Leave your email address and receive the latest developments in software, AI and Mendix.

Over the past few months we have taken you along on our road to certification. From password managers to Mobile Device Management, and from internal audits to the preparations for the external audit, step by step we have worked on raising our information security.
And now the moment has come: we have officially been awarded our ISO 27001 certificate! An important milestone for our team and confirmation that we safeguard the security of data and systems in a structural, professional way.
That we not only develop and manage securely, but also demonstrably meet the high standard for information security.
In the rest of this blog you can read our story on the way to the ISO 27001 certification, which we have since proudly achieved:
The volume of sensitive data generated, stored and exchanged every day is growing exponentially. Meanwhile the threat of hacks, cyberattacks and data breaches keeps growing too. So it is extremely important that this data is properly secured. At JAM-IT we take that very seriously, which is why we have started a major project: achieving the ISO 27001 certification.
ISO 27001 is an international standard for information security. It helps companies like JAM-IT to protect data properly. Think of financial information, client data and other sensitive data. To achieve this certification, we have to meet a series of strict requirements and guidelines. That means putting our processes and procedures under the microscope, identifying points for improvement and taking action to optimise them. We also have to demonstrate that we consistently meet the required security measures through audits and documentation.
At JAM-IT we aim to meet the highest standards at all times. By working towards the ISO certification we take a critical look at our current ways of working and raise them to a higher level. This process encourages us to keep innovating and to optimise our internal processes. That way we can work more efficiently, improve the quality of our services and respond better to what our clients need. Achieving this certification does not only strengthen our reputation, it also means that both we and our clients benefit from the highest standards of security and reliability. Both we and our clients are better off for it.
We have now started the ISO 27001 process. The first step was a GAP analysis, in which we looked at our current processes and at what we still have to do to meet the ISO standard. Thanks to that analysis we now have a clear view of which measures we already have properly in place and where there is still room for improvement. We will be working on those improvements in the period ahead. An important next step is documenting our procedures.
A big drawback of an ISO certification is that you have to record a great deal. You have to record that backups have taken place and that they have been checked, for instance. Normally that has to be done by hand, which of course asks a lot of your staff. But as it happens, automating that kind of task is our speciality. Naturally we are going to put that to use during this process as well.
We hope in the end to automate 95% of all the checks and controls that come with the ISO certification. For that automation we will partly build applications ourselves and partly look for existing (open source) solutions.
That way we can spend as much of our time as possible on what it is really about: building great applications for our clients.
We have discovered, for example, that we carry out backups properly and securely, but that the process is not yet fully documented. By documenting it now, we make sure everyone knows exactly what has to happen, and we can demonstrate it during an audit as well. We are also introducing stricter measures for the security of our laptops and our building. Because what if a developer's laptop is stolen, or someone breaks into our building? Those are things we can be even more alert to.
We still have a number of steps to take before we are ready for the ISO 27001 audit. Over the coming six months we will carry on implementing and documenting all the necessary measures.
In the meantime we are glad to share our insights and the steps we are taking to set everything up as efficiently as possible. Do you find it interesting to follow our journey? Then follow us on LinkedIn.
Want to know more?Ask Armando
Privacy, GDPR, contracts, leave, time tracking, invoicing: as an organisation grows, so does everything you need to arra...

When we started our IT traineeship at JAM-IT, the starting point was clear: give people with the right analytical skills...

How the way we develop is changing, and what that means for the choices you make today Over the past few years, low-code...