ISO/IEC 27001:2022 Certified Information Security

ISO/IEC 27001:2022 is the international standard for establishing, maintaining, and continually improving an Information Security Management System (ISMS).

The standard helps organizations manage information security risks through documented policies, operational controls, risk assessments, and continuous improvement. The 2022 revision organizes its security controls into four categories: organizational, people, physical, and technological.

TeamSync is certified to ISO/IEC 27001:2022 and also includes ISO/IEC 27017 for cloud security and ISO/IEC 27018 for protecting personal data in cloud environments.

What ISO 27001 Requires

  • Clauses 4–10: Context, leadership, planning, support, operation, performance evaluation, and improvement

  • Annex A (2022 revision): 93 controls across 4 themes — A.5 Organisational (37 controls), A.6 People (8 controls), A.7 Physical (14 controls), and A.8 Technological (34 controls)

  • Statement of Applicability (SoA): A declared inclusion or exclusion for each control, with justification

  • Surveillance and recertification: Annual surveillance audits, plus recertification every 3 years by an accredited certification body

How TeamSync Supports ISO 27001 Compliance

1. A certified ISMS scope
The ISMS scope covers the TeamSync platform, its supporting infrastructure, and supporting personnel, with the certificate available on request.

2. All 93 Annex A controls implemented and evidenced
Evidence is maintained for each control, the SoA is published, and evidence of both control design and operating effectiveness is available.

3. ISO 27017 and ISO 27018 extensions
Both the cloud-specific (27017) and personal-data-in-the-cloud (27018) extensions are certified.

4. Ongoing evidence of continuous improvement
Internal audits, management reviews, non-conformity tracking, and corrective action are all maintained on an ongoing basis.

5. Customer-facing documentation
Includes the certificate, the SoA, a control summary, a sub-processor list, and a security whitepaper.

What Customers Get

Aspect

TeamSync coverage

ISO 27001:2022 certification

Active

ISO 27017 cloud extension

Certified

ISO 27018 personal-data extension

Certified

Annex A 93 controls

Implemented

SoA

Published

Sub-processor list

Maintained

Security whitepaper

Available

  • ISO 27701 (privacy information management): An extension of the standard

  • ISO 22301 (business continuity): An adjacent certification

  • ISO 42001 (AI management system): An emerging extension

Who This Page Is For

  • CISO (cross-vertical)