Management Review Procedure

AegisGate Security, LLC ISMS management review procedure. Quarterly review of security posture, risks, and improvement opportunities.

Management Review Procedure

AegisGate Security, LLC

FieldValue
Document IDAG-MGTREV-2026-001
Version1.0
ClassificationConfidential — Internal Use
OwnerCompliance & Security Engineering
ApproverChief Executive Officer
Review CycleAnnual
Effective DateJuly 29, 2026
Next ReviewJuly 29, 2027

1. Purpose

This procedure establishes the requirements for conducting Management Reviews of the AegisGate Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 Clause 9.3. Management Reviews ensure that top leadership evaluates the ISMS’s continuing suitability, adequacy, and effectiveness, and drives continuous improvement through informed decision-making.

Management Reviews are the primary governance mechanism through which AegisGate leadership demonstrates commitment to information security and validates that the ISMS achieves its intended outcomes.


2. Scope

This procedure applies to:

  • All ISMS processes, controls, and supporting documentation
  • All information security objectives and their measurement
  • All risk assessment results and risk treatment plans
  • The ISO 27001 Statement of Applicability (AG-ISO27001-SoA-2026-001)
  • The Internal Audit Program (AG-IAUD-2026-001)
  • All personnel with responsibilities defined in the ISMS Policy (AG-ISMSPOL-2026-001)

3. Review Frequency

Management Reviews are conducted quarterly. The annual review cycle follows this schedule:

ReviewTarget PeriodWindow
Q1 ReviewJanuaryJanuary 1–31
Q2 ReviewAprilApril 1–30
Q3 ReviewJulyJuly 1–31
Q4 ReviewOctoberOctober 1–31

An extraordinary review is convened when any of the following occur:

  • A significant information security incident (Severity: Critical or High)
  • A material change to the ISMS scope
  • A regulatory or legal requirement change affecting information security
  • A significant change to the business context or risk profile
  • A request from top management

4. Review Inputs

Each Management Review receives the following inputs, prepared by Compliance & Security Engineering and distributed to attendees at least five business days before the review:

4.1 Internal Audit Results

  • Summary of internal audit findings per the Internal Audit Program (AG-IAUD-2026-001)
  • Status of corrective actions from previous audits
  • Trend analysis of audit findings over the previous four quarters

4.2 Compliance Assessment Results

  • ISO 27001 Statement of Applicability status update (implemented, partial, planned, N/A)
  • Compliance engine coverage metrics (857+ CheckFuncs across 27 frameworks)
  • Changes in regulatory or legal requirements affecting AegisGate

4.3 Risk Assessment Results

  • Updated risk register with current risk scores and treatment status
  • New risks identified during the quarter
  • Changes to existing risk ratings (increase or decrease)
  • Risk acceptance decisions and rationale

4.4 Information Security Performance

  • Progress against information security objectives (OBJ-01 through OBJ-08 per ISMS Policy)
  • Key performance indicators:
    • Platform availability metrics
    • Unauthorized access incidents
    • Vulnerability remediation timelines (Critical ≤ 48h, High ≤ 7d, Medium ≤ 30d)
    • Audit log integrity verification results
    • Training completion rates

4.5 Incident Reports

  • Information security incidents reported during the quarter
  • Severity classification and response timeline for each incident
  • Root cause analysis results
  • Status of corrective actions from incidents

4.6 Interested Party Feedback

  • Customer security inquiries and audit findings
  • Subprocessor security assessment results
  • Regulatory correspondence

4.7 Threat Intelligence

  • Emerging threats relevant to AegisGate’s risk profile
  • Threat intelligence feed updates (153+ detection patterns)
  • Industry threat advisories and vulnerability disclosures

4.8 Continuous Improvement Status

  • Status of improvement actions from previous Management Reviews
  • Continuous Improvement Roadmap progress
  • ISMS process effectiveness metrics

5. Review Outputs

Management Review outputs are documented decisions and actions addressing:

5.1 Required Outputs

OutputDescriptionDecision Authority
ISMS improvement opportunitiesIdentified improvements to ISMS processes, controls, or documentationChief Executive Officer
Changes to information security objectivesUpdated objectives based on performance data and business changesChief Executive Officer
Resource needsAllocation of additional resources for ISMS operation or improvementChief Executive Officer
Corrective action prioritiesPrioritized list of corrective actions from audit findings, incidents, or risk assessmentsCompliance & Security Engineering
Risk treatment updatesChanges to risk treatment plans based on new or changed risksCompliance & Security Engineering
Policy or procedure changesUpdates to ISMS policies or proceduresChief Executive Officer

5.2 Documentation

All Management Review outputs are recorded in:

  • Management Review minutes (formal record of discussion, decisions, and actions)
  • Action item tracker with assigned owners, deadlines, and status
  • Updated risk register (if risk treatment decisions changed)
  • Updated Statement of Applicability (if control status changed)

6. Agenda Template

Management Reviews follow this agenda structure. The facilitator may adjust time allocations based on review priority.

