ISMS Manual
Document Control
Section titled “Document Control”| Field | Detail |
|---|---|
| Document Owner | François Huet, Head of Platform |
| Approval Authority | Reuben Firmin (CISO) and François Huet (Head of Platform) |
| CISO | Reuben Firmin |
| Review Cycle | Annual (or upon significant change to scope, technology, or organization) |
| Classification | Confidential |
Version History
Section titled “Version History”| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 2026-02-24 | Reuben Firmin | Initial ISMS Manual for ISO 27001:2022 certification |
| 1.1 | 2026-07-01 | Bomee Jung | Corrected ISMS governance hierarchy: CISO is the accountable authority for the ISMS; removed CEO from ISMS roles/RACI (not involved in ISMS governance); removed “Lead Engineer” (not a role at Cadence OneFive) as a policy co-approver and reclassified Chuck Lin under Engineering Team (implements controls, does not approve policy) |
Introduction and Purpose
Section titled “Introduction and Purpose”What Is This Document?
Section titled “What Is This Document?”This Information Security Management System (ISMS) Manual is the governing document for Cadence OneFive’s information security program. It defines how Cadence OneFive establishes, implements, maintains, and continually improves its ISMS in accordance with ISO/IEC 27001:2022.
Why Does Cadence OneFive Have an ISMS?
Section titled “Why Does Cadence OneFive Have an ISMS?”Cadence OneFive is a Delaware Public Benefit Corporation providing the operating system for retrofits to accelerate the climate transition of multifamily buildings. Our Momentum platform processes building data, energy models, and customer information that must be protected with the highest standards of confidentiality, integrity, and availability.
This ISMS provides the governance framework to:
- Systematically manage information security risks
- Protect customer, employee, and business data
- Meet contractual and regulatory obligations
- Support trust with customers, investors, and partners
- Enable continual improvement of our security posture
Relationship to Existing Certifications
Section titled “Relationship to Existing Certifications”Cadence OneFive holds SOC 2 Type 2 certification. The existing policy suite developed for SOC 2 provides the operational controls that this ISMS governs. This manual does not replace those policies — it provides the management system wrapper required by ISO 27001:2022, tying existing policies to ISO clauses and filling governance gaps around context, leadership, planning, performance evaluation, and improvement.
For the full policy suite, see the Information Security Policy and the IT Security Policy TOC.
Context of the Organization (Clause 4)
Section titled “Context of the Organization (Clause 4)”Understanding the Organization and Its Context (4.1)
Section titled “Understanding the Organization and Its Context (4.1)”Cadence OneFive operates as a fully remote, cloud-native climate technology company. The following internal and external factors are relevant to the ISMS:
Internal Factors:
- Fully remote workforce distributed across multiple time zones
- Cloud-native technology stack (Fly.io, AWS S3, GitHub, Google Workspace)
- Small, cross-functional team with shared responsibilities
- Consent-based, horizontal decision-making culture
- Rapid product development cadence with PR-based review process
- SOC 2 Type 2 certified security program already in place
External Factors:
- Climate technology sector with growing regulatory attention
- Customer expectation of data protection for building and energy data
- Investor expectations for governance maturity as a Public Benefit Corporation
- Evolving cyber threat landscape targeting SaaS platforms
- Regulatory requirements including state privacy laws and building data regulations
- Third-party vendor ecosystem (Fly.io, AWS, Google, Cloudflare, Doppler, Sentry, Anthropic)
Needs and Expectations of Interested Parties (4.2)
Section titled “Needs and Expectations of Interested Parties (4.2)”| Interested Party | Security-Related Needs and Expectations |
|---|---|
| Customers (building owners, managers, utilities) | Confidentiality and integrity of building data; platform availability; regulatory compliance; transparent data handling practices |
| Investors | Governance maturity; risk management; protection of intellectual property; SOC 2 / ISO 27001 certification |
| Employees and contractors | Clear security policies; secure remote work tools; privacy of personal data; security awareness training |
| Regulators (state and federal) | Compliance with applicable privacy and data protection laws; incident notification capabilities |
