CCSI — Security & Compliance

How we protect the information our customers entrust to us.

Certification
ISO/IEC 27001:2022
Certified since 2021
Requirements described
127
41 management-system clauses · 86 Annex A controls

Scope of certification

The ISMS applies to CCSI IT Operations, Product Development, Customer Support and solutions covering functional areas that support its growth, security, and operations.

Our approach

Our information security management system (ISMS) is independently certified to ISO/IEC 27001:2022 and has been since 2021. The sections below describe, requirement by requirement, what the standard asks of us and how we meet it. They are written for customers and partners; internal documents, records and evidence are reviewed by our certification auditors and are not published.

We do not release our policies, procedures, standards or internal records to third parties, including under NDA; they are our intellectual property. Our ISMS is independently certified to ISO/IEC 27001:2022, and we can provide the certificate and the statement of certification scope as evidence. Where a customer needs more, we can answer specific questions or walk through our practice in a call.

Context of the organization

Clause 4

Context of the organization

Clause 4 of ISO/IEC 27001:2022 requires an organization to identify the external and internal issues, along with the needs and expectations of interested parties, that shape what the information security management system (ISMS) needs to achieve and the boundaries within which it operates. In practice this means understanding the business, legal, regulatory, competitive and stakeholder context so the ISMS scope and objectives remain relevant and effective. It underpins how the rest of the management system is scoped, resourced and prioritised.

We maintain a documented process for identifying and reviewing the external and internal issues relevant to our business and to the effectiveness of our ISMS, including regulatory, market, technological and organizational factors, alongside the needs and expectations of interested parties such as customers, regulators and employees. This analysis directly informs our defined ISMS scope, risk assessment criteria and security objectives, which are reviewed and updated on a regular cycle. Ownership of this context review sits with senior management and information security leadership as part of our management review process, ensuring the ISMS continues to reflect changes in our operating environment. We continue to mature this analysis over time through our internal audit and management review cycle, incorporating feedback from audits, risk assessments and stakeholder input. This process operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Clause 4.1

Understanding the organization and its context

Clause 4.1 requires an organization to identify the external and internal issues that shape its business context and that could affect its ability to achieve the intended outcomes of its information security management system. This includes factors such as the regulatory, competitive, technological, and market environment as well as internal culture, governance, and capabilities. This context forms the foundation for scoping and risk decisions made throughout the ISMS.

We maintain a documented process for identifying and reviewing the external and internal issues relevant to our organization and our information security management system, captured in our Understanding the Organization and Its Context policy. This analysis considers factors such as the regulatory and legal landscape, market and competitive pressures, technology trends, and internal factors including organizational structure, culture, and resource capabilities. Our leadership and ISMS governance team review this context as part of our periodic management review cycle, ensuring it continues to inform risk assessment, scope definition, and strategic security priorities. This determination has been maintained and refined since our initial certification and is examined by our certification body at every audit as part of the overall ISMS evaluation. We continue to mature this analysis to reflect evolving business conditions and stakeholder expectations.

Clause 4.2

Understanding the needs and expectations of interested parties

Clause 4.2 of ISO/IEC 27001:2022 requires an organisation to identify the interested parties relevant to its information security management system—such as customers, regulators, employees, and business partners—and to determine which of their expectations, legal obligations, and contractual requirements the ISMS must address. It ensures the security programme is shaped by real stakeholder and compliance needs rather than operating in isolation.

We maintain a documented process, set out in our Interested Parties & Security Requirements policy, for identifying the parties relevant to our ISMS, including customers, regulators, suppliers, employees, and shareholders, and for capturing their applicable legal, regulatory, and contractual security requirements. This register is reviewed and updated as part of our periodic management review and risk assessment cycle, ensuring new obligations—such as customer contractual clauses or regulatory changes—are incorporated into the scope and controls of the ISMS. The output of this process directly informs our risk treatment plan and Statement of Applicability, so that identified requirements are traceable to specific controls. This practice operates continuously and is examined by our certification body at every surveillance and recertification audit, and we continue to refine it through our internal audit and management review processes.

Clause 4.3

Determining the scope of the information security management system

Clause 4.3 requires an organization to clearly define the boundaries and applicability of its information security management system, taking into account external and internal context, the needs and expectations of interested parties, and the interfaces and dependencies with services or activities performed by other parties. The resulting scope must be documented and kept available. This ensures customers and auditors understand precisely what the ISMS covers.

We maintain a formally documented ISMS scope statement that defines the boundaries of our information security management system, including the organizational units, locations, services and technology environments covered. This scope was established with reference to our internal and external context and the requirements of interested parties, including customers, regulators and partners, and it explicitly accounts for dependencies on third parties and outsourced services. The scope document is retained as controlled documentation and is reviewed as part of our periodic management review and internal audit cycle to ensure it remains accurate as our business and service offerings evolve. This scope has been in place and examined by our certification body at every audit since our initial certification, and we continue to refine its wording and boundary definitions through our continual improvement process.

Clause 4.4

Information security management system

Clause 4.4 sets the foundational expectation that an organisation establish, operate and continually improve an information security management system (ISMS) as an integrated set of processes, rather than a collection of standalone controls. It requires that the various ISMS processes and their interactions are defined and managed coherently so that information security objectives are consistently achieved across the organisation.

We maintain a documented ISMS, described in our ISMS Overview Document, that defines the scope, processes and interactions required to manage information security across the organisation. This framework has operated as an integrated management system since our initial certification, encompassing risk management, policy governance, control implementation, internal audit and management review. We continually improve the ISMS through regular management review, internal audit findings and monitoring of security objectives, ensuring the processes remain effective and aligned with organisational context and stakeholder requirements. The overall ISMS, including how its processes interact, is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Leadership

Clause 5

Leadership

Clause 5 (Leadership) requires that top management actively directs and supports the information security management system rather than delegating it entirely, ensuring the ISMS policy and objectives align with the organisation's strategic direction. It calls for senior leaders to make sure adequate resources are available, roles and responsibilities are assigned, and information security is integrated into business processes and decision-making. In practice, this means demonstrable, visible commitment from the top rather than a policy that exists only on paper.

Our executive leadership sets and periodically reviews the information security policy and objectives, ensuring they remain aligned with business strategy and risk appetite. Senior management allocates the budget, staffing and tools needed to operate the ISMS and has assigned clear ownership for security roles and responsibilities across the organisation. Leadership commitment is evidenced through regular management review meetings, where security performance, risks and improvement actions are discussed and directed, and through visible sponsorship of security initiatives communicated to staff. This leadership engagement has been maintained since our initial certification and is examined by our certification body at every surveillance and recertification audit as part of the certified ISMS scope. We continue to mature how leadership involvement is documented and communicated through our ongoing management review and internal audit cycle.

Clause 5.1

Leadership and commitment

Clause 5.1 (Leadership and Commitment) requires top management to actively own the information security management system rather than delegate it entirely, ensuring the security policy and objectives align with business strategy, that security is embedded into normal business processes, and that adequate resources, communication, and support exist to make the ISMS effective. It also expects senior leaders to promote a culture of continual improvement and to encourage other managers to demonstrate similar ownership within their own areas.

Our executive leadership team maintains formal accountability for the ISMS, evidenced through an approved leadership commitment statement that ties information security objectives to our overall business strategy. Leadership involvement is embedded into our governance routines, including resourcing decisions, management review meetings, and internal communications that reinforce the importance of information security across the organisation. We ensure security requirements are integrated into core business and operational processes rather than treated as a separate function, and management actively supports staff and process owners in contributing to the ISMS's effectiveness. Senior leaders also promote continual improvement, using outcomes from internal audits and management reviews to refine governance practices over time. This leadership commitment has been demonstrated consistently within our certified ISMS since our initial certification and is reviewed by our certification body at every surveillance and recertification audit.

Clause 5.2

Policy

Clause 5.2 (Policy) requires top management to establish an information security policy that fits the organisation's purpose, sets or frames measurable security objectives, and commits the organisation to meeting applicable security requirements and to continually improving the management system. The policy must also be documented, communicated to staff, and made available to relevant external parties as needed.

We maintain a top-management-approved information security policy that is appropriate to our business, sets the direction for our security objectives, and commits us to meeting applicable legal, regulatory and contractual security requirements as well as to continually improving our ISMS. The policy is formally documented and version-controlled, and is communicated to all employees and relevant third parties as part of our onboarding and ongoing awareness processes. We make the policy available to customers and other interested parties upon reasonable request. This policy and its supporting framework are reviewed at planned intervals through our management review process and have been examined by our certification body at every surveillance and recertification audit since our initial certification.

Clause 5.3

Organizational roles responsibilities and authorities

Clause 5.3 requires top management to define and assign the key information security roles, responsibilities and authorities within the organisation, and to make sure these are clearly communicated so people understand what is expected of them. It specifically calls for someone to be accountable for ensuring the ISMS conforms to ISO/IEC 27001 and for reporting on its performance back to leadership.

We maintain a documented allocation of information security roles, responsibilities and authorities as part of our ISMS governance framework, covering ownership of the management system, control operation, and reporting lines into top management. Designated individuals hold accountability for ensuring ongoing conformance with ISO/IEC 27001 and for presenting ISMS performance, audit results and risk status to top management through our management review process. These assignments are communicated through role descriptions, onboarding, and internal governance documentation, and are reviewed periodically to reflect organisational changes. This structure has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit as part of the certified ISMS scope.

Planning

Clause 6

Planning

Clause 6 (Planning) requires an organisation to translate its understanding of internal and external context and interested party requirements into a structured plan for addressing information security risks and opportunities. This includes a documented approach to risk assessment and risk treatment, and the setting of measurable information security objectives that are consistent with the organisation's strategic direction. It also requires that any changes to the ISMS be carried out in a planned, controlled manner rather than reactively.

We maintain a documented risk assessment and risk treatment methodology that is applied consistently across the organisation and is reviewed as part of our annual ISMS planning cycle. Our information security objectives are defined at a management level, linked to identified risks and opportunities, and tracked for progress through management review. Changes affecting the scope, architecture, or operation of the ISMS are assessed for risk impact and planned through our change management process before implementation. This planning approach, including our risk register and objectives, sits within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit. We continue to refine our risk criteria and objective-setting process through our ongoing management review and internal audit cycle.

Clause 6.1

Actions to address risks and opportunities

Clause 6.1 requires an organization to systematically identify risks and opportunities relevant to its information security management system and to plan actions that ensure the ISMS achieves its intended outcomes, minimizes undesired effects, and drives continual improvement. This includes determining how those actions will be embedded into everyday ISMS processes and how their effectiveness will be evaluated over time.

We maintain a documented ISMS Risk Management Policy that governs how information security risks and opportunities are identified, assessed, treated, and monitored across the organization. Risk assessments are performed on a recurring basis and are integrated into our broader ISMS planning and operational processes, ensuring that risk treatment actions are actioned by accountable owners and tracked to completion. The effectiveness of these actions is reviewed through our management review and internal audit cycle, allowing us to continually refine our risk criteria, methodology, and treatment plans. This risk management approach has operated within our certified ISMS since our initial certification and is independently examined by our certification body at every surveillance and recertification audit.

Clause 6.1.1

General

Clause 6.1.1 (General) requires an organization to identify the internal and external issues and interested-party requirements that could affect its information security management system, and to determine the associated risks and opportunities that must be addressed. The intent is to ensure risk-based planning is built into the ISMS so that it reliably achieves its intended outcomes, avoids or minimises undesired effects, and drives ongoing improvement rather than being a static, one-off exercise.

We maintain a formal risk and opportunity identification process that considers our organizational context, stakeholder requirements, and the scope of our ISMS, and this feeds directly into our risk treatment plan and security objectives. This process has operated since our initial certification and is reviewed and updated as part of our regular management review and internal audit cycle, ensuring it stays aligned with changes in our business, technology, and threat landscape. Identified risks and opportunities are tracked, prioritised, and linked to specific controls and improvement actions, with ownership assigned to relevant functions. We continue to mature this process through periodic reassessment, incorporating lessons from audits, incidents, and management reviews to strengthen how risks and opportunities are identified and addressed. This activity is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Clause 6.1.2

Information security risk assessment

Clause 6.1.2 sets out how an organisation must run its information security risk assessment process, requiring defined risk acceptance and evaluation criteria, a repeatable methodology that produces consistent results over time, and a structured approach to identifying risks to confidentiality, integrity and availability, assigning risk owners, analysing likelihood and impact, and prioritising risks for treatment. It essentially asks for a disciplined, documented method for understanding and ranking information security risk rather than an ad hoc exercise.

We maintain a documented information security risk assessment methodology that defines our risk acceptance criteria and consistent scoring approach for likelihood and impact, ensuring comparable results across assessment cycles. Risks to the confidentiality, integrity and availability of information within our ISMS scope are identified, assigned to accountable risk owners, and analysed to determine risk levels using this established methodology. The resulting risk register is evaluated against our defined criteria to prioritise risks for treatment, and it is reviewed and updated as part of our regular management review and internal audit cycle. This process has operated continuously within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine the criteria and methodology over time as part of our ongoing continual improvement practice.

Clause 6.1.3

Information security risk treatment

Clause 6.1.3 requires an organization to take the outcomes of its information security risk assessment and decide how to treat each identified risk, selecting appropriate options and controls, cross-checking those controls against the Annex A reference set to ensure nothing necessary has been missed, and documenting the results in a Statement of Applicability. It also requires a risk treatment plan and formal sign-off by risk owners accepting any residual risk. In practice this is the bridge between identifying risk and operating a concrete set of controls.

We operate a documented risk treatment process as part of our certified ISMS, under which identified risks are evaluated and mapped to appropriate treatment options and controls. We maintain a Statement of Applicability that records which Annex A controls are applied, the justification for inclusion or exclusion, and their implementation status, and we cross-check this against our risk assessment outputs to confirm completeness. Our risk treatment plan is reviewed and updated through our regular management review and internal audit cycle, and residual risks are formally reviewed and accepted by designated risk owners. This process has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature it through ongoing risk assessment cycles and management review.

Clause 6.2

Information security objectives and planning to achieve them

Clause 6.2 requires the organisation to set concrete, measurable information security objectives that align with its security policy and take into account risk assessment results and applicable requirements. These objectives must be documented, communicated to relevant staff, monitored for progress, and periodically updated. The organisation must also define clear action plans for achieving each objective, specifying what will be done, what resources are needed, who is responsible, target timelines, and how success will be evaluated.

