ISO 27001 / 22301 Readiness

Management-system documentation + evidence for ISO/IEC 27001:2022 (information security) and ISO 22301 (business continuity) β€” the long-pole prerequisites for Prime's ASP accreditation. Living tracker; the certification audit itself is performed by an external accredited body.
Status: ISMS documented Β· approval + evidence pending Updated: 2026-06-30 ← Accreditation

🧭How Certification Works

Scope (draft): the Prime/Axalar ERP platform β€” on-prem services (Proxmox VMs: app-01, edge-01, files-drive/MinIO, Postgres, mail-01) + Firebase (Auth/Firestore/Storage) + Cloudflare edge, and the staff who operate them.

Gap Assessment β€” ISO 27001:2022 Annex A (93 controls)

First-pass self-assessment against Prime's known infrastructure. Status legend: Implemented Partial Gap N/A.
18Implemented
59Partial
10Gap
6N/A

Updated after drafting the full policy set + registers: the documentation is now substantially complete β€” most controls are "Partial" (documented, pending management approval + ~3 months of operating evidence). The ~10 true Gaps need actual doing/tooling, not just a policy: tested backup/restore, vulnerability scanning, malware/EDR, DLP, SAST in CI, internal audit + independent review (performed), and physical-monitoring evidence.

Statement of Applicability

The central audit artifact β€” every Annex A control, its status, and the note/evidence. Grouped by theme.
A.5 β€” Organizational controls (37)
#ControlStatusNote / evidence
5.1Policies for information securityPartialFull policy set drafted (12 policies below); needs management approval
5.2InfoSec roles & responsibilitiesPartialRoles exist (admin/super); not formally assigned an ISMS owner
5.3Segregation of dutiesPartialRole-based access; document approval workflows
5.4Management responsibilitiesGapNeed management commitment + review cadence
5.5Contact with authoritiesGapDocument FTA/MoF/CERT contacts
5.6Contact with special interest groupsPartialOpenPeppol membership planned
5.7Threat intelligenceGapMail-health monitor exists; formalize threat feeds
5.8InfoSec in project managementGapAdd security gate to project workflow
5.9Inventory of assetsPartialInfra known (Proxmox/VM map); formalize a register
5.10Acceptable use of assetsGapDraft Acceptable Use Policy
5.11Return of assetsPartialOffboarding exists (HR); add asset return step
5.12Classification of informationGapDraft Data Classification Policy
5.13Labelling of informationGapFollows classification
5.14Information transferPartialTLS + presigned URLs; document transfer rules
5.15Access controlImplFirebase Auth + Firestore rules + roles
5.16Identity managementImplFirebase Auth; chat-identity merges done
5.17Authentication informationPartialMFA (3 login methods, phone OTP); enforce universally
5.18Access rightsPartialRoles/permissions; add periodic access reviews
5.19InfoSec in supplier relationshipsPartialFirebase/Cloudflare/Mailjet; document supplier register
5.20Security in supplier agreementsGapCapture DPAs/SLAs
5.21Security in ICT supply chainGapnpm/dependency provenance
5.22Monitoring of supplier servicesPartialMail-health monitor; broaden
5.23Security for cloud servicesPartialFirebase/GCP/Cloudflare configured; document
5.24Incident management planningPartialIncident playbooks exist (outages); formalize
5.25Assessment of security eventsPartialBoard/monitor; define triage
5.26Response to incidentsPartialDemonstrated (mail/calling/deploy recoveries)
5.27Learning from incidentsImplIncident memory records + post-mortems
5.28Collection of evidenceGapDefine forensic evidence procedure
5.29InfoSec during disruptionPartialSee ISO 22301 BIA below
5.30ICT readiness for continuityPartialVM snapshots; needs tested DR
5.31Legal/regulatory requirementsPartialUAE VAT/e-invoicing tracked; build a register
5.32Intellectual property rightsPartialLicense inventory needed
5.33Protection of recordsPartialFirestore/Postgres; define retention
5.34Privacy & protection of PIIGapDraft Privacy Policy + PII map (UAE PDPL)
5.35Independent review of InfoSecGapSchedule internal audit
5.36Compliance with policiesGapFollows once policies approved
5.37Documented operating proceduresPartialDeploy/infra docs in memory; formalize runbooks
A.6 β€” People controls (8)
#ControlStatusNote / evidence
6.1ScreeningPartialHR onboarding; add background checks
6.2Terms & conditions of employmentPartialContracts module; add InfoSec clauses
6.3Awareness, education & trainingGapBuild a security-awareness programme
6.4Disciplinary processPartialHR process exists; reference in policy
6.5Responsibilities after terminationImplOffboarding revokes access (3-store)
6.6Confidentiality / NDAsPartialAdd NDA to onboarding
6.7Remote workingGapDraft Remote Working Policy
6.8Security event reportingPartialIn-app feedback→tasks; define channel
A.7 β€” Physical controls (14)
#ControlStatusNote / evidence
7.1Physical security perimetersPartialOn-prem Proxmox site; document perimeter
7.2Physical entryPartialSite access controls β€” document
7.3Securing offices/roomsPartialDocument server-room security
7.4Physical security monitoringGapCCTV/alarm evidence needed
7.5Physical & environmental threatsGapFire/flood/power assessment
7.6Working in secure areasN/AIf no classified secure areas
7.7Clear desk & clear screenGapAdd to Acceptable Use Policy
7.8Equipment siting & protectionPartialRack/UPS; document
7.9Security of assets off-premisesPartialLaptops (mac mini build host); MDM?
7.10Storage mediaPartialDisk handling policy
7.11Supporting utilitiesPartialUPS/power; document
7.12Cabling securityN/AScope-dependent
7.13Equipment maintenancePartialProxmox maintenance; log it
7.14Secure disposal / re-useGapMedia sanitisation procedure
A.8 β€” Technological controls (34)
#ControlStatusNote / evidence
8.1User endpoint devicesGapAdd endpoint/MDM policy
8.2Privileged access rightsPartialadmin/super roles; review + log
8.3Information access restrictionImplFirestore rules + role checks
8.4Access to source codePartialRepo access; the stale-clone incident shows control gap
8.5Secure authenticationImplFirebase Auth + MFA/OTP
8.6Capacity managementPartialCloud-run min-instances; monitor
8.7Protection against malwareGapAV/EDR + Drive scan policy
8.8Technical vulnerability mgmtGapAdd dependency + infra scanning
8.9Configuration managementPartialDocker/Caddy; baseline + drift control
8.10Information deletionPartialTrash/retention exists; document
8.11Data maskingPartialBank acct masking present; extend
8.12Data leakage preventionGapDLP controls
8.13Information backupPartialBackup & BCP drafted; restore-testing still required (key evidence gap)
8.14Redundancy of facilitiesPartialedge-01/app-01; document HA
8.15LoggingPartialBoard + audit logs; central retention
8.16Monitoring activitiesPartialMail-health + heartbeats; broaden SIEM
8.17Clock synchronizationPartialNTP on VMs; confirm
8.18Privileged utility programsPartialRestrict + log
8.19Software on operational systemsPartialControlled deploys; formalize
8.20Networks securityPartialCloudflare + on-prem; document
8.21Security of network servicesPartialTLS/TURN; document
8.22Segregation of networksImpl10.255.254.x internal; CF bridge edge
8.23Web filteringN/AScope-dependent
8.24Use of cryptographyImplTLS everywhere; presigned URLs; Fernet vault
8.25Secure development life cycleGapFormalize SDLC
8.26Application security requirementsPartialRules/validation; document
8.27Secure architecture principlesPartialOn-prem + cloud architecture documented
8.28Secure codingPartialAdd coding standards + review gates
8.29Security testing in devGapAdd SAST/DAST
8.30Outsourced developmentN/AIf none
8.31Separation of dev/test/prodPartialerp-live/erp-staging exist; korasai dev
8.32Change managementPartialChange & Release policy drafted; enforce single-source-of-truth + evidence
8.33Test informationPartialAvoid prod data in test; document
8.34Protection during audit testingN/ADefine when audits begin

ISO 22301 β€” Business Continuity (BIA + RTO/RPO)

Business Impact Analysis of the critical Prime services + recovery targets. Continuity plans draw on the real incident playbooks already on record.
ServiceImpact if downRTO (target)RPO (target)Continuity basis
ERP web (dash.primerp.ai)High β€” ops halt4 h1 hedge-01/app-01 + CF; VM snapshots
Prime MailHigh β€” comms4 h15 minStalwart on VM115; Mailjet outbound; replica
Prime Drive (files)Medium8 h1 hMinIO + on-prem drive service
Calling (WebRTC/TURN)Medium8 hn/aTURN rotator; multi-server
Firestore/Auth (Firebase)High2 h~0 (managed)Google-managed SLA

Gaps to close: formal BIA sign-off, tested backup/restore (currently snapshots, untested RPO), a written DR runbook per service, and a continuity test schedule. Incident history (mail-01 disk I/O, app-01 host fault, calling/TURN, deploy conflict) already provides post-mortem evidence (control 5.27 βœ“).

