Information Security Management

Risk Assessment

Harmony operates a formal information security risk assessment process as part of its ISO 27001 certified ISMS. Risks to the confidentiality, integrity and availability of customer data are identified, assessed against defined criteria, assigned an owner and a treatment, and reviewed at least annually and on material change to the environment.

How it is checked

Reviewed at least annually and on material change, within the certified ISMS.

Framework requirements this speaks to

  • ISO 27001 Clause 6.1.2 (information security risk assessment)
  • ISO 27001 Clause 8.2 (risk assessment performance)
  • SOC 2 Common Criteria - Risk Assessment

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.