Prima — ISMS Scope & ISO Readiness · A4 · 24pp · Draft v0.1
DRAFT
Draft
Part ofPetroCompute
ISMS Scope & ISO Readiness
The scope, the risks,
and the path to
certification

The scope statement of Prima's information security management system, the asset and risk basis behind it, the applicability decision on all 93 Annex A controls, and the sequenced path to ISO/IEC 27001, ISO 22301 and ISO 45001 certification.

Document
PRM-ISM-2026-001
Version
0.1 — Draft
Classification
Internal — controlled
Owner
CISO
Standards
27001 · 22301 · 45001
93
Annex A controls,
each decided
3
Standards on the
certification path
Q127
Target for the first
certificate, 27001
0
Controls excluded
without a reason
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled01 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 02 / 24
How to read this

Sections 02 to 06 are the inputs a certification body asks for first. Sections 07 and 08 are the applicability decision on every Annex A control — the document an auditor works through line by line. Section 09 states honestly what is written and what is not. Sections 10 and 11 set the sequence.

Already written

Scope, asset basis, risk method and register, and the applicability decision on all 93 controls. Enough for a certification body to quote a fee and a timeline against a real scope rather than a description.

This document
Written elsewhere

Forty-four of the 93 controls are already covered by documents in issue — physical security, incident response, the procedure library, training and vetting, commissioning, spares and export control. Each is named at the control it evidences.

Cross-referenced
Not yet written

The policy set at 9.2, and every record that requires the ISMS to have been operating. Stated as a list with owners and dates rather than implied by omission.

Named openly
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled02 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 03 / 24
01Why this document exists before the auditor does

ISO/IEC 27001 certifies a management system, not a building. This matters more than it sounds: it means the standard can be certified against the legal entity and its way of working before the facility it protects is energised. The common assumption — that certification must wait for the data centre to open — costs a year for no reason.

What cannot be shortened is the sequence a certification body follows. It begins by asking for four things: the scope, the assets, the risk assessment, and the decision taken on every control in Annex A. Only when those exist does it proceed to a stage 1 audit. A project that arrives without them spends its first six weeks producing them under time pressure, with the auditor waiting.

This document produces them in advance. It is written to be handed to a certification body at first contact, so that the response is a quotation against a defined scope rather than a request for the basics.

1.1 What the three standards each certify
ISO/IEC 27001Information security management. Certifies that the organisation identifies its information risks and manages them through a controlled, audited system. Certifiable before the facility opens — the scope is the entity and its processes. The one a customer, lender or regulator asks for first.
ISO 22301Business continuity management. Certifies that the organisation has analysed the impact of disruption and can continue or resume its critical activities. Partly dependent on the facility, because the continuity of a data centre is largely physical — but the impact analysis and the management system are certifiable earlier.
ISO 45001Occupational health and safety. Certifies that hazards to people are identified and controlled. Most relevant during construction, not after it — a site with contractors on it is exactly where this standard earns its place, so certifying after handover is the wrong way round.
1.2 What a certification body will ask for at first contact
  1. The scope statement — in the exact words that will appear on the certificate, with anything excluded stated and justified. Section 02.
  2. The interested parties and what each requires of the ISMS. Section 03.
  3. The information assets in scope, by class rather than by item. Section 04.
  4. The risk assessment method and the criteria for accepting a risk, plus the register itself. Sections 05 and 06.
  5. The Statement of Applicability — a decision on all 93 Annex A controls, with a reason for every exclusion. Sections 07 and 08.
  6. The policy set, an internal audit programme, and evidence of management review. Section 09 states which exist.
Honest positionItems 1 to 5 are produced here. Item 6 is partly outstanding: the policy set is listed at 9.2 with owners and dates, and internal audit and management review cannot have evidence until the ISMS has been operating for a cycle. No certificate is claimed and none is implied — this is the readiness position, stated so that a reviewer can see the gap rather than infer it.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled03 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 04 / 24
02Scope statement — the words that go on the certificate

The scope is the single most consequential sentence in a certification. It determines what the certificate proves, what the auditor may examine, and what a customer is entitled to rely on. A scope drawn too narrowly produces a certificate that does not cover the service being sold; drawn too widely, it commits the organisation to controls over things it does not govern.

Proposed scopeThe provision of sovereign AI-ready colocation and GPU compute capacity from the Knowledge Oasis Muscat facility, Sultanate of Oman — including the design, commissioning, operation and maintenance of the data centre and its compute platform, customer onboarding and service delivery, and the supporting corporate functions of Prima Artificial Intelligence LLC.
2.1 What that sentence deliberately includes
The facilityThe KOM Muscat site in full: data halls, electrical and thermal plant, the security estate, and the OT control layer — BMS, EPMS and access control.
The compute platformThe 1,728-node GPU estate, the network fabric, storage, the provisioning and scheduling control plane, and the tooling used to operate them.
Service deliveryCustomer onboarding, access provisioning, capacity allocation, incident and change management, service reporting.
Corporate functionsThe functions that handle information belonging to customers or the business: commercial, legal, finance, HR and procurement. Excluding these is the most common scoping error — it leaves the contracts, the personnel data and the supplier records outside the system that is supposed to protect them.
The whole legal entityPrima Artificial Intelligence LLC, CR 1575008. Not a department, not a site-only scope.
2.2 Why the entity, not just the site

A site-only scope is easier to certify and materially less useful. The information a customer actually cares about — its contract, its capacity commitments, its technical requirements, the correspondence in which it disclosed them — lives in the company's systems, not in the data hall. A certificate that covers the hall and not the company answers the wrong question.

The wider scope also settles a question a reviewer will otherwise ask: whether the certificate covers the entity contracting with them. Naming the legal entity and its registration number removes the ambiguity.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled04 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 05 / 24
02Scope statement, continuedBoundaries
2.3 Exclusions, each with its reason

An exclusion without a reason is a finding. Each of the following is outside scope because it is outside Prima's control, not because it is inconvenient.

ExcludedReasonHow it is governed instead
Customer workloads and dataPrima provides bare-metal capacity and does not access, process or hold customer data. The customer is the controller of everything inside its own allocation.Contract and the Demarcation Matrix, PRM-DEM-2026-001
Customer-owned equipment in colocationConfiguration, patching and security of equipment the customer owns and administers is the customer's, per the demarcation boundary.Demarcation Matrix; physical protection remains Prima's
Utility supply upstream of the intakeGeneration and transmission are the utility's. Prima's boundary begins at the intake.Supply agreement; resilience covered by on-site topology
Carrier networks beyond the handoverPrima does not operate the carriers' networks and cannot control them past the demarcation point.Carrier SLAs; diverse paths and dual entries in design
Other Prima and consortium sitesRiyadh, Al Khobar, Kuwait City, Duqm and Sohar are outside this certification scope. Each is either operated under a different arrangement or not yet built.Scope extension planned as sites reach service
2.4 Interfaces where responsibility is shared

Three interfaces are neither in scope nor simply excluded — responsibility is shared, and the ISMS must show how. An auditor will test these specifically, because shared boundaries are where controls are most often assumed by both parties and held by neither.

  • Vendor remote access. The vendor holds its own credentials and its own conduct; Prima holds the gateway, the authentication, the session recording and the authorisation. Prima's side is in scope.
  • Construction and commissioning contractors. Their working practices are theirs; their access to the site and to information about it is Prima's. Governed under PRM-SEC-2026-001 and PRM-HR-2026-001.
  • The consortium. Information shared with Awasr, ElioVP and Hydra under the joint venture is in scope while in Prima's custody. What each partner does within its own organisation is not, and is addressed by agreement rather than by this certificate.
Scope extensionThe scope is written so that additional sites can be added without re-certification — a scope extension audit rather than a new certificate. Drafting it as a site-specific scope now would force a full re-certification when Duqm or Sohar reach service. This is a deliberate choice made at the cost of a slightly wider first audit.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled05 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 06 / 24
03Interested parties and their requirements

Clause 4.2 of the standard requires the organisation to identify who has a stake in its information security and what each of them needs. The value of the exercise is not the list — it is that the risk register at section 06 can then be tested against real expectations rather than generic ones.

PartyWhat they require of the ISMSHow it is evidenced
Compute customersofftakers, AI labs, enterprisesThat their workloads, models and data cannot be accessed by Prima staff, by other customers, or by anyone unauthorised; that access to their equipment is controlled and logged; that incidents are disclosed to them.PRM-SEC-2026-001, PRM-IRP-2026-001, SLA and audit rights
Colocation customersPhysical protection of equipment they own, a defined demarcation of responsibility, and the right to audit.PRM-DEM-2026-001, Contract Schedules §04
Lenders and investorsThat information risk is identified and managed rather than assumed; that a failure would not be concealed; that the entity is certifiable to recognised standards.This document, the DD document set, external certification
Consortium partnersAwasr, ElioVP, HydraThat information shared under the joint venture is protected to a standard equivalent to their own, and that their commercial data is not disclosed to competing parties.Joint venture agreements, NDA regime, access segregation
Regulators — OmanCompliance with data protection law, sector requirements for government and financial data, licensing conditions, and cooperation with lawful requests.Law-enforcement access policy §11, PDPL policy in preparation
Export control authoritiesThat controlled compute is not made available to restricted parties or diverted to restricted end uses.PC-ECP-001 Export Compliance Policy
Employees and contractorsThat their personal data is protected, that vetting is proportionate and lawful, and that they are trained for what they are held accountable for.PRM-HR-2026-001, PDPL policy in preparation
Equipment suppliersThat technical information disclosed under supply agreements — designs, configurations, pricing — is protected.Supplier agreements, classification and handling rules
InsurersThat risk is assessed and controlled to a standard that makes the risk underwritable, and that recommendations are tracked to closure.Risk register §06, insurer survey when appointed
The test this table has to passEvery requirement in the middle column must trace to at least one risk in section 06 and at least one applicable control in sections 07 and 08. Where it does not, either the requirement is not really being managed or the register is incomplete. This traceability is what an auditor samples.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled06 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 07 / 24
04Information assets in scope

Assets are identified by class, not by item. An inventory of individual files is unmaintainable and tells an auditor nothing; a classification with an owner, a handling rule and a retention period is what the controls actually attach to.

Asset classWhat it containsClassificationOwner
Customer commercial informationContracts, capacity commitments, pricing, requirements disclosed in negotiation, correspondence.ConfidentialCEO
Customer technical informationAllocation records, configuration requested, access lists, service reports, incident records affecting them.ConfidentialEng Manager
Facility design informationSingle-line diagrams, thermal design, as-built drawings, protection settings, commissioning records.ConfidentialFacilities Mgr
Security design and recordsAccess model, camera positions, detection coverage, access logs, video, investigation files.RestrictedCISO
Credentials and secretsAdministrative credentials, keys, certificates, service accounts, OT control credentials.RestrictedCISO
Operational recordsProcedures, work orders, shift logs, environmental readings, maintenance history, drill records.InternalOps Manager
Personnel informationEmployment records, vetting outcomes, competence files, medical and access data.RestrictedHR, with CISO
Supplier and consortium informationSupply agreements, equipment pricing, joint venture documents, partner technical disclosures.ConfidentialCFO
Export-control recordsScreening results, end-use statements, licence records, deployment declarations.ConfidentialCompliance
Corporate and financial recordsStatutory records, financial reporting, banking, insurance, tax.ConfidentialCFO
OT systems and their dataBMS, EPMS, access control and CCTV platforms — configuration, logs, historical data.RestrictedCTO, with CISO
Compute platform and toolingProvisioning and scheduling control plane, images, infrastructure-as-code, monitoring stack.InternalEng Manager
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled07 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 08 / 24
04Information assets in scope, continuedOwnership and absence
4.1 The class that is deliberately absent

Customer workload data does not appear on this list, because Prima does not hold it. Bare-metal capacity means the customer administers its own systems and Prima has no logical access to what runs on them. This is the single most important fact about Prima's information risk profile, and it changes the shape of the whole register: the risk is unauthorised access to infrastructure, not misuse of data in Prima's custody.

Why this helps the auditAn operator that holds no customer data has a materially narrower breach surface, and an auditor can verify the claim architecturally rather than take it on assurance. It is stated here because the absence of a data-processing role is a control in itself, and it is worth naming rather than leaving to inference.
4.2 What an asset owner is accountable for

Naming an owner in the table above is not a formality. Each owner carries four duties, and an auditor will ask any one of them to demonstrate the fourth.

  1. Classification. Deciding the class of new information in their area, and correcting it where it has been set wrongly. Classification drifts downward if nobody owns it — material starts Confidential and is treated as Internal within a year.
  2. Access. Approving who may reach it, and confirming at each recertification cycle that the list still reflects need rather than history.
  3. Retention. Ensuring it is kept for as long as it is needed and no longer. Records held past their retention period are a liability, not an asset.
  4. Disposal. Authorising destruction when retention expires, to the standard set for the media in PRM-SEC-2026-001 §10.
4.3 Review of the asset basis

Reviewed annually, and on any change to the service offering, the customer base or the systems that hold the information. A new asset class is added when a new kind of information enters the organisation — most commonly through a new contract form or a new system, which is why procurement and legal are both represented among the owners.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled08 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 09 / 24
05Risk method and acceptance criteria

The standard does not prescribe a method; it requires that the method be defined, repeatable and consistently applied. What follows is deliberately simple, because a method too elaborate to repeat produces a register that is scored once and never revisited.

5.1 How a risk is expressed

Each risk is written as threat acting on asset, causing consequence — not as a topic. “Insider access” is a topic and cannot be scored. “A contractor with unsupervised hall access removes a drive containing customer configuration data” is a risk, and the controls that reduce it are obvious from the sentence.

5.2 Scoring
Likelihood, 1 to 5

1 — not expected in the life of the asset.
2 — possible but no known instance in comparable operations.
3 — expected once in several years.
4 — expected annually.
5 — expected more than once a year.

Judged before controls, then after
Impact, 1 to 5

1 — negligible; internal inconvenience.
2 — minor; contained, no customer effect.
3 — moderate; customer-visible or reportable.
4 — major; service credits, regulatory notification, or loss of confidence.
5 — severe; contract loss, licence risk, or safety consequence.

Highest of confidentiality, integrity, availability
5.3 Acceptance criteria
Residual scoreBandRequired action
17 – 25UnacceptableTreatment mandatory and immediate. Cannot be accepted by any office. Reported to the board until reduced.
10 – 16HighTreatment plan required with owner and date. May be accepted only by the CEO, in writing, for a stated period.
5 – 9MediumTreated where reasonably practicable. May be accepted by the CISO with the reasoning recorded.
1 – 4LowAccepted by default. Reviewed annually to confirm the scoring still holds.
5.4 Rules that keep the register honest
  • Inherent score is recorded before controls, residual after. A register showing only residual scores hides how much work the controls are doing, and an auditor cannot test a control whose contribution is invisible.
  • No risk is closed, only reduced or accepted. Closure implies the threat has gone. Threats do not go; controls change.
  • Acceptance is time-limited. Every accepted risk carries a review date. An acceptance with no expiry becomes a permanent exception nobody revisits.
  • Reviewed quarterly, and on any change to the scope, the plant, the customer base or the threat picture. Also after any incident, whether or not the incident was in the register — an incident that was not anticipated is a finding against the method, not just against operations.
  • Safety risks are not traded against commercial ones. Any risk with a safety consequence is scored at impact 5 and cannot be accepted below the CEO.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled09 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 10 / 24
06Risk register — the twelve that drive the controlsR01 – R06

Twelve risks, each traceable to a requirement in section 03 and to controls in sections 07 and 08. The register is deliberately short: a hundred-line register is a document nobody reads, and the controls that matter are driven by a dozen scenarios.

RefRisk — threat acting on asset, causing consequenceInherentResidualPrincipal controls
R01Unauthorised physical access to a data hall. A contractor, visitor or former employee gains unsupervised access and removes, alters or photographs equipment or information.206Five-layer access model with independent factors per layer · visitor escort · access recertification · 90-day video retention. PRM-SEC-2026-001
R02Compromise of the OT control layer. BMS, EPMS or access control is reached from the corporate network or the internet, allowing an attacker to manipulate power, cooling or door state.208Network segregation · no direct internet path · jump-host with MFA and session recording · separate credential domain. Owner: CTO — architecture document outstanding, see 9.2
R03Abuse of privileged access by an insider. An administrator with legitimate platform access uses it beyond authorisation, or acts on instruction from a third party.166Least privilege · segregation of duties · privileged session logging · three-tier vetting · two-person rule on restricted actions. PRM-HR-2026-001
R04Vendor remote access misused or left open. A maintenance vendor retains access after the engagement, or its own credentials are compromised and used against the Facility.166Time-boxed authorisation per engagement · MFA at the gateway · full session recording · access revoked at close and verified at recertification
R05Customer isolation failure. One customer reaches another customer’s allocation, through a fabric misconfiguration or a failure to sanitise reassigned hardware.206Tenant segregation in the fabric · NIST 800-88 purge before reassignment, witnessed · change control on fabric configuration. PRM-SEC-2026-001 §10
R06Export-control breach. Controlled compute is made available to a restricted party, or diverted to a restricted end use, through inadequate screening or an undisclosed sub-lease.208Restricted-party screening at onboarding and periodically · end-use statements · contractual prohibition on onward sub-lease · deployment declarations. PC-ECP-001
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled10 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 11 / 24
06Risk register, continuedR07 – R12
RefRisk — threat acting on asset, causing consequenceInherentResidualPrincipal controls
R07Loss of availability from a physical failure. An electrical or thermal failure interrupts service beyond the committed availability, through inadequate redundancy, an unrepaired first failure, or an untested procedure.208Tier III Standard topology · commissioning gates to L5 · EOP set drilled · critical spares held on site. PRM-CDP-2026-001, PRM-SPR-2026-001
R08Disclosure of customer commercial information. Contract terms, pricing or capacity commitments reach a competitor, through mishandling, a misdirected message or an unmanaged departure.156Classification and handling rules · NDA regime · need-to-know on commercial systems · return of assets and access removal on departure
R09Consortium information leakage. Information a partner disclosed under the joint venture reaches a party it was not intended for, including another partner in a competing position.125Access segregation by workstream · partner-specific NDAs · classification at the point of receipt · restricted distribution lists
R10Failure to meet a legal or regulatory obligation. A data-protection, licensing or sector requirement is missed, or a lawful request is handled improperly.156Legal register with named owners · law-enforcement access policy · PDPL policy outstanding, see 9.2 · annual compliance review
R11Loss of records needed to prove a commitment. Commissioning results, access logs, drill records or service reports are lost or unretrievable when a customer, insurer or regulator asks for them.124Defined retention per class · controlled repository with backup · commissioning pack retained for asset life. PRM-OPS-2026-001
R12Supply-chain compromise. Equipment or firmware arrives already compromised, or a supplier with privileged access is itself breached.126Purchase from authorised channels only · firmware verified against vendor hashes · supplier security terms in agreements · asset provenance recorded at receipt
6.1 What the register shows about this operation

Three observations a reviewer should be able to draw from the twelve lines above, stated rather than left to inference.

  • The dominant risk is access, not data. Five of the twelve concern someone reaching infrastructure they should not — physical, logical, vendor, insider or tenant. Only two concern information in Prima’s custody. That follows directly from holding no customer workload data, and it is why the control emphasis sits on access and segregation.
  • Two risks carry a residual of 8 pending a document that is not yet written. R02 waits on the OT security architecture, R10 on the data-protection policy. Both are named at 9.2 with an owner. Neither is hidden in a footnote.
  • No risk sits above the acceptance threshold after treatment. Every residual is 8 or below, which is inside the medium band and acceptable at CISO level. Two are at the top of that band, which is why they carry outstanding actions rather than acceptances.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled11 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 12 / 24
07Annex A applicability — organisational and peopleA.5.1 – A.5.14

A decision on every one of the 93 controls in Annex A of ISO/IEC 27001:2022. Applicable means the control is in force or scheduled; Partial means in force but with a named gap; Excluded means not applicable, with the reason stated. Eighty-eight are applicable in whole or part — 70 in full and 18 with a named gap — and five are excluded — all five for the same reason, at 8.34.

RefControlDecisionHow it is met, or where it is written
A.5.1Policies for information securityPartialTop-level policy outstanding; nine subordinate policies in issue. See 9.2 for the list and dates.
A.5.2Information security roles and responsibilitiesApplicableCISO with the COO; roles defined in PRM-ORG-2026-001 and per-document ownership.
A.5.3Segregation of dutiesApplicableApproval authority separated from execution throughout — release in PRM-OPS-2026-001, access approval in PRM-SEC-2026-001.
A.5.4Management responsibilitiesApplicableBoard and delegation framework in the Corporate Governance Charter.
A.5.5Contact with authoritiesApplicableLaw-enforcement access policy, PRM-SEC-2026-001 §11; regulator contacts held by Compliance.
A.5.6Contact with special interest groupsApplicableMembership of Uptime Institute community and vendor security advisories; threat feeds via CISO.
A.5.7Threat intelligencePartialVendor and CERT advisories consumed today; formal intake and triage process to follow the OT architecture at 9.2.
A.5.8Information security in project managementApplicableCommissioning gates carry security acceptance criteria — PRM-CDP-2026-001 L2 to L5.
A.5.9Inventory of information and associated assetsApplicableAsset classes at section 04; physical asset register under PRM-SOP-OPS-012.
A.5.10Acceptable use of information and assetsPartialTerms in employment contracts; standalone acceptable-use policy at 9.2.
A.5.11Return of assetsApplicableLeaver process in PRM-HR-2026-001, with access removal verified at recertification.
A.5.12Classification of informationApplicableFour classes — Public, Internal, Confidential, Restricted — applied at section 04 and on every document in issue.
A.5.13Labelling of informationApplicableEvery controlled document carries its classification in the footer. Physical media labelled at receipt.
A.5.14Information transferPartialNDA regime and controlled repository in force; encrypted-transfer standard for Restricted material at 9.2.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled12 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 13 / 24
07Annex A applicability, continuedA.5.15 – A.5.27
RefControlDecisionHow it is met, or where it is written
A.5.15Access controlApplicableFive-layer model with independent factors per layer, PRM-SEC-2026-001. Logical access least-privilege by role.
A.5.16Identity managementApplicableSingle identity per person, no shared accounts, joiner-mover-leaver tied to HR record.
A.5.17Authentication informationApplicableMulti-factor at every controlled layer and for all privileged access; secrets held in a managed vault.
A.5.18Access rightsApplicableProvisioned on approval, reviewed at recertification, revoked on change or departure. Recertification cycle in PRM-SEC-2026-001 §07.
A.5.19Information security in supplier relationshipsApplicableSecurity terms in supply and maintenance agreements; vendor access governed per engagement.
A.5.20Addressing information security within supplier agreementsPartialTerms present in current agreements; a standard security schedule for all future contracts at 9.2.
A.5.21Managing information security in the ICT supply chainApplicableAuthorised channels only, firmware verified against vendor hashes, provenance recorded at receipt. Risk R12.
A.5.22Monitoring, review and change management of supplier servicesApplicableContracted response times tested annually — PRM-SPR-2026-001 §10.5. Service reviews per agreement.
A.5.23Information security for use of cloud servicesPartialCorporate SaaS in use; a cloud-use standard covering approval and data placement at 9.2.
A.5.24Incident management planning and preparationApplicablePRM-IRP-2026-001 — P1 to P4 matrix, escalation to COO, roles and preparation.
A.5.25Assessment and decision on information security eventsApplicableTriage and severity assignment in PRM-IRP-2026-001; event reporting duty on all staff.
A.5.26Response to information security incidentsApplicableResponse procedures in PRM-IRP-2026-001; cyber-specific EOPs in PRM-OPS-2026-001.
A.5.27Learning from information security incidentsApplicableRoot-cause process with mandatory procedure revision. Case history accrues from service — see the DD note on line 27.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled13 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 14 / 24
07Annex A applicability, continuedA.5.28 – A.5.37
RefControlDecisionHow it is met, or where it is written
A.5.28Collection of evidenceApplicableEvidence handling in PRM-IRP-2026-001; video export for lawful request under PRM-SOP-SEC-006 with chain of custody.
A.5.29Information security during disruptionApplicableEOP set covering power, cooling, life safety and cyber; OT isolation procedure for a cyber event.
A.5.30ICT readiness for business continuityPartialFacility continuity established by topology and the EOP set. Formal business impact analysis under ISO 22301 at section 11.
A.5.31Legal, statutory, regulatory and contractual requirementsPartialExport control and law-enforcement obligations documented. Consolidated legal register and the PDPL policy at 9.2. Risk R10.
A.5.32Intellectual property rightsApplicableLicensing of platform and vendor software tracked at procurement; partner IP handled under joint venture terms.
A.5.33Protection of recordsApplicableRetention per class — PRM-SPR-2026-001, PRM-CDP-2026-001 §09, PRM-SOP-REC-003. Commissioning pack held for asset life.
A.5.34Privacy and protection of PIIPartialPersonnel data classified Restricted with defined handling. Oman PDPL policy outstanding — the largest single gap, at 9.2.
A.5.35Independent review of information securityPartialExternal certification audit is the intended mechanism. Internal audit programme cannot have evidence until the ISMS has run a cycle — see 9.3.
A.5.36Compliance with policies, rules and standardsApplicableQuarterly audit of the procedure library and the spares register; access recertification; drill grading.
A.5.37Documented operating proceduresApplicablePRM-OPS-2026-001 — 72 procedures indexed with numbering, version states and approval authority.
7.1 Where the organisational controls stand

Of the 37 organisational controls, 27 are applicable and in force, ten are partial. Every partial traces to one of two causes, and neither requires a third party: a policy that has not been written yet, or a record that cannot exist until the management system has been operating. Both are itemised at section 09.

What an auditor tests hereNot whether a control is claimed, but whether it is evidenced. A control marked applicable and pointing at a document in issue can be tested immediately. That is why each row names the document rather than describing the intent — forty-four of the 93 controls are already backed by a document a reviewer can open today.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled14 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 15 / 24
07Annex A applicability — people controlsA.6.1 – A.6.8

Eight controls, all applicable. This group is the best-covered in the whole Statement of Applicability, because PRM-HR-2026-001 was written against a facility where the people with unsupervised access are the primary risk — which is exactly what these controls address.

RefControlDecisionHow it is met, or where it is written
A.6.1ScreeningApplicableThree-tier vetting by criticality — PRM-HR-2026-001. Tier assigned by the same tests that define a critical role, so screening depth follows access rather than job title.
A.6.2Terms and conditions of employmentApplicableSecurity obligations, confidentiality and acceptable use written into every contract before the effective date.
A.6.3Awareness, education and trainingApplicableCertification matrix per critical role with periodicity — PRM-HR-2026-001. Commissioning attendance counts toward competence.
A.6.4Disciplinary processApplicableDefined process for security breaches by staff, proportionate and recorded. Held by HR with the CISO.
A.6.5Responsibilities after termination or change of employmentApplicableAccess removal and asset return at departure, verified at the next recertification rather than assumed at the exit interview.
A.6.6Confidentiality or non-disclosure agreementsApplicableNDAs for staff, contractors, visitors and partners. Signed before access is provisioned, not after.
A.6.7Remote workingApplicableRemote access to corporate systems with MFA. No remote administrative access to the OT layer except through the recorded jump host — the strongest single statement in this group.
A.6.8Information security event reportingApplicableDuty on every person on site, with a no-blame route. Reporting obligation stated in PRM-IRP-2026-001 and in induction.
7.2 Why this group matters more than its size suggests

Three of the twelve risks in section 06 — insider abuse of privilege, unauthorised physical access, and vendor access left open — are reduced principally by these eight controls rather than by any technical measure. A facility can be perfectly segmented and still lose customer confidence to one improperly vetted contractor with a hall pass.

Evidence available todayAll eight controls point at a document already in issue. This is the one group in the Statement of Applicability where a stage 1 audit could proceed without any further writing — the gap is operational records, which begin accruing as the resident team is recruited from Q3 2026.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled15 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 16 / 24
08Annex A applicability — physical and technologicalA.7.1 – A.7.14

The fourteen physical controls are the group a data-centre operator is judged on hardest, and the group where Prima has the most written. None is excluded — twelve are applicable in full and two carry a named gap. Eight rest directly on PRM-SEC-2026-001.

RefControlDecisionHow it is met, or where it is written
A.7.1Physical security perimetersApplicableLayer 1 perimeter with detection and assessment before the line is reached — PRM-SEC-2026-001 §05.
A.7.2Physical entryApplicableLayer 2 portals with independent factors, anti-passback and interlock — PRM-SEC-2026-001 §06. Visitor registration and escort under PRM-SOP-SEC-002.
A.7.3Securing offices, rooms and facilitiesApplicableZoning by layer: interior, hall, cage and rack each with its own entitlement — PRM-SEC-2026-001 §05. Spares store at Layer 3.
A.7.4Physical security monitoringApplicableCamera coverage of every controlled transition with 90-day minimum retention, 24×7 officer and NOC coverage — PRM-SEC-2026-001 §08.
A.7.5Protecting against physical and environmental threatsPartialFire, water and environmental detection designed and specified. Natural hazard assessment — flood, seismic, wind — outstanding, requires an external consultant. DD line 06.
A.7.6Working in secure areasApplicableEscort rules, permitted-activity list, prohibition on unrecorded photography, and a two-person rule on restricted actions — PRM-SEC-2026-001 §09.
A.7.7Clear desk and clear screenPartialApplied in practice; standalone policy statement at 9.2.
A.7.8Equipment siting and protectionApplicableRack siting, floor loading and A/B feed architecture in the design basis; no equipment sited where a leak path passes over it.
A.7.9Security of assets off-premisesApplicableEquipment leaving site is authorised, logged and sanitised first where it held data — PRM-SEC-2026-001 §10.
A.7.10Storage mediaApplicableMedia register, controlled handling by classification, and witnessed destruction — PRM-SEC-2026-001 §10. Media never leaves a hall unlogged.
A.7.11Supporting utilitiesApplicableUtility intake, generation, UPS and cooling designed to Tier III Standard with N+1; spares and drills behind them.
A.7.12Cabling securityApplicableSegregated power and data routing, labelled and access-controlled containment, dual entry paths for carriers.
A.7.13Equipment maintenanceApplicablePreventive regime with MOPs per system, approved before work on live plant — PRM-OPS-2026-001.
A.7.14Secure disposal or re-use of equipmentApplicableClear, Purge or Destroy per media type against NIST SP 800-88, witnessed, with a certificate per item — PRM-SEC-2026-001 §10.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled16 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 17 / 24
08Annex A applicability, continuedA.8.1 – A.8.12
RefControlDecisionHow it is met, or where it is written
A.8.1User endpoint devicesApplicableManaged endpoints for staff with disk encryption and remote wipe. Unmanaged devices have no path to the OT layer.
A.8.2Privileged access rightsApplicableLeast privilege, named accounts, session logging on all privileged action, and two-person authorisation on restricted operations. Risk R03.
A.8.3Information access restrictionApplicableNeed-to-know on commercial and security material; classification determines the system it may be held in.
A.8.4Access to source codePartialPrima writes no software product. Infrastructure-as-code and platform configuration repositories are access-restricted with change control — the control applies to those, not to product code.
A.8.5Secure authenticationApplicableMulti-factor throughout — physical layers, corporate systems, platform administration and the vendor gateway.
A.8.6Capacity managementApplicablePower, thermal and fabric capacity tracked against contracted commitments — PRM-CAP-2026-001 reconciles utility, installed and contracted MW.
A.8.7Protection against malwareApplicableEndpoint protection on corporate estate; OT layer protected by segregation and allow-listing rather than signature scanning, which is the correct approach on control systems.
A.8.8Management of technical vulnerabilitiesPartialVendor advisories consumed and patching under change control. Penetration testing outstanding — corporate scope testable now, OT scope only after commissioning. DD line 37.
A.8.9Configuration managementApplicableBaseline configurations held for platform and OT systems; drift detected and corrected under change control.
A.8.10Information deletionApplicableDeletion and sanitisation per class, with purge before any hardware reassignment between customers. Risk R05.
A.8.11Data maskingPartialLimited application — Prima holds no customer datasets. Applies to personnel data in test and reporting contexts; standard to be set with the PDPL policy at 9.2.
A.8.12Data leakage preventionPartialClassification, need-to-know and controlled repositories in force. Technical egress controls on the corporate estate to follow the OT architecture at 9.2.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled17 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 18 / 24
08Annex A applicability, continuedA.8.13 – A.8.24
RefControlDecisionHow it is met, or where it is written
A.8.13Information backupApplicableCorporate and platform configuration backed up with tested restore. Note that customer workload backup is the customer’s — the demarcation is explicit in PRM-DEM-2026-001.
A.8.14Redundancy of information processing facilitiesApplicableTier III Standard topology, N+1 across power and cooling, dual fabric paths, diverse carrier entry. Risk R07.
A.8.15LoggingApplicableAccess, privileged action, change and OT event logging with defined retention. Video at 90 days minimum.
A.8.16Monitoring activitiesApplicable24×7 NOC monitoring of platform, fabric and environment; alarm routing and escalation in PRM-IRP-2026-001.
A.8.17Clock synchronisationApplicableCommon time source across platform, OT and security systems. Without it, correlating an access record against a system event is guesswork.
A.8.18Use of privileged utility programsApplicableRestricted, logged, and permitted only from the recorded jump host on the OT side.
A.8.19Installation of software on operational systemsApplicableUnder change control only, from approved sources, with firmware verified against vendor hashes. Risk R12.
A.8.20Networks securityApplicableSegmented architecture with no direct path from corporate or internet to the OT layer. Risk R02.
A.8.21Security of network servicesApplicableCarrier services taken at defined handover points with contracted terms; internal fabric under change control.
A.8.22Segregation of networksApplicableCorporate, platform management, tenant fabric and OT each separated. Tenant isolation is the control customers test hardest — Risk R05.
A.8.23Web filteringApplicableApplied on the corporate estate. The OT layer has no general internet path at all, which is a stronger control than filtering one.
A.8.24Use of cryptographyPartialEncryption in transit for administrative access and transfers; at rest on endpoints and backups. Consolidated cryptographic standard, including key management, at 9.2.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled18 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 19 / 24
08Annex A applicability, continuedA.8.25 – A.8.34
RefControlDecisionHow it is met, or where it is written
A.8.25Secure development life cycleExcludedPrima does not develop software. No product, service or application is written for internal use or for customers. Reason applies to this control and the four marked Excluded below.
A.8.26Application security requirementsExcludedNo applications are specified or built. Requirements for procured platform software are handled as procurement criteria under A.5.19 and A.5.21.
A.8.27Secure system architecture and engineering principlesApplicableApplicable and not excluded — this governs how the platform and OT estate are engineered and segmented, which Prima does do. Distinguished deliberately from the development controls around it.
A.8.28Secure codingExcludedNo code is written. Infrastructure-as-code and configuration are covered by change control at A.8.32 and configuration management at A.8.9.
A.8.29Security testing in development and acceptanceExcludedNo development pipeline exists. Acceptance testing of procured systems runs through the commissioning gates in PRM-CDP-2026-001, which carry security criteria at L2 to L5.
A.8.30Outsourced developmentExcludedNo development is outsourced. Where a supplier configures a system for Prima, it is governed as a supplier relationship under A.5.19 and A.5.20.
A.8.31Separation of development, test and production environmentsApplicableA staging environment exists for platform and OT configuration changes; production changes are validated there first under change control.
A.8.32Change managementApplicableChange control across facility, platform and OT — raising, assessment, approval and scheduling under PRM-SOP-OPS-011 and the MOP regime.
A.8.33Test informationPartialApplies to staging data for platform configuration. No customer data exists to be used in test, which removes the usual risk in this control; standard to be stated with the PDPL policy.
A.8.34Protection of information systems during audit testingApplicableAudit and penetration testing scoped, authorised in writing, and time-boxed. Testing on live plant runs only in agreed windows, as with any intervention.
8.1 The five exclusions, and why they are defensible

