ssm.ro Docs
Security, Infrastructure & Operations

Information Security Policy

General framework of the information security policy on the SSM.ro platform

The information security policy defines the objectives, scope, and principles governing the protection of data and services on the SSM.ro platform. Detailed controls are documented on the dedicated pages of this section.

This policy is part of SSM.ro's Information Security Management System (ISMS), certified to ISO/IEC 27001 — see Certifications and Standards.

Objectives

The policy aims to protect the three fundamental properties of information:

  • Confidentiality — access to data is strictly restricted to authorized entities
  • Integrity — data and documents cannot be altered without authorization; tamper-evident audit trails
  • Availability — services and data are available in accordance with continuity objectives (see RTO and RPO)

Scope

The policy covers the SSM.ro application, the infrastructure on which it runs (Heroku, AWS), trusted third-party providers, as well as staff and collaborators with access to systems. It applies to both deployment models, with the particularities described in Deployment Models.

Control domains

DomainReference
Access and identity control (RBAC, tenant isolation, authentication)Access Control
Encryption (in transit, at rest, key management)Encryption
Application security (SDLC, OWASP, dependencies, secrets)Application Security
Network security and compensating WAF controlsNetwork Security
Risk managementRisk Management
Vulnerabilities, patching, and testingVulnerabilities & Testing
Backup, continuity, and recoveryBackup & Continuity
Incident managementIncident Management
Human resources securityHuman Resources

Governance principles

  • Least privilege — access to systems and services is granted strictly on a need-to-know basis (least privilege).
  • Layered security — defensive controls at the platform, framework, application, and observability levels.
  • Shared responsibility — the boundaries between SSM.ro, providers, and the client are defined in the Shared Responsibility Model.
  • Continuous improvement — risks and controls are reviewed annually or upon any significant architectural change.

Versioning and review

Core security documents (risk register, operational SOP, compensating WAF controls memo) are versioned v1.0 (2026-04-29) and reviewed annually.