Information Security Policy
General framework of the information security policy on the SSM.ro platform
The information security policy defines the objectives, scope, and principles governing the protection of data and services on the SSM.ro platform. Detailed controls are documented on the dedicated pages of this section.
This policy is part of SSM.ro's Information Security Management System (ISMS), certified to ISO/IEC 27001 — see Certifications and Standards.
Objectives
The policy aims to protect the three fundamental properties of information:
- Confidentiality — access to data is strictly restricted to authorized entities
- Integrity — data and documents cannot be altered without authorization; tamper-evident audit trails
- Availability — services and data are available in accordance with continuity objectives (see RTO and RPO)
Scope
The policy covers the SSM.ro application, the infrastructure on which it runs (Heroku, AWS), trusted third-party providers, as well as staff and collaborators with access to systems. It applies to both deployment models, with the particularities described in Deployment Models.
Control domains
| Domain | Reference |
|---|---|
| Access and identity control (RBAC, tenant isolation, authentication) | Access Control |
| Encryption (in transit, at rest, key management) | Encryption |
| Application security (SDLC, OWASP, dependencies, secrets) | Application Security |
| Network security and compensating WAF controls | Network Security |
| Risk management | Risk Management |
| Vulnerabilities, patching, and testing | Vulnerabilities & Testing |
| Backup, continuity, and recovery | Backup & Continuity |
| Incident management | Incident Management |
| Human resources security | Human Resources |
Governance principles
- Least privilege — access to systems and services is granted strictly on a need-to-know basis (least privilege).
- Layered security — defensive controls at the platform, framework, application, and observability levels.
- Shared responsibility — the boundaries between SSM.ro, providers, and the client are defined in the Shared Responsibility Model.
- Continuous improvement — risks and controls are reviewed annually or upon any significant architectural change.
Versioning and review
Core security documents (risk register, operational SOP, compensating WAF controls memo) are versioned v1.0 (2026-04-29) and reviewed annually.