Audit & Software Procedures
Software Approval Process
OET-ISMS-POL-012
Purpose
To ensure that new software used within the organization is reviewed for security, data protection, and business necessity before approval.
Responsibilities
- Requester: Provides business justification
- Process owner (IT): Performs security and risk review
- Management: Approves or rejects based on risk.
This process applies to all new software, SaaS tools, browser extensions, plugins, and open-source tools used for business purposes.
Policy document
Access the current version of the policy
Corrective Action Procedure
OET-ISMS-POL-013
Purpose
The purpose of this procedure is to ensure that all identified nonconformities within the ISMS are corrected in a timely, controlled, and traceable manner through documented corrective actions.
Scope
This procedure applies to all nonconformities identified during internal audits, external audits, incident reviews, monitoring activities, and day-to-day ISMS operations.
Policy document
Access the current version of the policy
Internal Audit Procedure
OET-ISMS-POL-014
Purpose
This procedure establishes the framework for conducting internal audits of the Information Security Management System (ISMS) to ensure compliance with ISO 27001:2022 requirements, organizational policies, and applicable legal and regulatory requirements. Internal audits verify the effectiveness of information security controls and identify opportunities for improvement.
Scope
This procedure applies to all components of Open Energy Transition's ISMS including:
- Information security policies and procedures
- Risk assessment and treatment processes
- Security controls implementation (ISO 27001:2022 Annex A controls)
- Asset management and data protection
- Access control and identity management
- Physical and environmental security
- Operations security and network management
- Incident management and business continuity
- Supplier relationships and cloud services
- Compliance with legal and regulatory requirements
Policy document
Access the current version of the policy
List of Applicable Standards and Regulations
OET-ISMS-POL-015
Purpose
The purpose of this list is to identify and document all relevant legal, statutory, regulatory, and contractual requirements related to information security that Open Energy Transition (OET) must comply with.
Scope
This policy applies to all OET activities, including software development , environmental consultancy, data management, and international research collaborations.
Policy document
Access the current version of the policy
List of all stakeholders/interested parties
OET-ISMS-POL-016
Purpose
The purpose of this list is to define the internal and external stakeholders (interested parties) relevant to the Information Security Management System (ISMS) of Open Energy Transition (OET). This policy ensures that OET identifies, monitors, and reviews the security requirements of these parties to maintain the confidentiality, integrity, and availability of its energy modeling services and software.
Scope
This policy applies to all operations within OET, including software development (PyPSA, Linopy, etc.), consultancy services, and data management.
Policy document
Access the current version of the policy
Artificial Intelligence (AI) Governance and Security Policy
OET-ISMS-POL-020
Purpose
The purpose of this policy is to define the principles for the secure and ethical use of AI systems within OET. This policy applies to all AI applications, including General Purpose AI (GPAI) like Gemini, coding assistants like Cursor, and any custom models developed for energy modeling. It aligns with ISO 27001 Clause 4.1 by considering the organizational context and stakeholders.
Policy document
Access the current version of the policy
Information Systems Testing during Auditing
OET-ISMS-POL-021
Purpose
To ensure that technical testing activities performed during audits or third-party engagements do not cause service disruptions, data breaches, or unauthorized changes to OET's operational systems.
Roles & Responsibilities
ISO: Owns this policy; must be present during technical testing on production systems; approves test plans jointly with the Head of Software Engineering. Head of Software Engineering: Approves test plans; ensures technical safeguards are in place during testing; validates post-test system integrity.
