Management Review Procedure
AegisGate Security, LLC
| Field | Value |
|---|---|
| Document ID | AG-MGTREV-2026-001 |
| Version | 1.0 |
| Classification | Confidential — Internal Use |
| Owner | Compliance & Security Engineering |
| Approver | Chief Executive Officer |
| Review Cycle | Annual |
| Effective Date | July 29, 2026 |
| Next Review | July 29, 2027 |
1. Purpose
This procedure establishes the requirements for conducting Management Reviews of the AegisGate Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 Clause 9.3. Management Reviews ensure that top leadership evaluates the ISMS’s continuing suitability, adequacy, and effectiveness, and drives continuous improvement through informed decision-making.
Management Reviews are the primary governance mechanism through which AegisGate leadership demonstrates commitment to information security and validates that the ISMS achieves its intended outcomes.
2. Scope
This procedure applies to:
- All ISMS processes, controls, and supporting documentation
- All information security objectives and their measurement
- All risk assessment results and risk treatment plans
- The ISO 27001 Statement of Applicability (AG-ISO27001-SoA-2026-001)
- The Internal Audit Program (AG-IAUD-2026-001)
- All personnel with responsibilities defined in the ISMS Policy (AG-ISMSPOL-2026-001)
3. Review Frequency
Management Reviews are conducted quarterly. The annual review cycle follows this schedule:
| Review | Target Period | Window |
|---|---|---|
| Q1 Review | January | January 1–31 |
| Q2 Review | April | April 1–30 |
| Q3 Review | July | July 1–31 |
| Q4 Review | October | October 1–31 |
An extraordinary review is convened when any of the following occur:
- A significant information security incident (Severity: Critical or High)
- A material change to the ISMS scope
- A regulatory or legal requirement change affecting information security
- A significant change to the business context or risk profile
- A request from top management
4. Review Inputs
Each Management Review receives the following inputs, prepared by Compliance & Security Engineering and distributed to attendees at least five business days before the review:
4.1 Internal Audit Results
- Summary of internal audit findings per the Internal Audit Program (AG-IAUD-2026-001)
- Status of corrective actions from previous audits
- Trend analysis of audit findings over the previous four quarters
4.2 Compliance Assessment Results
- ISO 27001 Statement of Applicability status update (implemented, partial, planned, N/A)
- Compliance engine coverage metrics (857+ CheckFuncs across 27 frameworks)
- Changes in regulatory or legal requirements affecting AegisGate
4.3 Risk Assessment Results
- Updated risk register with current risk scores and treatment status
- New risks identified during the quarter
- Changes to existing risk ratings (increase or decrease)
- Risk acceptance decisions and rationale
4.4 Information Security Performance
- Progress against information security objectives (OBJ-01 through OBJ-08 per ISMS Policy)
- Key performance indicators:
- Platform availability metrics
- Unauthorized access incidents
- Vulnerability remediation timelines (Critical ≤ 48h, High ≤ 7d, Medium ≤ 30d)
- Audit log integrity verification results
- Training completion rates
4.5 Incident Reports
- Information security incidents reported during the quarter
- Severity classification and response timeline for each incident
- Root cause analysis results
- Status of corrective actions from incidents
4.6 Interested Party Feedback
- Customer security inquiries and audit findings
- Subprocessor security assessment results
- Regulatory correspondence
4.7 Threat Intelligence
- Emerging threats relevant to AegisGate’s risk profile
- Threat intelligence feed updates (153+ detection patterns)
- Industry threat advisories and vulnerability disclosures
4.8 Continuous Improvement Status
- Status of improvement actions from previous Management Reviews
- Continuous Improvement Roadmap progress
- ISMS process effectiveness metrics
5. Review Outputs
Management Review outputs are documented decisions and actions addressing:
5.1 Required Outputs
| Output | Description | Decision Authority |
|---|---|---|
| ISMS improvement opportunities | Identified improvements to ISMS processes, controls, or documentation | Chief Executive Officer |
| Changes to information security objectives | Updated objectives based on performance data and business changes | Chief Executive Officer |
| Resource needs | Allocation of additional resources for ISMS operation or improvement | Chief Executive Officer |
| Corrective action priorities | Prioritized list of corrective actions from audit findings, incidents, or risk assessments | Compliance & Security Engineering |
| Risk treatment updates | Changes to risk treatment plans based on new or changed risks | Compliance & Security Engineering |
| Policy or procedure changes | Updates to ISMS policies or procedures | Chief Executive Officer |
5.2 Documentation
All Management Review outputs are recorded in:
- Management Review minutes (formal record of discussion, decisions, and actions)
- Action item tracker with assigned owners, deadlines, and status
- Updated risk register (if risk treatment decisions changed)
- Updated Statement of Applicability (if control status changed)
6. Agenda Template
Management Reviews follow this agenda structure. The facilitator may adjust time allocations based on review priority.
