ISO 27001 is an international standard that defines the requirements an ISMS (information security management system) must meet, published by the International Organization for Standardization (ISO). It provides a structured framework enabling organizations to protect their resources and information systems through a risk-based approach. The current version was published in 2022 and is built around seven mandatory clauses defining information security governance and management, as well as 93 controls providing concrete security measures to mitigate risks.
Certified by Cybeval, a cybersecurity audit firm, HarfangLab demonstrated its compliance with the high standards established by ISO and its commitment to continuously improving its information security management.
Technical testing and governance compliance
The ISO standard defines seven mandatory clauses that set out the requirements for establishing, operating, monitoring, and continuously improving an information security management system (ISMS). To be certified by the accredited body, HarfangLab had to meet the requirements associated with each of these seven clauses.
- Organizational context: defining the scope and understanding internal and external factors
- Leadership: ensuring management involvement and defining responsibilities
- Planning: assessing risks, setting objectives, and planning actions
- Support: allocating resources, developing skills, and managing documentation
- Operation: implementing and controlling security procedures
- Performance evaluation: monitoring, measuring, auditing, and reviewing information security management systems
- Improvement: addressing nonconformities and carrying out continual improvement actions.
The 93 controls in Annex A are divided into four themes: organizational, people, physical, and technological. These controls, assessed by the accredited body, Cybeval, cover areas including policies, risk management, supplier relationships, compliance, awareness, remote work, human resources security, the protection of physical premises, equipment and access, encryption, vulnerability management, and more. All these tests are conducted during a three-day on-site audit.
Compliance with the highest industry standards and international frameworks
“Achieving compliance with ISO 27001:2022 provides further evidence that HarfangLab is committed to respecting and continuously improving the security of its processes. It was important to officially tick this box to meet the requirements of our most security-conscious international customers, especially in the context of NIS2,” says Anouck Teiller, Deputy CEO at HarfangLab.
About HarfangLab
HarfangLab is the European leader in Workspace Detection and Response. As security teams juggle fragmented tools that compound coverage gaps across endpoints, identities, cloud environments, exposed assets, and AI agents, HarfangLab delivers a unified platform powered by a single lightweight agent and AI built for cyber. Certified by ANSSI and BSI, and recognized by Gartner and Forrester, HarfangLab extends detection and response across the modern workspace—from on-prem to the cloud, wherever work happens.