Management review record #
Effective date: 2026-09-23 Last reviewed: 2026-09-23 Next review: 2027-09-23 Owner: Yaroslav Shmarov, operator Version: 1.0
Clause 9.3 of ISO/IEC 27001:2022 requires that top management review the information security management system at planned intervals, against a defined list of inputs, and record the decisions that follow. This page is that record.
Current position. One review has been conducted, in September 2026. No reportable security incident occurred in the period, and the management system was found suitable and adequate for the Service. Two risks were re-assessed to a worse residual position during the period, which is recorded at input (f) below. Five decisions were taken; the principal one is to commission an independent external security review.
The review is conducted by the operator as top management, against evidence the same operator produced. The independence limit set out on the internal audit record applies here too.
Review 2026-09 — first review #
Conducted: 2026-09-23 · Period under review: 2026-05-21 (ISMS established) to 2026-09-23 · Conducted by: Yaroslav Shmarov, operator, as top management
Inputs considered #
| Clause 9.3 input | Position |
|---|---|
| (a) Status of actions from previous reviews | None. This is the first management review; there is no prior action list to carry forward. Establishing the baseline is the principal output |
| (b) Changes in external and internal issues | One sub-processor removed in the period (Crisp, in-app support chat, removed 2026-07-25 and replaced with self-hosted chat, reducing the number of parties with access to handler communications). No sub-processor added. The regulatory context is unchanged in substance: Directive 2019/1937 transpositions continue to evolve at Member-State level, which is carried as risk register R-10 rather than as a change requiring re-architecture |
| (c) Changes in the needs and expectations of interested parties | No change was recorded in the period. Controller expectations are expressed during procurement review, but they are not captured as a tracked input to this review, so this row reports the absence of a record rather than an absence of change — the practical consequence of OFI-02. Independent assurance is the expectation the ISMS itself identifies as unmet, at A.5.35 and Clause 9.2 |
| (d) Feedback on information security performance | See the four sub-rows below |
| — Findings and corrective actions | Six findings raised at the 2026-09 internal audit , all corrected before the audit closed. All six were documentation defects — claims that were incomplete, misclassified, or understated relative to what the system does. None was a control failure |
| — Monitoring and measurement results | No reportable security incident occurred in the period; the incident register has no entries. The production check set ran continuously, covering the presence of the append-only audit triggers on the deployed database, backup freshness, and completion of the GDPR retention, deadline and inactivity-close jobs. Five rounds of first-party security testing were performed between 2026-05-26 and 2026-08-27; the material finding — forwarding headers trusted on a directly internet-facing origin, which would have allowed per-IP rate limits to be bypassed — was fixed the same day |
| — Audit results | Internal audit 2026-09 : no control failures, six findings corrected, three opportunities for improvement left open. The audit could not satisfy the impartiality requirement of Clause 9.2 |
| — Fulfilment of objectives | Not concludable for this period. The three objectives in IS policy §3 carried no measure or target until this review cycle made them measurable (audit finding NC-05), so there is no baseline to conclude against. Availability is the exception: it has been measured against the published 99.5% monthly target throughout, per SLA#measurement . The next review is the first that can report on all three |
| (e) Feedback from interested parties | No material security event reached the incident register , which remains empty. Traffic to the responsible disclosure inbox and controller correspondence under the DPA are not counted as a measured input, so nothing is claimed about them here. Establishing that count is folded into OFI-02 |
| (f) Results of risk assessment and status of treatment | The risk register was reviewed on 2026-09-05. Ten risks are assessed: three In treatment (operator incapacity, provider outage, sub-processor chain), three Monitored, four Accepted including one accepted by design. Two risks moved to a worse residual position during the period: R-02 (provider outage) and R-03 (sub-processor chain) were re-assessed from Accepted to In treatment on 2026-09-13, after assurances about the supplier chain and backup encryption that had been carried as settled were found to be unverified. No new risk category entered the register |
| (g) Opportunities for continual improvement | The three opportunities recorded at the internal audit: a consolidated risk treatment plan with dates (OFI-01), a single view of interested parties (OFI-02), and a defined schedule for analysing monitoring data as distinct from collecting it (OFI-03) |
Conclusions #
- The ISMS is suitable and adequate for the Service, and its open items are structural rather than operational. Every finding this period was a documentation defect. None was a control that failed, and one — the restore-drill cadence — was a control operating more often than the documents claimed. Documentation is what a customer relies on, so the gap between the two is worth closing on the cadence the audit programme now sets.
- Re-assessing R-02 and R-03 downward is the register working, not failing. Both had been accepted on assurances that a closer look did not support. A register that only ever improves is a register nobody is testing. The corollary is that the accepted positions still carrying inherited assurance — rather than verified evidence — are the ones most likely to move next.
- The binding constraint is independence, not controls. The largest open items on the ISMS — A.5.35, Clause 9.2, and the recurring procurement ask at (c) — are the same item. No further self-assessment closes any of them. Adding controls would not change the answer; commissioning an independent review would.
- The second constraint is the single-operator structure, which holds Clause 7.1 (resources) at Partial and makes an impartial internal audit impossible. It is disclosed on Trust and carried as risk register R-01 .
- The objectives carried no measures, so performance against them could not be concluded. Corrected for the next cycle: each now has a target and a source. This is the finding with the longest tail, because it is what makes every future review capable of a conclusion.
Decisions and actions #
| Ref | Decision | Owner | Target |
|---|---|---|---|
| MR-01 | Commission an independent external security review. It is the single action that closes A.5.35, moves Clause 9.2 off Partial, and answers the recurring procurement question. Scope, date and remediation summary to be published on Trust when performed | Operator | 2027-06-30 (TP-05) |
| MR-02 | Give each In treatment risk a dated completion target, closing OFI-01 and moving Clauses 6.1.3 and 8.3 off Partial | Operator | Done 2026-09-23 — treatment plan , five dated items |
| MR-03 | Report each of the three objectives against its measure at the next management review, now that targets exist | Operator | 2027-09 review |
| MR-04 | No change to the ISMS scope, the information security policy’s substance, or the resourcing position. The scope at IS policy §2 remains correct for the Service, and the resourcing constraint is disclosed rather than resolvable at present | Operator | — |
| MR-05 | OFI-02 and OFI-03 accepted as open with no action this cycle. Both are presentational, and MR-01 takes priority over either | Operator | Reconsider at 2027-09 review |
Accredited certification remains unpursued, and this review did not change that. Certification follows from the independence decision at MR-01; the certification status page carries the current position in the meantime.
Document control #
| Field | Value |
|---|---|
| Document title | EthicsPortal Management Review Record |
| Version | 1.0 |
| Effective date | 2026-09-23 |
| Last reviewed | 2026-09-23 |
| Next scheduled review | 2027-09-23 |
| Review trigger (interim) | A material security incident; an audit finding that cannot be corrected within the audit that raised it; a change to the ISMS scope |
| Owner | Yaroslav Shmarov, operator |
| Distribution | Published on ethicsportal.eu/policies/ |
Signed: Yaroslav Shmarov, on behalf of EthicsPortal — 2026-09-23.
Last updated: