Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.5.9 Inventory of information and other associated assets

1. Asset Definition and Accountability

anDREa defines an asset as any item or property used by the organization for which anDREa is accountable or responsible. This definition expands upon traditional property-ownership models to accurately reflect our cloud-native footprint and extensive utilization of As-a-Service (SaaS/PaaS) solutions, satisfying A.05.09 - Inventory of information and other associated assets.

Every registered asset is assigned an explicit Asset Accountable (the individual with ultimate governance ownership and risk acceptance) and/or an Asset Responsible (the individual tasked with operational maintenance and control execution).


2. Internal Asset Management and Registries

Internal corporate assets are divided into two distinct logistical registries:

  • Application & Software Assets: All software applications, cloud tools, and digital platforms utilized or managed by anDREa are mapped, categorized, and tracked within the anDREa People - Asset Overview tab of the internal HR management system.
  • Physical Hardware Assets: Physical equipment, corporate laptops, and office hardware deployed to personnel are explicitly logged within the Inventory List. To maintain financial and operational accuracy, this ledger is periodically cross-referenced and validated during the formal Inventory Valuation lifecycle.

3. Supply Chain Governance: Virtual Asset Inventory (NIS 2 Compliance)

To satisfy NIS 2 Directive obligations regarding vulnerability management, supply chain visibility, and customer infrastructure tracking, anDREa maintains real-time monitoring of all virtual resources orchestrated for its institutional clients.

3.1 Exclusion of Physical Customer Equipment

anDREa operates strictly as a Software-as-a-Service (SaaS) and Platform-as-a-Service (PaaS) provider. anDREa does not supply, lease, or manage physical infrastructure, endpoints, or hardware servers for its clients. The responsibility for securing and managing physical end-user endpoints rests entirely with the Customer.

3.2 Automated Virtual Infrastructure Inventory

The inventory of supplied virtual infrastructure components (e.g., cloud-native Virtual Machines and isolated Workspaces) is fully automated, dynamic, and updated in real-time. This inventory is centrally orchestrated via admin.mydre.org and rendered transparently through the myDRE Insights Portal.

The myDRE Insights ecosystem provides a granular overview per client of:

  • Deployed Resources: Live Virtual Machines, backing storage endpoints, and their respective performance/architectural specifications.
  • Access Rights: Role-based IAM maps identifying precisely which users hold access permissions to specific workspaces.
  • Consumption Dynamics: Metrics detailing associated cloud operational costs and platform resource usage.

3.3 Configuration Management (Tenant Configurations)

Beyond dynamic resource tracking, client-specific environmental deviations are captured within the Tenant Configurations matrix. This restricted configuration management database (CMDB) tracks static operational parameters, including:

  • Specific Azure subscription alignments and underlying network topology settings.
  • Institutional license server connections and specialized API endpoint mappings.
  • Enabled optional features, custom software extensions, patch-level variances, or versions that deviate from standard baseline deployment configurations.

3.4 Version Unity and Patch Lifecycles

Because the core myDRE platform is architected and operated uniformly as a SaaS/PaaS ecosystem, only one production version and one consolidated patch level exist in active operation across the global framework at any given time. This ensures streamlined deployment validation and uniform application of security patches.