| Auditors (SOC 2, ISO 27001) | Evidence of implemented controls; documentation; management commitment; continual improvement |
| Technology vendors (Fly.io, AWS, Google, etc.) | Adherence to shared responsibility models; proper configuration of vendor services |
| Partners and integrators | Secure data exchange; contractual security requirements |
Scope of the ISMS (4.3)
Section titled “Scope of the ISMS (4.3)”In Scope
Section titled “In Scope”The ISMS applies to:
- The Momentum platform — the production application, staging environment, and all supporting services
- Cloud infrastructure — Fly.io (application hosting, databases), AWS S3 (file storage, knowledge base snapshots), Cloudflare (DNS, proxy, Zero Trust)
- Development and operations tooling — GitHub (source code, CI/CD), Doppler (secrets management), Sentry (error monitoring and log management), Anthropic (AI-assisted development; see AI Code Generation Practices)
- Business systems — Google Workspace (email, documents, calendar), Discord (internal communications), Hubspot (CRM)
- All personnel — employees, contractors, consultants, and temporary staff who access Cadence OneFive information assets
- All information assets — source code, customer data, building data, internal documentation, credentials, and configuration data
Exclusions
Section titled “Exclusions”| Excluded System | Rationale |
|---|---|
| Justworks PEO | HR and payroll data is processed and controlled by Justworks as an independent PEO. Cadence OneFive does not host, manage, or control the Justworks platform or the personal data it processes on our behalf. Justworks maintains its own SOC 1 and SOC 2 certifications. |
| QuickBooks Online | Financial accounting data is processed within Intuit’s QuickBooks Online platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel. Intuit maintains its own security certifications. |
| Ramp | Corporate card and expense management platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel. Ramp maintains its own SOC 2 certification. |
| Roger | Accounts payable platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel. |
These exclusions are documented with rationale per ISO 27001:2022 clause 4.3. Interfaces with excluded systems (e.g., credential management for Justworks and QuickBooks accounts) remain in scope.
Information Security Management System (4.4)
Section titled “Information Security Management System (4.4)”Cadence OneFive has established, and will implement, maintain, and continually improve, an Information Security Management System in accordance with the requirements of ISO/IEC 27001:2022.
This manual, together with the policies referenced herein, the Statement of Applicability, the risk register, and associated procedures, constitutes the documented ISMS.
Leadership (Clause 5)
Section titled “Leadership (Clause 5)”Leadership and Commitment (5.1)
Section titled “Leadership and Commitment (5.1)”The CISO and Head of Platform demonstrate leadership and commitment to the ISMS by:
- Ensuring the information security policy and objectives are established and compatible with the strategic direction of Cadence OneFive
- Ensuring ISMS requirements are integrated into business processes
- Ensuring resources needed for the ISMS are available
- Communicating the importance of effective information security management
- Ensuring the ISMS achieves its intended outcomes
- Directing and supporting persons to contribute to the effectiveness of the ISMS
- Promoting continual improvement
- Supporting other relevant management roles to demonstrate their leadership
Information Security Policy (5.2)
Section titled “Information Security Policy (5.2)”The Cadence OneFive Information Security Policy establishes the overarching policy framework. It:
- Is appropriate to the purpose of Cadence OneFive
- Includes information security objectives (see section 6.2)
- Includes a commitment to satisfy applicable requirements
- Includes a commitment to continual improvement of the ISMS
- Is available as documented information in this handbook
- Is communicated to all personnel during onboarding and annually via security awareness training
- Is available to interested parties as appropriate
Organizational Roles, Responsibilities, and Authorities (5.3)
Section titled “Organizational Roles, Responsibilities, and Authorities (5.3)”| Role | Person | ISMS Responsibilities |
|---|---|---|
| CISO | Reuben Firmin | Accountable for the ISMS; sets and approves security policy; conducts risk assessments; manages the SoA; coordinates audits; monitors security metrics; leads incident response |
| Head of Platform / ISMS Owner | François Huet | Co-approves policies; chairs management review; oversees risk treatment implementation; deputizes for the CISO |
| Strategic Growth Lead | Erika Parkins | Co-approves policies; lead human resources protocols; organizes and tracks training |
| Engineering Team | All engineers, including Chuck Lin | Implements technical controls; follows secure development practices; participates in code review; reports vulnerabilities |
| All Personnel | Everyone | Comply with security policies; complete security awareness training; report security incidents and suspected vulnerabilities; protect information assets |
RACI Matrix for Key ISMS Activities
Section titled “RACI Matrix for Key ISMS Activities”| Activity | CISO | Head of Platform | Strategic Growth Lead | Engineering | All Staff |
|---|---|---|---|---|---|
| ISMS policy approval | A | R | R | I | I |
| Risk assessment | A | C | — | C | — |
| Risk treatment decisions | A | R | — | C | — |
| Internal audit | A | C | — | C | C |
| Management review | A | R | I | I | — |
| Security awareness training | A | C | R | — | R |
| Incident response | A | C | — | R | C |
| Corrective actions | A | C | — | R | — |
| SoA maintenance | A | C | — | C | — |
R = Responsible, A = Accountable, C = Consulted, I = Informed
Planning (Clause 6)
Section titled “Planning (Clause 6)”Actions to Address Risks and Opportunities (6.1)
Section titled “Actions to Address Risks and Opportunities (6.1)”Risk Assessment Process (6.1.2)
Section titled “Risk Assessment Process (6.1.2)”Cadence OneFive maintains a formal risk assessment process as defined in the Risk Assessment Policy. The process is followed annually and upon significant changes to the organization, technology, or threat landscape, and the risk register is reviewed and updated accordingly.
Risk criteria and assessment methodology:
| Likelihood | Description |
|---|---|
| 1 — Very Low | Could occur only in exceptional circumstances (less than once per 5 years) |
| 2 — Low | Could occur but not expected (once per 2–5 years) |
| 3 — Moderate | Might occur at some time (once per 1–2 years) |
| 4 — High | Will probably occur in most circumstances (once or more per year) |
| 5 — Very High | Expected to occur frequently (multiple times per year) |
| Impact | Description |
|---|---|
| 1 — Very Low | No measurable impact on operations, data, or reputation |
| 2 — Low | Minor operational disruption; no data breach; minimal cost |
| 3 — Moderate | Noticeable operational disruption; limited data exposure; moderate cost |
| 4 — High | Significant operational disruption; material data breach; significant cost; regulatory notification |
| 5 — Very High | Extended outage; large-scale data breach; existential business impact; legal proceedings |
Risk score = Likelihood × Impact. Risks scoring ≥ 12 require immediate treatment. Risks scoring 6–11 require treatment within the next review cycle. Risks scoring ≤ 5 are accepted with monitoring.
| Risk Level | Score Range | Treatment Timeline |
|---|---|---|
| Critical | 15–25 | Immediate action required |
| High | 12–14 | Treatment within 30 days |
| Medium | 6–11 | Treatment within next review cycle |
| Low | 1–5 | Accept with monitoring |
Risk Treatment (6.1.3)
Section titled “Risk Treatment (6.1.3)”The Risk Treatment Plan defines treatment options, timelines, control selection, residual risk acceptance, and roles and responsibilities for treating identified risks.
Information Security Objectives (6.2)
Section titled “Information Security Objectives (6.2)”Cadence OneFive establishes measurable information security objectives that are consistent with the information security policy:
| Objective | Metric | Target | Measured By |
|---|---|---|---|
| Platform availability | Uptime of Momentum production environment | ≥ 99.5% monthly, excluding planned maintenance windows | Fly.io monitoring / Sentry |
| Security awareness | Percentage of personnel completing annual security training | 100% within 30 days of due date | Training records |
| Vulnerability remediation | Critical/high vulnerabilities remediated within SLA | 100% critical within 14 days; high within 30 days | Vulnerability tracking |
| Access reviews | Quarterly access reviews completed on schedule | 4 per year, 100% completion | Review records |
| Backup integrity | Annual backup restoration test completed successfully | 1 per year, successful | Test records |
| Incident response | Security incidents responded to within defined timeline | 100% acknowledged within 4 hours | incident-post-mortems repo |
These objectives are reviewed during management review (see section 9.3) and updated as needed.
