IEC 27017_2015 Certification

Virima Achieves ISO/IEC 27017:2015 Certification for Cloud Security Controls 

We are proud to announce that Virima is now ISO/IEC 27017:2015 certified, reinforcing our commitment to protecting customer data in line with global standards. ISO/IEC 27017:2015 is the international code of practice for information security controls based on ISO/IEC 27002 for cloud services. It gives cloud service customers and providers a shared set of expectations for how cloud environments should be secured, governed, and operated. 

“At Virima, we know our customers entrust us with highly sensitive information that manages their information technology. We provide the very best data protection, availability and privacy to ensure our customers can rely on our services. These third-party audits provide a validation that we achieve our stated goals.” 

– Mike Bombard, COO, Virima 

The independent assessment was carried out by Quality Research Organization (QRO), and the assessment concluded that Virima is compliant with the standards demanded for ISO/IEC 27017:2015 certification. The certificate bearing reference code 2026091534 was issued on 15 September 2026 and will be valid for three years, through 14 September 2029, subject to scheduled surveillance audits. 

“ISO/IEC 27017:2015 builds directly on the ISMS discipline we established with ISO/IEC 27001:2022,” said Saran Anandan, Virima’s IT Compliance Manager. “It confirms that our cloud security controls are designed and operated to the standard our customers expect when they put discovery, CMDB, and service-mapping data in a SaaS environment.” 

Scope of the Certificate

Our ISO/IEC 27017:2015 certification applies to the following scope: 

“The Information Security Management System (ISMS) and associated cloud security controls cover the development, operation, and support of the Virima SaaS IT management platform and related cloud services, including associated systems, processes, personnel, information assets, cloud environments, and supporting infrastructure, across Virima’s operational locations, remote working environments, and approved cloud service platforms.” 

Built for Enterprise Trust and Cloud-Ready Operations

Achieving ISO/IEC 27017:2015 underscores our focus on protecting customer information in the environments where modern IT estates actually run, including multi-tenant and hybrid cloud delivery models. 

“Customers evaluating discovery, CMDB, and service mapping platforms increasingly ask how we secure the cloud path their data travels,” stated Virima CEO Rajan “Raj” Palaniswamy. “ISO/IEC 27017:2015 is independent confirmation that our cloud security controls sit alongside our broader ISMS and quality approach to protecting customer data.” 

Adding to Our Compliance Foundations

This milestone builds on our existing security and transparency program, including: 

  • ISO/IEC 27001:2022 certification for our Information Security Management System (ISMS) covering development, operation, and support of the Virima SaaS IT management platform and related services 

Together, ISO/IEC 27001:2022, ISO/IEC 27017:2015, and SOC 2 Type 2 give customers the assurance they need that Virima operates with customer data protection as the highest priority. 

About Us

Virima helps enterprises across the globe simplify and automate IT asset discovery, CMDB maintenance, and service mapping across hybrid infrastructures. Through authoritative multi-source discovery, deep CMDB insights, and codeless integrations, Virima delivers Trusted Runtime Truth: what exists, how it’s connected, what could break, and who owns it, so teams can reduce risk, improve uptime, and move faster with confidence.