A.5.11 Return of Assets
1. Objective and Lifecycle Scope
anDREa enforces the systematic recovery or decommissioning of all corporate, technical, and digital assets upon the modification, expiration, or termination of an employment contract, contractor agreement, or third-party partnership. This offboarding workflow satisfies ISO/IEC 27001 Annex A.5.11 and ensures that access to sensitive health-data research environments and internal systems is cleanly severed, preventing residual risk or data sprawl.
2. Physical and Corporate Asset Decommissioning
The offboarding protocol accounts for variations in hardware delivery models, applying distinct controls for internal corporate hardware and Bring-Your-Own-Device (BYOD) configurations:
2.1 Corporate-Issued Hardware
- Loan Authorization: Internal anDREa personnel are issued an official, centrally managed corporate device. To receive this hardware, the employee must execute a formal Equipment & Acceptable Use Agreement detailing property boundaries and responsibility mandates.
- Return Verification: Upon termination or contract modification, the hardware must be returned to management. The receiving manager issues a signed Equipment Return Receipt confirming the physical collection and operational condition of the unit.
- Archival Retention: Both signed agreements are filed within the individual's restricted personnel directory.
2.2 External Contractors and BYOD Management
Where external contractors or specialized partners utilize Bring-Your-Own-Device (BYOD) endpoints to execute tasks:
- Offboarding Notification: Upon contract termination, the individual is explicitly reminded of their legal obligations regarding corporate data retention.
- Data Sanitization & Attestation: The contractor is required to purge all local cached environments, configuration files, and anDREa-related business items from their personal hardware.
- Auditable Confirmation: The contractor must submit a formal statement confirming that all anDREa-related data has been safely destroyed. This acknowledgment is recorded inside the central offboarding ticket.
3. Digital Assets and Access Revocation
The offboarding of virtual infrastructure, digital tokens, and software subscriptions is managed through central administrative controls:
- Asset Tracking: The allocation of corporate user licenses, SaaS accounts, and cloud architecture credentials is logged inside the anDREa People HR management portal.
- Revocation Automation: Upon the designated termination timestamp, all digital assets are "returned" by revoking user identity tokens, disabling active single sign-on (SSO) configurations, and removing platform licenses across Google Workspace, Microsoft Azure, and internal developer repositories.