CCSI — Security & Compliance
How we protect the information our customers entrust to us.
Scope of certification
The ISMS applies to CCSI IT Operations, Product Development, Customer Support and solutions covering functional areas that support its growth, security, and operations.
Our approach
Our information security management system (ISMS) is independently certified to ISO/IEC 27001:2022 and has been since 2021. The sections below describe, requirement by requirement, what the standard asks of us and how we meet it. They are written for customers and partners; internal documents, records and evidence are reviewed by our certification auditors and are not published.
We do not release our policies, procedures, standards or internal records to third parties, including under NDA; they are our intellectual property. Our ISMS is independently certified to ISO/IEC 27001:2022, and we can provide the certificate and the statement of certification scope as evidence. Where a customer needs more, we can answer specific questions or walk through our practice in a call.
Context of the organization
Context of the organization
We maintain a documented process for identifying and reviewing the external and internal issues relevant to our business and to the effectiveness of our ISMS, including regulatory, market, technological and organizational factors, alongside the needs and expectations of interested parties such as customers, regulators and employees. This analysis directly informs our defined ISMS scope, risk assessment criteria and security objectives, which are reviewed and updated on a regular cycle. Ownership of this context review sits with senior management and information security leadership as part of our management review process, ensuring the ISMS continues to reflect changes in our operating environment. We continue to mature this analysis over time through our internal audit and management review cycle, incorporating feedback from audits, risk assessments and stakeholder input. This process operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Understanding the organization and its context
We maintain a documented process for identifying and reviewing the external and internal issues relevant to our organization and our information security management system, captured in our Understanding the Organization and Its Context policy. This analysis considers factors such as the regulatory and legal landscape, market and competitive pressures, technology trends, and internal factors including organizational structure, culture, and resource capabilities. Our leadership and ISMS governance team review this context as part of our periodic management review cycle, ensuring it continues to inform risk assessment, scope definition, and strategic security priorities. This determination has been maintained and refined since our initial certification and is examined by our certification body at every audit as part of the overall ISMS evaluation. We continue to mature this analysis to reflect evolving business conditions and stakeholder expectations.
Understanding the needs and expectations of interested parties
We maintain a documented process, set out in our Interested Parties & Security Requirements policy, for identifying the parties relevant to our ISMS, including customers, regulators, suppliers, employees, and shareholders, and for capturing their applicable legal, regulatory, and contractual security requirements. This register is reviewed and updated as part of our periodic management review and risk assessment cycle, ensuring new obligations—such as customer contractual clauses or regulatory changes—are incorporated into the scope and controls of the ISMS. The output of this process directly informs our risk treatment plan and Statement of Applicability, so that identified requirements are traceable to specific controls. This practice operates continuously and is examined by our certification body at every surveillance and recertification audit, and we continue to refine it through our internal audit and management review processes.
Determining the scope of the information security management system
We maintain a formally documented ISMS scope statement that defines the boundaries of our information security management system, including the organizational units, locations, services and technology environments covered. This scope was established with reference to our internal and external context and the requirements of interested parties, including customers, regulators and partners, and it explicitly accounts for dependencies on third parties and outsourced services. The scope document is retained as controlled documentation and is reviewed as part of our periodic management review and internal audit cycle to ensure it remains accurate as our business and service offerings evolve. This scope has been in place and examined by our certification body at every audit since our initial certification, and we continue to refine its wording and boundary definitions through our continual improvement process.
Information security management system
We maintain a documented ISMS, described in our ISMS Overview Document, that defines the scope, processes and interactions required to manage information security across the organisation. This framework has operated as an integrated management system since our initial certification, encompassing risk management, policy governance, control implementation, internal audit and management review. We continually improve the ISMS through regular management review, internal audit findings and monitoring of security objectives, ensuring the processes remain effective and aligned with organisational context and stakeholder requirements. The overall ISMS, including how its processes interact, is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Leadership
Leadership
Our executive leadership sets and periodically reviews the information security policy and objectives, ensuring they remain aligned with business strategy and risk appetite. Senior management allocates the budget, staffing and tools needed to operate the ISMS and has assigned clear ownership for security roles and responsibilities across the organisation. Leadership commitment is evidenced through regular management review meetings, where security performance, risks and improvement actions are discussed and directed, and through visible sponsorship of security initiatives communicated to staff. This leadership engagement has been maintained since our initial certification and is examined by our certification body at every surveillance and recertification audit as part of the certified ISMS scope. We continue to mature how leadership involvement is documented and communicated through our ongoing management review and internal audit cycle.
Leadership and commitment
Our executive leadership team maintains formal accountability for the ISMS, evidenced through an approved leadership commitment statement that ties information security objectives to our overall business strategy. Leadership involvement is embedded into our governance routines, including resourcing decisions, management review meetings, and internal communications that reinforce the importance of information security across the organisation. We ensure security requirements are integrated into core business and operational processes rather than treated as a separate function, and management actively supports staff and process owners in contributing to the ISMS's effectiveness. Senior leaders also promote continual improvement, using outcomes from internal audits and management reviews to refine governance practices over time. This leadership commitment has been demonstrated consistently within our certified ISMS since our initial certification and is reviewed by our certification body at every surveillance and recertification audit.
Policy
We maintain a top-management-approved information security policy that is appropriate to our business, sets the direction for our security objectives, and commits us to meeting applicable legal, regulatory and contractual security requirements as well as to continually improving our ISMS. The policy is formally documented and version-controlled, and is communicated to all employees and relevant third parties as part of our onboarding and ongoing awareness processes. We make the policy available to customers and other interested parties upon reasonable request. This policy and its supporting framework are reviewed at planned intervals through our management review process and have been examined by our certification body at every surveillance and recertification audit since our initial certification.
Organizational roles responsibilities and authorities
We maintain a documented allocation of information security roles, responsibilities and authorities as part of our ISMS governance framework, covering ownership of the management system, control operation, and reporting lines into top management. Designated individuals hold accountability for ensuring ongoing conformance with ISO/IEC 27001 and for presenting ISMS performance, audit results and risk status to top management through our management review process. These assignments are communicated through role descriptions, onboarding, and internal governance documentation, and are reviewed periodically to reflect organisational changes. This structure has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit as part of the certified ISMS scope.
Planning
Planning
We maintain a documented risk assessment and risk treatment methodology that is applied consistently across the organisation and is reviewed as part of our annual ISMS planning cycle. Our information security objectives are defined at a management level, linked to identified risks and opportunities, and tracked for progress through management review. Changes affecting the scope, architecture, or operation of the ISMS are assessed for risk impact and planned through our change management process before implementation. This planning approach, including our risk register and objectives, sits within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit. We continue to refine our risk criteria and objective-setting process through our ongoing management review and internal audit cycle.
Actions to address risks and opportunities
We maintain a documented ISMS Risk Management Policy that governs how information security risks and opportunities are identified, assessed, treated, and monitored across the organization. Risk assessments are performed on a recurring basis and are integrated into our broader ISMS planning and operational processes, ensuring that risk treatment actions are actioned by accountable owners and tracked to completion. The effectiveness of these actions is reviewed through our management review and internal audit cycle, allowing us to continually refine our risk criteria, methodology, and treatment plans. This risk management approach has operated within our certified ISMS since our initial certification and is independently examined by our certification body at every surveillance and recertification audit.
General
We maintain a formal risk and opportunity identification process that considers our organizational context, stakeholder requirements, and the scope of our ISMS, and this feeds directly into our risk treatment plan and security objectives. This process has operated since our initial certification and is reviewed and updated as part of our regular management review and internal audit cycle, ensuring it stays aligned with changes in our business, technology, and threat landscape. Identified risks and opportunities are tracked, prioritised, and linked to specific controls and improvement actions, with ownership assigned to relevant functions. We continue to mature this process through periodic reassessment, incorporating lessons from audits, incidents, and management reviews to strengthen how risks and opportunities are identified and addressed. This activity is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Information security risk assessment
We maintain a documented information security risk assessment methodology that defines our risk acceptance criteria and consistent scoring approach for likelihood and impact, ensuring comparable results across assessment cycles. Risks to the confidentiality, integrity and availability of information within our ISMS scope are identified, assigned to accountable risk owners, and analysed to determine risk levels using this established methodology. The resulting risk register is evaluated against our defined criteria to prioritise risks for treatment, and it is reviewed and updated as part of our regular management review and internal audit cycle. This process has operated continuously within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine the criteria and methodology over time as part of our ongoing continual improvement practice.
Information security risk treatment
We operate a documented risk treatment process as part of our certified ISMS, under which identified risks are evaluated and mapped to appropriate treatment options and controls. We maintain a Statement of Applicability that records which Annex A controls are applied, the justification for inclusion or exclusion, and their implementation status, and we cross-check this against our risk assessment outputs to confirm completeness. Our risk treatment plan is reviewed and updated through our regular management review and internal audit cycle, and residual risks are formally reviewed and accepted by designated risk owners. This process has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature it through ongoing risk assessment cycles and management review.
Information security objectives and planning to achieve them
We maintain documented information security objectives that are derived from our risk assessment process and aligned with our information security policy, covering relevant functions and levels of the organisation. Each objective is assigned an owner, defined resources, a target timeframe, and measurable success criteria, and these are tracked through our management review cycle. Progress against objectives is monitored throughout the year and reported into management review, where objectives are reassessed and updated as our risk environment or business priorities evolve. Objectives and their associated plans are communicated to relevant personnel and retained as documented records within our ISMS. This process operates as part of our certified ISMS and is examined by our certification body at every surveillance and recertification audit, with continual refinement driven through our internal audit and management review programme.
Planning of changes
We manage changes to our ISMS through a structured change management process that is integrated into our governance and management review cycles, ensuring that changes to policies, scope, risk treatments, or supporting controls are assessed for impact before they are implemented. Proposed changes are reviewed by relevant owners to confirm that responsibilities, resourcing, and dependencies are addressed, and that the change does not introduce unintended risk to the confidentiality, integrity, or availability of information. This planning approach has been embedded within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We document significant changes and their rationale as part of our management review records and internal audit evidence, and we continue to mature our change planning practices through periodic review of lessons learned and evolving business needs. This ensures the ISMS remains consistent, controlled, and fit for purpose as our organization and threat environment evolve.
Support
Support
Our ISMS operates with dedicated resourcing, including assigned information security roles, budget and access to appropriate tools and platforms, which is reviewed by leadership as part of our management review cycle. We maintain a competence and awareness programme covering onboarding and periodic refresher training so staff understand their security responsibilities, supplemented by targeted communications on policy changes and security expectations. Documented information supporting the ISMS, such as policies, procedures and records, is controlled through a defined document management process that governs authoring, approval, versioning and periodic review. Internal and external communication relevant to information security is managed through defined channels and responsibilities. These arrangements are within the scope of our certified ISMS and are examined by our certification body at every surveillance and recertification audit.
Resources
We identify and provide the staffing, budget, tools, and infrastructure required to operate our ISMS effectively, with resourcing needs reviewed as part of our management review and annual planning cycles. Roles and responsibilities for information security are assigned to appropriately skilled personnel, and we allocate budget for security tooling, training, and third-party services such as audits and technical assessments as needed. Senior management, through governance forums, reviews resourcing adequacy against ISMS objectives, risk treatment plans, and audit outcomes, adjusting allocations where continual improvement opportunities are identified. This resourcing commitment has been in place and operating within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.
Competence
We maintain defined role requirements for positions that affect information security, covering the skills, qualifications and experience expected for each role. We verify competence during recruitment and onboarding and through ongoing performance and training reviews, and we provide role-specific security awareness and technical training to staff and relevant contractors. Training completion, certifications and other evidence of competence are retained in our HR and learning records. We periodically review competence requirements and training effectiveness as part of our management review and internal audit cycle, continuing to refine role profiles and training content as our operations evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every audit.
Awareness
We maintain a security awareness programme that communicates our information security policy and expectations to all personnel working under our ISMS, delivered through onboarding training and periodic refresher sessions. Staff are made aware of how their day-to-day roles support the organisation's security objectives and of the potential consequences, both to the organisation and to individuals, of non-conformance with ISMS requirements. Awareness content is reviewed and updated to reflect changes in policy, risk landscape, and lessons learned through internal audits and management review. Completion of awareness activities is tracked, and this area is examined as part of every certification and surveillance audit under our ISO/IEC 27001:2022 certified ISMS. We continue to mature the programme's delivery methods and content through our continual improvement process.
Communication
We maintain a defined communications approach for information security matters that identifies the audiences, timing, and channels for both routine and urgent messages, covering internal updates to staff and management as well as external communications to customers, regulators, and suppliers where relevant. This is supported by established processes such as management review, security awareness updates, incident notification procedures, and periodic reporting to leadership, each with a clear owner and communication channel. We use a mix of channels including our intranet, email, ticketing and collaboration platforms, and formal reports to ensure consistent and traceable delivery of security information. This approach operates within our certified ISMS and is reviewed as part of our ongoing management review and internal audit cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to refine our communication practices to reflect organisational changes, new stakeholder needs, and lessons from audits and incident exercises.
Documented information
We maintain a structured document control process that governs the creation, review, approval, versioning, and retention of all ISMS documentation, including policies, procedures, standards, and records generated by our security processes. Documents are held in a controlled repository with defined ownership, access permissions, and review cycles to ensure they remain accurate and current. Our internal audit and management review cycles include verification that documented information is properly maintained, version-controlled, and accessible to relevant personnel while being protected from unauthorized access or modification. This documentation control process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine our document management practices through continual improvement activities identified during internal audits and management reviews.
General
We maintain a structured set of documented information supporting our ISMS, including policies, procedures, standards, and records that satisfy the explicit documentation requirements of ISO/IEC 27001:2022 as well as additional internal documents we have determined are necessary for the ISMS to function effectively. This documentation is version-controlled, subject to defined ownership, and stored within our governance and document management platform, with access restricted appropriately. We review and update this documented information as part of our regular management review and internal audit cycle, ensuring it remains accurate, current, and fit for purpose as our ISMS matures. This approach has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit, confirming that our documentation practices continue to meet the standard's requirements.
Creating and updating
We maintain a documented information control process as part of our certified ISMS, under which policies, procedures and records are created and updated using consistent templates that capture titling, versioning, authorship and revision history. Documents are managed in our controlled electronic document repository, with defined formats and access controls appropriate to their sensitivity and audience. Before publication or update, documents go through a defined review and approval workflow to confirm they remain suitable and adequate for their purpose. This process has operated since our initial certification and is examined at every surveillance and recertification audit, and we continue to refine document governance practices through our management review and internal audit cycle.
Control of documented information
We maintain a document control process that governs how ISMS policies, procedures and records are created, reviewed, approved, distributed and retired. Documents are stored in managed platforms with access restricted according to role, version history retained, and current versions clearly identified to prevent use of outdated material. Retention and disposal of records follow defined schedules aligned with legal, regulatory and business requirements. This process operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it is examined by our certification body at every audit. We continue to mature our document control practices, including refining access permissions and lifecycle management as our tooling and organisational needs evolve.
Operation
Operation
We operate our information security management system through defined operational processes that translate our risk treatment plan into practical controls across IT, HR, vendor management and service delivery. Operational criteria, responsibilities and change management procedures are documented and followed so that planned changes are assessed and approved before implementation, and any unplanned change is reviewed for security impact. We maintain records and evidence of these operational activities, including logs, approvals and change tickets, which support ongoing monitoring and audit. These processes are reviewed as part of our internal audit programme and management review cycle, and they have been examined by our certification body at every surveillance and recertification audit since our initial certification. We continue to mature our operational controls through continual improvement identified in these review cycles.
Operational planning and control
We operate documented processes and procedures that translate our risk treatment plan and security objectives into day-to-day operational practice, with defined criteria for how key ISMS-relevant activities are to be performed. Changes to systems, processes, and services are managed through a formal change control process, which includes assessing security impact before changes are approved and reviewing outcomes to address any unintended effects. Third-party and outsourced services relevant to the ISMS are managed through vendor risk assessment, contractual security requirements, and ongoing monitoring to ensure external processes meet our security expectations. Operational records, logs, and process documentation are maintained to provide evidence that these controls are being carried out as intended. This operational planning and control framework has been part of our certified ISMS since our initial certification and is reviewed and refined through our internal audit and management review cycle, and it is examined by our certification body at every audit.
Information security risk assessment
We operate a documented risk assessment process that is run at planned intervals and is re-triggered when significant organisational, technical, or environmental changes occur. Assessments are performed against the risk identification, analysis and evaluation criteria established for our ISMS, and cover assets, threats, vulnerabilities, and business impact relevant to our operations. Results, including identified risks, risk ratings, and treatment decisions, are recorded and retained as documented information, and are reviewed through our management review and internal audit cycle. This process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our methodology and supporting tooling through that ongoing review cycle.
Information security risk treatment
We maintain a formal risk treatment process that translates the outputs of our risk assessment into an actionable treatment plan, with owners, target controls, and completion tracking managed through our risk register. Treatment actions are implemented through our operational security processes, spanning technical, procedural, and organisational controls drawn from our Statement of Applicability. We retain documented records of treatment decisions, implementation status, and residual risk outcomes, which are reviewed at planned intervals as part of our management review and internal audit cycle. This process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature the process, refining prioritisation and evidence capture based on management review and internal audit input.
Performance evaluation
Performance evaluation
We maintain an ongoing performance evaluation programme as part of our certified ISMS, including defined metrics and monitoring activities that track the operation and effectiveness of our security controls. We conduct internal audits on a planned cycle, covering all applicable clauses and Annex A controls, using qualified and independent auditors. Results from monitoring, audits, and risk assessments feed into regular management reviews, where leadership assesses ISMS performance, resource needs, and opportunities for improvement. We continue to mature our measurement approach and audit scope through successive management review and internal audit cycles. This entire process is examined by our certification body at every surveillance and recertification audit.
Monitoring measurement analysis and evaluation
We maintain a defined set of security metrics and monitoring activities covering key controls and processes across our ISMS, with clear ownership for who collects data, who reviews it, and how often each measure is assessed. Our methods are applied consistently so results can be compared over time and reproduced, and we record outcomes as documented evidence retained for audit and management review purposes. Findings from this monitoring feed into our internal audit programme and management review cycle, where we evaluate the ongoing effectiveness and performance of the ISMS and identify opportunities for improvement. This measurement and evaluation activity has been part of our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our metrics and review methods through this continual improvement cycle.
Internal audit
We maintain a documented internal audit programme covering the full scope of our certified ISMS, with an audit schedule that ensures all clauses and applicable Annex A controls are reviewed across a defined cycle. Audits are performed by personnel who are independent of the areas being reviewed, using a consistent methodology to assess conformance and operating effectiveness. Findings, observations and improvement opportunities from each audit are recorded and fed into our management review and corrective action processes, closing the loop between assurance activity and continual improvement. This internal audit process has operated since our initial certification and is itself examined by our certification body at every surveillance and recertification audit.
General
We maintain a documented internal audit programme that defines audit scope, criteria, frequency and methodology across the certified ISMS, covering all applicable clauses and Annex A controls on a rolling schedule. Audits are performed by personnel independent of the areas being audited, using a risk-based approach to prioritise higher-risk processes and controls, and results are recorded and tracked through to closure. Findings, non-conformities and improvement opportunities feed directly into our management review and corrective action processes, ensuring continual refinement of the ISMS. This internal audit programme has operated since our initial certification in 2021 and is itself reviewed and examined by our certification body at every surveillance and recertification audit.
Internal audit programme
We maintain a documented internal audit programme covering all areas of the certified ISMS, with a defined schedule, audit criteria and scope established for each audit cycle. Audits are performed by personnel independent of the process being reviewed to preserve objectivity and impartiality, using a consistent methodology for planning, fieldwork and reporting. Audit results, including any observations for improvement, are reported to relevant management and tracked through to resolution as part of our management review process. We retain audit plans, reports and related records as documented evidence, and this programme has operated continuously since our initial certification, with the certification body examining its operation at each surveillance and recertification audit. We continue to refine audit prioritisation and coverage based on the importance of processes and the outcomes of previous audits.
Management review
We conduct management reviews of our ISMS at planned intervals, bringing together leadership to evaluate the system's ongoing performance, risk posture, and alignment with business objectives. These reviews draw on inputs including internal and external audit results, risk assessment outcomes, security metrics, incident trends, and feedback from interested parties, ensuring decisions are grounded in current operational data. Outputs from each review, including decisions on resource needs, policy adjustments, and improvement initiatives, are documented and tracked to closure through subsequent review cycles. This practice has operated since our initial certification and continues to mature through refinements identified during our internal audit and management review cycle. The management review process itself is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
General
We conduct management reviews of our ISMS at planned intervals, bringing together senior leadership to assess the system's continuing suitability, adequacy, and effectiveness. These reviews draw on inputs such as audit results, risk assessments, security performance metrics, incident trends, and stakeholder feedback, and produce documented outputs including decisions and actions for improvement. This practice has operated since our initial certification and is embedded in our governance calendar as a recurring, minuted activity with defined attendees and agenda requirements. The management review process itself, along with its records and resulting actions, falls within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. We continue to refine the review's inputs and outputs through our internal audit and continual improvement cycle to ensure they remain aligned with organisational needs.
Management review inputs
We maintain a structured management review process that draws together all of these required inputs on a scheduled basis, including status updates on previous action items, relevant contextual and stakeholder changes, security performance metrics, internal and external audit results, progress against information security objectives, and the current state of risk assessment and treatment. These reviews are documented, with outcomes and follow-up actions tracked through to closure, and this process has operated consistently since our initial certification. Our approach to consolidating and analysing these inputs continues to mature through our internal audit and continual improvement cycle, refining how trends and feedback are presented to leadership. This process falls within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Management review results
We hold scheduled management reviews as an established part of our certified ISMS, bringing together inputs such as audit results, risk treatment status, security metrics, incidents, and stakeholder feedback so that leadership can make informed decisions. The outcomes of each review, including agreed improvement actions and any required changes to the ISMS scope, policies, controls or resourcing, are documented and tracked to completion. These records are retained as evidence and are reviewed as part of our internal audit programme. This process operates continuously and is examined by our certification body at every surveillance and recertification audit. We continue to mature the review process, refining the inputs considered and the way decisions are tracked through successive management review and internal audit cycles.
Improvement
Improvement
We operate a documented continual improvement process, established since our initial certification, that draws on internal audits, management reviews, risk assessments, and operational monitoring to identify opportunities to strengthen our ISMS. Corrective actions and improvement initiatives are tracked through defined procedures, ensuring root causes are addressed and outcomes are verified for effectiveness. Our leadership team reviews ISMS performance at planned intervals, using these findings to adjust policies, controls, and resourcing as needed. This improvement cycle is embedded within our certified ISMS and is examined by our certification body at every surveillance and recertification audit. Through successive audit cycles, we continue to mature this process, refining how we capture lessons learned and translate them into measurable enhancements to our security posture.
Continual improvement
Continual improvement is embedded in our ISMS through the ongoing cycle of internal audits, management reviews, risk assessments, and corrective action processes that have operated since our initial certification. Outputs from these activities, along with metrics, stakeholder feedback, and changes in our threat landscape, are reviewed by management on a regular cadence to identify opportunities to strengthen policies, processes, and technical controls. We maintain a structured approach to tracking improvement actions through to completion and verifying their effectiveness before closure. This continual improvement mechanism is a core part of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. Through successive audit cycles, we have refined our risk treatment, control implementation, and governance practices to keep pace with organisational and external changes.
Nonconformity and corrective action
We maintain a documented corrective action process that is used to capture nonconformities identified through internal audits, management review, monitoring activities, or day-to-day operations. Each nonconformity is logged, assessed for immediate containment needs, and investigated to determine underlying causes before corrective actions are defined and assigned to an owner. We track these actions through to completion and review their effectiveness before closure, updating related policies, procedures, or controls where the review indicates this is needed. This process operates as part of our certified ISMS and its outputs, including records of nonconformities and corrective actions, are reviewed at each internal audit and external certification audit cycle. We continue to refine how we identify trends and potential recurrence across similar areas of the ISMS through our ongoing management review process.
Other (Annex A)
We maintain documented policies and procedures that translate applicable Annex A controls into day-to-day operational practice across our organisation. These controls are implemented through a combination of governance processes, technical safeguards, and defined responsibilities, and are formally included within the scope of our certified information security management system. We review the design and operation of our controls on a recurring basis through internal audit and management review, adjusting and refining our approach as part of continual improvement. All controls, including this one, have remained within our certified ISMS and have been examined by our certification body at every surveillance and recertification audit since our initial certification. Supporting records and evidence for this control are maintained and made available for audit purposes as part of our standard ISMS documentation practices.
Organizational controls (Annex A)
Policies for information security
We maintain an information security policy framework, comprising an overarching policy and a set of topic-specific policies, that has been approved by management and is in effect within the scope of our certified ISMS. These policies are communicated to all personnel and made available to relevant interested parties, with acknowledgement obtained as part of our onboarding and ongoing awareness processes. We review our policies at planned intervals, and whenever significant organisational, technological, legal or regulatory changes occur, to ensure they remain aligned with business needs and risk. This policy framework, its approval records, and the associated review cycle are examined by our certification body at every surveillance and recertification audit, and we continue to refine our policies through our management review and internal audit cycle.
Information security roles and responsibilities
We maintain a defined organizational structure for information security that assigns clear ownership for governance, risk management, and operational security activities across relevant roles and functions. Responsibilities are documented within our ISMS governance framework and communicated to those who hold them, ensuring accountability for tasks such as policy approval, risk treatment, incident response, and control operation. We review and refine this allocation of roles periodically through our management review and internal audit cycle to reflect organizational changes and continual improvement. This structure has operated as part of our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.
Segregation of duties
We maintain role definitions and access provisioning practices that separate key conflicting duties, such as the ability to request, approve, and implement changes, or to initiate and authorise transactions and system modifications. Access to critical systems is granted according to defined roles, with privileged functions assigned so that development, operational, and approval responsibilities remain distinct wherever practicable. We periodically review role assignments and access rights as part of our access management and internal audit processes to confirm that segregation remains effective as teams and systems evolve. This control operates within our certified ISMS and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our segregation practices through our management review and internal audit cycle.
Management Responsibilities
We require managers across the business to communicate information security expectations to their teams and to reinforce compliance with our information security policy and supporting topic-specific policies as part of normal line management activity. This includes onboarding briefings, periodic security awareness communications, and performance and conduct processes that hold personnel accountable for following security procedures. Management responsibilities for security are documented within our ISMS roles and responsibilities framework and are reinforced through regular staff communications, training, and manager check-ins. We review the effectiveness of this control through our internal audit programme and management review process, and it has operated within our certified ISMS since our initial certification, with continual refinement through successive audit cycles.
Contact with Authorities
We maintain documented procedures identifying the relevant legal, regulatory, and supervisory authorities applicable to our operations, including law enforcement, data protection regulators, and sector-specific bodies. Designated roles within our organization are responsible for maintaining these relationships and ensuring timely, appropriate communication when circumstances require it, such as during incident response or regulatory inquiries. This process is integrated into our incident management and legal compliance procedures, ensuring authorities are engaged consistently with our obligations. As part of our certified ISMS, this control is reviewed through our internal audit and management review cycle, and its operation has been examined by our certification body at every surveillance and recertification audit since our initial certification. We continue to refine our authority contact lists and engagement procedures to reflect any changes in our regulatory environment or business operations.
Contact with Sspecial interest groups
We maintain ongoing engagement with relevant security special interest groups, professional associations, and industry forums as part of our information security programme. This engagement supports our threat awareness and horizon-scanning activities, feeding relevant intelligence and practice updates into our risk assessment and security planning processes. Membership and participation channels are reviewed periodically to ensure they remain relevant to our operating environment and threat landscape. This control operates within the scope of our certified ISMS and is reviewed as part of our management review and internal audit cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature how we capture and act on external intelligence gained through these channels.
Threat Intelligence
We operate a threat intelligence process that draws on multiple external and internal sources, including vendor and industry advisories, vulnerability feeds, and alerts from our security tooling, to identify threats relevant to our technology stack and operating context. This information is reviewed and assessed by responsible security personnel who determine relevance and any required mitigation, such as patching priorities, configuration changes, or awareness communications. Outputs from threat intelligence feed into our broader risk management, vulnerability management, and incident response processes so that mitigations are tracked to completion. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at each audit since our initial certification. We continue to mature our sourcing and analysis practices as part of our ongoing continual improvement process.
Information security in project management
We integrate information security requirements into our standard project management approach so that security is considered from initiation through delivery and closure of projects, including those involving new systems, products, or significant changes. Our project management practices require identification and assessment of information security risks relevant to project objectives and deliverables, with appropriate controls and responsibilities assigned as part of project planning. Security requirements are reviewed at key project milestones and incorporated into acceptance criteria before deliverables are finalised. This practice operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature how project-related security risks are documented and tracked as part of our continual improvement process.
Inventory of information and other associated assets
We maintain an inventory of information and other associated assets that supports our information security management system, covering the systems, data repositories and other assets relevant to our services. Each asset category is assigned an owner accountable for its appropriate handling, classification and protection. We review and update this inventory through our regular asset management and change control processes, ensuring it reflects our current operating environment. The inventory and its ownership assignments are examined by our certification body as part of every surveillance and recertification audit, and we continue to refine the process through our internal audit and management review cycle.
Acceptable use of information and other associated assets
We maintain a documented acceptable use policy that defines permitted and prohibited use of information, systems, and other assets, along with handling requirements aligned to our information classification scheme. This policy is communicated to all personnel as part of onboarding and ongoing security awareness activities, and acknowledgement is tracked as part of our ISMS records. Handling procedures cover matters such as secure storage, transmission, and disposal of information based on its classification level. We review and update these rules periodically through our management review and internal audit cycle to ensure they remain effective as our environment and asset inventory evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.
Return of assets
We maintain a formal offboarding and role-change process, integrated with our HR and IT service management workflows, that triggers asset return and access revocation whenever employment, contractor, or third-party agreements change or end. This includes recovery of laptops, mobile devices, access badges, and any physical or electronic media, along with de-provisioning of accounts and system access through our identity provider and endpoint management platform. Managers and IT complete a checklist confirming all assigned assets have been returned before final offboarding is closed out. This process has operated consistently since our initial certification and is reviewed periodically through internal audits and management review to ensure it remains effective as our asset inventory and workforce arrangements evolve. The control operates within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit.
Classification of information
We maintain a formal information classification scheme that defines categories of sensitivity based on confidentiality, integrity, and availability requirements, along with guidance for how each category should be labelled, handled, stored, and shared. This scheme is documented within our ISMS and is communicated to personnel through onboarding and ongoing security awareness activities. Classification decisions are applied to information assets as part of our broader asset management and handling procedures, and we periodically review the scheme to ensure it continues to reflect our operational and regulatory context. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit. We continue to mature our classification practices through our internal audit and management review cycle.
Labelling of information
We maintain an information labelling procedure aligned with our information classification scheme, covering both electronic and, where relevant, physical information assets. Labelling conventions are applied consistently across documents, messages and systems so that classification is visible to staff and, where feasible, enforced or supported through automated tagging in our productivity and information management platforms. Employees are trained on the classification scheme and associated labelling expectations as part of our security awareness programme. We review the labelling procedure and its application periodically through our internal audit and management review cycle to ensure it continues to reflect how information is created, shared and stored, and we refine it as our technology and business needs evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Information transfer
We maintain documented information transfer policies and procedures that define acceptable methods, protections, and approval requirements for sharing information internally and with external parties. These cover electronic transfers, such as email and file-sharing platforms, as well as physical media and verbal disclosures, and require appropriate safeguards such as encryption, access controls, and confidentiality or data-sharing agreements where relevant. We govern transfers with third parties through contractual terms that set expectations for secure handling of shared information. Our internal audit and management review cycle regularly assesses these controls to confirm they remain effective and appropriate as our transfer methods and partnerships evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit.
Access control
We maintain a formal access control policy that defines how access to systems, applications, and physical facilities is granted, reviewed, and revoked based on role and business need. Access provisioning follows a least-privilege and need-to-know model, with approvals required before rights are granted and periodic reviews to confirm continued appropriateness. Technical enforcement is achieved through our identity provider and endpoint management platform, including role-based access groups, authentication controls, and logging of access-related changes. Physical access to relevant facilities is similarly controlled through defined authorisation and monitoring procedures. These controls have operated within our certified ISMS since our initial certification and are reviewed through our internal audit and management review cycle, and examined by our certification body at every surveillance and recertification audit.
Identity Management
We maintain a formal identity management process covering the creation, modification, and timely deactivation of user and system accounts across our environment, tied to events such as onboarding, role changes, and offboarding. Identities are provisioned through our identity provider with unique identifiers assigned to individuals and systems to prevent shared or ambiguous credentials. We operate defined procedures for verifying identity requests, assigning access rights consistent with role requirements, and promptly disabling accounts that are no longer needed. This process is periodically reviewed as part of our internal audit and management review cycle, and we continue to refine identity governance practices as our environment evolves. This control operates within our certified ISMS and is examined by our certification body at every audit.
Authentication information
We maintain a formal process for the issuance, storage, and revocation of authentication information such as passwords and access credentials, covering onboarding, role changes, and offboarding. Authentication secrets are provisioned through our identity provider and endpoint management platform, with technical controls enforcing password complexity, secure storage, and protection against unauthorized disclosure. Personnel receive guidance on the appropriate handling of authentication information, including prohibitions on sharing or insecure storage, as part of our security awareness programme. We review and refine this process through periodic access reviews, internal audits, and management review to ensure it continues to operate effectively. This control has remained within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021.
Access Rights
We operate documented access control procedures that govern how access rights are requested, approved, granted, changed and revoked across our information systems and associated assets. Access provisioning is tied to defined business need and role-based authorisation, with removal or modification triggered promptly upon role change or termination through our joiner-mover-leaver processes. We periodically review user access rights, including privileged access, to confirm they remain appropriate and aligned with our access control policy. These controls have operated within our certified ISMS since our initial 2021 certification and are examined by our certification body at every surveillance and recertification audit, and we continue to refine review cadence and evidencing through our management review and internal audit cycle.
Information security in supplier relationships
We maintain a supplier risk management process that is part of our certified ISMS, covering supplier identification, risk-based due diligence, contractual security requirements, and ongoing monitoring through the relationship lifecycle. New suppliers are assessed for the sensitivity of the data or access they will handle, and relevant security obligations are captured in agreements before onboarding. We periodically review supplier performance and re-assess risk as relationships evolve, with changes managed through defined change and offboarding procedures. This process, and its operating effectiveness, is reviewed through our internal audit programme and management review, and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our supplier evaluation criteria and monitoring approach as part of our regular continual improvement cycle.
Addressing information security within supplier agreements
We maintain a supplier management process that identifies the type of relationship and associated risk before agreeing information security terms with each supplier or vendor. Security requirements, such as confidentiality obligations, access restrictions, and incident reporting expectations, are incorporated into supplier agreements as appropriate to the service provided. This process operates within our certified ISMS and has been in place since our initial certification, with supplier terms reviewed and refined through our periodic management review and internal audit cycle. Our approach ensures consistent treatment of security obligations across supplier types, scaled proportionately to the risk each relationship presents. This control is examined by our certification body at every audit as part of our ongoing conformance to ISO/IEC 27001:2022.
Managing information security in the ICT supply chain
We maintain defined processes for evaluating and managing information security risk across our ICT supply chain, applied consistently to vendors and service providers who deliver technology products, platforms, or services into our environment. Our supplier onboarding and contracting practices incorporate security requirements appropriate to the nature of the product or service, and we assess supplier risk as part of our supplier relationship management process. These processes have operated continuously within our certified ISMS since our initial 2021 certification and are reviewed through our internal audit programme and management review cycle. We continue to refine our ICT supply chain risk criteria and monitoring approach as our supplier landscape evolves, ensuring the control remains effective and proportionate. This control is included within the scope examined by our certification body at each surveillance and recertification audit.
Monitoring, review and change management of supplier services
We maintain a supplier management process that includes ongoing monitoring and periodic review of supplier security performance and service delivery against agreed requirements. Supplier relationships are assessed on a risk-based schedule, with reviews covering service levels, security incidents, audit reports or certifications, and any material changes to the supplier's operating environment. Where a supplier proposes or makes a significant change, such as to subcontractors, technology or processing locations, we evaluate the potential security impact before accepting the change. This process operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body across successive audits since our initial certification. We continue to mature our supplier oversight practices as part of this continual improvement cycle.
Information security for use of cloud services
We maintain a defined process for evaluating, onboarding and managing cloud service providers as part of our certified ISMS, incorporating information security requirements into supplier selection, contractual agreements and ongoing service reviews. Cloud services are assessed against our risk management and supplier security criteria before adoption, with responsibilities for configuration, access control and data protection clearly assigned between us and the provider. We monitor the use of cloud services on an ongoing basis through our operational security processes and periodically review provider performance and risk posture. Where a cloud service is retired or replaced, we follow a controlled exit process to protect the confidentiality and integrity of our data during transition. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Information security incident management planning and preparation
We maintain a documented information security incident management process that defines roles, responsibilities and escalation paths for identifying, triaging, and responding to security events. This process, including communication procedures for reporting and escalating incidents internally and to relevant stakeholders, has operated within our certified ISMS since our initial certification. Staff with incident response responsibilities understand their duties through defined procedures and periodic awareness activities, and the process is reviewed and refined through our internal audit and management review cycle to ensure it remains effective and consistent. This control is within the scope of our certified ISMS and is examined by our certification body at every audit.
Assessment and decision on information security events
We maintain a documented event assessment process as part of our certified ISMS, under which reported security events are reviewed by trained personnel against defined criteria to determine severity and whether incident response procedures should be triggered. This process includes clear escalation paths, defined roles and responsibilities, and consistent categorization criteria that align with our incident management procedures. We use logging, monitoring, and alerting tools, including our SIEM platform, to support timely identification and assessment of events. The effectiveness of this process is reviewed through internal audits and management review, and it has operated continuously within our certified ISMS since our initial certification. We continue to refine our assessment criteria and workflows as part of our ongoing continual improvement cycle.
Respone to information security incidents
We maintain a documented incident response procedure that defines roles, escalation paths, and the steps taken to contain, investigate, and remediate information security incidents. This procedure is integrated into our ISMS and is invoked by our security and operations teams whenever a security event is confirmed as an incident, ensuring a consistent and controlled response. We use our SIEM and related monitoring tooling to support detection and response activities, and incidents are tracked through to resolution with appropriate internal communication and, where relevant, notification to affected parties. Our incident response procedure and its execution are reviewed as part of our regular management review and internal audit cycle, and this control has operated within our certified ISMS since our initial certification, being examined by our certification body at every surveillance and recertification audit. We continue to mature our response capability through lessons learned and periodic testing as part of our continual improvement process.
Learning from information security incidents
We operate a post-incident review process that captures root cause analysis, contributing factors, and corrective actions for information security incidents, feeding these findings into updates to our policies, technical controls, and staff awareness activities. Lessons learned are logged and tracked through to resolution, and recurring themes are reviewed as part of our management review and internal audit cycle to ensure improvements are effective and sustained. This feedback loop has operated since our initial certification and continues to mature as we refine how incident insights are recorded, prioritised, and actioned. The process, its outputs, and evidence of resulting control improvements fall within the scope of our certified ISMS and are examined by our certification body at every surveillance and recertification audit.
Collection of evidence
We maintain documented procedures for identifying, collecting and preserving evidence arising from information security events, ensuring a consistent chain of custody from detection through resolution. These procedures define roles and responsibilities for evidence handling, including secure storage and access controls that protect the integrity and confidentiality of collected material. Our incident response process incorporates these evidence-handling steps so that any information relevant to disciplinary, regulatory or legal action is captured and preserved appropriately. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body across successive surveillance and recertification audits since our initial certification. We continue to mature our evidence-handling practices in line with evolving legal and operational requirements.
Information security during disruption
We maintain business continuity and disaster recovery plans that explicitly address how information security controls are sustained during disruptive events, rather than treating continuity and security as separate concerns. These plans identify critical systems and information assets, define fallback and recovery procedures, and specify how access control, logging, and data protection measures remain enforced or are safely reinstated during and after an incident. Roles and responsibilities for invoking and managing continuity arrangements are documented, and the plans are exercised and reviewed periodically as part of our management review and internal audit cycle. This control operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our disruption-readiness procedures through lessons learned from testing and periodic review, reinforcing consistent security posture under all operating conditions.
ICT readiness for business continuity
We maintain ICT continuity arrangements that are aligned with our business continuity objectives, covering the recovery of critical systems, infrastructure and data supporting our services. These arrangements include defined recovery priorities and technical measures such as resilient infrastructure, backups and recovery procedures for key platforms. We test and review these capabilities on a regular cycle, using the results to refine recovery procedures through our management review and internal audit process. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit.
Legal, statutory, regulatory and contractual requirements
We maintain a documented register of the legal, regulatory, statutory and contractual requirements relevant to information security that apply to our organization, covering areas such as data protection, sector-specific regulation, and security commitments made to customers and partners. This register is owned by our compliance and information security function and is reviewed on a periodic basis and whenever significant changes occur in our operations, jurisdictions, or customer contracts, to keep it accurate and current. Identified requirements are mapped to relevant policies, controls and processes within our ISMS so that legal and contractual obligations directly inform our security practices. Compliance with these requirements is monitored through our internal audit programme and management review cycle, and this control has operated within our certified ISMS and been examined by our certification body at every audit since our initial certification. We continue to refine the register and its associated processes as part of our ongoing continual improvement activities.
Intellectual property rights
We maintain policies and procedures governing the use of licensed and proprietary software and materials, ensuring that acquisition, use and disposal of third-party products are conducted in accordance with applicable licence terms and contractual obligations. Our processes cover tracking of software assets and licences to support compliance with vendor and legal requirements, and staff are made aware of their responsibilities regarding intellectual property through our security awareness programme. Compliance with IP-related obligations is considered as part of our regular legal and regulatory compliance reviews, which are integrated into our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every audit, with practices continually refined through ongoing review.
Protection of records
We maintain a records management approach that classifies records according to their retention requirements and applies appropriate storage, access control, and backup measures to protect them from loss, tampering, or unauthorised disclosure throughout their lifecycle. Access to records is restricted based on role and business need, and our systems enforce retention and disposal schedules aligned with legal, regulatory, and contractual obligations. We use secure storage platforms with logging and access controls to detect and prevent unauthorised changes or access, and backups are maintained to protect against data loss. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to mature our records protection practices as part of our ongoing continual improvement process.
Privacy and protection of PII
We maintain a documented process for identifying the privacy and data protection laws, regulations, and contractual commitments applicable to the personal data we handle, and we align our internal policies and procedures to those requirements. Roles and responsibilities for privacy oversight are defined, and personal data handling practices are incorporated into our broader information security controls, including access management, data minimisation, and secure processing. We review applicable legal and regulatory obligations periodically to account for changes in law or in our processing activities, and this review is integrated into our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our privacy practices through ongoing monitoring of the regulatory landscape and continual improvement of our ISMS.
Independent review of information security
We commission independent reviews of our information security management system at planned intervals and following significant organisational or technical changes, using reviewers who are separate from the teams responsible for day-to-day operation of the controls under review. These reviews assess the continuing suitability, adequacy and effectiveness of our security governance, processes and technical safeguards, and their outcomes feed into our management review process alongside internal audit findings. This independent review activity operates within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit. We use the results to continually refine and mature our security programme through our established management review and internal audit cycle.
Compliance with policies, rules and standards for information security
We maintain a program of regular compliance reviews that assess adherence to our information security policy and associated topic-specific policies and standards across the organization. These reviews are carried out through a combination of internal audits, management reviews, and control self-assessments performed by process and asset owners. Findings from these reviews feed into our corrective action process, ensuring that any deviations from policy are tracked and resolved in a controlled manner. This review activity operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our review methods and reporting through our ongoing management review and internal audit cycle.
Documented operating procedures
We maintain a set of documented operating procedures covering the routine administration, configuration and maintenance of our information processing facilities, including areas such as system start-up/shutdown, backup, change handling, and other recurring operational tasks. These procedures are stored in our controlled document management system, version-controlled, and made available to the personnel who need them to perform their duties. Procedure owners review and update the documentation on a periodic basis and whenever significant operational or technical changes occur, and we continue to mature this documentation through our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.
People controls (Annex A)
Screening
We operate a documented pre-employment screening process that verifies identity, employment history, and other relevant checks proportional to the role and the sensitivity of the information or systems it can access, consistent with applicable local laws and regulatory constraints. This screening is applied before personnel join the organisation and is supplemented by ongoing suitability considerations during employment, such as role changes affecting access levels. The process is embedded in our HR onboarding procedures and is part of our certified ISMS, examined by our certification body at each surveillance and recertification audit. We continue to refine screening criteria and thresholds through our management review and internal audit cycle to keep them aligned with evolving risk and regulatory requirements. This control has operated continuously since our initial certification in 2021.
Terms and conditions of employment
Within our certified ISMS, employment agreements for all personnel include defined information security responsibilities alongside general terms and conditions, ensuring these obligations are communicated from the outset of employment. Our human resources onboarding process incorporates review and acknowledgement of these responsibilities as part of standard contractual documentation. We maintain this practice consistently across roles, tailoring specific security duties where relevant to the position held. This control is reviewed as part of our ongoing management review and internal audit programme, and it has remained in place and been examined by our certification body through successive surveillance and recertification audits since our initial certification in 2021. We continue to refine our contractual language and onboarding materials as part of our continual improvement process.
Information security awareness, education and training
We maintain a formal security awareness and training programme covering all personnel and, where relevant, third parties who support our operations. New joiners complete baseline information security training as part of onboarding, and all staff receive periodic refresher training along with updates whenever policies or topic-specific procedures change. Training content addresses role-relevant risks such as phishing, data handling, acceptable use, and incident reporting, and completion is tracked centrally to confirm coverage. We review the programme's effectiveness through management review and internal audit, and we continue to mature the content and delivery methods based on those reviews. This control operates within the scope of our certified ISMS and is examined by our certification body at every audit.
Disciplinary Process
We maintain a formal disciplinary process, set out in our HR and information security policies, that applies to employees and other relevant interested parties who violate information security requirements. This process is communicated as part of onboarding and ongoing security awareness activities so that personnel understand the expectations placed on them and the consequences of non-compliance. Any suspected violation is investigated through a defined process involving relevant management and, where appropriate, HR, ensuring actions taken are proportionate and consistent. This control operates within the scope of our certified ISMS and is reviewed as part of our regular management review and internal audit cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature the process through periodic review of policy communication and case handling.
Responsibilities after termination or change of employment
We maintain documented HR and offboarding/transfer processes that define which information security obligations, such as confidentiality and non-disclosure commitments, continue beyond the end of employment or a change in role. These responsibilities are communicated to personnel through employment agreements, policy acknowledgements, and offboarding checklists, and are reinforced at the point of role change or departure. Our process includes coordinated deactivation of access and return of company assets, aligned with our access control and asset management procedures. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it has been assessed by our certification body at every audit since our initial certification in 2021. We continue to refine supporting documentation and evidence practices as part of our ongoing continual improvement process.
Confidentiality or non-disclosure agreements
We maintain a documented confidentiality/non-disclosure agreement that reflects our information protection requirements and require personnel and relevant third parties, such as contractors and vendors with access to sensitive information, to sign it before being granted access. These agreements are incorporated into our onboarding and vendor/contractor engagement processes and are periodically reviewed to ensure they continue to reflect our business and legal needs. This control has operated within our certified ISMS since our initial certification in 2021 and is reviewed at every successive audit, along with our internal audit and management review cycles, through which we continue to mature the associated processes.
Remote working
We maintain a remote working policy that defines the security expectations and responsibilities for personnel working outside our offices, covering areas such as secure connectivity, device configuration and acceptable use. Remote access to corporate systems and data is provided through managed, authenticated channels, with our endpoint management platform enforcing baseline security controls such as encryption, screen-locking and up-to-date patching on devices used remotely. We require the use of secure network connections, such as VPN or equivalent encrypted access, when personnel connect to company resources from remote locations. This control operates within the scope of our certified ISMS and its effectiveness is reviewed through our internal audit programme and management review cycle, with adjustments made as part of our continual improvement process.
Information security event reporting
We maintain a defined reporting mechanism that allows all employees and contractors to report suspected or observed information security events through established internal channels, including our service desk and direct escalation paths to the security team. Staff are made aware of this mechanism through onboarding and periodic security awareness activities, so they understand what constitutes a reportable event and how to raise it promptly. Reported events are logged, triaged and fed into our incident management process for assessment and response. This mechanism operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review to confirm it remains effective and accessible, with continual refinements made as part of our ongoing improvement cycle.
Physical controls (Annex A)
Phisical security perimeters
We maintain defined physical security perimeters around all locations and areas that house information assets and infrastructure supporting our services, including offices and any data centre or server room space we use. These perimeters are enforced through controlled entry points, physical barriers and layered access zones that separate public, general staff and restricted areas. We have operated this approach since our initial certification, with periodic review of site layouts and perimeter controls as part of our management review and internal audit cycle. Where third-party or co-located facilities are used, we rely on their independently assured physical security perimeters as part of our vendor management process. This control is within the scope of our certified ISMS and is examined by our certification body at every audit.
Physical entry
We maintain physical entry controls at our facilities and secure areas, using access mechanisms such as badges, keys, or electronic credentials to restrict entry to authorised personnel only. Visitor and contractor access is managed through sign-in and escort procedures where appropriate, and access rights are reviewed periodically to ensure they remain aligned with current personnel and business need. These controls have operated since our initial certification and are examined by our certification body at every surveillance and recertification audit as part of our certified ISMS. We continue to mature our physical access processes through regular management review and internal audit activity.
Securing offices, rooms and facilities
We maintain physical security controls across the offices, rooms and facilities within scope of our ISMS, designed to prevent unauthorised access, damage or interference to information and supporting assets. Access to premises and sensitive areas is restricted through controlled entry mechanisms, and facility layouts are designed to segregate and protect areas holding higher-risk assets. We maintain supporting procedures covering visitor handling, secure areas and environmental protections, and these arrangements are reviewed as part of our ongoing risk assessment and management review cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit, with continual refinements made through internal audit and management review.
Physical security monitoring
We maintain continuous physical security monitoring across the premises housing our information processing facilities, using a combination of surveillance and access-control mechanisms to detect and deter unauthorised entry. Monitoring coverage and access logs are reviewed as part of our ongoing physical security management process, and any anomalies are handled through our established incident management procedures. This control has operated within our certified ISMS since our initial certification and is reviewed through our internal audit and management review cycle. It is assessed by our certification body at every surveillance and recertification audit. We continue to mature our monitoring practices as part of our continual improvement process.
Protecting against physical and environmental threats
We have assessed the physical and environmental risks relevant to our operating locations and data processing facilities and have implemented controls proportionate to those risks, including environmental monitoring, fire detection and suppression measures, resilient power arrangements, and siting/facility safeguards appropriate to each location. These measures have operated within our certified ISMS since our initial certification and are maintained through routine facilities management and periodic review. We reassess these risks and controls as part of our management review and internal audit cycle, and we continue to mature our approach to physical and environmental resilience as our operating footprint evolves. This control is included in the scope examined by our certification body at every surveillance and recertification audit.
Working in secure areas
We maintain defined rules for working in our secure areas, covering matters such as supervision of personnel and visitors, restrictions on unsupervised access, controls over recording devices and equipment brought into these areas, and requirements to secure areas when unoccupied. These rules are communicated to relevant staff and contractors and are embedded in our physical and information security policies. We review and test these controls as part of our ongoing internal audit and management review cycle, and we continue to mature our practices based on operational experience and risk assessment outcomes. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every surveillance and recertification audit.
Equipment siting and protection
We site information-processing equipment in controlled locations selected to limit exposure to environmental hazards such as fire, water damage, temperature extremes, and unauthorised physical access. Our physical and environmental security policy defines placement standards, access restrictions, and environmental controls such as power protection and climate management for equipment areas. We review the suitability of equipment locations and associated protections as part of our ongoing risk assessment and physical security management processes. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive surveillance and recertification audits since our initial certification in 2021. We continue to mature our siting and protection practices through our management review and internal audit cycle.
