Benefits
Specifications
How-to
Contact Us
Learn More

January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.
Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and
improvements.
We ensure:
Atlas Platforms's information security policy:
Roles and responsibilities for ISMS are based on Atlas Platforms' flat governance structure:
Competencies and gaps are assessed through regular reviews and training programs.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Risk Assessment:
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Risk Treatment:
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Security Objectives:
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education.
Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-
compliance.
Internal and external security communications are coordinated and documented.
Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms performs internal audits of its ISMS on a recurring basis and has defined an ISMS Internal
Audit Procedure. For further details, please refer to the 07-ISMS Procedure for Internal Audits document.
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually
improving. For further details, please refer to the 08-ISMS Procedure for Management Review .
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
In case of any deviation from established standards, Atlas Platforms commits to:
For transparency and due diligence, Atlas Platforms will document:
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
EthosOne supports everyone who plays a role in school governance:
Book a Governance Review
Governance Clarity
Boards get consistent, ready-to-present insights.
Assurance Confidence
No blind spots, everything tracked under ownership.
Compliance Control
State-aligned obligations managed and visible.
Risk Transparency
ISO-aligned risk management with accountability.

Home
Articles
Contact
Board Governance
Risk Management
School Compliance
Operational Oversight
Oversight
Compliance
Duty of Care
vs Complispace
vs Veracross
vs EdSmart
vs Seqta
vs Doing it yourself
vs MS Teams
vs Convene
vs Diligent
vs Boardpro
Governance Infrastructure for Independent Schools
School Board Engagement for Principals
Oversight and Assurance for Business Managers
Accessibility for Private School Boards
Policy Management for Faith-based Schools
Risk Management for Private Schools
Board Management for Independent Schools
Camp & Excursion Management Tools
Benefits
Specifications
How-to
Contact Us
Learn More

January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.
Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and
improvements.
We ensure:
Atlas Platforms's information security policy:
Roles and responsibilities for ISMS are based on Atlas Platforms' flat governance structure:
Competencies and gaps are assessed through regular reviews and training programs.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Risk Assessment:
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Risk Treatment:
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Security Objectives:
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education.
Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-
compliance.
Internal and external security communications are coordinated and documented.
Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms performs internal audits of its ISMS on a recurring basis and has defined an ISMS Internal
Audit Procedure. For further details, please refer to the 07-ISMS Procedure for Internal Audits document.
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually
improving. For further details, please refer to the 08-ISMS Procedure for Management Review .
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
In case of any deviation from established standards, Atlas Platforms commits to:
For transparency and due diligence, Atlas Platforms will document:
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
Board-ready in 30 days
EthosOne supports everyone who plays a role in school governance:
Book a Governance Review
Governance Clarity
Boards get consistent, ready-to-present insights.
Assurance Confidence
No blind spots, everything tracked under ownership.
Compliance Control
State-aligned obligations managed and visible.
Risk Transparency
ISO-aligned risk management with accountability.

Home
Articles
Contact
Board Governance
Risk Management
School Compliance
Operational Oversight
Oversight
Compliance
Duty of Care
vs Complispace
vs Veracross
vs EdSmart
vs Seqta
vs Doing it yourself
vs MS Teams
vs Convene
vs Diligent
vs Boardpro
Governance Infrastructure for Independent Schools
School Board Engagement for Principals
Oversight and Assurance for Business Managers
Accessibility for Private School Boards
Policy Management for Faith-based Schools
Risk Management for Private Schools
Board Management for Independent Schools
Camp & Excursion Management Tools

January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.
Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and
improvements.
We ensure:
Atlas Platforms's information security policy:
Roles and responsibilities for ISMS are based on Atlas Platforms' flat governance structure:
Competencies and gaps are assessed through regular reviews and training programs.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Risk Assessment:
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Risk Treatment:
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Security Objectives:
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education.
Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-
compliance.
Internal and external security communications are coordinated and documented.
Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms performs internal audits of its ISMS on a recurring basis and has defined an ISMS Internal
Audit Procedure. For further details, please refer to the 07-ISMS Procedure for Internal Audits document.
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually
improving. For further details, please refer to the 08-ISMS Procedure for Management Review .
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
In case of any deviation from established standards, Atlas Platforms commits to:
For transparency and due diligence, Atlas Platforms will document:
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
Board-ready in 30 days
EthosOne supports everyone who plays a role in school governance:
Book a Governance Review
Governance Clarity
Boards get consistent, ready-to-present insights.
Assurance Confidence
No blind spots, everything tracked under ownership.
Compliance Control
State-aligned obligations managed and visible.
Risk Transparency
ISO-aligned risk management with accountability.

Home
Articles
Contact
Board Governance
Risk Management
School Compliance
Operational Oversight
Oversight
Compliance
Duty of Care
Governance Infrastructure for Independent Schools
School Board Engagement for Principals
Oversight and Assurance for Business Managers
Accessibility for Private School Boards
Policy Management for Faith-based Schools
Risk Management for Private Schools
Board Management for Independent Schools
Camp & Excursion Management Tools
vs Complispace
vs Veracross
vs EdSmart
vs Seqta
vs Doing it yourself
vs MS Teams
vs Convene
vs Diligent
vs Boardpro