ISO 27001

Jan 16, 2026

ISO/IEC 27001 is the leading international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) to systematically protect an organisation’s information assets, ensuring confidentiality, integrity, and availability by managing risks to data, people, processes, and technology. Certification demonstrates commitment to best practices, building customer trust and competitive advantage by showing a robust, risk-based approach to security.  – the definition from AI.

Why?

People has asked why we want on this journey for certification, and it’s a good question.  There are two main reasons:

  1. It begins with state education departments issuing RFIs and SOAs requesting certification in various standards, like: ISO27001, ISO18051, ISO9001, ISO27018, ENISA, CSA, and FedRAMP (among others).  For many years the ED was happy to accept “Working towards certification…” however in an effort to give an honest answer we responded with “No, we are not working towards these certifications”.  Consequently we were dropped from some of these tender processes.  Gaining certification in ISO27001 will now allow us to say “Yes” and we can provide a current certificate as proof.
  2. Cyber security has become one of the most important requirements for software applications dealing with personal identifiable information.  Every week we are seeing headlines about system breaches, data compromised, ransomware demands, and company data for sale on the dark web.  There has been an explosion of podcasts covering IT security through to dark web stories.  You could be a small business, a large corporate, or a government department, nobody is immune to being hacked, ransomed, and/or data compromised. We’ve all heard the story about the two guys who come across a bear in the forest, they don’t need to outrun the bear, they just need to outrun the other guy.  Similarly, ISO27001 doesn’t make us immune to being hacked, but it may allow us to “outrun the other guy”.

Are there benefits?

For us?  Being able to answer ‘Yes’ to those RFI/SOA questions about security certification.

For you, our customers?  Absolutely.  You can now have a reasonable amount of confidence that we have prioritised the security of your data.  Your data is protected by multiple layers of security.  If we are attacked by ransomware there is a very high probability that we will be able to recover all of your data and restore operations within 24 hours.  Can we be hacked and data compromised?  It’s always a possibility, however the probability has been significantly reduced due to the processes required by this certification.

Price increase

ISO 27001 certification requires annual audits which come at a cost.  To cover these ongoing costs of certification we are increasing the price of all SOBS applications by 6%.  In a way this is a guarantee that we intend to maintain this certification in to the future.

What has changed?

There are plenty of changes at our end that you won’t notice, such as regular reviews of network security, regular checks of every end point device, regular penetration tests, regular security training, and annual reviews of security policies.

Recently we have been implementing additional security measures into the application, most of these you won’t notice.  Very soon we will be updating our password policy that may require some users (with additional security) to provide stronger passwords or Multi Factor Authentication (MFA).