GitHub Adds ISO/IEC 27001:2013 to Its Compliance Portfolio

GitHub has completed certification for ISO/IEC 27001:2013, covering its Information Security Management System (ISMS). The audit process, which began in early September 2021, wrapped up a full quarter ahead of the original schedule.

What the ISMS Covers

An ISMS is a documented framework for establishing, operating and improving a security program that protects the confidentiality, integrity and availability of information. GitHub’s certified ISMS scope includes:

  • GitHub.com
  • GitHub Enterprise Cloud (GHEC)
  • GitHub Advanced Security (GHAS)
  • GitHub Actions
  • Pull Requests, Issues, Wikis, Pages and Packages

How to Access the Certification

Enterprise and organization owners can download the certification directly from GitHub. Instructions for enterprise owners are documented here, while organization owners can follow the steps here. The certificate is also broadly available on the GitHub security page under "ISO/IEC 27001:2013."

ISO/IEC 27001:2013 certification reflects continued investment in security processes, risk management and operational maturity. It joins GitHub’s existing compliance portfolio, which already includes SOC and ISAE reports, a FedRAMP Tailored LiSaaS ATO, and the Cloud Security Alliance CAIQ.

GitHub says it will continue pursuing new certifications and audits, as well as expanding the scope of its current ones, as part of its ongoing commitment to security.