Why?
In the hosting world, ISO 27001 is important. As a customer, you want the confidence that your data is in safe hands, and the certificate gives you that confirmation.
As a professional hosting partner, we are therefore obligated to pursue this certification. But because our baseline is not for nothing ‘Hosting. Better.’, we wanted to add a unique accent to it.
Thee vision
We didn’t want to certify ‘just because.’ The investment in time and resources is considerable, so we did it not only for the certificate but also for strategic reasons. By that, we mean that we don’t just want an ISO manual in the cupboard; we also want to actually implement the elements of ISO to make our organization even better.
That is also why we went not only for the usual ISO 27001 certificate but also immediately for the at least equally important ISO 9001 certificate.
Our partners
For an ISO audit, of course, you need an auditor, the organization authorized by ISO to determine whether a company qualifies for certification. Naturally, the reputation of this organization is also important. After thorough market research, we chose BSI Group.
An ISO audit consists of a pre-audit, where BSI checks if the basic requirements are met. A few weeks later, the actual audit follows, during which your entire company is examined in detail.
After that, an annual update is scheduled to check whether the organization still complies and whether any action points are being addressed. Every three years, a full audit takes place.
Anyone can request an audit from BSI Group. Much of how the standard is implemented also depends on common sense. But to truly meet all (sometimes technical and legal) aspects of the standard, we sought guidance. We found that guidance in Bob from KVGM-IS. Throughout the entire process, he has been our rock.
Our journey
What does such a journey actually consist of? Here I share our own experiences, how we approached this project, and what the pitfalls and successes were.
The start
Let’s start by saying that the efforts are considerable but not impossible. By considerable, I mean that it doesn’t happen automatically. It is not enough to bring an external ‘ISO Bob’ into your company, let him do his work, and after a few months hand the ISO book to the auditor. At least, not according to the vision we had in mind. The effort is complete: the entire organization must be involved in the process.
On the other hand, the effort is not impossible. In our case, we already had many processes and instructions before we started this journey. During our project, many of these instructions were optimized and adjusted to comply with the ISO standard.
In the first days of the project, we started by mapping everything we had. The existing processes were reviewed and evaluated together with Bob from KVGM-IS.
The tools
The next step is to set up a system to structure all the documentation. Hooray, we already had that: Confluence. Confluence is a so-called wiki, modeled after Wikipedia. A system where you can bring structure and where everyone can edit text and documentation:





