Scope (draft): the Prime/Axalar ERP platform β on-prem services (Proxmox VMs: app-01, edge-01, files-drive/MinIO, Postgres, mail-01) + Firebase (Auth/Firestore/Storage) + Cloudflare edge, and the staff who operate them.
Updated after drafting the full policy set + registers: the documentation is now substantially complete β most controls are "Partial" (documented, pending management approval + ~3 months of operating evidence). The ~10 true Gaps need actual doing/tooling, not just a policy: tested backup/restore, vulnerability scanning, malware/EDR, DLP, SAST in CI, internal audit + independent review (performed), and physical-monitoring evidence.
| # | Control | Status | Note / evidence |
|---|---|---|---|
| 5.1 | Policies for information security | Partial | Full policy set drafted (12 policies below); needs management approval |
| 5.2 | InfoSec roles & responsibilities | Partial | Roles exist (admin/super); not formally assigned an ISMS owner |
| 5.3 | Segregation of duties | Partial | Role-based access; document approval workflows |
| 5.4 | Management responsibilities | Gap | Need management commitment + review cadence |
| 5.5 | Contact with authorities | Gap | Document FTA/MoF/CERT contacts |
| 5.6 | Contact with special interest groups | Partial | OpenPeppol membership planned |
| 5.7 | Threat intelligence | Gap | Mail-health monitor exists; formalize threat feeds |
| 5.8 | InfoSec in project management | Gap | Add security gate to project workflow |
| 5.9 | Inventory of assets | Partial | Infra known (Proxmox/VM map); formalize a register |
| 5.10 | Acceptable use of assets | Gap | Draft Acceptable Use Policy |
| 5.11 | Return of assets | Partial | Offboarding exists (HR); add asset return step |
| 5.12 | Classification of information | Gap | Draft Data Classification Policy |
| 5.13 | Labelling of information | Gap | Follows classification |
| 5.14 | Information transfer | Partial | TLS + presigned URLs; document transfer rules |
| 5.15 | Access control | Impl | Firebase Auth + Firestore rules + roles |
| 5.16 | Identity management | Impl | Firebase Auth; chat-identity merges done |
| 5.17 | Authentication information | Partial | MFA (3 login methods, phone OTP); enforce universally |
| 5.18 | Access rights | Partial | Roles/permissions; add periodic access reviews |
| 5.19 | InfoSec in supplier relationships | Partial | Firebase/Cloudflare/Mailjet; document supplier register |
| 5.20 | Security in supplier agreements | Gap | Capture DPAs/SLAs |
| 5.21 | Security in ICT supply chain | Gap | npm/dependency provenance |
| 5.22 | Monitoring of supplier services | Partial | Mail-health monitor; broaden |
| 5.23 | Security for cloud services | Partial | Firebase/GCP/Cloudflare configured; document |
| 5.24 | Incident management planning | Partial | Incident playbooks exist (outages); formalize |
| 5.25 | Assessment of security events | Partial | Board/monitor; define triage |
| 5.26 | Response to incidents | Partial | Demonstrated (mail/calling/deploy recoveries) |
| 5.27 | Learning from incidents | Impl | Incident memory records + post-mortems |
| 5.28 | Collection of evidence | Gap | Define forensic evidence procedure |
| 5.29 | InfoSec during disruption | Partial | See ISO 22301 BIA below |
| 5.30 | ICT readiness for continuity | Partial | VM snapshots; needs tested DR |
| 5.31 | Legal/regulatory requirements | Partial | UAE VAT/e-invoicing tracked; build a register |
| 5.32 | Intellectual property rights | Partial | License inventory needed |
| 5.33 | Protection of records | Partial | Firestore/Postgres; define retention |
| 5.34 | Privacy & protection of PII | Gap | Draft Privacy Policy + PII map (UAE PDPL) |
| 5.35 | Independent review of InfoSec | Gap | Schedule internal audit |
