ISO/IEC 27001
Information Security Management System certification.
CREATIVE MEDIA TRUST CENTER
Creative Media publishes and distributes content across books, eBooks, audiobooks, magazines, apps, and music. This Trust Center documents the principal standards, frameworks, identifiers, assurance programs, and regulatory requirements relevant to those products and to our supporting technology.
Reference to a standard does not mean Creative Media is certified, audited, or independently attested against it. A certification or attestation is shown as held only when verified evidence has been published. Otherwise the status is explicitly listed as Not publicly asserted, Reference baseline, or Applicable when in scope.
ASSURANCE DIRECTORY
Programs a modern print-and-digital publisher may use to demonstrate third-party assurance. Current public status is intentionally conservative.
Information Security Management System certification.
Privacy Information Management System certification.
Business Continuity Management System certification.
Independent CPA attestation against applicable Trust Services Criteria; this is an attestation, not a certification.
Assessment or self-assessment evidence for environments that store, process, transmit, or can affect cardholder data.
Quality Management System certification for repeatable quality processes.
Environmental Management System certification.
Traceability certifications relevant to paper and print supply chains when certified materials are specified.
STANDARDS REGISTER
This register covers major cross-industry and media-specific references. Applicability varies by product, market, data flow, retailer, distributor, and customer.
| Standard / framework | Category | Primary scope | Public posture |
|---|
CONTROL OBJECTIVES
These objectives describe the control domains expected for Creative Media's publishing and technology environment. They are not a substitute for a third-party audit report.
Centralized identity, strong authentication, least privilege, role separation, periodic access review, and protected administrator workflows.
Secure configuration, HTTPS, dependency management, vulnerability remediation, logging, change control, and risk-based application security testing.
Data minimization, purpose limitation, retention rules, deletion workflows, data-subject rights support, and special care for children's data where applicable.
Accessible content structures, alternative text, keyboard support, readable contrast, semantic metadata, and product-level accessibility testing.
Identifier governance, metadata quality, edition/format separation, rights and territorial controls, provenance, corrections, and distribution consistency.
Risk-tiered suppliers, contract controls, subprocessors, secure software dependencies, printer/distributor requirements, and continuity considerations.
Detection, triage, containment, evidence preservation, recovery, stakeholder communication, root-cause review, and corrective actions.
Backups, recovery objectives, tested restoration, platform redundancy where appropriate, supplier dependencies, and documented continuity procedures.
Ownership and license records, permissions, takedown workflows, royalty/source metadata, territorial rights, and responsible use of third-party content.
FORMAT-SPECIFIC TRUST
Each media type has different technical and commercial controls. Creative Media's Trust Center keeps those requirements visible rather than treating publishing as a single-format workflow.
RESPONSIBLE DISCLOSURE
If you believe you found a vulnerability, privacy issue, rights problem, or accessibility barrier involving a Creative Media service, please contact us with enough detail to reproduce and assess it. Do not access, alter, download, or disclose data beyond what is necessary to demonstrate the issue.
EVIDENCE & REVIEWS
Architecture, access, change, logging, incident, and recovery controls are maintained as operational documentation. Public summaries are published here when appropriate.
Product accessibility metadata and testing evidence should travel with applicable digital products and be updated when formats change.
Printer, distributor, cloud, payment, and software suppliers may require separate attestations or certifications based on scope.
Standards and regulatory references are reviewed as specifications evolve. This page was last materially reviewed .