
How security policy helps you stay compliant and achieve ISO 27001 certification
Azure cost compass
op onze IT-scans
Processes require policy
To achieve your goals, you need a strategy and a plan. Security management is no different. If you want to stay secure or achieve ISO certification, you must meet a number of standards regarding processes. And for that, you need both technology and policy. We have written about this before. ISO 27001/9001 - Roadmap to Modern Service Management for the Azure Cloud.
Our previous blogs on MFA, secure score and monitoring with tools like Azure Sentinel all contribute to the technical checklist for ISO. The majority of our clients are ISO certified. It is therefore essential for them to keep developing in order to maintain this certification. You can read more about the results in our client cases. What does such a process look like and which checkboxes do you need to tick? Think of re-assessment through an ISO audit, process descriptions, access control, policies regarding system permissions, and an incident response handbook.
ISO & security Azure portal templates
There are plenty of ISO checklists available online. We have chosen to share our technical checklist with you so that you can bridge the gap between business and IT.
- Regulatory compliance details for ISO 27001:2013 - Azure Policy | Microsoft Learn
- Blueprint sample management options for ISO 27001 shared services - Azure Blueprints | Microsoft Learn
- Overview of the sample blueprint for ISO 27001 compliant shared services - Azure Blueprints | Microsoft Learn
Marco's tip: 9001 primarily contains rules regarding processes and reporting on exceptions. 27001 is mainly about data protection, such as GDPR, and access to workspaces and systems. If you're already at it, get both of them in order. 27001 isn't a logical next step; it's a must!
'Old' in a new jacket? – security.txt
Recently, security.nl published this report calling for websites to make a security.txt file available. Security.txt is a file that allows organizations and websites to state their policy for handling security vulnerabilities. Security researchers can use this information to directly contact the right department or person within the organization regarding discovered vulnerabilities. Tweakers also gave it the necessary attention. Digital Trust Center starts campaign for implementation of security.txt - Computer - News - Tweakers
Have you read it and implemented it yet? We did it this way.
Follow the example of Air Miles, Allego, Humanitas and Qualogy and request a no-obligation consultation or demo.
Scanpakket: Azure cost compass
1 juli t/m 30 september
Frequently asked questions (FAQ)
Fancy a chat?
Do you have a question, or would you like to know what we can do for your organization? Feel free to get in touch with us. We’re happy to help!

