Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.8 Information security in project management

1. Core Integration and Governance Framework

anDREa integrates information security directly into its project management lifecycle to ensure that security risks are identified, evaluated, and mitigated from project inception through to final deployment. This structural alignment satisfies ISO/IEC 27001 Annex A.5.8 and ensures that all new platform features, infrastructure expansions, or strategic initiatives conform to our core security baselines.

Rather than managing security as an isolated, late-stage checklist, anDREa weaves its information security requirements directly into our technical execution and engineering frameworks, specifically adhering to:


2. Project Classification and Triage

To determine the appropriate governance track for any proposed organizational or technical initiative, anDREa enforces the Project Compliance Framework.

This standard framework functions as an initial checkpoint to analyze the nature, scale, complexity, and risk profile of the proposed work. Based on this criteria, the framework defines whether the work must be managed under formal project management protocols (requiring an isolated project dossier, risk mapping, and executive oversight) or if it can be routed through standard operational sprint backlogs.