International standard for Information Security Management Systems (ISMS)
ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It defines the requirements an ISMS must meet to help organizations keep information assets secure.
quiXzoom has implemented a comprehensive Information Security Management System covering:
Policies, roles, responsibilities
Screening, training, awareness
Perimeter, equipment, storage
Crypto, operations, development
Comprehensive security policies reviewed annually. All employees and contractors must acknowledge policies before accessing systems.
Inventory of all information assets with defined ownership. Classification system (Public, Internal, Confidential, Restricted) applied to all data.
Role-based access with principle of least privilege. Multi-factor authentication enforced. Regular access reviews and automatic deprovisioning.
AES-256 for data at rest. TLS 1.3 for data in transit. Key management via AWS KMS with automatic rotation.
Change management with peer review. Capacity planning and monitoring. Malware protection on all endpoints.
Network segmentation with VPC isolation. VPN required for remote access. DDoS protection via AWS Shield.
Security requirements in all procurement. Secure development lifecycle (SDLC). Code review and automated security testing.
Security requirements in all contracts. Regular supplier assessments. Right to audit clauses.
24/7 security operations center. Incident response plan with defined roles. Post-incident reviews and lessons learned.
Business impact analysis. Disaster recovery plans tested annually. Backup and recovery procedures documented.
quiXzoom's ISMS follows the Plan-Do-Check-Act (PDCA) cycle: