Skyhigh 1st Cloud Access Security Broker to be ISO 27001 Certified

Posted by Lauren Ellis on September 22nd, 2014

One of the most robust certifications a cloud security service provider can attain is ISO 27001 certification. Attaining ISO certification is is a reflection of the company’s commitment to security across multiple functions, and a reflection of tremendous time and resource investment by these cloud providers. Specifically, the security standard audits and certifies across 11 domains

1.  Security policy– management direction
2.  Organization of information security– governance of information security
3.  Asset management– inventory and classification of information assets
4.  Human resources security– security aspects for employees joining, moving and leaving an organization
5.  Physical and environmental security– protection of the computer facilities
6.  Communications and operations management– management of technical security controls in systems and networks
7.  Access control- restriction of access rights to networks, systems, applications, functions and data
8.  Information systems acquisition, development and maintenance– building security into applications
9.  Information security incident management - anticipating and responding appropriately to information security breaches
10.  Business continuity management - protecting, maintaining and recovering business-critical processes and systems
11.  Compliance - ensuring conformance with information security policies, standards, laws and regulations

Only 4% of Cloud Providers ISO 27001 Certified
Given how extensive the certification process is, it’s not particularly surprising that only 4% of the 3,571 cloud security service providers used by over 200 companies are ISO 27001 certified. More surprising is the fact that, in today’s market where security breaches result in PR nightmares and executive beheadings, enterprises use so many services that are not certified and put so much sensitive corporate data at risk.

As a cloud provider, in the security space no less, we believe that it’s incredibly important to validate the investments we’ve made in security. To that end, we are incredibly proud to announce that Skyhigh has attained ISO 27001 Certification, joining the ranks of esteemed cloud providers like Salesforce, Workday, Servicenow, Box, Jive, and Ping.

An Industry First
Skyhigh is the first Cloud Access Security Broker to attain ISO 27001 certification, building on Skyhigh’s commitment to open standards and controls (Skyhigh was also the first vendor to publish CSA controls in STAR registry as well)

The certification also reflects the maturity of controls and practices that Skyhigh has in place, which aligns with feedback we’ve received from customers like BMC Software, Cisco, Diebold, and DirecTV.


Author :
Lauren Ellis is a research analyst covering the technology industry’s top trends & topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,

Like it? Share it!


Lauren Ellis

About the Author

Lauren Ellis
Joined: July 25th, 2014
Articles Posted: 53

More by this author