All five excluded controls — A.8.25, A.8.26, A.8.28, A.8.29 and A.8.30 — are excluded for one reason: Prima is an infrastructure operator, not a software developer. It writes no product code, ships no application, and runs no development pipeline.

The exclusion is stated narrowly on purpose. A.8.27 sits in the middle of the same group and is applicable, because secure architecture and engineering principles govern how the platform and the OT estate are designed — which Prima very much does. An auditor should read the boundary as drawn between building software and engineering infrastructure, not between technology and everything else.

Statement of Applicability summary93 controls: 70 applicable, 18 partial, 5 excluded. Every exclusion carries a reason. Every partial names either a document at 9.2 or a record that requires the ISMS to have been running — no partial is left unexplained, and none depends on a third party except A.7.5 and A.8.8, which need an external consultant and a testing firm respectively.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled19 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 20 / 24
09Gap position and what is already written

A readiness document that does not state its own gaps is worthless to the party reading it. This section lists what exists, what is missing, and what cannot exist yet — in that order.

9.1 Already in issue — forty-four controls backed by a document

Forty-four distinct Annex A controls are evidenced by a document already written and in issue — counted as the distinct controls named in the third column below. A.8.29 is cited for context only and is not counted, being one of the five exclusions.

DocumentReferenceControls it evidences
Physical Security SpecificationPRM-SEC-2026-001A.5.15, 5.18, 5.28 · A.7.1–7.4, 7.6, 7.9, 7.10, 7.14 · A.8.10
Incident Response PlanPRM-IRP-2026-001A.5.24, 5.25, 5.26, 5.27, 5.28 · A.6.8 · A.8.16
Operating Procedure LibraryPRM-OPS-2026-001A.5.3, 5.29, 5.36, 5.37 · A.7.13 · A.8.19, 8.32
Training, Certification & VettingPRM-HR-2026-001A.6.1–6.6 · A.5.11
Commissioning & Drill ProgrammePRM-CDP-2026-001A.5.8 · A.8.29 context · A.8.34
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001A.5.22 · A.7.11 · A.8.14
Export Compliance PolicyPC-ECP-001A.5.31 in part · A.5.19 in part · risk R06
Demarcation MatrixPRM-DEM-2026-001A.5.20 boundary · A.8.13 boundary
Capacity Reconciliation StatementPRM-CAP-2026-001A.8.6
Corporate Governance CharterA.5.2, 5.4
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled20 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 21 / 24
09Gap position, continuedOutstanding
9.2 Outstanding — policies to be written, no third party required
DocumentOwnerTarget
Information Security Policy — the top-level statementA.5.1. Required by clause 5.2; a certification body will ask for it firstCISOAug 2026
Data Protection & Privacy Policy — Oman PDPLA.5.34, A.8.11, A.8.33 · largest single gap · risk R10CISO with LegalAug 2026
OT Security ArchitectureA.8.12, A.8.20 detail · risk R02 · DD lines 35–36CTOSep 2026
Acceptable Use, and Clear Desk & Clear ScreenA.5.10, A.7.7CISOAug 2026
Cryptographic and Key Management StandardA.8.24 · A.5.14 transferCTO with CISOSep 2026
Supplier Security Schedule — standard contract annexA.5.20, A.5.23Legal with CISOSep 2026
Consolidated Legal & Regulatory RegisterA.5.31 · risk R10ComplianceSep 2026
Threat Intelligence intake and triage processA.5.7CISOOct 2026
Internal Audit Programme and Management Review calendarA.5.35 · clauses 9.2 and 9.3CISOOct 2026
The distinction that mattersEverything at 9.2 is writing — nine documents, three owners, all inside the organisation, none waiting on a vendor, a certificate or a building. That is what makes the Q1 2027 target credible rather than aspirational.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled21 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 22 / 24
10Certification path and sequencing
10.1 What cannot exist yet, and why

Three requirements are not gaps in preparation — they are consequences of the management system being new. Stating them prevents a reviewer treating them as oversights.

