4.3 Scope of the Information Security Management System
anDREa determines the boundaries and applicability of the ISMS to establish its formal scope. In defining this scope, we account for the internal and external issues identified in Clause 4.1 - Understanding the organisation and its context, the stakeholder requirements detailed in Clause 4.2 - Understanding the needs and expectations of interested parties, and the operational dependencies and interfaces with external organizations.
4.3.1 Purpose of the ISMS
The purpose of the ISMS across its defined scope is to:
- Align information security policies and objectives with overarching organizational needs.
- Implement, operate, and monitor technical and organizational controls to manage information security risks and incidents.
- Routinely review the performance, adequacy, and operational effectiveness of established controls.
- Drive continual improvement of anDREa’s security posture based on objective, data-driven measurements.
4.3.2 Scope Definition
The scope of the ISMS encompasses all information security, data protection, and operational governance activities related to the development, maintenance, commercialization, and management of anDREa BV, its core product myDRE, and any services provided.
Scope: The development, implementation, operation, maintenance and valorisation of the anDREa Digital Research Environment by anDREa B.V., including the provision of deployment tooling and related support services that enable client organisations to deploy and operate workspaces within their own Microsoft Azure subscriptions.
1. Organizational Boundaries
The ISMS applies universally to all business units and operational functions of anDREa BV, including:
- All corporate governance, business operations, and remote-work environments ("office work").
- All cloud-native engineering, product design, and architectural management functions for the myDRE platform and other services.
2. Services In-Scope
The following services are managed under the ISMS framework:
- myDRE-as-a-Service: Delivered directly to enterprise organizations and independent consortia/users.
- Subscription Management: Provisioning, 24/7/365 monitoring, and administrative support of platform infrastructure.
- Patch & Lifecycle Management: Orchestrated updating, security hardening, and patching of workspace virtual machines (Windows and Linux).
- User Engagement: Structured onboarding consultancy and platform support services.
- Internal Operations: Corporate administration, financial control, and human resources as governed by the anDREa Internal Control Framework (AO/IC & P&C) and the Security Hub (non-public).
3. Core Activities In-Scope
- Continuous software development, security testing, maintenance, and commercialization of the myDRE platform and other services.
- Tier-3 technical support, infrastructure troubleshooting, and bug remediation.
- Tier-2 operational assistance provided directly to institutional, tenant-employed Research Support Teams (RSTs).
4.3.3 Exclusions
To establish clear operational boundaries, the following areas and dependencies are explicitly excluded from the anDREa ISMS scope:
- Hyperscale Infrastructure (Microsoft Azure): Core cloud fabric, data center physical security, and underlying hypervisor layers are inherited from Microsoft’s independently certified ISO/IEC 27001 compliance frameworks.
- User Data Governance: The specific classification, treatment, analysis, and ethical management of data ingested into a workspace by end-users. These actions remain under the sole governance of the customer organization's internal security and privacy policies.
- Data Processing Consultancy: Specialized support, scripting, or consulting services related to statistical data processing or scientific analysis.
- Non-Native Software Support: Technical support, installation, or maintenance of third-party, non-Azure resources or custom software packages requested by users within their workspaces.
- Legal and Regulatory Counsel: Formal legal advice, regulatory compliance interpretation, or institutional data governance consulting for client research projects.