ISO 27001:2022 requirements (Clauses 4–10) establish a structured framework that embeds information security into business strategy through context analysis, leadership accountability, risk-based planning, resource support, operational controls, performance evaluation, and continuous improvement. Together, these clauses ensure a systematic approach to secure information, measurable system that strengthens resilience, trust, and continuous improvements.
Clause 4 Context of the Organization
|
|
|---|---|
|
4.1 |
Understanding the organization and its context We identify internal and external issues affecting the ISMS: legal/regulatory obligations (GDPR, CCPA, Swedish law), client contractual requirements, SaaS and hosting dependencies, and organizational changes. Asset and risk owners continuously evaluate threats and vulnerabilities per ISO 27005, feeding context into risk assessment and the Statement of Applicability. For more information see Information Security Policy and Risk Management Policy https://trust.safeture.com/policies-and-documents |
|
4.2 |
Understanding the needs and expectations of interested parties Interested parties include clients, end users, clients, employees, partners, regulators, and certification bodies. We determine which requirements are addressed through the ISMS - contractual (Terms, DPA, SLA), legal (privacy laws), and operational (security questionnaires). Regulatory tracking uses open-source tools and tools such as OneTrust Data Guidance. For more information see Information Security Policy, Risk Management Policy https://trust.safeture.com/policies-and-documents and Terms of Service https://www.safeture.com/terms-of-service/ |
|
4.3 |
Determining the scope of the information security management system ISMS scope covers our SaaS platform, supporting operations, personnel, and suppliers processing client data—hosted in Sweden with documented boundaries. Scope considers internal/external issues, interested-party requirements, and dependencies on certified hosting providers. Scope is documented and available to auditors and clients on request. For more information see Information Security Policy, Statement of Applicability https://trust.safeture.com/policies-and-documents |
|
4.4 |
Information security management system We establish, implement, maintain, and continually improve an ISO 27001:2022-certified ISMS, including processes for risk assessment, control operation, monitoring, audit, and improvement. The ISMS integrates with day-to-day operations, product development, and client service delivery. For more information see Information Security Policy and Statement of Applicability https://trust.safeture.com/policies-and-documents |
Clause 5 Leadership
|
|
|---|---|
|
5.1 |
Leadership and commitment Top management demonstrates commitment through approved security policy, resource allocation, biannual management review, integration of security into processes, and communication of importance of ISMS conformance. Security goals and objectives align with strategic direction (availability, incident limits, awareness). For more information see Information Security Policy and Business Continuity Plan https://trust.safeture.com/policies-and-documents |
|
5.2 |
Policy Top management establishes the Information Security Policies appropriate to our purpose, including objectives framework, commitment to applicable requirements, and continual improvement. The policies are documented, communicated internally (onboarding, annual training, Teams), and shared externally as the public policy version. For more information see policies and documents https://trust.safeture.com/policies-and-documents |
|
5.3 |
Organizational roles, responsibilities and authorities Responsibilities and authorities are assigned to Security Steering Group (SSG) that consists of DPO and Information Security Manager (ISM) CEO, team leads, asset owners and risk owners. Our ISM is responsible for ISMS conformity; management is informed of ISMS performance through SSG reporting and biannual management review. Records of training, skills, experience, and qualifications is kept in our ISMS. For more information see Information Security Policy https://trust.safeture.com/policies-and-documents |
Clause 6 Planning
|
|
|---|---|
|
6.1 |
Actions to address risks and opportunities |
|
6.1.1 |
General Planning considers context (4.1) and interested-party requirements (4.2), defines risks/opportunities affecting ISMS outcomes, and plans actions integrated into ISMS processes with effectiveness evaluation and continual improvements. |
|
6.1.2 |
Information security risk assessment Documented risk assessment per ISO/IEC 27005: risk criteria, consistent repeatable assessments, identification of CIA risks and risk owners, analysis/evaluation, and retention of documented results. Asset inventory is central; assessments run continuously and yearly. |
|
6.1.3 |
Information security risk treatment In our ISMS and Jira we keep records of all assets, and the risk treatments. Treatment selects controls, compares against Annex A (no omissions—all 93 applicable in SoA), produces Statement of Applicability with justification, implements risk treatment plan, and obtains risk owner approval of residual risk. Risk Management Policy https://trust.safeture.com/policies-and-documents |
|
6.2 |
Information security objectives and planning to achieve them Measurable goals include platform availability per month, no major incidents and max three minor per quarter. Measures and objectives include improved control effectiveness, Security Steering Group (SSG) review biannually, and 100% annual awareness participation. Planning defines actions, resources, owners, timelines, and evaluation. Information Security Policy https://trust.safeture.com/policies-and-documents, https://www.safeture.com/terms-of-service/ Section 5 - Service level |
|
6.3 |
Planning of changes Changes to the ISMS are carried out in a planned manner. To prevent security gaps a formal risk assessment and authorization prior to implementation is in place, this ensures the continuous integrity of our ISMS. |
Clause 7 Support
|
|
|---|---|
|
7.1 |
Resources Resources for ISMS establishment and operation are determined and provided Security Steering Group (SSG), ISM Information Security Manager (ISM), DPO, operations, security tooling, audit budget, training. |
|
7.2 |
Competence Competence is ensured for roles affecting security (developers, operations, support with client data) through education, experience, onboarding, and annual training; evidence retained. |
|
7.3 |
Awareness Personnel are aware of the Information Security Policy, their contribution to ISMS effectiveness, and implications of non-conformance - via onboarding and annual awareness training for all employees including phishing exercises. In addition, e-learning are mandatory for all employees. |
|
7.4 |
Communication Internal/external ISMS communication is defined: internal via Teams and training; external via email, public policies, DPA, and client security documentation on request. For more information see policies and documents https://trust.safeture.com/policies-and-documents |
|
7.5.1-3 |
Documented information ISMS includes required documented information (policies, SoA, procedures, records) plus documents needed for effectiveness (work instructions, BCP/DRP, SSDLC, asset inventory). Documents have identification, format, review/approval (owner, approver, version, date in revision history and classification). Documented information is available when needed, protected for confidentiality/integrity, version-controlled, retained per policy, and external documents (standards, regulations) identified and controlled. For more information see policies and documents https://trust.safeture.com/policies-and-documents |
Clause 8 Operation
|
|
|---|---|
|
8.1 |
Operational planning and control Processes to meet requirements and Clause 6 actions are planned, implemented, and controlled (SSDLC, change management, operations and ISMS). Planned changes are controlled; unintended changes reviewed. Supplier/cloud services are controlled via Supplier Security Policy and DPAs. For more information see policies and documents https://trust.safeture.com/policies-and-documents |
|
8.2 |
Information security risk assessment Risk assessments performed at planned intervals and when significant changes occur; results documented and retained. For more information see Risk Management Policy https://trust.safeture.com/policies-and-documents |
|
8.3 |
Information security risk treatment Risk treatment plan is implemented; results documented (asset inventory, SoA updates, Jira risk actions, audit evidence). |
Clause 9 Performance Evaluation
|
|
|---|---|
|
9.1 |
Monitoring, measurement, analysis and evaluation Goals, Measures and objectives including control effectiveness is review biannually by Security Steering Group (SSG). ISMS performance is monitored: uptime (third-party checks), incident metrics, audit results, control effectiveness, log/SIEM monitoring. Results analyzed and evaluated; evidence retained. ISMS performance is monitored: uptime (third-party checks), incident metrics, audit results, control effectiveness, log/SIEM monitoring. Results analyzed and evaluated; evidence retained. Goals Major incidents Minor incidents Uptime Measures and Objectives External pentest External audit DR test etc. For more information see Auditing and Monitoring Policy and Information Security Policy https://trust.safeture.com/policies-and-documents |
|
9.2.1-2 |
Internal audit Quarterly internal audits cover ISO 27001 aspects, to verify that our ISMS conforms to ISO 27001, own requirements and is effectively maintained; the program considers process importance and prior findings; objective auditors; results reported to Security Steering Group (SSG), management; evidence retained. |
|
9.3 |
Management review Top management reviews ISMS at planned intervals (biannually) for continuing suitability, adequacy, and effectiveness. Reviews include prior actions, context/interested-party changes, security performance trends (nonconformities, monitoring, audits, objectives), stakeholder feedback, risk assessment/treatment status, and improvement opportunities. Results include decisions on continual improvement and ISMS changes; documented evidence retained. Standing agenda as follows:
|
Clause 10 Improvement
|
|
|---|---|
|
10.1 |
Continual improvement ISMS suitability, adequacy, and effectiveness are continually improved through audits, incident lessons learned, management review, and organizational learning culture encouraged by management. Security Steering Group (SSG) is committed to continuous improvement, please see goals, measures and objectives below. |
|
10.2 |
Nonconformity and corrective action Nonconformities (including audit findings and control gaps) are reacted to, root-caused, corrected, and reviewed for effectiveness; documented in ISMS - Jira and incident processes where applicable. |