# ISO 27001

Published articles for ISO 27001.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Trust you can verify: Figma is now ISO 42001 certified

DevFeed: [Trust you can verify: Figma is now ISO 42001 certified](<https://devfeed.tech/articles/trust-you-can-verify-figma-is-now-iso-42001-certified-9687.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/figma-is-now-iso-42001-certified/>)

Author: Tushar Badlani

Published: 2026-07-01T12:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Figma](<https://devfeed.tech/topics/figma.md>), [responsible-ai](<https://devfeed.tech/topics/responsible-ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [figma](<https://devfeed.tech/tags/figma.md>), [iso](<https://devfeed.tech/tags/iso.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Figma announces ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System. An accredited independent auditor assessed Figma's AI governance policies, risk management processes, data practices, development practices, and technical safeguards across its platform.

### Source excerpt

Saying you use AI responsibly is easy, but proving it to an accredited auditor is harder. We decided that was a standard worth meeting.

## Pulumi ships a 238-policy ISO/IEC 27001:2022 pack for AWS

DevFeed: [Pulumi ships a 238-policy ISO/IEC 27001:2022 pack for AWS](<https://devfeed.tech/articles/enforce-iso-27001-across-your-aws-infrastructure-19009.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/iso-27001-policy-pack-for-aws/>)

Author: Dan Biwer

Published: 2026-06-30T00:00:00Z

Content type: release

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [crossguard](<https://devfeed.tech/tags/crossguard.md>), [features](<https://devfeed.tech/tags/features.md>), [governance](<https://devfeed.tech/tags/governance.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [iso](<https://devfeed.tech/tags/iso.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [policy](<https://devfeed.tech/tags/policy.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [product](<https://devfeed.tech/tags/product.md>), [pulumi](<https://devfeed.tech/tags/pulumi.md>), [pulumi-cloud](<https://devfeed.tech/tags/pulumi-cloud.md>), [security](<https://devfeed.tech/tags/security.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

Pulumi announces a pre-built ISO/IEC 27001:2022 policy pack for AWS, available in Pulumi Cloud as iso-27001-aws. The pack contains 238 policies mapped to relevant ISO 27001 controls and supports auditing existing AWS resources and preventing non-compliant resources during pulumi up.

### Source excerpt

ISO/IEC 27001 is the international standard for information security management. Proving you meet it usually means months of mapping abstract security controls to concrete cloud configuration, then authoring custom checks one resource at a time. We're changing that. Today we're shipping a pre-built ISO/IEC 27001:2022 policy pack for AWS, live now in Pulumi Cloud as iso-27001-aws. It encodes the standard's security expectations as 238 ready-to-run policies, so you can align your AWS estate to ISO 27001 in minutes, not months. Why ISO 27001 matters For many companies, ISO 27001 is what stands between them and a customer or a market. The sooner you can reach a certifiable state and prove you stay there, the less compliance slows the business down. The pack collapses months of policy work into something you run continuously, so security keeps pace with growth instead of blocking it. How the pack maps to ISO 27001 The hard part of ISO 27001 has always been translation: its controls are written in the language of governance and risk management, not in the language of AWS resources. Every team has had to interpret each control and decide what it means for an S3 bucket or an RDS instance. The pack does that interpretation for you. Its 238 policies are aligned to the relevant ISO 27001 controls, so each result connects back to the standard instead of leaving you to map it yourself. You can browse the full pack in the pack reference. Audit and prevent The same pack works two ways, so you can both reach compliance and stay there: Audit. Scan your existing AWS estate against the pack, including resources that Pulumi doesn't manage. You get an honest baseline of where you stand against ISO 27001 today, with every finding tied back to the control it affects. Prevent. Run the same pack as a preventative policy during pulumi up to block non-compliant resources before they're ever created. New infrastructure is born aligned to the standard. Audit gets you clean. Preventative policie

## EU AI Act Compliance: Requirements, Risks, and What to Document

DevFeed: [EU AI Act Compliance: Requirements, Risks, and What to Document](<https://devfeed.tech/articles/eu-ai-act-compliance-requirements-risks-and-what-to-document-29638.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-ai-act-requirements/>)

Author: info@goteleport.com (Kayne McGladrey, CISSP)

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [audit](<https://devfeed.tech/topics/audit.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [lifecycle](<https://devfeed.tech/tags/lifecycle.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [versioning](<https://devfeed.tech/tags/versioning.md>)

### AI overview

A practical guide to EU AI Act compliance covering requirements, risks, technical documentation, logging, data governance, lifecycle evidence, traceability, monitoring, and human oversight. It outlines key compliance milestones from August 2025 through August 2027.

### Source excerpt

Cut through EU AI Act complexity with practical guidance on requirements, risks, and documentation.