Policy Library

The mandatory ISMS documents. The master Information Security Policy is drafted below; the rest are queued.
PolicyStatusCovers (Annex A)
Information Security Policy (master)Drafted5.1, 5.2, 5.4, 5.36
Access Control PolicyDrafted5.15–5.18, 8.2–8.5
Acceptable Use PolicyDrafted5.10, 7.7, 8.1
Cryptography PolicyDrafted8.24
Data Classification & HandlingDrafted5.12–5.14, 5.33
Supplier / Cloud Security PolicyDrafted5.19–5.23
Incident Response PlanDrafted5.24–5.28, 6.8
Change & Release ManagementDrafted8.32, 8.19, 8.31
Secure Development PolicyDrafted8.25–8.29
Backup & Business Continuity PlanDrafted8.13, 5.29, 5.30
Privacy / PII Policy (UAE PDPL)Drafted5.34
HR Security PolicyDrafted6.1–6.6
Information Security Policy (master) β€” draft v0.1

1. Purpose

Axalar establishes, operates and continually improves an Information Security Management System (ISMS) conforming to ISO/IEC 27001:2022 to protect the confidentiality, integrity and availability of information processed by the Prime platform and its customers.

2. Scope

All information assets, systems and personnel supporting the Prime/Axalar ERP platform: on-prem services (Proxmox VMs β€” app-01, edge-01, files-drive/MinIO, Postgres, mail-01), Firebase (Auth/Firestore/Storage), Cloudflare edge, and supporting cloud services.

3. Objectives

Protect customer + business data; meet UAE legal/regulatory obligations (VAT, e-invoicing, PDPL); maintain service availability per the BIA; and achieve + maintain ISO 27001 / 22301 certification.

4. Principles

Least-privilege access; defence in depth; encryption in transit and at rest; secure-by-design development; risk-based decision-making; and continual improvement via internal audit and management review.

5. Roles & responsibilities

Top management provides resources and reviews ISMS performance. An ISMS Owner / CISO (to be appointed) maintains the risk register, SoA and this policy set. All staff comply with policies and report security events.

6. Risk management

Risks to information assets are identified, assessed and treated; residual risk is accepted by management. The Statement of Applicability records control applicability and status.

7. Compliance & review

Non-compliance is handled via the HR disciplinary process. This policy is reviewed at least annually and after significant change. Approved by: ______ Β· Date: ______ Β· Version 0.1 (draft).

Access Control Policy β€” draft v0.1

Purpose/scope: govern who may access Prime systems and data, and how. Covers Firebase Auth, Firestore rules, on-prem services and admin access. (A.5.15–5.18, A.8.2–8.5)

  • Access is granted on least-privilege / need-to-know and role-based (engineer/supervisor/accounting/admin/super).
  • Every user has a unique identity; shared/generic accounts are prohibited.
  • MFA is required for all accounts; privileged (admin/super) access additionally logged.
  • Joiner-Mover-Leaver: access provisioned on hire, changed on role change, revoked immediately on termination (HR offboarding revokes Auth + Firestore + mail).
  • Quarterly access reviews of privileged and standard accounts; recertify or remove.
  • Secrets/keys held in managed vaults (Firebase, Fernet board vault); never in source or chat.
Acceptable Use Policy β€” draft v0.1

Purpose/scope: rules for acceptable use of Prime systems, devices and data by all staff. (A.5.10, A.7.7, A.8.1)

  • Systems are for authorised business use; no sharing of credentials or bypassing controls.
  • Clear-desk / clear-screen: lock sessions when away; no Confidential data left exposed.
  • Devices must be encrypted, patched, screen-locked and (where issued) enrolled in management.
  • No installation of unapproved software on operational systems; no use of personal cloud for company data.
  • Suspected security events reported immediately via the incident channel.
Cryptography Policy β€” draft v0.1

