logo level
SME
Agency
Large enterprise
contactOperationalControl Panel
newswhat-is-the-meaning-of-the-iso-standard

What is the meaning of the ISO standard??

The "International Organization for Standardization" is an organization that sets norms or standards. What is a standard then? A standard is in fact nothing more or less than an agreement on how to do or build something. Every company has internal standards, for example about how the hamburgers look and taste in all McDonald's. Or how wide the body seams of all Audis in the world may be.

General21/11/2017
What is the meaning of the ISO standard?? image

There are also external standards set by organizations like ISO. Companies can get certified by ISO for different standards through a so-called audit. After such an audit, you can trust that the company operates according to a specific standard, a certain level or 'level (27)'.

ISO maintains and publishes thousands of standards, each with its own number. Many are product-specific, some are general.

  • The most known and heard of is ISO 9001. This is the international standard for quality management systems. Companies with ISO 9001 have quality thinking fundamentally embedded, which gives you as a customer the confidence that a high-quality service is the top priority.
  • ISO 27001 is a standard for information security. Specifically, the standard checks the so-called ISMS (Information Security Management System). This management system for information security gives you the freedom to grow, innovate, and expand your customer base, knowing that all your confidential data truly remains confidential.

We now go into more detail regarding the above-mentioned standards.

ISO 27001

I find this a nice summary:

The ISO 27001 certificate shows that sensitive customer information is in safe hands.

Confidentiality, integrity, and availability

Let’s start with the last one: availability. Although it may seem like this has little to do with security, continuity is included in the ISO standard. After all, this is an important aspect of our service and absolutely necessary to earn our customers’ trust.

Integrity is about the assurance that your data is not tampered with. So that you can be sure your data is exactly what you want it to be.

Confidentiality is clear: you always want the data you want to protect to not fall into the wrong hands.

Risks

First, the ISO standard requires you to think about risks, in the broad sense of the word. A risk has 2 properties: the likelihood of it occurring and the impact if it occurs. The product of these 2 properties determines the need to take measures against the risk. If measures are required, we implement them and reassess the risk before deciding whether to accept it.

An example: the likelihood of a volcanic eruption at one of our data centers is rated as ‘very low’. However, the impact on availability if it were to happen is ‘high’. The impact on integrity and confidentiality is low, so we accept the risk of volcanic eruptions.

Another example: the likelihood that a website of one of our clients will be hacked is ‘very high’. Combined with a high impact on confidentiality, integrity, and availability, this risk is not simply acceptable. However, by implementing various measures, we reduce the likelihood of it happening, making the overall risk acceptable.

Measures

Now that the risks have been mapped, we look at all the controls of the ISO standard. Here we go into detail about which measures exist and where we still need to expand. The auditor checks, for example, whether we have an asset management system, whether we evaluate our suppliers, whether there are correct access procedures, whether employees are screened, and so on.

So I’ll repeat once more what you should remember:

The ISO 27001 certificate shows that sensitive customer information is in safe hands.

ISO 9001

An ISO 27001 implementation means that you must critically examine your organization and its processes. The performance of an organization stands or falls with the quality of its processes.

It would therefore be unwise not to go the extra mile towards ISO 9001! After focusing on ISO 27001, we now turn our attention to the operation of the organization as a whole!

ISO 9001 describes the existence and operation of a quality management system. An important note: this does not mean that the quality of the product or service meets your desires. It is about having a system in place to guarantee the operation and quality of your organization. That does not mean that you will find the end product good, beautiful, or tasty! McDonald's also has ISO 9001, but not everyone will appreciate its hamburgers. :)

So what is it then? It is a guarantee that quality thinking is embedded in the organization. As a customer, you can be sure that the treatment you receive is not by chance, but that it has been thought through and that the processes are designed to deliver consistent quality.

Our ISO 9001 implementation plan contains many elements:

  • Measuring all important elements in our service through KPIs (Key Performance Indicators)
  • Regular and structured surveys on customer satisfaction
  • Working towards specific, targeted, and time-bound goals
  • Continuous improvement and adjustment of described processes (Kaizen philosophy)
  • Regular sessions on quality thinking

Here too, I want to end with the sentence you should remember:

The ISO 9001 certificate shows that the quality of our service and your satisfaction is our top priority.

Conclusion

For Level27, both ISO certificates are the recognition of the growth and professionalism of our organization.

Stay informed

Subscribe to our newsletter and receive the latest updates on our products and services.

By subscribing, you agree to our privacy policy