Information Security (ISMS)

Information Security at Acaboom

At Acaboom, protecting the confidentiality, integrity and availability of information is a core part of how we operate.
We maintain an Information Security Management System (ISMS) that governs how information security risks are identified, assessed and managed across our business, systems and suppliers.

Our ISMS is aligned to the principles and control framework of ISO/IEC 27001, which we view as best practice for managing information security in a structured and proportionate way. While we do not currently hold ISO 27001 certification, we use the standard as a benchmark to ensure we operate to a high and continually improving standard.

What our ISMS covers

Our ISMS includes:

  • Governance and management oversight of information security
  • Risk assessment and treatment (including cloud and third-party risks)
  • Access control, encryption and data protection measures
  • Incident and near-miss management
  • Supplier and contractor security considerations
  • Regular internal reviews and audits

The system is reviewed at least annually and whenever material changes occur, ensuring it remains appropriate for the size, nature and risk profile of our business.

Transparency

We recognise that our customers and partners may require assurance around how we manage information security.

A high-level overview of our ISMS is provided here.
The full ISMS documentation is available on request for customers and partners with a legitimate need to review it.