Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5: Organisational Controls

Purpose & Objective

This domain defines the core governance framework used to direct, manage, and continuously audit information security across anDREa B.V. (anDREa). Structured in absolute alignment with the ISO/IEC 27001:2023 (Control A.5) taxonomy and NIS 2 (Article 21) management accountability standards, these controls integrate security directly into our daily corporate culture and multi-tenant cloud operations. By establishing clear operational policies, explicit role boundaries, and formal risk tracking mechanisms, this framework ensures that all security decisions—from standard user provisioning to executing an Emergency Breaks—are executed under strict, verifiable management oversight.

Scope

The operational scope of these human-centric controls is fully detailed within Clause 4: Context of the Organisation of the master ISMS Manual.

Availability

This document is classified as Public and is managed under the following access parameters:

  • Required Reading: Mandatory for all anDREa employees and contractors, requiring annual review and technical policy sign-off.
  • General Availability: Accessible to all external interested parties.