Planning of Changes (6.3)
Section titled “Planning of Changes (6.3)”Changes to the ISMS are planned and implemented in a controlled manner. When Cadence OneFive determines the need for changes to the ISMS, the changes are carried out in a planned manner considering:
- The purpose of the changes and their potential consequences
- The integrity of the ISMS
- The availability of resources
- The allocation or reallocation of responsibilities and authorities
Significant changes are discussed during management review, documented via pull requests to this handbook, and communicated to affected personnel.
Support (Clause 7)
Section titled “Support (Clause 7)”Resources (7.1)
Section titled “Resources (7.1)”Cadence OneFive determines and provides the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS, including:
- Personnel time for security activities (risk assessment, audit, review)
- Security tools and platforms (Sentry, Cloudflare, ClamAV)
- External services where needed (penetration testing, audit support)
- Training programs for security awareness and technical competence
Competence (7.2)
Section titled “Competence (7.2)”Cadence OneFive ensures that persons doing work under its control that affects information security performance are competent on the basis of appropriate education, training, or experience.
- Hiring: Security competence requirements are included in role definitions for engineering and IT positions
- Training: All personnel complete security awareness training upon hire and annually thereafter
- Technical competence: Engineers maintain competence through peer code review, architecture discussions, and professional development
- Records: Training completion and competence records are maintained by the Strategic Growth Lead
Awareness (7.3)
Section titled “Awareness (7.3)”All persons doing work under Cadence OneFive’s control are made aware of:
- The information security policy (communicated during onboarding and annual training)
- Their contribution to the effectiveness of the ISMS
- The implications of not conforming with ISMS requirements
Awareness is achieved through:
- Onboarding security training and policy acknowledgement
- Annual security awareness training
- Policy updates communicated via Discord #tech_security channel
- This handbook, accessible to all personnel
Communication (7.4)
Section titled “Communication (7.4)”| What | When | From | To | Channel |
|---|---|---|---|---|
| Security policy updates | Upon change | CISO | All personnel | Handbook + Discord announcement |
| Security incidents | Upon detection | CISO / Incident Commander | Emergency Response Team → All personnel | Discord #tech_security → All-hands |
| Risk assessment results | Annually | CISO | Head of Platform | Management review meeting |
| ISMS performance metrics | Quarterly | CISO | Head of Platform | Management review / written report |
| Security awareness reminders | Quarterly | CISO | All personnel | Discord #tech_security |
| Audit findings | Upon completion | CISO / Auditor | Head of Platform | Written report + management review |
| Change control notifications | Per change | Engineering team | Stakeholders | Discord #tech_change-control |
Documented Information (7.5)
Section titled “Documented Information (7.5)”Document Control
Section titled “Document Control”All ISMS documentation is maintained as Markdown files in the Cadence OneFive handbook, stored in a private GitHub repository. This approach provides:
- Version control: Full change history via Git commits
- Change approval: Pull request review process for all policy changes
- Access control: Repository access managed per the GitHub Access Policy
- Availability: Published to the handbook website, accessible to all authorized personnel
- Integrity: Git cryptographic hashes ensure document integrity; branch protection prevents unauthorized changes
Document Hierarchy
Section titled “Document Hierarchy”- ISMS Manual (this document) — Governance framework
- Statement of Applicability — Control selection and justification
- Policies — Detailed requirements per domain (the existing policy suite)
- Procedures — Operational how-to documents (e.g., on/offboarding checklists)
- Records — Evidence of ISMS operation (training records, audit reports, risk register)
External records (risk register, training logs, audit evidence) are maintained in Google Drive with access restricted to authorized personnel.
Policy Review Cycle
Section titled “Policy Review Cycle”All ISMS policies are reviewed annually through a structured policy readthrough conducted by the CISO and Head of Platform. The review assesses each policy for:
- Accuracy against current practices and technology
- Alignment with changes in organizational context, risk landscape, or regulatory requirements
- Gaps identified through audits, incidents, or operational feedback
Policy updates resulting from the review follow the standard change approval process (pull request review). Each policy records its last review date in its frontmatter and Policy Review section.
