logo level
SME
Agency
Large enterprise
contactOperationalControl Panel
newsthe-iso-certification-of-level27

The ISO certification of Level27

Level27 is ISO 27001 (information security) and ISO 9001 (quality) certified. In this article, we share our personal experiences during our journey.

General21/11/2017
The ISO certification of Level27 image

Why?

In the hosting world, ISO 27001 is important. As a customer, you want the confidence that your data is in safe hands, and the certificate gives you that confirmation.

As a professional hosting partner, we are therefore obligated to pursue this certification. But because our baseline is not for nothing ‘Hosting. Better.’, we wanted to add a unique accent to it.

Thee vision

We didn’t want to certify ‘just because.’ The investment in time and resources is considerable, so we did it not only for the certificate but also for strategic reasons. By that, we mean that we don’t just want an ISO manual in the cupboard; we also want to actually implement the elements of ISO to make our organization even better.

That is also why we went not only for the usual ISO 27001 certificate but also immediately for the at least equally important ISO 9001 certificate.

Our partners

For an ISO audit, of course, you need an auditor, the organization authorized by ISO to determine whether a company qualifies for certification. Naturally, the reputation of this organization is also important. After thorough market research, we chose BSI Group.

An ISO audit consists of a pre-audit, where BSI checks if the basic requirements are met. A few weeks later, the actual audit follows, during which your entire company is examined in detail.

After that, an annual update is scheduled to check whether the organization still complies and whether any action points are being addressed. Every three years, a full audit takes place.

Anyone can request an audit from BSI Group. Much of how the standard is implemented also depends on common sense. But to truly meet all (sometimes technical and legal) aspects of the standard, we sought guidance. We found that guidance in Bob from KVGM-IS. Throughout the entire process, he has been our rock.

Our journey

What does such a journey actually consist of? Here I share our own experiences, how we approached this project, and what the pitfalls and successes were.

The start

Let’s start by saying that the efforts are considerable but not impossible. By considerable, I mean that it doesn’t happen automatically. It is not enough to bring an external ‘ISO Bob’ into your company, let him do his work, and after a few months hand the ISO book to the auditor. At least, not according to the vision we had in mind. The effort is complete: the entire organization must be involved in the process.

On the other hand, the effort is not impossible. In our case, we already had many processes and instructions before we started this journey. During our project, many of these instructions were optimized and adjusted to comply with the ISO standard.

In the first days of the project, we started by mapping everything we had. The existing processes were reviewed and evaluated together with Bob from KVGM-IS.

The tools

The next step is to set up a system to structure all the documentation. Hooray, we already had that: Confluence. Confluence is a so-called wiki, modeled after Wikipedia. A system where you can bring structure and where everyone can edit text and documentation:

image371

Confluence is not loved by everyone, but it is a tool that continues to develop strongly and offers all the features we need!

An example of the KPI page and the general structure of our Operations department:

image372

Confluence contains a lot of information, documentation, and records. Action points and to-dos are tracked in Trello. Trello is now also maintained by Atlassian, the creator of Confluence. The beauty of Trello is that it offers enough freedom while still allowing for structured work.

The digital equivalent of this, then:

image373

The road to the pre-audit

During the months leading up to the pre-audit, we streamlined our processes. We further identified our risks and added action points in Trello.

The most important aspect during this phase was involving all employees in the project. The importance of the project was therefore made clear to all staff from the very beginning. Everyone carried out part of the tasks.

As the project progressed and the pre-audit deadline approached, it became clear that we were on track. The milestones we had set at the start of the project were very helpful in this regard.

The pre-audit

Before BSI Group starts the audit, they first come for a ‘look,’ the so-called ‘pre-audit.’ The purpose of this short pre-audit is to save time and money if it turns out the organization is not ready for an ISO audit. Comments and advice are also provided during this pre-audit, which can be addressed before the real audit.

The pre-audit went very well :)

The road to the audit

In the weeks between the pre-audit and the audit, we took the time to finish everything. Loose ends were tied up, asset tags were placed on our devices, and final adjustments were made to the risks and the Confluence documentation.

The audit

Then the time comes – the audit itself. A full ISO audit (in our case both 9001 and 27001) takes several days and is conducted very thoroughly. The auditor examines the entire management system and notes their findings. Since we involved all employees in the process, this also meant the auditor reviewed each component individually with them.

During an audit, the auditor can note the following findings:

  • an opportunity for improvement
  • a non-critical deviation
  • a critical deviation

Critical deviations logically mean that you have not passed the audit and must take corrective actions before the certificate can be issued. During our audit, not a single critical deviation was found!

‘What particularly struck me during my visit was the tranquillity – as if Level27 were immune to stress and problems. The reason for this is the impressive technical expertise, highly advanced automation, and concrete, measurable objectives. This combination of factors, coupled with a clear delineation of the hosting activities and a pragmatic interpretation of the standard requirements, resulted in an effective management system for quality and information security.’

Koen Beroudiaux

Auditor

The result

Two weeks after our audit, we had our certificates in the mailbox. Level27 is ISO 27001 and 9001 certified!

And now?

From now on, we will receive an annual visit from the BSI Group auditor. He will verify whether we continue to comply with the standard and will confirm this by renewing the certification for one year.

What we have learned and what you can learn from this

The main point we have learned is that even a small organization can obtain an ISO certificate. We waited until we were large enough, but that is not necessary! That would be my advice: you don’t need to wait! Your organization is ready for an ISO audit sooner than you think. And if you’re not yet ready, an ISO process really helps you reflect on yourself and professionalize.

What I am also convinced of is that you must approach this as an organization as a whole. It doesn’t work to ‘assign’ the ISO task to one or two people. Many organizations do this, but the result is a paper tiger in the cupboard that nobody uses. An ISO journey must be experienced throughout your entire organization, and awareness must be embedded in everyone. Otherwise, it’s a waste of time and money.

"General conclusion: it was worth it!"

Stay informed

Subscribe to our newsletter and receive the latest updates on our products and services.

By subscribing, you agree to our privacy policy