IT security by Service Provider. Service Provider maintains a certified information security management system (hereinafter ISMS) according to ISO/IEC 27001. ISMS is a security framework to align information security objectives such as confidentiality, integrity and availability with business objectives of provided services. ISMS includes security controls such as risk management, defined processes and responsibilities, compliance to applicable laws, security in operations and audits.