ACCELQ Logo

Information Security Management System (ISMS) Policy

The Management of ACCELQ is committed to implementing the Information Security Controls in line with ISO 27001:2013 and SOC (Service Organization Control), to protect the Security, Availability, Processing integrity, Confidentiality & Privacy of various Information assets hosted at ACCELQ.

We ensure this through establishing a formal Information Security Management System with appropriate processes, creation of information security infrastructure, maintenance of ISMS and training all our stakeholders. All the teams are committed to satisfy all applicable requirements within this policy and to the continual improvement of the ISMS, and therefore have established this information security policy so that:

  • it is appropriate to the purpose of the organization.
  • It includes information security objectives and provides the framework for setting continual
    information security objectives.

This information security policy shall be available as documented information; be communicated within the organization; and be available to interested parties, as appropriate. This document forms an integral part of the Information Security Management System (ISMS).

The IS policy shall address the following aspects related to Security, Availability, Processing integrity, Confidentiality & Privacy.:

Product Lifecycle Phases: Alignment of organization and user’s CIA needs across all phases of product lifecycle such as Test automation product development/engineering, testing, end user implementations/ configurations, rollouts, and annual maintenance & support.

  1. Human Resource Security: ISMS policy governs all phases of employee journey within the organization including Hire to Retire/ relieve, enablement & training and day to day activity monitoring
  2. Asset Management: Asset management to identify, track, classify, maintain, and assign ownership for
    all assets at ACCELQ to ensure they are adequately protected. The assets can be physical or assets in
    AWS
  3. Access Control: Governs access management including the process of granting authorized users the
    right to use a service while preventing access to non-authorized users in logical access points in both
    on-premises assets and AWS services.
  4. Cryptography: Ensure proper and effective use of cryptography to protect the confidentiality,
    authenticity and/or integrity of information and data in both rest and in-transit
  5. Physical and environmental security: Prevent unauthorized physical access, damage and
    interference to ACCELQ information and information processing facilities, and to prevent loss, damage,
    theft or compromise of assets and interruption to ACCELQ operations.
  6. Operations Security: Ensure correct and secure operations across all information processing facilities
    inline with AWS Shared Security Model. The operation security is assured across on-premises, platform
    level, applications/product level and AWS infrastructure
  7. Communications Security: Stresses the security of the network and network services through
    controls such as segregation of networks, network service level agreements, and other network
    controls that are e
  8. Security assurance: Ensure that security is an integral part across
    1. All phases of System acquisition, Development, maintenance that includes security governance, security, engineering, security testing and security monitoring.
    2. System architecture by defining and operationalizing enterprise security framework coupled with Secure by Design architecture principles.
    3. Application / platform reliability through Robust vulnerability and incident management framework
    4. Security Information and Event Management (SIEM) SIEM mainly refers to threat detection, prevention, and management.
  9. Supplier Relationships: Ensure protection of ACCELQ’s assets that are accessible by suppliers; and
    maintain an agreed level of information security and service delivery in line with supplier agreements.
  10. Incident Management: Provide organization-wide guidance to employees on the proper response to, and efficient and timely reporting of, computer security-related incidents, such as computer viruses, unauthorized user activity, and suspected compromise of data
  11. Business Continuity: Provides a framework to plan, establish, implement, operate, monitor, review, maintain and continually improve a business continuity management system (BCMS) leveraging AWS Availability zones and scalability capabilities. The framework should enable to define and govern the backups, resiliency, failover, segregation of duties, business continuity assurance, and crisis management.
  12. Audit and logging: Ensuring the operations are inline with defined policies, procedures, processes,
    best practices, and work instructions through.,

    1. Continuous and periodic monitoring of pre-established metrics (SLAs, OLAs, KPIs, and
      KRAs) and associated performance targets continuous
    2. Continuous and periodic review of logs related to user actions, incidents, events along
      with the efficacy of alert mechanisms across ACCELQ test platform, ACCELQ Cloud Infra,
      ACCELQ Internal-IT
  13. Regulatory and Compliance: Governs breaches of legal, statutory, regulatory or contractual obligations related to information security and of any security requirements. The policy emphasizes on technical and organizational measure to protect personal data against accidental or unlawful destruction or accidental loss or alteration, and unauthorized disclosure or access.

READY TO GET STARTED?

Let our team of experts walk you through how ACCELQ can assist you in achieving a true continous testing automation.