Security & ISO/IEC 27001 Readiness

PUBLIC STATEMENT:

This document describes the UMW Security Program, its control domains, and the evidentiary standard required to communicate its maturity. It does not constitute a certificate and does not authorize the use of an ISO/IEC 27001 seal. The information, systems, catalogs, and records protected by the Program are referred to as the “Assets.” The set of policies, responsible persons, and controls is referred to as the “Security Program.”

PUBLIC STATUS: UMW does not claim to hold a current ISO/IEC 27001 certification.

The following domains describe the scope that must be supported by responsible persons, evidence, and testing.

FIRST.— DOMAIN SEC-01 · CLEAR STATEMENT.

UMW RECORDINGS, INC. S.A.S. is organizing its information security management system with reference to ISO/IEC 27001:2022.

Until UMW receives a current, independently issued, and verifiable certificate, it must not use:

  • ISO certified;
  • certification in progress, unless a contract and schedule exist;
  • the ISO logo;
  • the seal of a certification body;
  • a certificate number;
  • a certified scope.

ISO publishes standards. It does not directly certify companies.

SECOND.— DOMAIN SEC-02 · ASSETS THE PROGRAM MUST COVER.

The intended scope must identify, at a minimum:

  • the umwrecordingsinc.com website;
  • UMW Core;
  • authentication and Accounts;
  • uploading of audio, cover artwork, and Metadata;
  • UMW Scan;
  • DSP delivery and statuses;
  • report imports;
  • wallet and payment requests;
  • UMW Song Assets;
  • white-label Services;
  • sandbox and production API environments;
  • webhooks;
  • support;
  • DMCA and anti-fraud records;
  • backups;
  • providers;
  • equipment and persons with access.

Any future certification will cover only the Assets expressly included within its defined scope.

THIRD.— DOMAIN SEC-03 · INFORMATION PROTECTED BY UMW.

The Security Program covers:

  • credentials;
  • identification documents;
  • agreements;
  • unreleased master recordings;
  • cover artwork;
  • Metadata;
  • catalogs;
  • DSP reports;
  • balances;
  • payment Accounts;
  • splits;
  • compositions;
  • support tickets;
  • fraud alerts;
  • API keys;
  • logs.

Not all information requires the same level of protection.

An unreleased master recording, identification document, or production credential requires stricter controls than a title that is already public.

FOURTH.— DOMAIN SEC-04 · GOVERNANCE.

Before claiming alignment, UMW must maintain:

  • an executive owner;
  • an operational security owner;
  • DPO participation;
  • an Asset inventory;
  • a risk matrix;
  • approved policies;
  • control owners;
  • a schedule;
  • evidence;
  • an internal audit;
  • Management review.

The DPO independently supervises privacy compliance and must not be the sole person responsible for implementing security controls.

The DPO role performed by Verónica Gabriela Salazar Castro remains separate from the roles of:

  • security officer;
  • compliance officer;
  • control implementer.

Security, Engineering, Operations, Finance, and Legal are responsible for implementing the controls applicable to their respective areas.

The DPO:

  • provides advice;
  • verifies compliance;
  • escalates observations;
  • has direct access to the appropriate decision-making level.

FIFTH.— DOMAIN SEC-05 · UMW-SPECIFIC RISKS.

The risk matrix must include, at a minimum:

  • theft of an artist or label Account;
  • fraudulent change of a payment beneficiary;
  • unauthorized access to unreleased master recordings;
  • unauthorized delivery;
  • alteration of UPCs, ISRCs, or Metadata;
  • exposure of a report or balance;
  • disclosure of an API credential;
  • forged webhooks;
  • abuse by a white-label Administrator;
  • loss of backups;
  • compromise of a provider;
  • malware on a server;
  • dependence on a single delivery route;
  • exposure of an identification document;
  • misuse of UMW Scan;
  • unavailability during deliveries or payments;
  • human error.

SIXTH.— DOMAIN SEC-06 · ACCESS TO UMW CORE.

