In April 2018, SapphireOne successfully achieved certification to ISO 27001:2013, the internationally recognised standard for Information Security Management Systems (ISMS). This certification provided independent confirmation that SapphireOne’s approach to information security met rigorous international standards.
ISO 27001 certification requires organisations to adopt a structured and systematic approach to managing sensitive information. This includes identifying security risks, assessing threats and vulnerabilities, and implementing appropriate controls to minimise risk and protect information assets.
To achieve ISO 27001:2013 certification, SapphireOne demonstrated that it had implemented a comprehensive framework of information security controls and governance processes. These processes were designed not only to address current risks but also to ensure that security controls remained effective and relevant as the organisation and technology environment evolved.
The certification confirmed that SapphireOne had established, documented, trained, maintained, and supported its enterprise resource management platform in accordance with ISO standards. In particular, SapphireOne’s Information Security Management System addressed the three core principles of information security:
- Confidentiality – Ensuring that information was protected from unauthorised access, disclosure, or use by individuals, entities, or processes.
- Integrity – Maintaining the accuracy, consistency, and reliability of information throughout its entire lifecycle.
- Availability – Ensuring that information remained accessible and usable on demand by authorised users.
By attaining ISO 27001:2013 certification in 2018, SapphireOne reinforced its commitment to protecting client data and maintaining robust security practices across the development, implementation, training, maintenance, and support of its ERP, CRM, and Business Accounting Software suite.
At the time of certification, SapphireOne continued to be recognised as an industry leader in both functionality and feature depth, with information security forming a core part of its enterprise offering.
For further detail, the original announcement was published on the SapphireOne Blog in April 2018.
