Breadcrumbs

ISO 27001 Information Security Management System

ISO 27001:2022 requirements (Clauses 4–10) establish a structured framework that embeds information security into business strategy through context analysis, leadership accountability, risk-based planning, resource support, operational controls, performance evaluation, and continuous improvement. Together, these clauses ensure a systematic approach to secure information, measurable system that strengthens resilience, trust, and continuous improvements. 

Clause 4 Context of the Organization

4.1

Understanding the organization and its context 

We identify internal and external issues affecting the ISMS: legal/regulatory obligations (GDPR, CCPA, Swedish law), client contractual requirements, SaaS and hosting dependencies, and organizational changes. Asset and risk owners continuously evaluate threats and vulnerabilities per ISO 27005, feeding context into risk assessment and the Statement of Applicability. 

For more information see Information Security Policy and Risk Management Policy https://trust.safeture.com/policies-and-documents

4.2

Understanding the needs and expectations of interested parties 

Interested parties include clients, end users, clients, employees, partners, regulators, and certification bodies. We determine which requirements are addressed through the ISMS - contractual (Terms, DPA, SLA), legal (privacy laws), and operational (security questionnaires). Regulatory tracking uses open-source tools and tools such as OneTrust Data Guidance. 

For more information see Information Security Policy, Risk Management Policy https://trust.safeture.com/policies-and-documents and Terms of Service https://www.safeture.com/terms-of-service/

4.3

Determining the scope of the information security management system 

ISMS scope covers our SaaS platform, supporting operations, personnel, and suppliers processing client data—hosted in Sweden with documented boundaries. Scope considers internal/external issues, interested-party requirements, and dependencies on certified hosting providers. Scope is documented and available to auditors and clients on request. 

For more information see Information Security Policy, Statement of Applicability https://trust.safeture.com/policies-and-documents

4.4

Information security management system  

We establish, implement, maintain, and continually improve an ISO 27001:2022-certified ISMS, including processes for risk assessment, control operation, monitoring, audit, and improvement. The ISMS integrates with day-to-day operations, product development, and client service delivery. 

For more information see Information Security Policy and Statement of Applicability https://trust.safeture.com/policies-and-documents

Clause 5 Leadership

5.1

Leadership and commitment 

Top management demonstrates commitment through approved security policy, resource allocation, biannual management review, integration of security into processes, and communication of importance of ISMS conformance. Security goals and objectives align with strategic direction (availability, incident limits, awareness). 

For more information see Information Security Policy and Business Continuity Plan https://trust.safeture.com/policies-and-documents

5.2

Policy 

Top management establishes the Information Security Policies appropriate to our purpose, including objectives framework, commitment to applicable requirements, and continual improvement. The policies are documented, communicated internally (onboarding, annual training, Teams), and shared externally as the public policy version. 

For more information see policies and documents https://trust.safeture.com/policies-and-documents

5.3

Organizational roles, responsibilities and authorities 

Responsibilities and authorities are assigned to Security Steering Group (SSG) that consists of DPO and Information Security Manager (ISM) CEO, team leads, asset owners and risk owners. Our ISM is responsible for ISMS conformity; management is informed of ISMS performance through SSG reporting and biannual management review. Records of training, skills, experience, and qualifications is kept in our ISMS. 

For more information see Information Security Policy https://trust.safeture.com/policies-and-documents

Clause 6 Planning

6.1

Actions to address risks and opportunities 

6.1.1

General 

Planning considers context (4.1) and interested-party requirements (4.2), defines risks/opportunities affecting ISMS outcomes, and plans actions integrated into ISMS processes with effectiveness evaluation and continual improvements. 

6.1.2

Information security risk assessment  

Documented risk assessment per ISO/IEC 27005: risk criteria, consistent repeatable assessments, identification of CIA risks and risk owners, analysis/evaluation, and retention of documented results. Asset inventory is central; assessments run continuously and yearly. 

6.1.3

Information security risk treatment 

In our ISMS and Jira we keep records of all assets, and the risk treatments. Treatment selects controls, compares against Annex A (no omissions—all 93 applicable in SoA), produces Statement of Applicability with justification, implements risk treatment plan, and obtains risk owner approval of residual risk. 

Risk Management Policy https://trust.safeture.com/policies-and-documents

6.2

Information security objectives and planning to achieve them 

Measurable goals include platform availability per month, no major incidents and max three minor per quarter. Measures and objectives include improved control effectiveness, Security Steering Group (SSG) review biannually, and 100% annual awareness participation. Planning defines actions, resources, owners, timelines, and evaluation. 

