Flex software

Flex HRM is now covered by Visma's VCDM security model

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Flex HRM is now covered by Visma's VCDM security model</span>

How do you combine a fast pace of development with security efforts that never stop? The Visma Cloud Delivery Model (VCDM) provides us with a common framework for strengthening security every step of the way, from development to day-to-day operations. Here’s what that means for you as a Flex HRM user.

Security takes the next step with Visma

When you manage data related to employees, payroll, and employment, you need to be able to trust that the information is protected and accessible. That’s why security has long been an integral part of Flex HRM, through measures such as encryption, access control, secure logins, and regular security tests.

Now we’re taking the next step. Through the Visma Cloud Delivery Model (VCDM), Flex HRM becomes part of a unified approach within Visma for the secure development, delivery, and operation of cloud services. The model sets high standards for both technology and working methods and is based, among other things, on established standards and audits such as ISO 27001 and ISAE 3402.

“The fact that Flex HRM now meets the requirements of VCDM is an important step for both us and our customers. It strengthens our ability to protect customer data and deliver a stable and accessible service. At the same time, it provides us with a clearer and more consistent structure for our security efforts,” says Oskar Anderstål, Development Manager.

How VCDM Contributes to a Secure and Stable Service

VCDM covers the entire system lifecycle, from development to ongoing operations and improvements. More specifically, this means that:

  • Security is built in from the start. Security requirements are factored in as soon as new features are planned, which reduces the risk of problems being discovered only after the fact.

  • Changes are verified before they reach you. Testing and other checks help us detect errors and vulnerabilities early on, before they have a chance to affect your work.

  • Updates can be made incrementally and in a controlled manner. Automation and frequent, minor updates make it easier to test, monitor, and adjust changes—while maintaining stability.

  • Security efforts continue after launch. Operations and risks are monitored even after launch, so that security can evolve and improve over time.

VCDM, ISO 27001, and ISAE 3402—how are they related?

VCDM, ISO 27001, and ISAE 3402 are all parts of the same whole but serve slightly different functions in security work. Let’s break down how they’re connected:

  • VCDM is the model. It describes how Visma’s cloud services are to be developed, delivered, and operated, as well as the processes and technical requirements that must be followed.

  • ISO 27001 is the certification. The standard requires a systematic information security management system, including risk management, accountability, processes, and continuous improvement.

  • ISAE 3402 Type II is the independent audit. An external party reviews how established processes and controls have functioned over a specific period of time.

In short: VCDM governs how the work is to be conducted, ISO 27001 confirms that the management system meets an international standard, and ISAE 3402 provides additional evidence for assessing how the controls function in practice.

Clearer documentation simplifies compliance work

If you work with information security, procurement, or compliance, you’re probably familiar with these questions: How is personal data protected? What controls are in place? How are incidents handled? And how can you verify that procedures are actually being followed? With VCDM, the answers are now easier to find.

– With clear and independently audited documentation, it becomes easier to see how we, as a supplier, approach security. “Together, VCDM, ISO 27001, and ISAE 3402 provide a comprehensive picture of our work with risks, controls, and information security, which facilitates both the procurement process and ongoing security audits,” says Oskar Anderstål, Development Manager.

How We Leverage Visma’s Collective Expertise

The threat landscape is constantly changing, with cyber threats such as data breaches and ransomware becoming both more frequent and more sophisticated. At the same time, technology is evolving and new regulatory requirements are emerging. So how do we ensure that our security efforts keep pace?

An important part of the answer is not to work alone. As part of Visma, we can draw on the expertise and experience of over 200 companies in areas such as information security, cloud computing, and regulatory compliance. This gives us greater resources to identify new risks, improve our work processes, and take a proactive approach—a level of security that would have been significantly more difficult to build on our own.

To summarize: Flex HRM’s inclusion in VCDM is not an end in itself, but rather the foundation for continued collaborative work within Visma, where you, as a customer, can feel confident that our security solutions will continue to evolve in step with the changing world.

Questions or concerns? Learn more about how we approach security in Flex HRM or contact us, and we’ll tell you more.

You may also be interested in