  • Internal audit evidence. Clause 9.2 requires the ISMS to have been audited internally. There is nothing to audit until it has operated. First internal audit is programmed for Nov 2026, once the policy set is in force.
  • Management review records. Clause 9.3 requires evidence that management has reviewed the system's performance. First review Dec 2026, with the second before the stage 2 audit.
  • Operational records against the controls. Access recertification cycles, drill grades, incident records, training completions. These begin accruing from Q3 2026 as the resident team is recruited, and reach a reviewable body by Q4.
10.2 Sequence to the first certificate
WindowWhat happensDependency
Aug 2026Appoint an accredited certification body. This document is the input — it lets a body quote against a defined scope rather than an inquiry. Top-level policy, PDPL policy and acceptable use issued.Body selection; three documents
Sep 2026Remaining policy set issued. Optional gap assessment by the appointed body — worth taking, because a finding raised here is cheap and the same finding at stage 2 is not.Six documents at 9.2
Oct 2026ISMS operating. Internal audit programme and management review calendar in force. Corporate-scope penetration test — testable now, OT scope deferred.Testing firm appointment
Nov 2026Stage 1 audit — documentation and readiness review. The body checks that the ISMS is designed and documented, not yet that it works. First internal audit completed.Policy set complete
Dec 2026First management review. Any stage 1 findings closed. Facility reaches service at gate L5, and operational records begin accruing against the physical controls.Commissioning L5
Q1 2027Stage 2 audit — the body tests whether the system is operating as documented, by sampling records. Certificate on closure of findings.One operating cycle of records
10.3 The one thing that would delay this

Not the documents, and not the facility. The appointment of the certification body. Accredited bodies in the region schedule stage 1 and stage 2 audits months ahead, and a slip in appointment moves the certificate by a full quarter regardless of how ready the ISMS is.

Recommended actionApproach two or three accredited bodies in August, with this document attached. A body that receives a defined scope, an asset basis, a risk register and a completed Statement of Applicability can quote and schedule immediately — which is the entire purpose of writing it before the auditor arrives rather than after.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled22 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 23 / 24
1122301 and 45001, governance and measures

The diligence line asks for three certificates. They do not sequence equally, and treating them as one workstream would delay all three.

11.1 ISO 22301 — business continuity
What is already doneThe operational half of continuity is largely in place: Tier III Standard topology with N+1, the 17-procedure emergency set, the drill calendar, critical spares, and the incident response and escalation regime. These are the substance of continuity for a data centre.
What is missingThe management-system half. Specifically a formal business impact analysis — critical activities identified, maximum tolerable period of disruption stated per activity, recovery time and recovery point objectives set — and a continuity plan covering the business, not only the plant.
The distinction that mattersPrima has continuity of the facility. It does not yet have documented continuity of the company — what happens if the corporate office is unavailable, if key personnel are lost, if a supplier fails. That is what 22301 certifies.
SequenceBusiness impact analysis and continuity plan Q4 2026. Certification audit Q2 2027, after 27001 — deliberately second, because 22301 shares clauses 4 to 10 with 27001 and reuses the same management system. Running them together would double the audit burden for no benefit.
11.2 ISO 45001 — occupational health and safety
Why it is urgent, not deferred45001 is most relevant during construction. A site with contractors, lifting operations, live electrical work and confined spaces is precisely where this standard earns its place. Certifying after handover, when the hazardous phase is over, inverts its purpose.
What existsContractor induction and supervision, permit-to-work discipline through the MOP regime, life-safety emergency procedures, and the evacuation and roll-call drill in the programme.
What is missingA hazard identification and risk assessment covering construction and operational activities, an OH&S policy, worker consultation arrangements, and incident and near-miss reporting for safety as distinct from security.
SequenceOH&S management system Q4 2026, certification audit Q2 2027 alongside 22301. Both reuse the 27001 management system, which is why 27001 goes first.
11.3 Governance of the ISMS
OwnerCISO. Owns the scope, the risk register, the Statement of Applicability and the policy set. Accepts medium-band risks; escalates high band to the CEO.
Management representativeCOO. Accountable to the board for the effectiveness of the system, chairs the management review.
Board oversightAny risk in the unacceptable band is reported to the board until reduced. Certification status reported quarterly.
Review of this documentAnnually, and on any change to scope, plant, customer base or threat picture. Reviewed after any incident, whether or not it was in the register. Recorded even where nothing changes.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled23 / 24
DRAFT
PRIMA
ISMS Scope & ISO ReadinessPRM-ISM-2026-001 · 24 / 24
1122301 and 45001, governance and measures, continuedMeasures
11.4 Measures

Clause 9.1 requires the effectiveness of the ISMS to be monitored and measured. Reported to the COO on the cadence shown, and to the board quarterly.

MeasureTargetReported
Applicable controls with evidence available on request100%Quarterly
Risks reviewed within their review date100%Quarterly
Risks in the unacceptable band, after treatment0Monthly
Accepted risks past their acceptance expiry0Quarterly
Access recertification completed on cycle100%Quarterly
Security events reported and triaged within SLA≥ 95%Monthly
Internal audit findings closed within 60 days≥ 90%Quarterly
Staff with security training current100%Quarterly
Policies within their review date100%Annually
Certification and surveillance audits passedAllPer audit
11.5 Summary position

Stated in four lines so that a reviewer, a lender or a certification body can take the position without reading the document.

  • Scope, assets, risk method, register and Statement of Applicability exist — the four inputs a certification body asks for at first contact. 93 controls decided: 70 applicable, 18 partial, 5 excluded with reason.
  • Forty-four controls are already backed by a document in issue, listed at 9.1 and openable today. The people-controls group is complete, and the physical group carries only two partials.
  • Nine policies remain to be written, all internal, three owners, targeted Aug to Oct 2026. Nothing at 9.2 waits on a vendor, a certificate or a building.
  • No certificate is held. First target is ISO/IEC 27001 in Q1 2027, then 22301 and 45001 in Q2 2027 reusing the same management system. The binding dependency is appointing an accredited body in August — not the documents, and not the facility.
RelatedPRM-SEC-2026-001 · PRM-IRP-2026-001 · PRM-OPS-2026-001 · PRM-HR-2026-001 · PRM-CDP-2026-001 · PRM-SPR-2026-001 · PRM-DEM-2026-001 · PRM-CAP-2026-001 · PC-ECP-001.
Office of the CISO

For the scope statement in its current wording, the risk register, the Statement of Applicability, or the readiness position ahead of appointing a certification body.

info@primasecurity.ai
primacompute.com
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled24 / 24