Skip to main content
Review and revision metadata
Review Date: 2026-07-21
Reviewer: Operations Manager

previous version on gdrive

Clause 8: Operation

1. Objective​

The objective of this control framework is to translate security planning into operational execution by:

  • Planning, implementing, and controlling the operational processes required to meet systemic information security requirements (Clause 8.1)
  • Ensuring that information security risk assessments are performed at planned intervals or when material changes occur (Clause 8.2)
  • Ensuring that the finalized information security risk treatment plan is systematically executed and monitored (Clause 8.3)

2. Scope​

The scope of this document aligns directly with the overall scope of the ISMS as defined in Clause 4 (Context of the Organization).

3. Availability and Access​

This document is:

  • Required reading for all anDREa employees and contractors.
  • Available to all authorized interested parties and platform users via our public ISMS repository.