
The scope statement of Prima's information security management system, the asset and risk basis behind it, the applicability decision on all 93 Annex A controls, and the sequenced path to ISO/IEC 27001, ISO 22301 and ISO 45001 certification.

Sections 02 to 06 are the inputs a certification body asks for first. Sections 07 and 08 are the applicability decision on every Annex A control — the document an auditor works through line by line. Section 09 states honestly what is written and what is not. Sections 10 and 11 set the sequence.
Scope, asset basis, risk method and register, and the applicability decision on all 93 controls. Enough for a certification body to quote a fee and a timeline against a real scope rather than a description.
Forty-four of the 93 controls are already covered by documents in issue — physical security, incident response, the procedure library, training and vetting, commissioning, spares and export control. Each is named at the control it evidences.
The policy set at 9.2, and every record that requires the ISMS to have been operating. Stated as a list with owners and dates rather than implied by omission.

ISO/IEC 27001 certifies a management system, not a building. This matters more than it sounds: it means the standard can be certified against the legal entity and its way of working before the facility it protects is energised. The common assumption — that certification must wait for the data centre to open — costs a year for no reason.
What cannot be shortened is the sequence a certification body follows. It begins by asking for four things: the scope, the assets, the risk assessment, and the decision taken on every control in Annex A. Only when those exist does it proceed to a stage 1 audit. A project that arrives without them spends its first six weeks producing them under time pressure, with the auditor waiting.
This document produces them in advance. It is written to be handed to a certification body at first contact, so that the response is a quotation against a defined scope rather than a request for the basics.
| ISO/IEC 27001 | Information security management. Certifies that the organisation identifies its information risks and manages them through a controlled, audited system. Certifiable before the facility opens — the scope is the entity and its processes. The one a customer, lender or regulator asks for first. |
|---|---|
| ISO 22301 | Business continuity management. Certifies that the organisation has analysed the impact of disruption and can continue or resume its critical activities. Partly dependent on the facility, because the continuity of a data centre is largely physical — but the impact analysis and the management system are certifiable earlier. |
| ISO 45001 | Occupational health and safety. Certifies that hazards to people are identified and controlled. Most relevant during construction, not after it — a site with contractors on it is exactly where this standard earns its place, so certifying after handover is the wrong way round. |

The scope is the single most consequential sentence in a certification. It determines what the certificate proves, what the auditor may examine, and what a customer is entitled to rely on. A scope drawn too narrowly produces a certificate that does not cover the service being sold; drawn too widely, it commits the organisation to controls over things it does not govern.
| The facility | The KOM Muscat site in full: data halls, electrical and thermal plant, the security estate, and the OT control layer — BMS, EPMS and access control. |
|---|---|
| The compute platform | The 1,728-node GPU estate, the network fabric, storage, the provisioning and scheduling control plane, and the tooling used to operate them. |
| Service delivery | Customer onboarding, access provisioning, capacity allocation, incident and change management, service reporting. |
| Corporate functions | The functions that handle information belonging to customers or the business: commercial, legal, finance, HR and procurement. Excluding these is the most common scoping error — it leaves the contracts, the personnel data and the supplier records outside the system that is supposed to protect them. |
| The whole legal entity | Prima Artificial Intelligence LLC, CR 1575008. Not a department, not a site-only scope. |
A site-only scope is easier to certify and materially less useful. The information a customer actually cares about — its contract, its capacity commitments, its technical requirements, the correspondence in which it disclosed them — lives in the company's systems, not in the data hall. A certificate that covers the hall and not the company answers the wrong question.
The wider scope also settles a question a reviewer will otherwise ask: whether the certificate covers the entity contracting with them. Naming the legal entity and its registration number removes the ambiguity.

An exclusion without a reason is a finding. Each of the following is outside scope because it is outside Prima's control, not because it is inconvenient.
| Excluded | Reason | How it is governed instead |
|---|---|---|
| Customer workloads and data | Prima provides bare-metal capacity and does not access, process or hold customer data. The customer is the controller of everything inside its own allocation. | Contract and the Demarcation Matrix, PRM-DEM-2026-001 |
| Customer-owned equipment in colocation | Configuration, patching and security of equipment the customer owns and administers is the customer's, per the demarcation boundary. | Demarcation Matrix; physical protection remains Prima's |
| Utility supply upstream of the intake | Generation and transmission are the utility's. Prima's boundary begins at the intake. | Supply agreement; resilience covered by on-site topology |
| Carrier networks beyond the handover | Prima does not operate the carriers' networks and cannot control them past the demarcation point. | Carrier SLAs; diverse paths and dual entries in design |
| Other Prima and consortium sites | Riyadh, Al Khobar, Kuwait City, Duqm and Sohar are outside this certification scope. Each is either operated under a different arrangement or not yet built. | Scope extension planned as sites reach service |
Three interfaces are neither in scope nor simply excluded — responsibility is shared, and the ISMS must show how. An auditor will test these specifically, because shared boundaries are where controls are most often assumed by both parties and held by neither.

Clause 4.2 of the standard requires the organisation to identify who has a stake in its information security and what each of them needs. The value of the exercise is not the list — it is that the risk register at section 06 can then be tested against real expectations rather than generic ones.
| Party | What they require of the ISMS | How it is evidenced |
|---|---|---|
| Compute customersofftakers, AI labs, enterprises | That their workloads, models and data cannot be accessed by Prima staff, by other customers, or by anyone unauthorised; that access to their equipment is controlled and logged; that incidents are disclosed to them. | PRM-SEC-2026-001, PRM-IRP-2026-001, SLA and audit rights |
| Colocation customers | Physical protection of equipment they own, a defined demarcation of responsibility, and the right to audit. | PRM-DEM-2026-001, Contract Schedules §04 |
| Lenders and investors | That information risk is identified and managed rather than assumed; that a failure would not be concealed; that the entity is certifiable to recognised standards. | This document, the DD document set, external certification |
| Consortium partnersAwasr, ElioVP, Hydra | That information shared under the joint venture is protected to a standard equivalent to their own, and that their commercial data is not disclosed to competing parties. | Joint venture agreements, NDA regime, access segregation |
| Regulators — Oman | Compliance with data protection law, sector requirements for government and financial data, licensing conditions, and cooperation with lawful requests. | Law-enforcement access policy §11, PDPL policy in preparation |
| Export control authorities | That controlled compute is not made available to restricted parties or diverted to restricted end uses. | PC-ECP-001 Export Compliance Policy |
| Employees and contractors | That their personal data is protected, that vetting is proportionate and lawful, and that they are trained for what they are held accountable for. | PRM-HR-2026-001, PDPL policy in preparation |
| Equipment suppliers | That technical information disclosed under supply agreements — designs, configurations, pricing — is protected. | Supplier agreements, classification and handling rules |
| Insurers | That risk is assessed and controlled to a standard that makes the risk underwritable, and that recommendations are tracked to closure. | Risk register §06, insurer survey when appointed |

Assets are identified by class, not by item. An inventory of individual files is unmaintainable and tells an auditor nothing; a classification with an owner, a handling rule and a retention period is what the controls actually attach to.
| Asset class | What it contains | Classification | Owner |
|---|---|---|---|
| Customer commercial information | Contracts, capacity commitments, pricing, requirements disclosed in negotiation, correspondence. | Confidential | CEO |
| Customer technical information | Allocation records, configuration requested, access lists, service reports, incident records affecting them. | Confidential | Eng Manager |
| Facility design information | Single-line diagrams, thermal design, as-built drawings, protection settings, commissioning records. | Confidential | Facilities Mgr |
| Security design and records | Access model, camera positions, detection coverage, access logs, video, investigation files. | Restricted | CISO |
| Credentials and secrets | Administrative credentials, keys, certificates, service accounts, OT control credentials. | Restricted | CISO |
| Operational records | Procedures, work orders, shift logs, environmental readings, maintenance history, drill records. | Internal | Ops Manager |
| Personnel information | Employment records, vetting outcomes, competence files, medical and access data. | Restricted | HR, with CISO |
| Supplier and consortium information | Supply agreements, equipment pricing, joint venture documents, partner technical disclosures. | Confidential | CFO |
| Export-control records | Screening results, end-use statements, licence records, deployment declarations. | Confidential | Compliance |
| Corporate and financial records | Statutory records, financial reporting, banking, insurance, tax. | Confidential | CFO |
| OT systems and their data | BMS, EPMS, access control and CCTV platforms — configuration, logs, historical data. | Restricted | CTO, with CISO |
| Compute platform and tooling | Provisioning and scheduling control plane, images, infrastructure-as-code, monitoring stack. | Internal | Eng Manager |

Customer workload data does not appear on this list, because Prima does not hold it. Bare-metal capacity means the customer administers its own systems and Prima has no logical access to what runs on them. This is the single most important fact about Prima's information risk profile, and it changes the shape of the whole register: the risk is unauthorised access to infrastructure, not misuse of data in Prima's custody.
Naming an owner in the table above is not a formality. Each owner carries four duties, and an auditor will ask any one of them to demonstrate the fourth.
Reviewed annually, and on any change to the service offering, the customer base or the systems that hold the information. A new asset class is added when a new kind of information enters the organisation — most commonly through a new contract form or a new system, which is why procurement and legal are both represented among the owners.

