Clause 8: Operation
1. Objective
The objective of this control framework is to translate security planning into operational execution by:
- Planning, implementing, and controlling the operational processes required to meet systemic information security requirements (Clause 8.1)
- Ensuring that information security risk assessments are performed at planned intervals or when material changes occur (Clause 8.2)
- Ensuring that the finalized information security risk treatment plan is systematically executed and monitored (Clause 8.3)
2. Scope
The scope of this document aligns directly with the overall scope of the ISMS as defined in Clause 4 (Context of the Organization).
3. Availability and Access
This document is:
- Required reading for all anDREa employees and contractors.
- Available to all authorized interested parties and platform users via our public ISMS repository.