
SERDANG, 25 September 2025 – The Information and Communication Development Centre (iDEC), Universiti Putra Malaysia (UPM), successfully conducted the Information Security Management System (ISMS) ISO/IEC 27001:2022 Audit to assess the level of compliance and effectiveness of its information security management practices.
The audit was conducted by SIRIM and led by Ms Sazlin binti Alias as the appointed auditor. The assessment forms part of iDEC’s continuous efforts to ensure that information security management is implemented systematically and effectively in accordance with the requirements of the international ISO/IEC 27001:2022 standard.
The audit scope included inspections and site visits to two key facilities, namely the Data Centre at iDEC Beta and the Disaster Recovery Centre (DRC) at iDEC Epsilon. The assessment focused on several critical areas, including information security controls, compliance with established operational procedures and work processes, information security risk management, as well as the effectiveness of ISMS policies and controls implemented at both locations.
The audit visits to the Data Centre and DRC also provided an opportunity for the auditor to assess the implementation of security controls comprehensively, particularly in relation to information asset protection, business and service continuity, and the readiness of ICT infrastructure in responding to risks and disruptions that could affect the delivery of the university’s digital services.
The successful implementation of the audit reflects iDEC’s continued commitment to safeguarding the confidentiality, integrity and availability of information, which are fundamental elements in the delivery of secure and reliable ICT services at UPM. A robust information security management system not only protects data and ICT assets but also strengthens the confidence of university stakeholders in the university’s ability to manage information securely and effectively.
The audit was completed smoothly through the cooperation and commitment of iDEC personnel involved throughout the assessment process. The findings from the audit will serve as an important reference for identifying areas for improvement and strengthening information security controls on a continuous basis.
Through regular ISMS audits, iDEC remains committed to ensuring that its information security management system remains relevant, effective and responsive to technological developments and the evolving cybersecurity threat landscape. This ongoing effort supports iDEC’s aspiration to deliver secure, resilient and quality ICT services while contributing to UPM’s broader digital transformation agenda.
The audit also reinforces the importance of continuous monitoring, evaluation and improvement in maintaining an effective information security management framework. With consistent implementation of established controls and procedures, iDEC is well positioned to strengthen its information security governance and ensure the sustainability of secure digital services for the university community.
Date of Input: 28/09/2025 | Updated: 21/08/2026 | zuraya

Universiti Putra Malaysia
UPM Putra InfoPort - IOI Resort
Jalan Kajang - Puchong
43400 UPM Serdang
Selangor Darul Ehsan