9.1 Monitoring, Measurement, Analysis, and Evaluation
anDREa evaluates the performance and operational effectiveness of the ISMS by using standardized, reproducible methods that ensure comparable results. This measurement framework satisfies ISO/IEC 27001 Clause 9.1 and incorporates compliance indicators dictated by the NIS 2 Directive.
9.1.1 Monitoring and Measurement Framework
Operational security monitoring is split into structural schedules and metrics to ensure complete coverage across all organizational levels.
Routine Technical and Process Checks
What, when, and by whom tracking tasks are executed is governed by the Periodic Security Controls ledger. This internal operational runbook details step-by-step instructions, execution frequencies, and explicit ownership assignments to verify that controls operate as intended.
Strategic Policy Effectiveness
To measure the impact of security policies, anDREa maintains explicit benchmarks within the Information Security Performance dashboard.
- Measurement & Log Assembly: Designated asset owners collect raw security data according to the criteria and timelines mapped out in each policy. The Director aggregates and logs these results.
- Analysis & Governance Evaluation: Aggregated results are analyzed collectively during our bi-monthly Information Security Management Board (ISMB) Meetings and compiled into the annual Security Management Reports for formal validation and strategy updates by top management.
9.1.2 European Union NIS 2 Directive Integration
To fulfill regulatory obligations under NIS 2 legislation for cloud service infrastructures, anDREa maintains a targeted monitoring and detection profile:
- Control Adequacy: Performance reviews verify all security controls listed across our active Statement of Applicability (SoA), focusing heavily on supply chain security, automated vulnerability patch cycles, and platform access logging.
- Core Cloud Fabric Infrastructure Telemetry: The operational performance, horizontal scale capacity, and resilience profiles of critical underlying infrastructure components—including Microsoft Azure resource endpoints and core myDRE orchestration components—are continuously evaluated against strict Availability and Downtime Key Performance Indicators (Information Security Performance).
- Significant Incident Detection: Event logs are paired with correlation rules specifically tuned to isolate and flag "significant incidents" as defined by the NIS 2 framework (any disruption causing material operational downtime, severe financial impact, or downstream systemic risk).
- Incident Metrics & Telemetry: Measurement criteria track key indicators, such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). These metrics provide top management with empirical evidence regarding anDREa's cybersecurity posture and statutory compliance status.
9.1.3 Retention of Evidence
To guarantee data integrity for compliance reviews and independent third-party certification audits:
- All performance data, measurement outputs, telemetry logs, and analysis reports are retained as documented evidence.
- These records are stored securely in restricted directories within the master Security Management Reports and Information Security Performance archives.