| 5.36 | Compliance with policies | Gap | Follows once policies approved |
| 5.37 | Documented operating procedures | Partial | Deploy/infra docs in memory; formalize runbooks |
| # | Control | Status | Note / evidence |
|---|---|---|---|
| 6.1 | Screening | Partial | HR onboarding; add background checks |
| 6.2 | Terms & conditions of employment | Partial | Contracts module; add InfoSec clauses |
| 6.3 | Awareness, education & training | Gap | Build a security-awareness programme |
| 6.4 | Disciplinary process | Partial | HR process exists; reference in policy |
| 6.5 | Responsibilities after termination | Impl | Offboarding revokes access (3-store) |
| 6.6 | Confidentiality / NDAs | Partial | Add NDA to onboarding |
| 6.7 | Remote working | Gap | Draft Remote Working Policy |
| 6.8 | Security event reporting | Partial | In-app feedbackβtasks; define channel |
| # | Control | Status | Note / evidence |
|---|---|---|---|
| 7.1 | Physical security perimeters | Partial | On-prem Proxmox site; document perimeter |
| 7.2 | Physical entry | Partial | Site access controls β document |
| 7.3 | Securing offices/rooms | Partial | Document server-room security |
| 7.4 | Physical security monitoring | Gap | CCTV/alarm evidence needed |
| 7.5 | Physical & environmental threats | Gap | Fire/flood/power assessment |
| 7.6 | Working in secure areas | N/A | If no classified secure areas |
| 7.7 | Clear desk & clear screen | Gap | Add to Acceptable Use Policy |
| 7.8 | Equipment siting & protection | Partial | Rack/UPS; document |
| 7.9 | Security of assets off-premises | Partial | Laptops (mac mini build host); MDM? |
| 7.10 | Storage media | Partial | Disk handling policy |
| 7.11 | Supporting utilities | Partial | UPS/power; document |
| 7.12 | Cabling security | N/A | Scope-dependent |
| 7.13 | Equipment maintenance | Partial | Proxmox maintenance; log it |
| 7.14 | Secure disposal / re-use | Gap | Media sanitisation procedure |
| # | Control | Status | Note / evidence |
|---|---|---|---|
| 8.1 | User endpoint devices | Gap | Add endpoint/MDM policy |
| 8.2 | Privileged access rights | Partial | admin/super roles; review + log |
| 8.3 | Information access restriction | Impl | Firestore rules + role checks |
| 8.4 | Access to source code | Partial | Repo access; the stale-clone incident shows control gap |
| 8.5 | Secure authentication | Impl | Firebase Auth + MFA/OTP |
| 8.6 | Capacity management | Partial | Cloud-run min-instances; monitor |
| 8.7 | Protection against malware | Gap | AV/EDR + Drive scan policy |
| 8.8 | Technical vulnerability mgmt | Gap | Add dependency + infra scanning |
| 8.9 | Configuration management | Partial | Docker/Caddy; baseline + drift control |
| 8.10 | Information deletion | Partial | Trash/retention exists; document |
| 8.11 | Data masking | Partial | Bank acct masking present; extend |
| 8.12 | Data leakage prevention | Gap | DLP controls |
| 8.13 | Information backup | Partial | Backup & BCP drafted; restore-testing still required (key evidence gap) |
| 8.14 | Redundancy of facilities | Partial | edge-01/app-01; document HA |
| 8.15 | Logging | Partial | Board + audit logs; central retention |
| 8.16 | Monitoring activities | Partial | Mail-health + heartbeats; broaden SIEM |
| 8.17 | Clock synchronization | Partial | NTP on VMs; confirm |
| 8.18 | Privileged utility programs | Partial | Restrict + log |
| 8.19 | Software on operational systems | Partial | Controlled deploys; formalize |
| 8.20 | Networks security | Partial | Cloudflare + on-prem; document |
| 8.21 | Security of network services | Partial | TLS/TURN; document |
| 8.22 | Segregation of networks | Impl | 10.255.254.x internal; CF bridge edge |
| 8.23 | Web filtering | N/A | Scope-dependent |
