NextPort has obtained ISO 27001 certification for its offices in Algeciras and Valencia, in Spain, along with its parent company, Moffatt & Nichol, which has achieved the same certification for its offices in Long Beach and Raleigh, in the United States.
The acquisition of this certification has occurred after the teams from NextPort and Moffatt & Nichol completed an external audit, according to information provided by the company.
ISO 27001 is an international standard for Information Security Management Systems (ISMS). It establishes the requirements that an organization must follow to identify, manage, and mitigate risks related to information and data security.
NextPort notes that the implementation of this system allows for the management of information and its security within a framework of continuous improvement. The company also believes that the application of ISO 27001 provides clients and partners with a reference framework on how it manages cybersecurity.
The process has been jointly developed by NextPort and Moffatt & Nichol. According to representatives of both companies in a video released in connection with the certification, the coordinated work has allowed for the establishment of procedures linked to the management of information security.
The company indicates that the certification is not limited to the initial acquisition of accreditation, as the management system requires ongoing maintenance. Once implemented, teams must work together in its review and continuous improvement.
Among the aspects addressed during the process is infrastructure management. According to NextPort, the implementation of the system has provided greater structure to the way this area is managed and has impacted issues such as operational procedures, documentation, and monitoring.
The company maintains that these changes allow for a more resilient and reliable infrastructure, as well as being better prepared for unexpected situations.
Security has also been incorporated into daily work related to product development. According to the provided information, the criteria established by ISO 27001 are considered from the design of new functionality and continue during the development and testing phases.
Another area highlighted by the company is administration. The acquisition and maintenance of ISO 27001 require coordination processes between teams, as well as tasks related to documentation, planning, and operational support associated with audits.
Training and awareness of employees are also part of the implemented system. NextPort explains that periodic training allows employees to understand their responsibilities, identify potential risks, and apply security policies and best practices in their daily work.
The company views information security as a shared responsibility within the organization. In this context, the Information Security Management System establishes procedures that affect different areas and workers at NextPort and Moffatt & Nichol.
The certification obtained includes the two Spanish offices of NextPort, located in Algeciras and Valencia, and the U.S. headquarters of Moffatt & Nichol in Long Beach and Raleigh.
Following the acquisition of ISO 27001, both companies must maintain the implemented system and continue with the processes of review and improvement contemplated within the management model itself, as explained by NextPort in the information released on the certification.