Skip to content

Security is a practice the business can show.

The business limits access, protects sensitive information and records important decisions. Those controls contribute to an ISO 27001 review of the company’s wider security management system.

Security management begins with your organization’s risks.

ISO/IEC 27001 specifies requirements for an information security management system. Risk assessment, treatment, and ongoing review shape the controls an organization needs. Product safeguards and records contribute to that work within their defined scope.

Trust & security

The company’s information

Roles and permissions

Who can read, request or approve

An authorized request

Access remains within the company’s boundary.

Private conversations and personal notes are separate from the company record.

Review the safeguards within their scope.

These are relevant security review topics. The current catalog does not map ISO 27001 Annex A controls, and no certification is claimed.

Identity and access

Sign-in safeguards, revocable sessions, and configurable access permissions.

Still needs review

Control configuration and the organization’s access-review process must be assessed.

Data boundaries

Access restricted to the company, additional database boundaries where enabled, and encrypted credentials.

Still needs review

Infrastructure, key custody, and deployment configuration need their own verification.

Change accountability

Audit events and receipts connect captured changes to actors and decisions.

Still needs review

The complete change-management process also includes systems and procedures beyond these records.

These review topics are not a control mapping, an audit opinion or a finding of legal compliance.

Build the assessment around your management system.

Take product evidence into the wider program that establishes, operates, and improves your information-security controls.

Trust & security
  • 01

    Security management scope, risk assessment and treatment plan

  • 02

    Statement of Applicability and control responsibilities

  • 03

    Supplier assurance, incident response, and independent assessment

Questions about ISO 27001?

Is Orcinta ISO 27001 certified?

No ISO 27001 certification is currently claimed. Ask for the current assurance status and the evidence available for your security review.

Does this page provide an Annex A control mapping?

No. It explains architecture relevant to security-management work. The current receipt catalog does not include ISO 27001 control references.

Are hosting and key-management arrangements the same for every deployment?

No. Review region, infrastructure protections, key custody, and deployment-specific delivery with our team. Availability and key custody must be confirmed for the proposed deployment.

Go back to the source.

The authoritative framework and the scope of your review remain the reference points.

Start with the access your business needs to justify.

Discuss your requirements