Management review procedure
A quarterly, dated, written record that the security program's evidence was examined and what was decided, committed to the repository for a tamper-evident timestamp. The first review completed on 26 July 2026 — the ISMS go-live date.
What this policy commits us to
- Quarterly cadence — deliberately more frequent than the ISO annual minimum — plus a review after any significant incident or material change.
- 'A measure not taken is a finding' is an explicit rule of the standing agenda.
- A standing item verifies the automated controls actually executed recently, added after a silent CI outage was discovered.
- Honest limitation stated: a sole-operator review provides discipline and a verifiable record, not independence.
Controls mapped to this policy
Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.
Standards mappings
Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.
ISO/IEC 27001:2022InfoSec complianceSelf-assessed
A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.
- 9.3Management review
- 10.2Nonconformity and corrective action
- 7.5Documented information
- 9.1Monitoring, measurement, analysis, evaluation
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.