Security of assets off premises
We maintain a policy and set of technical controls governing the use and protection of assets outside our premises, covering laptops, mobile devices and any equipment used remotely or in transit. Devices issued for off-site use are enrolled in our endpoint management platform, which enforces encryption, screen-lock, patching and remote wipe capability, and are protected in line with our acceptable use and mobile device requirements. We require staff to apply physical safeguards such as secure storage, cable locks where appropriate, and not leaving devices unattended in public or high-risk locations, and we maintain asset tracking so that off-site equipment remains accounted for and can be actioned if lost or stolen. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review, with continual refinement of our off-site asset protections as part of our ongoing risk assessment process. The control has been examined by our certification body at every audit since our initial certification.
Storage media
We maintain a storage media handling process aligned with our information classification scheme, covering acquisition, authorized use, secure transport, and controlled disposal or destruction of media. Access to storage media containing sensitive information is restricted to authorized personnel, and media is tracked and secured throughout its operational life. When media reaches end of life, we apply secure destruction or sanitization methods appropriate to the classification of the data it held. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, with continual refinements made as our technology and storage practices evolve.
Supporting utilities
We maintain physical and environmental controls designed to protect our information processing facilities against disruption from utility failures, including safeguards for power supply continuity, environmental conditioning, and monitoring of critical building services. Our facilities are equipped with resilience measures such as backup power arrangements and environmental controls appropriate to the risk profile of the sites housing information processing equipment, and we monitor these systems to detect and respond to abnormal conditions. These measures operate under our documented physical security and business continuity procedures, which define responsibilities for maintenance, testing, and incident response related to supporting utilities. We review the adequacy of these controls through our regular internal audit and management review cycle, and they have been examined as part of our certified ISMS by our certification body at every audit since our initial certification in 2021. Where facilities are provided by third-party data centre or hosting providers, we obtain assurance over their supporting utility controls as part of our supplier management process.
Cabling security
We maintain physical and environmental controls that protect the power and data cabling supporting our facilities and systems from damage, interference, and unauthorised interception. Cabling supporting critical infrastructure is routed and secured in accordance with our physical security standards, with segregation of power and data lines and restricted access to spaces housing cabling infrastructure where applicable. These measures are part of our certified ISMS and are reviewed as part of our ongoing risk assessment, internal audit, and management review processes. We continue to mature our physical security controls, including cabling protections, in line with evolving operational and facility requirements. This control has remained within the scope of our ISO/IEC 27001:2022 certification since our initial certification and is examined by our certification body at every surveillance and recertification audit.
Equipment maintenance
We maintain a physical and environmental security programme that includes scheduled maintenance of equipment supporting our information systems, carried out by authorised personnel or vendors in accordance with manufacturer guidance. Maintenance activities, including servicing, repairs and equipment disposal or reuse, are logged and tracked as part of our asset management processes. Access to equipment for maintenance purposes is controlled and monitored, and any equipment taken off-site for repair is handled under our asset handling and data protection procedures. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management reviews, and is examined by our certification body at each surveillance and recertification audit. We continue to mature our maintenance tracking and evidencing practices as part of our ongoing continual improvement cycle.
Secure disposal or reuse of equipment
We maintain a documented process for the secure disposal and reuse of equipment containing storage media, covering laptops, servers, and other devices that may hold sensitive information. Before any device is retired, transferred, or reused, storage media are verified to ensure data and licensed software have been securely erased or destroyed using approved methods appropriate to the media type. Verification steps confirm sanitisation is complete before equipment is released for reuse or disposal, and records of this process are retained as evidence. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it is examined by our certification body at every surveillance and recertification audit.
Technological controls (Annex A)
User and point devices
We maintain an endpoint security policy and supporting technical baseline that applies to all user devices with access to company or customer information, covering configuration hardening, disk encryption, screen locking, malware protection and patching. Devices are managed through our endpoint management platform, which enforces these controls centrally and allows us to monitor compliance and remotely respond where a device is lost, stolen or found non-compliant. Access to corporate systems from endpoints is further controlled through our identity provider, including multi-factor authentication and conditional access based on device health. This control has operated within our certified ISMS since our initial certification, and its design and operating effectiveness are reviewed through periodic internal audit, management review and continual improvement of our technical baselines as new device types and threats emerge.
Privileged access rights
We maintain a formal privileged access management process that governs how elevated access rights are requested, approved, granted and periodically reviewed across our systems and services. Privileged accounts are provisioned separately from standard user accounts, restricted to authorised personnel and services with a defined operational need, and are subject to enhanced authentication and monitoring controls. We periodically review privileged access assignments to confirm they remain appropriate and revoke rights promptly when they are no longer required. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive annual audits since our initial certification in 2021, and we continue to mature our review and monitoring practices through our management review and internal audit cycle.
Information access restriction
We restrict access to information and systems according to our documented access control policy, applying role-based and need-to-know principles across applications, file stores, and infrastructure. Access rights are provisioned and revoked through defined onboarding, transfer, and offboarding procedures, with permissions enforced through our identity provider and supporting technical access controls such as group- and role-based permissions. We periodically review user access and privileged entitlements to confirm they remain appropriate to current job responsibilities, and adjust configurations as our environment evolves. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit, and we continue to mature our access review processes through our management review and internal audit cycle.
Secure authentication
We have implemented secure authentication mechanisms, including multi-factor authentication, across systems, applications and services in accordance with our topic-specific access control policy. Authentication requirements are risk-based, so higher-sensitivity systems and privileged access are protected with stronger controls, such as MFA and conditional access enforced through our identity provider. Password and credential handling follow secure configuration standards, including complexity, storage and rotation requirements aligned with good practice. We monitor authentication events through our SIEM and access management tooling to detect anomalous login activity, and we review the effectiveness of these controls as part of our ongoing internal audit and management review cycle. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Capacity management
We monitor utilisation of key infrastructure and processing resources, including compute, storage, and network capacity, using automated monitoring and alerting tools integrated with our operational and SIEM platforms. Capacity thresholds and growth trends are reviewed periodically by the relevant technical and management teams, who adjust resourcing, scaling, or staffing plans in line with current and forecast demand. This extends beyond technology to cover workforce and facilities planning, ensuring that operational teams have adequate resources to support business and security commitments. These practices operate within the scope of our certified ISMS and are reviewed as part of our ongoing internal audit and management review cycle, and have been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our capacity monitoring and forecasting practices as part of continual improvement.
Protection against Malware
We deploy anti-malware and endpoint protection technology across our estate, configured to automatically update signatures/detection logic and to actively scan and block malicious content in real time. Devices are managed through our endpoint management platform, which enforces protection status and alerts our security team to anomalies for investigation. We reinforce these technical controls with regular user security awareness activities covering phishing, safe browsing, and safe handling of attachments and removable media. The effectiveness of these controls is reviewed as part of our ongoing internal audit and management review cycle, and this control operates within the scope of our ISO/IEC 27001:2022 certified ISMS, which has been maintained since 2021 and is independently examined by our certification body at every audit.
Management of technical vulnerabilities
We operate a continuous technical vulnerability management process that includes regular scanning of infrastructure, applications and endpoints, together with monitoring of vendor and industry vulnerability advisories relevant to our technology stack. Identified vulnerabilities are assessed for risk and exploitability and tracked through to remediation within defined timeframes based on severity, using patch management and configuration controls across our endpoint management and infrastructure platforms. Our process assigns clear ownership for triage, remediation and verification, and remediation activity is evidenced and reviewed as part of our internal audit and management review cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our tooling and processes through that ongoing review.
Configuration management
We maintain documented baseline configuration standards for the hardware, operating systems, applications, services, and network devices within scope of our ISMS, reflecting security hardening principles appropriate to each asset type. These baselines are applied through standardised build and deployment processes, and configuration state is monitored using our endpoint management and infrastructure tooling to detect drift or unauthorized changes. Any changes to established configurations are managed through our formal change management process, which requires review and approval before implementation. We periodically review configuration standards and monitoring outcomes as part of our internal audit and management review cycle, refining them to reflect evolving threats and technology changes. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.
Information deletion
We maintain a documented approach to information deletion that governs how data is removed from systems, devices, and storage media once retention periods or business need have expired. This includes defined retention criteria aligned to legal, regulatory, and contractual requirements, and secure deletion or destruction methods applied to both digital records and physical or decommissioned media. Deletion practices are embedded in our data lifecycle and asset disposal processes, and are reviewed as part of our ongoing internal audit and management review cycle. This control has operated within our certified ISMS since our initial ISO/IEC 27001:2022 certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine our deletion procedures to reflect changes in systems, storage technologies, and applicable regulatory requirements.
Data masking
We apply data masking and related data-minimisation techniques to sensitive data, including personal data, based on business requirements and the sensitivity classification defined in our topic-specific access control and data protection policies. These controls are applied consistently across environments such as non-production systems, analytics and support access, so that individuals and processes only see the level of detail necessary for their role. Our approach considers applicable legal, statutory, regulatory and contractual obligations relevant to the data being protected. This control operates within our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature our masking techniques and their application scope as part of our continual improvement process.