The standard does not prescribe a method; it requires that the method be defined, repeatable and consistently applied. What follows is deliberately simple, because a method too elaborate to repeat produces a register that is scored once and never revisited.
Each risk is written as threat acting on asset, causing consequence — not as a topic. “Insider access” is a topic and cannot be scored. “A contractor with unsupervised hall access removes a drive containing customer configuration data” is a risk, and the controls that reduce it are obvious from the sentence.
1 — not expected in the life of the asset.
2 — possible but no known instance in comparable operations.
3 — expected once in several years.
4 — expected annually.
5 — expected more than once a year.
1 — negligible; internal inconvenience.
2 — minor; contained, no customer effect.
3 — moderate; customer-visible or reportable.
4 — major; service credits, regulatory notification, or loss of confidence.
5 — severe; contract loss, licence risk, or safety consequence.
| Residual score | Band | Required action |
|---|---|---|
| 17 – 25 | Unacceptable | Treatment mandatory and immediate. Cannot be accepted by any office. Reported to the board until reduced. |
| 10 – 16 | High | Treatment plan required with owner and date. May be accepted only by the CEO, in writing, for a stated period. |
| 5 – 9 | Medium | Treated where reasonably practicable. May be accepted by the CISO with the reasoning recorded. |
| 1 – 4 | Low | Accepted by default. Reviewed annually to confirm the scoring still holds. |

Twelve risks, each traceable to a requirement in section 03 and to controls in sections 07 and 08. The register is deliberately short: a hundred-line register is a document nobody reads, and the controls that matter are driven by a dozen scenarios.
| Ref | Risk — threat acting on asset, causing consequence | Inherent | Residual | Principal controls |
|---|---|---|---|---|
| R01 | Unauthorised physical access to a data hall. A contractor, visitor or former employee gains unsupervised access and removes, alters or photographs equipment or information. | 20 | 6 | Five-layer access model with independent factors per layer · visitor escort · access recertification · 90-day video retention. PRM-SEC-2026-001 |
| R02 | Compromise of the OT control layer. BMS, EPMS or access control is reached from the corporate network or the internet, allowing an attacker to manipulate power, cooling or door state. | 20 | 8 | Network segregation · no direct internet path · jump-host with MFA and session recording · separate credential domain. Owner: CTO — architecture document outstanding, see 9.2 |
| R03 | Abuse of privileged access by an insider. An administrator with legitimate platform access uses it beyond authorisation, or acts on instruction from a third party. | 16 | 6 | Least privilege · segregation of duties · privileged session logging · three-tier vetting · two-person rule on restricted actions. PRM-HR-2026-001 |
| R04 | Vendor remote access misused or left open. A maintenance vendor retains access after the engagement, or its own credentials are compromised and used against the Facility. | 16 | 6 | Time-boxed authorisation per engagement · MFA at the gateway · full session recording · access revoked at close and verified at recertification |
| R05 | Customer isolation failure. One customer reaches another customer’s allocation, through a fabric misconfiguration or a failure to sanitise reassigned hardware. | 20 | 6 | Tenant segregation in the fabric · NIST 800-88 purge before reassignment, witnessed · change control on fabric configuration. PRM-SEC-2026-001 §10 |
| R06 | Export-control breach. Controlled compute is made available to a restricted party, or diverted to a restricted end use, through inadequate screening or an undisclosed sub-lease. | 20 | 8 | Restricted-party screening at onboarding and periodically · end-use statements · contractual prohibition on onward sub-lease · deployment declarations. PC-ECP-001 |

| Ref | Risk — threat acting on asset, causing consequence | Inherent | Residual | Principal controls |
|---|---|---|---|---|
| R07 | Loss of availability from a physical failure. An electrical or thermal failure interrupts service beyond the committed availability, through inadequate redundancy, an unrepaired first failure, or an untested procedure. | 20 | 8 | Tier III Standard topology · commissioning gates to L5 · EOP set drilled · critical spares held on site. PRM-CDP-2026-001, PRM-SPR-2026-001 |
| R08 | Disclosure of customer commercial information. Contract terms, pricing or capacity commitments reach a competitor, through mishandling, a misdirected message or an unmanaged departure. | 15 | 6 | Classification and handling rules · NDA regime · need-to-know on commercial systems · return of assets and access removal on departure |
| R09 | Consortium information leakage. Information a partner disclosed under the joint venture reaches a party it was not intended for, including another partner in a competing position. | 12 | 5 | Access segregation by workstream · partner-specific NDAs · classification at the point of receipt · restricted distribution lists |
| R10 | Failure to meet a legal or regulatory obligation. A data-protection, licensing or sector requirement is missed, or a lawful request is handled improperly. | 15 | 6 | Legal register with named owners · law-enforcement access policy · PDPL policy outstanding, see 9.2 · annual compliance review |
| R11 | Loss of records needed to prove a commitment. Commissioning results, access logs, drill records or service reports are lost or unretrievable when a customer, insurer or regulator asks for them. | 12 | 4 | Defined retention per class · controlled repository with backup · commissioning pack retained for asset life. PRM-OPS-2026-001 |
| R12 | Supply-chain compromise. Equipment or firmware arrives already compromised, or a supplier with privileged access is itself breached. | 12 | 6 | Purchase from authorised channels only · firmware verified against vendor hashes · supplier security terms in agreements · asset provenance recorded at receipt |
Three observations a reviewer should be able to draw from the twelve lines above, stated rather than left to inference.

