Information Security Management Standard (ISMS)
Last updated: 26 July 2026
1. Purpose
Keep our code, servers, people, and customers safe while meeting SOC 2 expectations - without turning security into rocket science.
2. Scope
Applies to all ScottLabz staff, contractors, systems, code, data, and self-hosted infrastructure.
3. Our Security Basics
- Common Control Framework (CCF): One master list of controls mapped to SOC 2, ISO 27001, and NIST, owned and followed directly on every engagement.
- Defense-in-Depth: Identity → Device → Code → Data → Infra → Monitoring.
- Least Privilege: Nobody gets more access than they need, for longer than they need.
- Security by Default: New services ship locked-down; open only what’s required.
4. Roles & Responsibilities
| Role | What They Do |
|---|---|
| Founder | Owns the ISMS end-to-end - sets policy, reviews risk, and approves exceptions personally. |
| Contractors (when engaged) | Follow this Standard on any engagement, report anything shady in <24 hrs. |
5. Policy Statements
5.1 Governance
- Policy & Standard Review: Every 12 months or major change, whichever comes first. Reviewed and signed off personally.
- Exception Management: Submit ticket → reviewed and approved directly → expiry date set → audit monthly.
- Quarterly Security Review: Self-review of threats, program scorecard, and resourcing.
5.2 Risk & Compliance
- Annual risk assessment mapped to SOC 2 TSC; results drive roadmap.
- CCF lives in the repo
security/ccf.md; pull requests update controls.
5.3 Asset & Access Management
- All laptops: full-disk encryption, auto-lock 5 min, MDM enforced.
- Prod access: SSO + MFA + Just-in-Time (max 8 hrs).
- Terminate access < 24 hrs after off-boarding.
5.4 Data Handling
- No regulated data stored; treat customer code as Confidential.
- Encrypt data in transit (TLS 1.2+) and at rest (AES-256+).
- Backups daily; test restores quarterly.
5.5 Secure Development
- All code reviewed by a peer and scanned (SAST/OSS) pre-merge.
- Prod changes use CI/CD with automated tests and approvals.
- Security bugs = P1; fix or mitigate within 30 days.
5.6 Infrastructure & Operations
- Servers live in managed data centers; we harden OS images, disable unused services.
- Patching: critical < 7 days, high < 30 days.
- Logs centralised, immutable 365 days, monitored 24×7 (alerts to PagerDuty).
5.7 Monitoring & Incident Response
- Detect → Triage (15 min) → Contain → Eradicate → Post-mortem (72 hrs).
- IR playbooks stored in
security/ir/repo; tabletop exercise twice a year.
5.8 Vendor & Third-Party Management
- Security review before onboarding, then annually.
- SOC 2 Type II or equivalent required for critical vendors.
5.9 Business Continuity & Disaster Recovery
- BC/DR plan tested yearly; RPO = 24 hrs, RTO = 8 hrs.
- Remote workforce ensures zero single-office dependency.
5.10 Awareness & Training
- Security 101 within 7 days of hire, refresher yearly.
- Phishing drills 4× per year; failure ⇒ micro-training.
5.11 Documentation & Whitepapers
- Public whitepapers describe system purpose, design, boundaries; review at least annually.
6. Enforcement
Breaking this Standard can lead to access removal or disciplinary action - up to and including termination.
7. References
- SOC 2 Trust Services Criteria 2024
- NIST CSF v2.0
- ISO/IEC 27001:2022
cott Labz