Objectives
To implement an ISMS meeting the latest version of ISO/IEC 27001, strengthening security and efficiency in software development and in the processes associated with electronic invoicing.
Technology
Implementation of an Information Security Management System under ISO/IEC 27001:2022 for a leading electronic invoicing company in Panama, listed as a Qualified Authorised Provider (PAC).
Problem
As an authorised provider within Panama’s electronic invoicing system, the company occupies a position of trust in the country’s digital economy. It needed to consolidate that trust and demonstrate security in its software development processes, where the real risk for a provider of this kind is concentrated.
Solution
We implemented an ISMS conforming to the 2022 version of ISO/IEC 27001, drawing on the organisation’s technical and management maturity to achieve certification in a notably short timeframe without relaxing any requirement of the standard.
Result
One of the country’s first certifications against the updated version of the standard, and a concrete improvement in software development processes that reinforced confidence in the product.
As an authorised and qualified provider within Panama’s electronic invoicing system, the client plays a crucial role in the country’s digital economy: third-party tax documents pass through its platform. Guaranteeing information security across its operations and its development life cycle was an absolute priority and, given its role in the PAC ecosystem, also a responsibility towards the State and its clients.
Objectives
To implement an ISMS meeting the latest version of ISO/IEC 27001, strengthening security and efficiency in software development and in the processes associated with electronic invoicing.
Approach
The company’s advanced technical and management maturity allowed for an accelerated implementation. Rather than building from scratch, the work consisted of formalising and evidencing practices that already existed, closing the real gaps and aligning everything with the 93 Annex A controls of the 2022 version, including the new ones that bear directly on secure development and configuration management.
Results
The company positioned itself as one of the first in Panama to receive ISO/IEC 27001:2022 certification and significantly improved the confidence and efficiency of its development processes. That reaffirmed its standing as a reference in the electronic invoicing market and allowed it to offer clients a guarantee verifiable by an independent third party.
The project demonstrates that a solid technical base and efficient management can accelerate the implementation of a critical security system. The speed did not come from cutting scope but from starting with an organisation that already did much of the work well.
For SORT, this project also marked its first venture into the Panamanian market, opening the door to new opportunities in the region.
Annex A went from 114 controls across fourteen domains to 93 controls grouped into four themes —organisational, people, physical and technological— with five attributes that allow them to be filtered. Eleven new controls were added, among them threat intelligence, cloud services security, configuration management, information deletion, data masking, data leakage prevention and secure coding.
The limit is evidence: the standard requires the system to have been operating —at least one internal audit cycle, a management review and process records— before stage 2. An organisation with already mature processes can cover that ground in a few months; one starting from scratch will rarely do it in under a year, because there is no way to manufacture operating history.
It is a company authorised by Panama’s tax authority to validate and transmit electronic tax documents on behalf of taxpayers. Because it acts as an intermediary for third-party tax information, its exposure and its responsibility in information security are considerably greater than those of an ordinary software provider.
your business partner