“IMS-Smart On-Line is indeed a product of the 21st Century”, as an ISO/IEC 27001/ISO 9001 assessor said at the conclusion of an initial audit in 2008
 

Mastering Risk Assessment and the Statement of Applicability

Conditions of use for an evaluation licence

Definitions

The customer: an organisation that uses the Mastering Risk Assessment and the Statement of Applicability Software Assistant hereafter referred to as the Assistant.

IMS-Smart: a methodology with associated technology and productised IP-led services, including training for creating integrated management systems, including information security management systems.

The Assistant: the Mastering Risk Assessment and the Statement of Applicability Assistant provided by IMS-Smart Limited, a company registered in England, number 6630803.

Purpose: the purpose of the Assistant is to assist customers to the perform information security risk assessment, risk treatment and produce a Statement of Applicability in conformity to the requirements of ISO/IEC 27001.

IMSid: The identifier with which the customer has licensed its use of the Assistant.

Custom text: text generated by the customer, including answers to Assistant questions, which is stored in the Assistant.

Regular Assistant user: a person with customer authority to generate and modify custom text.

IMS-Smart text: text generated by IMS-Smart Limited which is stored in the Assistant.

A Management System: a set of interrelated or interacting elements of an organisation to establish policies and objectives and processes to achieve those objectives.

An Information Security Management System (ISMS): a management system that conforms to ISO/IEC 27001.

Your obligations

The customer is responsible for the performance of all the steps necessary to develop and implement their ISMS. The use of the Assistant greatly facilitates those tasks but IMS-Smart Limited makes no claim as to the ability of the customer to properly accomplish their implementation through use of the Assistant alone. In particular:

  • The Assistant does not by itself create or maintain an ISMS or guarantee conformance with ISO/IEC 27001:2022.
  • The Assistant only assists customers to fulfil the risk assessment, risk treatment and Statement of Applicability requirements of ISO/IEC 27001. The Assistant does not assist customers to meet the many other requirements of ISO/IEC 27001.
  • The customer must provide custom text in accordance with the instructions provided by the Assistant.
  • The customer is responsible for ensuring the accuracy and truthfulness of custom text, including the results of calculations performed on such custom text by the Assistant.
  • Specifically, the customer is responsible for approving the results of risk assessment and effectiveness calculations.

The customer is responsible for breaches of copyright arising from actions of their employees, or persons under their control.

The customer is responsible for ensuring that any hyperlinks they place in custom text do not redirect their Assistant administrators or regular Assistant users to phishing or malware sites, or use forwards to access unauthorised pages.

The customer must not provide custom text that contains:

  • Warez, illegal, immoral or copyright material. The onus is on you the customer to prove that you own the rights to publish material, not for IMS-Smart Limited to prove that you do not.
  • MP3 and other multimedia files.
  • Password protected archive (e.g. zip or rar) files, or data back ups.
  • Pornographic or other lewd material. Adult Material includes all pornography, erotic images, or otherwise lewd or obscene content. The designation of "adult material" is left entirely to the discretion of IMS-Smart Limited.
  • HTML forms or JavaScript or other executable code.

The customer must not attempt to:

  • Circumvent the user authentication and access control mechanisms.
  • Access the the Assistant databases directly.
  • Decipher the Assistant encrypted information.
  • Reverse engineer the the Assistant software.

Limitation of Liability

In no event will IMS-Smart Limited be liable to the customer for any damages, claims or costs whatsoever or any consequential, indirect, incidental damages, or any lost profits or lost savings, even if IMS-Smart Limited’s representative has been advised of the possibility of such loss, damages, claims or costs or for any claim by any third party. The foregoing limitations and exclusions apply to the extent permitted by applicable law in customer’s jurisdiction. IMS-Smart Limited’s aggregate liability under or in connection with this agreement shall be limited to the amount paid for the use of the Assistant, if any.

Governing Law

The Law pertaining to these conditions of use and any correspondence or contracts related thereto shall be governed and construed by the Laws of England.

Termination

IMS-Smart Limited reserves the right to suspend or cancel a customer’s access to the Assistant, where IMS-Smart Limited decides that the Assistant has been inappropriately used, or that the customer has violated these conditions of use.

The evaluation licence expires 5 days after registration.

When the licence has expired, users and administrators will not be able to log on or access Assistant data.


Additional conditions of use for a full licence

With a full licence:

  1. under the heading of termination, the clause about the expiry of the evaluation licence is replaced with one of the form:
    The IMS-Smart licence expires on yyyy-mm-dd

  2. the following additional conditions will appear under the headings of definitions and your obligations. The ellipses (...) represent text in the above conditions to enable you to see where this additional text fits.

Note that the clause under the heading of your obligations lists the maximum number of administrators and regular users permitted by the licence.

 

under the heading of Definitions

Assistant administrator: a person with customer authority to perform administrative functions in addition to generating and modifying custom text.

under the heading of Your obligations

The customer is responsible for assigning their users to the various Assistant administrator or regular Assistant user roles and for obligating users to look after their passwords so as to protect IMS-Smart On-Line from unauthorised access.