Security is a key issue for Finder, a value that is part of a well-defined corporate governance plan aimed at ensuring a solid foundation for the company’s strategic business activities.
With this in mind, in 2022, Finder embarked upon a plan that recently concluded with the attainment of ISO/IEC 27001 and 27701 certification, two international standards that attest to the compliance of corporate best practice in information security and risk mitigation.
The project involved all of the group’s sites, and is part of a solid business continuity plan aimed at keeping infrastructures operational even in the event of unforeseen events, ensuring that the company’s services are always available and reliable.
ISO/IEC 27001 outlines the essential requirements that must be adopted – as part of an ‘Information Security Management System’ (ISMS) – to protect information in a systematic and consistent manner. Obtaining this certification means having completed a structured audit trail defined by precise and rigorous parameters, met through the fine-tuning of security policies, operational processes, data storage and processing technologies.
To identify areas for improvement, a meticulous risk assessment was conducted, followed by the implementation of controls (essential for bringing risk levels within acceptable parameters). After that, a gap analysis was conducted, and the required corrections and improvements were made. Finally, certification audits were conducted, leading to the achievement of this important milestone.
The system, ensures the protection of data and information through:
Finder has also implemented an ISO/IEC 27701 certified ‘Privacy Information Management System’ (PIMS) to ensure maximum protection of personal data, and in full compliance with the principles and rules of Regulation 2016/679.
These certifications demonstrate the company’s commitment to cybersecurity and the protection of information integrity and confidentiality, strengthening the trust of customers and business partners.
For more in-depth information on these and all other company certifications, visit the website.