6.2 Information Security Objectives and Planning to Achieve Them
anDREa establishes measurable information security objectives at all relevant functional levels to maintain strategic alignment with our core Information Security Policy, regulatory mandates, and risk treatment outputs.
6.2.1 Objective Formulation and Structure
To satisfy ISO/IEC 27001 Clause 6.2, our objectives are explicitly structured to ensure complete accountability:
- Strategic Mapping: Corporate security milestones and cybersecurity goals are maintained in the central anDREa Information Security Strategy.
- Operational Control Metrics: ** In alginment with our risk-based approach, anDREa tracks macro-level process effectiviness, derived from operations, with measurable targets in Information Security Performance.
- Risk Integration: The creation or modification of any security objective directly incorporates findings from recent risk assessments, threat intelligence triggers, and legislative shifts.
6.2.2 Monitoring, Review, and Evaluation
Planning the execution, resourcing, and evaluation of security objectives is integrated directly into the corporate operational cycle:
- Lifecycle Oversight: The Management Team actively tracks progress, resource utilization, and delivery timelines throughout the fiscal year.
- Annual Reporting: Control effectiveness data and objective status updates are consolidated by the MT and formally presented in the annual Security Management Report.
- Management Authorization: The Board of Directors reviews and approves the objective tracking list annually, authorizing target adjustments or updates as the threat landscape changes.