Controls
Information Security Management
Who owns security at Harmony, the policies they maintain, and what every employee is held to.
Security Leadership
The Harmony leadership team and Data Privacy Officer (DPO) are responsible for determining and updating information security measures at Harmony.
- ISO 27001 A.5.2 (roles and responsibilities)
- GDPR Art. 37 (data protection officer)
Information Security Policies and Procedures
Harmony maintains established information security policies and procedures for all employees and contractors, covering a range of topics. Policies and procedures are approved by management, reviewed at least annually, updated as needed, and made available to all employees via our intranet.
How it is checked: Approved by management and reviewed at least annually.
- ISO 27001 A.5.1 (policies for information security)
- SOC 2 Common Criteria - Control Environment
Background Checks
Harmony performs background checks on all new employees in accordance with local laws.
How it is checked: Pre-employment screening, to the extent local law permits.
- ISO 27001 A.6.1 (screening)
Employee Confidentiality
All employee contracts include a confidentiality agreement.
- ISO 27001 A.6.6 (confidentiality agreements)
Mandatory Security Awareness Training
All employees undergo mandatory security awareness training on an annual basis. Certain higher risk roles go through additional training specific for their role and its associated risks, annually.
How it is checked: Annually for everyone, with extra role-specific training for higher-risk roles.
- ISO 27001 A.6.3 (awareness, education and training)
Access Provisioning and Offboarding
Access is granted by role from a documented baseline once onboarding is complete, and requires approval from the system owner for anything touching production. On a role change, access is reviewed and anything no longer needed is removed. On termination, a documented clearance process revokes system and premises access and recovers company property, and corporate accounts are disabled the same business day. Access permissions are recertified on a regular cycle.
How it is checked: A documented termination clearance process tracked in our internal IT ticket system, and periodic recertification of access permissions.
- ISO 27001 A.5.18 (access rights)
- ISO 27001 A.6.5 (responsibilities after termination or change of employment)
- SOC 2 Common Criteria - Logical Access
Risk Assessment
Harmony operates a formal information security risk assessment process as part of its ISO 27001 certified ISMS. Risks to the confidentiality, integrity and availability of customer data are identified, assessed against defined criteria, assigned an owner and a treatment, and reviewed at least annually and on material change to the environment.
How it is checked: Reviewed at least annually and on material change, within the certified ISMS.
- ISO 27001 Clause 6.1.2 (information security risk assessment)
- ISO 27001 Clause 8.2 (risk assessment performance)
- SOC 2 Common Criteria - Risk Assessment
Vendor Risk Assessments
We formally assess the security posture of all third-party vendors, with a higher bar for those which handle sensitive data or have access to critical systems.
How it is checked: Formal assessment before onboarding, with a higher bar for vendors that handle sensitive data.
- ISO 27001 A.5.19 (security in supplier relationships)
- SOC 2 Common Criteria - Risk Assessment
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls