October 20, 2022
iCure has been ISO 27001:2013 certified
iCure is proudly announcing to the world its ISO/IEC 27001:2013 certification as of October 2022! An external and independent accreditation body, TÜV Austria Hellas, has officially certified, that iCure is managing information security according to the latest provisions of the ISO27000 family of standards.
ISO 27001 is a standard used for the successful implementation of an Information Security Management System (ISMS) and the audit of this system has warranted the certification of iCure with the ISO 27001. The standard examines the organization’s Information Security risks and proposes a set of 114 Information Security controls, to mitigate those risks.
The Confidentiality, Availability, and Integrity of data are the core components of Information Security and their protection is the focal point of the ISO Standard. At iCure, we embedded these components into our operations and technology since the founding of the company.
iCure follows a unique approach towards Information Security, especially when it comes to confidentiality of data, which is implemented by design. Not only do we commit ourselves to never accessing the data of our customers, but we also hand over the encryption keys to them, without ever learning what those keys are. The structured approach of the Standard towards Risk Management has proved to be a helpful tool in our effort to further safeguard data Integrity and Availability.
Accreditation Body selection has been a meticulous mission. We have selected TÜV Austria Hellas, the Greek subsidiary of TÜV Austria . The story of the company is exciting. Founded as early as 1872 as an inspectorate for the latest technology of the time, steam boilers, the company has evolved to safeguard the latest cloud storage technology in the ever-evolving realm of information security. The Auditor assigned to iCure is also a Lead Auditor in Services and Management and Continuity of Business, but also an active Penetration Tester himself.
The standardized approach of ISO is one big step further into the future, which allows our security philosophy to grow further and scale with our customers. A successful audit is the first step in the journey of standardized management of Information Security for iCure. To continue, internal and external audits have been planned, all aimed at continuously improving information security, so that our clients can keep entrusting us with safeguarding their most private data, knowing that they will never be compromised .