News1 min read

Tvimenning achieves ISO 27001 certification

Tvimenning has completed and passed ISO 27001:2022 certification. The certification covers our information security management system (ISMS).

What does the certification mean?

ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. is the internationally recognized standard for information security management. The certification confirms that TvimenningOld Norse meaning 'two bound together' - one who solves a task shoulder to shoulder with another. has established, implemented, and maintains an Information Security Management SystemThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works. (ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.) in accordance with the requirements of ISO/IEC 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used.:2022.

For our customers, this means:

  • All systems and processes are risk-assessed and documented
  • Access management, incident handling, and deviation procedures are in place
  • We continuously review and improve our security routines
  • An independent auditor (Insight Assurance) has verified that all requirements are met
ISO/IEC 27001:2022 Certified, issued by Insight Assurance
Tvimenning AS, information security management system. ISO/IEC 27001:2022, certified by Insight Assurance.

Why is this important for the energy sector?

Energy companies and grid operators handle critical infrastructure data - consumption data, meter values, grid topology. This data is subject to strict requirements under regulatory frameworks, GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement., and the new NIS2EU directive on network and information security - imposes strict security requirements on critical infrastructure. directive.

TvimenningOld Norse meaning 'two bound together' - one who solves a task shoulder to shoulder with another. processes such data on behalf of its customers. ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. certification is our proof that we take that responsibility seriously.

What happens next?

The certificate is valid for three years, with annual follow-up audits.

Feel free to reach out if you would like to know more about how we handle data security in your integrations.

About the author

Jon Petter Hjulstad

CEO

Integration expert with 20+ years in the energy industry. Long-term leader and founder of Sysco's integration division. Oracle ACE Associate with experience from, among others, Elhub, BKK, Helgeland Kraft and Skagerak. MSc from NTNU.