Information security

ISO 27001:2022 — Information Security Management System.

Halo maintains an Information Security Management System aligned to ISO 27001:2022. External certification audit is scheduled; Statement of Applicability and gap analysis available under NDA.

ISO 27001:2022 compliance badge

Our position, in detail

Scope

The ISMS covers the design, development, delivery, and operation of the Halo Connected Health platform and associated web and mobile applications, and the supporting corporate IT environment. The scope includes all personnel, all sub-processors handling personal data, and all AWS-hosted infrastructure.

Statement of Applicability

All 93 controls from Annex A of ISO 27001:2022 are considered. 91 are applied; 2 are excluded with documented justification (physical entry controls for a data centre we don’t operate; teleworking-only equipment for a role we don’t have).

Risk assessment methodology

Threat-based risk assessment refreshed quarterly. Assets classified by CIA impact. Threats scored by likelihood × impact. Risk treatment plan reviewed by leadership monthly.

Key controls in operation

Access control (A.5, A.8), cryptography (A.8.24, A.8.28), supplier management (A.5.19–A.5.22), incident management (A.5.24–A.5.28), business continuity (A.5.29–A.5.30), compliance (A.5.31–A.5.36).

Internal audit

Rolling internal audit programme — every control area reviewed at least annually. Findings tracked to closure with named owner.

Management review

Quarterly ISMS management review with executive team. Standing agenda: risk register, incident summary, audit findings, resourcing, customer feedback, changes to context, planned changes.

Documents & evidence available under NDA

  • Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
  • Sub-processor register
  • Data Processing Agreement template
  • Incident response runbook (redacted)
  • Independent penetration test summary
  • Latest internal audit findings (redacted)

Need this evidence for procurement?

Send us an NDA and we’ll return the full evidence pack for ISO 27001:2022 within 3 working days.