A.5.4 Management responsibilities
1. Contractual Mandates and Operational Enforcement
Management ensures that all personnel actively apply information security principles in accordance with anDREa’s established policies, topic-specific standards, and operational procedures. This commitment satisfies ISO/IEC 27001 Annex A.5.4 by establishing security compliance as a core employment requirement.
Formal accountability begins at the contractual level. Adherence to organizational policies, information security baselines, and data safety procedures is explicitly hardcoded into see: Employee Contracts (templates). By signing this agreement, all personnel legally commit to upholding the security posture of the organization.
2. Structured Security Onboarding Flow
Upon joining the organization, management requires every employee and contractor to complete a comprehensive security onboarding path. This process ensures that personnel fully understand our operational controls before they are granted access to production systems or sensitive data.
New hires must review, digest, and acknowledge the following core components:
- The Information Security Management System (ISMS): Our overarching security framework and core principles (CClause 5.2 - Policy).
- The Disciplinary Procedure: The formal remediation steps and administrative consequences applied in the event of policy violations (AA.06.04 - Disciplinary process).
- The Incident Response Procedure: Step-by-step standard operating guidelines for identifying, isolating, and reporting security anomalies (A.05.26 - Response to information security incidents).
- The Roles & Responsibilities Matrix: Clear definitions of individual accountability and technical boundaries (A.05.02 - Information security roles and responsibilities).
- The HR Hub Manual: The central human resources repository detailing corporate ethics and behavioral guidelines (see: andREa's HR Hub).
- The AI/LLM Use Policy: Explicit governance criteria outlining the safe, authorized interaction with Artificial Intelligence and Large Language Models (see: AI/Large Language Model (LLM) Use Policy).
- The Information Security and Data Protection Training: A mandatory technical course covering data classification, threat vectors, and safe handling procedures (see: Training).
3. Mandatory Security Training Lifecycle
To maintain high security awareness and satisfy compliance mandates, anDREa enforces a automated, recurring training lifecycle:
[Onboarding Triggered] ──► [Mandatory Training Completed] ──► [MT Verification & Sign-off]
│
▼
[Yearly Re-evaluation] ◄── [Automated 12-Month Trigger] ◄─── [Active System Access]
- Initial Verification: The Training module is a mandatory task automatically generated within the onboarding workflow. The Management Team (MT) verifies completion before finalizing the onboarding process.
- Continuous Recertification: This training is not a one-time event. It is a mandatory, yearly recurring task for every employee and contractor. The system automatically triggers a recertification ticket exactly 12 months after the completion date of the previous training module.