Purpose/scope: protect data with appropriate cryptography. (A.8.24)

  • In transit: TLS 1.2+ everywhere (Cloudflare edge, on-prem Caddy, TURN/DTLS-SRTP for calls).
  • At rest: provider-managed encryption (Firebase, GCP, MinIO) + time-limited presigned URLs for media.
  • Key management: secrets in Firebase config / Fernet-encrypted board vault; rotation on compromise; no hard-coded keys.
  • Deprecated ciphers/protocols (SSLv3, TLS 1.0/1.1, MD5/SHA-1 for signatures) are prohibited.
  • Certificates are monitored and renewed before expiry.
Data Classification & Handling β€” draft v0.1

Purpose/scope: classify and handle information by sensitivity. (A.5.12–5.14, A.5.33)

  • Classes: Public Β· Internal Β· Confidential Β· Restricted (PII, financial, credentials = Restricted).
  • Handling, sharing, storage and transfer rules scale with class; Restricted requires encryption + access logging.
  • Records retained per legal/tax requirements (UAE VAT/e-invoicing) then securely deleted.
  • Labelling applied in documents/repositories where practical.
Supplier & Cloud Security Policy β€” draft v0.1

Purpose/scope: manage security risk from suppliers and cloud services. (A.5.19–5.23)

  • All suppliers recorded in the Supplier Register with the data they process and their assurance (SOC2/ISO).
  • Security + privacy assessed before onboarding; DPAs/SLAs in place for processors of Restricted data.
  • Cloud service configurations reviewed against provider security baselines; least-privilege service accounts.
  • Supplier performance + security monitored; access revoked at contract end.
Incident Response Plan β€” draft v0.1

Purpose/scope: detect, respond to and learn from security incidents. (A.5.24–5.28, A.6.8)

  • Report: any suspected event via the incident channel; auto-signals from mail-health monitor + heartbeats.
  • Triage: severity (Low/Med/High/Critical) and impact assessed; an owner assigned.
  • Respond: contain β†’ eradicate β†’ recover, following per-service runbooks; preserve evidence.
  • Post-mortem: root cause + corrective actions recorded (existing playbooks: mail-01 disk I/O, app-01 host fault, calling/TURN, stale-deploy).
  • Regulator/customer notification where legally required.
Change & Release Management β€” draft v0.1 priority

Purpose/scope: control changes to production safely. (A.8.32, A.8.19, A.8.31) β€” directly addresses the recurring stale-deploy incident.

  • Single source of truth: one canonical repository; all deploys originate from it. No deploys from out-of-date local clones (root cause of the #49 regressions).
  • Changes follow request β†’ review β†’ approve β†’ deploy, with version bump + changelog.
  • Separate environments: dev (korasai) Β· staging (erp-staging) Β· production (erp-live); promote, don't edit-in-place.
  • Every deploy is reversible (backups/version refs) with a documented rollback.
  • Emergency changes are logged and reviewed retrospectively.
Secure Development Policy β€” draft v0.1

Purpose/scope: build security into the SDLC. (A.8.25–8.29)

  • Security requirements considered at design; threat-aware review for sensitive features (auth, payments, e-invoicing).
  • Secure coding: input validation, output encoding, parameterised queries, no secrets in code.
  • Code review before production; dependency provenance + vulnerability scanning.
  • Automated tests (e.g. the PINT-AE engine has 36 unit tests) + security testing before release.
  • No production data in development/test environments.
Backup & Business Continuity Plan β€” draft v0.1 priority

Purpose/scope: ensure data is recoverable and critical services continue. (A.8.13, A.5.29–5.30) β€” see the BIA above.

  • Backup scope: Firestore exports, Postgres, MinIO/files, mail store, VM snapshots; frequency set to meet each service RPO.
  • At least one offsite / immutable copy; backups encrypted.
  • Restore tests performed on a schedule (currently untested β€” top priority gap).
  • Per-service DR runbooks with RTO/RPO from the BIA; continuity exercises at least annually.
Privacy / PII Policy (UAE PDPL) β€” draft v0.1

Purpose/scope: protect personal data per the UAE Personal Data Protection Law. (A.5.34)

  • Maintain a PII inventory (staff, customers, contacts) and lawful basis for processing.
  • Honour data-subject rights (access, correction, deletion) and consent where required.
  • Retention limited to purpose + legal need; secure deletion thereafter.
  • Cross-border transfers assessed; breach notification per PDPL timelines.
HR Security Policy β€” draft v0.1

Purpose/scope: security across the employment lifecycle. (A.6.1–6.6)

  • Screening proportionate to role before access to Restricted data.
  • Employment terms include information-security responsibilities + an NDA.
  • Awareness training at onboarding and annually; phishing awareness.
  • Onboarding provisions least-privilege access; offboarding revokes all access (Auth + Firestore + mail, asset return).
  • Breaches handled via the disciplinary process.

