
January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.

Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
Leadership and commitment
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and improvements.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education. Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-compliance.
Internal and external security communications are coordinated and documented. Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually improving. For further details, please refer to the 08-ISMS Procedure for Management Review.
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
Connect with us, follow our journey
Strateji was designed for the complexity of enterprise — and built to simplify it. To explore containerised deployment or discuss alignment with your enterprise architecture and compliance team:
Book an enterprise briefing





Lead through complexity — with confidence.
Strateji brings structure, visibility and accountability to modern leadership. Let’s explore how it could work for you.
Book an Enterprise Briefing
Turn complexity into clarity.

January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.

Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
Leadership and commitment
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and improvements.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education. Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-compliance.
Internal and external security communications are coordinated and documented. Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually improving. For further details, please refer to the 08-ISMS Procedure for Management Review.
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
Connect with us, follow our journey
Strateji was designed for the complexity of enterprise — and built to simplify it. To explore containerised deployment or discuss alignment with your enterprise architecture and compliance team:
Book an enterprise briefing




Lead through complexity — with confidence.
Strateji brings structure, visibility and accountability to modern leadership. Let’s explore how it could work for you.
Book an Enterprise Briefing
Turn complexity into clarity.

January 8, 2025
•
Dave Yeates
Information Security Management System (ISMS) Policy
This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system ("ISMS"), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 ("ISO 27001") standard.

Atlas Platforms Pty Ltd (The Company) is the company responsible for the EthosOne and the Strateji Platform it sits on.
Leadership and commitment
The Company is committed to continually enhancing its ISMS. This commitment is demonstrated through the actions of the ISMS Governance Council, which oversees implementation, monitoring, and improvements.
Atlas Platforms prioritizes the identification of risks and opportunities, embedding iterative risk assessments into agile workflows.
Regular evaluation of security risks and prioritization of mitigations.
Documented outcomes and updates tracked in all active products (eg. Strateji and Meta Agility).
Selection and implementation of controls to address identified risks.
Documented approvals and reviews integrated into quarterly retrospectives.
Atlas Platforms allocates funding, expertise, and tools to support ISMS operations.
Roles impacting information security are evaluated based on training, experience, and education. Competence gaps are addressed through mentoring, external expertise, or training.
Personnel complete annual awareness training and understand their roles and consequences of non-compliance.
Internal and external security communications are coordinated and documented. Policies are stored in Confluence and reviewed after major updates or annually.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Processes for creating, updating, and storing ISMS documentation are defined in the 05-ISMS Document Control Procedure.
Atlas Platforms integrates information security into agile workflows:
Atlas Platforms has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually improving. For further details, please refer to the 08-ISMS Procedure for Management Review.
Atlas Platforms is dedicated to perpetually enhancing the relevance, sufficiency, and efficiency of our information security management system.
All personnel, including employees, contractors, and third parties, must protect Atlas Platforms' data and systems. Violations may result in corrective actions, including training, reassignment, or termination, in line with severity and applicable laws.
ISO 27001 4.1; 4.2; 4.3; 5.1
This addendum is automatically applicable for organizations implementing ISO 27701 and optional for organizations who are implementing ISO 27001 only.
Connect with us, follow our journey
Strateji was designed for the complexity of enterprise — and built to simplify it. To explore containerised deployment or discuss alignment with your enterprise architecture and compliance team:Every organisation’s journey begins differently. Let’s discuss how to bring Strateji to life in yours.
Book a Discovery Call





Lead through complexity — with confidence.
Strateji brings structure, visibility and accountability to modern leadership. Let’s explore how it could work for you.
Book an Enterprise Briefing
Turn complexity into clarity.