Information security to international standards
Tvimenning is certified to ISO 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used. - the globally recognised standard for information security management systems. The certificate confirms that we handle your data with structured processes, documented procedures and independent audit.
What is ISO 27001?
ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. is the international standard for information security management systems (ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.). It specifies requirements for establishing, implementing, maintaining and continually improving a management system that protects an organisation's information assetsPhysical equipment owned and used over time - transformer, cable, breaker. It has both a technical and an accounting side, and the two rarely agree..
For an energy SaaSSoftware as a Service - software delivered as subscription service over the internet. company like Tvimenning, this means that all data handling - from power market data and meter readings to customer contracts and personal data - is subject to systematic security controls reviewed by an independent certification body.
Certification is not a one-time stamp - it requires annual surveillance audits and full recertification every three years, ensuring the security level is maintained over time.
Tvimenning AS is certified to ISO/IEC 27001:2022, certified by Insight Assurance. The certification covers our information security management system (ISMS) and confirms that we have documented, audited routines for how we handle data, access and risk across the entire business. It is not a product certification, but the management system governs how the software comes about: code review, separated development, test and production environments, and traceable approval before anything goes live.
iso.org/standard/27001Security domains we control
ISO 27001 Annex A defines 93 controls across four domains. Here are the key measures we have in place.
Organisational controls
- Information security policy approved by management
- Roles and responsibilities documented for all staff
- Risk assessments carried out regularly
- Supplier security assessed at all procurements
People controls
- Background check and NDA on hiring
- Mandatory security training for all employees
- Procedure for handling and reporting security incidents
- Revocation of access rights on termination of employment
Physical controls
- Infrastructure hosted in ISO 27001-certified data centres
- No server infrastructure of our own - physical security is handled by certified hosting providers
- Secure destruction of information and storage media
Technological controls
- Encryption of data at rest and in transit (TLS 1.3 / AES-256)
- Multi-factor authentication on all critical systems
- Automated vulnerability scanning and patch management
- Logging, monitoring and incident response plan
- Penetration testing and code reviews
- Separate environments for development, test and production
- Change management with traceable approval before deployment
- Backups with regular restore testing
The certification journey
Gap analysis and scoping
Mapping of existing security posture against ISO 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used. requirements. Defined scope, risk appetite and project plan.
Implementation of management system
Establishing the ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.: policies, procedures, risk assessments, risk treatment plan and Statement of ApplicabilityThe document listing which of ISO 27001's security controls an organisation actually applies - and justifying every one that has been excluded. (SoA).
Internal audit and management review
Internal audit of all control domains. Closure of non-conformities. Management review and approval of ISMS.
External certification audit (Stage 1 + 2)
Independent audit by certification body. Stage 1: document review. Stage 2: operational on-site audit.
Certificate received
Tvimenning AS is ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. certified. The certificate is valid for three years with annual surveillance audits.
What does this mean for you as a customer?
When you choose Tvimenning as your technology partner, ISO 27001 certification means we meet a recognised international standard for information security - independently confirmed, not merely claimed.
For your compliance function and IT security team, it means Tvimenning can document its security posture, risk assessments and controls - simplifying your own supplier assessments and GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement. documentation.
Documented security
Access to security summaries, processing grounds and risk assessments for your supplier documentation.
GDPR-simplified
ISO 27001 covers many of the requirements in GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement. Article 32 on technical and organisational security measures.
Continuous improvement
Certification requires ongoing audit - not a one-time stamp. Security posture is actively maintained.
Independently confirmed
An accredited certification body - not Tvimenning itself - confirms that controls are in place and operational.
Questions about information security?
Contact us for security summaries, DPA (data processing agreementThe data processing agreement GDPR Article 28 requires between a controller and a processor - regulates what the vendor is allowed to do with personal data.) or questions related to your vendor assessment of Tvimenning.