Skip to main content
Review and revision metadata
Review Date: 2026-08-18
Reviewer: Director

previous version on gdrive

4.1 Understanding the organisation and its context

anDREa identifies and monitors internal and external issues that affect its ability to achieve the intended outcomes of the ISMS. Given our dynamic operating environment, this context is reviewed annually. Significant changes trigger updates to both this document and the ISMS framework to ensure continuous alignment and compliance.

4.1.1 Core Activities & Functions

anDREa develops, maintains, and commercializes myDRE, a cloud-native Digital Research Environment (DRE)-as-a-Service / Secure Processing Environment (SPE) delivered via a shared-tenant model.

  • Primary Target Audience: Organizations requiring a secure, compliant environment to ingress, process, analyze, and egress sensitive data while collaborating seamlessly with internal and external peers.
  • Secondary Target Audience: Research consortia, multi-institutional projects, and independent researchers requiring robust collaboration capabilities without the need for an enterprise-managed control plane.

Federated Projects & Local Sub-Scopes

To support specialized research workflows and technical innovations without compromising core platform governance, anDREa operates an Umbrella Governance Framework. Under this framework, specific projects, platform extensions, and auxiliary services function as autonomous technical enclaves.

While these enclaves inherit anDREa’s overarching ISMS corporate governance, legal frameworks, and physical/HR controls, they operate their own localized Statements of Applicability (SoA) Addenda, Risk Registers, and technical controls tailored to their specific technical boundaries.

The current inventory of sub-scoped projects and delegated operational enclaves operating under the anDREa ISMS umbrella includes:

  • Data Request Portal (DRP) Enclave: Autonomous Data Request Handling as a Service (DRHaaS) orchestration layer operating its own dedicated Entra ID tenant, Azure Subscription, and Secure SDLC pipeline under ISO 27001:2023 and NIS2 SC-30. (DRP ISMS)

Operations and Infrastructure

andrea organogram

anDREa operates as a remote-first scale-up. Governance, roles, and organizational accountability are defined in:


We maintain no physical IT infrastructure. All operations rely entirely on enterprise cloud services:

  • Microsoft Azure: Core infrastructure and platform hosting.
  • Google Workspace: Internal documentation, collaboration, and records management.
  • Zoho: Customer support ticketing, help sites, and public documentation hosting.

4.1.2 Internal Issues

The primary internal factors influencing anDREa’s security posture include:

  • Resource Constraints: Operating as a scale-up requires strict prioritization of security and operational resources while maintaining break-even.
  • Governance Obligations: Accountable to our founding university medical centers: Radboudumc, Erasmus MC, and UMC Utrecht.
  • Decentralized Workforce: A comprehensive work-from-home policy means anDREa has no physical oversight of employees' immediate working environments or localized physical security risks.

4.1.3 External Issues (PESTLE Analysis)

External issues fall within our defined Boundaries of Reasonable Preparedness and serve as direct inputs for our risk assessment process.

Political & Sovereign Risks

  • Geopolitical Cloud Dependencies: Core reliance on US-owned infrastructure (Microsoft Azure, Google Workspace) amidst evolving European data sovereignty sentiments.
  • Healthcare Data Strategy: Political decisions surrounding the European Health Data Space (EHDS) and Health Data Access Bodies (HDAB/HDAB-NL).

Economic & Market Access

  • (Dutch) Academic Market Procurement: Decision making is characterized by lengthy, committee‑driven tender procedures and strict public‑sector compliance requirements, which slow market entry.

Social & Trust Factors

  • Stakeholder Confidence: Retaining institutional trust from key national research and healthcare networks, including umcnl, Health-RI, and AcZie and their stakeholders like patient advocacy organizations.

Technological & Supplier Dependencies

  • For a complete list, see the anDREa Supplier List.
  • Hyperscale Cloud Dependency (Microsoft Azure): Vulnerable to rapid paces of innovation, unexpected service retirements, localized cloud outages, scaling/onboarding new clients, and inherent vendor lock-in.
  • SaaS Dependency (Google Workspace): Operational vulnerability to service downtime and vendor lock-in.
  • Inherited Compliance: Security requirements and compliance baselines are frequently inherited directly from our customers' strict regulatory profiles.
  • Mandatory Baselines: Continuous compliance with the General Data Protection Regulation (GDPR), ISO/IEC 27001 is required, and other Legal Requirements
  • Evolving Frameworks: Monitoring the regulatory timeline for mandatory EHDS compliance and Other Frameworks.
  • NIS 2 Stance: While anDREa falls below the mandatory NIS 2 thresholds (<100 employees and <€10M turnover), institutional clients require NIS 2 alignment.
  • Target Standards: Ongoing alignment with ISO 9001, SOC 2, and NIST guidelines based on market preferences.

Environmental Sustainability

  • Carbon Reduction: Remote-first operations, minimized physical infrastructure, and green travel policies (bike/public transport) reduce our corporate CO2 footprint.
  • Digital Substitution: myDRE acts as a virtual office space, reducing the need for customer and partner travel (including aviation).
  • Efficiency Measures: Automated workload management within myDRE workspaces reduces idle compute time, lowering cloud energy consumption.
  • Paperless Mandate: anDREa operates 99% paperless; physical printing is prohibited unless legally or explicitly required.
  • Re-use: ICT hardware that is no longer suitable for anDREa’s operational or security requirements, but remains technically sound, is securely data‑wiped and then donated, sold, or otherwise transferred to trusted organizations for continued use, reducing e‑waste and embodied emissions while maintaining full data protection.