Skip to content

ISMS Manual

Field Detail
Document Owner François Huet, Head of Platform
Approval Authority Reuben Firmin (CISO) and François Huet (Head of Platform)
CISO Reuben Firmin
Review Cycle Annual (or upon significant change to scope, technology, or organization)
Classification Confidential
Version Date Author Changes
1.0 2026-02-24 Reuben Firmin Initial ISMS Manual for ISO 27001:2022 certification
1.1 2026-07-01 Bomee Jung Corrected ISMS governance hierarchy: CISO is the accountable authority for the ISMS; removed CEO from ISMS roles/RACI (not involved in ISMS governance); removed “Lead Engineer” (not a role at Cadence OneFive) as a policy co-approver and reclassified Chuck Lin under Engineering Team (implements controls, does not approve policy)

This Information Security Management System (ISMS) Manual is the governing document for Cadence OneFive’s information security program. It defines how Cadence OneFive establishes, implements, maintains, and continually improves its ISMS in accordance with ISO/IEC 27001:2022.

Cadence OneFive is a Delaware Public Benefit Corporation providing the operating system for retrofits to accelerate the climate transition of multifamily buildings. Our Momentum platform processes building data, energy models, and customer information that must be protected with the highest standards of confidentiality, integrity, and availability.

This ISMS provides the governance framework to:

  • Systematically manage information security risks
  • Protect customer, employee, and business data
  • Meet contractual and regulatory obligations
  • Support trust with customers, investors, and partners
  • Enable continual improvement of our security posture

Cadence OneFive holds SOC 2 Type 2 certification. The existing policy suite developed for SOC 2 provides the operational controls that this ISMS governs. This manual does not replace those policies — it provides the management system wrapper required by ISO 27001:2022, tying existing policies to ISO clauses and filling governance gaps around context, leadership, planning, performance evaluation, and improvement.

For the full policy suite, see the Information Security Policy and the IT Security Policy TOC.

Understanding the Organization and Its Context (4.1)

Section titled “Understanding the Organization and Its Context (4.1)”

Cadence OneFive operates as a fully remote, cloud-native climate technology company. The following internal and external factors are relevant to the ISMS:

Internal Factors:

  • Fully remote workforce distributed across multiple time zones
  • Cloud-native technology stack (Fly.io, AWS S3, GitHub, Google Workspace)
  • Small, cross-functional team with shared responsibilities
  • Consent-based, horizontal decision-making culture
  • Rapid product development cadence with PR-based review process
  • SOC 2 Type 2 certified security program already in place

External Factors:

  • Climate technology sector with growing regulatory attention
  • Customer expectation of data protection for building and energy data
  • Investor expectations for governance maturity as a Public Benefit Corporation
  • Evolving cyber threat landscape targeting SaaS platforms
  • Regulatory requirements including state privacy laws and building data regulations
  • Third-party vendor ecosystem (Fly.io, AWS, Google, Cloudflare, Doppler, Sentry, Anthropic)

Needs and Expectations of Interested Parties (4.2)

Section titled “Needs and Expectations of Interested Parties (4.2)”
Interested Party Security-Related Needs and Expectations
Customers (building owners, managers, utilities) Confidentiality and integrity of building data; platform availability; regulatory compliance; transparent data handling practices
Investors Governance maturity; risk management; protection of intellectual property; SOC 2 / ISO 27001 certification
Employees and contractors Clear security policies; secure remote work tools; privacy of personal data; security awareness training
Regulators (state and federal) Compliance with applicable privacy and data protection laws; incident notification capabilities
Auditors (SOC 2, ISO 27001) Evidence of implemented controls; documentation; management commitment; continual improvement
Technology vendors (Fly.io, AWS, Google, etc.) Adherence to shared responsibility models; proper configuration of vendor services
Partners and integrators Secure data exchange; contractual security requirements

The ISMS applies to:

  • The Momentum platform — the production application, staging environment, and all supporting services
  • Cloud infrastructure — Fly.io (application hosting, databases), AWS S3 (file storage, knowledge base snapshots), Cloudflare (DNS, proxy, Zero Trust)
  • Development and operations tooling — GitHub (source code, CI/CD), Doppler (secrets management), Sentry (error monitoring and log management), Anthropic (AI-assisted development; see AI Code Generation Practices)
  • Business systems — Google Workspace (email, documents, calendar), Discord (internal communications), Hubspot (CRM)
  • All personnel — employees, contractors, consultants, and temporary staff who access Cadence OneFive information assets
  • All information assets — source code, customer data, building data, internal documentation, credentials, and configuration data
Excluded System Rationale
Justworks PEO HR and payroll data is processed and controlled by Justworks as an independent PEO. Cadence OneFive does not host, manage, or control the Justworks platform or the personal data it processes on our behalf. Justworks maintains its own SOC 1 and SOC 2 certifications.
QuickBooks Online Financial accounting data is processed within Intuit’s QuickBooks Online platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel. Intuit maintains its own security certifications.
Ramp Corporate card and expense management platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel. Ramp maintains its own SOC 2 certification.
Roger Accounts payable platform. Cadence OneFive does not host or control this platform. Access is limited to authorized finance personnel.

These exclusions are documented with rationale per ISO 27001:2022 clause 4.3. Interfaces with excluded systems (e.g., credential management for Justworks and QuickBooks accounts) remain in scope.

Information Security Management System (4.4)

Section titled “Information Security Management System (4.4)”

Cadence OneFive has established, and will implement, maintain, and continually improve, an Information Security Management System in accordance with the requirements of ISO/IEC 27001:2022.

This manual, together with the policies referenced herein, the Statement of Applicability, the risk register, and associated procedures, constitutes the documented ISMS.

The CISO and Head of Platform demonstrate leadership and commitment to the ISMS by:

  • Ensuring the information security policy and objectives are established and compatible with the strategic direction of Cadence OneFive
  • Ensuring ISMS requirements are integrated into business processes
  • Ensuring resources needed for the ISMS are available
  • Communicating the importance of effective information security management
  • Ensuring the ISMS achieves its intended outcomes
  • Directing and supporting persons to contribute to the effectiveness of the ISMS
  • Promoting continual improvement
  • Supporting other relevant management roles to demonstrate their leadership

The Cadence OneFive Information Security Policy establishes the overarching policy framework. It:

  • Is appropriate to the purpose of Cadence OneFive
  • Includes information security objectives (see section 6.2)
  • Includes a commitment to satisfy applicable requirements
  • Includes a commitment to continual improvement of the ISMS
  • Is available as documented information in this handbook
  • Is communicated to all personnel during onboarding and annually via security awareness training
  • Is available to interested parties as appropriate

Organizational Roles, Responsibilities, and Authorities (5.3)

Section titled “Organizational Roles, Responsibilities, and Authorities (5.3)”
Role Person ISMS Responsibilities
CISO Reuben Firmin Accountable for the ISMS; sets and approves security policy; conducts risk assessments; manages the SoA; coordinates audits; monitors security metrics; leads incident response
Head of Platform / ISMS Owner François Huet Co-approves policies; chairs management review; oversees risk treatment implementation; deputizes for the CISO
Strategic Growth Lead Erika Parkins Co-approves policies; lead human resources protocols; organizes and tracks training
Engineering Team All engineers, including Chuck Lin Implements technical controls; follows secure development practices; participates in code review; reports vulnerabilities
All Personnel Everyone Comply with security policies; complete security awareness training; report security incidents and suspected vulnerabilities; protect information assets
Activity CISO Head of Platform Strategic Growth Lead Engineering All Staff
ISMS policy approval A R R I I
Risk assessment A C C
Risk treatment decisions A R C
Internal audit A C C C
Management review A R I I
Security awareness training A C R R
Incident response A C R C
Corrective actions A C R
SoA maintenance A C C

R = Responsible, A = Accountable, C = Consulted, I = Informed

Actions to Address Risks and Opportunities (6.1)

Section titled “Actions to Address Risks and Opportunities (6.1)”

Cadence OneFive maintains a formal risk assessment process as defined in the Risk Assessment Policy. The process is followed annually and upon significant changes to the organization, technology, or threat landscape, and the risk register is reviewed and updated accordingly.