The control design must address:

  • unique identity;
  • roles;
  • least privilege;
  • multi-factor authentication where available;
  • session management;
  • secure Account recovery;
  • User offboarding;
  • periodic review of Administrators;
  • logs of sensitive actions;
  • protection of beneficiary changes.

A white-label Client must not be able to view another Client’s personal data or information.

SEVENTH.— DOMAIN SEC-07 · API AND WEBHOOKS.

The API requires:

  • separation of sandbox and production;
  • credentials assigned to each partner;
  • scopes;
  • credential rotation;
  • rate limits;
  • payload validation;
  • webhook signatures;
  • replay protection;
  • logs;
  • alerts;
  • revocation;
  • private production documentation.

Public examples must not contain:

  • secrets;
  • usable administrative endpoints.

EIGHTH.— DOMAIN SEC-08 · CATALOG AND FILES.

UMW must control:

  • accepted formats;
  • file analysis;
  • integrity;
  • storage;
  • encryption in transit;
  • reviewer access;
  • downloads;
  • temporary copies;
  • deletion;
  • backups;
  • transmission to providers.

Marketing personnel do not ordinarily require access to complete KYC documents or reports.

NINTH.— DOMAIN SEC-09 · ROYALTIES AND PAYMENTS.

Controls must distinguish between:

  • imported reports;
  • transformations;
  • Commissions;
  • adjustments;
  • reserves;
  • balances;
  • requests;
  • approvals;
  • beneficiaries;
  • payment transmission;
  • receipts.

Changes to payment methods and high-risk payments require enhanced verification and traceability.

Checkout must preserve:

  • the Order and displayed total;
  • identification of the processor;
  • contractual acceptance as a separate event;
  • authorization result;
  • transaction reference;
  • invoice or receipt;
  • refund information;
  • status changes;
  • Client access to payment history.

UMW will not store CVVs.

UMW will not publicly state that it never receives payment card information until it has technically verified the applicable payment-gateway integration.

Any public statement must correspond to the actual flow, including:

  • logs;
  • support systems;
  • anti-fraud tools.

TENTH.— DOMAIN SEC-10 · DEVELOPMENT AND CHANGES.

For changes to UMW Core, white-label Services, and the API, UMW must retain:

  • a ticket;
  • review;
  • testing;
  • dependency information;
  • secrets review;
  • deployment information;
  • rollback procedure;
  • responsible person;
  • date.

An urgent update must be documented and reviewed afterward.

ELEVENTH.— DOMAIN SEC-11 · VULNERABILITIES.

The Security Program must include:

  • an inventory of dependencies;
  • security advisories;
  • prioritization;
  • patching;
  • testing;
  • scanning;
  • responsible disclosure;
  • temporary exceptions;
  • closure verification.

UMW will not claim to be one hundred percent (100%) secure or free of vulnerabilities.

TWELFTH.— DOMAIN SEC-12 · PROVIDERS.

Before granting access to a provider, UMW must identify:

  • the contracting legal entity;
  • the Service;
  • country;
  • personal data or information involved;
  • access level;
  • Subproviders;
  • incident procedures;
  • continuity arrangements;
  • deletion procedures;
  • the applicable agreement;
  • the DPA;
  • exit procedures.

The public Provider Registry does not replace the provider assessment.

THIRTEENTH.— DOMAIN SEC-13 · BACKUPS AND RECOVERY.

For each system, UMW must define:

  • what is backed up;
  • frequency;
  • encryption;
  • location;
  • retention;
  • responsible person;
  • restoration testing;
  • Recovery Point Objective (RPO);
  • Recovery Time Objective (RTO);
  • external dependencies.

UMW must not publish an RPO or RTO as a guarantee without supporting evidence and an SLA.

FOURTEENTH.— DOMAIN SEC-14 · INCIDENTS.

The incident-response procedure must cover:

  1. reporting;
  2. classification;
  3. containment;
  4. preservation;
  5. analysis;
  6. communication;
  7. recovery;
  8. legally required notification;
  9. root-cause analysis;
  10. improvement.

