Challenge
In the global fashion retail industry, protecting business information and customer data has become a strategic priority. The rapid growth of e-commerce, the digitalisation of sales channels, and the management of increasing volumes of personal and commercial data require organisations to adopt a structured approach to information security. Ensuring the confidentiality, integrity, and availability of information helps strengthen the trust of customers, partners, and stakeholders while safeguarding brand value and reputation.
For GUESS, protecting personal data and integrating information security into business processes are essential elements to support responsible growth and strengthen stakeholder trust. Furthermore, the need to implement a shared model at an international level, involving multiple countries and different organisational processes, enabled the company to embark on a path of continuous improvement and strengthen the entire value chain.
Applied expertise
RINA conducted the certification process of GUESS's Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 standard, the internationally recognised standard for managing risks related to the confidentiality, integrity, and availability of information, with a strong focus on cybersecurity and privacy protection.
Through the certification assessment, RINA evaluated data management processes spanning different countries and business functions, verifying compliance with the requirements of the standard and the effectiveness of the controls implemented to protect information assets and personal data.
Thanks to ISO/IEC 27001 certification, GUESS has adopted an internationally recognized framework to demonstrate its commitment to data security and privacy to customers, suppliers and business partners worldwide.
Impact
Achieving ISO/IEC 27001 certification represents an important milestone in GUESS's journey towards a more structured and mature approach to information security management.
Internally, the certification has helped define priorities, objectives, and future stages of the company's information security program, promoting greater integration of data protection principles across business processes and strengthening personal data protection practices.
Externally, the certification serves as a practical tool for strengthening relationships with suppliers and partners, promoting high security standards throughout the supply chain and supporting the assessment of risks associated with new vendors and collaborators.
In a sector where ISO/IEC 27001 certification is still not widely adopted, GUESS has chosen to stand out through a tangible commitment to protecting the personal data of customers and employees, turning information security into a
key driver of trust,
responsibility,
and competitive value.
Through this project, RINA confirms its role as an independent third-party certification body, contributing to the dissemination of information security best practices and strengthening trust across the entire value chain.