We maintain documented information security objectives that are derived from our risk assessment process and aligned with our information security policy, covering relevant functions and levels of the organisation. Each objective is assigned an owner, defined resources, a target timeframe, and measurable success criteria, and these are tracked through our management review cycle. Progress against objectives is monitored throughout the year and reported into management review, where objectives are reassessed and updated as our risk environment or business priorities evolve. Objectives and their associated plans are communicated to relevant personnel and retained as documented records within our ISMS. This process operates as part of our certified ISMS and is examined by our certification body at every surveillance and recertification audit, with continual refinement driven through our internal audit and management review programme.

Clause 6.3

Planning of changes

Clause 6.3, Planning of Changes, addresses how an organization manages modifications to its information security management system so that changes are introduced deliberately rather than in an ad hoc way. It expects that when the ISMS needs to change—whether due to new risks, business changes, structural changes, or improvement initiatives—the organization considers the purpose of the change, potential consequences, resource needs, and allocation of responsibilities before the change is carried out. The intent is to preserve the integrity and effectiveness of the ISMS as it evolves over time.

We manage changes to our ISMS through a structured change management process that is integrated into our governance and management review cycles, ensuring that changes to policies, scope, risk treatments, or supporting controls are assessed for impact before they are implemented. Proposed changes are reviewed by relevant owners to confirm that responsibilities, resourcing, and dependencies are addressed, and that the change does not introduce unintended risk to the confidentiality, integrity, or availability of information. This planning approach has been embedded within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We document significant changes and their rationale as part of our management review records and internal audit evidence, and we continue to mature our change planning practices through periodic review of lessons learned and evolving business needs. This ensures the ISMS remains consistent, controlled, and fit for purpose as our organization and threat environment evolve.

Support

Clause 7

Support

Clause 7 (Support) of ISO/IEC 27001:2022 requires an organisation to ensure it provides the resources, competent people, awareness, internal and external communication, and controlled documented information needed to establish, operate and continually improve its ISMS. In practice this means management commits sufficient staffing, budget, tools and training so that the security programme can function effectively, that people understand their security responsibilities, and that policies, records and procedures are properly created, version-controlled and kept available to those who need them.

Our ISMS operates with dedicated resourcing, including assigned information security roles, budget and access to appropriate tools and platforms, which is reviewed by leadership as part of our management review cycle. We maintain a competence and awareness programme covering onboarding and periodic refresher training so staff understand their security responsibilities, supplemented by targeted communications on policy changes and security expectations. Documented information supporting the ISMS, such as policies, procedures and records, is controlled through a defined document management process that governs authoring, approval, versioning and periodic review. Internal and external communication relevant to information security is managed through defined channels and responsibilities. These arrangements are within the scope of our certified ISMS and are examined by our certification body at every surveillance and recertification audit.

Clause 7.1

Resources

Clause 7.1 (Resources) requires an organisation to identify and allocate the people, time, budget, tools, and infrastructure necessary to establish, operate, maintain, and continually improve its information security management system. It is a foundational enablement clause ensuring the ISMS is not just documented but genuinely resourced to function effectively across all its processes and controls.

We identify and provide the staffing, budget, tools, and infrastructure required to operate our ISMS effectively, with resourcing needs reviewed as part of our management review and annual planning cycles. Roles and responsibilities for information security are assigned to appropriately skilled personnel, and we allocate budget for security tooling, training, and third-party services such as audits and technical assessments as needed. Senior management, through governance forums, reviews resourcing adequacy against ISMS objectives, risk treatment plans, and audit outcomes, adjusting allocations where continual improvement opportunities are identified. This resourcing commitment has been in place and operating within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.

Clause 7.2

Competence

Clause 7.2 (Competence) requires an organization to identify the skills and experience needed by people whose work affects information security, confirm they possess that competence through education, training, or experience, take steps to close any gaps, and keep records demonstrating this. It is about ensuring the people operating and supporting the ISMS are genuinely capable of performing their security-related responsibilities.

We maintain defined role requirements for positions that affect information security, covering the skills, qualifications and experience expected for each role. We verify competence during recruitment and onboarding and through ongoing performance and training reviews, and we provide role-specific security awareness and technical training to staff and relevant contractors. Training completion, certifications and other evidence of competence are retained in our HR and learning records. We periodically review competence requirements and training effectiveness as part of our management review and internal audit cycle, continuing to refine role profiles and training content as our operations evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every audit.

Clause 7.3

Awareness

Clause 7.3 (Awareness) requires that people working under the organisation's control understand the information security policy, how their own role contributes to the effectiveness of the ISMS, and what the consequences are if they don't follow ISMS requirements. It's about ensuring security is understood as a shared responsibility, not just a set of rules imposed from outside.

We maintain a security awareness programme that communicates our information security policy and expectations to all personnel working under our ISMS, delivered through onboarding training and periodic refresher sessions. Staff are made aware of how their day-to-day roles support the organisation's security objectives and of the potential consequences, both to the organisation and to individuals, of non-conformance with ISMS requirements. Awareness content is reviewed and updated to reflect changes in policy, risk landscape, and lessons learned through internal audits and management review. Completion of awareness activities is tracked, and this area is examined as part of every certification and surveillance audit under our ISO/IEC 27001:2022 certified ISMS. We continue to mature the programme's delivery methods and content through our continual improvement process.

Clause 7.4

Communication

Clause 7.4 (Communication) requires an organisation to work out its internal and external communication needs relevant to the information security management system: what needs to be communicated, when, to whom, and through what channels. It ensures that security-relevant information reaches employees, management, and outside parties such as customers, regulators, and suppliers in a timely and consistent way, so that decisions and responses are properly informed.

We maintain a defined communications approach for information security matters that identifies the audiences, timing, and channels for both routine and urgent messages, covering internal updates to staff and management as well as external communications to customers, regulators, and suppliers where relevant. This is supported by established processes such as management review, security awareness updates, incident notification procedures, and periodic reporting to leadership, each with a clear owner and communication channel. We use a mix of channels including our intranet, email, ticketing and collaboration platforms, and formal reports to ensure consistent and traceable delivery of security information. This approach operates within our certified ISMS and is reviewed as part of our ongoing management review and internal audit cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to refine our communication practices to reflect organisational changes, new stakeholder needs, and lessons from audits and incident exercises.

Clause 7.5

Documented information

Clause 7.5, Documented Information, sets expectations for how an organization creates, maintains, and controls the records and documentation that support its information security management system. This includes both the documentation explicitly required by the ISO/IEC 27001:2022 standard and any additional documentation the organization itself determines is necessary for the ISMS to operate effectively. The clause also addresses how such documented information is identified, formatted, reviewed, approved, and made available to those who need it while being protected from unauthorized changes or loss.

We maintain a structured document control process that governs the creation, review, approval, versioning, and retention of all ISMS documentation, including policies, procedures, standards, and records generated by our security processes. Documents are held in a controlled repository with defined ownership, access permissions, and review cycles to ensure they remain accurate and current. Our internal audit and management review cycles include verification that documented information is properly maintained, version-controlled, and accessible to relevant personnel while being protected from unauthorized access or modification. This documentation control process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine our document management practices through continual improvement activities identified during internal audits and management reviews.

Clause 7.5.1

General

Clause 7.5.1 (General) sets out the expectation that an information security management system be supported by documented information — both the records and procedures explicitly required by the ISO/IEC 27001:2022 standard and any additional documentation the organisation itself judges necessary for the ISMS to operate effectively. The intent is to ensure that policies, procedures, and records are captured, controlled, and available in a form that supports consistent operation and evidences conformity, rather than dictating a rigid documentation set.

We maintain a structured set of documented information supporting our ISMS, including policies, procedures, standards, and records that satisfy the explicit documentation requirements of ISO/IEC 27001:2022 as well as additional internal documents we have determined are necessary for the ISMS to function effectively. This documentation is version-controlled, subject to defined ownership, and stored within our governance and document management platform, with access restricted appropriately. We review and update this documented information as part of our regular management review and internal audit cycle, ensuring it remains accurate, current, and fit for purpose as our ISMS matures. This approach has operated since our initial certification and is examined by our certification body at every surveillance and recertification audit, confirming that our documentation practices continue to meet the standard's requirements.

Clause 7.5.2

Creating and updating

Clause 7.5.2 sets out how documented information within the ISMS should be properly created and maintained, covering consistent identification (such as titles, version dates, authors or reference numbers), suitable format and media, and a formal review and approval step before documents are relied upon. The intent is to ensure that policies, procedures and records are trustworthy, current and traceable, rather than informally produced.

We maintain a documented information control process as part of our certified ISMS, under which policies, procedures and records are created and updated using consistent templates that capture titling, versioning, authorship and revision history. Documents are managed in our controlled electronic document repository, with defined formats and access controls appropriate to their sensitivity and audience. Before publication or update, documents go through a defined review and approval workflow to confirm they remain suitable and adequate for their purpose. This process has operated since our initial certification and is examined at every surveillance and recertification audit, and we continue to refine document governance practices through our management review and internal audit cycle.

Clause 7.5.3

Control of documented information

Clause 7.5.3 of ISO/IEC 27001:2022 addresses how an organisation controls the documented information that underpins its information security management system, including policies, procedures and records. It requires that such documents remain available, usable and appropriately protected, with clear management of distribution, access, storage, version control, and retention or disposal throughout their lifecycle. The intent is to ensure that ISMS documentation stays accurate, current and accessible only to those who need it.

We maintain a document control process that governs how ISMS policies, procedures and records are created, reviewed, approved, distributed and retired. Documents are stored in managed platforms with access restricted according to role, version history retained, and current versions clearly identified to prevent use of outdated material. Retention and disposal of records follow defined schedules aligned with legal, regulatory and business requirements. This process operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it is examined by our certification body at every audit. We continue to mature our document control practices, including refining access permissions and lifecycle management as our tooling and organisational needs evolve.

Operation

Clause 8

Operation

Clause 8 (Operation) requires the organisation to plan, execute and control the operational processes needed to satisfy its information security requirements and to deliver the treatment plans defined during risk assessment. It calls for establishing criteria for these processes, controlling planned changes, reviewing the consequences of unintended changes, and maintaining documented evidence that operations are carried out as intended. In effect, it ensures the ISMS is not just designed on paper but actively run and controlled in day-to-day business activity.

We operate our information security management system through defined operational processes that translate our risk treatment plan into practical controls across IT, HR, vendor management and service delivery. Operational criteria, responsibilities and change management procedures are documented and followed so that planned changes are assessed and approved before implementation, and any unplanned change is reviewed for security impact. We maintain records and evidence of these operational activities, including logs, approvals and change tickets, which support ongoing monitoring and audit. These processes are reviewed as part of our internal audit programme and management review cycle, and they have been examined by our certification body at every surveillance and recertification audit since our initial certification. We continue to mature our operational controls through continual improvement identified in these review cycles.

Clause 8.1

Operational planning and control

Clause 8.1 requires an organization to plan, execute, and control the operational processes needed to satisfy information security requirements and the risk treatment actions identified during ISMS planning. This includes setting clear operating criteria, managing planned and unplanned changes to those processes, and ensuring that externally provided processes, products, or services relevant to the ISMS are appropriately controlled. In practice, it is about making sure day-to-day operations reliably deliver the security outcomes the organization has committed to.

We operate documented processes and procedures that translate our risk treatment plan and security objectives into day-to-day operational practice, with defined criteria for how key ISMS-relevant activities are to be performed. Changes to systems, processes, and services are managed through a formal change control process, which includes assessing security impact before changes are approved and reviewing outcomes to address any unintended effects. Third-party and outsourced services relevant to the ISMS are managed through vendor risk assessment, contractual security requirements, and ongoing monitoring to ensure external processes meet our security expectations. Operational records, logs, and process documentation are maintained to provide evidence that these controls are being carried out as intended. This operational planning and control framework has been part of our certified ISMS since our initial certification and is reviewed and refined through our internal audit and management review cycle, and it is examined by our certification body at every audit.

Clause 8.2

Information security risk assessment

Clause 8.2 (Information Security Risk Assessment) requires an organisation to carry out formal, repeatable assessments of information security risk on a planned cadence and whenever significant changes to the business, systems, or threat landscape occur, using the risk criteria it has already defined under Clause 6.1.2. It also requires that the outcomes of each assessment be documented and retained as evidence that risk is being actively identified, analysed, and evaluated over time.

We operate a documented risk assessment process that is run at planned intervals and is re-triggered when significant organisational, technical, or environmental changes occur. Assessments are performed against the risk identification, analysis and evaluation criteria established for our ISMS, and cover assets, threats, vulnerabilities, and business impact relevant to our operations. Results, including identified risks, risk ratings, and treatment decisions, are recorded and retained as documented information, and are reviewed through our management review and internal audit cycle. This process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our methodology and supporting tooling through that ongoing review cycle.

Clause 8.3

Information security risk treatment

Clause 8.3 (Information Security Risk Treatment) requires an organisation to actually carry out the risk treatment plan produced during risk assessment, ensuring that the chosen controls and actions are implemented, assigned, and tracked to completion. It also requires that the outcomes of this treatment activity be documented and retained, so there is verifiable evidence of how identified risks were addressed.

We maintain a formal risk treatment process that translates the outputs of our risk assessment into an actionable treatment plan, with owners, target controls, and completion tracking managed through our risk register. Treatment actions are implemented through our operational security processes, spanning technical, procedural, and organisational controls drawn from our Statement of Applicability. We retain documented records of treatment decisions, implementation status, and residual risk outcomes, which are reviewed at planned intervals as part of our management review and internal audit cycle. This process has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature the process, refining prioritisation and evidence capture based on management review and internal audit input.

Performance evaluation

Clause 9

Performance evaluation

Clause 9 of ISO/IEC 27001:2022, Performance Evaluation, requires an organisation to systematically check whether its information security management system is actually working as intended, not just documented. This covers monitoring and measuring security processes, conducting periodic internal audits, and having top management formally review the ISMS to confirm it remains suitable, adequate, and effective. The intent is to create a structured feedback loop that drives evidence-based decisions about the security programme.

We maintain an ongoing performance evaluation programme as part of our certified ISMS, including defined metrics and monitoring activities that track the operation and effectiveness of our security controls. We conduct internal audits on a planned cycle, covering all applicable clauses and Annex A controls, using qualified and independent auditors. Results from monitoring, audits, and risk assessments feed into regular management reviews, where leadership assesses ISMS performance, resource needs, and opportunities for improvement. We continue to mature our measurement approach and audit scope through successive management review and internal audit cycles. This entire process is examined by our certification body at every surveillance and recertification audit.

