PoliciesTechnical & Organisational Security Measures
DOCUMENT 06 OF 12ISO 27001 / SOC 2 Alignment

Technical & Organisational Security Measures

Security controls, encryption, access management

# DOCUMENT 06: Technical & Organisational Security Measures (TOMS)

Standard: Targeting ISO 27001:2022 / SOC 2 Type II alignment
Review Cycle: Semi-annual review; updated upon material change

1. Data Encryption

  • At rest: AES-256 encryption for all stored user data and documents.
  • In transit: TLS 1.3 enforced for all data transmission between client and server.
  • Database encryption: Encrypted database volumes with key management via dedicated key management service.
  • Backup encryption: All backups encrypted with separate encryption keys.

2. Access Controls

  • Role-based access control (RBAC): Access to production data restricted to authorised personnel on a need-to-know basis.
  • Multi-factor authentication (MFA): Required for all internal administrative access.
  • Privileged access management: Elevated privileges granted on a time-limited, request-and-approval basis.
  • Contractor access: Third-party contractors sign NDAs and are granted minimum necessary access.

3. Infrastructure Security

  • Cloud infrastructure deployed on reputable cloud providers with Indian data residency commitments.
  • Network segmentation: Production, staging, and development environments fully isolated.
  • Web Application Firewall (WAF) deployed to detect and block common attacks.
  • DDoS protection via cloud-native mitigation services.
  • Regular vulnerability scanning of infrastructure components.

4. Application Security

  • Secure Software Development Lifecycle (SSDLC) with security review at each development stage.
  • Dependency scanning for known vulnerabilities in third-party libraries.
  • Annual penetration testing by qualified third-party security professionals.
  • Bug bounty programme for responsible disclosure of security vulnerabilities.
  • API authentication via OAuth 2.0 and JWT tokens with short expiry windows.

5. Organisational Measures

  • Designated Information Security Officer responsible for security governance.
  • Annual security awareness training mandatory for all employees.
  • Background verification conducted for all employees with access to production data.
  • Incident Response Plan maintained and tested annually.
  • Business Continuity and Disaster Recovery plans with defined RTO and RPO targets.

6. Data Lifecycle Management

  • Automated deletion of data upon expiry of retention periods.
  • Cryptographic erasure for data on decommissioned storage media.
  • Audit logs maintained for all data access events, retained for 12 months.

7. Vendor and Sub-Processor Security

  • All sub-processors assessed for security posture before onboarding.
  • Contractual obligations for sub-processors to maintain equivalent security standards.
  • Annual review of sub-processor security practices.
Yugality Consultancy Services Private Limited (CIN: U69100BR2026PTC081586)
Governing Law: Laws of India | Courts of Bihar, India