compliance
ISO 27001 — Information Security (audit planned)
How QEHS supports an ISO 27001 ISMS for customers (evidence artefacts) and our own ISO 27001 audit roadmap and current posture.
10 min read · 3 sections
Overview
ISO 27001:2022 is the information security standard (audit planned for QEHS). The certified entity maintains an Information Security Management System (ISMS) and applies controls from Annex A.
Our posture
- QEHS publishes 14 ISMS security policies aligned to ISO 27001:2022 Annex A (audit planned). Full ISO 27001 certification is on the roadmap; certification status visible in the Trust Center.
- Annual surveillance audits will follow once certification is achieved.
- Shared responsibility model — customer owns identity, access, and their tenant data; we own platform confidentiality, integrity, and availability.
Supporting your ISMS
For customers running their own ISMS, QEHS modules can host the asset inventory, risk register, SoA, control evidence, awareness training records, and internal audit programme. The Documents module enforces versioned approval for policies, and the Audit log is tamper-evident (hash-chained, 1–7 years retention).