Risk criteria and assessment methodology:

Likelihood Description
1 — Very Low Could occur only in exceptional circumstances (less than once per 5 years)
2 — Low Could occur but not expected (once per 2–5 years)
3 — Moderate Might occur at some time (once per 1–2 years)
4 — High Will probably occur in most circumstances (once or more per year)
5 — Very High Expected to occur frequently (multiple times per year)
Impact Description
1 — Very Low No measurable impact on operations, data, or reputation
2 — Low Minor operational disruption; no data breach; minimal cost
3 — Moderate Noticeable operational disruption; limited data exposure; moderate cost
4 — High Significant operational disruption; material data breach; significant cost; regulatory notification
5 — Very High Extended outage; large-scale data breach; existential business impact; legal proceedings

Risk score = Likelihood × Impact. Risks scoring ≥ 12 require immediate treatment. Risks scoring 6–11 require treatment within the next review cycle. Risks scoring ≤ 5 are accepted with monitoring.

Risk Level Score Range Treatment Timeline
Critical 15–25 Immediate action required
High 12–14 Treatment within 30 days
Medium 6–11 Treatment within next review cycle
Low 1–5 Accept with monitoring

The Risk Treatment Plan defines treatment options, timelines, control selection, residual risk acceptance, and roles and responsibilities for treating identified risks.

Cadence OneFive establishes measurable information security objectives that are consistent with the information security policy:

Objective Metric Target Measured By
Platform availability Uptime of Momentum production environment ≥ 99.5% monthly, excluding planned maintenance windows Fly.io monitoring / Sentry
Security awareness Percentage of personnel completing annual security training 100% within 30 days of due date Training records
Vulnerability remediation Critical/high vulnerabilities remediated within SLA 100% critical within 14 days; high within 30 days Vulnerability tracking
Access reviews Quarterly access reviews completed on schedule 4 per year, 100% completion Review records
Backup integrity Annual backup restoration test completed successfully 1 per year, successful Test records
Incident response Security incidents responded to within defined timeline 100% acknowledged within 4 hours incident-post-mortems repo

These objectives are reviewed during management review (see section 9.3) and updated as needed.

Changes to the ISMS are planned and implemented in a controlled manner. When Cadence OneFive determines the need for changes to the ISMS, the changes are carried out in a planned manner considering:

  • The purpose of the changes and their potential consequences
  • The integrity of the ISMS
  • The availability of resources
  • The allocation or reallocation of responsibilities and authorities

Significant changes are discussed during management review, documented via pull requests to this handbook, and communicated to affected personnel.

Cadence OneFive determines and provides the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS, including:

  • Personnel time for security activities (risk assessment, audit, review)
  • Security tools and platforms (Sentry, Cloudflare, ClamAV)
  • External services where needed (penetration testing, audit support)
  • Training programs for security awareness and technical competence

Cadence OneFive ensures that persons doing work under its control that affects information security performance are competent on the basis of appropriate education, training, or experience.

  • Hiring: Security competence requirements are included in role definitions for engineering and IT positions
  • Training: All personnel complete security awareness training upon hire and annually thereafter
  • Technical competence: Engineers maintain competence through peer code review, architecture discussions, and professional development
  • Records: Training completion and competence records are maintained by the Strategic Growth Lead

All persons doing work under Cadence OneFive’s control are made aware of:

  • The information security policy (communicated during onboarding and annual training)
  • Their contribution to the effectiveness of the ISMS
  • The implications of not conforming with ISMS requirements

Awareness is achieved through:

  • Onboarding security training and policy acknowledgement
  • Annual security awareness training
  • Policy updates communicated via Discord #tech_security channel
  • This handbook, accessible to all personnel
What When From To Channel
Security policy updates Upon change CISO All personnel Handbook + Discord announcement
Security incidents Upon detection CISO / Incident Commander Emergency Response Team → All personnel Discord #tech_security → All-hands
Risk assessment results Annually CISO Head of Platform Management review meeting
ISMS performance metrics Quarterly CISO Head of Platform Management review / written report
Security awareness reminders Quarterly CISO All personnel Discord #tech_security
Audit findings Upon completion CISO / Auditor Head of Platform Written report + management review
Change control notifications Per change Engineering team Stakeholders Discord #tech_change-control

