Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.1 Policies for information security

1. High-Level Governance & Information Security Strategy

anDREa's overarching cybersecurity vision and operational strategy are governed by the anDREa Information Security Strategy. Underneath this guiding framework, anDREa maintains a core Information Security Policy (Clause 5.2 - Policy) and a comprehensive suite of topic-specific policies that satisfy ISO/IEC 27001 Annex A.5.1.

To maintain full transparency and support compliance for healthcare clients and institutional research partners, all policies, operational procedures, supporting documentation, and formal management reports are registered within the central anDREa ISMS repository and published openly on the public myDRE Knowledge Base.


2. Systematic Policy Review & Operational Cadence

To ensure all governance documentation remains relevant, accurate, and aligned with our threat landscape, anDREa enforces strict review loops.

2.1 Review Triggers and Windows

At a minimum, every information security policy is evaluated:

  • Annually: During a comprehensive, scheduled baseline cycle (Overviews).
  • Contextual Shifting: Immediately upon the occurrence of significant technical, structural, or organizational changes.
  • Operational Insight: When strategic alignment discussions or tracking metrics during ISMB - Meeting Notes yield new risk insights.
  • Compliance Evaluation: Directly following the conclusion of an internal or external compliance audit.

2.2 Risk-Based Pre-Read & Acknowledgment Cadence

To maintain continuous familiarity with policy requirements among leadership:

  • Prior to each monthly ISMB session, the Management Team selects a targeted set of policies using a risk-based assessment methodology.
  • Board members must complete a mandatory pre-read of these selected files.
  • During the live ISMB session, the chosen policies are scrutinized, updated where necessary, and formally acknowledged by management.

2.3 Lifecycle of Changes and Version Control

When an active policy document requires updates, anDREa follows a strict governance sequence:

  1. Archiving: The existing active policy version is captured and moved to the secure archive repository (in accordance with Clause 7.5.2 - Documented information).
  2. Task Creation: An internal governance tracking ticket is created, outlining the proposed changes.
  3. Approval: The Management Team reviews the changes and grants formal approval via the internal ticketing environment.
  4. Publication: The newly authorized version is pushed live to the public Knowledge Base.
  5. Communication: Impactful modifications are proactively communicated to all anDREa employees and relevant external stakeholders.

3. Topic-Specific Policy Framework Matrix

anDREa organizes its technical and administrative controls into distinct operational domains. The table below maps these specific policy topics to their governing Annex A control structures:

Policy DomainGoverning Control ReferenceCore Functional Focus
Access SecurityA.05.15 - Access control
A.08.02 - Privileged access rights
Defines Identity and Access Management (IAM) baselines, role segregation, and the restriction of administrative privileges.
Application ManagementA.08.25 - Secure development life cycleOutlines secure coding standards, CI/CD pipeline automation criteria, and environment isolation rules for the myDRE platform.
IT & Asset ManagementA.05.09 - Inventory of information and other associated assets
A.06.07 - Remote working
Governs the registration, classification, and lifecycle management of hardware/software endpoints, alongside remote-work security requirements.
Network ManagementA.08.20 - Networks security
A.08.22 - Segregation of networks
Enforces perimeter protection boundaries, virtual network isolation, and encryption of transit telemetry across cloud infrastructure.
Backup ManagementA.08.13 - Information backup
A.08.14 - Redundancy of information processing facilities
Mandates immutable backup configurations, disaster recovery intervals, and geographic data redundancy parameters for high availability.

4. Governance Registries and Audit Evidence

To demonstrate active compliance to external assessment authorities, the primary tracking index is maintained openly:

  • Statement of Applicability (SoA): Hosted and tracked publicly within the Statement of Applicability register, serving as our central log for control implementation statuses.