Trust Center / ISO/IEC 27001:2022

ISO/IEC 27001:2022

Certified to ISO/IEC 27001:2022 under UKAS accreditation.

What It Is

ISO 27001:2022 is an internationally recognized standard for information security management systems (ISMS), independently audited and certified.

What It Majorly Requires, and How VIDIZMO Supports It

  • An Information Security Management System (ISMS) with a defined scope: covers the information security management system for all VIDIZMO service lines.
  • Ongoing risk assessment and treatment, and documented policies: backed by a formal Information Security Program with regular internal risk assessments and policy reviews.
  • A certification audit by an accredited certification body, repeated on a 3-year cycle with annual surveillance audits: VIDIZMO holds Certificate #RA-2507091, issued by the United Kingdom Accreditation Service (UKAS), VIDIZMO’s accredited certification body, on July 9, 2025, valid through July 8, 2028.

Customers can review VIDIZMO’s compliance annually, through a meeting with our team, a completed audit questionnaire, or supporting documentation, generally under a mutual non-disclosure agreement when sensitive internal detail is involved.

How the ISMS Is Maintained Across the Lifecycle

Software Development

  • Security user stories built into the Agile process
  • A Definition of Done that includes security requirements
  • Threat modeling before code is written
  • Secure code reviews
  • Static Application Security Testing (SAST) integrated into the development environment

Production

  • Dynamic and Interactive Application Security Testing (DAST, IAST) during the testing phase
  • Patch management for third-party releases
  • Security gates with dependency scanning built into CI/CD pipelines (Azure DevOps, GitHub Actions)

Operations

  • Weekly automated vulnerability scans
  • Quarterly independent penetration testing
  • Real-time audit logging retained in tamper-evident, immutable storage
  • A documented incident response plan
  • Annual security awareness training for staff

FAQ

ISO/IEC 27001:2022, asked and answered

What does VIDIZMO's ISO 27001 certification actually cover?

VIDIZMO holds ISO/IEC 27001:2022 certification for its information security management system (ISMS), covering how information security is managed across all VIDIZMO service lines, not just a single product or environment.

Is this certification VIDIZMO's own, or inherited from a cloud provider?

It's audited and issued directly in VIDIZMO's own name, distinct from compliance frameworks like SOC 2 that VIDIZMO inherits through its underlying cloud infrastructure. That means an independent certification body assessed VIDIZMO's own security practices and controls, not just the data center it runs on.

What is ISO/IEC 27001:2022, and why does it matter for evaluating a vendor?

ISO/IEC 27001 is the leading international standard for information security management systems, covering how an organization identifies risks, implements controls, and continuously manages security. Certification against the 2022 revision, the current version of the standard, signals that a vendor's security program has been independently audited rather than self-declared.

How does ISO 27001 fit alongside VIDIZMO's other compliance and security capabilities?

ISO 27001 certification sits alongside broader security objectives such as least-privilege access (MFA, SSO, RBAC), data integrity, and support for frameworks like SOC 2, GDPR, CCPA, CJIS, and HIPAA. It reflects the security management system underlying VIDIZMO's platform, which customers can pair with deployment-specific compliance needs (e.g., government cloud hosting for CJIS or FedRAMP-aligned environments).

Does ISO 27001 certification get renewed or re-audited?

Yes, ISO 27001 certification is issued for a defined validity period and requires periodic surveillance audits and recertification to remain current, rather than being a one-time assessment.

Can we request VIDIZMO's ISO 27001 certificate or audit documentation?

VIDIZMO can provide certification evidence and relevant security documentation to prospects and customers as part of due diligence; reach out to your VIDIZMO contact to request it.

Need our security documentation?

Tell us what your review requires and we will send the relevant evidence.