By: Tony Savoy, Director of Risk and Compliance at VMware
We are happy to announce that VMware has been awarded ISO/IEC 27001 certification for its information security management system supporting vCloud® Hybrid Service™. ISO/IEC 27001:2005 is a globally recognized standard for the establishment and certification of an information security management system (ISMS). The standard maintains the requirements for implementing an ISMS, which include a detailed risk assessment, internal audit, and continuous monitoring of the controls supporting the vCloud Hybrid Service. It also outlines numerous control activities across 11 different control objective domains, necessary to effectively mitigate information security risk applicable to the vCloud Hybrid Service.
Why is this important?
As a service provider, VMware is committed to providing a secure platform and with this certification can provide customers assurance that our security program follows industry best practices. ISO/IEC 27001, is defined by the International Organization for Standardization, and lists the critical components for an ISMS. Achieving certification means that VMware has implemented a holistic security program that conforms with the 27001 standard requirements, both in the management system and control activities.
What is required to get certified?
An audit of the ISMS supporting the VMware vCloud Hybrid Service was completed by Brightline CPAs and Associates – an ANAB accredited certification body. Included in the certification review of the ISMS Brightline audited VMware’s policies and procedures, Risk Treatment Plan (RTP), documents supporting the ISMS, as well as the applicable controls to substantiate that the ISMS was operational. The result was the issuance of the Brightline certificate which can be found here.
A commitment to our customers
Achieving ISO/IEC 27001 certification is an important milestone for VMware vCloud Hybrid Service and the first step towards our commitment to providing a secure cloud environment for your mission-critical applications.
vCloud Hybrid Service is in limited availability today. To apply for a spot in the Early Access Program, register on the website.
For future updates, be sure to follow us on Twitter at @vCloud.