ISO — Information Security

ISO 27001 certification in Uganda.

ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). It covers risk assessment and the controls that protect the confidentiality, integrity and availability of information.

Who needs it

Banks, SACCOs, FinTechs, telecoms, health providers, software companies, and any organization that holds personal or sensitive data.

Why get certified

  • A risk-based security program
  • Support for Data Protection and Privacy Act compliance
  • Evidence of security for clients and regulators

How we get you there

Five steps to ISO 27001.

  1. 01

    Gap analysis

    We assess current practice against the standard's requirements.

  2. 02

    Implementation

    We design and roll out the processes the standard needs.

  3. 03

    Documentation

    Policies, procedures and records — written and organized.

  4. 04

    Internal audit

    We verify compliance before the auditors arrive.

  5. 05

    Certification

    We guide you through the external certification audit.

Led by Mohammed Rizwan, our Head of Certifications. The certificate itself is issued by an accredited certification body after its external audit; we prepare you for it and support you on audit day.

GuideUganda's Data Protection and Privacy Act: What Organizations Must Do

FAQ

ISO 27001 questions.

Does ISO 27001 help with Uganda's Data Protection and Privacy Act?

Yes. Its risk assessment and controls cover much of what the Act expects for protecting personal data.

Do you also do the technical security work?

Yes. Our cybersecurity team carries out penetration tests, access control and incident-response planning alongside the ISMS.

Move your cursor — then let's talk

Ready to build what's next?