Information Security Policy
BETAInformation Security Policy aligned with ISO 27001:2022 and SOC 2 Trust Services Criteria. Covers access control, asset management, incident response, BCDR, cryptography, and security awareness.
HIPAA Notice of Privacy Practices (NPP)
BETAHIPAA Notice of Privacy Practices (NPP) for a covered entity under the HIPAA Privacy Rule, 45 CFR §164.520. Describes how protected health information (PHI) is used and disclosed, uses requiring authorization, individual rights, the entity's duties, and how to complain to the entity and to HHS OCR.
HIPAA Business Associate Agreement (BAA)
BETAHIPAA Business Associate Agreement between a Covered Entity and a Business Associate under 45 CFR §164.502(e) and §164.504(e). Covers permitted and required uses and disclosures of PHI, safeguards including Security Rule compliance for ePHI, breach and security-incident reporting, subcontractor flow-down, individual access/amendment/accounting support, HHS access, and return or destruction of PHI on termination.
HIPAA Breach Notification Policy
BETAHIPAA Breach Notification Policy aligned with the HIPAA Breach Notification Rule (45 CFR §§164.400–414). Covers the definition of breach and its exceptions, the four-factor risk assessment, notification to individuals, HHS, and media, business-associate reporting, and the documentation and burden-of-proof requirements.
AI Management System (AIMS) Policy — ISO/IEC 42001:2023
BETAAI Management System (AIMS) Policy aligned with ISO/IEC 42001:2023. Establishes a full management system — not a plain AI-use policy — covering the AI policy and objectives, context and interested parties, leadership and roles, AI risk management and the AI system impact assessment process (Clause 6.1.4 / Annex A.5, guided by ISO/IEC 42005), the Annex A control areas (A.2–A.10), responsible-AI principles, and continual improvement. Optionally aligns to the EU AI Act and NIST AI RMF.
AI System Impact Assessment (AIIA)
BETAAI System Impact Assessment record aligned with ISO/IEC 42001:2023 (Clauses 6.1.4 and 8.4) and ISO/IEC 42005:2025 guidance. Documents system description, intended purpose, affected individuals and groups, potential harms (bias, safety, privacy, security, transparency, autonomy, environmental), likelihood and severity, mitigations, human oversight, residual impact and the acceptability decision. Supports EU AI Act fundamental-rights and conformity context.
Information Security in Project Management Policy
BETAPolicy for embedding information security into every project, aligned with ISO/IEC 27001:2022 Annex A 5.8. Covers security-by-design from initiation, per-project risk assessment, security requirements and acceptance criteria at project gates, roles, and post-project review.
Configuration & Hardening Management Policy
BETAConfiguration & Hardening Management Policy aligned with ISO/IEC 27001:2022 Annex A 8.9 (new control), SOC 2 CC7.1, and PCI DSS Requirement 2. Covers secure baseline configurations, hardening standards (CIS Benchmarks), configuration control and approval, drift detection and monitoring, documentation and inventory, and periodic review.
Data Masking, Deletion & Loss Prevention Standard
BETAA control standard covering secure information deletion, data masking / pseudonymisation / anonymisation for non-production and display, and data leakage prevention across email, web, endpoint and cloud. Maps to ISO/IEC 27001:2022 A.8.10, A.8.11 and A.8.12, SOC 2 CC6.7 and the DPDP Act, 2023.
Legal, Regulatory & Contractual Requirements Register
BETAA living register of the legal, statutory, regulatory and contractual requirements the organisation must meet, aligned with ISO/IEC 27001:2022 controls A.5.31–A.5.34. India-first coverage of the DPDP Act 2023, IT Act 2000 with CERT-In Directions, Copyright Act 1957, and sectoral rules, plus GDPR where operating abroad.
Access Provisioning (Joiner-Mover-Leaver) Procedure
BETAJoiner-Mover-Leaver access lifecycle procedure covering approval-based provisioning, role changes, SLA-bound de-provisioning, least privilege, privileged access, recertification and break-glass.
Endpoint & Anti-Malware Policy
BETAEndpoint hardening, EDR/anti-malware, disk encryption, patch SLAs, MDM/BYOD and removable-media controls mapped to ISO 27001, SOC 2 and PCI DSS.
Network Security Policy
BETANetwork segmentation and trust zones, default-deny firewalls / network security controls reviewed every six months, secure remote access and VPN, wireless security, DMZ, web/DNS filtering and IDS/IPS aligned to ISO 27001 A.8.20–A.8.23, SOC 2 and PCI DSS.
Security Awareness & Training Programme
BETAFormal security awareness, competence and role-based training programme with phishing simulations, completion tracking, attestation and sanctions, mapped to ISO 27001, SOC 2 and PCI DSS.
Information Security Risk Management Methodology
BETAInformation Security Risk Management Methodology defining risk and acceptance criteria, an asset/threat/vulnerability approach, 5x5 likelihood and impact scales, risk ownership, treatment options and the link to the Statement of Applicability and Risk Treatment Plan. Aligned with ISO/IEC 27001:2022 Clause 6.1.2 and SOC 2 CC3.1-CC3.4.
