Skip to main content
Review and revision metadata
Review Date: 2026-06-19
Reviewer: Director

previous version on gdrive

9.1 Monitoring, Measurement, Analysis, and Evaluation

anDREa evaluates the performance and operational effectiveness of the ISMS by using standardized, reproducible methods that ensure comparable results. This measurement framework satisfies ISO/IEC 27001 Clause 9.1 and incorporates compliance indicators dictated by the NIS 2 Directive.


9.1.1 Monitoring and Measurement Framework

Operational security monitoring is split into structural schedules and metrics to ensure complete coverage across all organizational levels.

Routine Technical and Process Checks

What, when, and by whom tracking tasks are executed is governed by the Periodic Security Controls ledger. This internal operational runbook details step-by-step instructions, execution frequencies, and explicit ownership assignments to verify that controls operate as intended.

Strategic Policy Effectiveness

To measure the impact of security policies, anDREa maintains explicit benchmarks within the Information Security Performance dashboard.

  • Measurement & Log Assembly: Designated asset owners collect raw security data according to the criteria and timelines mapped out in each policy. The Director aggregates and logs these results.
  • Analysis & Governance Evaluation: Aggregated results are analyzed collectively during our bi-monthly Information Security Management Board (ISMB) Meetings and compiled into the annual Security Management Reports for formal validation and strategy updates by top management.

9.1.2 European Union NIS 2 Directive Integration

To fulfill regulatory obligations under NIS 2 legislation for cloud service infrastructures, anDREa maintains a targeted monitoring and detection profile:

  • Control Adequacy: Performance reviews verify all security controls listed across our active Statement of Applicability (SoA), focusing heavily on supply chain security, automated vulnerability patch cycles, and platform access logging.
  • Core Cloud Fabric Infrastructure Telemetry: The operational performance, horizontal scale capacity, and resilience profiles of critical underlying infrastructure components—including Microsoft Azure resource endpoints and core myDRE orchestration components—are continuously evaluated against strict Availability and Downtime Key Performance Indicators (Information Security Performance).
  • Significant Incident Detection: Event logs are paired with correlation rules specifically tuned to isolate and flag "significant incidents" as defined by the NIS 2 framework (any disruption causing material operational downtime, severe financial impact, or downstream systemic risk).
  • Incident Metrics & Telemetry: Measurement criteria track key indicators, such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). These metrics provide top management with empirical evidence regarding anDREa's cybersecurity posture and statutory compliance status.

9.1.3 Retention of Evidence

To guarantee data integrity for compliance reviews and independent third-party certification audits: