Security Attestation

Effective Date: 1 October 2025

Last Reviewed: 17 August 2026

This Security Attestation outlines the minimum set of controls and practices implemented by Entag to protect the confidentiality, integrity and availability of its services and information assets. It is intended to provide transparency into Entag’s security posture and may be referenced in contractual agreements or vendor due diligence processes.

Entag maintains a comprehensive Information Security Management System (ISMS), certified to the ISO/IEC 27001:2022 standard. The scope of certification includes:

The provision of technology services, solutions and consulting. It covers the management of information and business activities that support these services, in accordance with the ISMS Statement of Applicability revision 1, dated 10th February, 2025. It covers the offices located at Vitality Village, Level 4, 5 Discovery Court, Birtinya, Queensland 4575 Australia as well as Lower and Ground floors at 20 Hudson Rd Albion, Queensland 4010, Australia.

Entag has also achieved Maturity Level 3 alignment with the Australian Cyber Security Centre’s (ACSC) Essential Eight mitigation strategies, independently validated by ProcessUnity (formerly CyberGRX).

Minimum Security Controls

  1. Governance & Oversight
    • Dedicated security and compliance personnel responsible for ISMS implementation and maintenance.
    • Regular internal audits and risk assessments reported to senior management.
  2. Access Control & Identity Management
    • Enforcement of Least Privilege and Need-to-Know principles.
    • Multi-Factor Authentication (MFA) for privileged and remote access.
    • Automated provisioning/deprovisioning and periodic access reviews.
  3. Data Protection & Encryption
    • Encryption of data at rest and in transit using industry-standard protocols.
    • Logical segregation of data and role-based access controls.
    • Secure disposal of media and assets.
  4. System & Network Security
    • Enterprise-grade firewalls and layered network architecture.
    • Vulnerability scanning, patch management and threat protection technologies.
    • Traffic monitoring and event correlation to detect and respond to threats.
  5. Monitoring & Logging
    • Centralised logging of system and user activity.
    • Integration with SIEM tools for real-time alerting and analysis.
  6. Incident Management
    • Documented incident response procedures with regular testing.
    • Root cause analysis and corrective actions following security events.
  7. Change Management
    • Formal change control processes for all material system and infrastructure changes.
    • Configuration standards are developed in consultation with external cyber security firms and aligned with industry best practices.
  8. Physical & Environmental Security
    • Controlled access to data centres and server rooms.
    • Environmental safeguards against fire, water, and heat damage.
  9. Third-Party Risk Management
    • Risk assessments for critical suppliers and cloud providers.
    • Assessments are supported by engagements with independent cyber security consultancies to validate control effectiveness and identify areas for improvement.
  10. Business Continuity & Disaster Recovery
    • Documented and tested recovery procedures to ensure service continuity.
  11. Security Awareness & Training
    • Mandatory training for all staff, including phishing simulations.
    • Annual policy reviews and updates.
  12. Human Resource Security
    • Pre-employment screening including police checks and reference verification.
    • Mandatory onboarding training covering acceptable use, data handling, phishing, and incident reporting.
    • Formal acknowledgement of key ISMS policies such as the Acceptable Use Policy and Data Protection Policy.
    • Secure offboarding procedures including prompt access revocation and asset recovery.

Entag is committed to the continual improvement of its information security management framework. This attestation will be reviewed and updated as required to reflect changes in our practices; risk landscape; regulatory and contractual obligations.

View ISO207001 Certificate here

For more information or to request access to ISMS policies, please contact info@entag.com.au