News

‘ISO 27001 certification solid basis for information security’

Since 1991 Dutch company H&R Business IT Solutions has been supporting organizations in developing and managing their complete IT environment. The Utrecht family business offers an extensive service portfolio to this end, varying from consultancy, project management, implementation and migration to workplace design and data and cloud solutions.

IECEE appoints Kiwa for the IEC 62443: Cyber security for Industrial Automation and Control Systems

The IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components (IECEE) recently appointed Kiwa to carry out assessments and certifications in the context of the series of standards IEC 62443. Kiwa was already partially accredited, but this accreditation has now been expanded to include even more parts of the standard. To qualify for this allocation, Kiwa successfully completed the IECEE Certification Body Testing Laboratory (CBTL) and National Certification Body (NCB) audits.

Transition to new version ISO 27001

The new version of ISO 27001 was published on 25 October 2022. A transition period of three years applies and certified organizations must therefore have switched to ISO 27001:2022 on November 1st 2025. Below we have listed the most important information about the transition process.

ISO 27001 standard for information security revised

Recently, the ISO 27001 standard for information security received an update. The revised standard was published on 25 October 2022. The updated standard has been aligned with ISO 27002:2022 published in February this year and includes some technical corrections. ISO 27001:2022 is subject to a three-year transition period. This means that certified organisations must have switched to ISO 27001:2022 by autumn 2025.

The most important changes to the revised ISO 27001 and ISO 27002

On February 15, 2022, the new version of the ISO 27002 standard was published. The ISO 27002 is an extension of the ISO 27001 standard for information security and specifies the requirements of an Information Security Management System (ISMS). The extension provides best practices for security controls and measures that you can implement to improve your security. Although ISO 27002 is not a certifiable standard, this revision does have consequences for organizations that are or want to become ISO 27001 certified. That is why we share the most important changes with you.

Video: Combined certification ISO 9001, 14001 and 27001 at T-Mobile

Within three months towards recertification for the internationally recognized standards ISO 9001 (quality), ISO 14001 (environment) and ISO 27001 (information security). Kiwa and T-Mobile Netherlands recently achieved this in a compact process in which recertification against these three standards was combined.

Kiwa accredited for ETSI EN 303 645 cybersecurity testing

Kiwa was recently accredited by the Dutch accreditation council RvA as the first Notified Body (NoBo) for testing and assessing the cybersecurity of IoT consumer products. By independently assessing the cybersecurity of 'smart' devices such as doorbells, thermostats, tv’s and lighting, manufacturers can ensure that consumers are less likely to become victims of cybercrime.

Revision ISO 27002: simplification and modernization

To ensure that quality standards remain relevant and current, they are reviewed at least every five years. For that reason, the ISO 27002 was recently revised. This standard contains the practical guidelines and control measures for management systems for information security (ISMS) that are inextricably linked to the information security standard ISO 27001.

Delegated Regulation RED compliance cybersecurity IoT products published in OJEU

The Official Journal of the European Union (OJEU) has published the Delegated Regulation (2022/30/EU), making compliance to the RED (2014/53/EU) articles 3.3 (d), (e) and (f) mandatory for cybersecurity aspects of IoT products. The Delegated Regulation will come in effect on the 1st of February 2022. After a transition period, compliance will become mandatory from 1st of August 2024.

Cybersecurity for Fire Protection Systems: a compliance and risk based approach

Recently SFPE Europe released a publication on the topic of cybersecurity for fire protection systems. This article, based on a recent research of the Fire Protection Research Foundation, highlights just and accurate reasons regarding the importance of cybersecurity for fire protection systems.

EU wants to curb cybercrime through 'smart' consumer electronics

Thermostats, doorbells, security cameras and other 'smart' products that do not meet minimum cybersecurity requirements are expected to be banned from the European market from 2024. This is the result of new EU legislation that was recently adopted, aiming to ensure that European consumers are better protected against cybercrime via web connected electronics.

Kiwa quickly and effectively supports SanoMed with ISO 13485 certification

SanoMed Manufacturing BV produces cosmetics, wound care products and nutritional supplements. The Dutch company’s unique feature is the frequent use of natural ingredients such as honey and olive oil. But medical devices and products based on natural sources also have to comply with the applicable laws and regulations, so SanoMed turned to Kiwa for renewal of its ISO 13485 certification.

Digital gadgets often make security alarm systems vulnerable

An alarm system used by many thousands of people across Europe can be remotely disabled by criminals. This is shown by research by Dutch television news program RTL Nieuws. The leak can also be used to turn the alarm siren on or off or to peek along with the security cameras.

Cyber security expert Hudson Cybertec and Kiwa join forces

Hudson Cybertec, specialized in cyber security for Industrial Automation & Control Systems (IACS), is part of the Kiwa Group as from May 5th 2021. With this participation, Kiwa - a leading independent testing, inspection and certification organization - aims to expand its presence in the cyber security market, whereas Hudson Cybertec will profit from Kiwa’s worldwide network and expertise in the field of certification.

Blog: Cyber security paramount for functioning of utility companies

Recently a hacker managed to gain remote access to the operational system of a water recycling facility in Florida, USA. He illegally adjusted the values of the caustic soda solution to values that are potentially dangerous for drinking water. As a result, the discussion about the cyber security of drinking water facilities and other critical infrastructures flared up again.

Hartis telecare receives first Kiwa ISO/IEC 27701 certification

Kiwa has awarded Hartis Telecare the ISO/IEC 27701 certification for privacy information management in cooperation with NEN. Read more.

Swiss alarm transmission expert TUS first to obtain Kiwa RARS certificate

Like many other modern telecom related devices, alarm transmission systems are increasingly being connected to the web. This offers numerous possibilities when it comes to availability and remote operating, but can also entail security risks. Swiss alarm transmission expert TUS Telekommunikation und Sicherheit can boast decades of experience when it comes to end-to-end secure alarm chains and was recently the first to certify against Kiwa’s scheme Remote Access for Remote Services (RARS).

What aspects are part of the security of an IoT-environment?

The impact of the Internet of Things (IoT) on our daily live increases. The more and more evolving functionalities of smart devices offer opportunities. In contrary to these benefits, there are also some challenges when it comes to safety and security

Whitepaper: How to get more out of your internal audit?

Internal IT audit programs are key if you want to make sure all your information assets remain properly secured from any threat. An internal audit provides assurance and helps organizations to manage their risks and controlling their processes effectively. All in order to improve and mature the practices used within the business

Clientcase Pulse: 'ISO 27001 certification increased our data security awareness'

Microsoft Dynamics 365 service provider Pulse was certified by Kiwa against the ISO 27001 standard in June 2018. For Pascal Thönissen, service delivery manager and security officer at Pulse, this certification cuts both ways: 'We demonstrate our information security processes are in order and we can now help our customers with their data security issues.'