Management Review Procedure¶
Purpose. Ensures top management regularly reviews the ISMS so it stays suitable, adequate and effective, and that decisions on improvement and resources are recorded (ISO/IEC 27001 clause 9.3).
1. Scope¶
The management review of Soon's entire ISMS. This is a single procedure — Soon does not run separate quarterly and annual review tracks; one review covers all inputs, held at least annually.
2. Procedure¶
2.1 Cadence and relationship to the weekly ISMS meeting¶
- The management review is held at least annually, and additionally when a significant change warrants it (major incident, certification audit, major organisational or platform change).
- The weekly ISMS meeting (Thursdays 13:00 CEST) is the operational cadence: it tracks actions, risks and progress week to week and feeds its open items and trends into the management review. It does not replace the formal review.
2.2 Attendees¶
The review is attended by top management and the security responsible
(Olaf Jacobson). The external consultant (Andrea Cardinali) prepares
materials and may attend. TODO(owner): confirm attendees — who constitutes
top management at Soon? The review is chaired by top management or a
nominated deputy.
2.3 Preparation¶
The security responsible, supported by the consultant, prepares and distributes before the meeting:
- status of actions from the previous review;
- the current risk register and Risk Treatment Plan status;
- internal/external audit results and nonconformity status;
- monitoring and measurement results (Sentry, CloudWatch, security metrics);
- progress against the Information Security Objectives & Plan;
- the current REGISTER.md document status and Statement of Applicability.
2.4 Inputs (ISO/IEC 27001 9.3.2 checklist)¶
The agenda must cover:
- Status of actions from previous management reviews
- Changes in external and internal issues relevant to the ISMS
- Changes in needs and expectations of interested parties (customers, regulators, suppliers)
- Nonconformities and corrective actions
- Monitoring and measurement results
- Audit results
- Fulfilment of information security objectives
- Feedback from interested parties
- Results of risk assessment and status of the risk treatment plan
- Opportunities for continual improvement
2.5 Outputs (ISO/IEC 27001 9.3.3 checklist)¶
The minutes must record decisions on:
- Opportunities for continual improvement
- Any needed changes to the ISMS (scope, policy, objectives, resources, risk acceptance)
- Actions, each with an owner and target date
2.6 Records¶
Every review is minuted. Minutes are classified Confidential, stored at
TODO(owner): confirm storage location for management review minutes, and
retained as ISMS records. Actions are tracked to completion via the weekly
ISMS meeting.
3. Roles & responsibilities¶
- Top management — chairs the review, makes resource and risk-acceptance
decisions, owns the outcome.
TODO(owner): confirm named chair. - Security responsible (Olaf Jacobson) — prepares inputs, presents ISMS status, tracks resulting actions.
- External consultant (Andrea Cardinali) — compiles materials and drafts minutes.
4. Related documents¶
- docs/06-planning/isms6-infosec-objectives-plan.md — Information Security Objectives & Plan
- docs/06-planning/ISMS-DOC-06-2-risk-assessment-and-treatment-process.md — Risk Assessment and Treatment Process
- docs/06-planning/risk-treatment-plan.md — Risk Treatment Plan
- REGISTER.md — document register and status
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2025-06-07 | Olaf Jacobson | First draft document |
| 0.2 | 2026-07-18 | Andrea Cardinali | Rewritten lean and Soon-specific (ISMS overhaul); merged quarterly/annual structures into one procedure |