Skip to main content
Review and revision metadata
Review Date: 2026-07-21
Reviewer: Operations Manager

previous version on gdrive

Clause 8: Operation

1. Objective

The objective of this control framework is to translate security planning into operational execution by:

  • Planning, implementing, and controlling the operational processes required to meet systemic information security requirements (Clause 8.1)
  • Ensuring that information security risk assessments are performed at planned intervals or when material changes occur (Clause 8.2)
  • Ensuring that the finalized information security risk treatment plan is systematically executed and monitored (Clause 8.3)

2. Scope

The scope of this document aligns directly with the overall scope of the ISMS as defined in Clause 4 (Context of the Organization).

3. Availability and Access

This document is:

  • Required reading for all anDREa employees and contractors.
  • Available to all authorized interested parties and platform users via our public ISMS repository.