ISO-27001-Certification
Nomasis is certified by ISO/IEC 27001
Certified information security for managed services and IT security services
Nomasis AG’s Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022. The independent certification by Swiss Safety Center AG confirms that Nomasis systematically organises, reviews and continuously improves its information security within the defined scope.
The certified scope comprises: Managed Services and IT security services
What is ISO/IEC 27001
ISO/IEC 27001:2022 is an internationally recognised standard for information security management systems, or ISMS for short.
The standard sets out requirements for how organisations identify, assess, manage and monitor information security risks. It covers not only technical measures, but also organisational processes, responsibilities, controls and continuous improvement.
What does this mean for our customers and partners?
The certification provides independent evidence that information security at Nomasis is managed in a structured and traceable manner.
The certification can support security, compliance and supplier audits.
Our customers and partners benefit from:
clearly defined security processes
structured management of information security risks
clear lines of responsibility
regular internal and external audits
employees who receive ongoing training and are made aware of the issues
the ongoing development of the ISMS
Continuous security in accordance with ISO 27001
What is an information security management system?
An ISMS establishes a binding framework for the protection of information.
Among other things, it specifies:
- what risks exist
- how these risks are assessed and managed
- who is responsible for which security tasks
- what organisational and technical measures apply
- how their effectiveness is monitored
- how improvements are implemented
Information security is thus treated not as a one-off measure, but as an ongoing management task.
Continuous improvement
Certification is not a one-off project. The Information Security Management System (ISMS) is continuously monitored, reviewed and further developed. New risks, technological changes and relevant legal, regulatory and contractual requirements are assessed on a regular basis.
In this way, Nomasis reinforces its commitment to providing secure and reliable managed services and IT security services.
Certified Scope
The certification applies to managed services and IT security services.
It relates to the ISMS within this defined scope. ISO/IEC 27001 is not a product certification and does not guarantee protection against all security incidents.
