Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.27 Learning from Information Security Incidents

Control Objective

Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.

Policy Statement

anDREa systematically analyzes security incidents to identify root causes, detect trends, and continuously improve its security posture. Lessons learned are directly integrated into our risk management framework, policy updates, and employee security awareness programs to minimize the likelihood of recurrence.


Incident Analysis and Continuous Improvement

  • Trend Detection: All security tickets are categorized using specific descriptive tags. These tags are monitored to identify systemic vulnerabilities, technical anomalies, or emerging threat patterns (see: Issues and Risk Logging).
  • Governance and Reporting: Identified trends are formally reported and reviewed during ISMB - Meeting Notes and included in Chief Technology Officer (CTO) reports (see: Management Reports).
  • Targeted Mitigation: Trend data directly informs strategic security adjustments, including the design of targeted training campaigns, workshops (e.g., anti-phishing simulations), and technical control enhancements.