Clause 4 — Context
Interested parties, internal and external issues, and the ISMS scope are documented and reviewed annually or after any material change.
Trust Center
Our Information Security Management System is documented and operating against all 93 Annex A controls. Certification audits are the remaining step. Last reviewed September 9, 2026.
Scope
The Information Security Management System (ISMS) covers the design, development, operation and support of the GuardSource security enterprise management platform delivered by GuardResourceOne, including the supporting cloud infrastructure, corporate systems and the people who administer them.
We describe ourselves as aligned to ISO/IEC 27001:2022 and in progress toward certification. We do not claim a certificate until an accredited body issues one.
Management system
The requirements an auditor tests before looking at a single technical control.
Interested parties, internal and external issues, and the ISMS scope are documented and reviewed annually or after any material change.
Management approves the information security policy, assigns a security owner and reviews performance at a scheduled management review.
A risk register scores threats by likelihood and impact against defined acceptance criteria, with treatment plans and a Statement of Applicability covering all Annex A controls.
Defined roles, security awareness training at onboarding and annually, and version-controlled documented information.
Risk assessment and treatment are run on a set cadence and before significant changes; change control evidences the outcome.
Security metrics, internal audits against Annex A, and a formal management review with recorded decisions.
Nonconformities, incidents and audit findings are logged with root cause, corrective action and verification of effectiveness.
Annex A
Grouped by the four 2022 themes. Each control is evidenced in the same programme that supports our SOC 2 readiness.
Approved information security policy set, defined ownership and segregation of duties.
Sub-processors are assessed before onboarding, bound by contract and re-reviewed annually; the register is published.
Documented response plan with severities, owners, breach notification within 48 hours of confirmation and post-incident review.
Encrypted daily backups, tested restores, RPO 24 hours and RTO 8 hours.
Register of statutory obligations covering GDPR, UK GDPR and CCPA, with a documented retention schedule.
Background checks where lawful, confidentiality agreements and security responsibilities written into employment terms.
Security and privacy training at onboarding and annually, with completion recorded.
Access revoked the day someone leaves, verified against the access review record.
All production data is held with certified cloud providers operating manned, access-controlled facilities; we run no server rooms of our own.
Staff devices are encrypted, screen-locked and centrally wipeable; clear desk and clear screen expectations apply.
Least-privilege role-based access, single sign-on with mandatory multi-factor authentication and quarterly access reviews.
TLS 1.2 or better in transit, AES-256 at rest for databases, storage and backups; secrets held in a managed secret store.
Row-level security enforced in the database so a query can only return rows belonging to the authenticated account.
Append-only audit logs of authentication, plan changes, exports and deletions, retained two years, plus uptime and error alerting.
Peer review, automated type and lint checks, separated environments and dependency vulnerability scanning on every build.
Dependency and configuration findings are triaged on a defined SLA; an independent penetration test is scheduled before general availability.
Evidence
Security questionnaires, the Statement of Applicability summary and our risk treatment approach can be requested at security@guardresourceone.com. Certification reports are shared under NDA once issued.
See also our Security & Trust page, Sub-Processor Register and Data Processing Addendum.