Skip to main content
Review and revision metadata
Review Date: 2026-06-19
Reviewer: Director

previous version on gdrive

9.3 Management Review

9.3.1 General Requirements

Top Management reviews anDREa’s Information Security Management System (ISMS) at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.

To satisfy ISO/IEC 27001 Clause 9.3.1, our leadership team maintains active oversight through a structured governance cadence:

  • Document Authorization: The Director reviews and formally approves all additions or structural revisions to the documented information within the ISMS.
  • Active Governance: Management representatives participate directly in our bi-monthly Information Security Management Board (ISMB) Meetings.
  • Audit Participation: Management representatives actively participate in internal and external compliance audits to ensure an accurate understanding of our security posture.
  • Annual Reporting Evaluation: Leadership performs an annual, comprehensive evaluation of the security framework driven by the formal Security Management Reports.
  • Action Tracking: All operational findings, resource adjustments, and corrective directives originating from these management reviews are logged and tracked until resolution within the Issues and Risk Logging system.

Statutory NIS 2 Directive Adjustments

In addition to standard ISO/IEC 27001 evaluation parameters, our management reviews explicitly incorporate the following statutory items:

  • Regulatory Landscape Evolution: Tracking and evaluating changes in local NIS 2 national legislation or sector-specific data protection guidelines.
  • Incident History Analysis: Reviewing formal summaries of all "significant incidents" reported to national authorities, such as the National Cyber Security Centre Netherlands (NCSC-NL).
  • Mandatory Executive Competence: Documenting and verifying that the Management Team has successfully completed mandatory cybersecurity risk management training as legally required under NIS 2 Article 20.

9.3.2 Management Review Inputs and Metrics

The annual evaluation of the ISMS integrates data from across the organization to form a complete overview of our security posture. The review includes a comprehensive analysis of:

  • Historical Commitments: The operational status of actions and directives originating from previous management reviews.
  • Contextual Shifts: Changes in internal or external issues (PESTLE factors) affecting our operational environment.
  • Stakeholder Requirements: Shifting expectations from regulatory bodies, healthcare clients, and cloud hosting partners.
  • Performance Telemetry and Gaps: Aggregated trend indicators across reported nonconformities, remediation actions, control measurement outputs, audit findings, and progress toward our core security objectives.
  • External Feedback Loops: Inbound security questionnaires, complaints, or improvement requests from customers and third-party auditors.
  • Risk Profile Vector: The current status of the Risk-Control Matrix, emerging threat intelligence patterns, and the progression of open risk treatment plans.
  • Improvement Inlets: Identified optimization areas across our technical architecture and procedural controls.

9.3.3 Management Review Results and Reporting

The outputs of our management reviews document leadership's decisions regarding improvement opportunities and any necessary structural updates to the ISMS.

The primary artifact summarizing these decisions is the annual Security Management Report, compiled by the Director and archived within the Security Management Reports library. This report contains:

  • An analysis of shifting internal and external environmental factors.
  • Aggregated performance results from internal/external audits, penetration tests, SLA compliance tracking, and automated security effectiveness metrics.
  • A lookback validating the fulfillment of information security objectives from the preceding year.
  • The formalized information security objectives and baseline KPIs established for the current fiscal period.
  • An updated snapshot of the overall corporate risk architecture and the status of our treatment plans.
  • Identified opportunities for continuous framework improvement.
  • Resource Allocation Plan: A formalized budget layout authorizing sufficient financial and human resources to sustain required technical and organizational security controls (Resource Allocation Plan).
  • Statutory Liability Acknowledgment: Explicit, written acceptance and formal sign-off by the Director regarding our current residual risk levels, satisfying the executive governance duties mandated under the NIS 2 Directive (https://docs.google.com/document/d/1x_WVds159AKszVqIX6WjKwYGAz67nK0k5aj47MTqYMs/edit?tab=t.uucxhgpxcy01#heading=h.nn224s6wbvg3).

Audit Traceability: All official leadership directives, strategic pivots, and policy authorizations resulting from this review lifecycle are permanently logged in the Management Decisions register.