All ISMS documentation is maintained as Markdown files in the Cadence OneFive handbook, stored in a private GitHub repository. This approach provides:

  • Version control: Full change history via Git commits
  • Change approval: Pull request review process for all policy changes
  • Access control: Repository access managed per the GitHub Access Policy
  • Availability: Published to the handbook website, accessible to all authorized personnel
  • Integrity: Git cryptographic hashes ensure document integrity; branch protection prevents unauthorized changes
  1. ISMS Manual (this document) — Governance framework
  2. Statement of Applicability — Control selection and justification
  3. Policies — Detailed requirements per domain (the existing policy suite)
  4. Procedures — Operational how-to documents (e.g., on/offboarding checklists)
  5. Records — Evidence of ISMS operation (training records, audit reports, risk register)

External records (risk register, training logs, audit evidence) are maintained in Google Drive with access restricted to authorized personnel.

All ISMS policies are reviewed annually through a structured policy readthrough conducted by the CISO and Head of Platform. The review assesses each policy for:

  • Accuracy against current practices and technology
  • Alignment with changes in organizational context, risk landscape, or regulatory requirements
  • Gaps identified through audits, incidents, or operational feedback

Policy updates resulting from the review follow the standard change approval process (pull request review). Each policy records its last review date in its frontmatter and Policy Review section.

Cadence OneFive plans, implements, and controls the processes needed to meet information security requirements through the following operational controls:

Domain Implementing Policy Key Controls
Overarching security framework Information Security Policy Policy framework, scope, responsibilities, awareness training
Risk management Risk Assessment Policy Annual risk assessment, threat identification, risk treatment
Data protection Data Security Policy Access control, encryption, secure transfer, data handling
Data classification Data Classification Policy Classification scheme, handling requirements per level
Data lifecycle Data Disposal Policy Retention, disposal procedures, verification
Backup and recovery Backup Policy Asset-specific backup procedures, verification, testing
Business continuity Business Continuity and Disaster Recovery RTO/RPO, emergency response team, recovery procedures
Change management Configuration Management Policy PR-based change process, staging, deployment, rollback
Vulnerability management Vulnerability Management Policy Endpoint protection, patching, scanning, penetration testing
Log management Log Management Policy Centralized logging, retention, monitoring, incident support
Encryption Encryption Key Management Policy TLS management, key rotation, key storage
Access control GitHub Access Policy Least privilege, team structure, quarterly reviews
Remote access Remote Access Policy VPN requirements, MFA, network security, acceptable use
Endpoint security Bring Your Own Device Policy Device registration, OS updates, antivirus, encryption
Personnel security On & Off Boarding Procedures Access provisioning, checklist-based onboarding/offboarding
Infrastructure hardening VM Hardening Policy OS standards, monitoring, antivirus, network controls, firewall
Vendor management Vendor Management Policy Vendor evaluation, SOC 2 review, SLA management
Systems inventory How Our Systems Are Set Up System registry, domain management, access inventory

Information Security Risk Assessment (8.2)

Section titled “Information Security Risk Assessment (8.2)”

Cadence OneFive performs information security risk assessments:

  • Annually — A comprehensive risk assessment covering all in-scope assets, threats, and vulnerabilities
  • Upon significant change — When introducing new systems, services, processes, or organizational changes
  • After a security incident — When an incident reveals previously unidentified or underestimated risks

Risk assessments follow the criteria defined in section 6.1.2 and the process defined in the Risk Assessment Policy. Results are documented in the risk register and reported to the Head of Platform and CEO during management review.

Risk treatment is implemented according to the Risk Treatment Plan. The Statement of Applicability documents the controls selected and their justification.