Clause 9.1

Monitoring measurement analysis and evaluation

Clause 9.1, Monitoring, Measurement, Analysis and Evaluation, requires an organisation to decide what aspects of its information security processes and controls need to be tracked, how those measurements will be taken so that results are consistent and repeatable, and who is responsible for gathering and analysing the data. It also requires that the timing of monitoring, analysis and evaluation be defined and that results be retained as evidence, so leadership can judge whether the ISMS and its controls are actually performing and delivering the intended security outcomes.

We maintain a defined set of security metrics and monitoring activities covering key controls and processes across our ISMS, with clear ownership for who collects data, who reviews it, and how often each measure is assessed. Our methods are applied consistently so results can be compared over time and reproduced, and we record outcomes as documented evidence retained for audit and management review purposes. Findings from this monitoring feed into our internal audit programme and management review cycle, where we evaluate the ongoing effectiveness and performance of the ISMS and identify opportunities for improvement. This measurement and evaluation activity has been part of our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our metrics and review methods through this continual improvement cycle.

Clause 9.2

Internal audit

Clause 9.2, Internal Audit, requires the organisation to run planned, periodic audits of its information security management system to check that it satisfies both its own internal requirements and the ISO/IEC 27001:2022 standard, and that the controls in place are genuinely operating as intended rather than existing only on paper.

We maintain a documented internal audit programme covering the full scope of our certified ISMS, with an audit schedule that ensures all clauses and applicable Annex A controls are reviewed across a defined cycle. Audits are performed by personnel who are independent of the areas being reviewed, using a consistent methodology to assess conformance and operating effectiveness. Findings, observations and improvement opportunities from each audit are recorded and fed into our management review and corrective action processes, closing the loop between assurance activity and continual improvement. This internal audit process has operated since our initial certification and is itself examined by our certification body at every surveillance and recertification audit.

Clause 9.2.1

General

Clause 9.2.1 (Internal Audit – General) requires an organisation to carry out internal audits at planned intervals to check that its information security management system both conforms to its own defined requirements and to the requirements of ISO/IEC 27001, and that it is genuinely working as intended in practice. It is the mechanism by which the organisation independently tests itself between external assessments, rather than relying solely on the certification body's audits.

We maintain a documented internal audit programme that defines audit scope, criteria, frequency and methodology across the certified ISMS, covering all applicable clauses and Annex A controls on a rolling schedule. Audits are performed by personnel independent of the areas being audited, using a risk-based approach to prioritise higher-risk processes and controls, and results are recorded and tracked through to closure. Findings, non-conformities and improvement opportunities feed directly into our management review and corrective action processes, ensuring continual refinement of the ISMS. This internal audit programme has operated since our initial certification in 2021 and is itself reviewed and examined by our certification body at every surveillance and recertification audit.

Clause 9.2.2

Internal audit programme

Clause 9.2.2 requires an organization to run a planned programme of internal audits that checks whether the ISMS conforms to both the ISO/IEC 27001 requirements and the organization's own policies, and whether it is operating effectively. This means defining audit scope and criteria for each audit, choosing auditors who are independent of the areas they assess, prioritising audits based on process importance and prior results, and reporting outcomes to relevant management with records retained as evidence.

We maintain a documented internal audit programme covering all areas of the certified ISMS, with a defined schedule, audit criteria and scope established for each audit cycle. Audits are performed by personnel independent of the process being reviewed to preserve objectivity and impartiality, using a consistent methodology for planning, fieldwork and reporting. Audit results, including any observations for improvement, are reported to relevant management and tracked through to resolution as part of our management review process. We retain audit plans, reports and related records as documented evidence, and this programme has operated continuously since our initial certification, with the certification body examining its operation at each surveillance and recertification audit. We continue to refine audit prioritisation and coverage based on the importance of processes and the outcomes of previous audits.

Clause 9.3

Management review

Clause 9.3 (Management Review) requires top management to periodically review the information security management system to confirm it remains suitable, adequate, and effective for the organization's context and objectives. This review considers factors such as audit results, risk trends, performance metrics, stakeholder feedback, and opportunities for improvement, and it drives decisions on resource allocation and strategic direction for the ISMS.

We conduct management reviews of our ISMS at planned intervals, bringing together leadership to evaluate the system's ongoing performance, risk posture, and alignment with business objectives. These reviews draw on inputs including internal and external audit results, risk assessment outcomes, security metrics, incident trends, and feedback from interested parties, ensuring decisions are grounded in current operational data. Outputs from each review, including decisions on resource needs, policy adjustments, and improvement initiatives, are documented and tracked to closure through subsequent review cycles. This practice has operated since our initial certification and continues to mature through refinements identified during our internal audit and management review cycle. The management review process itself is within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Clause 9.3.1

General

Clause 9.3.1 requires top management to review the information security management system at planned intervals to confirm it remains suitable, adequate, and effective in supporting the organisation's objectives and risk posture. This ensures leadership stays actively engaged in the ISMS rather than delegating oversight entirely, and that the review process considers changing business context, risks, and performance data.

We conduct management reviews of our ISMS at planned intervals, bringing together senior leadership to assess the system's continuing suitability, adequacy, and effectiveness. These reviews draw on inputs such as audit results, risk assessments, security performance metrics, incident trends, and stakeholder feedback, and produce documented outputs including decisions and actions for improvement. This practice has operated since our initial certification and is embedded in our governance calendar as a recurring, minuted activity with defined attendees and agenda requirements. The management review process itself, along with its records and resulting actions, falls within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. We continue to refine the review's inputs and outputs through our internal audit and continual improvement cycle to ensure they remain aligned with organisational needs.

Clause 9.3.2

Management review inputs

Clause 9.3.2 sets out the specific inputs that must feed into management reviews of the ISMS, including the status of prior action items, changes in internal and external context, evolving stakeholder needs, performance feedback such as nonconformities, monitoring results, audit outcomes and objective attainment, risk assessment and treatment status, and opportunities for improvement. The intent is to ensure leadership reviews are evidence-based and comprehensive rather than a superficial check-in, so that strategic decisions about the ISMS are properly informed.

We maintain a structured management review process that draws together all of these required inputs on a scheduled basis, including status updates on previous action items, relevant contextual and stakeholder changes, security performance metrics, internal and external audit results, progress against information security objectives, and the current state of risk assessment and treatment. These reviews are documented, with outcomes and follow-up actions tracked through to closure, and this process has operated consistently since our initial certification. Our approach to consolidating and analysing these inputs continues to mature through our internal audit and continual improvement cycle, refining how trends and feedback are presented to leadership. This process falls within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Clause 9.3.3

Management review results

Clause 9.3.3 (Management Review Results) requires that top management's periodic review of the ISMS produce documented outputs, specifically decisions on opportunities for continual improvement and any changes needed to the management system, its policies, resources or controls. The intent is to ensure leadership actively steers the ISMS based on performance data rather than treating review as a passive status update, and that these decisions are recorded and traceable over time.

We hold scheduled management reviews as an established part of our certified ISMS, bringing together inputs such as audit results, risk treatment status, security metrics, incidents, and stakeholder feedback so that leadership can make informed decisions. The outcomes of each review, including agreed improvement actions and any required changes to the ISMS scope, policies, controls or resourcing, are documented and tracked to completion. These records are retained as evidence and are reviewed as part of our internal audit programme. This process operates continuously and is examined by our certification body at every surveillance and recertification audit. We continue to mature the review process, refining the inputs considered and the way decisions are tracked through successive management review and internal audit cycles.

Improvement

Clause 10

Improvement

Clause 10 of ISO/IEC 27001:2022 requires an organization to continually improve the suitability, adequacy, and effectiveness of its information security management system over time. This means learning from nonconformities, audit results, and monitoring data, and using that insight to strengthen controls, processes, and risk treatment on an ongoing basis rather than treating certification as a one-time achievement.

We operate a documented continual improvement process, established since our initial certification, that draws on internal audits, management reviews, risk assessments, and operational monitoring to identify opportunities to strengthen our ISMS. Corrective actions and improvement initiatives are tracked through defined procedures, ensuring root causes are addressed and outcomes are verified for effectiveness. Our leadership team reviews ISMS performance at planned intervals, using these findings to adjust policies, controls, and resourcing as needed. This improvement cycle is embedded within our certified ISMS and is examined by our certification body at every surveillance and recertification audit. Through successive audit cycles, we continue to mature this process, refining how we capture lessons learned and translate them into measurable enhancements to our security posture.

Clause 10.1

Continual improvement

Clause 10.1 (Continual Improvement) requires an organisation to keep enhancing how well its information security management system fits its needs and how effectively it operates, rather than treating certification as a static achievement. It expects security management to evolve over time in response to changing risks, lessons learned, audit findings, and business context, with improvements driven deliberately rather than left to chance.

Continual improvement is embedded in our ISMS through the ongoing cycle of internal audits, management reviews, risk assessments, and corrective action processes that have operated since our initial certification. Outputs from these activities, along with metrics, stakeholder feedback, and changes in our threat landscape, are reviewed by management on a regular cadence to identify opportunities to strengthen policies, processes, and technical controls. We maintain a structured approach to tracking improvement actions through to completion and verifying their effectiveness before closure. This continual improvement mechanism is a core part of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. Through successive audit cycles, we have refined our risk treatment, control implementation, and governance practices to keep pace with organisational and external changes.

Clause 10.2

Nonconformity and corrective action

Clause 10.2, Nonconformity and Corrective Action, sets out how an organisation must respond when something in the ISMS doesn't work as intended - whether identified through audits, monitoring, or day-to-day operations. It requires correcting the immediate issue, investigating root causes to prevent recurrence, implementing corrective actions proportionate to the impact, and verifying that those actions were effective. It also requires keeping records that demonstrate this process was followed.

We maintain a documented corrective action process that is used to capture nonconformities identified through internal audits, management review, monitoring activities, or day-to-day operations. Each nonconformity is logged, assessed for immediate containment needs, and investigated to determine underlying causes before corrective actions are defined and assigned to an owner. We track these actions through to completion and review their effectiveness before closure, updating related policies, procedures, or controls where the review indicates this is needed. This process operates as part of our certified ISMS and its outputs, including records of nonconformities and corrective actions, are reviewed at each internal audit and external certification audit cycle. We continue to refine how we identify trends and potential recurrence across similar areas of the ISMS through our ongoing management review process.

Other (Annex A)

Control

This entry corresponds to an Annex A control within ISO/IEC 27001:2022, which sets out a specific safeguard that organisations must implement and manage as part of their information security management system to address a defined risk or security objective. As the specific control identifier and title were not provided in the source record, this summary reflects the general intent of Annex A controls: to translate risk treatment decisions into concrete, verifiable operational practices. Each such control is selected based on the organisation's risk assessment and Statement of Applicability, and is expected to operate consistently and be subject to ongoing review.

We maintain documented policies and procedures that translate applicable Annex A controls into day-to-day operational practice across our organisation. These controls are implemented through a combination of governance processes, technical safeguards, and defined responsibilities, and are formally included within the scope of our certified information security management system. We review the design and operation of our controls on a recurring basis through internal audit and management review, adjusting and refining our approach as part of continual improvement. All controls, including this one, have remained within our certified ISMS and have been examined by our certification body at every surveillance and recertification audit since our initial certification. Supporting records and evidence for this control are maintained and made available for audit purposes as part of our standard ISMS documentation practices.

Organizational controls (Annex A)

Control 5.01

Policies for information security

Annex A control 5.1 (Policies for information security) calls for a set of management-approved policies that establish clear direction for information security across the organisation, covering both an overarching policy and topic-specific policies for key risk areas. These policies must be communicated to staff and relevant external parties, formally acknowledged, and reviewed on a planned basis or when significant changes to the business or risk environment occur, ensuring they remain fit for purpose over time.

We maintain an information security policy framework, comprising an overarching policy and a set of topic-specific policies, that has been approved by management and is in effect within the scope of our certified ISMS. These policies are communicated to all personnel and made available to relevant interested parties, with acknowledgement obtained as part of our onboarding and ongoing awareness processes. We review our policies at planned intervals, and whenever significant organisational, technological, legal or regulatory changes occur, to ensure they remain aligned with business needs and risk. This policy framework, its approval records, and the associated review cycle are examined by our certification body at every surveillance and recertification audit, and we continue to refine our policies through our management review and internal audit cycle.

Control 5.02

Information security roles and responsibilities

ISO/IEC 27001:2022 Annex A 5.2 requires an organization to clearly define information security roles and responsibilities and allocate them to appropriate individuals or functions, ensuring accountability across the organization's needs. The intent is to avoid ambiguity in ownership of security tasks so that decisions, oversight, and operational duties are consistently assigned and understood.

We maintain a defined organizational structure for information security that assigns clear ownership for governance, risk management, and operational security activities across relevant roles and functions. Responsibilities are documented within our ISMS governance framework and communicated to those who hold them, ensuring accountability for tasks such as policy approval, risk treatment, incident response, and control operation. We review and refine this allocation of roles periodically through our management review and internal audit cycle to reflect organizational changes and continual improvement. This structure has operated as part of our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.

Control 5.03

Segregation of duties

Annex A 5.03 (Segregation of Duties) addresses the need to divide critical or conflicting tasks and responsibilities among different individuals so that no single person can both execute and conceal errors, fraud, or unauthorized changes to systems and data. The intent is to design roles and access so that opportunities for misuse of privilege or bypassing controls are structurally limited, rather than relying solely on trust or after-the-fact detection.

We maintain role definitions and access provisioning practices that separate key conflicting duties, such as the ability to request, approve, and implement changes, or to initiate and authorise transactions and system modifications. Access to critical systems is granted according to defined roles, with privileged functions assigned so that development, operational, and approval responsibilities remain distinct wherever practicable. We periodically review role assignments and access rights as part of our access management and internal audit processes to confirm that segregation remains effective as teams and systems evolve. This control operates within our certified ISMS and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our segregation practices through our management review and internal audit cycle.

Control 5.04

Management Responsibilities

Annex A 5.4 (Management Responsibilities) requires that managers actively reinforce information security by ensuring employees, contractors and other personnel understand and apply the organization's information security policy, topic-specific policies and procedures in their day-to-day work. The intent is that security is not just documented but actively championed and role-modelled by leadership at all levels, embedding it into normal management practice rather than treating it as a separate compliance activity.

We require managers across the business to communicate information security expectations to their teams and to reinforce compliance with our information security policy and supporting topic-specific policies as part of normal line management activity. This includes onboarding briefings, periodic security awareness communications, and performance and conduct processes that hold personnel accountable for following security procedures. Management responsibilities for security are documented within our ISMS roles and responsibilities framework and are reinforced through regular staff communications, training, and manager check-ins. We review the effectiveness of this control through our internal audit programme and management review process, and it has operated within our certified ISMS since our initial certification, with continual refinement through successive audit cycles.

