Skip to main content
Review and revision metadata
Review Date: 2026-08-18
Reviewer: Director

previous version on gdrive

5.2 Policy

This policy defines the overarching governance framework for information security at anDREa. It establishes our core security principles, outlines accountability structures, and ensures compliance with mandatory regulatory frameworks.

Our cybersecurity approach is fundamentally driven by the Information Security Management Board (ISMB) Meetings.


5.2.1 Core Security Principles

All personnel, systems, and operations within the scope of the ISMS must adhere to the following foundational principles:


5.2.2 Accountability and Governance

  • Ultimate Accountability: The Director is explicitly accountable for the overall performance, compliance, and legal integrity of the ISMS.
  • Operational Responsibility: The Management Team (MT) is collectively responsible for executing security strategy, ensuring resource availability, and managing daily security operations.
  • Control Enforcement: Personnel with specific data-owner responsibilities—as defined in the anDREa Roles and Responsibilities Matrix—are responsible for establishing asset classifications, ensuring compliance within their domains, and verifying that external partners adhere to contractual security terms.
  • New Systems and Services: The Director determines and authorizes the required security baselines and control measures for all new information systems, cloud architectures, and operational services prior to deployment.

5.2.3 Supporting Policies & Document Access

To reinforce this high-level policy, anDREa maintains a comprehensive suite of subsidiary security policies.

  • Policy Creation: The MT oversees the drafting and lifecycle of all subsidiary policies, leveraging specialized input from internal technical and compliance experts.
  • Public Availability: To ensure transparency for clients, platform users, and external auditors, all primary policy documents are publicly accessible within our open ISMS repository.
  • Access Restrictions: Internal corporate records, asset registers, risk ledgers, and operational event logs are confidential and require explicit administrative authorization to access.

5.2.4 Information Security Objectives

anDREa explicitly defines, tracks, and measures its information security milestones to ensure alignment with our strategic direction: