Clause 6: Planning
1. Objective
The objective of this control framework is to establish an actionable methodology for security planning and lifecycle management by:
- Identifying, evaluating, and addressing strategic risks and opportunities through structured risk assessment and treatment processes Clause 6.1 - Actions to address risks and opportunities
- Defining, measuring, and planning the achievement of clear information security objectives Clause 6.2 - Information Security Objectives and Planning to Achieve Them
- Establishing a controlled process for managing structural or operational changes to the ISMS Clause 6.3 - Planning of Changes
2. Scope
The scope of this document aligns directly with the overall scope of the ISMS as defined in Clause 4 - Context of the Organisation.
3. Availability and Access
This document is:
- Required reading for all anDREa employees and contractors.
- Available to all authorized interested parties and platform users via our public ISMS repository.