Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager
previous version on gdrive
anDREa determines the internal and external communication requirements relevant to the ISMS to ensure accurate, timely, and secure information dissemination.
General communication standards, tool selections, and baseline facilities are governed by the Communication Facilities Policy. Specific information security and compliance communications are executed according to the structured matrices below, satisfying ISO/IEC 27001 Clause 7.4.
| What to Communicate | When to Communicate | Target Audience | Responsible Role | Process / Channel |
|---|
| Statement of Applicability (SoA) | Always publicly accessible | All Interested Parties | Management Team | Public ISMS Repository |
| Information Security Policy | Always publicly accessible | All Interested Parties | Management Team | Public ISMS Repository (Clause 5.2) |
| Subsidiary Policy Documents | Always publicly accessible | All Interested Parties | Management Team | Public ISMS Repository |
| Internal ISMS Documentation | During formal audit windows | External Auditors / Compliance Consultants | Management Team | Secure Audit Data Room |
| Operational ISMS Records | During formal audit windows | External Auditors / Compliance Consultants | Management Team | Secure Audit Data Room |
7.4.2 Security Incidents and Anomalies
| What to Communicate | When to Communicate | Target Audience | Responsible Role | Process / Channel |
|---|
| External Incident Notification | Within timelines specified by SLAs, contracts, or Data Processing Agreements (DPAs) | Affected Customers & Partners | Management Team | Direct security advisory via established client communication protocols |
| Internal Incident Reporting | Immediately upon observation or suspicion | Management Team | All Employees & Contractors | Internal Incident Logging System (Annex A.05) |
7.4.3 Internal Security and Compliance Updates
| What to Communicate | When to Communicate | Target Audience | Responsible Role | Process / Channel |
|---|
| Implemented Policy Changes | Immediately following a new version release or authorization | All Employees & Contractors | Management Team | Internal announcement and distribution channels |
| Security Awareness Briefings | Bi-annually (at minimum) | All Employees & Contractors | Management Team | Structured awareness training and corporate Knowledge Base articles (Annex A.06.03) |