Control 5.05

Contact with Authorities

Annex A 5.5 (Contact with Authorities) requires an organization to identify and maintain relationships with relevant legal, regulatory, and supervisory bodies so that information can flow appropriately in both directions when needed. This ensures the organization stays current on legal and regulatory obligations and can engage authorities promptly during security incidents, investigations, or compliance matters.

We maintain documented procedures identifying the relevant legal, regulatory, and supervisory authorities applicable to our operations, including law enforcement, data protection regulators, and sector-specific bodies. Designated roles within our organization are responsible for maintaining these relationships and ensuring timely, appropriate communication when circumstances require it, such as during incident response or regulatory inquiries. This process is integrated into our incident management and legal compliance procedures, ensuring authorities are engaged consistently with our obligations. As part of our certified ISMS, this control is reviewed through our internal audit and management review cycle, and its operation has been examined by our certification body at every surveillance and recertification audit since our initial certification. We continue to refine our authority contact lists and engagement procedures to reflect any changes in our regulatory environment or business operations.

Control 5.06

Contact with Sspecial interest groups

ISO/IEC 27001:2022 Annex A control 5.6 asks an organisation to maintain active connections with security-focused interest groups, specialist forums, and professional associations. The intent is to ensure the organisation stays current on emerging threats, vulnerabilities, and industry practice, and can draw on external expertise and threat intelligence to inform its own risk decisions.

We maintain ongoing engagement with relevant security special interest groups, professional associations, and industry forums as part of our information security programme. This engagement supports our threat awareness and horizon-scanning activities, feeding relevant intelligence and practice updates into our risk assessment and security planning processes. Membership and participation channels are reviewed periodically to ensure they remain relevant to our operating environment and threat landscape. This control operates within the scope of our certified ISMS and is reviewed as part of our management review and internal audit cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature how we capture and act on external intelligence gained through these channels.

Control 5.07

Threat Intelligence

ISO/IEC 27001:2022 Annex A control 5.07, Threat Intelligence, calls for an organisation to gather and evaluate information about emerging security threats relevant to its environment so it can anticipate risks and take timely, informed mitigation action. The intent is to move beyond reactive incident response toward a proactive understanding of the threat landscape affecting the organization's people, systems and data.

We operate a threat intelligence process that draws on multiple external and internal sources, including vendor and industry advisories, vulnerability feeds, and alerts from our security tooling, to identify threats relevant to our technology stack and operating context. This information is reviewed and assessed by responsible security personnel who determine relevance and any required mitigation, such as patching priorities, configuration changes, or awareness communications. Outputs from threat intelligence feed into our broader risk management, vulnerability management, and incident response processes so that mitigations are tracked to completion. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at each audit since our initial certification. We continue to mature our sourcing and analysis practices as part of our ongoing continual improvement process.

Control 5.08

Information security in project management

ISO/IEC 27001:2022 Annex A control 5.08, Information Security in Project Management, calls for information security considerations to be built into the way projects are planned, executed and closed out, regardless of the project's type or subject matter. The intent is to ensure security risks and requirements are identified and addressed as an ordinary part of project governance rather than treated as an afterthought once a deliverable is nearing completion.

We integrate information security requirements into our standard project management approach so that security is considered from initiation through delivery and closure of projects, including those involving new systems, products, or significant changes. Our project management practices require identification and assessment of information security risks relevant to project objectives and deliverables, with appropriate controls and responsibilities assigned as part of project planning. Security requirements are reviewed at key project milestones and incorporated into acceptance criteria before deliverables are finalised. This practice operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature how project-related security risks are documented and tracked as part of our continual improvement process.

Control 5.09

Inventory of information and other associated assets

ISO/IEC 27001:2022 Annex A control 5.09, Inventory of Information and Other Associated Assets, calls for organisations to identify and maintain a record of the information and other assets that support their operations, and to assign clear ownership for each so accountability for protecting them is unambiguous. The intent is to ensure nothing of security relevance is overlooked simply because it isn't tracked, and that responsibility for each asset's protection is assigned to a specific role.

We maintain an inventory of information and other associated assets that supports our information security management system, covering the systems, data repositories and other assets relevant to our services. Each asset category is assigned an owner accountable for its appropriate handling, classification and protection. We review and update this inventory through our regular asset management and change control processes, ensuring it reflects our current operating environment. The inventory and its ownership assignments are examined by our certification body as part of every surveillance and recertification audit, and we continue to refine the process through our internal audit and management review cycle.

Control 5.10

Acceptable use of information and other associated assets

ISO/IEC 27001:2022 Annex A 5.10 requires an organisation to define and communicate clear rules for how employees and other users may use information and associated assets, and how such assets should be handled throughout their lifecycle. The intent is to ensure everyone understands their responsibilities for protecting company and customer data, preventing misuse, and applying consistent handling practices based on the sensitivity of the asset.

We maintain a documented acceptable use policy that defines permitted and prohibited use of information, systems, and other assets, along with handling requirements aligned to our information classification scheme. This policy is communicated to all personnel as part of onboarding and ongoing security awareness activities, and acknowledgement is tracked as part of our ISMS records. Handling procedures cover matters such as secure storage, transmission, and disposal of information based on its classification level. We review and update these rules periodically through our management review and internal audit cycle to ensure they remain effective as our environment and asset inventory evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.

Control 5.11

Return of assets

Annex A control 5.11 (Return of Assets) requires that when someone's employment, contract, or engagement changes or ends, all organizational assets in their possession—such as devices, access cards, documents, and data—are recovered and accounted for. This control exists to prevent lingering access, data leakage, or loss of company property once a working relationship changes or concludes.

We maintain a formal offboarding and role-change process, integrated with our HR and IT service management workflows, that triggers asset return and access revocation whenever employment, contractor, or third-party agreements change or end. This includes recovery of laptops, mobile devices, access badges, and any physical or electronic media, along with de-provisioning of accounts and system access through our identity provider and endpoint management platform. Managers and IT complete a checklist confirming all assigned assets have been returned before final offboarding is closed out. This process has operated consistently since our initial certification and is reviewed periodically through internal audits and management review to ensure it remains effective as our asset inventory and workforce arrangements evolve. The control operates within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit.

Control 5.12

Classification of information

ISO/IEC 27001:2022 Annex A control 5.12, Classification of Information, calls for information to be categorised according to how sensitive or critical it is, factoring in confidentiality, integrity, and availability needs as well as any legal or contractual expectations from customers and other interested parties. The intent is to ensure that everyone handling information understands its relative importance so that appropriate protections can be applied consistently.

We maintain a formal information classification scheme that defines categories of sensitivity based on confidentiality, integrity, and availability requirements, along with guidance for how each category should be labelled, handled, stored, and shared. This scheme is documented within our ISMS and is communicated to personnel through onboarding and ongoing security awareness activities. Classification decisions are applied to information assets as part of our broader asset management and handling procedures, and we periodically review the scheme to ensure it continues to reflect our operational and regulatory context. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit. We continue to mature our classification practices through our internal audit and management review cycle.

Control 5.13

Labelling of information

ISO/IEC 27001:2022 Annex A 5.13 asks organisations to establish procedures for labelling information in a way that reflects its assigned classification level, so that people and systems handling the information can recognise its sensitivity and apply appropriate protections. The intent is to make classification actionable and visible, supporting consistent handling, storage, transmission and disposal decisions throughout the information lifecycle.

We maintain an information labelling procedure aligned with our information classification scheme, covering both electronic and, where relevant, physical information assets. Labelling conventions are applied consistently across documents, messages and systems so that classification is visible to staff and, where feasible, enforced or supported through automated tagging in our productivity and information management platforms. Employees are trained on the classification scheme and associated labelling expectations as part of our security awareness programme. We review the labelling procedure and its application periodically through our internal audit and management review cycle to ensure it continues to reflect how information is created, shared and stored, and we refine it as our technology and business needs evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Control 5.14

Information transfer

Annex A 5.14 (Information Transfer) calls for defined rules, procedures, or agreements that protect information whenever it moves — whether between internal teams, systems, or facilities, or when it is shared with external parties such as customers, partners, or suppliers. The intent is to ensure that confidentiality, integrity, and traceability of information are preserved consistently across all transfer methods, including electronic, physical, and verbal exchanges.

We maintain documented information transfer policies and procedures that define acceptable methods, protections, and approval requirements for sharing information internally and with external parties. These cover electronic transfers, such as email and file-sharing platforms, as well as physical media and verbal disclosures, and require appropriate safeguards such as encryption, access controls, and confidentiality or data-sharing agreements where relevant. We govern transfers with third parties through contractual terms that set expectations for secure handling of shared information. Our internal audit and management review cycle regularly assesses these controls to confirm they remain effective and appropriate as our transfer methods and partnerships evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit.

Control 5.15

Access control

ISO/IEC 27001:2022 Annex A control 5.15 (Access Control) requires an organisation to define and apply rules governing who can access information and associated assets, both physically and logically, based on actual business and security needs rather than convenience. It expects access decisions to follow documented criteria such as job role, need-to-know, and asset sensitivity, and to be consistently enforced across systems and facilities.

We maintain a formal access control policy that defines how access to systems, applications, and physical facilities is granted, reviewed, and revoked based on role and business need. Access provisioning follows a least-privilege and need-to-know model, with approvals required before rights are granted and periodic reviews to confirm continued appropriateness. Technical enforcement is achieved through our identity provider and endpoint management platform, including role-based access groups, authentication controls, and logging of access-related changes. Physical access to relevant facilities is similarly controlled through defined authorisation and monitoring procedures. These controls have operated within our certified ISMS since our initial certification and are reviewed through our internal audit and management review cycle, and examined by our certification body at every surveillance and recertification audit.

Control 5.16

Identity Management

Annex A control 5.16 (Identity Management) requires an organisation to manage the full lifecycle of identities used to access information systems and data, from creation through modification to eventual deactivation. The intent is to ensure every person or system accessing organisational assets can be uniquely identified and that identity records remain accurate and current, forming the foundation for reliable access control decisions.

We maintain a formal identity management process covering the creation, modification, and timely deactivation of user and system accounts across our environment, tied to events such as onboarding, role changes, and offboarding. Identities are provisioned through our identity provider with unique identifiers assigned to individuals and systems to prevent shared or ambiguous credentials. We operate defined procedures for verifying identity requests, assigning access rights consistent with role requirements, and promptly disabling accounts that are no longer needed. This process is periodically reviewed as part of our internal audit and management review cycle, and we continue to refine identity governance practices as our environment evolves. This control operates within our certified ISMS and is examined by our certification body at every audit.

Control 5.17

Authentication information

Annex A 5.17 (Authentication Information) requires organisations to govern how passwords, tokens, keys and other authentication information are issued, distributed, stored and revoked, and to ensure personnel understand how to handle such information responsibly. The intent is to prevent unauthorized access resulting from weak, mishandled, or improperly lifecycle-managed credentials.

We maintain a formal process for the issuance, storage, and revocation of authentication information such as passwords and access credentials, covering onboarding, role changes, and offboarding. Authentication secrets are provisioned through our identity provider and endpoint management platform, with technical controls enforcing password complexity, secure storage, and protection against unauthorized disclosure. Personnel receive guidance on the appropriate handling of authentication information, including prohibitions on sharing or insecure storage, as part of our security awareness programme. We review and refine this process through periodic access reviews, internal audits, and management review to ensure it continues to operate effectively. This control has remained within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021.

Control 5.18

Access Rights

Annex A 5.18 (Access Rights) requires an organisation to formally provision, periodically review, modify and promptly remove access rights to information and other associated assets, ensuring these actions consistently follow its documented access control policy and business authorisation requirements. The intent is to ensure that access granted at any point in time is deliberate, approved, and reflects a person's current role and need, throughout the full lifecycle of that access.

We operate documented access control procedures that govern how access rights are requested, approved, granted, changed and revoked across our information systems and associated assets. Access provisioning is tied to defined business need and role-based authorisation, with removal or modification triggered promptly upon role change or termination through our joiner-mover-leaver processes. We periodically review user access rights, including privileged access, to confirm they remain appropriate and aligned with our access control policy. These controls have operated within our certified ISMS since our initial 2021 certification and are examined by our certification body at every surveillance and recertification audit, and we continue to refine review cadence and evidencing through our management review and internal audit cycle.

Control 5.19

Information security in supplier relationships

Annex A control 5.19 requires an organisation to identify and manage the information security risks that arise from using suppliers' products or services, covering how suppliers are selected, onboarded, contracted, monitored and offboarded. The intent is to ensure that reliance on third parties does not weaken the confidentiality, integrity or availability of information, and that expectations for security are agreed and verified throughout the relationship rather than assumed.

We maintain a supplier risk management process that is part of our certified ISMS, covering supplier identification, risk-based due diligence, contractual security requirements, and ongoing monitoring through the relationship lifecycle. New suppliers are assessed for the sensitivity of the data or access they will handle, and relevant security obligations are captured in agreements before onboarding. We periodically review supplier performance and re-assess risk as relationships evolve, with changes managed through defined change and offboarding procedures. This process, and its operating effectiveness, is reviewed through our internal audit programme and management review, and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our supplier evaluation criteria and monitoring approach as part of our regular continual improvement cycle.

Control 5.20

Addressing information security within supplier agreements

Annex A control 5.20 addresses how an organisation embeds information security requirements into agreements with suppliers, ensuring that expectations around confidentiality, data protection, access control, and incident notification are clearly defined and agreed based on the nature and risk of each supplier relationship. The intent is to make security obligations explicit and enforceable within contractual arrangements rather than assumed.

We maintain a supplier management process that identifies the type of relationship and associated risk before agreeing information security terms with each supplier or vendor. Security requirements, such as confidentiality obligations, access restrictions, and incident reporting expectations, are incorporated into supplier agreements as appropriate to the service provided. This process operates within our certified ISMS and has been in place since our initial certification, with supplier terms reviewed and refined through our periodic management review and internal audit cycle. Our approach ensures consistent treatment of security obligations across supplier types, scaled proportionately to the risk each relationship presents. This control is examined by our certification body at every audit as part of our ongoing conformance to ISO/IEC 27001:2022.

Control 5.21

Managing information security in the ICT supply chain

ISO/IEC 27001:2022 Annex A control 5.21 requires an organisation to establish processes for managing information security risks that arise from the ICT products and services it obtains through its supply chain, including hardware, software, cloud platforms, and technology-related service providers. The intent is to ensure that security expectations are defined and carried through the full lifecycle of technology sourcing, from selection and contracting to delivery and ongoing use, so that supplier weaknesses do not undermine the organisation's own security posture.

