Skip to main content
Review and revision metadata
Review Date: 2026-06-17
Reviewer: Director

Statement of Applicability

Trust Through Transparency

Driven and actively governed by anDREa's Information Security Strategy, this Statement of Applicability (SoA) provides a clear overview of how we protect our organization and services for you.

By mapping our specific security controls—which are an integral part of how we work—directly to ISO 27001 and NIS2 SC-30 standards, we turn complex regulatory requirements into practical, everyday defenses.

Control ID Name Status
A.05.00A.5 Organisational ControlsImplemented
A.05.01Policies for information securityImplemented
A.05.02Information security roles and responsibilitiesImplemented
A.05.03Segregation of dutiesImplemented
A.05.04Management responsibilitiesImplemented
A.05.05Contact with authoritiesImplemented
A.05.06Contact with special interest groupsImplemented
A.05.07Threat intelligenceImplemented
A.05.08Information security in project managementWIP
A.05.09Inventory of information and other associated assetsImplemented
A.05.10Acceptable use of information and other associated assetsImplemented
A.05.11Return of assetsImplemented
A.05.12Classification of informationImplemented
A.05.13Labelling of informationImplemented
A.05.14Information transferImplemented
A.05.15Access controlImplemented
A.05.16Identity managementImplemented
A.05.17Authentication informationImplemented
A.05.18Access rightsImplemented
A.05.19Information security in supplier relationshipsImplemented
A.05.20Addressing information security within supplier agreementsImplemented
A.05.21Managing information security in the information and communication technology (ICT) supply chainImplemented
A.05.22Monitoring, review and change management of supplier servicesImplemented
A.05.23Information security for use of cloud servicesImplemented
A.05.24Information security incident management planning and preparationImplemented
A.05.25Assessment and decision on information security eventsImplemented
A.05.26Response to information security incidentsImplemented
A.05.27Learning from information security incidentsImplemented
A.05.28Collection of evidenceImplemented
A.05.29Information security during disruptionImplemented
A.05.30ICT readiness for business continuityImplemented
A.05.31Legal, statutory, regulatory and contractual requirementsImplemented
A.05.32Intellectual property rightsImplemented
A.05.33Protection of recordsImplemented
A.05.34Privacy and protection of personal identifiable information (PII)Implemented
A.05.35Independent review of information securityImplemented
A.05.36Compliance with policies, rules and standards for information securityImplemented
A.05.37Documented operating proceduresImplemented
A.06.00A.6 Organisational Controls
A.06.01ScreeningImplemented
A.06.02Terms and conditions of employmentImplemented
A.06.03Information security awareness, education and trainingImplemented
A.06.04Disciplinary processImplemented
A.06.05Responsibilities after termination or change of employmentImplemented
A.06.06Confidentiality or non-disclosure agreementsImplemented
A.06.07Remote workingImplemented
A.06.08Information security event reportingImplemented
A.07.00A.7 Physical Controls
A.07.01Physical security perimetersN/A
A.07.02Physical entryN/A
A.07.03Securing offices, rooms and facilitiesN/A
A.07.04Physical security monitoringN/A
A.07.05Protecting against physical and environmental threatsN/A
A.07.06Working in secure areasN/A
A.07.07Clear desk and clear screenImplemented
A.07.08Equipment siting and protectionN/A
A.07.09Security of assets off-premisesImplemented
A.07.10Storage mediaImplemented
A.07.11Supporting utilitiesN/A
A.07.12Cabling securityN/A
A.07.13Equipment maintenanceImplemented
A.07.14Secure disposal or re-use of equipmentImplemented
A.08.00A.8 Technological Controls
A.08.01User end point devicesImplemented
A.08.02Privileged access rightsImplemented
A.08.03Information access restrictionImplemented
A.08.04Access to source codeImplemented
A.08.05Secure authenticationImplemented
A.08.06Capacity managementImplemented
A.08.07Protection against malwareImplemented
A.08.08Management of technical vulnerabilitiesImplemented
A.08.09Configuration managementImplemented
A.08.10Information deletionImplemented
A.08.11Data maskingN/A
A.08.12Data leakage preventionImplemented
A.08.13Information backupImplemented
A.08.14Redundancy of information processing facilitiesImplemented
A.08.15LoggingImplemented
A.08.16Monitoring activitiesImplemented
A.08.17Clock synchronizationImplemented
A.08.18Use of privileged utility programsImplemented
A.08.19Installation of software on operational systemsImplemented
A.08.20Networks securityImplemented
A.08.21Security of network servicesImplemented
A.08.22Segregation of networksImplemented
A.08.23Web filteringImplemented
A.08.24Use of cryptographyImplemented
A.08.25Secure development life cycleImplemented
A.08.26Application security requirementsImplemented
A.08.27Secure system architecture and engineering principlesImplemented
A.08.28Secure codingImplemented
A.08.29Security testing in development and acceptanceImplemented
A.08.30Outsourced developmentN/A
A.08.31Separation of development, test and production environmentsImplemented
A.08.32Change managementImplemented
A.08.33Test informationImplemented
A.08.34Protection of information systems during audit testingImplemented

ISO 27001 SoA Source - IsoSoa.json