## Latacora Achieves AWS Advanced Tier Services Partner Status

DevFeed: [Latacora Achieves AWS Advanced Tier Services Partner Status](<https://devfeed.tech/articles/latacora-achieves-aws-advanced-tier-services-partner-status-29190.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2026/01/27/aws-advanced-tier-status/>)

Published: 2026-01-27T21:00:00Z

Content type: release

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Latacora announces that it has achieved Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network. The company says the designation reflects validated technical expertise, AWS-certified professionals, and a proven record of customer success in cloud security and compliance.

### Source excerpt

We are thrilled to announce a major milestone for Latacora: we have achieved the Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network (APN). This designation reflects Latacora's technical expertise and diligence in delivering exceptional cloud security and compliance solutions to our clients, and confirms that we have successfully completed a rigorous validation process demonstrating a proven track record of customer success delivered by a team of AWS-certified professionals with specialized technical capabilities.

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## ISO 27001:2022 Requirements Explained

DevFeed: [ISO 27001:2022 Requirements Explained](<https://devfeed.tech/articles/iso-27001-2022-requirements-explained-29721.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/iso-iec-27001-2022-explained/>)

Author: jackson.pitts@goteleport.com (Jack Pitts)

Published: 2025-08-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Requirements](<https://devfeed.tech/topics/requirements.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iso](<https://devfeed.tech/tags/iso.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [migration](<https://devfeed.tech/tags/migration.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article explains the requirements of ISO/IEC 27001:2022, including its Information Security Management System framework, changes from the 2013 edition, certification migration, formal clauses, and Annex A controls. It describes how organizations can prepare for audits and certification.

### Source excerpt

Learn about ISO 27001:2022 requirements.

## Neon is HIPAA Compliant

DevFeed: [Neon is HIPAA Compliant](<https://devfeed.tech/articles/neon-is-hipaa-compliant-5328.md>)

Original publisher: [Read original article](<https://neon.com/blog/hipaa>)

Author: Busra Demir

Published: 2025-03-13T16:17:42Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Shared Responsibility Model](<https://devfeed.tech/topics/shared-responsibility-model.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [company](<https://devfeed.tech/tags/company.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [shared-responsibility](<https://devfeed.tech/tags/shared-responsibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Neon announces completion of its HIPAA compliance audit, enabling customers to store Protected Health Information (PHI) on its database platform. The article describes safeguards including encryption, role-based access control, audit logging, continuous monitoring, incident response, breach notification, employee training, third-party requirements, and shared customer responsibilities.

### Source excerpt

Neon has completed its HIPAA compliance audit, adding to our security achievements: SOC 2 Type 2, ISO 27001, ISO 27701, GDPR, and CCPA. If your company needs a HIPAA-compliant database, Neon can now securely store Protected Health Information (PHI). What is HIPAA Compliance? The...

## Improving Laravel Application Security with Aikido

DevFeed: [Improving Laravel Application Security with Aikido](<https://devfeed.tech/articles/improving-laravel-application-security-with-aikido-3720.md>)

Original publisher: [Read original article](<https://laravel.com/blog/improving-laravel-application-security-with-aikido>)

Author: James Brooks

Published: 2024-07-08T14:30:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [PHP](<https://devfeed.tech/topics/php.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

Laravel has partnered with Aikido to add security scanning for Laravel applications using Forge. The integration identifies potential vulnerabilities and security flags, surfaces findings within Forge, and combines code and cloud security scanners to help developers manage application security and compliance requirements.

### Source excerpt

As your Laravel application grows, managing security objectives becomes more challenging, especially for small teams or solo developers. Today, Laravel has teamed up with Aikido to provide a seamless solution for securing your Laravel application. With Aikido, Laravel developers using Forge can effortlessly scan for and identify potential security vulnerabilities, all in less than 1 minute.

## Introducing Chainguard's Trust Center

DevFeed: [Introducing Chainguard's Trust Center](<https://devfeed.tech/articles/introducing-chainguard-s-trust-center-13114.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguards-trust-center>)

Published: 2024-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-best-practices](<https://devfeed.tech/tags/software-security-best-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>)

### AI overview

Chainguard introduces its Trust Center, a platform that centralizes security, compliance, and privacy information for users and customers. The center provides access to independent penetration-testing assessments, a SOC 2 Type 2 audit report, hardening guidance, privacy information, data-subprocessor details, and information security policies.

### Source excerpt

Learn how Chainguard prioritizes security with our new Trust Center. Find info on our policies, certifications, and how we protect your software supply chain.

## Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones

DevFeed: [Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones](<https://devfeed.tech/articles/teleport-achieves-iso-27001-hipaa-and-soc-2-compliance-milestones-29855.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-iso-27001-hipaa/>)

Author: reed@goteleport.com (Reed Loden)

Published: 2023-08-11T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Teleport announces ISO 27001 certification, HIPAA compliance, and an expanded SOC 2 Type II report covering the Confidentiality and Availability trust service criteria.

### Source excerpt

An overview of Teleport Achieved ISO 27001, HIPAA, and SOC 2 Compliance Milestones