9.2 Internal Audit
9.2.1 General Requirements
anDREa conducts formal internal audits at planned intervals to ensure the ISMS complies with our corporate requirements, fully satisfies the clauses of the ISO/IEC 27001 standard, and remains effectively implemented and maintained.
To maintain compliance with both ISO/IEC 27001 Clause 9.2 and European Union regulatory mandates, our internal audit strategy is driven by a comprehensive Audit Planning schedule that explicitly mandates the following objectives:
- NIS 2 Article 21 Verification: Review and test the practical implementation of all technical and operational cybersecurity risk-management measures required by Article 21 of the NIS 2 Directive.
- Incident Telemetry Validation: Test the technical effectiveness and operational speed of our "early warning" (24-hour) and mandatory "incident notification" (72-hour) alerting protocols.
- Comprehensive Environmental Scope: Ensure the audit boundaries cover the entirety of the myDRE platform architecture, including underlying cloud infrastructure, backing configurations, operational workflows, and critical third-party supply chain dependencies.
9.2.2 Internal Audit Program Governance
To safeguard the integrity of our assessment loops, anDREa establishes and executes its internal audit program through specific operational rules:
1. Auditor Competence and Impartiality
To ensure absolute objectivity and impartiality, anDREa contracts an independent, qualified external third party to conduct all formal internal audits. The designated auditor must fulfill the following criteria:
- Technical Domain Expertise: Demonstrate deep knowledge of information technology and cloud-native architectures to thoroughly evaluate security configurations and systemic interdependencies.
- Professional Credentials: Hold an active, verified industry credential (e.g., Lead Auditor certification, Register Accountant) or demonstrate a minimum of three years of professional information security auditing experience.
- Regulatory Focus: The auditor must explicitly highlight all findings regarding ISO 27001 and NIS 2 compliance within the final deliverable to allow for immediate triage by the Management Team.
2. Organizational Support
All anDREa personnel are required to support the auditor. The Management Team provides complete access to all policies, technical configurations, operational procedures, and evidence registries needed to execute the review.
3. The Three-Tier Assessment Methodology
Every audit systematically tests controls across three operational dimensions:
- Design: Is there an approved, documented policy or standard operating procedure that meets the target compliance criteria?
- Existence: Has the documented control been practically deployed and made active within our operational or technical environment?
- Functioning: Is the deployed control operating effectively, and is there verifiable, reproducible evidence confirming its ongoing performance?
9.2.3 Audit Lifecycle Procedure
The execution of the internal audit program follows a structured four-stage procedure:
1. Audit Planning and Initialization
The external auditor drafts an explicit audit plan defining the target areas, technical scope, specialized subject-matter experts involved, and specific personnel to be interviewed.
This plan is reviewed and refined with the Management Team. Once finalized, the MT distributes the plan across the organization, and the Business Manager schedules the necessary interview slots.
2. Preparing the Audit Environment
The Management Team and the auditor establish dedicated digital collaboration spaces.
The MT brief the designated interviewees on the plan and update specific audit target items based on recent technical changes, current events, or active threat trends to maximize the auditor's time.
3. Carrying Out the Audit
- Sampling and Risk Focus: The auditor evaluates the existence and functioning of controls against the core standard. The auditor and the Management Team may dynamically adjust focus areas during execution—allocating more or less attention to specific controls based on recent security incidents, emerging threat indicators, previous audit results, and process criticality. All adjustments and justifications are documented within the final report.
- Audit Trail Preservation: The auditor maintains a comprehensive audit trail documenting all items, configurations, and logs reviewed as evidence. Once the audit session concludes, the Management Team secures and archives this audit trail to preserve data integrity.
4. Reporting Architecture
The auditor compiles a formal report detailing findings categorized by subject area. This deliverable includes:
- The specific evaluation criteria tested.
- Definitive assessment results and identified gaps.
- A list of interviewed personnel and a complete index of the reviewed audit trail.
- Detailed explanations of any observed nonconformities, supported by empirical evidence.
The finalized audit report is delivered directly to the Business Manager for distribution and management response.
9.2.4 Corrective Action Follow-Up and Recording
If nonconformities or systemic gaps are discovered during the audit loop, anDREa executes an immediate remediation lifecycle:
- Root-Cause Remediation: The Director authors a formal follow-up report detailing the nature of the deficiency, its potential blast radius, its root cause, and immediate corrective actions alongside long-term structural fixes.
- Tracking and Ticket Isolation: Remediation tracks are logged within our technical ticketing system, tagged explicitly with the metadata marker
internal audit, and managed in accordance with Clause 10 (Improvement). Progress is monitored regularly by management until the ticket is resolved. - Central Logging: All audit findings, recommendations, and remediation actions are archived inside the central Issues and Risk Logging register to provide historical proof of compliance.
- Executive Transparency: The Director distills the final audit report into an internal management summary for publication in Management Reports.