Mekong Digital
Contact

ISO certification support

Obtaining a certification is a project. Keeping it is a daily discipline. We handle both.

Discuss certification

What we cover

Why this matters in the region

Across Southeast Asia, certification is often a condition for joining a supply chain, answering a public tender, or satisfying a foreign head office. The requirement usually arrives with a deadline attached.

The certificate is not the finish line

Many organisations obtain a certificate, then let the system fall out of use. The next surveillance audit finds it.

We set up something your teams can actually maintain, with tools that fit the way they already work. We can also stay involved afterwards to keep the system alive between audits.

Standards we support

We work on IT-related standards only. For quality, environmental or sector-specific standards, we will point you to a specialist.

Standard and scope
ISO/IEC 27001Information security management
ISO/IEC 27701Privacy information management
ISO/IEC 27017Security controls for cloud services
ISO/IEC 27018Personal data in public cloud services
ISO/IEC 20000-1IT service management
ISO 22301Business continuity management

GDPR

The European data protection regulation applies to organisations outside Europe as soon as they handle the personal data of people in Europe. Many companies in the region are concerned through a head office, a European client, or an online audience.

GDPR is a regulation, not a standard: there is no certificate to obtain. We help you map the data you hold, put the required records and procedures in place, and answer requests from individuals. ISO/IEC 27701 is the usual way to show that the work has been done.