ssm.ro Docs
Compliance & Data ProtectionCompliance & Audit

Internal and External Audits

The internal audit program and support for customers' external audits

Internal audit

SSM.ro maintains an internal security and compliance review process, part of the Information Security Management System (ISMS) certified to ISO/IEC 27001:

  • Internal ISO/IEC 27001 audit of the ISMS — carried out periodically, with management review
  • Review of core documents (risk register, operational SOP, WAF compensating controls memo) — annually or upon significant architectural changes
  • Risk review and residual controls (see Risk Register)
  • Post-incident analysis for events with production impact
  • Restore capability verification through ad-hoc restores (backup/DR)

External audit / independent testing

  • ISO/IEC 27001 certification audit — performed by an independent certification body, with periodic surveillance audits
  • Penetration testing — see Penetration Testing
  • Customer security audits — SSM.ro provides compliance documentation under NDA
  • Vendor certifications (AWS, Heroku) cover the infrastructure layers

Evidence provided to customers

For external audit or security processes, customers can receive the compliance documentation set (DFD, architecture diagram, risk register, roles catalog, WAF memo, SOP), classified Confidential and provided under NDA — see Reports Available to Customers.

Customer responsibility

Evidence regarding user activity within the customer's tenant (authentications, deletions, role changes) is extracted by the customer from their own tenant (3-month activity logs, downloadable). SSM.ro does not provide these reports on the customer's behalf — see Periodic Access Review.