ISO 27001:2022
FSET holds active ISO/IEC 27001:2022 certification — the internationally recognised standard for Information Security Management Systems. Certification confirms that FSET systematically manages information security risks across its operations, with controls audited annually by an accredited third party.
Quick Facts
OVERVIEW
Law enforcement agencies, healthcare providers, and municipal governments operate under strict regulatory obligations for data privacy, system availability, and security governance — and those obligations extend to the technology partners they work with.
FSET’s ISO 27001:2022 certification, compliance framework alignments, and published policies give clients documented, auditable evidence to satisfy their own procurement requirements and risk assessments.
For a police service managing sensitive investigative data, or a health authority responsible for personal health information under PHIPA, due diligence means verifying — not assuming — that your IT partner meets the same standard you’re held to.
KEY REQUIREMENTS
Information Security Policy
Maintain a documented information security policy approved by leadership, communicated to staff, and reviewed at planned intervals or following significant changes.
Risk Assessment & Treatment
Conduct information security risk assessments at planned intervals, identify risk owners, and apply risk treatment options aligned to organisational risk acceptance criteria.
Access Control
Implement and maintain access control policies ensuring information access is restricted based on business and security requirements, with access rights reviewed regularly.
Continuous Monitoring & Audit
Perform internal audits at planned intervals and conduct annual management reviews to evaluate ISMS performance and drive continual improvement.