Information Security Policy https://trust.safeture.com/policies-and-documents, https://www.safeture.com/terms-of-service/ Section 5 - Service level

6.3

Planning of changes 

Changes to the ISMS are carried out in a planned manner. To prevent security gaps a formal risk assessment and authorization prior to implementation is in place, this ensures the continuous integrity of our ISMS.  

Clause 7 Support

7.1

Resources 

Resources for ISMS establishment and operation are determined and provided Security Steering Group (SSG), ISM Information Security Manager (ISM), DPO, operations, security tooling, audit budget, training. 

7.2

Competence

Competence is ensured for roles affecting security (developers, operations, support with client data) through education, experience, onboarding, and annual training; evidence retained.  

7.3

Awareness 

Personnel are aware of the Information Security Policy, their contribution to ISMS effectiveness, and implications of non-conformance - via onboarding and annual awareness training for all employees including phishing exercises. In addition, e-learning are mandatory for all employees. 

7.4

Communication 

Internal/external ISMS communication is defined: internal via Teams and training; external via email, public policies, DPA, and client security documentation on request. 

For more information see policies and documents https://trust.safeture.com/policies-and-documents

7.5.1-3 

Documented information 

ISMS includes required documented information (policies, SoA, procedures, records) plus documents needed for effectiveness (work instructions, BCP/DRP, SSDLC, asset inventory). 

Documents have identification, format, review/approval (owner, approver, version, date in revision history and classification). 

 Documented information is available when needed, protected for confidentiality/integrity, version-controlled, retained per policy, and external documents (standards, regulations) identified and controlled. 

For more information see policies and documents https://trust.safeture.com/policies-and-documents

Clause 8 Operation

8.1

Operational planning and control

Processes to meet requirements and Clause 6 actions are planned, implemented, and controlled (SSDLC, change management, operations and ISMS). Planned changes are controlled; unintended changes reviewed. Supplier/cloud services are controlled via Supplier Security Policy and DPAs.  

For more information see policies and documents https://trust.safeture.com/policies-and-documents

8.2

Information security risk assessment 

Risk assessments performed at planned intervals and when significant changes occur; results documented and retained. 

For more information see Risk Management Policy https://trust.safeture.com/policies-and-documents

8.3

Information security risk treatment 

Risk treatment plan is implemented; results documented (asset inventory, SoA updates, Jira risk actions, audit evidence). 

Clause 9 Performance Evaluation

9.1

Monitoring, measurement, analysis and evaluation  

Goals, Measures and objectives including control effectiveness is review biannually by Security Steering Group (SSG). ISMS performance is monitored: uptime (third-party checks), incident metrics, audit results, control effectiveness, log/SIEM monitoring. Results analyzed and evaluated; evidence retained. 

ISMS performance is monitored: uptime (third-party checks), incident metrics, audit results, control effectiveness, log/SIEM monitoring. Results analyzed and evaluated; evidence retained. 

Goals 

Major incidents 

Minor incidents  

Uptime 

Measures and Objectives 

External pentest 

External audit 

DR test 

etc. 

For more information see Auditing and Monitoring Policy and Information Security Policy https://trust.safeture.com/policies-and-documents

9.2.1-2 

Internal audit 

Quarterly internal audits cover ISO 27001 aspects, to verify that our ISMS conforms to ISO 27001, own requirements and is effectively maintained; the program considers process importance and prior findings; objective auditors; results reported to Security Steering Group (SSG), management; evidence retained. 

9.3

Management review 

Top management reviews ISMS at planned intervals (biannually) for continuing suitability, adequacy, and effectiveness.  

Reviews include prior actions, context/interested-party changes, security performance trends (nonconformities, monitoring, audits, objectives), stakeholder feedback, risk assessment/treatment status, and improvement opportunities. 

Results include decisions on continual improvement and ISMS changes; documented evidence retained. Standing agenda as follows: 

  1. Protocol of Last Management Review 

  1. Information Security Goals 

  1. High/Medium Risk Assets 

  1. Document Control 

  1. BCP and Organization 

  1. Sub Suppliers  

  1. Changes in Platform and Landscape 

  1. Feedback from Interested Parties 

  1. Internal Audit 

  1. Previous External Audit 

  1. Opportunities for Continuous Improvement 

  1. Way Forward

Clause 10 Improvement

10.1

Continual improvement 

ISMS suitability, adequacy, and effectiveness are continually improved through audits, incident lessons learned, management review, and organizational learning culture encouraged by management.  

Security Steering Group (SSG) is committed to continuous improvement, please see goals, measures and objectives below. 

10.2

Nonconformity and corrective action 

Nonconformities (including audit findings and control gaps) are reacted to, root-caused, corrected, and reviewed for effectiveness; documented in ISMS - Jira and incident processes where applicable.