Certifications and Qualifications
UNI EN ISO 9001:2015 Certification
The ISO 9001:2015 standard outlines an approach based on the documentation and control processes of the structure, responsibilities and procedures necessary to obtain a satisfactory level of quality management within an organization.
The ISO 9001:2015 certification certifies that CloudFire has implemented a Quality Management System in compliance with UNI EN ISO 9001:2015 in the field of application Provision of Cloud and Hybrid Cloud services.
This certification is aimed at achieving the business objectives of:
Quality in the supply of HW and SW products, with particular attention to responsiveness, timeliness and completeness of deliveries and price competitiveness;
Quality in the assistance to the products supplied, with particular attention to responsiveness to requests and to minimize the time needed to resolve problems;
Quality of software packages, with the offer of technologically innovative solutions in selected application areas, with a full range of functionality and a high level of reliability;
Quality of the services provided, with recognized professionalism with regard to the operational start-up of the solutions sold and continuous willingness to understand, anticipate and promptly satisfy customer needs.
The Quality objectives are expressed in the document of Quality Policy CloudFire.
The quality management system is also a guarantee of the reliability of production processes for customers, suppliers, employees and collaborators.
Certificate No. IT23-13504A
ISO/IEC 27001:2022 Certification
ISO/IEC 27001:2022 is a standard that specifies best practices for security management and comprehensive security controls based on the best practice guidance of the ISO/IEC 27002 standard. The basis of this certification is the development and implementation of a rigorous security program, that is, an IT security management system that defines the ways in which CloudFire continuously manages security in a holistic and complete way.
In fact, the ISO 27001:2022 certification attests that CloudFire has implemented a information security management system in compliance with the ISO 27001 standard in the field of application Cloud and Hybrid Cloud service delivery.
The principles contained in the certification and the related controls are oriented to:
Strengthen the interfunctionality of information security and the trust of its business partners;
Integrate information and system security into the Organization's overall risk management strategy;
Meet the requirements of Stakeholders (Shareholders, Legislators, Customers, Staff, Administration and Community) by demonstrating that they face and manage risk, ensuring business sustainability;
Reduce incidents involving legal and contractual liabilities;
Improve relations with the Public Administration;
Ensure the protection of trade secrets and business know-how.
Certificate No. IT23-13504D
ISO/IEC 27017:2015 Certification
ISO/IEC 27017:2015 provides guidance on cybersecurity aspects affecting cloud computing and recommendations regarding the implementation of cloud-specific information security controls, which integrate the guidelines of the ISO/IEC 27002 and ISO/IEC 27001 standards. This code of conduct provides cloud service providers with additional guidelines for implementing information security controls.
CloudFire's compliance with the guidelines contained in the standard ISO/IEC 27017:2015, not only attests to its constant commitment to align with globally recognized best practices, but it shows that CloudFire has a system of extremely precise controls, specific to cloud services.
Certificate No. IT23-13504D
ISO/IEC 27018:2019 Certification
ISO/IEC 27018:2019 is the code of conduct focused on protecting personal data in the cloud. It is based on the ISO/IEC 27002 information security standard and provides guidance for implementing ISO/IEC 27002 controls that apply to Personally Identifiable Information (PII) in the public cloud. It also provides for a series of additional controls and associated indications aimed at satisfying the requirements relating to personal information in the public cloud not provided for by the group of controls of the existing ISO/IEC 27002 standard.
The Code of Conduct ISO/IEC 27018 certifies that CloudFire adheres to protection of personally identifiable information (PII) in Public Clouds and that has a system of controls aimed specifically at protecting the privacy of the content entrusted by customers. CloudFire's compliance with this internationally recognized code of conduct, proven by an independent third-party assessment, demonstrates CloudFire's commitment to privacy and the protection of customer content.
Certificate No. IT23-13504D
ACN Certification
The ACN certification is a recognition issued by the National Cybersecurity Agency, aimed at validating the conformity of cloud infrastructures and services intended for the Italian Public Administration. This qualification requires the implementation of strict security measures, processing capacity, energy saving and reliability.
The ACN certification attests that CloudFire services and infrastructure are qualified to be provided to projects and tenders for the Public Administration. Specifically, we have obtained the qualifications:
'QC1' to 'SaaS' services called "Veeam Cloud Platform”, “Talky Time” e “CloudFire 3CX”;
'QC1' to 'IaaS' services called "CloudFire Openstack as a Service” e “CloudFire vSphere as a Service”;
'QI1' to the 'Infrastructure' named 'CloudFire Datacenter Data4 Mi1'CloudFire Datacenter Data4 MI1”.
The ACN certification therefore validates CloudFire's ability to:
Managing Risk: strict controls and procedures are in place to identify, assess and mitigate security risks;
Protect Data: the protection of sensitive and personal data is ensured through advanced cybersecurity measures;
Guarantee Business Continuity: continuity of services is guaranteed even in the event of accidents, thanks to careful planning and emergency management.