Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.35 Independent Review of Information Security

Control Objective

The organisation’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.”

Policy Statement

anDREa’s Information Security Management System (ISMS)—including our personnel practices, operational processes, and underlying technologies—is independently evaluated at planned intervals and upon significant platform changes. This dual-layered audit strategy ensures our technical controls continuously satisfy ISO/IEC 27001 standards and NIS 2 regulatory mandates.


Independent Audit Framework

Our evaluation model relies on two distinct layers of objective, third-party validation:

  • Internal Audits: Conducted at scheduled intervals by an independent third-party security firm. This comprehensive review assesses the operational effectiveness of our entire ISMS framework against both ISO/IEC 27001 requirements and NIS 2 compliance criteria (see Clause 9 - Performance).
  • External Audits: Executed annually by an accredited independent certifying body to maintain our formal security certifications. This process evaluates our overall security posture and includes mandatory technical validation via specialized third-party penetration testing.

Execution

  • Audit Tracking & Scheduling: The planning, execution deadlines, and remediation tracking for all internal and external audit findings are centrally governed within the Periodic Security Controls repository.
  • Access Control:
    • Management Reports are available at Management Reports
    • Full audit reports, evidence submittals, and corrective action plans are restricted to Authorized Personnel Only.