We maintain defined processes for evaluating and managing information security risk across our ICT supply chain, applied consistently to vendors and service providers who deliver technology products, platforms, or services into our environment. Our supplier onboarding and contracting practices incorporate security requirements appropriate to the nature of the product or service, and we assess supplier risk as part of our supplier relationship management process. These processes have operated continuously within our certified ISMS since our initial 2021 certification and are reviewed through our internal audit programme and management review cycle. We continue to refine our ICT supply chain risk criteria and monitoring approach as our supplier landscape evolves, ensuring the control remains effective and proportionate. This control is included within the scope examined by our certification body at each surveillance and recertification audit.

Control 5.22

Monitoring, review and change management of supplier services

Annex A 5.22 requires an organisation to actively monitor, review and manage changes in how its suppliers deliver services and handle information security, rather than relying solely on the assurances given at onboarding. This means checking that agreed security requirements continue to be met over time, and having a process to assess the impact of any changes suppliers make to their services, systems or subcontractors. The intent is to keep supplier risk visibility current throughout the life of the relationship, not just at contract signing.

We maintain a supplier management process that includes ongoing monitoring and periodic review of supplier security performance and service delivery against agreed requirements. Supplier relationships are assessed on a risk-based schedule, with reviews covering service levels, security incidents, audit reports or certifications, and any material changes to the supplier's operating environment. Where a supplier proposes or makes a significant change, such as to subcontractors, technology or processing locations, we evaluate the potential security impact before accepting the change. This process operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body across successive audits since our initial certification. We continue to mature our supplier oversight practices as part of this continual improvement cycle.

Control 5.23

Information security for use of cloud services

ISO/IEC 27001:2022 Annex A 5.23 asks organisations to treat cloud services as a distinct risk area, with defined processes covering how cloud providers are selected, how security requirements are set and agreed, how the services are used and monitored on an ongoing basis, and how data and access are safely exited or transitioned away from a provider when a relationship ends. The intent is to ensure cloud adoption is deliberate and governed rather than ad hoc, so that security expectations are clear across the full lifecycle of the service.

We maintain a defined process for evaluating, onboarding and managing cloud service providers as part of our certified ISMS, incorporating information security requirements into supplier selection, contractual agreements and ongoing service reviews. Cloud services are assessed against our risk management and supplier security criteria before adoption, with responsibilities for configuration, access control and data protection clearly assigned between us and the provider. We monitor the use of cloud services on an ongoing basis through our operational security processes and periodically review provider performance and risk posture. Where a cloud service is retired or replaced, we follow a controlled exit process to protect the confidentiality and integrity of our data during transition. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Control 5.24

Information security incident management planning and preparation

Annex A 5.24 requires an organisation to plan ahead for information security incidents by defining clear processes, roles and responsibilities before an incident occurs, so that events can be detected, assessed and responded to in a consistent and orderly manner. It sets the foundation for the rest of the incident management lifecycle, including how incidents are communicated, escalated and resolved.

We maintain a documented information security incident management process that defines roles, responsibilities and escalation paths for identifying, triaging, and responding to security events. This process, including communication procedures for reporting and escalating incidents internally and to relevant stakeholders, has operated within our certified ISMS since our initial certification. Staff with incident response responsibilities understand their duties through defined procedures and periodic awareness activities, and the process is reviewed and refined through our internal audit and management review cycle to ensure it remains effective and consistent. This control is within the scope of our certified ISMS and is examined by our certification body at every audit.

Control 5.25

Assessment and decision on information security events

ISO/IEC 27001:2022 Annex A control 5.25 requires an organization to have a defined process for evaluating reported information security events to determine whether they meet the criteria to be classified as an information security incident. This ensures events are consistently triaged, prioritized based on potential impact, and routed to the appropriate response process rather than being handled inconsistently or overlooked.

We maintain a documented event assessment process as part of our certified ISMS, under which reported security events are reviewed by trained personnel against defined criteria to determine severity and whether incident response procedures should be triggered. This process includes clear escalation paths, defined roles and responsibilities, and consistent categorization criteria that align with our incident management procedures. We use logging, monitoring, and alerting tools, including our SIEM platform, to support timely identification and assessment of events. The effectiveness of this process is reviewed through internal audits and management review, and it has operated continuously within our certified ISMS since our initial certification. We continue to refine our assessment criteria and workflows as part of our ongoing continual improvement cycle.

Control 5.26

Respone to information security incidents

Annex A 5.26 (Response to Information Security Incidents) requires an organisation to act on identified security incidents in a structured, repeatable way rather than ad hoc, following documented procedures that cover containment, eradication, recovery, and communication with relevant parties. The intent is to ensure that when an incident occurs, the response is timely, consistent, and minimises harm to the organisation and its stakeholders.

We maintain a documented incident response procedure that defines roles, escalation paths, and the steps taken to contain, investigate, and remediate information security incidents. This procedure is integrated into our ISMS and is invoked by our security and operations teams whenever a security event is confirmed as an incident, ensuring a consistent and controlled response. We use our SIEM and related monitoring tooling to support detection and response activities, and incidents are tracked through to resolution with appropriate internal communication and, where relevant, notification to affected parties. Our incident response procedure and its execution are reviewed as part of our regular management review and internal audit cycle, and this control has operated within our certified ISMS since our initial certification, being examined by our certification body at every surveillance and recertification audit. We continue to mature our response capability through lessons learned and periodic testing as part of our continual improvement process.

Control 5.27

Learning from information security incidents

Annex A 5.27 addresses the organisation's ability to capture and apply lessons learned from information security incidents so that controls, procedures, and awareness are strengthened over time. It expects a structured feedback loop where root causes and contributing factors identified during incident handling are translated into concrete improvements, reducing the likelihood or impact of similar events recurring.

We operate a post-incident review process that captures root cause analysis, contributing factors, and corrective actions for information security incidents, feeding these findings into updates to our policies, technical controls, and staff awareness activities. Lessons learned are logged and tracked through to resolution, and recurring themes are reviewed as part of our management review and internal audit cycle to ensure improvements are effective and sustained. This feedback loop has operated since our initial certification and continues to mature as we refine how incident insights are recorded, prioritised, and actioned. The process, its outputs, and evidence of resulting control improvements fall within the scope of our certified ISMS and are examined by our certification body at every surveillance and recertification audit.

Control 5.28

Collection of evidence

Annex A 5.28 (Collection of Evidence) requires an organization to have defined procedures for identifying, collecting, acquiring and preserving evidence relating to information security events, so that such evidence remains admissible and reliable for internal, disciplinary, regulatory or legal purposes. The focus is on maintaining a consistent chain of custody and integrity of records from the point an event is detected through to any subsequent proceeding.

We maintain documented procedures for identifying, collecting and preserving evidence arising from information security events, ensuring a consistent chain of custody from detection through resolution. These procedures define roles and responsibilities for evidence handling, including secure storage and access controls that protect the integrity and confidentiality of collected material. Our incident response process incorporates these evidence-handling steps so that any information relevant to disciplinary, regulatory or legal action is captured and preserved appropriately. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body across successive surveillance and recertification audits since our initial certification. We continue to mature our evidence-handling practices in line with evolving legal and operational requirements.

Control 5.29

Information security during disruption

ISO/IEC 27001:2022 Annex A control 5.29, Information security during disruption, calls for organisations to plan how information security controls will continue to operate, or be suitably substituted, when normal operations are interrupted by an incident, outage or other disruptive event. The intent is to prevent security from being deprioritised or abandoned under pressure, ensuring confidentiality, integrity and availability commitments hold even during degraded or emergency operating conditions.

We maintain business continuity and disaster recovery plans that explicitly address how information security controls are sustained during disruptive events, rather than treating continuity and security as separate concerns. These plans identify critical systems and information assets, define fallback and recovery procedures, and specify how access control, logging, and data protection measures remain enforced or are safely reinstated during and after an incident. Roles and responsibilities for invoking and managing continuity arrangements are documented, and the plans are exercised and reviewed periodically as part of our management review and internal audit cycle. This control operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our disruption-readiness procedures through lessons learned from testing and periodic review, reinforcing consistent security posture under all operating conditions.

Control 5.30

ICT readiness for business continuity

Annex A 5.30 addresses ICT readiness for business continuity, requiring an organisation to plan, implement, maintain and test the technical recovery capabilities needed to keep critical information systems and data available during and after a disruption. It expects ICT continuity arrangements to be derived from business continuity objectives and recovery requirements, rather than treated as a purely technical afterthought.

We maintain ICT continuity arrangements that are aligned with our business continuity objectives, covering the recovery of critical systems, infrastructure and data supporting our services. These arrangements include defined recovery priorities and technical measures such as resilient infrastructure, backups and recovery procedures for key platforms. We test and review these capabilities on a regular cycle, using the results to refine recovery procedures through our management review and internal audit process. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit.

Control 5.31

Legal, statutory, regulatory and contractual requirements

ISO/IEC 27001:2022 Annex A 5.31 requires an organization to identify the laws, regulations, statutory obligations and contractual commitments that affect its information security practices, to document them, and to keep that register current as the business, its markets and its agreements evolve. The intent is to ensure that legal and contractual security obligations are known, tracked and actively factored into how the ISMS is designed and operated, rather than assumed or handled ad hoc.

We maintain a documented register of the legal, regulatory, statutory and contractual requirements relevant to information security that apply to our organization, covering areas such as data protection, sector-specific regulation, and security commitments made to customers and partners. This register is owned by our compliance and information security function and is reviewed on a periodic basis and whenever significant changes occur in our operations, jurisdictions, or customer contracts, to keep it accurate and current. Identified requirements are mapped to relevant policies, controls and processes within our ISMS so that legal and contractual obligations directly inform our security practices. Compliance with these requirements is monitored through our internal audit programme and management review cycle, and this control has operated within our certified ISMS and been examined by our certification body at every audit since our initial certification. We continue to refine the register and its associated processes as part of our ongoing continual improvement activities.

Control 5.32

Intellectual property rights

Annex A 5.32 requires an organisation to have procedures in place to protect intellectual property rights, covering both the organisation's own IP and its obligations regarding third-party licensed material and proprietary products. The intent is to ensure the organisation complies with legal, statutory, regulatory and contractual requirements around software licensing, copyright and use of proprietary works, and manages the risk of unauthorised use or infringement.

We maintain policies and procedures governing the use of licensed and proprietary software and materials, ensuring that acquisition, use and disposal of third-party products are conducted in accordance with applicable licence terms and contractual obligations. Our processes cover tracking of software assets and licences to support compliance with vendor and legal requirements, and staff are made aware of their responsibilities regarding intellectual property through our security awareness programme. Compliance with IP-related obligations is considered as part of our regular legal and regulatory compliance reviews, which are integrated into our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every audit, with practices continually refined through ongoing review.

Control 5.33

Protection of records

ISO/IEC 27001:2022 Annex A control 5.33 (Protection of Records) requires an organisation to safeguard its business records throughout their retention period against loss, destruction, falsification, unauthorized access, and unauthorized release. This ensures records remain trustworthy, available, and usable for as long as they are needed to satisfy legal, regulatory, contractual, and business obligations. The control addresses both the integrity and the accessibility of records as evidence over time.

We maintain a records management approach that classifies records according to their retention requirements and applies appropriate storage, access control, and backup measures to protect them from loss, tampering, or unauthorised disclosure throughout their lifecycle. Access to records is restricted based on role and business need, and our systems enforce retention and disposal schedules aligned with legal, regulatory, and contractual obligations. We use secure storage platforms with logging and access controls to detect and prevent unauthorised changes or access, and backups are maintained to protect against data loss. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to mature our records protection practices as part of our ongoing continual improvement process.

Control 5.34

Privacy and protection of PII

Annex A 5.34 (Privacy and protection of PII) requires an organisation to determine which privacy and data protection laws, regulations, and contractual obligations apply to the personal data it processes, and to put in place the governance needed to meet those obligations consistently. It reflects the intent that protection of personal information should be treated as an integral part of the ISMS rather than a separate, ad-hoc activity.

We maintain a documented process for identifying the privacy and data protection laws, regulations, and contractual commitments applicable to the personal data we handle, and we align our internal policies and procedures to those requirements. Roles and responsibilities for privacy oversight are defined, and personal data handling practices are incorporated into our broader information security controls, including access management, data minimisation, and secure processing. We review applicable legal and regulatory obligations periodically to account for changes in law or in our processing activities, and this review is integrated into our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our privacy practices through ongoing monitoring of the regulatory landscape and continual improvement of our ISMS.

Control 5.35

Independent review of information security

Annex A 5.35 calls for periodic, independent review of an organisation's information security management approach - covering people, processes and technology - by parties who are not responsible for the areas being reviewed. The intent is to provide objective assurance that the ISMS remains suitable, adequate and effective over time, rather than relying solely on self-assessment by those who operate the controls.

We commission independent reviews of our information security management system at planned intervals and following significant organisational or technical changes, using reviewers who are separate from the teams responsible for day-to-day operation of the controls under review. These reviews assess the continuing suitability, adequacy and effectiveness of our security governance, processes and technical safeguards, and their outcomes feed into our management review process alongside internal audit findings. This independent review activity operates within the scope of our certified ISMS and is examined by our certification body at each surveillance and recertification audit. We use the results to continually refine and mature our security programme through our established management review and internal audit cycle.

Control 5.36

Compliance with policies, rules and standards for information security

Annex A 5.36 calls for periodic verification that the organization's information security policies, topic-specific policies, rules, and standards are actually being followed in practice, rather than assuming documented requirements translate into operational reality. It requires a structured review process to confirm alignment between stated policy and day-to-day activities across the organization.

We maintain a program of regular compliance reviews that assess adherence to our information security policy and associated topic-specific policies and standards across the organization. These reviews are carried out through a combination of internal audits, management reviews, and control self-assessments performed by process and asset owners. Findings from these reviews feed into our corrective action process, ensuring that any deviations from policy are tracked and resolved in a controlled manner. This review activity operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our review methods and reporting through our ongoing management review and internal audit cycle.

Control 5.37

Documented operating procedures

Annex A 5.37 asks organisations to document the operating procedures used to run information processing facilities and systems, and to make these procedures available to the staff and contractors who carry out or rely on them. The intent is to ensure consistency, correctness and secure operation of routine and administrative IT activities, reducing reliance on individual knowledge and minimising the risk of error or misconfiguration.

We maintain a set of documented operating procedures covering the routine administration, configuration and maintenance of our information processing facilities, including areas such as system start-up/shutdown, backup, change handling, and other recurring operational tasks. These procedures are stored in our controlled document management system, version-controlled, and made available to the personnel who need them to perform their duties. Procedure owners review and update the documentation on a periodic basis and whenever significant operational or technical changes occur, and we continue to mature this documentation through our management review and internal audit cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.

