ISMS Scope & Framework
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Security & Infrastructure Owner (Sekhar) · Approved by COO (Payeli) | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. The front door to the Finaisse Information Security Management System (ISMS). It defines the ISMS scope, objectives, governance, and the map to the policies, controls, and records that make up the system. An auditor starts here.
1. ISMS scope
The ISMS covers the security of the Finaisse multi-tenant financial platform and the information entrusted to it:
- Systems — the
blitzbackend microservices,blitz-uifrontend, andfin-infrainfrastructure-as-code. - Environments — staging (Railway, live) and production (AWS
ap-south-1, in build). - Data — all customer financial data and PII (Restricted), and the internal data supporting the platform.
- People — all Finaisse personnel and contractors, and the subprocessors that process its data.
Boundaries and exclusions are recorded in the Statement of Applicability.
2. Objectives
- Protect the confidentiality, integrity, and availability of customer financial data.
- Enforce tenant isolation — no customer can reach another's data, workload, or identity.
- Achieve SOC 2 Type II attestation; maintain India DPDP baseline; pursue ISO 27001 and ISO 42001 as demand warrants.
- Drive the findings gap list to closure before the first production tenant.
Measurable targets are tracked via the posture dashboard and programme history.
3. Governance & leadership
| Role | Responsibility | Holder |
|---|---|---|
| Executive sponsor / Approver | Approves the ISMS, policies, and risk posture; demonstrates management commitment | COO (Payeli) |
| ISMS owner | Owns and operates the ISMS, chairs reviews | Security & Infrastructure Owner (Sekhar) |
| Policy owners | Own individual policies per function | See Policy Library |
| Engineering | Implements and evidences controls | All engineers |
4. The ISMS map
| Component | Location |
|---|---|
| Charter | Information Security Policy |
| Policy library | /policies/ |
| Risk process | Risk Management Policy → Risk Register |
| Control set | Control Register · Domains |
| Applicability | Statement of Applicability |
| Evidence & assessment | Evidence Register · Audit & Assessment Log |
| Programme history | Programme History |
5. ISMS Policies
The 18 policies that govern this ISMS live in the ISMS Policy Library — each mapped to the SOC 2 trust services criteria it satisfies, with an owner and a revision history. Start there for the governing rules; this page is the map, not the ruleset itself.
6. ISO-mandatory documents (status)
Required for ISO 27001 certification (not for SOC 2):
| Document | Status |
|---|---|
| ISMS scope statement | 🟠 this page |
| Security objectives | 🟠 §2 above; formalise on ISO pursuit |
| Risk assessment methodology | ✅ Risk Management Policy |
| Statement of Applicability | ✅ SoA |
| Internal audit programme | 🔴 placeholder |
| Management review records | 🔴 placeholder |
Related
- → Policy Library · → Control Register · → System Description
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Security & Infrastructure Owner | Initial ISMS scope and framework. |
| 0.2 | 2026-09-07 | Security & Infrastructure Owner | Added §5 (ISMS Policies), a dedicated section pointing to the Policy Library; renumbered the ISO-mandatory documents section to §6. |
Finaisse Internal — Confidential. Not for external distribution.