Asset Register (draft)

Primary information assets in ISMS scope (A.5.9).
AssetTypeClassificationLocation / owner
Firestore (project axalar)Database β€” customer + business dataRestrictedFirebase / GCP Β· IT
Firebase AuthIdentity storeRestrictedFirebase Β· IT
app-01 / edge-01 (Proxmox)App + edge serversConfidentialOn-prem 10.255.254.x Β· IT
files-drive (MinIO)Object storage β€” documentsConfidentialOn-prem Β· IT
Postgres (10.255.254.112)Drive/HR/microservice DBRestrictedOn-prem Β· IT
mail-01 (Stalwart, VM115)Mail storeRestrictedOn-prem Β· IT
Source repository (axalar-erp)Source code + IaCConfidentialDev workstations Β· Eng
Secrets / keys (Firebase, Fernet vault)CredentialsRestrictedVaults Β· IT
Cloudflare zone + DNSEdge / DNSConfidentialCloudflare Β· IT

Risk Register (draft)

Top information-security risks + treatment. L/I = Likelihood/Impact (H/M/L).
RiskL/ITreatmentControl
Stale-clone deploy overwrites productionH/MChange & Release policy β€” single source of truth, no out-of-date deploys8.32
Data loss β€” backups untestedM/HBackup plan + scheduled restore tests8.13
Credential compromise / account takeoverM/HMFA, access reviews, secret vaulting5.17, 8.5
Supplier/cloud outage (Firebase/CF/mail)M/MBIA, redundancy, monitoring5.30, 8.14
PII breach (UAE PDPL exposure)L/HClassification, encryption, Privacy policy5.34, 8.24
Unpatched vulnerability exploitedM/MVulnerability + patch management8.8
Malware via Drive uploadM/MUpload scanning + endpoint protection8.7
Insider misuse of privileged accessL/HLeast privilege, logging, segregation8.2, 8.15

Supplier Register (draft)

Third parties processing or supporting in-scope data (A.5.19–5.23).
SupplierServiceDataAssurance
Google / Firebase (GCP)Auth, Firestore, Storage, FunctionsRestrictedISO 27001 / SOC 2 (Google)
CloudflareEdge, DNS, WAF, tunnelsConfidential (traffic)ISO 27001 / SOC 2
MailjetOutbound email relayConfidential (mail metadata)ISO 27001 / GDPR
Proxmox / hostingOn-prem virtualizationRestricted (hosts data)Self-managed β€” document physical controls
OpenPeppol + ASP (planned)E-invoice transmission (AS4)Confidential (invoices)Peppol-accredited (to select)

Recommended Next Steps

Documentation is done (policies + SoA + registers). What's left is approval, operation and the external audit.

Progress Log

Most recent first.
2026-06-30
Full ISMS documentation set drafted
Drafted all 12 policies (master ISP + Access Control, Acceptable Use, Cryptography, Data Classification, Supplier/Cloud, Incident Response, Change & Release, Secure Development, Backup & BCP, Privacy/PDPL, HR Security) and the Asset, Risk and Supplier registers. Gap assessment re-scored: 18 implemented Β· 59 partial Β· 10 gap Β· 6 N/A β€” the documentation is substantially complete. Remaining ~10 gaps are operational (tested restores, vuln scanning, EDR, DLP, SAST, internal audit) + the external audit. The in-house ISMS package is now ready for an ISMS-owner to approve and operate.
2026-06-30
ISO readiness initiated β€” gap assessment + SoA + BIA + master policy
First-pass self-assessment of all 93 ISO 27001:2022 Annex A controls (18 implemented Β· 41 partial Β· 28 gap Β· 6 N/A), an ISO 22301 BIA with RTO/RPO for the 5 critical services, a 12-policy library, and a draft master Information Security Policy. Next: appoint ISMS owner + draft the remaining policies.