5.1 Leadership and Commitment
anDREa’s Top Management—formally defined as the Management Team (comprising the Director, Business Manager, and Operations Manager)—demonstrates direct leadership and accountability for the ISMS. Management ensures that information security is inherently aligned with the strategic direction of the company, integrated into standard business operations, and resourced effectively.
In alignment with ISO/IEC 27001 Clause 5.1 and NIS 2, management actively fosters a culture of proactive preparedness and urgency regarding the protection of data confidentiality, integrity, and availability.
5.1.1 Governance and Strategy
- Strategic Alignment: Our overarching security architecture and principles are governed by the anDREa's Information Security Strategy.
- Policy Authorization: The Management Team establishes, approves, and routinely reviews the high-level Information Security Policy (see Clause 5.2 - Policy) alongside all supporting security policies. To maintain complete transparency, all approved policies are publicly accessible within the anDREa ISMS repository.
- Oversight and Reporting: Management maintains continuous oversight of the ISMS through two primary channels:
- Bi-monthly Information Security Management Board (ISMB) Meetings: Dedicated sessions to review security tickets, risk registers, and operational metrics.
- Security Management Reports: Formal annual summaries detailing the overall health, performance, and maturity of the ISMS (see Management Reports).
5.1.2 Resource Allocation and Operational Support
In accordance with Clause 4 - Context of the Organisation, Clause 7 - Support, and Clause 10 - Improvement, the Management Team is committed to providing the infrastructure, specialized tools, and financial resources required to maintain a resilient security posture. This commitment includes:
- Human Capital & Training: Provisioning targeted security training, continuous professional development, and technical certifications for personnel.
- Culture and Onboarding: Communicating the critical importance of ISMS compliance directly to all new hires during the mandatory onboarding process and reinforcing these expectations during routine internal meetings.
- Ecosystem Awareness: Promoting broader industry security awareness by authorizing the publication of educational insights and security articles on the myDRE Knowledge Base and our corporate LinkedIn channel.