Freiburg, 24/01/2025
The University of Freiburg has a reliable information security management system for operation of its resources in IT Services’ Machine Rooms I, II and III.
TÜV SÜD Management Service GmbH has once again certified the University of Freiburg’s information security management system (ISMS) as reliable. Recertification in accordance with ISO/IEC 27001 took place routinely in October 2024; the ISMS was first certified in 2021. The certificate was presented by auditor Kai Weber from TÜV SÜD on 16 January 2025 to the University of Freiburg’s CIO, Prof. Dr. Stefan Günther and the acting heads of IT Services, Dr. Dirk von Suchodoletz and Dr. Nicole Wöhrle. “I’m extremely pleased about the recertification of our information security management. This objective assessment shows that we treat the information and data processed in Machine Rooms I, II and III very responsibly and that the IT systems of the central administration is professionally structured as well,” says Günther.
Requirements for IT security have risen significantly since initial certification, as the new standard, ISO/IEC 27001:2022, includes additional areas of responsibility such as the use of Cloud services, and threat management. In addition, processes for operation of resources in Machine Room III are now also included in ISO/IEC 27001 certification.
For information security officer Dr. Marc Herbstritt, certification is a major component in the ongoing development and improvement of information security at the University of Freiburg: “Certification is increasingly important as its independent assessment enables us to show that we are keeping up with the state of the art.” Digital sovereignty and control of own critical processes such as revision-proof documentation or inventory management also play an important part in this. Consequently, IT Services makes use of open source software, which is especially well suited to this. The goal is to maintain and constantly improve the information security management system.