An Information Security Management System (ISMS) is not a single software product. It is the documented way a company identifies information risk, selects and operates controls, assigns ownership, and reviews those controls as the business changes. ISO/IEC 27001 is the globally recognised specification for building and running that system.
Certification is independently audited. External auditors assess whether the ISMS is designed, operated, and continually improved as the standard requires — access control, incident handling, supplier management, asset inventory, and how confidential information is classified and shared.
Moxie Company Limited is ISO/IEC 27001 certified through LRQA under UKAS accreditation. That is the same LRQA / UKAS mark on this page: a management-system certification, independently assessed, for how we protect information across Hong Kong and Asia Pacific delivery.
- International ISMS standard ISO/IEC 27001 defines how organisations manage information security as a system — people, process, and technology together.
- Independently audited Certification is awarded after external assessment of the ISMS, not after a self-declared checklist.
- LRQA under UKAS accreditation Moxie's certificate is issued through LRQA, with UKAS accreditation of the management-system certification.
- Continual improvement The standard requires the ISMS to be reviewed and strengthened over time as programmes, platforms, and suppliers change.