People controls (Annex A)

Control 6.01

Screening

Annex A 6.1 (Screening) requires the organisation to verify the background, identity, and suitability of candidates before they join and to reassess this on an ongoing basis where warranted, with checks scaled to the sensitivity of the role, the data it can access, and applicable legal and ethical constraints. The intent is to reduce the risk of insider threat or unsuitable personnel gaining access to sensitive information or systems.

We operate a documented pre-employment screening process that verifies identity, employment history, and other relevant checks proportional to the role and the sensitivity of the information or systems it can access, consistent with applicable local laws and regulatory constraints. This screening is applied before personnel join the organisation and is supplemented by ongoing suitability considerations during employment, such as role changes affecting access levels. The process is embedded in our HR onboarding procedures and is part of our certified ISMS, examined by our certification body at each surveillance and recertification audit. We continue to refine screening criteria and thresholds through our management review and internal audit cycle to keep them aligned with evolving risk and regulatory requirements. This control has operated continuously since our initial certification in 2021.

Control 6.02

Terms and conditions of employment

ISO/IEC 27001:2022 Annex A 6.2 (Terms and conditions of employment) requires that employment contracts and related agreements clearly set out both the employee's and the organisation's information security responsibilities. The intent is to ensure that security expectations are formally established and understood before and during employment, so personnel are contractually aware of their obligations to protect information assets.

Within our certified ISMS, employment agreements for all personnel include defined information security responsibilities alongside general terms and conditions, ensuring these obligations are communicated from the outset of employment. Our human resources onboarding process incorporates review and acknowledgement of these responsibilities as part of standard contractual documentation. We maintain this practice consistently across roles, tailoring specific security duties where relevant to the position held. This control is reviewed as part of our ongoing management review and internal audit programme, and it has remained in place and been examined by our certification body through successive surveillance and recertification audits since our initial certification in 2021. We continue to refine our contractual language and onboarding materials as part of our continual improvement process.

Control 6.03

Information security awareness, education and training

Annex A control 6.3, Information Security Awareness, Education and Training, requires that employees and relevant third parties receive ongoing training so they understand their information security responsibilities and stay current with the organisation's policies and procedures relevant to their roles. The intent is to build a workforce that recognises threats, follows secure practices, and actively supports the ISMS rather than treating security as a one-off exercise.

We maintain a formal security awareness and training programme covering all personnel and, where relevant, third parties who support our operations. New joiners complete baseline information security training as part of onboarding, and all staff receive periodic refresher training along with updates whenever policies or topic-specific procedures change. Training content addresses role-relevant risks such as phishing, data handling, acceptable use, and incident reporting, and completion is tracked centrally to confirm coverage. We review the programme's effectiveness through management review and internal audit, and we continue to mature the content and delivery methods based on those reviews. This control operates within the scope of our certified ISMS and is examined by our certification body at every audit.

Control 6.04

Disciplinary Process

Annex A 6.4, Disciplinary Process, calls for a formal, communicated process for taking action against personnel and other relevant interested parties who violate information security policy. The intent is to ensure consequences for policy violations are clear, consistently applied, and proportionate, providing both a deterrent effect and a fair mechanism for addressing confirmed breaches.

We maintain a formal disciplinary process, set out in our HR and information security policies, that applies to employees and other relevant interested parties who violate information security requirements. This process is communicated as part of onboarding and ongoing security awareness activities so that personnel understand the expectations placed on them and the consequences of non-compliance. Any suspected violation is investigated through a defined process involving relevant management and, where appropriate, HR, ensuring actions taken are proportionate and consistent. This control operates within the scope of our certified ISMS and is reviewed as part of our regular management review and internal audit cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature the process through periodic review of policy communication and case handling.

Control 6.05

Responsibilities after termination or change of employment

ISO/IEC 27001:2022 Annex A 6.5 addresses the need to define and enforce information security obligations that continue to apply after an employee or contractor leaves the organisation or moves to a different role. It requires that such ongoing duties—such as confidentiality, return of assets, and access revocation—are clearly communicated and contractually or procedurally enforceable, so that security is not weakened by staff turnover or internal transfers.

We maintain documented HR and offboarding/transfer processes that define which information security obligations, such as confidentiality and non-disclosure commitments, continue beyond the end of employment or a change in role. These responsibilities are communicated to personnel through employment agreements, policy acknowledgements, and offboarding checklists, and are reinforced at the point of role change or departure. Our process includes coordinated deactivation of access and return of company assets, aligned with our access control and asset management procedures. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it has been assessed by our certification body at every audit since our initial certification in 2021. We continue to refine supporting documentation and evidence practices as part of our ongoing continual improvement process.

Control 6.06

Confidentiality or non-disclosure agreements

Annex A 6.6 (Confidentiality or non-disclosure agreements) requires an organisation to define, document and keep current the confidentiality or non-disclosure commitments it expects from employees, contractors and other relevant third parties who may access sensitive information. The intent is to ensure that everyone with such access has formally acknowledged their obligation to protect it, and that these agreements are periodically reviewed to remain aligned with the organisation's actual protection needs.

We maintain a documented confidentiality/non-disclosure agreement that reflects our information protection requirements and require personnel and relevant third parties, such as contractors and vendors with access to sensitive information, to sign it before being granted access. These agreements are incorporated into our onboarding and vendor/contractor engagement processes and are periodically reviewed to ensure they continue to reflect our business and legal needs. This control has operated within our certified ISMS since our initial certification in 2021 and is reviewed at every successive audit, along with our internal audit and management review cycles, through which we continue to mature the associated processes.

Control 6.07

Remote working

ISO/IEC 27001:2022 Annex A control 6.07 (Remote Working) requires an organisation to establish safeguards that protect information accessed, processed or stored by personnel working outside its physical premises, addressing risks such as loss of devices, insecure networks and unauthorized viewing of sensitive data. The intent is to ensure that the same standard of confidentiality, integrity and availability applies regardless of where work is performed.

We maintain a remote working policy that defines the security expectations and responsibilities for personnel working outside our offices, covering areas such as secure connectivity, device configuration and acceptable use. Remote access to corporate systems and data is provided through managed, authenticated channels, with our endpoint management platform enforcing baseline security controls such as encryption, screen-locking and up-to-date patching on devices used remotely. We require the use of secure network connections, such as VPN or equivalent encrypted access, when personnel connect to company resources from remote locations. This control operates within the scope of our certified ISMS and its effectiveness is reviewed through our internal audit programme and management review cycle, with adjustments made as part of our continual improvement process.

Control 6.08

Information security event reporting

Annex A 6.8 (Information Security Event Reporting) requires an organisation to give all personnel a clear, accessible way to report observed or suspected information security events, and to ensure such reports are handled promptly through appropriate channels. The intent is to enable early detection of potential incidents by making it easy and expected for staff to flag anomalies as soon as they notice them.

We maintain a defined reporting mechanism that allows all employees and contractors to report suspected or observed information security events through established internal channels, including our service desk and direct escalation paths to the security team. Staff are made aware of this mechanism through onboarding and periodic security awareness activities, so they understand what constitutes a reportable event and how to raise it promptly. Reported events are logged, triaged and fed into our incident management process for assessment and response. This mechanism operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review to confirm it remains effective and accessible, with continual refinements made as part of our ongoing improvement cycle.

Physical controls (Annex A)

Control 7.01

Phisical security perimeters

Annex A 7.1 (Physical security perimeters) requires an organisation to define and enforce physical boundaries around locations that house information and information-processing assets, so that unauthorised access, damage or interference can be prevented. In practice this means establishing clearly defined secure areas, such as offices, data centres or equipment rooms, with barriers and access points that separate them from less trusted spaces. The control focuses on the layout and physical demarcation used to protect assets rather than the specific access technology used at each boundary.

We maintain defined physical security perimeters around all locations and areas that house information assets and infrastructure supporting our services, including offices and any data centre or server room space we use. These perimeters are enforced through controlled entry points, physical barriers and layered access zones that separate public, general staff and restricted areas. We have operated this approach since our initial certification, with periodic review of site layouts and perimeter controls as part of our management review and internal audit cycle. Where third-party or co-located facilities are used, we rely on their independently assured physical security perimeters as part of our vendor management process. This control is within the scope of our certified ISMS and is examined by our certification body at every audit.

Control 7.02

Physical entry

Annex A control 7.2, Physical Entry, addresses the need to control access to secure areas so that only authorised individuals can reach premises, offices, and locations where information and information-processing assets are held. It calls for defined entry points, mechanisms to verify and permit only appropriate individuals, and oversight of who accesses these areas and when.

We maintain physical entry controls at our facilities and secure areas, using access mechanisms such as badges, keys, or electronic credentials to restrict entry to authorised personnel only. Visitor and contractor access is managed through sign-in and escort procedures where appropriate, and access rights are reviewed periodically to ensure they remain aligned with current personnel and business need. These controls have operated since our initial certification and are examined by our certification body at every surveillance and recertification audit as part of our certified ISMS. We continue to mature our physical access processes through regular management review and internal audit activity.

Control 7.03

Securing offices, rooms and facilities

Annex A control 7.3 addresses the physical security of offices, rooms and facilities, requiring that spaces where information and information-processing assets reside be designed and equipped to prevent unauthorised access, damage and interference. It calls for physical safeguards proportionate to the sensitivity of the assets housed, such as controlled entry points, layout considerations and protection against environmental or physical threats.

We maintain physical security controls across the offices, rooms and facilities within scope of our ISMS, designed to prevent unauthorised access, damage or interference to information and supporting assets. Access to premises and sensitive areas is restricted through controlled entry mechanisms, and facility layouts are designed to segregate and protect areas holding higher-risk assets. We maintain supporting procedures covering visitor handling, secure areas and environmental protections, and these arrangements are reviewed as part of our ongoing risk assessment and management review cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every audit, with continual refinements made through internal audit and management review.

Control 7.04

Physical security monitoring

Annex A control 7.4 (Physical Security Monitoring) requires that premises housing information and information processing facilities be continuously monitored to detect and deter unauthorised physical access. The intent is to ensure that any attempt to gain unauthorised entry to secure areas is identified promptly and can be investigated or acted upon, rather than relying solely on preventive barriers such as locks or badges.

We maintain continuous physical security monitoring across the premises housing our information processing facilities, using a combination of surveillance and access-control mechanisms to detect and deter unauthorised entry. Monitoring coverage and access logs are reviewed as part of our ongoing physical security management process, and any anomalies are handled through our established incident management procedures. This control has operated within our certified ISMS since our initial certification and is reviewed through our internal audit and management review cycle. It is assessed by our certification body at every surveillance and recertification audit. We continue to mature our monitoring practices as part of our continual improvement process.

Control 7.05

Protecting against physical and environmental threats

Annex A 7.5 (Protecting against physical and environmental threats) requires an organisation to identify plausible natural and man-made physical hazards, such as fire, flood, storm, power failure, or environmental damage, that could disrupt facilities and information processing equipment, and to design and implement proportionate safeguards to prevent or limit the impact of such events. It's about ensuring resilience of premises and infrastructure against events outside normal operational threats.

We have assessed the physical and environmental risks relevant to our operating locations and data processing facilities and have implemented controls proportionate to those risks, including environmental monitoring, fire detection and suppression measures, resilient power arrangements, and siting/facility safeguards appropriate to each location. These measures have operated within our certified ISMS since our initial certification and are maintained through routine facilities management and periodic review. We reassess these risks and controls as part of our management review and internal audit cycle, and we continue to mature our approach to physical and environmental resilience as our operating footprint evolves. This control is included in the scope examined by our certification body at every surveillance and recertification audit.

Control 7.06

Working in secure areas

Annex A 7.6 (Working in Secure Areas) addresses the need to establish rules and safeguards governing how personnel and third parties conduct activities within secure areas, so that information and assets located there are protected from damage, misuse or unauthorized interference while work is being performed. It requires the organisation to define acceptable behaviours, supervision arrangements and operational restrictions specific to areas holding sensitive information or critical assets.

We maintain defined rules for working in our secure areas, covering matters such as supervision of personnel and visitors, restrictions on unsupervised access, controls over recording devices and equipment brought into these areas, and requirements to secure areas when unoccupied. These rules are communicated to relevant staff and contractors and are embedded in our physical and information security policies. We review and test these controls as part of our ongoing internal audit and management review cycle, and we continue to mature our practices based on operational experience and risk assessment outcomes. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every surveillance and recertification audit.

Control 7.08

Equipment siting and protection

ISO/IEC 27001:2022 Annex A control 7.8, Equipment Siting and Protection, calls for organisations to position and safeguard equipment so that it is protected against environmental hazards, unauthorised access, and accidental or deliberate damage. The intent is to reduce risks arising from the physical environment in which information-processing equipment operates, whether in offices, data centres, or equipment rooms.

We site information-processing equipment in controlled locations selected to limit exposure to environmental hazards such as fire, water damage, temperature extremes, and unauthorised physical access. Our physical and environmental security policy defines placement standards, access restrictions, and environmental controls such as power protection and climate management for equipment areas. We review the suitability of equipment locations and associated protections as part of our ongoing risk assessment and physical security management processes. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive surveillance and recertification audits since our initial certification in 2021. We continue to mature our siting and protection practices through our management review and internal audit cycle.

Control 7.09

Security of assets off premises

Annex A control 7.9, Security of Assets Off-Premises, addresses the need to protect equipment and information assets that are used or stored outside of the organisation's normal premises, such as laptops used remotely, devices in transit, or equipment stored at third-party sites. The intent is to ensure that being off-site does not create a gap in protection against loss, theft, damage or unauthorised access, and that the risks of remote or mobile use are managed with the same rigour as on-premises assets.

We maintain a policy and set of technical controls governing the use and protection of assets outside our premises, covering laptops, mobile devices and any equipment used remotely or in transit. Devices issued for off-site use are enrolled in our endpoint management platform, which enforces encryption, screen-lock, patching and remote wipe capability, and are protected in line with our acceptable use and mobile device requirements. We require staff to apply physical safeguards such as secure storage, cable locks where appropriate, and not leaving devices unattended in public or high-risk locations, and we maintain asset tracking so that off-site equipment remains accounted for and can be actioned if lost or stolen. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review, with continual refinement of our off-site asset protections as part of our ongoing risk assessment process. The control has been examined by our certification body at every audit since our initial certification.

