Controls
Corporate and Physical Security
How the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled.
Endpoint Encryption
All corporate devices are encrypted to protect data in case of loss or theft. They can be remotely wiped to prevent data leakage if a device is compromised or lost.
- ISO 27001 A.8.1 (user endpoint devices)
- ISO 27001 A.8.24 (use of cryptography)
Endpoint Management
We push updates to employee laptops such that they are on the latest, patched version of their required operating system. We require the use of a managed browser with only an approved set of browser extensions.
- ISO 27001 A.8.1 (user endpoint devices)
- ISO 27001 A.8.8 (management of technical vulnerabilities)
Physical and Environmental Security
Harmony operates no data centres of its own. All customer data is held in AWS facilities, whose physical and environmental controls are covered by AWS’s own audited certifications. Harmony offices are access-controlled, and visitors are received rather than given unaccompanied access.
- ISO 27001 A.7.1 (physical security perimeters)
- ISO 27001 A.7.2 (physical entry)
- ISO 27001 A.7.4 (physical security monitoring)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls