Audit Planning
1. Multi-Year Audit Strategy and Strategic Alignment
The internal audit program serves as a primary governance mechanism to verify that information security controls are implemented, operating as intended, and effectively mitigating identified risks. This strategy enables the proactive identification of control deficiencies and continuous improvement opportunities prior to external certification cycles or regulatory oversight reviews.
1.1 Regulatory Integration Framework
To address the evolving European regulatory landscape, the audit strategy explicitly integrates standard ISO/IEC 27001:2023 requirements with (upcoming) statutory mandates:
- EU NIS 2 Directive: Focused heavily on supply chain integrity, governance, and rapid incident notification metrics.
- European Health Data Space (EHDS): Emphasizing strict data handling, cross-border privacy boundaries, and healthcare-specific data sovereignty.
Regulatory Presumption of Impact: Because NIS 2 and EHDS requirements inherently impact the anDREa ISMS, all controls are presumed to be fully within the audit scope. This table must be formally updated bi-annually by the Management Team to narrow down specific clauses as technical standards mature. If specific impacts are not yet explicitly defined by regulators, the default audit stance assumes all systems, processes, and controls are subject to thorough evaluation.
2. Resource Allocation Plan & Audit Ledger (2025–2028)
The following multi-year matrix establishes the mandatory audit coverage across the anDREa ISMS framework, tracking standard norm elements, core Key Performance Indicators (KPIs), and specialized regulatory focus areas.
| Norm Element / Control Area | 2025 | 2026 (KPI / NIS 2 / EHDS Focus) | 2027 (NIS 2 / EHDS Focus) | 2028 (NIS 2 / EHDS Focus) |
|---|---|---|---|---|
| ISMS Clauses 4 through 10 (Main Body) | ||||
| Preceding Audit Remediations (Internal & External) | ||||
| Control Domain A.5: Organizational Controls | ||||
| Control Domain A.6: People Controls | ||||
| Control Domain A.7: Physical Controls | ||||
| Control Domain A.8: Technological Controls | ||||
| KPIs (Specifically Effectiveness Logging) | ||||
| NIS 2 / EHDS-Specific Controls & Reporting |
3. Operational Implementation Guidelines
3.1 Advanced KPI Validation
Beginning in the 2026 audit cycle, targeted focus must be directed toward Key Performance Indicators. Internal auditors must formally validate:
- Auditability: Assessing the completeness, tamper-resistance, and retention of system event logging infrastructure.
- Metrics Verification: Verifying that logging configurations provide sufficient forensic visibility to detect, isolate, and reconstruct potential security incidents.
3.2 Target Focus Areas (2026 Onward)
All internal audit assessments executed from 2026 onward must explicitly evaluate the following technical and operational control perimeters for strict NIS 2 and EHDS compliance:
- Data Handling & Sovereignty: Auditing cryptographic controls, pseudonymization techniques, and access boundaries within the myDRE platform to ensure safe processing of health-related datasets.
- Incident Response & Communication Channels: Testing the organization’s capability to execute early warning notifications and formal incident reports within the statutory 24-hour and 72-hour regulatory windows mandated under NIS 2.
- Supplier Risk Management: Reviewing the security posture of upstream cloud infrastructure providers and third-party software vendors to prevent supply chain contamination and secure the anDREa operational perimeter.