Operation (Clause 8)
Section titled “Operation (Clause 8)”Operational Planning and Control (8.1)
Section titled “Operational Planning and Control (8.1)”Cadence OneFive plans, implements, and controls the processes needed to meet information security requirements through the following operational controls:
| Domain | Implementing Policy | Key Controls |
|---|---|---|
| Overarching security framework | Information Security Policy | Policy framework, scope, responsibilities, awareness training |
| Risk management | Risk Assessment Policy | Annual risk assessment, threat identification, risk treatment |
| Data protection | Data Security Policy | Access control, encryption, secure transfer, data handling |
| Data classification | Data Classification Policy | Classification scheme, handling requirements per level |
| Data lifecycle | Data Disposal Policy | Retention, disposal procedures, verification |
| Backup and recovery | Backup Policy | Asset-specific backup procedures, verification, testing |
| Business continuity | Business Continuity and Disaster Recovery | RTO/RPO, emergency response team, recovery procedures |
| Change management | Configuration Management Policy | PR-based change process, staging, deployment, rollback |
| Vulnerability management | Vulnerability Management Policy | Endpoint protection, patching, scanning, penetration testing |
| Log management | Log Management Policy | Centralized logging, retention, monitoring, incident support |
| Encryption | Encryption Key Management Policy | TLS management, key rotation, key storage |
| Access control | GitHub Access Policy | Least privilege, team structure, quarterly reviews |
| Remote access | Remote Access Policy | VPN requirements, MFA, network security, acceptable use |
| Endpoint security | Bring Your Own Device Policy | Device registration, OS updates, antivirus, encryption |
| Personnel security | On & Off Boarding Procedures | Access provisioning, checklist-based onboarding/offboarding |
| Infrastructure hardening | VM Hardening Policy | OS standards, monitoring, antivirus, network controls, firewall |
| Vendor management | Vendor Management Policy | Vendor evaluation, SOC 2 review, SLA management |
| Systems inventory | How Our Systems Are Set Up | System registry, domain management, access inventory |
Information Security Risk Assessment (8.2)
Section titled “Information Security Risk Assessment (8.2)”Cadence OneFive performs information security risk assessments:
- Annually — A comprehensive risk assessment covering all in-scope assets, threats, and vulnerabilities
- Upon significant change — When introducing new systems, services, processes, or organizational changes
- After a security incident — When an incident reveals previously unidentified or underestimated risks
Risk assessments follow the criteria defined in section 6.1.2 and the process defined in the Risk Assessment Policy. Results are documented in the risk register and reported to the Head of Platform and CEO during management review.
Information Security Risk Treatment (8.3)
Section titled “Information Security Risk Treatment (8.3)”Risk treatment is implemented according to the Risk Treatment Plan. The Statement of Applicability documents the controls selected and their justification.
Performance Evaluation (Clause 9)
Section titled “Performance Evaluation (Clause 9)”Monitoring, Measurement, Analysis, and Evaluation (9.1)
Section titled “Monitoring, Measurement, Analysis, and Evaluation (9.1)”Cadence OneFive monitors and measures the effectiveness of the ISMS through the following metrics:
| Metric | Method | Frequency | Owner |
|---|---|---|---|
| Platform availability (uptime) | Fly.io monitoring, Sentry dashboards | Continuous; reported monthly | Engineering Team |
| Security training completion rate | Training records review | Annually (with quarterly check) | CISO |
| Vulnerability scan results | Quarterly vulnerability scans | Quarterly | CISO |
| Critical/high vulnerability remediation time | Vulnerability tracking | Continuous; reported quarterly | Engineering Team |
| Access review completion | Review records | Quarterly | CISO |
| Backup restoration test results | Test documentation | Annually | Engineering Team |
| Security incident count and response time | incident-post-mortems repo | Continuous; reported quarterly | CISO |
| Policy review completion | Handbook version history | Annually | CISO |
| Vendor SOC 2 report review | Vendor management records | Annually | CISO |
| Nonconformity/corrective action status | GitHub issues | Quarterly | CISO |
Internal Audit (9.2)
Section titled “Internal Audit (9.2)”The Internal Audit Policy defines how Cadence OneFive plans, conducts, and follows up on internal audits. Audits are conducted at least annually, covering all ISMS clauses and a sample of Annex A controls over each cycle. Nonconformities are tracked through the Corrective Action Procedure.
