7.3 Awareness
anDREa ensures that all personnel performing work under organizational control are fully aware of their responsibilities, the strategic importance of the ISMS, and the critical role they play in maintaining platform and organizational security.
To satisfy ISO/IEC 27001 Clause 7.3, all staff and contractors must understand:
- The Information Security Policy: Direct awareness of our overarching security principles, classification rules, and operational guidelines (see Clause 5.2).
- Security Contribution: Individual responsibility to actively contribute to the effectiveness of the ISMS, including the tangible benefits of maintaining a robust security posture for our platform users and healthcare clients.
- Non-Conformance Implications: The structural and legal risks that operational deviations or security non-conformance present to our certifications, corporate reputation, and stakeholder trust.
7.3.1 Training, Education, and Accountability
Operational execution, onboarding tracks, and disciplinary frameworks reinforcing security awareness are governed by our specific Annex A control procedures:
- Continuous Awareness: Structured security Training, interactive educational campaigns, and regular technical updates are detailed and executed under Clause 6.3 (Information Security Awareness, Education, and Training).
- Operational Accountability: The formal remediation structures and disciplinary mechanisms applied in the event of deliberate security non-conformance or behavioral policy violations are defined under Annex A.06.04 (Disciplinary Process).