Skip to main content
AI in Production 2026 is now open for talk proposals.
Share insights that help teams build, scale, and maintain stronger AI systems.
items
Menu
  • About
    • Overview 
    • Join Us  
    • Community 
    • Contact 
  • Training
    • Overview 
    • Course Catalogue 
    • Public Courses 
  • Posit
    • Overview 
    • License Resale 
    • Managed Services 
    • Health Check 
  • Data Science
    • Overview 
    • Visualisation & Dashboards 
    • Open-source Data Science 
    • Data Science as a Service 
    • Gallery 
  • Engineering
    • Overview 
    • Cloud Solutions 
    • Enterprise Applications 
  • Our Work
    • Blog 
    • Case Studies 
    • R Package Validation 
    • diffify  

Our ISO 27001 Certification

Author: Liam Kalita

Published: August 24, 2023

tags: infosec, security, iso, cyber

Hello from the Jumping Rivers team! Today, we’re taking a moment to chat about our recent achievement – becoming ISO certified.

What is ISO 27001 and Why Does It Matter?

ISO 27001 is an internationally recognised standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive company information, ensuring its confidentiality, integrity, and availability. The standard outlines a framework that helps organisations identify and manage information security risks, implement appropriate controls, and continuously improve their security posture.

In today’s digitally driven world, where data breaches and cyberattacks are rampant, ISO 27001 offers a proactive approach to safeguarding sensitive information. It not only helps companies protect their own data but also builds trust with clients, partners, and stakeholders by demonstrating a commitment to maintaining robust information security practices.

Why We Chose the ISO Path

A couple of reasons nudged us towards these certifications:

  • The clients we interact with often required them.
  • It presented a brilliant opportunity for a bit of introspection. Were our current security practices up to scratch? We were keen to find out.

Data comes in all shapes and sizes. It can often be difficult to know where to start. Whatever your problem, Jumping Rivers can help.

Our Route to Certification

While it was an enlightening six months, it wasn’t without its hurdles. We had to sift through our security practices and ensure they were robust. The real task, however, was fostering a company-wide understanding that security isn’t just an IT department’s concern – it’s everyone’s business. We enlisted the help of a consultant who really knew their stuff. They guided us through the intricacies of the ISO standards, ensuring we were on the right track.

The Statement of Applicability: An Analogy

Personally, my favourite exercise in the standard is the Statement of Applicability (SoA). Think of the SoA in the context of building a house. Imagine you’re constructing a new home and you want it to be safe and secure for your family. You wouldn’t just randomly choose security measures; you’d assess the risks, identify potential vulnerabilities, and then decide which security features to include.

Similarly, the Statement of Applicability is like the blueprint for securing your organisation’s digital “house.” It’s a crucial component of ISO 27001 implementation. The SoA lists the specific controls from the ISO 27001 standard that your organisation has chosen to implement based on its unique risk profile. These controls act as the security measures that protect your sensitive information. Just as you wouldn’t install an alarm system in your home if you live in a crime-free neighbourhood, you wouldn’t implement certain controls if they aren’t relevant to your organisation’s operations and risks.

The SoA ensures that your information security efforts are targeted, effective, and aligned with your business objectives. It’s a dynamic document that evolves as your organisation grows, risks change, and technology advances. Just as you might update your home security system as new threats emerge, you’ll revise your Statement of Applicability to adapt to evolving cybersecurity challenges.

An example of a control we’ve excluded from our Statement of Applicability is “Cabling Security,” which pertains to safeguarding power and telecommunications cabling carrying data or supporting information services. This control emphasises protection against interception, interference, or damage to physical cabling infrastructure.

Our decision to exclude this control stems from our company’s primary mode of operation, which is rooted in remote work and cloud-based infrastructure. Given that we extensively leverage major cloud providers for our server architecture, our reliance on physical on-site cabling is significantly limited. The inherent nature of cloud-based systems means that the responsibility for cabling security largely falls under the purview of these established providers.

By creating a well-thought-out Statement of Applicability, you’re essentially tailoring your security “blueprint” to fit your organisation’s needs, making your ISO 27001 implementation not just a compliance exercise, but a strategic decision that aligns with your business goals and risk appetite.

The Post-Certification Landscape

Since waving our ISO certificates about:

  • We’ve noticed more of a focus on processes across the company. They have become clearer and more streamlined. It’s less winging it, and more standardised and easy to follow instructions.
  • The procurement process with clients? It’s been smoother sailing. That certification tends to be the seal of approval many are looking for.

Staying the Course

We’re not ones to become complacent. We have a risk treatment plan in place to implement over the coming year up to our next audit, as well as regular internal audits on the horizon, so we’re all set to keep our standards sky-high.


Jumping Rivers Logo

Recent Posts

  • Start 2026 Ahead of the Curve: Boost Your Career with Jumping Rivers Training 
  • Should I Use Figma Design for Dashboard Prototyping? 
  • Announcing AI in Production 2026: A New Conference for AI and ML Practitioners 
  • Elevate Your Skills and Boost Your Career – Free Jumping Rivers Webinar on 20th November! 
  • Get Involved in the Data Science Community at our Free Meetups 
  • Polars and Pandas - Working with the Data-Frame 
  • Highlights from Shiny in Production (2025) 
  • Elevate Your Data Skills with Jumping Rivers Training 
  • Creating a Python Package with Poetry for Beginners Part2 
  • What's new for Python in 2025? 

Top Tags

  • R (236) 
  • Rbloggers (182) 
  • Pybloggers (89) 
  • Python (89) 
  • Shiny (63) 
  • Events (26) 
  • Training (23) 
  • Machine Learning (22) 
  • Conferences (20) 
  • Tidyverse (17) 
  • Statistics (14) 
  • Packages (13) 

Authors

  • Amieroh Abrahams 
  • Colin Gillespie 
  • Aida Gjoka 
  • Shane Halloran 
  • Gigi Kenneth 
  • Osheen MacOscar 
  • Sebastian Mellor 
  • Keith Newman 
  • Pedro Silva 
  • Tim Brock 
  • Russ Hyde 
  • Myles Mitchell 
  • Theo Roe 

Keep Updated

Like data science? R? Python? Stan? Then you’ll love the Jumping Rivers newsletter. The perks of being part of the Jumping Rivers family are:

  • Be the first to know about our latest courses and conferences.
  • Get discounts on the latest courses.
  • Read news on the latest techniques with the Jumping Rivers blog.

We keep your data secure and will never share your details. By subscribing, you agree to our privacy policy.

Follow Us

  • GitHub
  • Bluesky
  • LinkedIn
  • YouTube
  • Eventbrite

Find Us

The Catalyst Newcastle Helix Newcastle, NE4 5TG
Get directions

Contact Us

  • hello@jumpingrivers.com
  • + 44(0) 191 432 4340

Newsletter

Sign up

Events

  • North East Data Scientists Meetup
  • Leeds Data Science Meetup
  • Shiny in Production
British Assessment Bureau, UKAS Certified logo for ISO 9001 - Quality management British Assessment Bureau, UKAS Certified logo for ISO 27001 - Information security management Cyber Essentials Certified Plus badge
  • Privacy Notice
  • |
  • Booking Terms

©2016 - present. Jumping Rivers Ltd