Scott Labz

Information Security Management Standard (ISMS)

Last updated: 26 July 2026

1. Purpose

Keep our code, servers, people, and customers safe while meeting SOC 2 expectations - without turning security into rocket science.

2. Scope

Applies to all ScottLabz staff, contractors, systems, code, data, and self-hosted infrastructure.

3. Our Security Basics

  • Common Control Framework (CCF): One master list of controls mapped to SOC 2, ISO 27001, and NIST, owned and followed directly on every engagement.
  • Defense-in-Depth: Identity → Device → Code → Data → Infra → Monitoring.
  • Least Privilege: Nobody gets more access than they need, for longer than they need.
  • Security by Default: New services ship locked-down; open only what’s required.

4. Roles & Responsibilities

Role What They Do
Founder Owns the ISMS end-to-end - sets policy, reviews risk, and approves exceptions personally.
Contractors (when engaged) Follow this Standard on any engagement, report anything shady in <24 hrs.

5. Policy Statements

5.1 Governance

  • Policy & Standard Review: Every 12 months or major change, whichever comes first. Reviewed and signed off personally.
  • Exception Management: Submit ticket → reviewed and approved directly → expiry date set → audit monthly.
  • Quarterly Security Review: Self-review of threats, program scorecard, and resourcing.

5.2 Risk & Compliance

  • Annual risk assessment mapped to SOC 2 TSC; results drive roadmap.
  • CCF lives in the repo security/ccf.md; pull requests update controls.

5.3 Asset & Access Management

  • All laptops: full-disk encryption, auto-lock 5 min, MDM enforced.
  • Prod access: SSO + MFA + Just-in-Time (max 8 hrs).
  • Terminate access < 24 hrs after off-boarding.

5.4 Data Handling

  • No regulated data stored; treat customer code as Confidential.
  • Encrypt data in transit (TLS 1.2+) and at rest (AES-256+).
  • Backups daily; test restores quarterly.

5.5 Secure Development

  • All code reviewed by a peer and scanned (SAST/OSS) pre-merge.
  • Prod changes use CI/CD with automated tests and approvals.
  • Security bugs = P1; fix or mitigate within 30 days.

5.6 Infrastructure & Operations

  • Servers live in managed data centers; we harden OS images, disable unused services.
  • Patching: critical < 7 days, high < 30 days.
  • Logs centralised, immutable 365 days, monitored 24×7 (alerts to PagerDuty).

5.7 Monitoring & Incident Response

  • Detect → Triage (15 min) → Contain → Eradicate → Post-mortem (72 hrs).
  • IR playbooks stored in security/ir/ repo; tabletop exercise twice a year.

5.8 Vendor & Third-Party Management

  • Security review before onboarding, then annually.
  • SOC 2 Type II or equivalent required for critical vendors.

5.9 Business Continuity & Disaster Recovery

  • BC/DR plan tested yearly; RPO = 24 hrs, RTO = 8 hrs.
  • Remote workforce ensures zero single-office dependency.

5.10 Awareness & Training

  • Security 101 within 7 days of hire, refresher yearly.
  • Phishing drills 4× per year; failure ⇒ micro-training.

5.11 Documentation & Whitepapers

  • Public whitepapers describe system purpose, design, boundaries; review at least annually.

6. Enforcement

Breaking this Standard can lead to access removal or disciplinary action - up to and including termination.

7. References

  • SOC 2 Trust Services Criteria 2024
  • NIST CSF v2.0
  • ISO/IEC 27001:2022