ISO 27001 external audit with only one observation!

ISO 27001 external audit with only one observation!

At anDREa BV we do take Information Security seriously. But is a 100% score with one observation good enough?

Publicly we go nearly the full Monty with our Information Security Management System (ISMS) for ISO 27001. Our certificate, our statement-of-applicability, all relevant clauses and policies, pentest results, etc are for all to see, including the results:

https://support.mydre.org/portal/en/kb/articles/andrea-public-management-reports

Trust = describe how you do things (our ISMS) and demonstrate that you do it (audits, reports)


The only thing that is not publicly accessible are the underlying records and details of some reports. However, our clients can request to see the underacted versions as make use of the standing invitation to directly observe the internal and external audits. I.e. we go the full Monty and for good reason.


From time to time researchers need to answer questions related to ISO 27001 for grant applications, in their collaborations, and from internal auditors. Questions like: what is the access policy, our answer, imagine that the answer is just a link to https://support.mydre.org/portal/en/kb/articles/a-9-access-control-27-12-2022. Does this unburden the researchers? Does this help them to have and create trust with their stakeholders?


#ISO27001 #myDRE #anDREa #trust #unburden #SPE #TPE #DRE

要查看或添加评论,请登录

Stefan van Aalst的更多文章

  • Interesting Parliamentary Debate on Healthcare Data Security: Implications for Research Collaboration

    Interesting Parliamentary Debate on Healthcare Data Security: Implications for Research Collaboration

    Today, the Dutch Parliament held a thoughtful debate on Healthcare & Health, focusing on the security of national…

  • RSU Research Week 2025 - March 25th

    RSU Research Week 2025 - March 25th

    I am delighted having participated at RSU Research Week in Riga. Interesting presentations by Microsoft.

  • Can your TPE/SPE do this? - Access Review

    Can your TPE/SPE do this? - Access Review

    Access Reviews are an essential part of any organization's risk mitigation strategy, especially from both privacy and…

  • Insights in myDRE usage

    Insights in myDRE usage

    Academic Research is not a black-and-white story, it is not even gray, it is a full color spectrum in both what they do…

    1 条评论
  • ?? Empowering Users Through AI: A Weekend Project Journey

    ?? Empowering Users Through AI: A Weekend Project Journey

    In our fast-paced tech landscape, staying hands-on with emerging technologies isn't just about keeping current—it's…

  • Why Public Cloud Over Private Cloud?

    Why Public Cloud Over Private Cloud?

    Context At anDREa, we specialize in Trusted Processing Environments for health data, mainly serving academic…

    3 条评论
  • AI and Health Data

    AI and Health Data

    During the HDAB-NL meeting on September 3rd the AI-act (https://digital-strategy.ec.

    1 条评论
  • EHDS, HDAB-NL, blooming heather - a reflection

    EHDS, HDAB-NL, blooming heather - a reflection

    Last Sunday I was biking over the Hilversumse heide and was able to take the above picture. It triggered a reflection…

    1 条评论
  • LLMs and GPTs in Research - Cloud, Local or ...?

    LLMs and GPTs in Research - Cloud, Local or ...?

    How were you doing your work a year ago? How are you doing your work today? I personally was playing a bit with GPTs…

    1 条评论
  • XNAT & SPEs/TPEs

    XNAT & SPEs/TPEs

    In the field of secondary use of health data, XNAT-servers play an important role for some researchers. The…

社区洞察

其他会员也浏览了