Skip to main content

Information Security Management System (ISMS) Policy

PropertyValue
Document IDSID-POL-ISMS-OVERVIEW
Version1.2
OwnerBoard of SIROS Foundation
Review CycleAnnual, and after any material change to scope

This document is SIROS Foundation's public statement of its Information Security Management System (ISMS): what it covers, who governs it, and what other documentation makes it up. It is not an index of linked sub-pages — most of the ISMS's supporting documentation is maintained internally rather than published (see §5 below for exactly what and why).

1. Purpose

SIROS Foundation is pursuing ISO/IEC 27001:2022 certification for its own ISMS, governing how the Foundation itself operates as an organization. This is separate from — and complements — the platform-level security controls and framework coverage (EUDI, FitCEM, GDPR, OWASP ASVS, STRIDE, NOBCCS, and ISO 27001 Annex A for the SIROS ID platform) documented elsewhere on this site, which assess the SIROS ID wallet product for the benefit of deployment operators.

2. Certified Entity

SIROS Foundation — the organization that designs, builds, and maintains the SIROS ID digital identity wallet platform as open source software.

3. ISMS Scope

The initial certification scope is the SIROS Foundation software development process: the people, systems, and procedures used to design, write, review, test, build, release, and maintain source code for SIROS Foundation projects.

In scope: source code management and secure development lifecycle practices; CI/CD, build, and release infrastructure; dependency and open-source supply chain management; vulnerability management; access control to development systems; personnel security for staff and contributors with elevated access.

Out of scope this cycle: production operation of deployed SIROS ID wallet instances — a deployment operator responsibility, addressed by the platform/operator security framework already published on this site — and end-user data processing or physical/network security of operator infrastructure. Later certification cycles may expand this scope as the Foundation's own operational footprint grows.

4. Governance

The ISMS is governed by the Board of SIROS Foundation, with day-to-day ownership held by the Tech Lead and a designated Chief Information Security Officer responsible for risk management.

5. What Makes Up the ISMS

An ISO 27001 ISMS is more than one policy — it's a set of documents working together. This is what SIROS Foundation's consists of, and which parts are published here versus kept as internal management records:

Published on this site:

Maintained as internal management records (not published, consistent with normal practice for documents that describe specific access arrangements, named personnel, or in-progress gap remediation — publishing them would itself create a security or privacy exposure rather than reduce one):

  • Information Security Policy (the Board-approved policy statement this page summarizes) — a signed PDF will be published here once Board approval is complete
  • Statement of Applicability (control-by-control applicability and evidence status against ISO 27001 Annex A)
  • Risk assessment methodology and risk register
  • Information security objectives
  • Access control, personnel security, and supplier management policies
  • Incident response and nonconformity/corrective-action procedures

These internal documents are available to the certification body and to SIROS Foundation's independent internal auditor as part of their respective engagements.

6. Status

SIROS Foundation is actively preparing for Stage 1 and Stage 2 ISO/IEC 27001:2022 certification audits, including an independent internal audit review ahead of the external certification engagement.

8. Document History

VersionDateChanges
1.02026-07-31Initial publication as "ISMS Overview"
1.12026-08-01Renamed to "ISMS Policy" and restructured to clearly state what the ISMS comprises and what is/isn't published, rather than implying a navigable overview
1.22026-08-03Noted that a signed Information Security Policy PDF will be published here once Board approval completes