A communication channel must exist for:

  • compromised Accounts;
  • personal data exposure;
  • payment fraud;
  • catalog issues.

FIFTEENTH.— DOMAIN SEC-15 · DISTRIBUTION CONTINUITY.

Distribution continuity includes:

  • catalog export;
  • UPCs and ISRCs;
  • status for each DSP;
  • provider and delivery route;
  • takedowns;
  • pending reports;
  • payments;
  • Client communications;
  • migration.

UMW must not promise permanent availability when continuity depends on an external route.

SIXTEENTH.— DOMAIN SEC-16 · PRIVACY.

Security must be coordinated with:

  • the inventory of processing activities;
  • data minimization;
  • retention;
  • Data-Subject rights;
  • the DPO;
  • incidents;
  • international transfers;
  • white-label Services;
  • high-risk assessments.

ISO certification does not replace compliance with the LOPDP.

The Security Program must also cover:

  • effective blocking of non-essential cookies before a choice is made;
  • rejection and withdrawal controls equivalent to the acceptance control;
  • acceptance history recording the applicable version and action;
  • secure personal data downloads and portability;
  • the complaint channel to the DPO;
  • separation between evidentiary records and profiling;
  • periodic testing of the six modules of the Privacy Center.

When UMW uses artificial intelligence to process personal data, the Security Program must include:

  • an inventory of the system and provider;
  • the Record of Processing Activities;
  • information provided to Data Subjects;
  • risk management;
  • a prior impact assessment when applicable;
  • continuous security;
  • human supervision;
  • proportionate auditing;
  • records of relevant automated decisions.

UMW must also assess and document whether a processing activity qualifies as large-scale processing under current regulations.

When applicable, UMW will:

  • update the Record of Processing Activities;
  • activate enhanced measures.

SEVENTEENTH.— DOMAIN SEC-17 · PERSONNEL.

UMW must document:

  • confidentiality;
  • training;
  • roles;
  • access;
  • onboarding;
  • changes;
  • offboarding;
  • conflicts;
  • internal sanctions.

Access must be revoked and verified when the relationship ends.

EIGHTEENTH.— DOMAIN SEC-18 · MINIMUM EVIDENCE BEFORE CLAIMING ALIGNMENT.

AreaRequired EvidenceScopeApproved document identifying systems and locationsRisksCurrent risk matrix and processing activitiesAccessExport of roles and completed access reviewProvidersProvider Case Files and DPAsChangesTickets and approvalsVulnerabilitiesRegister and internal SLABackupsRestoration test resultsIncidentsExercises and Case FilesContinuityRecovery or migration testPrivacyRecords, DPIA when applicable, and DPOAI and large-scale processingRecord of Processing Activities, impact assessment, Large-Scale Technical Model calculation, auditing, and supervisionAuditInternal audit report and corrective actionsManagementManagement-review minutes

Without this evidence, UMW must describe the Security Program as being under development rather than claim that alignment has been achieved.

NINETEENTH.— DOMAIN SEC-19 · PATH TO CERTIFICATION.

A responsible path consists of:

  1. defining the scope;
  2. completing the inventory;
  3. assessing risks;
  4. approving controls;
  5. operating the controls and generating evidence;
  6. conducting an internal audit;
  7. correcting nonconformities;
  8. completing Management review;
  9. selecting an accredited certification body;
  10. completing external audits.

There is no public certification date until UMW approves one and can substantiate it.

TWENTIETH.— DOMAIN SEC-20 · INFORMATION TO BE PUBLISHED IF CERTIFICATION IS OBTAINED.

When certification is obtained, UMW will publish:

  • the standard and edition;
  • the certified legal name;
  • the certified scope;
  • applicable locations;
  • the certification body;
  • certificate number;
  • issuance date;
  • expiration date;
  • status;
  • a verifiable link.

UMW will not extend the certificate to products or Services outside its certified scope.