Standard Compliance

Services Portfolio

ISO 9001:2008 Read More ISO/IEC 20000-2:2005

ISO/IEC 20000-2:2005 represents an industry consensus on guidance to auditors and offers assistance to service providers planning service improvements or to be audited against ISO/IEC 20000-1. ISO/IEC 20000-2:2005 is based on BS 15000-2, which has been superseded.

Organizations require increasingly advanced facilities (at minimum cost) to meet their business needs. With the increasing dependencies in support services and the diverse range of technologies available, service providers can struggle to maintain high levels of customer service. Working reactively, they spend too little time planning, training, reviewing, investigating, and working with customers. The result is a failure to adopt structured, proactive working practices. Those same service providers are being asked for improved quality, lower costs, greater flexibility, and faster response to customers.

ISO/IEC 24762:2008

ISO/IEC 24762:2008 provides guidelines on the provision of information and communications technology disaster recovery (ICT DR) services as part of business continuity management, applicable to both "in-house" and "outsourced" ICT DR service providers of physical facilities and services.

ISO/IEC 24762:2008 specifies:
  • the requirements for implementing, operating, monitoring and maintaining ICT DR services and facilities;
  • the capabilities which outsourced ICT DR service providers should possess and the practices they should follow, so as to provide basic secure operating environments and facilitate organizations' recovery efforts;
  • the guidance for selection of recovery site; and
  • the guidance for ICT DR service providers to continuously improve their ICT DR services.
ISO/IEC 27000:2009 ~ ISO/IEC 27001:2005 Read More The objectives of ISO/IEC 27000:

2009 are to provide terms and definitions, and an introduction to the ISMS family of standards that:

  • define requirements for an ISMS and for those certifying such systems;
  • provide direct support, detailed guidance and/or interpretation for the overall Plan-Do-Check-Act (PDCA) processes and requirements;
  • address sector-specific guidelines for ISMS; and
  • address conformity assessment for ISMS.
ISO/IEC 27001:2005

all types of organizations (e.g. commercial enterprises, government agencies, not-for profit organizations). ISO/IEC 27001:2005 specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System within the context of the organization's overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. ISO/IEC 27001:2005 is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties.