Protecting information, systems, and trust.
IRIS maintains an ISO/IEC 27001-certified information security management system and applies a risk-based approach to the confidentiality, integrity, and availability of information. This public statement summarizes the principles that guide our governance; detailed internal controls remain confidential.
Governance and accountability
Information security responsibilities are assigned across leadership, process owners, technical teams, and users. Security risks are assessed, treated, monitored, and reviewed as part of business and delivery governance.
Risk-based protection
Controls are selected according to information sensitivity, threat exposure, contractual commitments, operational impact, and applicable legal or regulatory requirements. We use defense in depth rather than relying on a single product or control.
Identity, access, and data protection
Access should follow least privilege, need-to-know, strong authentication, segregation of duties, and timely lifecycle management. Information is classified, handled, retained, transferred, and disposed of according to risk and business need.
Secure delivery and operations
Security is considered through architecture, configuration, change, deployment, monitoring, maintenance, and decommissioning. Vulnerabilities and security events are prioritized according to credible risk and potential business impact.
Resilience and incident management
IRIS maintains processes for reporting, assessing, containing, investigating, recovering from, and learning from information security incidents. Continuity and recovery arrangements are reviewed according to service criticality.
People and suppliers
Personnel receive security awareness appropriate to their roles. Relevant suppliers and service providers are evaluated and governed according to the information, systems, and services they may access or support.
Continuous improvement
We use monitoring, audits, reviews, lessons learned, corrective actions, threat intelligence, and changes in technology or regulation to improve the information security management system over time.
