Home › 03 Registers › Statement of Applicability
◎Focus mode Statement of Applicability
DYN-DOC-003 · v1.1 · updated 16 Sep 2026
0%
All controls93Organisational37Resources8Physical14Technological34
⌕
# Control Title Implemented by Evidence Discussed Remarks
1 A.5.1 Policies for information security Required to direct and support information security across the organisation. POL-013 ▤ Information Security Policy issued, approved and current
2 A.5.2 Information security roles and responsibilities Roles must be defined and allocated for the ISMS to operate. POL-013 DOC-039 ▤ ISMS Steering Committee Charter, roles and decision rights ▤ Roles and responsibilities defined in the Information Security Policy ▤ Security role training plan — Honey Ricci, Information Security Lead ▤ Security role training plan — Zahid Mubarak, CTO
3 A.5.3 Segregation of duties Conflicting duties must be separated to reduce the risk of error or misuse. Second developer reviews every pull request; the CTO approves releases separately. POL-015 POL-018 POL-024 ▤ Second-person pull request approval, CTO approves releases separately ▤ Delegation of Authority and deployment approval records ▤ Access segregation rules
4 A.5.4 Management responsibilities Personnel must apply information security in line with company policy. POL-013 POL-059 ▤ ISMS Steering Committee Charter ▤ Management review with named ISMS actions, 25 Sep 2026 ▤ Management responsibilities for personnel
5 A.5.5 Contact with authorities Required for breach notification to UAE regulators under the PDPL. POL-016 ▤ Breach notification route to UAE regulators under the PDPL ○ Named contact list for authorities
6 A.5.6 Contact with special interest groups Maintaining awareness of the threat landscape informs our controls. POL-068 ▤ Microsoft advisories, Defender and Entra alerts, IBEX as consultant ○ Formal security forum membership
7 A.5.7 Threat intelligence Threat information is needed to keep controls proportionate to real risk. Confirmed by the CTO on 1 September 2026 that no threat intelligence feed is subscribed to or reviewed. Reliance is on Microsoft Defender advisories only. POL-050 POL-057 ▤ Microsoft Defender advisories relied on ○ Threat intelligence feed subscribed and reviewed
8 A.5.8 Information security in project management Security must be considered in platform and client delivery projects. POL-018 ▤ Security considered in platform and client delivery
9 A.5.9 Inventory of information and other associated assets We cannot protect what we have not identified. POL-049 REG-004 ↗ Licensing 01 EntraID P2 Assigned Users ↗ Licensing 01 PowerApps Premium Resolved ↗ DYN-DOC-074 Config 03 Microsoft365 Licences ↗ DYN-DOC-074 Config 04 Azure Resources ↗ DYN-DOC-086 System Architecture v2.0 ▤ Policy clause in force ▤ Operating record
10 A.5.10 Acceptable use of information and other associated assets Rules for acceptable use are required for all personnel and consultants. POL-014 ▤ Acceptable Use Policy issued and current ▤ Sample signed acknowledgement — Adil Maqbool, Associate Consultant ▤ Sample signed acknowledgement — Aditya Rawat, Head of Development
1–10 of 93Page 1 of 10‹ PreviousNext ›