Internal and External Audits
The internal audit program and support for customers' external audits
Internal audit
SSM.ro maintains an internal security and compliance review process, part of the Information Security Management System (ISMS) certified to ISO/IEC 27001:
- Internal ISO/IEC 27001 audit of the ISMS — carried out periodically, with management review
- Review of core documents (risk register, operational SOP, WAF compensating controls memo) — annually or upon significant architectural changes
- Risk review and residual controls (see Risk Register)
- Post-incident analysis for events with production impact
- Restore capability verification through ad-hoc restores (backup/DR)
External audit / independent testing
- ISO/IEC 27001 certification audit — performed by an independent certification body, with periodic surveillance audits
- Penetration testing — see Penetration Testing
- Customer security audits — SSM.ro provides compliance documentation under NDA
- Vendor certifications (AWS, Heroku) cover the infrastructure layers
Evidence provided to customers
For external audit or security processes, customers can receive the compliance documentation set (DFD, architecture diagram, risk register, roles catalog, WAF memo, SOP), classified Confidential and provided under NDA — see Reports Available to Customers.
Customer responsibility
Evidence regarding user activity within the customer's tenant (authentications, deletions, role changes) is extracted by the customer from their own tenant (3-month activity logs, downloadable). SSM.ro does not provide these reports on the customer's behalf — see Periodic Access Review.