We Have Retained Our ISO/IEC 27001:2022 Certification
Elisian has successfully completed its annual surveillance audit and retained certification to ISO/IEC 27001:2022, the international standard for information security management systems.
This is not a box-ticking exercise. ISO 27001:2022 is one of the most rigorous independently audited standards in information security. Retaining it requires demonstrating, year on year, that our controls are not only in place but operating effectively.
What ISO 27001:2022 Actually Covers
The 2022 revision of the standard updated and restructured the control set to reflect the modern threat landscape. Certification means Elisian maintains a documented, tested, and independently verified information security management system across:
- Risk assessment and treatment - threats are identified, scored, and mitigated against defined risk appetite
- Access control - who can access what, under what conditions, and with what level of authorisation
- Asset management - all information assets are catalogued and handled in line with their classification
- Supplier security - third-party risk is assessed before any integration or data sharing
- Incident management - defined procedures for detection, response, and recovery from security events
- Business continuity - ensuring platform availability is maintained in the event of disruption
For clients in oil and gas, energy, and regulated industries, these are not theoretical controls. They reflect the same rigour you apply to your own operational safety management systems.
Why This Matters If You Are Evaluating Operational Assurance Software
When you are deploying software to manage permit to work, process safety, or integrity management workflows, the security of that platform is part of your own risk picture. A data breach, an access control failure, or an unplanned outage in your operational assurance system is not just an IT problem, it is an operational safety exposure.
ISO 27001:2022 certification gives you independent assurance that Elisian has addressed that risk systematically. You are not taking our word for it. An accredited certification body has audited our controls and confirmed they meet the standard.
Clients subject to regulatory scrutiny, whether under the Health and Safety at Work Act, COMAH, PSSR, or sector-specific frameworks, can reference Elisian's certification as part of their own supplier assurance and vendor due diligence processes.
What the Audit Process Involves
Surveillance audits are not a rubber stamp. The auditor reviews evidence that controls are functioning, not just that they are documented. That means reviewing logs, testing procedures, interviewing staff, and examining any security incidents or near misses from the preceding period.
Where gaps or non-conformances are found, they must be corrected and re-evidenced before certification is confirmed. Elisian passed without major non-conformances.
Continuous Improvement, Not Annual Compliance
Retaining ISO 27001:2022 is a milestone, not a destination. The standard requires a culture of continuous improvement, security risks are reassessed as the threat landscape changes, controls are refined, and the system evolves with the business.
For Elisian's clients, that means the platform you rely on for operational assurance is backed by an information security programme that does not stand still either.
If you have questions about our security posture, our controls, or how Elisian's certification supports your own compliance requirements, get in touch.