A decision on every one of the 93 controls in Annex A of ISO/IEC 27001:2022. Applicable means the control is in force or scheduled; Partial means in force but with a named gap; Excluded means not applicable, with the reason stated. Eighty-eight are applicable in whole or part — 70 in full and 18 with a named gap — and five are excluded — all five for the same reason, at 8.34.
| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.5.1 | Policies for information security | Partial | Top-level policy outstanding; nine subordinate policies in issue. See 9.2 for the list and dates. |
| A.5.2 | Information security roles and responsibilities | Applicable | CISO with the COO; roles defined in PRM-ORG-2026-001 and per-document ownership. |
| A.5.3 | Segregation of duties | Applicable | Approval authority separated from execution throughout — release in PRM-OPS-2026-001, access approval in PRM-SEC-2026-001. |
| A.5.4 | Management responsibilities | Applicable | Board and delegation framework in the Corporate Governance Charter. |
| A.5.5 | Contact with authorities | Applicable | Law-enforcement access policy, PRM-SEC-2026-001 §11; regulator contacts held by Compliance. |
| A.5.6 | Contact with special interest groups | Applicable | Membership of Uptime Institute community and vendor security advisories; threat feeds via CISO. |
| A.5.7 | Threat intelligence | Partial | Vendor and CERT advisories consumed today; formal intake and triage process to follow the OT architecture at 9.2. |
| A.5.8 | Information security in project management | Applicable | Commissioning gates carry security acceptance criteria — PRM-CDP-2026-001 L2 to L5. |
| A.5.9 | Inventory of information and associated assets | Applicable | Asset classes at section 04; physical asset register under PRM-SOP-OPS-012. |
| A.5.10 | Acceptable use of information and assets | Partial | Terms in employment contracts; standalone acceptable-use policy at 9.2. |
| A.5.11 | Return of assets | Applicable | Leaver process in PRM-HR-2026-001, with access removal verified at recertification. |
| A.5.12 | Classification of information | Applicable | Four classes — Public, Internal, Confidential, Restricted — applied at section 04 and on every document in issue. |
| A.5.13 | Labelling of information | Applicable | Every controlled document carries its classification in the footer. Physical media labelled at receipt. |
| A.5.14 | Information transfer | Partial | NDA regime and controlled repository in force; encrypted-transfer standard for Restricted material at 9.2. |

| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.5.15 | Access control | Applicable | Five-layer model with independent factors per layer, PRM-SEC-2026-001. Logical access least-privilege by role. |
| A.5.16 | Identity management | Applicable | Single identity per person, no shared accounts, joiner-mover-leaver tied to HR record. |
| A.5.17 | Authentication information | Applicable | Multi-factor at every controlled layer and for all privileged access; secrets held in a managed vault. |
| A.5.18 | Access rights | Applicable | Provisioned on approval, reviewed at recertification, revoked on change or departure. Recertification cycle in PRM-SEC-2026-001 §07. |
| A.5.19 | Information security in supplier relationships | Applicable | Security terms in supply and maintenance agreements; vendor access governed per engagement. |
| A.5.20 | Addressing information security within supplier agreements | Partial | Terms present in current agreements; a standard security schedule for all future contracts at 9.2. |
| A.5.21 | Managing information security in the ICT supply chain | Applicable | Authorised channels only, firmware verified against vendor hashes, provenance recorded at receipt. Risk R12. |
| A.5.22 | Monitoring, review and change management of supplier services | Applicable | Contracted response times tested annually — PRM-SPR-2026-001 §10.5. Service reviews per agreement. |
| A.5.23 | Information security for use of cloud services | Partial | Corporate SaaS in use; a cloud-use standard covering approval and data placement at 9.2. |
| A.5.24 | Incident management planning and preparation | Applicable | PRM-IRP-2026-001 — P1 to P4 matrix, escalation to COO, roles and preparation. |
| A.5.25 | Assessment and decision on information security events | Applicable | Triage and severity assignment in PRM-IRP-2026-001; event reporting duty on all staff. |
| A.5.26 | Response to information security incidents | Applicable | Response procedures in PRM-IRP-2026-001; cyber-specific EOPs in PRM-OPS-2026-001. |
| A.5.27 | Learning from information security incidents | Applicable | Root-cause process with mandatory procedure revision. Case history accrues from service — see the DD note on line 27. |

| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.5.28 | Collection of evidence | Applicable | Evidence handling in PRM-IRP-2026-001; video export for lawful request under PRM-SOP-SEC-006 with chain of custody. |
| A.5.29 | Information security during disruption | Applicable | EOP set covering power, cooling, life safety and cyber; OT isolation procedure for a cyber event. |
| A.5.30 | ICT readiness for business continuity | Partial | Facility continuity established by topology and the EOP set. Formal business impact analysis under ISO 22301 at section 11. |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | Partial | Export control and law-enforcement obligations documented. Consolidated legal register and the PDPL policy at 9.2. Risk R10. |
| A.5.32 | Intellectual property rights | Applicable | Licensing of platform and vendor software tracked at procurement; partner IP handled under joint venture terms. |
| A.5.33 | Protection of records | Applicable | Retention per class — PRM-SPR-2026-001, PRM-CDP-2026-001 §09, PRM-SOP-REC-003. Commissioning pack held for asset life. |
| A.5.34 | Privacy and protection of PII | Partial | Personnel data classified Restricted with defined handling. Oman PDPL policy outstanding — the largest single gap, at 9.2. |
| A.5.35 | Independent review of information security | Partial | External certification audit is the intended mechanism. Internal audit programme cannot have evidence until the ISMS has run a cycle — see 9.3. |
| A.5.36 | Compliance with policies, rules and standards | Applicable | Quarterly audit of the procedure library and the spares register; access recertification; drill grading. |
| A.5.37 | Documented operating procedures | Applicable | PRM-OPS-2026-001 — 72 procedures indexed with numbering, version states and approval authority. |
Of the 37 organisational controls, 27 are applicable and in force, ten are partial. Every partial traces to one of two causes, and neither requires a third party: a policy that has not been written yet, or a record that cannot exist until the management system has been operating. Both are itemised at section 09.

Eight controls, all applicable. This group is the best-covered in the whole Statement of Applicability, because PRM-HR-2026-001 was written against a facility where the people with unsupervised access are the primary risk — which is exactly what these controls address.
| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.6.1 | Screening | Applicable | Three-tier vetting by criticality — PRM-HR-2026-001. Tier assigned by the same tests that define a critical role, so screening depth follows access rather than job title. |
| A.6.2 | Terms and conditions of employment | Applicable | Security obligations, confidentiality and acceptable use written into every contract before the effective date. |
| A.6.3 | Awareness, education and training | Applicable | Certification matrix per critical role with periodicity — PRM-HR-2026-001. Commissioning attendance counts toward competence. |
| A.6.4 | Disciplinary process | Applicable | Defined process for security breaches by staff, proportionate and recorded. Held by HR with the CISO. |
| A.6.5 | Responsibilities after termination or change of employment | Applicable | Access removal and asset return at departure, verified at the next recertification rather than assumed at the exit interview. |
| A.6.6 | Confidentiality or non-disclosure agreements | Applicable | NDAs for staff, contractors, visitors and partners. Signed before access is provisioned, not after. |
| A.6.7 | Remote working | Applicable | Remote access to corporate systems with MFA. No remote administrative access to the OT layer except through the recorded jump host — the strongest single statement in this group. |
| A.6.8 | Information security event reporting | Applicable | Duty on every person on site, with a no-blame route. Reporting obligation stated in PRM-IRP-2026-001 and in induction. |
Three of the twelve risks in section 06 — insider abuse of privilege, unauthorised physical access, and vendor access left open — are reduced principally by these eight controls rather than by any technical measure. A facility can be perfectly segmented and still lose customer confidence to one improperly vetted contractor with a hall pass.

The fourteen physical controls are the group a data-centre operator is judged on hardest, and the group where Prima has the most written. None is excluded — twelve are applicable in full and two carry a named gap. Eight rest directly on PRM-SEC-2026-001.
| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.7.1 | Physical security perimeters | Applicable | Layer 1 perimeter with detection and assessment before the line is reached — PRM-SEC-2026-001 §05. |
| A.7.2 | Physical entry | Applicable | Layer 2 portals with independent factors, anti-passback and interlock — PRM-SEC-2026-001 §06. Visitor registration and escort under PRM-SOP-SEC-002. |
| A.7.3 | Securing offices, rooms and facilities | Applicable | Zoning by layer: interior, hall, cage and rack each with its own entitlement — PRM-SEC-2026-001 §05. Spares store at Layer 3. |
| A.7.4 | Physical security monitoring | Applicable | Camera coverage of every controlled transition with 90-day minimum retention, 24×7 officer and NOC coverage — PRM-SEC-2026-001 §08. |
| A.7.5 | Protecting against physical and environmental threats | Partial | Fire, water and environmental detection designed and specified. Natural hazard assessment — flood, seismic, wind — outstanding, requires an external consultant. DD line 06. |
| A.7.6 | Working in secure areas | Applicable | Escort rules, permitted-activity list, prohibition on unrecorded photography, and a two-person rule on restricted actions — PRM-SEC-2026-001 §09. |
| A.7.7 | Clear desk and clear screen | Partial | Applied in practice; standalone policy statement at 9.2. |
| A.7.8 | Equipment siting and protection | Applicable | Rack siting, floor loading and A/B feed architecture in the design basis; no equipment sited where a leak path passes over it. |
| A.7.9 | Security of assets off-premises | Applicable | Equipment leaving site is authorised, logged and sanitised first where it held data — PRM-SEC-2026-001 §10. |
| A.7.10 | Storage media | Applicable | Media register, controlled handling by classification, and witnessed destruction — PRM-SEC-2026-001 §10. Media never leaves a hall unlogged. |
| A.7.11 | Supporting utilities | Applicable | Utility intake, generation, UPS and cooling designed to Tier III Standard with N+1; spares and drills behind them. |
| A.7.12 | Cabling security | Applicable | Segregated power and data routing, labelled and access-controlled containment, dual entry paths for carriers. |
| A.7.13 | Equipment maintenance | Applicable | Preventive regime with MOPs per system, approved before work on live plant — PRM-OPS-2026-001. |
| A.7.14 | Secure disposal or re-use of equipment | Applicable | Clear, Purge or Destroy per media type against NIST SP 800-88, witnessed, with a certificate per item — PRM-SEC-2026-001 §10. |

| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.8.1 | User endpoint devices | Applicable | Managed endpoints for staff with disk encryption and remote wipe. Unmanaged devices have no path to the OT layer. |
| A.8.2 | Privileged access rights | Applicable | Least privilege, named accounts, session logging on all privileged action, and two-person authorisation on restricted operations. Risk R03. |
| A.8.3 | Information access restriction | Applicable | Need-to-know on commercial and security material; classification determines the system it may be held in. |
| A.8.4 | Access to source code | Partial | Prima writes no software product. Infrastructure-as-code and platform configuration repositories are access-restricted with change control — the control applies to those, not to product code. |
| A.8.5 | Secure authentication | Applicable | Multi-factor throughout — physical layers, corporate systems, platform administration and the vendor gateway. |
| A.8.6 | Capacity management | Applicable | Power, thermal and fabric capacity tracked against contracted commitments — PRM-CAP-2026-001 reconciles utility, installed and contracted MW. |
| A.8.7 | Protection against malware | Applicable | Endpoint protection on corporate estate; OT layer protected by segregation and allow-listing rather than signature scanning, which is the correct approach on control systems. |
| A.8.8 | Management of technical vulnerabilities | Partial | Vendor advisories consumed and patching under change control. Penetration testing outstanding — corporate scope testable now, OT scope only after commissioning. DD line 37. |
| A.8.9 | Configuration management | Applicable | Baseline configurations held for platform and OT systems; drift detected and corrected under change control. |
| A.8.10 | Information deletion | Applicable | Deletion and sanitisation per class, with purge before any hardware reassignment between customers. Risk R05. |
| A.8.11 | Data masking | Partial | Limited application — Prima holds no customer datasets. Applies to personnel data in test and reporting contexts; standard to be set with the PDPL policy at 9.2. |
| A.8.12 | Data leakage prevention | Partial | Classification, need-to-know and controlled repositories in force. Technical egress controls on the corporate estate to follow the OT architecture at 9.2. |

| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.8.13 | Information backup | Applicable | Corporate and platform configuration backed up with tested restore. Note that customer workload backup is the customer’s — the demarcation is explicit in PRM-DEM-2026-001. |
| A.8.14 | Redundancy of information processing facilities | Applicable | Tier III Standard topology, N+1 across power and cooling, dual fabric paths, diverse carrier entry. Risk R07. |
| A.8.15 | Logging | Applicable | Access, privileged action, change and OT event logging with defined retention. Video at 90 days minimum. |
| A.8.16 | Monitoring activities | Applicable | 24×7 NOC monitoring of platform, fabric and environment; alarm routing and escalation in PRM-IRP-2026-001. |
| A.8.17 | Clock synchronisation | Applicable | Common time source across platform, OT and security systems. Without it, correlating an access record against a system event is guesswork. |
| A.8.18 | Use of privileged utility programs | Applicable | Restricted, logged, and permitted only from the recorded jump host on the OT side. |
| A.8.19 | Installation of software on operational systems | Applicable | Under change control only, from approved sources, with firmware verified against vendor hashes. Risk R12. |
| A.8.20 | Networks security | Applicable | Segmented architecture with no direct path from corporate or internet to the OT layer. Risk R02. |
| A.8.21 | Security of network services | Applicable | Carrier services taken at defined handover points with contracted terms; internal fabric under change control. |
| A.8.22 | Segregation of networks | Applicable | Corporate, platform management, tenant fabric and OT each separated. Tenant isolation is the control customers test hardest — Risk R05. |
| A.8.23 | Web filtering | Applicable | Applied on the corporate estate. The OT layer has no general internet path at all, which is a stronger control than filtering one. |
| A.8.24 | Use of cryptography | Partial | Encryption in transit for administrative access and transfers; at rest on endpoints and backups. Consolidated cryptographic standard, including key management, at 9.2. |

| Ref | Control | Decision | How it is met, or where it is written |
|---|---|---|---|
| A.8.25 | Secure development life cycle | Excluded | Prima does not develop software. No product, service or application is written for internal use or for customers. Reason applies to this control and the four marked Excluded below. |
| A.8.26 | Application security requirements | Excluded | No applications are specified or built. Requirements for procured platform software are handled as procurement criteria under A.5.19 and A.5.21. |
| A.8.27 | Secure system architecture and engineering principles | Applicable | Applicable and not excluded — this governs how the platform and OT estate are engineered and segmented, which Prima does do. Distinguished deliberately from the development controls around it. |
| A.8.28 | Secure coding | Excluded | No code is written. Infrastructure-as-code and configuration are covered by change control at A.8.32 and configuration management at A.8.9. |
| A.8.29 | Security testing in development and acceptance | Excluded | No development pipeline exists. Acceptance testing of procured systems runs through the commissioning gates in PRM-CDP-2026-001, which carry security criteria at L2 to L5. |
| A.8.30 | Outsourced development | Excluded | No development is outsourced. Where a supplier configures a system for Prima, it is governed as a supplier relationship under A.5.19 and A.5.20. |
| A.8.31 | Separation of development, test and production environments | Applicable | A staging environment exists for platform and OT configuration changes; production changes are validated there first under change control. |
| A.8.32 | Change management | Applicable | Change control across facility, platform and OT — raising, assessment, approval and scheduling under PRM-SOP-OPS-011 and the MOP regime. |
| A.8.33 | Test information | Partial | Applies to staging data for platform configuration. No customer data exists to be used in test, which removes the usual risk in this control; standard to be stated with the PDPL policy. |
| A.8.34 | Protection of information systems during audit testing | Applicable | Audit and penetration testing scoped, authorised in writing, and time-boxed. Testing on live plant runs only in agreed windows, as with any intervention. |
All five excluded controls — A.8.25, A.8.26, A.8.28, A.8.29 and A.8.30 — are excluded for one reason: Prima is an infrastructure operator, not a software developer. It writes no product code, ships no application, and runs no development pipeline.
The exclusion is stated narrowly on purpose. A.8.27 sits in the middle of the same group and is applicable, because secure architecture and engineering principles govern how the platform and the OT estate are designed — which Prima very much does. An auditor should read the boundary as drawn between building software and engineering infrastructure, not between technology and everything else.

A readiness document that does not state its own gaps is worthless to the party reading it. This section lists what exists, what is missing, and what cannot exist yet — in that order.
Forty-four distinct Annex A controls are evidenced by a document already written and in issue — counted as the distinct controls named in the third column below. A.8.29 is cited for context only and is not counted, being one of the five exclusions.
| Document | Reference | Controls it evidences |
|---|---|---|
| Physical Security Specification | PRM-SEC-2026-001 | A.5.15, 5.18, 5.28 · A.7.1–7.4, 7.6, 7.9, 7.10, 7.14 · A.8.10 |
| Incident Response Plan | PRM-IRP-2026-001 | A.5.24, 5.25, 5.26, 5.27, 5.28 · A.6.8 · A.8.16 |
| Operating Procedure Library | PRM-OPS-2026-001 | A.5.3, 5.29, 5.36, 5.37 · A.7.13 · A.8.19, 8.32 |
| Training, Certification & Vetting | PRM-HR-2026-001 | A.6.1–6.6 · A.5.11 |
| Commissioning & Drill Programme | PRM-CDP-2026-001 | A.5.8 · A.8.29 context · A.8.34 |
| Critical Spares & Spare Parts Policy | PRM-SPR-2026-001 | A.5.22 · A.7.11 · A.8.14 |
| Export Compliance Policy | PC-ECP-001 | A.5.31 in part · A.5.19 in part · risk R06 |
| Demarcation Matrix | PRM-DEM-2026-001 | A.5.20 boundary · A.8.13 boundary |
| Capacity Reconciliation Statement | PRM-CAP-2026-001 | A.8.6 |
| Corporate Governance Charter | — | A.5.2, 5.4 |

| Document | Owner | Target |
|---|---|---|
| Information Security Policy — the top-level statementA.5.1. Required by clause 5.2; a certification body will ask for it first | CISO | Aug 2026 |
| Data Protection & Privacy Policy — Oman PDPLA.5.34, A.8.11, A.8.33 · largest single gap · risk R10 | CISO with Legal | Aug 2026 |
| OT Security ArchitectureA.8.12, A.8.20 detail · risk R02 · DD lines 35–36 | CTO | Sep 2026 |
| Acceptable Use, and Clear Desk & Clear ScreenA.5.10, A.7.7 | CISO | Aug 2026 |
| Cryptographic and Key Management StandardA.8.24 · A.5.14 transfer | CTO with CISO | Sep 2026 |
| Supplier Security Schedule — standard contract annexA.5.20, A.5.23 | Legal with CISO | Sep 2026 |
| Consolidated Legal & Regulatory RegisterA.5.31 · risk R10 | Compliance | Sep 2026 |
| Threat Intelligence intake and triage processA.5.7 | CISO | Oct 2026 |
| Internal Audit Programme and Management Review calendarA.5.35 · clauses 9.2 and 9.3 | CISO | Oct 2026 |

Three requirements are not gaps in preparation — they are consequences of the management system being new. Stating them prevents a reviewer treating them as oversights.
| Window | What happens | Dependency |
|---|---|---|
| Aug 2026 | Appoint an accredited certification body. This document is the input — it lets a body quote against a defined scope rather than an inquiry. Top-level policy, PDPL policy and acceptable use issued. | Body selection; three documents |
| Sep 2026 | Remaining policy set issued. Optional gap assessment by the appointed body — worth taking, because a finding raised here is cheap and the same finding at stage 2 is not. | Six documents at 9.2 |
| Oct 2026 | ISMS operating. Internal audit programme and management review calendar in force. Corporate-scope penetration test — testable now, OT scope deferred. | Testing firm appointment |
| Nov 2026 | Stage 1 audit — documentation and readiness review. The body checks that the ISMS is designed and documented, not yet that it works. First internal audit completed. | Policy set complete |
| Dec 2026 | First management review. Any stage 1 findings closed. Facility reaches service at gate L5, and operational records begin accruing against the physical controls. | Commissioning L5 |
| Q1 2027 | Stage 2 audit — the body tests whether the system is operating as documented, by sampling records. Certificate on closure of findings. | One operating cycle of records |
Not the documents, and not the facility. The appointment of the certification body. Accredited bodies in the region schedule stage 1 and stage 2 audits months ahead, and a slip in appointment moves the certificate by a full quarter regardless of how ready the ISMS is.

The diligence line asks for three certificates. They do not sequence equally, and treating them as one workstream would delay all three.
| What is already done | The operational half of continuity is largely in place: Tier III Standard topology with N+1, the 17-procedure emergency set, the drill calendar, critical spares, and the incident response and escalation regime. These are the substance of continuity for a data centre. |
|---|---|
| What is missing | The management-system half. Specifically a formal business impact analysis — critical activities identified, maximum tolerable period of disruption stated per activity, recovery time and recovery point objectives set — and a continuity plan covering the business, not only the plant. |
| The distinction that matters | Prima has continuity of the facility. It does not yet have documented continuity of the company — what happens if the corporate office is unavailable, if key personnel are lost, if a supplier fails. That is what 22301 certifies. |
| Sequence | Business impact analysis and continuity plan Q4 2026. Certification audit Q2 2027, after 27001 — deliberately second, because 22301 shares clauses 4 to 10 with 27001 and reuses the same management system. Running them together would double the audit burden for no benefit. |
| Why it is urgent, not deferred | 45001 is most relevant during construction. A site with contractors, lifting operations, live electrical work and confined spaces is precisely where this standard earns its place. Certifying after handover, when the hazardous phase is over, inverts its purpose. |
|---|---|
| What exists | Contractor induction and supervision, permit-to-work discipline through the MOP regime, life-safety emergency procedures, and the evacuation and roll-call drill in the programme. |
| What is missing | A hazard identification and risk assessment covering construction and operational activities, an OH&S policy, worker consultation arrangements, and incident and near-miss reporting for safety as distinct from security. |
| Sequence | OH&S management system Q4 2026, certification audit Q2 2027 alongside 22301. Both reuse the 27001 management system, which is why 27001 goes first. |
| Owner | CISO. Owns the scope, the risk register, the Statement of Applicability and the policy set. Accepts medium-band risks; escalates high band to the CEO. |
|---|---|
| Management representative | COO. Accountable to the board for the effectiveness of the system, chairs the management review. |
| Board oversight | Any risk in the unacceptable band is reported to the board until reduced. Certification status reported quarterly. |
| Review of this document | Annually, and on any change to scope, plant, customer base or threat picture. Reviewed after any incident, whether or not it was in the register. Recorded even where nothing changes. |

Clause 9.1 requires the effectiveness of the ISMS to be monitored and measured. Reported to the COO on the cadence shown, and to the board quarterly.
| Measure | Target | Reported |
|---|---|---|
| Applicable controls with evidence available on request | 100% | Quarterly |
| Risks reviewed within their review date | 100% | Quarterly |
| Risks in the unacceptable band, after treatment | 0 | Monthly |
| Accepted risks past their acceptance expiry | 0 | Quarterly |
| Access recertification completed on cycle | 100% | Quarterly |
| Security events reported and triaged within SLA | ≥ 95% | Monthly |
| Internal audit findings closed within 60 days | ≥ 90% | Quarterly |
| Staff with security training current | 100% | Quarterly |
| Policies within their review date | 100% | Annually |
| Certification and surveillance audits passed | All | Per audit |
Stated in four lines so that a reviewer, a lender or a certification body can take the position without reading the document.
For the scope statement in its current wording, the risk register, the Statement of Applicability, or the readiness position ahead of appointing a certification body.