Kiro adds ISO/IEC 27001:2022 coverage

By
AR

Arundeep Nagaraj

Customer Success

JA

Jay Raval

Customer Success

KR

Krishna Parab

Product Marketing

We’re happy to share that procurement, security, and vendor-risk teams now have independently verified evidence to support decisions about adopting Kiro. Kiro is included in the defined scope of AWS’s ISO/IEC 27001:2022 certification.

Teams use Kiro with source code, system architecture, internal documentation, and other project context. That information can include intellectual property and data governed by an organization’s security policies. Before approving a developer tool, organizations need clear evidence of how the organization behind it identifies, manages, and reviews information security risks.

What ISO/IEC 27001 covers

ISO/IEC 27001 defines requirements for an information security management system, often called an ISMS. An ISMS brings together the policies, processes, responsibilities, and controls an organization uses to manage information security risks.

The standard requires organizations to identify risks, select appropriate controls, assign responsibility for operating them, and monitor whether they remain effective. These requirements are ongoing, not limited to a point-in-time review. Organizations must adapt their approach as services, technology, and risks change.

AWS’s ISO/IEC 27001:2022 certification is verified by EY CertifyPoint, an independent certification body accredited by the Dutch Accreditation Council. The certification provides independent assurance that the AWS information security management system covering the defined scope has been evaluated against the standard’s requirements.

How this helps your review

Organizations can use this evidence in several practical ways:

  • Procurement and vendor approval. Security, procurement, legal, and vendor-risk teams can use the certificate and supporting documentation as common inputs to their review.
  • Internal information security. Teams can evaluate the certification alongside Kiro’s documentation for data storage, encryption, residency, and other data handling practices.
  • Customer and partner questions. Organizations can use the certification and Kiro documentation to support answers about how Kiro fits into their development-tooling security review.

The certification provides evidence about the security management process covering Kiro. Each organization can consider that evidence alongside its own policies, intended use, data requirements, and governance controls.

Review the evidence

A practical Kiro review can combine:

Together, these resources give organizations a concrete starting point for evaluating Kiro against their security, procurement, and governance requirements.