| # | Agenda Item | Description | Time Allocation | Responsible |
|---|---|---|---|---|
| 1 | Opening and attendance | Confirm quorum, note absences | 5 min | Chair |
| 2 | Review of previous actions | Status update on actions from previous Management Review | 15 min | Compliance & Security Engineering |
| 3 | Internal audit results | Findings, corrective actions, trends | 15 min | Compliance & Security Engineering |
| 4 | Compliance assessment | ISO 27001 SoA status, framework coverage, regulatory changes | 15 min | Compliance & Security Engineering |
| 5 | Risk assessment review | Risk register updates, new risks, risk treatment status | 20 min | Compliance & Security Engineering |
| 6 | Information security performance | Objective achievement, KPIs, metrics | 15 min | Compliance & Security Engineering |
| 7 | Incident reports | Incidents, root causes, corrective actions, lessons learned | 15 min | Incident Response Lead |
| 8 | Interested party feedback | Customer feedback, subprocessor assessments | 10 min | Compliance & Security Engineering |
| 9 | Threat intelligence update | Emerging threats, detection pattern updates | 10 min | Compliance & Security Engineering |
| 10 | Continuous improvement | Roadmap progress, ISMS effectiveness | 10 min | Compliance & Security Engineering |
| 11 | Decisions and actions | Prioritize improvements, allocate resources, update objectives | 20 min | Chief Executive Officer |
| 12 | Closing and next steps | Confirm action owners, schedule next review | 5 min | Chair |
| — | Total | — | 155 min | — |
7. Attendees and Roles
7.1 Required Attendees
| Role | Responsibility |
|---|---|
| Chief Executive Officer | Chairs the review. Makes final decisions on ISMS direction, resource allocation, and objective changes. Approves Management Review minutes. |
| Compliance & Security Engineering Lead | Prepares and presents review inputs. Provides subject-matter expertise on ISMS operations, risk assessments, and audit findings. Tracks action items. |
| Engineering Leadership Representative | Provides input on technical implementation status, resource needs, and engineering constraints. |
7.2 Optional Attendees
| Role | Attendance Trigger |
|---|---|
| Incident Response Lead | When significant incidents occurred during the quarter |
| Human Resources Representative | When personnel security matters are on the agenda |
| Legal Counsel | When regulatory or legal matters are on the agenda |
| External Auditor | When an external audit has been conducted during the quarter |
7.3 Quorum
A Management Review is quorate when the Chief Executive Officer and Compliance & Security Engineering Lead are both present. If the CEO is unavailable, a delegate with written authority may attend.
8. Records and Evidence Retention
8.1 Records Maintained
| Record | Retention Period | Storage | Access Control |
|---|---|---|---|
| Management Review minutes | 7 years | Hash-chained audit log system | Restricted — ISMS personnel |
| Action item tracker | 7 years | Project management system | Restricted — ISMS personnel |
| Risk register updates | 7 years | Hash-chained audit log system | Restricted — ISMS personnel |
| Updated Statement of Applicability | 7 years | Version-controlled documentation | Restricted — ISMS personnel |
| Attendance records | 7 years | Hash-chained audit log system | Restricted — ISMS personnel |
| Supporting evidence (metrics, reports) | 7 years | Hash-chained audit log system | Restricted — ISMS personnel |
8.2 Evidence Integrity
All Management Review records are stored in AegisGate’s hash-chained audit log system, ensuring:
- Integrity: Cryptographic hash chains prevent undetected modification of records.
- Authenticity: Records are attributable to their authors via authenticated access.
- Availability: Records are available for internal and external audit at any time.
- Retention: Records retained for a minimum of seven years per the ISMS records retention policy.
9. Escalation Procedures
9.1 Escalation Criteria
The following conditions require escalation beyond the standard Management Review:
| Condition | Escalation Path | Timeline |
|---|---|---|
| Critical information security incident | CEO immediate notification → Management Review extraordinary session | Within 4 hours |
| ISMS scope change requiring policy amendment | CEO approval → Policy revision → Management Review ratification | Within 5 business days |
| Resource allocation dispute | CEO final decision authority | Within 5 business days |
| Risk acceptance above threshold | CEO formal acceptance required | Within 5 business days |
| Regulatory or legal compliance failure | CEO notification → Legal counsel engagement → Management Review extraordinary session | Within 24 hours |
9.2 Extraordinary Review Convening
An extraordinary Management Review is convened by the CEO or Compliance & Security Engineering Lead when escalation criteria are met. The extraordinary review follows the same agenda structure as a quarterly review, with focus on the triggering event.
10. Continuous Improvement
This procedure is subject to continuous improvement. At each Management Review, the effectiveness of the review process itself is evaluated:
- Are review inputs complete, accurate, and timely?
- Are review outputs actionable and tracked to completion?
- Is the review frequency sufficient?
- Are the right people attending?
- Is the agenda structure effective?
Improvements to this procedure are documented in the Management Review minutes and implemented per the document control requirements in the ISMS Policy.
11. References
| Document | ID |
|---|---|
| ISMS Policy | AG-ISMSPOL-2026-001 |
| ISO 27001 Statement of Applicability | AG-ISO27001-SoA-2026-001 |
| Internal Audit Program | AG-IAUD-2026-001 |
| ISO/IEC 27001:2022 | Clause 9.3 — Management review |
This procedure is maintained per the ISMS document control requirements. Questions regarding this procedure should be directed to Compliance & Security Engineering at compliance@aegisgatesecurity.io.