#Agenda ItemDescriptionTime AllocationResponsible
1Opening and attendanceConfirm quorum, note absences5 minChair
2Review of previous actionsStatus update on actions from previous Management Review15 minCompliance & Security Engineering
3Internal audit resultsFindings, corrective actions, trends15 minCompliance & Security Engineering
4Compliance assessmentISO 27001 SoA status, framework coverage, regulatory changes15 minCompliance & Security Engineering
5Risk assessment reviewRisk register updates, new risks, risk treatment status20 minCompliance & Security Engineering
6Information security performanceObjective achievement, KPIs, metrics15 minCompliance & Security Engineering
7Incident reportsIncidents, root causes, corrective actions, lessons learned15 minIncident Response Lead
8Interested party feedbackCustomer feedback, subprocessor assessments10 minCompliance & Security Engineering
9Threat intelligence updateEmerging threats, detection pattern updates10 minCompliance & Security Engineering
10Continuous improvementRoadmap progress, ISMS effectiveness10 minCompliance & Security Engineering
11Decisions and actionsPrioritize improvements, allocate resources, update objectives20 minChief Executive Officer
12Closing and next stepsConfirm action owners, schedule next review5 minChair
Total155 min

7. Attendees and Roles

7.1 Required Attendees

RoleResponsibility
Chief Executive OfficerChairs the review. Makes final decisions on ISMS direction, resource allocation, and objective changes. Approves Management Review minutes.
Compliance & Security Engineering LeadPrepares and presents review inputs. Provides subject-matter expertise on ISMS operations, risk assessments, and audit findings. Tracks action items.
Engineering Leadership RepresentativeProvides input on technical implementation status, resource needs, and engineering constraints.

7.2 Optional Attendees

RoleAttendance Trigger
Incident Response LeadWhen significant incidents occurred during the quarter
Human Resources RepresentativeWhen personnel security matters are on the agenda
Legal CounselWhen regulatory or legal matters are on the agenda
External AuditorWhen an external audit has been conducted during the quarter

7.3 Quorum

A Management Review is quorate when the Chief Executive Officer and Compliance & Security Engineering Lead are both present. If the CEO is unavailable, a delegate with written authority may attend.


8. Records and Evidence Retention

8.1 Records Maintained

RecordRetention PeriodStorageAccess Control
Management Review minutes7 yearsHash-chained audit log systemRestricted — ISMS personnel
Action item tracker7 yearsProject management systemRestricted — ISMS personnel
Risk register updates7 yearsHash-chained audit log systemRestricted — ISMS personnel
Updated Statement of Applicability7 yearsVersion-controlled documentationRestricted — ISMS personnel
Attendance records7 yearsHash-chained audit log systemRestricted — ISMS personnel
Supporting evidence (metrics, reports)7 yearsHash-chained audit log systemRestricted — ISMS personnel

8.2 Evidence Integrity

All Management Review records are stored in AegisGate’s hash-chained audit log system, ensuring:

  • Integrity: Cryptographic hash chains prevent undetected modification of records.
  • Authenticity: Records are attributable to their authors via authenticated access.
  • Availability: Records are available for internal and external audit at any time.
  • Retention: Records retained for a minimum of seven years per the ISMS records retention policy.

9. Escalation Procedures

9.1 Escalation Criteria

The following conditions require escalation beyond the standard Management Review:

ConditionEscalation PathTimeline
Critical information security incidentCEO immediate notification → Management Review extraordinary sessionWithin 4 hours
ISMS scope change requiring policy amendmentCEO approval → Policy revision → Management Review ratificationWithin 5 business days
Resource allocation disputeCEO final decision authorityWithin 5 business days
Risk acceptance above thresholdCEO formal acceptance requiredWithin 5 business days
Regulatory or legal compliance failureCEO notification → Legal counsel engagement → Management Review extraordinary sessionWithin 24 hours

9.2 Extraordinary Review Convening

An extraordinary Management Review is convened by the CEO or Compliance & Security Engineering Lead when escalation criteria are met. The extraordinary review follows the same agenda structure as a quarterly review, with focus on the triggering event.


10. Continuous Improvement

This procedure is subject to continuous improvement. At each Management Review, the effectiveness of the review process itself is evaluated:

  • Are review inputs complete, accurate, and timely?
  • Are review outputs actionable and tracked to completion?
  • Is the review frequency sufficient?
  • Are the right people attending?
  • Is the agenda structure effective?

Improvements to this procedure are documented in the Management Review minutes and implemented per the document control requirements in the ISMS Policy.


11. References

DocumentID
ISMS PolicyAG-ISMSPOL-2026-001
ISO 27001 Statement of ApplicabilityAG-ISO27001-SoA-2026-001
Internal Audit ProgramAG-IAUD-2026-001
ISO/IEC 27001:2022Clause 9.3 — Management review

This procedure is maintained per the ISMS document control requirements. Questions regarding this procedure should be directed to Compliance & Security Engineering at compliance@aegisgatesecurity.io.