Piano maintains an Information Security Management System (ISMS) based on the standard ISO/IEC 27001:2022, which is designed to ensure that the data safeguards established for compliance are maintained.
Information Security Policy (ISP)
Our ISMS is supported by the established Piano Software Information Security Policy (ISP), which ensures the data safeguards established for compliance are maintained.
Applicability
The ISP applies to all Piano team members, agents, contractors, representatives, and other parties with access to private data.
Annex A Controls (12 domains)
The Piano Software Information Security Policy covers ISO 27001:2022 Annex A controls.
-
Organization of information security
-
Human resource security
-
Asset Management
-
Access Control
-
Cryptography
-
Physical and environmental security
-
Operations security
-
Communications security
-
System acquisition, development and maintenance
-
Supplier relationships
-
Information security incident management
-
Information security aspects of business continuity management
Additional Coverage (Risk Management / Awareness / Measurement)
Our Information Security Management System also covers:
-
Risk management
-
Employee awareness
-
Periodical measurement and evaluation of the Information security framework effectiveness
Public documents available upon request
-
Piano Public Acceptable Use Policy
-
Piano Public BCP&DRP
-
Piano Public Information Security Policy
-
Statement of Applicability