Information Security Program
ISO 27001:2022 Compliance Framework
Program Overview
Our Information Security Management System (ISMS) is designed and implemented in accordance with ISO/IEC 27001:2022 international standard. This framework ensures comprehensive protection of information assets through systematic risk management, continuous improvement, and stakeholder confidence.
Confidentiality
Ensuring information is accessible only to authorized individuals
Integrity
Safeguarding accuracy and completeness of information
Availability
Ensuring authorized users have access when needed
A.5.1 - Information Security Policies
Documented policies approved by management
A.5.2 - Information Security Roles
Clear assignment of security responsibilities
A.5.3 - Segregation of Duties
Separation of incompatible duties
A.8.1 - Asset Inventory
Comprehensive inventory of information assets
A.8.2 - Information Classification
Classification scheme based on sensitivity
A.8.3 - Media Handling
Secure handling of removable media
A.9.1 - Access Control Policy
Business requirements for access control
A.9.2 - User Access Management
Registration, provisioning, and deprovisioning
A.9.3 - User Responsibilities
Password management and secure authentication
A.9.4 - System Access Control
Secure log-on procedures and authentication
A.10.1 - Cryptographic Controls
Use of encryption to protect information
A.10.2 - Key Management
Secure generation, storage, and destruction of keys
A.12.1 - Operational Procedures
Documented operating procedures
A.12.2 - Protection from Malware
Detection, prevention, and recovery controls
A.12.3 - Backup
Regular backup and restoration testing
A.12.4 - Logging and Monitoring
Security event logging and monitoring
A.12.5 - Software Control
Control of operational software
A.12.6 - Vulnerability Management
Technical vulnerability management
A.13.1 - Network Security
Security of networks and network services
A.13.2 - Information Transfer
Secure information transfer policies
A.16.1 - Incident Response
Procedures for handling security incidents
A.16.2 - Evidence Collection
Collection and preservation of evidence
A.17.1 - Continuity Planning
ICT continuity planning
A.17.2 - Redundancies
Availability of information processing facilities
A.18.1 - Legal Compliance
Identification of applicable legislation
A.18.2 - Security Reviews
Independent review of information security
Security Contact Information
Chief Information Security Officer (CISO)
ciso@servicelog.app
Security Incident Reporting
security@servicelog.app
Data Protection Officer (DPO)
dpo@servicelog.app
Vulnerability Disclosure
bugbounty@servicelog.app