DOCUMENT 06 OF 12ISO 27001 / SOC 2 Alignment
Technical & Organisational Security Measures
Security controls, encryption, access management
# DOCUMENT 06: Technical & Organisational Security Measures (TOMS)
Standard: Targeting ISO 27001:2022 / SOC 2 Type II alignment
Review Cycle: Semi-annual review; updated upon material change
1. Data Encryption
- At rest: AES-256 encryption for all stored user data and documents.
- In transit: TLS 1.3 enforced for all data transmission between client and server.
- Database encryption: Encrypted database volumes with key management via dedicated key management service.
- Backup encryption: All backups encrypted with separate encryption keys.
2. Access Controls
- Role-based access control (RBAC): Access to production data restricted to authorised personnel on a need-to-know basis.
- Multi-factor authentication (MFA): Required for all internal administrative access.
- Privileged access management: Elevated privileges granted on a time-limited, request-and-approval basis.
- Contractor access: Third-party contractors sign NDAs and are granted minimum necessary access.
3. Infrastructure Security
- Cloud infrastructure deployed on reputable cloud providers with Indian data residency commitments.
- Network segmentation: Production, staging, and development environments fully isolated.
- Web Application Firewall (WAF) deployed to detect and block common attacks.
- DDoS protection via cloud-native mitigation services.
- Regular vulnerability scanning of infrastructure components.
4. Application Security
- Secure Software Development Lifecycle (SSDLC) with security review at each development stage.
- Dependency scanning for known vulnerabilities in third-party libraries.
- Annual penetration testing by qualified third-party security professionals.
- Bug bounty programme for responsible disclosure of security vulnerabilities.
- API authentication via OAuth 2.0 and JWT tokens with short expiry windows.
5. Organisational Measures
- Designated Information Security Officer responsible for security governance.
- Annual security awareness training mandatory for all employees.
- Background verification conducted for all employees with access to production data.
- Incident Response Plan maintained and tested annually.
- Business Continuity and Disaster Recovery plans with defined RTO and RPO targets.
6. Data Lifecycle Management
- Automated deletion of data upon expiry of retention periods.
- Cryptographic erasure for data on decommissioned storage media.
- Audit logs maintained for all data access events, retained for 12 months.
7. Vendor and Sub-Processor Security
- All sub-processors assessed for security posture before onboarding.
- Contractual obligations for sub-processors to maintain equivalent security standards.
- Annual review of sub-processor security practices.
Yugality Consultancy Services Private Limited (CIN: U69100BR2026PTC081586)
Governing Law: Laws of India | Courts of Bihar, India
