Information Security Management

Information Security Policies and Procedures

Harmony maintains established information security policies and procedures for all employees and contractors, covering a range of topics. Policies and procedures are approved by management, reviewed at least annually, updated as needed, and made available to all employees via our intranet.

How it is checked

Approved by management and reviewed at least annually.

Framework requirements this speaks to

  • ISO 27001 A.5.1 (policies for information security)
  • SOC 2 Common Criteria - Control Environment

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.