NOA always guarantees quality, and soon also with official ISO certificate (9001 and 27001). For some customers, certification is important, for others it is not. NOA wants to meet the highest quality requirements anyway and certification is part of that.

In a broad sense, certification sets requirements for how things are organized, this concerns quality management (9001) but also information security (27001). Not surprising, and certainly not at an organization that revolves around privacy-sensitive material. Online tests and stored material are always risk-sensitive. There are specific requirements for how information is stored. "Of course, we at NOA are constantly aware of this. And our working method and storage method meet the strictest requirements. But certification forces you as an organization to think about that again," says Remko van den Berg, director of NOA.

That is why all processes were critically examined last year. For example, the export of data, but also the granting of rights, in other words, who has what role and who can access which data. And how do employees deal with information. In the security chain, people are always the weakest link. Does it take a USB stick with you and is it protected with a password? Are passwords refreshed regularly, et cetera. Within ISO certification, protocols apply not only to processes, but also to employees.

Van den Berg: "We had and have our processes in order. That's nice to have confirmed. A disadvantage of the certification is that everything has to be recorded according to certain procedures. That entails a lot of administration. Yet it was also useful for us as an organization. The mandatory description of procedures increases awareness and thus increases quality. For example, always logging in with the 'two-factor authentication' and logging out when you leave your computer. And with clearly defined procedures, everyone works in the same way, it is more quickly clear when something is faltering in the process and it is adjusted more quickly. The recurring audits and management reviews force you to remain critical and also make it possible to take improvement measures more quickly."

"A big advantage of ISO is that it is a qualification with which you as an organization indicate that you meet strict requirements," says Remko van den Berg. "Customers want, quite rightly, to know how their information is secured. Without certification, you must be able to demonstrate how processes run and what safety margins are built into them. This can also be time-consuming. Certification makes that unnecessary. ISO is your proof of guarantee."

09 March 2020

Newsletter (Dutch only)

Four times a year news and tips!

Tip: accept our marketing cookies

Our certificates

ISO 9001 TUV 2023 ISO 27001 TUV 2023