5.2 Policy
This policy defines the overarching governance framework for information security at anDREa. It establishes our core security principles, outlines accountability structures, and ensures compliance with mandatory regulatory frameworks.
Our cybersecurity approach is fundamentally driven by the Information Security Management Board (ISMB) Meetings.
5.2.1 Core Security Principles
All personnel, systems, and operations within the scope of the ISMS must adhere to the following foundational principles:
- Classification and Labeling: All data must be classified based on Confidentiality, Integrity, and Availability (mydre CIA-AA Classification) requirements. Handling, storage, and transmission must strictly align with the assigned classification level (A.05.12 - Classification of information, A.05.13 - Labelling of information, A.05.31 - Legal, statutory, regulatory and contractual requirements).
- Access Control & Least Privilege: Information is made available only to those with a validated, legitimate business need. Access rights are strictly provisioned based on the principles of Least Privilege and Need-to-Know (A.05.15 - Access control).
- System Protection: Information assets are proactively secured against unauthorized access, malicious processing, and data exfiltration in accordance with their risk profile (Clause 7 - Support, A.05.15 - Access control.
- Incident Reporting: Any suspected or validated breach of this policy, or any observed security anomaly, must be reported immediately through established incident channels (A.05.25 - Assessment and decision on information security events, A.05.31 - Legal, statutory, regulatory and contractual requirements.
- Independent Evaluation: The efficacy of our security controls is routinely validated through annual internal audits, independent third-party penetration testing, and formal vulnerability assessments (Clause 9 - Performance, A.05.31 - Legal, statutory, regulatory and contractual requirements, A.08.34 - Protection of information systems during audit testing).
- Continuous Improvement: The ISMS framework, underlying technical controls, and operational processes are iteratively refined using data-driven continuous improvement methodologies (Clause 10 - Improvement).
5.2.2 Accountability and Governance
- Ultimate Accountability: The Director is explicitly accountable for the overall performance, compliance, and legal integrity of the ISMS.
- Operational Responsibility: The Management Team (MT) is collectively responsible for executing security strategy, ensuring resource availability, and managing daily security operations.
- Control Enforcement: Personnel with specific data-owner responsibilities—as defined in the anDREa Roles and Responsibilities Matrix—are responsible for establishing asset classifications, ensuring compliance within their domains, and verifying that external partners adhere to contractual security terms.
- New Systems and Services: The Director determines and authorizes the required security baselines and control measures for all new information systems, cloud architectures, and operational services prior to deployment.
5.2.3 Supporting Policies & Document Access
To reinforce this high-level policy, anDREa maintains a comprehensive suite of subsidiary security policies.
- Policy Creation: The MT oversees the drafting and lifecycle of all subsidiary policies, leveraging specialized input from internal technical and compliance experts.
- Public Availability: To ensure transparency for clients, platform users, and external auditors, all primary policy documents are publicly accessible within our open ISMS repository.
- Access Restrictions: Internal corporate records, asset registers, risk ledgers, and operational event logs are confidential and require explicit administrative authorization to access.
5.2.4 Information Security Objectives
anDREa explicitly defines, tracks, and measures its information security milestones to ensure alignment with our strategic direction:
- Strategic Mapping: Long-term cybersecurity goals are detailed directly within the anDREa's Information Security Strategy.
- Performance Tracking: Tactical security goals and performance metrics are managed via our Information Security Performance registers.
- Reporting: Performance against these objectives is formally evaluated and communicated transparently via our annual, public Management Reports.
- Internal Auditing: Operational anomalies, compliance events, and financial controls are logged securely within the internal anDREa Internal Control Framework (AO/IC & P&C) and Issues and Risk Logging.