The international standard for information security management — and the baseline we hold our own infrastructure and practices to.
International Organization for Standardization
The Standard
ISO 27001 is the most widely recognised framework for information security in the world — here's what it covers and why it's become the trusted baseline for procurement and supplier assessment.
ISO 27001 is the globally recognised gold standard for information security. An accredited third-party auditor reviews an organisation's controls and, if satisfied, issues a certificate that the rest of the world understands.
It covers people, processes, and technology. It asks whether an organisation has identified what could go wrong with its data and taken proportionate, documented steps to prevent it — not just bought the right software.
The certificate is valid for three years with surveillance audits in between. That ongoing discipline is exactly why procurement teams and regulators trust it — it proves security is a habit, not a tick-box exercise.
Why It Matters
Knowing your technology partner operates to a recognised security standard has real, practical consequences for your business.
Large organisations and public sector bodies routinely ask their technology suppliers whether they operate to ISO 27001. Knowing that your provider's infrastructure and practices meet the standard removes a meaningful procurement risk — and simplifies your own security questionnaires.
When you share client records, financial data, or sensitive business information with a technology partner, ISO 27001 alignment is independent evidence that controls around access, storage, and handling are formally governed — not improvised.
ISO 27001 gives procurement, legal, and executive stakeholders a common reference point. Rather than evaluating a supplier's custom security claims, they can ask a single question: does this provider operate to the standard? We do.
How We Operate
Our infrastructure runs on platforms that hold their own ISO 27001 certification. Our internal practices are built around the same principles. Here is what that looks like in practice.
Whether a workload sits on public cloud — Google Cloud, AWS, or Microsoft Azure — or a private hosting environment, we exclusively use providers that hold their own ISO 27001 certification. The physical and logical security of every environment your data lives in is independently audited by accredited third parties. That is a deliberate requirement, not a coincidence.
We apply the ISO 27001 principle of least privilege across every engagement. Developers access only what they need, for only as long as they need it. Production access is logged, reviewed, and revoked on project completion. No shared credentials, no lingering permissions.
The standard requires that security decisions are made deliberately and recorded — not left to individual judgement. Our internal processes cover change management, incident response, and vulnerability handling in documented procedures that the whole team follows, not just security-minded individuals.
ISO 27001 treats human behaviour as a core control, because it is. Our team is trained on secure development practices, phishing awareness, and data handling obligations. We don't treat security as a job for a single person — it is embedded in how we work.
Related Services
ISO 27001 alignment runs through these parts of our practice in particular.
The ISO 27001-certified hosting environments we build and manage for clients — secure by design, not by accident.
Strategic guidance on security posture, vendor assessment, and aligning your technology decisions with recognised standards.
Work With Us
When you work with Black Opal, your data sits on ISO 27001-certified infrastructure and is handled by a team that takes the underlying principles seriously. If you'd like to understand how that applies to your specific requirements, we're happy to talk it through.