Control 7.10

Storage media

ISO/IEC 27001:2022 Annex A 7.10 (Storage Media) requires organizations to manage removable and physical storage media throughout its lifecycle—from acquisition through use, transport, and disposal—in a manner consistent with the organization's information classification scheme. The intent is to prevent unauthorized access, disclosure, modification, or loss of information that resides on media such as drives, backup tapes, or portable devices.

We maintain a storage media handling process aligned with our information classification scheme, covering acquisition, authorized use, secure transport, and controlled disposal or destruction of media. Access to storage media containing sensitive information is restricted to authorized personnel, and media is tracked and secured throughout its operational life. When media reaches end of life, we apply secure destruction or sanitization methods appropriate to the classification of the data it held. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, with continual refinements made as our technology and storage practices evolve.

Control 7.11

Supporting utilities

Annex A control 7.11 (Supporting Utilities) requires that information processing facilities be protected against disruptions arising from failures of essential utilities such as electrical power, telecommunications, water supply, gas, and HVAC systems. The intent is to ensure that outages or fluctuations in these underlying services do not cause loss of availability, damage to equipment, or compromise of information and associated assets. Organisations are expected to design resilience and continuity measures proportionate to the criticality of the facilities involved.

We maintain physical and environmental controls designed to protect our information processing facilities against disruption from utility failures, including safeguards for power supply continuity, environmental conditioning, and monitoring of critical building services. Our facilities are equipped with resilience measures such as backup power arrangements and environmental controls appropriate to the risk profile of the sites housing information processing equipment, and we monitor these systems to detect and respond to abnormal conditions. These measures operate under our documented physical security and business continuity procedures, which define responsibilities for maintenance, testing, and incident response related to supporting utilities. We review the adequacy of these controls through our regular internal audit and management review cycle, and they have been examined as part of our certified ISMS by our certification body at every audit since our initial certification in 2021. Where facilities are provided by third-party data centre or hosting providers, we obtain assurance over their supporting utility controls as part of our supplier management process.

Control 7.12

Cabling security

ISO/IEC 27001:2022 Annex A control 7.12 (Cabling Security) calls for power, data, and telecommunications cabling to be safeguarded against interception, interference, or physical damage so that information integrity, availability, and confidentiality are not compromised through the physical infrastructure. This includes protecting cabling that supports critical systems from accidental or deliberate disruption.

We maintain physical and environmental controls that protect the power and data cabling supporting our facilities and systems from damage, interference, and unauthorised interception. Cabling supporting critical infrastructure is routed and secured in accordance with our physical security standards, with segregation of power and data lines and restricted access to spaces housing cabling infrastructure where applicable. These measures are part of our certified ISMS and are reviewed as part of our ongoing risk assessment, internal audit, and management review processes. We continue to mature our physical security controls, including cabling protections, in line with evolving operational and facility requirements. This control has remained within the scope of our ISO/IEC 27001:2022 certification since our initial certification and is examined by our certification body at every surveillance and recertification audit.

Control 7.13

Equipment maintenance

ISO/IEC 27001:2022 Annex A 7.13 (Equipment Maintenance) calls for equipment supporting information processing to be properly and regularly maintained so that it continues to operate reliably and does not become a source of confidentiality, integrity or availability loss. This covers maintaining hardware in line with manufacturer or supplier specifications, using authorised service personnel, and keeping records of servicing and repairs.

We maintain a physical and environmental security programme that includes scheduled maintenance of equipment supporting our information systems, carried out by authorised personnel or vendors in accordance with manufacturer guidance. Maintenance activities, including servicing, repairs and equipment disposal or reuse, are logged and tracked as part of our asset management processes. Access to equipment for maintenance purposes is controlled and monitored, and any equipment taken off-site for repair is handled under our asset handling and data protection procedures. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management reviews, and is examined by our certification body at each surveillance and recertification audit. We continue to mature our maintenance tracking and evidencing practices as part of our ongoing continual improvement cycle.

Control 7.14

Secure disposal or reuse of equipment

Annex A 7.14 addresses the secure disposal or reuse of equipment that contains storage media, requiring that sensitive data and licensed software be reliably erased or overwritten before equipment leaves the organisation's control or is repurposed. The intent is to prevent residual information on decommissioned or reassigned hardware from being recovered by unauthorised parties.

We maintain a documented process for the secure disposal and reuse of equipment containing storage media, covering laptops, servers, and other devices that may hold sensitive information. Before any device is retired, transferred, or reused, storage media are verified to ensure data and licensed software have been securely erased or destroyed using approved methods appropriate to the media type. Verification steps confirm sanitisation is complete before equipment is released for reuse or disposal, and records of this process are retained as evidence. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it is examined by our certification body at every surveillance and recertification audit.

Technological controls (Annex A)

Control 8.01

User and point devices

Annex A control 8.1 (User Endpoint Devices) requires organisations to protect information that is stored on, processed by, or accessible from laptops, mobile devices and other endpoints used by staff. The intent is to ensure that the convenience and mobility these devices provide does not introduce uncontrolled risk to the confidentiality, integrity or availability of information, through a combination of technical controls, configuration standards and user responsibilities.

We maintain an endpoint security policy and supporting technical baseline that applies to all user devices with access to company or customer information, covering configuration hardening, disk encryption, screen locking, malware protection and patching. Devices are managed through our endpoint management platform, which enforces these controls centrally and allows us to monitor compliance and remotely respond where a device is lost, stolen or found non-compliant. Access to corporate systems from endpoints is further controlled through our identity provider, including multi-factor authentication and conditional access based on device health. This control has operated within our certified ISMS since our initial certification, and its design and operating effectiveness are reviewed through periodic internal audit, management review and continual improvement of our technical baselines as new device types and threats emerge.

Control 8.02

Privileged access rights

ISO/IEC 27001:2022 Annex A 8.2 addresses how organisations control the allocation and use of privileged access rights, such as system administrator or root-level accounts, which carry a heightened risk of misuse or compromise. It calls for a formal process to authorise, grant, review and revoke elevated access, ensuring that only individuals, software components and services with a demonstrated business need hold such rights, and that their use is monitored and constrained accordingly.

We maintain a formal privileged access management process that governs how elevated access rights are requested, approved, granted and periodically reviewed across our systems and services. Privileged accounts are provisioned separately from standard user accounts, restricted to authorised personnel and services with a defined operational need, and are subject to enhanced authentication and monitoring controls. We periodically review privileged access assignments to confirm they remain appropriate and revoke rights promptly when they are no longer required. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive annual audits since our initial certification in 2021, and we continue to mature our review and monitoring practices through our management review and internal audit cycle.

Control 8.03

Information access restriction

ISO/IEC 27001:2022 Annex A control 8.3 (Information Access Restriction) requires that access to information and associated assets be limited in line with the organisation's documented access control policy, so that individuals and systems can only reach the data and functions required for their role. It reflects the least-privilege and need-to-know principles that underpin a mature access management programme, rather than leaving access decisions ad hoc or overly permissive.

We restrict access to information and systems according to our documented access control policy, applying role-based and need-to-know principles across applications, file stores, and infrastructure. Access rights are provisioned and revoked through defined onboarding, transfer, and offboarding procedures, with permissions enforced through our identity provider and supporting technical access controls such as group- and role-based permissions. We periodically review user access and privileged entitlements to confirm they remain appropriate to current job responsibilities, and adjust configurations as our environment evolves. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit, and we continue to mature our access review processes through our management review and internal audit cycle.

Control 8.05

Secure authentication

Annex A 8.5 Secure Authentication requires an organisation to implement authentication technologies and procedures that reliably verify the identity of users and entities before granting access to systems, applications and services, with the strength of authentication proportionate to the sensitivity of the information being accessed. It expects these mechanisms to be aligned with the organisation's access control policy and to resist common attack techniques such as credential theft, replay and brute-force attempts.

We have implemented secure authentication mechanisms, including multi-factor authentication, across systems, applications and services in accordance with our topic-specific access control policy. Authentication requirements are risk-based, so higher-sensitivity systems and privileged access are protected with stronger controls, such as MFA and conditional access enforced through our identity provider. Password and credential handling follow secure configuration standards, including complexity, storage and rotation requirements aligned with good practice. We monitor authentication events through our SIEM and access management tooling to detect anomalous login activity, and we review the effectiveness of these controls as part of our ongoing internal audit and management review cycle. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Control 8.06

Capacity management

ISO/IEC 27001:2022 Annex A control 8.6 (Capacity Management) requires an organisation to monitor its use of computing, human, and facility resources and to adjust or plan capacity so that current and anticipated business needs can be met without unacceptable performance or availability risk. It reflects the expectation that resource constraints be identified proactively rather than discovered through outages or degraded service.

We monitor utilisation of key infrastructure and processing resources, including compute, storage, and network capacity, using automated monitoring and alerting tools integrated with our operational and SIEM platforms. Capacity thresholds and growth trends are reviewed periodically by the relevant technical and management teams, who adjust resourcing, scaling, or staffing plans in line with current and forecast demand. This extends beyond technology to cover workforce and facilities planning, ensuring that operational teams have adequate resources to support business and security commitments. These practices operate within the scope of our certified ISMS and are reviewed as part of our ongoing internal audit and management review cycle, and have been examined by our certification body at every audit since our initial certification in 2021. We continue to mature our capacity monitoring and forecasting practices as part of continual improvement.

Control 8.07

Protection against Malware

Annex A control 8.07 (Protection Against Malware) calls for organisations to deploy technical defences that detect and prevent malicious software from compromising information systems, backed by user awareness so people recognise and avoid malware-related risks such as phishing or untrusted downloads. The intent is a layered defence combining automated controls with informed human behaviour, rather than relying on a single tool.

We deploy anti-malware and endpoint protection technology across our estate, configured to automatically update signatures/detection logic and to actively scan and block malicious content in real time. Devices are managed through our endpoint management platform, which enforces protection status and alerts our security team to anomalies for investigation. We reinforce these technical controls with regular user security awareness activities covering phishing, safe browsing, and safe handling of attachments and removable media. The effectiveness of these controls is reviewed as part of our ongoing internal audit and management review cycle, and this control operates within the scope of our ISO/IEC 27001:2022 certified ISMS, which has been maintained since 2021 and is independently examined by our certification body at every audit.

Control 8.08

Management of technical vulnerabilities

ISO/IEC 27001:2022 Annex A 8.8 requires an organisation to proactively identify technical vulnerabilities in the information systems it operates, assess how exposed it is to them, and take timely, risk-appropriate action to remediate or mitigate them before they can be exploited. It reflects an ongoing lifecycle of vulnerability intelligence gathering, assessment and treatment rather than a one-off check.

We operate a continuous technical vulnerability management process that includes regular scanning of infrastructure, applications and endpoints, together with monitoring of vendor and industry vulnerability advisories relevant to our technology stack. Identified vulnerabilities are assessed for risk and exploitability and tracked through to remediation within defined timeframes based on severity, using patch management and configuration controls across our endpoint management and infrastructure platforms. Our process assigns clear ownership for triage, remediation and verification, and remediation activity is evidenced and reviewed as part of our internal audit and management review cycle. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit, and we continue to mature our tooling and processes through that ongoing review.

Control 8.09

Configuration management

Annex A 8.9 (Configuration Management) calls for organisations to define, document, and apply standard secure configurations for hardware, software, services, and network components, and to monitor these settings so that unauthorized or unintended changes are detected and corrected. The intent is to reduce risk from misconfiguration by ensuring systems are deployed and maintained in a known, secure, and consistent state throughout their lifecycle.

We maintain documented baseline configuration standards for the hardware, operating systems, applications, services, and network devices within scope of our ISMS, reflecting security hardening principles appropriate to each asset type. These baselines are applied through standardised build and deployment processes, and configuration state is monitored using our endpoint management and infrastructure tooling to detect drift or unauthorized changes. Any changes to established configurations are managed through our formal change management process, which requires review and approval before implementation. We periodically review configuration standards and monitoring outcomes as part of our internal audit and management review cycle, refining them to reflect evolving threats and technology changes. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at every surveillance and recertification audit.

Control 8.10

Information deletion

Annex A control 8.10 (Information Deletion) calls for organisations to remove information from systems, devices, or storage media once it is no longer needed for its original purpose, legal obligation, or contractual requirement. This reduces the risk of unnecessary retention leading to unauthorised disclosure and supports compliance with data protection and retention obligations. It applies across the full information lifecycle, including production systems, backups, and end-of-life media.

We maintain a documented approach to information deletion that governs how data is removed from systems, devices, and storage media once retention periods or business need have expired. This includes defined retention criteria aligned to legal, regulatory, and contractual requirements, and secure deletion or destruction methods applied to both digital records and physical or decommissioned media. Deletion practices are embedded in our data lifecycle and asset disposal processes, and are reviewed as part of our ongoing internal audit and management review cycle. This control has operated within our certified ISMS since our initial ISO/IEC 27001:2022 certification and is examined by our certification body at every surveillance and recertification audit. We continue to refine our deletion procedures to reflect changes in systems, storage technologies, and applicable regulatory requirements.

Control 8.11

Data masking

ISO/IEC 27001:2022 Annex A control 8.11 (Data Masking) addresses the use of techniques such as masking, pseudonymisation or anonymisation to reduce the exposure of sensitive data, including personal information, in accordance with the organization's access control policy and applicable legal, statutory, regulatory and contractual requirements. The intent is to limit the amount of sensitive data visible to individuals, systems or environments that do not need full access to it, thereby reducing risk in situations such as testing, development, analytics or support activities.

We apply data masking and related data-minimisation techniques to sensitive data, including personal data, based on business requirements and the sensitivity classification defined in our topic-specific access control and data protection policies. These controls are applied consistently across environments such as non-production systems, analytics and support access, so that individuals and processes only see the level of detail necessary for their role. Our approach considers applicable legal, statutory, regulatory and contractual obligations relevant to the data being protected. This control operates within our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to mature our masking techniques and their application scope as part of our continual improvement process.

Control 8.12

Data leakage prevention

ISO/IEC 27001:2022 Annex A 8.12 (Data Leakage Prevention) calls for controls that detect and prevent the unauthorised disclosure, exfiltration, or extraction of sensitive information from systems, networks, and devices that process, store, or transmit it. The intent is to reduce the risk of confidential or regulated data leaving the organisation's control through accidental or deliberate means, whether via endpoints, email, cloud services, or removable media.

We maintain data leakage prevention measures across the systems, networks, and endpoints that handle sensitive information within the scope of our certified ISMS, using a combination of technical controls, access restrictions, and monitoring to detect and prevent unauthorised disclosure or extraction of data. These measures are integrated with our broader security tooling, including endpoint management and monitoring platforms, and are aligned with our data classification and handling policies. We review the effectiveness and coverage of these controls as part of our ongoing risk assessment, internal audit, and management review cycle, and we continue to mature our approach as the organisation's technology estate and data flows evolve. This control has operated within our certified ISMS since our initial certification and is examined by our certification body at each surveillance and recertification audit.

