8.1 Operational Planning and Control
anDREa plans, implements, and controls the core operational processes necessary to meet our information security requirements and execute the risk-mitigation actions defined in Clause 6.
Operational control is managed via our continuous Plan-Do-Study-Act (PDSA) cycle, establishing clear performance criteria and maintaining verifiable documentation to ensure processes execute exactly as planned.
8.1.1 Operational Process Control & Documentation
To maintain verifiable confidence in our operational integrity, anDREa explicitly defines process criteria and retains documented execution evidence across four primary operational domains:
1. Business & Information Security Operations
- Operational Criteria: Daily, (bi)weekly, monthly, quaterly, annual and semi-annual compliance tasks must be executed according to predefined security baselines.
- Evidence Management: Verification logs, recurring technical checklists, and administrative controls are tracked within the Periodic Security Controls.
2. Platform Engineering & Development
- Operational Criteria: Code modifications, infrastructure updates, and architectural changes must follow secure coding standards and explicit acceptance parameters.
- Evidence Management: Engineering pipelines, peer-review sign-offs, and deployment criteria are managed and recorded directly as Product Backlog Items (PBIs) within our enterprise Azure DevOps orchestration ecosystem.
3. Technical Testing & Vulnerability Validation
- Operational Criteria: Before production deployment, all software increments must undergo automated linting, security scanning, and functional regression validation in isolated staging boundaries.
- Evidence Management: Documented validation logs are preserved via Azure DevOps Test Plans, supplemented by master records preserved in the Decisions, Testing, & Plans ledger and Production Testing Documents repository.
4. Customer Support & Incident Management
- Operational Criteria: User tier alerts, platform performance anomalies, and security events must be logged, categorized, and triaged within mandatory contractual response windows.
- Evidence Management: Ticket histories, diagnostic traces, and triage records are hosted securely within our Support & Assurance ecosystem and the central Issues and Risk Logging register.
8.1.2 Change Lifecycle Control & Mitigation
To satisfy ISO/IEC 27001 Clause 8.1 boundaries regarding operational changes:
- Planned Changes: Strategic changes to the myDRE production platform, cloud fabric, or core ISMS policies are executed through our structured change management framework in strict compliance with Annex A.08.32 (Change Management).
- Unintended Changes: Deviations, system regressions, or unauthorized alterations discovered during regular monitoring loops are captured via the Issues and Risk Logging system. Management immediately evaluates downstream security consequences and executes targeted containment or rollback procedures to mitigate adverse effects.
8.1.3 Governance of Externally Provided Services
anDREa operates as a cloud-native scale-up, meaning external SaaS and PaaS dependencies represent a critical component of our operational footprint.
- To ensure that outsourced processes and external service provisions remain secure, anDREa enforces strict evaluation, onboarding, and monitoring baselines.
- Every relevant external supplier must align with our organizational security baselines through binding legal provisions, Service Level Agreement (SLAs), and Data Processing Agreement (specimen) (DPAs).
- Ongoing vendor control, continuous risk assessments, and compliance verifications are executed in accordance with Annex A.05.19 (Information Security in Supplier Relationships) and Annex A.05.20 (Addressing Information Security within Supplier Agreements).