Follow Us

Everest Discovery Achieves ISO 27001 Recertification

Company demonstrates commitment to the highest standards of information security management through recertification process

Philadelphia, PA—May 16, 2022—Everest Discovery LLC, a leading national litigation support and eDiscovery provider, today announces the company has achieved recertification for the ISO 27001:2013 standard for information security management systems. This marks the seventh consecutive year the company has passed its Security Surveillance II Audit.

ISO 27001:2013 is a globally recognized standard that outlines the requirements for establishing, implementing, maintaining and continually improving an ISMS. The certification demonstrates the company’s commitment to protecting the sensitive information and data of its clients.

To achieve ISO 27001:2013 recertification, an organization must demonstrate that it has:

  • Maintained the ISMS since the last certification audit, including ensuring that all policies and procedures are up to date and staff are trained in the latest security practices.
  • Implemented corrective actions for any nonconformances that were identified during the last certification audit.
  • Continued to improve the ISMS by implementing new security controls or refining existing ones.
  • Conducted internal audits to ensure that the company is operating effectively and meets the requirements of the standard.
  • Conducted management reviews of the policies and procedures ensuring the company is compliant.

“Everest Discovery LLC has undergone rigorous audits and assessments to ensure that all necessary measures have been taken to maintain compliance with the standard,” states Sue Pellegrino, owner and president of Everest Discovery. “This recertification affirms our dedication to continuously improving our information security practices, policies and procedures and is a testament to our ongoing commitment to information security and protecting our clients’ sensitive information.”

“Our clients can trust that their data is secure and that we continue to take all necessary steps to maintain the highest standards of information security. This recertification demonstrates our ability to manage and protect information assets with integrity and confidentiality,” continues Pellegrino.

To learn more about Everest Discovery LLC, please visit www.everestdiscovery.com.

About Everest Discovery LLC

Everest Discovery is a leading litigation support and eDiscovery provider serving legal departments, law firms and government agencies nationwide. Our core focus on solutions, service and security enables us to provide actionable insights that transform workflows, reduce risk and generate significant cost savings for our client base. We comprehensively address our clients’ business problems by incorporating best-of-breed technologies, knowledge-based services and a consultative approach. Everest is proud to be ISO 27001 certified, a certified WBENC Women’s Business Enterprise, a WOSB (Women-Owned Small Business) certified via the SBA and a GSA contractor.

Everest Discovery Achieves ISO 27001 Recertification

Cybersecurity is one of the most critical issues for businesses today, and Everest Discovery is excited to share that the company has achieved ISO 27001:2013 recertification after passing its Security Surveillance II Audit for the seventh consecutive year. The company first earned ISO 27001:2013 certification in 2017 and continues to strengthen its security processes every year.

Achieving ISO 27001:2013 recertification is a significant accomplishment for any organization. It demonstrates a commitment to the highest standards of information security management and that the team has taken the necessary steps to maintain and improve the company’s information security management system.

ISO 27001:2013 is an internationally recognized standard for information security management that provides a systematic approach to managing sensitive information so that it remains secure. It outlines the requirements for establishing, implementing, maintaining and continuously improving an ISMS.

The recertification process involves a thorough audit of a company’s ISMS by an external auditor. The auditor will review all documentation, conduct interviews with staff and assess security controls to determine whether the ISMS meets the requirements of the standard.

To achieve ISO 27001:2013 recertification, an organization must demonstrate that it has:

  1. Maintained its ISMS: The organization must demonstrate that it has maintained the ISMS since the last certification audit. This includes ensuring that all policies and procedures are up to date and staff are trained in the latest security practices.
  2. Implemented corrective actions: If any nonconformances were identified during the last certification audit, corrective actions needed to have been taken to address them.
  3. Continued to improve the ISMS: The organization must demonstrate that it has continued to improve the ISMS by implementing new security controls or refining existing ones.
  4. Conducted internal audits: Internal audits of the ISMS need to be run to ensure that it is operating effectively and meets the requirements of the standard.
  5. Conducted management reviews: The senior management team must assess the policies and procedures and ensure the company is compliant.

When I first acquired Everest Discovery, I decided that getting our ISO certification was important to how we do business. We wanted to show our clients that we have an undeniable commitment to security and the best possible practices in place for handling the sensitive data we deal with each day. This includes not only the right technology but also the right training for our team. And while the certification procedure is a process that takes considerable time, it was something we knew was important and were excited to undertake.

Each year, our executive team commits the time it takes to go through the auditing process to maintain our certification and further our security commitment to our clients. We go through the proper testing to make sure all processes that are in place are still working and are being followed by our entire team. This also gives us the opportunity to refresh our team on what is expected of them and to give them any training needed to ensure we are following all the policies and procedures we have established to ensure we get recertified each and every year.

Getting an ISO certification is a commitment – both of time and technology – but it is well worth the peace of mind the results give to us and our clients.

View the press release on this topic.