Certifications & Assurance
Certifications and controls supporting security and compliance
ISO 27001 defines how organisations manage information security through a formal management system.
At FMIS, this standard underpins how we:
This includes policies covering areas such as access control, incident management, supplier management, and secure development.
Security is managed as an ongoing process rather than a one-off activity. Controls are reviewed regularly, and risks are assessed and addressed through defined procedures.
ISO 9001 focuses on quality management and the consistent delivery of services.
At FMIS, this supports:
Processes are documented, monitored, and refined over time. This helps ensure that systems are delivered and supported in a consistent and controlled way.
Cyber Essentials Plus is a UK government-backed certification focused on core technical security controls. It includes independent testing of systems and controls.
At FMIS, this covers areas such as:
Key security controls are tested externally to confirm they are in place and operating as expected.
Certifications form part of a wider assurance framework.
FMIS maintains an Information Security Management System that includes:
These processes ensure that controls remain effective as systems and requirements evolve.
FMIS carries out regular independent testing to validate its security posture.
This includes annual infrastructure and application penetration testing (ITHC). Findings are reviewed, prioritised, and addressed through defined remediation processes.
Security controls are tested from an external perspective, with any identified issues tracked and resolved as part of ongoing improvement.
If you require additional documentation or have specific security or compliance questions, please contact: