Inovum – Establishing a Mature NEN 7510 Organization

Inovum has the ambition to bring information security and privacy to a demonstrably higher level. To realize this ambition, SourceMinds supported the organization in the implementation of NEN 7510 and the further professionalization of the Information Security Management System (ISMS).

The Challenge

The baseline assessment revealed that the technical security measures within Inovum were largely in order. The biggest challenge lay in structurally securing and demonstrating information security within the organization. Policies, governance, processes, and responsibilities were only formally documented to a limited extent, while the requirements surrounding NEN 7510, GDPR, and future NIS2 obligations were becoming increasingly important.

Our approach

SourceMinds guided Inovum throughout the entire improvement process, including:

  • Conducting a baseline assessment and gap analysis.
  • Drafting a roadmap and implementation plan.
  • Developing policy documents and policy frameworks.
  • Setting up an ISMS in accordance with NEN 7510.
  • Developing vendor, cloud, and access security policies.
  • Providing support with governance, risk analyses, and audits.

Assurance and Adoption

In addition to drafting policies and setting up the ISMS, the emphasis was on sustainably embedding information security within the organization. This meant that roles, responsibilities, and consultation structures were refined so that information security does not remain dependent on isolated initiatives but becomes part of regular governance and decision-making.

Attention was also paid to adoption within the organization. By actively involving stakeholders, making policies practically applicable, and increasing awareness, support is created among management, process owners, and employees. As a result, NEN 7510 becomes not just a compliance process, but a way of working that aligns with Inovum's daily practice.

Result

Inovum now possesses a coherent system of policies, processes, and control measures with which information security is structurally managed and secured. The process has resulted in more mature governance, a demonstrably functioning ISMS, and a solid foundation for NEN 7510 compliance and future external audits. In addition, Inovum has gained better insight into risks, responsibilities, and improvement measures, ensuring that information security is no longer a standalone activity but an integral part of daily business operations.

Get in contact

Reach out to us for any questions

Noordeindseweg 88, 2651CX Berkel en Rodenrijs

010 - 203 66 40