ISMS implemented - Certification in process

Information security
with processes, evidence and deadlines committed

We operate an Information Security Management System (ISMS) aligned with ISO/IEC 27001. The controls are already in place; certification completes the cycle. For our public sector clients, this means continuity, confidentiality, and auditable traceability from day one.

ISMS in operation UNIT-ISO/IEC 27001:2022 Designated CISO Current policies
ISMS Status
In operation
ISMS operational and certified.
Certification
UNIT-ISO/IEC 27001:2022
Certificate obtained in July 2026.
Why it matters

Why a robust ISMS is not optional in the State

When we operate public systems, we handle data that affects rights, benefits, and strategic information for the country. Security is a contractual, legal, and ethical obligation—not a "nice-to-have."

Protection of citizen data

Medical records, tax data, civil registries, information on vulnerable individuals. That trust cannot be lost.

Regulatory compliance

Data protection laws, sector regulations and public procurement frameworks require demonstrable and traceable controls.

Continuity of public service

A security incident can halt an entire program. Managing risk is about protecting operations.

Defensibility before an audit

Our public procurement team and the court of auditors will ask questions. We provide auditable evidence, not statements of intent.

Uruguay · Cybersecurity Framework

Adaptation to the AGESIC Cybersecurity Framework

AGESIC defines the cybersecurity framework that guides and regulates information security management for Uruguayan government agencies. Our ISMS is aligned with its categories and controls, ensuring that projects with Uruguayan public clients benefit from this compliance from day one.

UY
AGESIC · Uruguay

ISMS adapted to the five functions of the framework: Identify, Protect, Detect, Respond and Recover

We work with the same structure and terminology of the framework — based on NIST CSF and adapted to the Uruguayan public sector — so that the evidence, controls and reports of our ISMS are directly usable by the client.

  • Identify — asset inventory and risk management aligned with the framework.
  • Protect — access controls, encryption, training, and secure development.
  • Detect — continuous monitoring, logging, alerts, and event analysis.
  • Responder — incident response plan and integration with CERTuy / CSIRTuy.
  • Recover — proven business continuity and disaster recovery plans.
  • Reporting — evidence in the format required for AGESIC audits.
Controls framework

Controls aligned with Annex A of ISO 27001:2022

We work with the 93 controls of Annex A grouped into the 4 thematic clauses of the 2022 version. Below are representative examples by group.

Organizational

IS Policy Roles and Responsibilities Classification of information Classification of information Supplier Management Incident Management Business continuity Legal Compliance

People

Background check Confidentiality Agreements Awareness and training Disciplinary proceedings Secure Remote Work Event Report

Físicos

Safe zones Physical Access Control Protection against environmental threats Clean desktop and screen Equipment Safety Media Management

Technology

Access Management · MFA Encryption in transit and at rest Vulnerability Management Logging and monitoring Network Segregation Backups and Disaster Recovery SAST · DAST · SCA Secure Development · SSDLC
Support from the organization

ISO 27001 complements a mature management system

ISO 27001 certification is based on a management system that is already certified for quality, environmental, and anti-bribery standards, as well as a CMMI-DEV ML3-appraised development maturity model.

Quality

ISO 9001:2015

Certified quality management system.

ENVIRONMENT

ISO 14001:2015

Certified environmental management system.

Security

ISO 27001:2022

Certified information security management system.

Anti-bribery

ISO 37001:2016

Certified anti-bribery management system.

Process maturity

CMMI-DEV ML3 Appraised

Maturity Level 3 in software development processes.