Control 8.13

Information back up

Annex A control 8.13, Information Backup, calls for maintaining regular backup copies of information, software, and systems so that data and services can be restored following loss, corruption, or disruption. It requires a defined backup policy covering scope, frequency, retention, and storage, along with periodic testing to confirm that restoration actually works when needed.

We maintain a topic-specific backup policy that defines what information and systems are backed up, the frequency of backups, retention periods, and storage arrangements, including safeguards to protect backup data from loss or unauthorised access. Backups are performed on a scheduled basis and monitored to confirm successful completion. We periodically test restoration processes to verify that data and systems can be recovered effectively, and we review our backup approach as part of our ongoing risk management and management review cycle. This control operates within the scope of our certified ISMS and has been examined by our certification body during successive audits since our initial certification in 2021. We continue to refine backup coverage and testing practices as part of our continual improvement process.

Control 8.14

Redundancy of information processing facilities

ISO/IEC 27001:2022 Annex A 8.14 requires that information processing facilities be designed with sufficient redundancy to meet the organisation's defined availability requirements, so that failures of individual components or systems do not disrupt critical services. It calls for a risk-based approach to identifying which systems need duplication, failover, or resilient architecture, and for these measures to be tested and maintained over time.

We design and operate our information processing facilities with redundancy commensurate with the availability requirements of the services they support, including resilient infrastructure and failover mechanisms for critical systems. Our approach to redundancy is informed by risk assessment and business impact considerations, and is reviewed as part of our ongoing ISMS operation. We maintain documented architecture and operational practices covering redundant components, and we periodically review and test resilience measures to confirm they continue to meet availability needs. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit. We continue to mature our redundancy practices through our management review and internal audit cycle.

Control 8.15

Logging

Annex A 8.15 (Logging) calls for systems and applications to generate logs capturing user activity, exceptions, faults, and other security-relevant events, and for those logs to be retained, safeguarded from tampering or unauthorized access, and regularly reviewed. The intent is to ensure organizations have reliable evidence to detect anomalous behaviour, support investigations, and demonstrate accountability over time.

We generate logs across critical systems, infrastructure, and applications to capture security-relevant events, exceptions, and operational faults. Log data is centralized and protected through access controls and retention settings that guard against unauthorized modification or deletion, preserving the integrity of records used for monitoring and investigation. Our logging configuration and retention practices are reviewed periodically as part of our internal audit and management review cycle to ensure continued alignment with operational and security needs. This control has operated within our certified ISMS since our initial 2021 certification and is examined by our certification body at every surveillance and recertification audit. We continue to mature our logging and monitoring capabilities through ongoing risk assessment and technology improvements.

Control 8.16

Monitoring activities

Annex A control 8.16 (Monitoring Activities) requires an organisation to continuously monitor networks, systems and applications for unusual or suspicious behaviour so that potential information security incidents can be identified and evaluated in a timely manner. The intent is to ensure sufficient visibility across the environment to detect deviations from expected activity before they escalate into significant security events.

We maintain continuous monitoring of our networks, systems and applications using centralised logging and a security information and event management (SIEM) capability that aggregates and correlates activity across the environment. Defined detection rules and alerting thresholds are used to identify anomalous behaviour, with alerts triaged by our security team and escalated through our incident management process where warranted. Monitoring coverage, alert tuning and detection logic are reviewed periodically as part of our management review and internal audit cycle, allowing us to continue to mature detection effectiveness over time. This control operates within the scope of our certified ISMS and has been examined by our certification body at every audit since our initial certification in 2021.

Control 8.17

Clock synchronization

Annex A control 8.17 (Clock Synchronization) requires that all information processing systems reference approved, consistent time sources so that timestamps across logs, applications, and infrastructure remain accurate and aligned. This ensures that event records from different systems can be reliably correlated during monitoring, troubleshooting, and security incident investigations.

We maintain synchronized time across our information processing systems by configuring them to reference approved and consistent time sources. This practice supports accurate and comparable timestamps across logs and system events, which is essential for effective monitoring, correlation of security-related activity, and incident investigation when required. Clock synchronization is applied consistently across the infrastructure within the scope of our certified ISMS. This control has operated since our initial certification and continues to be reviewed as part of our ongoing internal audit and management review cycle to ensure it remains effective as our systems evolve.

Control 8.18

Use of privileged utility programs

Annex A control 8.18 addresses the need to restrict and tightly control utility programs that have the capability to bypass or override normal system and application security controls, such as diagnostic tools, disk utilities or system administration software. The intent is to ensure that such powerful tools are only available to authorised personnel and cannot be misused to circumvent access controls, logging or other safeguards, thereby protecting the integrity of systems and data.

We maintain an inventory and access control regime for utility programs capable of overriding system or application controls, ensuring their use is restricted to authorised, appropriately privileged personnel. Access to such tools is granted through our formal access management process, is subject to segregation of duties considerations, and is removed promptly when no longer required. We monitor and log the use of privileged utilities as part of our broader logging and monitoring controls, and we periodically review installed utilities and associated permissions to confirm they remain appropriate. This control operates within the scope of our certified ISMS and is reviewed through our internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit.

Control 8.19

Installation of software on operational systems

ISO/IEC 27001:2022 Annex A control 8.19 requires an organisation to control how software is installed and updated on operational systems so that only authorised, verified software is deployed, reducing the risk of malware, misconfiguration or exploitation of technical vulnerabilities. It expects defined procedures covering who can install software, how installations are tested and approved, and how the resulting environment is kept auditable and reversible.

We maintain a documented software installation and change process for operational systems that restricts installation rights to authorised personnel and requires approvals before deployment. Software packages and updates are sourced from trusted, verified sources and are tested prior to installation on production systems, with rollback options preserved where applicable. Administrative and installation privileges on operational systems are controlled through our access management and endpoint management platform, limiting the ability to introduce unauthorised software. We periodically review installed software and installation logs as part of our internal audit and management review cycle to confirm ongoing compliance, and we continue to mature the associated tooling and monitoring through this cycle. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Control 8.20

Network security

ISO/IEC 27001:2022 Annex A control 8.20 (Network Security) calls for organisations to protect information as it moves across and resides within networks by identifying network assets, segmenting and controlling access between zones, monitoring for malicious activity, and ensuring only authorised devices and traffic can traverse the environment. It reflects the practical need to treat the network itself as a managed, hardened layer of defence rather than an open transport medium.

We maintain a network security policy and supporting technical architecture that defines how our networks are segmented, monitored and controlled to protect information in transit and the systems that process it. Network devices are configured and managed under change control, with access restricted to authorised administrators and traffic filtered through firewalls and access control lists aligned to defined security zones. We use monitoring tools, including our SIEM, to detect anomalous or unauthorised network activity, and network configurations are reviewed periodically as part of our internal audit and management review cycle. This control has operated within our certified ISMS since our initial certification in 2021 and is examined by our certification body at every surveillance and recertification audit. We continue to mature our network security controls through ongoing risk assessment and technology review.

Control 8.21

Security of network services

Annex A 8.21 (Security of network services) requires an organisation to identify the security features, service levels, and performance requirements of the network services it uses—whether internally provided or outsourced—and to ensure these are implemented, contractually agreed where relevant, and actively monitored throughout the service lifecycle. The intent is to prevent gaps in accountability for network security controls when services are delivered by third parties or across complex network architectures.

We maintain an inventory of the network services used across our environment, documenting the security mechanisms, service levels, and usage requirements expected of each, including those provided by external network and connectivity vendors. Security requirements such as encryption, access control, authentication, and availability targets are defined and, where applicable, incorporated into service agreements with providers. We monitor network service performance and security posture on an ongoing basis using our network monitoring and SIEM tooling, with alerts and periodic reviews feeding into our operational security processes. This control operates within the scope of our certified ISMS and is reviewed through our internal audit programme and management review cycle, and it has been examined by our certification body at every audit since our initial certification. We continue to mature our monitoring and service-level oversight as our network architecture evolves.

Control 8.22

Segregation of networks

Annex A control 8.22 (Segregation of networks) calls for dividing an organization's network into distinct security zones so that groups of users, systems and services with different trust levels or business functions are separated, with controlled traffic flow between them. The intent is to limit the ability of a compromise in one area of the network from spreading freely to others, reducing overall attack surface and blast radius.

We maintain a segmented network architecture that separates groups of systems, users and services into defined security zones based on business function and risk sensitivity. Traffic between these zones is controlled through firewall and routing policies that permit only the connections required for legitimate business purposes, following a least-privilege approach to network access. This segmentation design is reviewed periodically as part of our ongoing risk management and infrastructure change processes to ensure it continues to reflect our operating environment. This control operates within the scope of our certified ISMS and has been assessed by our certification body across successive annual audits. We continue to mature our network segmentation practices through our management review and internal audit cycle.

Control 8.23

Web filtering

Annex A control 8.23 (Web Filtering) calls for organizations to manage and restrict access to external websites in order to reduce the risk of users or systems being exposed to malicious content, phishing sites, or other unauthorized and harmful web resources. The intent is to proactively limit the attack surface presented by internet browsing rather than relying solely on endpoint detection after the fact.

We operate web filtering controls across our environment to restrict access to malicious, high-risk, and unauthorized website categories, reducing the likelihood of malware infection or exposure to phishing and other web-based threats. These controls are applied through our endpoint management and network security tooling and are configured according to our internal security policies governing acceptable use and safe browsing. We periodically review and refine the filtering rules and categories to keep pace with the evolving threat landscape and business needs, as part of our ongoing security operations. This control operates within the scope of our certified ISMS and is examined by our certification body during each surveillance and recertification audit, alongside our other technological controls.

Control 8.24

Use of cryptography

ISO/IEC 27001:2022 Annex A control 8.24 (Use of Cryptography) requires an organisation to define and operate clear rules governing when and how cryptographic techniques are applied to protect the confidentiality, integrity and authenticity of information, along with sound management of the cryptographic keys that underpin those techniques. It expects decisions on cryptography to reflect business needs, risk assessment, and applicable legal, regulatory and contractual obligations rather than ad-hoc technical choices.

We maintain a documented cryptography policy that sets out the approved algorithms, protocols and use cases for protecting data at rest and in transit, aligned with our risk assessment and applicable legal and contractual requirements. Cryptographic key management, including generation, storage, rotation, access control and retirement of keys, is governed by defined procedures and supported by our technical platforms and key management tooling. These controls have operated within our certified ISMS since our initial certification and are reviewed periodically through internal audit and management review to ensure they remain effective as technology and business needs evolve. We continue to mature our cryptography standards in line with industry practice and evolving regulatory expectations. This control, along with its supporting evidence, is examined by our independent certification body at every surveillance and recertification audit.

Control 8.26

Application security requirements

ISO/IEC 27001:2022 Annex A control 8.26 (Application Security Requirements) calls for organisations to define, document and approve information security requirements before developing or acquiring applications, ensuring that security is considered as an integral part of the design and procurement process rather than added afterward. This includes identifying relevant security functions, data protection needs and secure design principles appropriate to the application's purpose and risk profile.

We maintain a documented process for identifying and approving information security requirements as part of our application development and acquisition activities, ensuring security considerations are addressed from the earliest stages of design or vendor selection. Requirements such as authentication, access control, data protection and secure configuration are defined and reviewed prior to development or procurement decisions being finalised. This process is embedded within our software development lifecycle and vendor evaluation procedures, and is subject to periodic review as part of our ISMS governance activities. As with all controls in our Annex A Statement of Applicability, this practice has operated within our certified ISMS since our initial certification and is examined by our certification body at each surveillance and recertification audit. We continue to mature our application security requirements process through ongoing management review and internal audit findings, refining criteria and documentation practices to reflect evolving development and procurement activities.

Control 8.32

Change management

Annex A control 8.32 (Change Management) calls for a formal process governing changes to information systems and processing facilities so that security is preserved throughout planning, testing, approval and deployment. The intent is to prevent unauthorised or poorly assessed changes from introducing vulnerabilities, instability or unintended impact to production environments.

We maintain a documented change management process covering changes to information systems and processing facilities, requiring appropriate risk assessment, testing and authorisation prior to deployment. Changes are logged and tracked through a controlled workflow, with defined approval gates commensurate with the significance and risk of the change, and separation between development, testing and production activities where applicable. We review the effectiveness of this process through our internal audit programme and management review, refining procedures as our environment and tooling evolve. This control operates within the scope of our certified ISMS and is examined by our certification body at every surveillance and recertification audit.

Control 8.33

Test information

ISO/IEC 27001:2022 Annex A control 8.33 addresses how test information is selected, protected and managed so that testing activities are effective without exposing sensitive or operational data to unnecessary risk. It expects organisations to control the use of production or live data in test environments and to apply appropriate safeguards, such as anonymisation, masking, or access restrictions, when such data is used for testing purposes.

We maintain a documented approach to selecting and handling test information that ensures test environments and datasets are appropriate for their purpose while protecting sensitive or operational data. Where information derived from production systems is used for testing, we apply controls such as data minimisation, sanitisation, or restricted access to limit exposure. Access to test environments and test data is governed by the same access management and change control processes that apply across our ISMS. This control operates within the scope of our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, through which we continue to mature our practices for handling test information.

Control 8.34

Protection of information systems during audit testing

ISO/IEC 27001:2022 Annex A 8.34 addresses the protection of information systems during audit testing and other assurance activities, requiring that any technical testing or verification of live operational systems be planned and formally agreed with appropriate management before it takes place. The intent is to ensure that audits, vulnerability scans, or similar assurance work provide meaningful assurance without disrupting operations, corrupting data, or creating unintended security exposure.

We maintain a documented process for planning and authorising audit testing and other technical assurance activities that touch operational systems, including internal audits, vulnerability assessments, and independent security testing. Before any such activity takes place, scope, timing, and access requirements are agreed with the relevant system or business owners to prevent adverse impact on production services. Testing is conducted using controlled access, monitored execution, and, where appropriate, non-production or replica environments to limit risk to live data and services. This process operates within our certified ISMS and is reviewed as part of our ongoing internal audit and management review cycle, and it is examined by our certification body at every surveillance and recertification audit. We continue to refine our approach to testing coordination and risk management as part of our continual improvement practice.

Reporting a security concern

If you believe you have found a vulnerability or a security issue involving our services, please e-mail tony.aiello@obix.com. We acknowledge reports promptly and keep reporters informed.