| 8.24 | Use of cryptography | Impl | TLS everywhere; presigned URLs; Fernet vault |
| 8.25 | Secure development life cycle | Gap | Formalize SDLC |
| 8.26 | Application security requirements | Partial | Rules/validation; document |
| 8.27 | Secure architecture principles | Partial | On-prem + cloud architecture documented |
| 8.28 | Secure coding | Partial | Add coding standards + review gates |
| 8.29 | Security testing in dev | Gap | Add SAST/DAST |
| 8.30 | Outsourced development | N/A | If none |
| 8.31 | Separation of dev/test/prod | Partial | erp-live/erp-staging exist; korasai dev |
| 8.32 | Change management | Partial | Change & Release policy drafted; enforce single-source-of-truth + evidence |
| 8.33 | Test information | Partial | Avoid prod data in test; document |
| 8.34 | Protection during audit testing | N/A | Define when audits begin |
| Service | Impact if down | RTO (target) | RPO (target) | Continuity basis |
|---|---|---|---|---|
| ERP web (dash.primerp.ai) | High β ops halt | 4 h | 1 h | edge-01/app-01 + CF; VM snapshots |
| Prime Mail | High β comms | 4 h | 15 min | Stalwart on VM115; Mailjet outbound; replica |
| Prime Drive (files) | Medium | 8 h | 1 h | MinIO + on-prem drive service |
| Calling (WebRTC/TURN) | Medium | 8 h | n/a | TURN rotator; multi-server |
| Firestore/Auth (Firebase) | High | 2 h | ~0 (managed) | Google-managed SLA |
Gaps to close: formal BIA sign-off, tested backup/restore (currently snapshots, untested RPO), a written DR runbook per service, and a continuity test schedule. Incident history (mail-01 disk I/O, app-01 host fault, calling/TURN, deploy conflict) already provides post-mortem evidence (control 5.27 β).
| Policy | Status | Covers (Annex A) |
|---|---|---|
| Information Security Policy (master) | Drafted | 5.1, 5.2, 5.4, 5.36 |
| Access Control Policy | Drafted | 5.15β5.18, 8.2β8.5 |
| Acceptable Use Policy | Drafted | 5.10, 7.7, 8.1 |
| Cryptography Policy | Drafted | 8.24 |
| Data Classification & Handling | Drafted | 5.12β5.14, 5.33 |
| Supplier / Cloud Security Policy | Drafted | 5.19β5.23 |
| Incident Response Plan | Drafted | 5.24β5.28, 6.8 |
| Change & Release Management | Drafted | 8.32, 8.19, 8.31 |
| Secure Development Policy | Drafted | 8.25β8.29 |
| Backup & Business Continuity Plan | Drafted | 8.13, 5.29, 5.30 |
| Privacy / PII Policy (UAE PDPL) | Drafted | 5.34 |
| HR Security Policy | Drafted | 6.1β6.6 |
Axalar establishes, operates and continually improves an Information Security Management System (ISMS) conforming to ISO/IEC 27001:2022 to protect the confidentiality, integrity and availability of information processed by the Prime platform and its customers.
All information assets, systems and personnel supporting the Prime/Axalar ERP platform: on-prem services (Proxmox VMs β app-01, edge-01, files-drive/MinIO, Postgres, mail-01), Firebase (Auth/Firestore/Storage), Cloudflare edge, and supporting cloud services.
Protect customer + business data; meet UAE legal/regulatory obligations (VAT, e-invoicing, PDPL); maintain service availability per the BIA; and achieve + maintain ISO 27001 / 22301 certification.
Least-privilege access; defence in depth; encryption in transit and at rest; secure-by-design development; risk-based decision-making; and continual improvement via internal audit and management review.
Top management provides resources and reviews ISMS performance. An ISMS Owner / CISO (to be appointed) maintains the risk register, SoA and this policy set. All staff comply with policies and report security events.
Risks to information assets are identified, assessed and treated; residual risk is accepted by management. The Statement of Applicability records control applicability and status.
