Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.24 Objective assessment of the information security approach

Control Overview

This control mandates that the organization undergoes independent, objective assessments at scheduled intervals to verify that its cybersecurity program effectively meets the objectives defined in its information security policy. To ensure continuous operational compliance and prevent security decay, these reviews must evaluate the effectiveness of both day-to-day security controls and long-term business continuity plans. Any identified deficiencies or non-conformities must be reported directly to senior management, who are then obligated to authorize and enforce formalized corrective actions.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs the formal validation cycles of its entire compliance posture.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement relies on the performance evaluation and continuous improvement structures embedded within our ISO/IEC 27001-based ISMS, turning audits into proactive governance tools.

Rather than relying on self-assessments, anDREa maintains an unbroken, multi-tiered independent audit cycle managed under Clause 9 - Performance. Our assurance framework is split into two independent tracks: first, formal internal audits conducted by an objective, qualified external third party; and second, comprehensive certification audits performed by an accredited external certification body. All findings, recommendations, and minor deviations discovered during these programs are automatically tracked via our central security task overview, translated into formal corrective action plans, and directly integrated into senior management reviews to drive continuous improvement.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001Clause 9 - PerformanceEnforces the strategic requirement to measure, analyze, evaluate, and internally audit the entire effectiveness of the ISMS.
ISO/IEC 27001A.05.35 - Independent review of information securityMandates that the organization’s approach to managing information security and its implementation are reviewed independently.
Audit SchedulesAudit PlanningChronological audit plans detailing exact schedules, defined assessment criteria, and the scope of upcoming independent reviews.
Task ManagementPeriodic Security ControlsThe centralized tracking repository where audit findings are assigned owners, given completion deadlines, and verified post-remediation.
Governance OutputsPeriodic Controls MTDocumented executive sessions demonstrating that leadership formally reviews independent audit outcomes and signs off on required corrective actions.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Accredited external audit cycles, independent third-party internal audits, and automated corrective action tracking are fully active. Continuous Improvement: To ensure seamless future regulatory alignments, verify that all future internal and external audit scope statements explicitly list compliance with NIS 2 criteria alongside standard ISO/IEC 27001 parameters.