Given the critical role of the State Operator for Non-Lethal Acquisition (DOT) in supporting the Armed Forces of Ukraine, continuous improvement of the comprehensive Information Security Management System (ISMS) remains one of our steadfast objectives.
Last week, we took another significant step toward this goal: an independent external organization conducted a thorough audit of our entire ISMS. The auditors provided recommendations for preparing for the certification audit and for the future development of the system. Overall, they confirmed the high level of compliance of DOT with information security standards.
“Efficient processing, safeguarding, and security of information are key indicators of trust in DOT, especially under the conditions of regular cyberattacks on Ukraine's infrastructure by adversaries. That is why we work tirelessly to ensure that none of these attacks achieve their objectives. Achieving one of the most recognized and prestigious certifications in the world in the field of information security will further demonstrate our agency's responsible approach to all matters related to information security and ensuring the Armed Forces have everything they need,” emphasized Aliona Zhuja, IT Advisor for DOT.
What Is ISO/IEC 27001?
ISO/IEC 27001 is an international standard that defines requirements for ISMS and evaluates a comprehensive approach to information security, covering people, policies, and technologies. Compliance with this standard indicates that an organization has implemented and adheres to the best practices of information security management, including:
-
Proactive responses to evolving risks;
-
A centralized and managed structure protecting information in one place;
-
Preparing people, processes, and technologies to counteract information threats;
-
Safeguarding information on all media types: paper, cloud, and digital;
-
Cost savings through optimized processes.
The next stage following the internal audit will be the certification audit, after which the State Operator for Non-Lethal Acquisition (DOT) is expected to achieve this prestigious standard.