A.5.8 Information security in project management
1. Core Integration and Governance Framework
anDREa integrates information security directly into its project management lifecycle to ensure that security risks are identified, evaluated, and mitigated from project inception through to final deployment. This structural alignment satisfies ISO/IEC 27001 Annex A.5.8 and ensures that all new platform features, infrastructure expansions, or strategic initiatives conform to our core security baselines.
Rather than managing security as an isolated, late-stage checklist, anDREa weaves its information security requirements directly into our technical execution and engineering frameworks, specifically adhering to:
- A.08.25 - Secure development life cycle Governing phase-by-phase security milestones across our product pipeline.
- A.08.27 - Secure system architecture and engineering principles Ensuring cloud infrastructure designs minimize threat surfaces.
- A.08.28 - Secure coding Implementing programmatic boundaries, automated code analysis, and strict peer-review mandates.
- A.08.32 - Change management Enforcing strict testing and authorization paths before any project output enters the myDRE production environment.
2. Project Classification and Triage
To determine the appropriate governance track for any proposed organizational or technical initiative, anDREa enforces the Project Compliance Framework.
This standard framework functions as an initial checkpoint to analyze the nature, scale, complexity, and risk profile of the proposed work. Based on this criteria, the framework defines whether the work must be managed under formal project management protocols (requiring an isolated project dossier, risk mapping, and executive oversight) or if it can be routed through standard operational sprint backlogs.