Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-22_Managementbewertung-und-Kennzahlen.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

78 lines
3.9 KiB
Markdown

# Management Review & Metrics
| Document information | Value |
|-----------------------|------|
| Document type | Procedure instruction (VA-22) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Process owner | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
<!-- FULFILLS 9.1-1, 9.3-1 | POLICY R03 -->
## 1. Purpose
This procedure governs how information security performance is measured and evaluated and how top management reviews the ISMS at planned intervals. It elaborates the corresponding policy ({{LINK:R03}}).
## 2. Scope
Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) to all information security metrics and to the management review of the ISMS.
## 3. Trigger
Measurement interval of the respective metric, date of the management review (BL-GOV-02), significant changes within the scope, severe incident.
## 4. Inputs
- Metrics sheet with target values and owners ({{TOOL_NAME}})
- Audit results and open findings ({{LINK:VA-15}})
- Nonconformities and corrective actions ({{LINK:VA-21}})
- Risk assessment and status of the risk treatment plan ({{LINK:VA-09}})
- Incidents and reporting obligations ({{LINK:VA-01}})
- Feedback from interested parties
## 5. Process
1. **Define metrics:** for each metric determine what is measured, by which method and data source, at which interval, who measures, when it is analysed and who analyses it.
2. **Measure:** collect the values at the defined interval and record them in {{TOOL_NAME}}.
3. **Analyse:** evaluate the results against the target values and form trends; a deviation from the target value raises a nonconformity ({{LINK:VA-21}}).
4. **Prepare the management review:** compile the inputs — status of actions from previous reviews, changes in relevant internal and external issues and in the requirements of interested parties, feedback on information security performance, feedback from interested parties, results of the risk assessment, opportunities for improvement.
5. **Conduct the review:** {{ROLE_MANAGEMENT}} reviews the ISMS at the interval {{MGMT_REVIEW_CYCLE}} against the fixed agenda (BL-GOV-02).
6. **Take decisions:** decisions on opportunities for improvement and on any need to change the ISMS, each with a responsible role and a due date.
7. **Record and follow up:** retain the minutes in {{TOOL_NAME}}; track the decisions through to completion.
## 6. RACI
| # | Step | R (execution) | A (accountable) | C (consulted) | I (informed) |
|---|------|---------------|-----------------|---------------|--------------|
| 1 | Define metrics | {{ROLE_ISB}} | {{ROLE_MANAGEMENT}} | {{ROLE_IT_LEAD}} | Business units |
| 2 | Measure | Metric owner | {{ROLE_ISB}} | - | - |
| 3 | Analyse | {{ROLE_ISB}} | {{ROLE_ISB}} | Business unit | - |
| 4 | Prepare the review | {{ROLE_ISB}} | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | - |
| 5 | Conduct the review | {{ROLE_MANAGEMENT}} | {{ROLE_MANAGEMENT}} | {{ROLE_ISB}} | Business units |
| 6 | Take decisions | {{ROLE_MANAGEMENT}} | {{ROLE_MANAGEMENT}} | {{ROLE_ISB}} | - |
| 7 | Record and follow up | {{ROLE_ISB}} | {{ROLE_ISB}} | - | {{ROLE_MANAGEMENT}} |
## 7. Result & evidence
A maintained metrics sheet with measured values per period and minutes of the management review with decisions, owners and due dates. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).
## 8. Key performance indicators (KPI)
- Share of metrics actually collected at the defined interval
- Share of metrics within their target value
- On-time completion of decisions from the management review
## 9. Related documents
- Corresponding policy: {{LINK:R03}}
- Nonconformities and corrective actions: {{LINK:VA-21}}
- Internal audits: {{LINK:VA-15}}
- Risk management procedure: {{LINK:VA-09}}
- Technical security baseline: {{LINK:BASELINE}}
<!-- Fulfils the requirements listed under FULFILLS above; coupling in mapping-iso.json. Not visible in reading mode. -->