Data leakage prevention
We maintain data leakage prevention measures across the systems, networks, and endpoints that handle sensitive information within the scope of our certified ISMS, using a combination of technical controls, access restrictions, and monitoring to detect and prevent unauthorised disclosure or extraction of data. These measures are integrated with our broader security tooling, including endpoint management and monitoring platforms, and are aligned with our data classification and handling policies. We review the effectiveness and coverage of these controls as part of our ongoing risk assessment, internal audit, and management review cycle, and we continue to mature our approach as the organisation's technology estate and data flows evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at each surveillance and recertification audit.
Information back up
We maintain a topic-specific backup policy that defines what information and systems are backed up, the frequency of backups, retention periods, and storage arrangements, including safeguards to protect backup data from loss or unauthorised access. Backups are performed on a scheduled basis and monitored to confirm successful completion. We periodically test restoration processes to verify that data and systems can be recovered effectively, and we review our backup approach as part of our ongoing risk management and management review cycle. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive audits since our initial certification in 2021. We continue to refine backup coverage and testing practices as part of our continual improvement process.
Redundancy of information processing facilities
We design and operate our information processing facilities with redundancy commensurate with the availability requirements of the services they support, including resilient infrastructure and failover mechanisms for critical systems. Our approach to redundancy is informed by risk assessment and business impact considerations, and is reviewed as part of our ongoing ISMS operation. We maintain documented architecture and operational practices covering redundant components, and we periodically review and test resilience measures to confirm they continue to meet availability needs. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. We continue to mature our redundancy practices through our management review and internal audit cycle.
Logging
We generate logs across critical systems, infrastructure, and applications to capture security-relevant events, exceptions, and operational faults. Log data is centralized and protected through access controls and retention settings that guard against unauthorized modification or deletion, preserving the integrity of records used for monitoring and investigation. Our logging configuration and retention practices are reviewed periodically as part of our internal audit and management review cycle to ensure continued alignment with operational and security needs. This control has operated within our certified ISMS since our initial 2021 certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our logging and monitoring capabilities through ongoing risk assessment and technology improvements.
Monitoring activities
We maintain continuous monitoring of our networks, systems and applications using centralised logging and a security information and event management (SIEM) capability that aggregates and correlates activity across the environment. Defined detection rules and alerting thresholds are used to identify anomalous behaviour, with alerts triaged by our security team and escalated through our incident management process where warranted. Monitoring coverage, alert tuning and detection logic are reviewed periodically as part of our management review and internal audit cycle, allowing us to continue to mature detection effectiveness over time. This control operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021.
Clock synchronization
We maintain synchronized time across our information processing systems by configuring them to reference approved and consistent time sources. This practice supports accurate and comparable timestamps across logs and system events, which is essential for effective monitoring, correlation of security-related activity, and incident investigation when required. Clock synchronization is applied consistently across the infrastructure within the scope of our certified ISMS. This control has operated since our initial certification and continues to be reviewed as part of our ongoing internal audit and management review cycle to ensure it remains effective as our systems evolve.
Use of privileged utility programs
We maintain an inventory and access control regime for utility programs capable of overriding system or application controls, ensuring their use is restricted to authorised, appropriately privileged personnel. Access to such tools is granted through our formal access management process, is subject to segregation of duties considerations, and is removed promptly when no longer required. We monitor and log the use of privileged utilities as part of our broader logging and monitoring controls, and we periodically review installed utilities and associated permissions to confirm they remain appropriate. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit.
Installation of software on operational systems
We maintain a documented software installation and change process for operational systems that restricts installation rights to authorised personnel and requires approvals before deployment. Software packages and updates are sourced from trusted, verified sources and are tested prior to installation on production systems, with rollback options preserved where applicable. Administrative and installation privileges on operational systems are controlled through our access management and endpoint management platform, limiting the ability to introduce unauthorised software. We periodically review installed software and installation logs as part of our internal audit and management review cycle to confirm ongoing compliance, and we continue to mature the associated tooling and monitoring through this cycle. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Network security
We maintain a network security policy and supporting technical architecture that defines how our networks are segmented, monitored and controlled to protect information in transit and the systems that process it. Network devices are configured and managed under change control, with access restricted to authorised administrators and traffic filtered through firewalls and access control lists aligned to defined security zones. We use monitoring tools, including our SIEM, to detect anomalous or unauthorised network activity, and network configurations are reviewed periodically as part of our internal audit and management review cycle. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every surveillance and recertification audit. We continue to mature our network security controls through ongoing risk assessment and technology review.
Security of network services
We maintain an inventory of the network services used across our environment, documenting the security mechanisms, service levels, and usage requirements expected of each, including those provided by external network and connectivity vendors. Security requirements such as encryption, access control, authentication, and availability targets are defined and, where applicable, incorporated into service agreements with providers. We monitor network service performance and security posture on an ongoing basis using our network monitoring and SIEM tooling, with alerts and periodic reviews feeding into our operational security processes. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to mature our monitoring and service-level oversight as our network architecture evolves.
Segregation of networks
We maintain a segmented network architecture that separates groups of systems, users and services into defined security zones based on business function and risk sensitivity. Traffic between these zones is controlled through firewall and routing policies that permit only the connections required for legitimate business purposes, following a least-privilege approach to network access. This segmentation design is reviewed periodically as part of our ongoing risk management and infrastructure change processes to ensure it continues to reflect our operating environment. This control operates within the scope of our certified ISMS and has been assessed by our certification body across successive annual audits. We continue to mature our network segmentation practices through our management review and internal audit cycle.
Web filtering
We operate web filtering controls across our environment to restrict access to malicious, high-risk, and unauthorized website categories, reducing the likelihood of malware infection or exposure to phishing and other web-based threats. These controls are applied through our endpoint management and network security tooling and are configured according to our internal security policies governing acceptable use and safe browsing. We periodically review and refine the filtering rules and categories to keep pace with the evolving threat landscape and business needs, as part of our ongoing security operations. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit, alongside our other technological controls.
Use of cryptography
We maintain a documented cryptography policy that sets out the approved algorithms, protocols and use cases for protecting data at rest and in transit, aligned with our risk assessment and applicable legal and contractual requirements. Cryptographic key management, including generation, storage, rotation, access control and retirement of keys, is governed by defined procedures and supported by our technical platforms and key management tooling. These controls have operated within our certified ISMS since our initial certification and are reviewed periodically through internal audit and management review to ensure they remain effective as technology and business needs evolve. We continue to mature our cryptography standards in line with industry practice and evolving regulatory expectations. This control, along with its supporting evidence, is examined by our independent certification body at every surveillance and recertification audit.
Application security requirements
We maintain a documented process for identifying and approving information security requirements as part of our application development and acquisition activities, ensuring security considerations are addressed from the earliest stages of design or vendor selection. Requirements such as authentication, access control, data protection and secure configuration are defined and reviewed prior to development or procurement decisions being finalised. This process is embedded within our software development lifecycle and vendor evaluation procedures, and is subject to periodic review as part of our ISMS governance activities. As with all controls in our Annex A Statement of Applicability, this practice has operated within our certified ISMS since our initial certification and is examined by our certification body at each surveillance and recertification audit. We continue to mature our application security requirements process through ongoing management review and internal audit findings, refining criteria and documentation practices to reflect evolving development and procurement activities.
Change management
We maintain a documented change management process covering changes to information systems and processing facilities, requiring appropriate risk assessment, testing and authorisation prior to deployment. Changes are logged and tracked through a controlled workflow, with defined approval gates commensurate with the significance and risk of the change, and separation between development, testing and production activities where applicable. We review the effectiveness of this process through our internal audit programme and management review, refining procedures as our environment and tooling evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.
Test information
We maintain a documented approach to selecting and handling test information that ensures test environments and datasets are appropriate for their purpose while protecting sensitive or operational data. Where information derived from production systems is used for testing, we apply controls such as data minimisation, sanitisation, or restricted access to limit exposure. Access to test environments and test data is governed by the same access management and change control processes that apply across our ISMS. This control operates within the scope of our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, through which we continue to mature our practices for handling test information.
Protection of information systems during audit testing
We maintain a documented process for planning and authorising audit testing and other technical assurance activities that touch operational systems, including internal audits, vulnerability assessments, and independent security testing. Before any such activity takes place, scope, timing, and access requirements are agreed with the relevant system or business owners to prevent adverse impact on production services. Testing is conducted using controlled access, monitored execution, and, where appropriate, non-production or replica environments to limit risk to live data and services. This process operates within our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to refine our approach to testing coordination and risk management as part of our continual improvement practice.
Reporting a security concern
If you believe you have found a vulnerability or a security issue involving our services, please e-mail tony.aiello@obix.com. We acknowledge reports promptly and keep reporters informed.