit covers, amongst other things:
- information security policy
- management methods
- security measures and backups
- change management methodology
- incident management plan
- software licence compliance and up-to-date security systems
- access control policy
- operating procedures
- business continuity
In addition, all processes, contracts and procedures are also audited. An independent body also checks other aspects of the company’s operations, including even the functionality of fire-fighting equipment. Naturally, the greatest emphasis is placed on information security. That is why most of the time and effort is devoted to meetings between the auditors and the IT and compliance departments, as well as with the representative responsible for the information security management system.
Audit objectives
All the activities listed above were designed to verify the procedures we use to ensure the security of your information. The renewal of the ISO 27001:2013 certificate has confirmed the management system’s ability to comply with the laws, regulations and contracts applicable to i360.
At the same time, the audit assesses the system’s compliance using sampling methods. It also determines its effectiveness in meeting the objectives set by i360, thereby enabling the current certificate to be maintained.
Why is obtaining ISO certification important to us?
„The organisation has established and implemented an effective system to achieve its policy and objectives. The audit team confirms, in accordance with the audit objectives, that the organisation’s management system meets the requirements of ISO/IEC 27001:2013 and is properly maintained and improved” – this statement fully confirms that our management methods and the security of your information are of a high standard.
Why is this important to us? Because we are well aware that many companies offering loyalty and incentive programme management claim to provide security and reliability. However, only ISO 27001:2013 certification backs up these claims, and only i360 can boast of having held this certification for the past 5 years.
It is therefore worth checking whether the company that supports your loyalty programmes has passed an ISO audit. For our part, we provide support for these programmes in the areas of processes, logistics, legal and tax matters, information security, as well as the implementation of B2B incentive schemes and B2C loyalty programmes.
