Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

8.3 Information Security Risk Treatment

To satisfy ISO/IEC 27001 Clause 8.3, anDREa systematically implements and tracks its approved information security risk treatment plan. This structure ensures that all identified vulnerabilities are driven down to acceptable residual risk thresholds through monitored engineering and operational tasks.

8.3.1 Governance and Execution Framework

The execution and oversight of our risk treatment strategies are managed via a structured corporate cadence:

  • Information Security Management Board (ISMB) Meetings: This specialized governance board convenes monthly to discuss information security performance, evaluate risk treatment plans, and perform compliance checks.
  • Operational Execution: Approved treatment plans are translated into actionable items and logged within the ISMB Action List. These actions are integrated into our standard sprint cycles for engineering or administrative execution, in strict alignment with the requirements established in Clause 6 (Planning).

8.3.2 Retention of Documented Results

anDREa retains comprehensive, auditable evidence of all risk treatment outcomes. These records allow internal teams and external auditors to trace a risk from its initial identification and evaluation through to its final mitigation and sign-off by the risk owner.

Evidence is securely preserved across the following controlled systems:

  • Governance Records: Detailed decisions, authorized treatment paths, and residual risk acceptances are archived within the ISMB Meeting Notes and the Periodic Security Controls.
  • Technical Evidence: Code modifications, infrastructure hardening steps, and deployment validations are retained as tracking tickets and pull requests within our secure development repositories and the central Issues and Risk Logging register.