Management Review (9.3)
Section titled “Management Review (9.3)”Top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.
Frequency: At least annually, with interim reviews as needed based on significant events.
Inputs to management review include:
- Status of actions from previous management reviews
- Changes in external and internal issues relevant to the ISMS
- Feedback on information security performance, including:
- Nonconformities and corrective actions
- Monitoring and measurement results (section 9.1 metrics)
- Audit results (section 9.2)
- Fulfilment of information security objectives (section 6.2)
- Feedback from interested parties
- Results of risk assessment and status of risk treatment plan
- Opportunities for continual improvement
Outputs of management review include:
- Decisions related to continual improvement opportunities
- Any need for changes to the ISMS
- Resource needs
- Updated risk acceptance decisions
- Updated information security objectives (if needed)
Management review is documented in meeting minutes, retained as records, and actions are tracked to completion.
Improvement (Clause 10)
Section titled “Improvement (Clause 10)”Continual Improvement (10.1)
Section titled “Continual Improvement (10.1)”Cadence OneFive continually improves the suitability, adequacy, and effectiveness of the ISMS through:
- Management review outcomes and decisions
- Internal and external audit findings
- Analysis of security metrics and trends
- Lessons learned from security incidents
- Changes in the risk landscape or organizational context
- Feedback from employees and interested parties
Improvement actions are prioritized, assigned, tracked, and verified through the corrective action process.
Nonconformity and Corrective Action (10.2)
Section titled “Nonconformity and Corrective Action (10.2)”The Corrective Action Procedure defines how Cadence OneFive identifies, documents, and resolves nonconformities. Corrective actions are tracked on the DevOps & Security GitHub project board and reviewed quarterly by the CISO, with status reported during management review.
Policy Suite Reference (Annex)
Section titled “Policy Suite Reference (Annex)”The following table provides a consolidated reference mapping each document in the Cadence OneFive security policy suite to its primary ISO 27001:2022 clause and Annex A control coverage. For detailed control mapping, see the Statement of Applicability.
| Document | Link | Primary ISO 27001 Clause/Controls |
|---|---|---|
| Information Security Policy | View | 5.2, A.5.1 |
| IT Security Policy TOC | View | Overview reference |
| ISMS Manual | This document | Clauses 4–10 |
| Statement of Applicability | View | 6.1.3 |
| Risk Assessment Policy | View | 6.1.2, 8.2, A.5.8 |
| Risk Treatment Plan | View | 6.1.3, 8.3 |
| Corrective Action Procedure | View | 10.2 |
| Data Security Policy | View | A.5.10, A.5.13, A.8.10, A.8.24 |
| Data Classification Policy | View | A.5.12, A.5.13 |
| Data Disposal Policy | View | A.5.11, A.7.14, A.8.10 |
| Backup Policy | View | A.8.13 |
| Business Continuity and Disaster Recovery | View | A.5.29, A.5.30 |
| Configuration Management Policy | View | A.8.9, A.8.32 |
| Vulnerability Management Policy | View | A.8.8, A.8.7 |
| Log Management Policy | View | A.8.15, A.8.16 |
| Encryption Key Management Policy | View | A.8.24 |
| GitHub Access Policy | View | A.5.15, A.5.18, A.8.2, A.8.3 |
| Remote Access Policy | View | A.6.7, A.8.1 |
| Bring Your Own Device Policy | View | A.7.9, A.8.1 |
| On & Off Boarding Procedures | View | A.6.1, A.6.2, A.6.5 |
| VM Hardening Policy | View | A.8.8, A.8.9, A.8.20 |
| Vendor Management Policy | View | A.5.19, A.5.20, A.5.21, A.5.22 |
| How Our Systems Are Set Up | View | A.5.9 (partial) |
| Internal Audit Policy | View | 6.2, 8.1, 9.2, A.8.34 |
| Privacy Program | View | A.5.34 |
| Network Monitoring Policy | View | A.8.21 |
Policy Review
Section titled “Policy Review”- This ISMS Manual will be reviewed annually and updated as necessary to reflect changes in the organization, technology, risk landscape, or regulatory requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
