Skip to main content
Review and revision metadata
Review Date: 2026-08-11
Reviewer: Operations Manager

previous version on gdrive

10.1 Continual Improvement

anDREa is committed to systematically enhancing the suitability, adequacy, and effectiveness of its ISMS. Our improvement lifecycle ensures that technical safeguards and administrative procedures evolve alongside our changing organizational footprint and threat landscape, satisfying ISO/IEC 27001 Clause 10.1.


10.1.1 Strategic Alignment with Organizational Context

Every identified improvement initiative is mapped directly to our operational boundaries as defined in Clause 4 - Context of the Organisation. This approach guarantees that updates to security controls remain aligned with:

  • The regulatory frameworks governing health-data architectures (such as NEN 7510, GDPR, and the NIS 2 Directive).
  • Technical dependencies associated with our cloud-native Microsoft Azure environment.
  • The specific confidentiality and compliance expectations of our institutional research partners and healthcare clients.

10.1.2 Proactive Improvement Inlets

anDREa identifies framework optimization opportunities through four primary inputs, in accordance with the planning principles established in Clause 6 (Planning):

  • Internal and External Audits: Systematically evaluating our controls against design, existence, and functioning criteria to reveal process gaps and areas for optimization (Clause 9.2 - Internal Audit).
  • Dynamic Risk Assessments: Reviewing and updating the master Risk-Control Matrix as new vulnerabilities emerge, allowing us to proactively deploy hardened controls before threat vectors can be exploited (Clause 6 - Planning / Clause 8 - Operation).
  • Structured Management Reviews: Analyzing long-term trends, resource distribution, and organizational telemetry during our annual review to implement broad structural modifications (Clause 9.3 - Management Review).
  • Stakeholder Feedback Loops: Integrating inbound security questionnaires, client requests, and security researcher insights directly into our risk management and architectural development backlogs.

10.1.3 Metrics-Driven Optimization

Beyond qualitative governance reviews, anDREa uses data-driven validation to guide its improvement initiatives:

  • As mandated by Clause 9 - Performance, specific Information Security Performance KPIs are established for every active policy document.
  • Designated asset owners systematically monitor, measure, and analyze these performance metrics.
  • When a control fails to meet its predefined effectiveness criteria, the deficiency is treated as an operational signal. This triggers an immediate review by the Information Security Management Board (ISMB) to optimize, patch, or redesign the underlying control.