4.2 Understanding the needs and expectations of interested parties
anDREa identifies the internal and external interested parties relevant to the ISMS and determines their security, operational, and regulatory requirements. This section outlines these parties, their core expectations, and the framework elements or supporting documents used to address them.
Currently, no interested parties have established or communicated specific environmental requirements regarding our ISMS.
| Interested Party | Requirement Summary | Addressing Framework / Supporting Document |
|---|---|---|
| Advisory Board (Radboudumc, Erasmus MC, UMC Utrecht) | • Scalable, secure, and cost-effective solutions for institutional employees. • Multi-tenant scalability for organizations handling secondary use of health data to optimize per-tenant costs. | • Corporate Strategy Documents • ISMS Platform Governance |
| Suppliers | • Adherence to agreed payment schedules and commercial contract terms. | • Procurement and Finance Procedures |
| Customers & Collaboration Partners | • Execution of data Confidentiality, Integrity, and Availability controls based on CIA (BIV) classifications. • Provision of robust business continuity and disaster recovery capabilities. • Verification of established technical and organizational security controls. | • ISMS Policy Framework • ISO/IEC 27001 Certification • Contingency Plans & Disaster Recovery Plan |
| Customer User Groups | • Functional usability, accessibility, and uptime of the myDRE workspaces. | • Service Level Agreement • Roadmap |
| Regulatory Bodies (e.g., Autoriteit Persoonsgegevens, HDAB-NL) | • Full compliance with statutory data privacy and security regulations. • Formal, documented response protocols for security incidents and data breaches. | • GDPR Compliance Assessment • Data Breach Procedure • ISO 27001 & NIS 2 |
| Employees & Contractors | • A safe, inclusive, collaborative, and rewarding work environment focused on delivering societal value. | • HR Policies • Employee Code of Conduct |
| Natural Individuals (Patients, study participants) | • Lawful, ethical, and secure processing of personal and sensitive healthcare data. | • GDPR Compliance Assessment • Data Breach Procedure • myDRE Highlevel Architecture |