7networks’ Information Security Management System (ISMS) is certified according to ISO/IEC 27001:2022. We adopt ISO standards as our operational reference framework for security controls and risk management, and we have voluntarily aligned with the European NIS2 Directive. All of this is carried out in compliance with the Swiss Federal Act on Data Protection (nFADP).
Access to information only by authorized parties.
Accurate, complete data protected from unauthorized alterations.
Information and systems available when needed.
Structured assessment and treatment of security risks.
7networks has obtained ISO/IEC 27001:2022 certification (certificate no. ITA-10331-ISMS) issued by Scandinavian Certification AS, an IAF-accredited certification body.
The certification covers the design, integration, management, and support of IT infrastructures, cloud solutions, and cybersecurity services, as well as the delivery of managed services and business continuity services.
Each service is managed through structured risk management processes, ensuring the confidentiality, integrity, and availability of information.
7networks has chosen to align with the European NIS2 Directive (EU 2022/2555), undergoing an independent assessment with a positive outcome across all controls. The audit, conducted by an independent Lead Auditor, verified the consistency of the organizational and technical measures with the requirements of the directive and its guidelines.
Questo testo è identico al precedente: la traduzione resta la stessa.
The NIS2 Directive extends cybersecurity obligations to the supply chain. With 7networks as your IT management partner, your supply chain gains a certified element of reliability, simplifying your compliance journey.
We identify and address risks in proportion to the criticality of assets and the threat context. Decisions on controls and investments stem from risk assessments.
Security is not the sole prerogative of technical functions: every person who accesses information or systems actively contributes to their protection.
Security controls across multiple layers — organizational, physical, logical, procedural — so that the failure of a single control does not compromise overall protection.
Access granted solely to the extent necessary for assigned duties, with periodic review and timely revocation.
Compliance with legal, regulatory and contractual requirements, verified through internal and third-party audits.
A permanent cycle of planning, implementation, verification and corrective action, driven by the results of audits, incidents and management reviews.