ISMS context and interested parties
The analysis behind the program: the external and internal issues shaping it, every interested party and what each requires — with an honest 'addressed?' column — and the improvement opportunities that follow.
What this policy commits us to
- States plainly that one person holds every ISMS role, and that every compensating control (immutable audit log, CI gates, shared register) exists because of that.
- Tenant isolation is structural — row-level security, deny by default, verified live — rather than promised in application code.
- Honest disclosure is treated as a differentiator: the risk register is deliberately shared with procurement.
- Subprocessor data-processing terms are recorded per provider with the clause and basis they rest on, rather than counted as a single open gap.
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.