# Objective Plan

The following table describes the plan for 2026 to achieve FundApps' objectives.

<table data-full-width="true"><thead><tr><th width="142.99993896484375">Objective</th><th width="180">What will be done</th><th width="120">Responsible</th><th width="138.666748046875">Resources required</th><th width="502.666748046875">Evaluation</th><th>Est. completion date</th></tr></thead><tbody><tr><td>1) Consolidate to a unified control set and audit cycle for the merged entity.</td><td>Align governance, policies, and assurance activities across the merged group, and reduce duplication in ways of working.</td><td>Security team</td><td>Security team time</td><td><ul><li>Gap assessment completed by 30 Jun 2026, and leadership-approved roadmap in place.</li><li>End-of-year evidence of consolidated governance and a defined joint audit plan for 2027.</li><li>Residual risk statement for client data leakage harmonised across FundApps and Surveillance, with one documented risk acceptance process.</li></ul></td><td>End of December 2026</td></tr><tr><td>2) Ensure the protection of sensitive data managed by FundApps’ information systems</td><td>Run structured risk reviews across in-scope teams and ensure prioritised mitigations are planned and delivered.</td><td>Security team</td><td>Security team time</td><td><ul><li>Threat modelling completed for all in-scope teams by 1 Oct 2026.</li><li>Risk registers maintained with owners and target dates.</li><li>Target of at least 80% of agreed mitigations implemented by 31 Dec 2026, excluding formally accepted risks.</li></ul></td><td>End of December 2026</td></tr><tr><td>3) Protect information systems against external security threats and vulnerabilities.</td><td>Maintain layered assurance through a combination of continuous external testing and periodic structured assessments, supported by clear remediation ownership and timelines.</td><td>Security team</td><td>Security team time, Engineering time</td><td><ul><li>Continuous bug bounty operational by 30 Apr 2026.</li><li>Annual penetration test completed in 2026.</li></ul></td><td>End of December 2026</td></tr><tr><td>4) Maintain compliance with security standards</td><td>Complete scheduled assurance activities against recognised security and responsible AI management standards, and track any follow-up actions to completion.</td><td>Security team</td><td>Security team time</td><td><ul><li>ISO 27001:2022 and ISO 42001 surveillance audits completed in 2026.</li><li>SOC 2 Type II audit completed in 2026.</li><li>Final reports received and any nonconformities or exceptions logged with owners and due dates.</li></ul></td><td>End of December 2026</td></tr><tr><td>5) Maintain a cycle of continuous improvement.</td><td>Remediate findings identified by audits.</td><td>Security team</td><td>Ad-hoc</td><td><ul><li>ISO 27001:2022 certification maintained in 2026 with 0 nonconformities.</li><li>SOC 2 audit with 0 exceptions in the final report.</li><li>ISO 42001 certification achieved in 2026.</li></ul></td><td>End of December 2026</td></tr><tr><td>6) Foster a culture of security awareness within FundApps.</td><td>Maintain a robust security awareness programme covering onboarding and refresher training, with emphasis on practical reporting behaviours.</td><td>Security team</td><td>Security team time</td><td><ul><li>All staff complete required security awareness training.</li><li>0 C1, C2, or C3 incidents attributable to lack of awareness.</li><li>Annual survey confirming confidence in reporting, with actions tracked.</li></ul></td><td>End of December 2026</td></tr><tr><td>8) Strengthen infrastructure security and resilience</td><td>Reduce exposure to common web threats and improve resilience to high-volume attack patterns.</td><td>Security team</td><td>Security team time, Engineering time</td><td><ul><li>AWS WAF and DDoS protection deployed to production for in-scope workloads by 31 Dec 2026.</li></ul></td><td>30 Jun 2026</td></tr><tr><td>9) Reduce operational and third-party security risks</td><td>Improve privileged access governance and remove the last remaining legacy component.</td><td>Security team</td><td>Security team time</td><td><ul><li>Privileged access solution implemented by 30 Mar 2026 with 0 incidents attributable to misconfiguration or service failure.</li><li>Legacy notification component decommissioned by 30 Jun 2026.</li></ul></td><td>End of December 2026</td></tr></tbody></table>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://policies.fundapps.co/client-portal/-LubIC9uIsME-_T0mNXu/fundapps-policies/information-security-management-system/objective-plan.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
