Valid until: 2025-04-10
Classification: Low
3.0 | Edward Robinson | Additions/changes as part of the periodic review and improvement. Added links for data breach procedure and contingency procedure. Added the use of the alerting banner on top of mydre.org. Replaced (C)ST with Research Support. |
In the interest of all the stakeholders, the top management of anDREa B.V. (hereafter called anDREa) is actively committed to demonstrably maintain and continually improve an information management system in accordance with the requirements of the ISO 27001:2017.
The purpose of this document is to describe the incident management procedure of anDREa and the associated controls, checks and administrations.
This document will be reviewed at least annually and when significant change happens.
The objectives of this control are:
To ensure a consistent and effective approach to the management of information security incidents, including communication on security events and weaknesses (A.16.1).
The scope of this document corresponds to Clause 4 Context of the organisation.
This document is:
required reading for:
all employees and contractors of anDREa.
available for all interested parties as appropriate.
Related procedures
Communication
At every step and as frequent as required updates and findings will be communicated to relevant stakeholders.
Public/generic communication takes place via the alerts banner which will also be displayed at the login screen of mydre.org.
Direct communication when called for will take place through the suitable media such as e-mail and phone.
Detailed description
Report request, an issue, or finding:
How you can report security-related events:
Administrations
Relevant security-related tickets.
Relevant PBIs.