ISO/IEC 27001:2022 Compliance
iSamic adheres to the international standard for Information Security Management Systems (ISMS), ensuring the highest level of data protection and security for our platform and mobile applications.
What is ISO 27001?
The global gold standard for information security management
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive company and customer information, ensuring confidentiality, integrity, and availability.
Confidentiality
Ensuring information is accessible only to authorized individuals and systems
Integrity
Maintaining accuracy and completeness of information and processing methods
Availability
Ensuring authorized users have access to information and assets when needed
How iSamic Complies
Our comprehensive approach to information security management
Security Controls (Annex A)
93 security controls across 4 categories
Organizational Controls
Information security policies, asset management, access control policies
People Controls
Background verification, security awareness training, disciplinary process
Physical Controls
Physical security perimeters, secure areas, equipment security
Technological Controls
Access control, cryptography, network security, secure development
Data Protection
Protecting audit data and user information
Encryption in Transit
TLS 1.3 protocol
Encryption at Rest
AES-256 encryption
Security Audits
Regular penetration testing
Backup & Recovery
Disaster recovery procedures
Access Logging
Comprehensive audit trails
24/7 Monitoring
Real-time threat detection
Access Control
Multi-layered authentication and authorization
AWS Cognito for user authentication and identity management
Role-based access control (RBAC) for system features
Multi-factor authentication (MFA) support
Session timeout and automatic logout
Password policies enforcing complexity requirements
Incident Management
Detecting and responding to security incidents
24/7 Monitoring
Continuous security monitoring and alerting systems
Response Procedures
Documented incident response and escalation paths
Regular Drills
Security incident drills and tabletop exercises
Continuous Improvement
Post-incident analysis and lessons learned
Official ISO 27001 Resources
Authoritative sources and certification bodies
Standards & Guidelines
ISO Official Website
International Organization for Standardization
Official ISO 27001:2022 standard documentation and comprehensive information
Visit ISO.org βISO 27001 Implementation Guide
Comprehensive implementation resources
Detailed guide on implementing ISO 27001 ISMS in your organization
Read Guide βNIST Cybersecurity Framework
U.S. National Institute of Standards
Complementary framework for managing cybersecurity risks
Visit NIST βSANS Security Resources
Security training and certification
Security best practices and ISO 27001 training resources
Visit SANS βCertification Bodies
ποΈBSI Group
British Standards Institution
πSGS
SociΓ©tΓ© GΓ©nΓ©rale de Surveillance
πΏπ¦SABS
South African Bureau of Standards
βSANAS
South African National Accreditation System
Questions About Our Security?
For security-related inquiries or to request our security documentation, please contact our information security team.
Contact Security Team