Skip to main content
Review and revision metadata
Review Date: 2026-08-18
Reviewer: Director

previous version on gdrive

6.1 Actions to Address Risks and Opportunities

6.1.1 General Methodology

anDREa identifies and addresses strategic risks and opportunities by cross-referencing internal and external issues with stakeholder expectations (Clause 4 - Context of the Organisation). Strategic risks are consolidated into our Risk Register, creating a direct link between identified vulnerabilities and active mitigation strategies.

To satisfy ISO/IEC 27001 Clause 6.1, we manage this lifecycle through integrated framework layers:

  • Outcome Delivery: System performance and compliance baselines are evaluated using the processes detailed in Clause 9 - Performance.
  • Undesired Effect Mitigation: Control performance and continuous security baselines are tracked via our Information Security Performance.
  • Continual Improvement: Structural optimization of the threat landscape follows the procedures established in Clause 10 - Improvement.

6.1.2 Information Security Risk Assessment Process

Risk assessments are executed in accordance with our formal Risk Assessment Guidance to ensure that repeatable analyses produce consistent, objective, and comparable results.

Foundational Baseline Security Criteria

Every assessment evaluates assets against our core structural security principles, as outlined in the Security Manifesto:

  • Identity & Access: myDRE workspaces and backing orchestration components must remain accessible only to authorized users and authenticated programmatic services using role-based access control (RBAC) and least-privilege principles.
  • Blast Radius Isolation: A security compromise within an individual workspace must be structurally contained, preventing lateral movement or spillover to other workspaces or the myDRE cloud fabric.
  • Telemetry & Auditability: Continuous, active logging and security monitoring must be maintained to provide early warning metrics and forensic traceability.
  • Rapid Containment Controls: The platform must support immediate, granular isolation procedures, including blocking specific users, terminating workspaces, tearing down individual cloud subscriptions, or executing a full myDRE platform lockdown.

Risk Assessment Typologies

anDREa utilizes three distinct triggers for risk evaluation:

  1. Annual Integral Risk Assessment: A comprehensive review of all systemic dependencies, corporate operations, and information security risks across our full ISMS scope.
  2. Specific Risk Assessment: A targeted analysis initiated prior to major software releases, architectural changes, or operational pivots to map new localized vectors (SIA Instructions).
  3. Threat-Driven Assessment: An ad-hoc evaluation triggered by threat intelligence alerts (A.05.07 - Threat intelligence) indicating novel zero-days, supply-chain vulnerabilities, or shifting ransomware tactics affecting our infrastructure stack.

Governance Roles and Responsibilities

  • Management Team (MT): Coordinates integral and specific risk assessments, chairs workshops, and documents findings.
  • Asset/Process Owners: Identify operational dependencies, surface vulnerabilities, and maintain accountability within their domains.
  • Extended Team & Stakeholders: The MT engages internal developers, external experts, and client representatives as necessary to refine assessment data.

6.1.3 Risk Assessment Procedure

The Management Team governs the implementation of the six-stage risk assessment process, archiving all collateral within designated Security Impact Assessment Register repositories in the corporate document store.

  1. Stage 1: Preparation Define the specific assessment scope and objectives. Cross-reference relevant internal or external PESTLE factors and inventory the processes, business assets, cloud resources, and corresponding data owners under review.
  2. Stage 2: Dependency Analysis Convene a workshop with the MT, asset owners, and technical experts. Map systemic cross-dependencies and establish baseline security values across five vectors: Confidentiality, Integrity, Availability, Cost, Auditability, and Authenticity.
  3. Stage 3: Risk Identification Conduct workshops or structured interviews to uncover exact risk scenarios, assigning an explicit risk owner to each item. Execute a formal Data Protection Impact Assessment (DPIA) if the scope involves material adjustments to the processing of privacy-sensitive healthcare or personal data.
  4. Stage 4: Evaluation & Mitigation Planning Evaluate risks against defined qualitative thresholds (Low, Medium, High) accounting for likelihood, consequence, control costs, and stakeholder tolerance levels. Map each risk to one of four lifecycle options: Accept, Mitigate, Avoid, or Deflect.
  5. Stage 5: Reporting & Authorization Compile the findings into the Compliance and Risk Matrices. Present the matrix to the the Director for approval. The Director must explicitly review and sign off on all proposed mitigations and documented residual risks. Determine if any specific risks necessitate communication to external interested parties.
  6. Stage 6: Risk Treatment Execution Log approved mitigation tasks within the Information Security Management Board (ISMB) action register as Product Backlog Items (PBIs) or tracking tickets. Following implementation, assess control effectiveness to calculate the updated net residual risk level.

6.1.4 Information Security Risk Treatment

anDREa treats the ISO/IEC 27002:2022 control set as a comprehensive, mutually reinforcing framework of security best practices.

Because the myDRE platform functions as an advanced data-hosting, ingress, and analytics workspace environment for highly sensitive data—rather than an active medical-care application—the ISO/IEC 27002 standard provides a superior operational security baseline for our architecture than localized healthcare standards like NEN7510.

  • Statement of Applicability (SoA): anDREa maintains a formal Statement of Applicability that details all required ISO/IEC 27001 Annex A controls, their current implementation status, and comprehensive justifications for any explicit inclusions or exclusions (Statement of Applicability).
  • Action Prioritization: When executing risk treatment plans, tasks are prioritized dynamically based on:
    • The net severity of the linked risk.
    • Operational "quick wins" (high risk reduction with low engineering friction).
    • Staff capacity and available budgetary resources.
  • Continuous Review: Active risk treatment plans, residual risk acceptances, and open PBIs are reviewed and updated during our bi-monthly Information Security Management Board (ISMB) sessions.