Information security
ISO 27001:2022 — Information Security Management System.
Halo maintains an Information Security Management System aligned to ISO 27001:2022. External certification audit is scheduled; Statement of Applicability and gap analysis available under NDA.
Our position, in detail
Scope
The ISMS covers the design, development, delivery, and operation of the Halo Connected Health platform and associated web and mobile applications, and the supporting corporate IT environment. The scope includes all personnel, all sub-processors handling personal data, and all AWS-hosted infrastructure.
Statement of Applicability
All 93 controls from Annex A of ISO 27001:2022 are considered. 91 are applied; 2 are excluded with documented justification (physical entry controls for a data centre we don’t operate; teleworking-only equipment for a role we don’t have).
Risk assessment methodology
Threat-based risk assessment refreshed quarterly. Assets classified by CIA impact. Threats scored by likelihood × impact. Risk treatment plan reviewed by leadership monthly.
Key controls in operation
Access control (A.5, A.8), cryptography (A.8.24, A.8.28), supplier management (A.5.19–A.5.22), incident management (A.5.24–A.5.28), business continuity (A.5.29–A.5.30), compliance (A.5.31–A.5.36).
Internal audit
Rolling internal audit programme — every control area reviewed at least annually. Findings tracked to closure with named owner.
Management review
Quarterly ISMS management review with executive team. Standing agenda: risk register, incident summary, audit findings, resourcing, customer feedback, changes to context, planned changes.
Documents & evidence available under NDA
- Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
- Sub-processor register
- Data Processing Agreement template
- Incident response runbook (redacted)
- Independent penetration test summary
- Latest internal audit findings (redacted)
