4.4 Information Security Management System Framework
anDREa establishes, implements, maintains, and continually improves its ISMS in strict accordance with ISO/IEC 27001 requirements. We leverage the Plan-Do-Check-Act (PDCA) methodology to embed security operations directly into our organizational culture and product development lifecycle.
4.4.1 Plan
Information security management is driven by clearly defined strategic goals, which dictate our operational activities and resource allocations.
- Annual Reassessments: Management conducts a formal, comprehensive risk assessment annually to re-evaluate anDREa’s assets, dependencies, and risk profile.
- Ad-hoc Reassessments: Material changes to our operational landscape, infrastructure, or threat environment trigger immediate, targeted risk assessments.
- Compliance Alignment: This structured approach satisfies the requirements of Clause 6 (Planning) and Clause 8 (Operation).
4.4.2 Do
anDREa executes its security strategy by deploying and maintaining a comprehensive set of procedural, technical, and organizational controls.
- Operational Integration: Security controls are not isolated silos; they are fully integrated into our way of working and general quality assurance workflows.
- Governance Reporting: Control owners routinely report on control performance, operational metrics, and effectiveness directly to the Management Team.
- Documentation Architecture: Active controls, baseline expectations, and operational instructions are codified in formal policy documents, standard operating procedures (SOPs), and guidelines.
4.4.3 Check (Study) & Act
anDREa systematically monitors the ISMS to detect process deficiencies, identify potential security breaches, and evaluate control performance. This continuous oversight ensures management receives timely data to execute effective corrective actions.
Security verification is structured across three core areas:
- Control Effectiveness Appraisals: Designated asset and control owners verify whether security objectives are met based on predefined, measurable criteria.
- Independent Audits: We conduct periodic internal and external audits of the ISMS, supplemented by independent, technical security assessments (e.g., penetration testing).
- Impartiality Mandate: To prevent conflicts of interest, anDREa employees are strictly prohibited from acting as formal auditors for our own certified boundaries.
- Adequacy Assessments: Management reviews the overall suitability and adequacy of the security policy framework at least annually, or sooner if a significant operational shift occurs. This assessment aggregates inputs from:
- Internal and external audit findings.
- Recent risk assessment outputs.
- Historical security incident data and near-misses.
Records Management: The findings, metrics, and definitive conclusions of these evaluations are formally recorded in the annual Security Management Report. The management reports of internal and external audits, and pentests are published in the section Management Reports.
4.4.4 Continuous Improvement
The evaluation of performance data directly feeds our continuous improvement loop. Validated insights from audits, reviews, and incident post-mortems are systematically translated into corrective and preventive actions. These updates result in the iterative refinement, adjustment, or creation of security policies and technical controls—all of which require formal Management Team authorization prior to deployment.