Information Security Program

ISO 27001:2022 Compliance Framework

ISO 27001:2022 Aligned

Program Overview

Our Information Security Management System (ISMS) is designed and implemented in accordance with ISO/IEC 27001:2022 international standard. This framework ensures comprehensive protection of information assets through systematic risk management, continuous improvement, and stakeholder confidence.

Confidentiality

Ensuring information is accessible only to authorized individuals

Integrity

Safeguarding accuracy and completeness of information

Availability

Ensuring authorized users have access when needed

A.5 - Organizational Controls

A.5.1 - Information Security Policies

Documented policies approved by management

Implemented

A.5.2 - Information Security Roles

Clear assignment of security responsibilities

Implemented

A.5.3 - Segregation of Duties

Separation of incompatible duties

Implemented
A.8 - Asset Management

A.8.1 - Asset Inventory

Comprehensive inventory of information assets

Implemented

A.8.2 - Information Classification

Classification scheme based on sensitivity

Implemented

A.8.3 - Media Handling

Secure handling of removable media

Implemented
A.9 - Access Control

A.9.1 - Access Control Policy

Business requirements for access control

Implemented

A.9.2 - User Access Management

Registration, provisioning, and deprovisioning

Implemented

A.9.3 - User Responsibilities

Password management and secure authentication

Implemented

A.9.4 - System Access Control

Secure log-on procedures and authentication

Implemented
A.10 - Cryptography

A.10.1 - Cryptographic Controls

Use of encryption to protect information

Implemented

A.10.2 - Key Management

Secure generation, storage, and destruction of keys

Implemented
A.12 - Operations Security

A.12.1 - Operational Procedures

Documented operating procedures

Implemented

A.12.2 - Protection from Malware

Detection, prevention, and recovery controls

Implemented

A.12.3 - Backup

Regular backup and restoration testing

Implemented

A.12.4 - Logging and Monitoring

Security event logging and monitoring

Implemented

A.12.5 - Software Control

Control of operational software

Implemented

A.12.6 - Vulnerability Management

Technical vulnerability management

Implemented
A.13 - Communications Security

A.13.1 - Network Security

Security of networks and network services

Implemented

A.13.2 - Information Transfer

Secure information transfer policies

Implemented
A.16 - Incident Management

A.16.1 - Incident Response

Procedures for handling security incidents

Implemented

A.16.2 - Evidence Collection

Collection and preservation of evidence

Implemented
A.17 - Business Continuity

A.17.1 - Continuity Planning

ICT continuity planning

Implemented

A.17.2 - Redundancies

Availability of information processing facilities

Implemented
A.18 - Compliance

A.18.1 - Legal Compliance

Identification of applicable legislation

Implemented

A.18.2 - Security Reviews

Independent review of information security

Implemented

Security Contact Information

Chief Information Security Officer (CISO)

ciso@servicelog.app

Security Incident Reporting

security@servicelog.app

Data Protection Officer (DPO)

dpo@servicelog.app

Vulnerability Disclosure

bugbounty@servicelog.app

Cookie Preferences

We use cookies to improve your experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. You can also reject non-essential cookies by clicking "Reject All".