Information Security Objectives Register
BETAA controlled register of SMART, measurable information security objectives set at relevant functions and levels, each with an owner, metric/KPI, baseline, target, deadline, resources, monitoring method and status — linked to the Information Security Policy and risk-assessment results per ISO/IEC 27001:2022 Clause 6.2.
Information Security Roles, Responsibilities & RACI
BETADefines the information security governance structure, role-by-role responsibilities, a RACI matrix for key security activities, and segregation-of-duties principles. Aligned with ISO/IEC 27001:2022 Clause 5.3, Annex A.5.2 & A.5.3, and SOC 2 CC1.3.
ISMS Monitoring, Measurement & Metrics Report
BETAPeriodic monitoring, measurement, analysis and evaluation report for an Information Security Management System, aligned with ISO/IEC 27001:2022 Clause 9.1 and SOC 2 CC4.1. Presents the security metrics programme — what is measured, method, frequency, owner — and a target-vs-actual metrics table with trend and analysis for management review.
Documented Information Control Procedure
BETAISMS procedure governing how documents and records are identified, versioned, approved, distributed, classified, retained and retired, aligned to ISO/IEC 27001:2022 Clause 7.5.
Personnel (HR) Security Policy
BETAHuman Resources security policy covering the full employment lifecycle — pre-employment background verification, security terms of employment, onboarding, disciplinary process, offboarding, post-employment obligations, and contractor screening. Aligned with ISO/IEC 27001:2022 people controls, SOC 2, and PCI DSS.
Cryptography & Key Management Policy
BETAApproved algorithms, full key lifecycle, HSM/KMS storage, rotation, split knowledge and dual control, and certificate management aligned to ISO 27001 A.8.24, SOC 2 and PCI DSS.
Secure Development (Secure SDLC) Policy
BETASecure Software Development Lifecycle (Secure SDLC) Policy aligned with ISO 27001:2022 A.8.25–A.8.31, SOC 2 CC8.1, and PCI DSS v4.0.1 Req 6.2–6.3. Covers threat modelling, secure coding (OWASP Top 10), SAST/DAST/SCA, code review, dependency and patch management, environment separation, change approval, and use of production data in test.
Supplier & Third-Party Security Policy
BETASupplier & Third-Party Security Policy aligned with ISO 27001:2022 (A.5.19-A.5.23), SOC 2 CC9.2, and PCI DSS v4.0.1 Req 12.8. Covers supplier risk tiering, due diligence, security clauses, DPAs, right-to-audit, SOC 2/ISO evidence, ongoing monitoring, and offboarding.
Physical & Environmental Security Policy
BETAPhysical zones, access control, visitor management, CCTV, environmental controls, media handling and secure disposal — aligned to ISO 27001 A.7, SOC 2 CC6.4/CC6.5 and PCI DSS Req 9.
Information Backup Policy
BETAInformation Backup Policy aligned with ISO 27001:2022 A.8.13, SOC 2 Availability (A1.2), and PCI DSS v4.0.1 Req. 12.10. Covers backup scope, the 3-2-1 rule, encryption, geographic separation, retention, restore-testing cadence, RTO/RPO alignment, and immutability / ransomware protection.
ISMS Internal Audit Report
BETAISO/IEC 27001:2022 Clause 9.2 internal audit report recording scope, methodology, classified findings, per-clause and Annex A results, conclusions and the link to corrective action.
Nonconformity & Corrective Action (CAPA) Register
BETAA controlled register recording each ISMS nonconformity, its root cause, correction, corrective action, owner, due date and effectiveness verification.
SOC 2 System Description
BETAManagement's Description of the System for a SOC 2 report, built to the AICPA 2018 Description Criteria (DC section 200, DC1-DC9, with revised implementation guidance 2022). Covers services, service commitments and system requirements, the five system components, boundaries, control environment, the applicable Trust Services Criteria, system incidents, complementary user-entity controls (CUECs), subservice organisations (carve-out / inclusive) and CSOCs.
Professional Tax — Employer Monthly Working
BETAMonthly professional tax deduction working sheet and challan summary for employers. Covers all major PT states — Maharashtra, Karnataka, West Bengal, AP/Telangana, Tamil Nadu, Gujarat, MP, Odisha, Kerala — with applicable salary slabs, deduction amounts, and payment due dates. Includes employee-wise register and Form III / annual return reference.
Form 16 — Salary TDS Certificate Working
BETAForm 16 working sheet — TDS certificate for salary income. Covers Part A (TDS deducted and deposited quarter-wise, TRACES-generated data) and Part B (detailed income computation: gross salary, exemptions, deductions, taxable income, tax under old and new regime). Mandatory issuance by employer by 15 June each year.
Audit Planning Memorandum
BETAAudit planning memorandum recording the overall audit strategy, assessed risk areas, materiality thresholds, timelines and team responsibilities for a statutory audit, in line with the risk-based planning approach set out in the Standards on Auditing.