Monitoring, Measurement, Analysis, and Evaluation (9.1)

Section titled “Monitoring, Measurement, Analysis, and Evaluation (9.1)”

Cadence OneFive monitors and measures the effectiveness of the ISMS through the following metrics:

Metric Method Frequency Owner
Platform availability (uptime) Fly.io monitoring, Sentry dashboards Continuous; reported monthly Engineering Team
Security training completion rate Training records review Annually (with quarterly check) CISO
Vulnerability scan results Quarterly vulnerability scans Quarterly CISO
Critical/high vulnerability remediation time Vulnerability tracking Continuous; reported quarterly Engineering Team
Access review completion Review records Quarterly CISO
Backup restoration test results Test documentation Annually Engineering Team
Security incident count and response time incident-post-mortems repo Continuous; reported quarterly CISO
Policy review completion Handbook version history Annually CISO
Vendor SOC 2 report review Vendor management records Annually CISO
Nonconformity/corrective action status GitHub issues Quarterly CISO

The Internal Audit Policy defines how Cadence OneFive plans, conducts, and follows up on internal audits. Audits are conducted at least annually, covering all ISMS clauses and a sample of Annex A controls over each cycle. Nonconformities are tracked through the Corrective Action Procedure.

Top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.

Frequency: At least annually, with interim reviews as needed based on significant events.

Inputs to management review include:

  • Status of actions from previous management reviews
  • Changes in external and internal issues relevant to the ISMS
  • Feedback on information security performance, including:
    • Nonconformities and corrective actions
    • Monitoring and measurement results (section 9.1 metrics)
    • Audit results (section 9.2)
    • Fulfilment of information security objectives (section 6.2)
  • Feedback from interested parties
  • Results of risk assessment and status of risk treatment plan
  • Opportunities for continual improvement

Outputs of management review include:

  • Decisions related to continual improvement opportunities
  • Any need for changes to the ISMS
  • Resource needs
  • Updated risk acceptance decisions
  • Updated information security objectives (if needed)

Management review is documented in meeting minutes, retained as records, and actions are tracked to completion.

Cadence OneFive continually improves the suitability, adequacy, and effectiveness of the ISMS through:

  • Management review outcomes and decisions
  • Internal and external audit findings
  • Analysis of security metrics and trends
  • Lessons learned from security incidents
  • Changes in the risk landscape or organizational context
  • Feedback from employees and interested parties

Improvement actions are prioritized, assigned, tracked, and verified through the corrective action process.

Nonconformity and Corrective Action (10.2)

Section titled “Nonconformity and Corrective Action (10.2)”

The Corrective Action Procedure defines how Cadence OneFive identifies, documents, and resolves nonconformities. Corrective actions are tracked on the DevOps & Security GitHub project board and reviewed quarterly by the CISO, with status reported during management review.

The following table provides a consolidated reference mapping each document in the Cadence OneFive security policy suite to its primary ISO 27001:2022 clause and Annex A control coverage. For detailed control mapping, see the Statement of Applicability.

Document Link Primary ISO 27001 Clause/Controls
Information Security Policy View 5.2, A.5.1
IT Security Policy TOC View Overview reference
ISMS Manual This document Clauses 4–10
Statement of Applicability View 6.1.3
Risk Assessment Policy View 6.1.2, 8.2, A.5.8
Risk Treatment Plan View 6.1.3, 8.3
Corrective Action Procedure View 10.2
Data Security Policy View A.5.10, A.5.13, A.8.10, A.8.24
Data Classification Policy View A.5.12, A.5.13
Data Disposal Policy View A.5.11, A.7.14, A.8.10
Backup Policy View A.8.13
Business Continuity and Disaster Recovery View A.5.29, A.5.30
Configuration Management Policy View A.8.9, A.8.32
Vulnerability Management Policy View A.8.8, A.8.7
Log Management Policy View A.8.15, A.8.16
Encryption Key Management Policy View A.8.24
GitHub Access Policy View A.5.15, A.5.18, A.8.2, A.8.3
Remote Access Policy View A.6.7, A.8.1
Bring Your Own Device Policy View A.7.9, A.8.1
On & Off Boarding Procedures View A.6.1, A.6.2, A.6.5
VM Hardening Policy View A.8.8, A.8.9, A.8.20
Vendor Management Policy View A.5.19, A.5.20, A.5.21, A.5.22
How Our Systems Are Set Up View A.5.9 (partial)
Internal Audit Policy View 6.2, 8.1, 9.2, A.8.34
Privacy Program View A.5.34
Network Monitoring Policy View A.8.21
  • This ISMS Manual will be reviewed annually and updated as necessary to reflect changes in the organization, technology, risk landscape, or regulatory requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.