Non-compliance is handled via the HR disciplinary process. This policy is reviewed at least annually and after significant change. Approved by: ______ Β· Date: ______ Β· Version 0.1 (draft).
Purpose/scope: govern who may access Prime systems and data, and how. Covers Firebase Auth, Firestore rules, on-prem services and admin access. (A.5.15β5.18, A.8.2β8.5)
Purpose/scope: rules for acceptable use of Prime systems, devices and data by all staff. (A.5.10, A.7.7, A.8.1)
Purpose/scope: protect data with appropriate cryptography. (A.8.24)
Purpose/scope: classify and handle information by sensitivity. (A.5.12β5.14, A.5.33)
Purpose/scope: manage security risk from suppliers and cloud services. (A.5.19β5.23)
Purpose/scope: detect, respond to and learn from security incidents. (A.5.24β5.28, A.6.8)
Purpose/scope: control changes to production safely. (A.8.32, A.8.19, A.8.31) β directly addresses the recurring stale-deploy incident.
Purpose/scope: build security into the SDLC. (A.8.25β8.29)
Purpose/scope: ensure data is recoverable and critical services continue. (A.8.13, A.5.29β5.30) β see the BIA above.
Purpose/scope: protect personal data per the UAE Personal Data Protection Law. (A.5.34)
Purpose/scope: security across the employment lifecycle. (A.6.1β6.6)
| Asset | Type | Classification | Location / owner |
|---|---|---|---|
Firestore (project axalar) | Database β customer + business data | Restricted | Firebase / GCP Β· IT |
| Firebase Auth | Identity store | Restricted | Firebase Β· IT |
| app-01 / edge-01 (Proxmox) | App + edge servers | Confidential | On-prem 10.255.254.x Β· IT |
| files-drive (MinIO) | Object storage β documents | Confidential | On-prem Β· IT |
| Postgres (10.255.254.112) | Drive/HR/microservice DB | Restricted | On-prem Β· IT |
| mail-01 (Stalwart, VM115) | Mail store | Restricted | On-prem Β· IT |
| Source repository (axalar-erp) | Source code + IaC | Confidential | Dev workstations Β· Eng |
| Secrets / keys (Firebase, Fernet vault) | Credentials | Restricted | Vaults Β· IT |
| Cloudflare zone + DNS | Edge / DNS | Confidential | Cloudflare Β· IT |
| Risk | L/I | Treatment | Control |
|---|---|---|---|
| Stale-clone deploy overwrites production | H/M | Change & Release policy β single source of truth, no out-of-date deploys | 8.32 |
| Data loss β backups untested | M/H | Backup plan + scheduled restore tests | 8.13 |
| Credential compromise / account takeover | M/H | MFA, access reviews, secret vaulting | 5.17, 8.5 |
| Supplier/cloud outage (Firebase/CF/mail) | M/M | BIA, redundancy, monitoring | 5.30, 8.14 |
| PII breach (UAE PDPL exposure) | L/H | Classification, encryption, Privacy policy | 5.34, 8.24 |
| Unpatched vulnerability exploited | M/M | Vulnerability + patch management | 8.8 |
| Malware via Drive upload | M/M | Upload scanning + endpoint protection | 8.7 |
| Insider misuse of privileged access | L/H | Least privilege, logging, segregation | 8.2, 8.15 |
| Supplier | Service | Data | Assurance |
|---|---|---|---|
| Google / Firebase (GCP) | Auth, Firestore, Storage, Functions | Restricted | ISO 27001 / SOC 2 (Google) |
| Cloudflare | Edge, DNS, WAF, tunnels | Confidential (traffic) | ISO 27001 / SOC 2 |
| Mailjet | Outbound email relay | Confidential (mail metadata) | ISO 27001 / GDPR |
| Proxmox / hosting | On-prem virtualization | Restricted (hosts data) | Self-managed β document physical controls |
| OpenPeppol + ASP (planned) | E-invoice transmission (AS4) | Confidential (invoices) | Peppol-accredited (to select) |