A publicly visible subset of our ISO 27001:2022 Annex A control mapping. Representative controls identify ownership, intended implementation, and evidence status where available.
3
A.5 Organizational
3
A.6 People
3
A.7 Physical
3
A.8 Technological
3 representative controls from this domain.
Ensure management direction and support for information security in accordance with business requirements and applicable regulations.
Board-approved Information Security Policy reviewed annually. All sub-policies (access control, encryption, incident response) derive from this master policy and undergo version-controlled reviews.
Define and assign all information security responsibilities to ensure accountability.
RACI matrix maintained for Annex A control mapping. Dedicated ISMS Manager, Security Lead, Privacy Officer, and Compliance Officer roles with documented job descriptions and KPIs.
Collect and analyze information about threats to provide situational awareness for risk decisions.
Automated CVE feeds, CISA advisories, and healthcare-specific ISAC alerts ingested into centralized threat log. Weekly triage by Security Lead with escalation criteria defined.
3 representative controls from this domain.
Verify backgrounds of all personnel prior to granting access to information assets.
Pre-employment background checks (criminal, education, reference) mandatory for all staff and contractors. Results documented in HR system with restricted access.
Ensure personnel and contractors are aware of and fulfill their information security responsibilities.
Mandatory onboarding security training, annual HIPAA & security awareness refresher, quarterly phishing simulations. Completion tracked in LMS with <95% pass-rate triggering retraining.
Protect information accessed, processed, or stored at remote working sites.
Remote work policy enforces VPN or Zero Trust network access, full-disk encryption, screen lock at 5 minutes, and prohibition of PHI storage on personal devices.
3 representative controls from this domain.
Prevent unauthorized physical access, damage, and interference to the organization's information.
Cloud-first architecture eliminates on-premises data centers. Office access controlled via badge readers with visitor logs. Server rooms (where applicable) require two-factor physical access.
Protect organization equipment and information when used outside the premises.
All company laptops enrolled in MDM with remote wipe capability, enforced FDE, and geo-fencing alerts. No PHI on removable media policy.
Prevent information leakage from equipment being disposed of or reused.
NIST SP 800-88 compliant media sanitization. Certificate of destruction obtained for all decommissioned hardware. Cloud storage deletion verified via provider attestation.
3 representative controls from this domain.
Protect information stored on, processed by, or accessible via user endpoint devices.
MDM-enforced device policies: OS auto-update, EDR agent mandatory, full-disk encryption, application allowlisting. Non-compliant devices blocked from corporate resources within 24 hours.
Ensure users and systems are securely authenticated before granting access.
MFA enforced for all production, admin, and cloud console access. Passwords meet NIST SP 800-63B guidelines. Session tokens expire after 15 minutes of inactivity for PHI systems.
Ensure proper and effective use of cryptography to protect the confidentiality, authenticity, and integrity of information.
TLS 1.3 for all data in transit. AES-256-GCM for data at rest in Fly.io-managed Postgres and S3-compatible object storage. Key management via managed KMS with automatic annual rotation. Crypto standard document maintained.
Need the full Statement of Applicability, evidence artifacts, or internal audit reports? Register for auditor-level access to our Evidence Vault.
The controls listed above are a public subset of CUBE OneCare's ISO 27001:2022 Annex A mapping and readiness program. This page does not claim ISO 27001 certification, a complete Statement of Applicability, or external auditor approval. The full SoA, detailed control justifications, and evidence references are shared under NDA with qualified auditors, enterprise procurement teams, and regulatory bodies when available. Control descriptions are simplified for public consumption; detailed implementation evidence is available through the Evidence vault.