✓ ISO 27001:2022

ISO 27001 Certification

International standard for Information Security Management Systems (ISMS)

What is ISO 27001?

ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It defines the requirements an ISMS must meet to help organizations keep information assets secure.

quiXzoom's ISMS

quiXzoom has implemented a comprehensive Information Security Management System covering:

Organizational Controls

Policies, roles, responsibilities

People Controls

Screening, training, awareness

Physical Controls

Perimeter, equipment, storage

Technological Controls

Crypto, operations, development

Key Security Controls

Information Security Policies

Comprehensive security policies reviewed annually. All employees and contractors must acknowledge policies before accessing systems.

Asset Management

Inventory of all information assets with defined ownership. Classification system (Public, Internal, Confidential, Restricted) applied to all data.

Access Control

Role-based access with principle of least privilege. Multi-factor authentication enforced. Regular access reviews and automatic deprovisioning.

Cryptography

AES-256 for data at rest. TLS 1.3 for data in transit. Key management via AWS KMS with automatic rotation.

Operations Security

Change management with peer review. Capacity planning and monitoring. Malware protection on all endpoints.

Communications Security

Network segmentation with VPC isolation. VPN required for remote access. DDoS protection via AWS Shield.

System Acquisition

Security requirements in all procurement. Secure development lifecycle (SDLC). Code review and automated security testing.

Supplier Relationships

Security requirements in all contracts. Regular supplier assessments. Right to audit clauses.

Incident Management

24/7 security operations center. Incident response plan with defined roles. Post-incident reviews and lessons learned.

Business Continuity

Business impact analysis. Disaster recovery plans tested annually. Backup and recovery procedures documented.

Certification Details

Continuous Improvement

quiXzoom's ISMS follows the Plan-Do-Check-Act (PDCA) cycle: