ISO 27001 and CISPE Code of Conduct Certifications
In a landscape rife with cybersecurity threats, the credibility and trustworthiness of your Cloud Service Provider (CSP) are non-negotiable. At UpCloud, we make it easier for you by demonstrating our unwavering commitment to data security. Our ISO 27001 certification and CISPE Code of Conduct compliancy aren’t just badges – they’re promises of robust, transparent, and secure cloud infrastructure services.
ISO 27001: The Gold Standard in Security
As an integral part of our security framework, we’re proud to be ISO 27001 certified. This international standard not only signifies our dedication to maintaining the high level of information security but also ensures that we adhere to industry-recognized best practices in managing and safeguarding your data.
Risk Management
Part of our ISO 27001 commitment involves a holistic approach to risk management. We don’t just focus on technology; we encompass people, processes, and tech in our security endeavours. Human error can be a significant security risk. We invest in regular training for our team, ensuring they’re always up to date with the latest security protocols and practices.
Regular Audits
The ISO 27001 standard is not a one-off certification. We are regularly audited by independent third parties to ensure our adherence to ISO 27001 standards and the efficiency of our security controls.
Beyond ISO 27001
While ISO 27001 remains a core component of our security compliance, we’re also committed to aligning with other global and regional security standards and regulations, ensuring a comprehensive and multi-faceted approach to security. We are aligned with ISO 31000, NIST CSF and CISPE Code of Conduct and our data centres have multiple industry certifications on top of ISO 27001.
What is the CISPE Code of Conduct?
The Cloud Infrastructure Services Providers in Europe (CISPE) is a non-profit organisation with members that include UpCloud, Amazon Web Services, OVH, Hetzner, Leaseweb, and Aruba. The CISPE Code of Conduct focuses on data protection principles, and adhering to this ensures that your data remains within your control, isn’t used for anything other than what you’ve authorized, and remains in the EU, providing an additional layer of protection given the stringent data protection laws in place.
Read more