ISO — Information Security
ISO 27001 certification in Uganda.
ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). It covers risk assessment and the controls that protect the confidentiality, integrity and availability of information.
Who needs it
Banks, SACCOs, FinTechs, telecoms, health providers, software companies, and any organization that holds personal or sensitive data.
Why get certified
- A risk-based security program
- Support for Data Protection and Privacy Act compliance
- Evidence of security for clients and regulators
How we get you there
Five steps to ISO 27001.
- 01
Gap analysis
We assess current practice against the standard's requirements.
- 02
Implementation
We design and roll out the processes the standard needs.
- 03
Documentation
Policies, procedures and records — written and organized.
- 04
Internal audit
We verify compliance before the auditors arrive.
- 05
Certification
We guide you through the external certification audit.
Led by Mohammed Rizwan, our Head of Certifications. The certificate itself is issued by an accredited certification body after its external audit; we prepare you for it and support you on audit day.
FAQ
ISO 27001 questions.
Does ISO 27001 help with Uganda's Data Protection and Privacy Act?
Yes. Its risk assessment and controls cover much of what the Act expects for protecting personal data.
Do you also do the technical security work?
Yes. Our cybersecurity team carries out penetration tests, access control and incident-response planning alongside the ISMS.
