Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.14 Information Transfer

1. Objective and Communication Governance

anDREa enforces strict rules, procedures, and architectural barriers for all types of information transfer facilities. This framework applies to data transit within the internal organization, as well as data sharing between anDREa and external partners, satisfying ISO/IEC 27001 Annex A.5.14.

These controls prevent data leakage, unauthorized interception, and phishing exploits when transferring corporate information, source code, and platform configurations.


2. Technical Safeguards and Transport Security

anDREa utilizes multi-layered technical boundaries to protect information assets during transit:

2.1 Cryptographic Enforcements

All data moving across public or untrusted network environments is secured using advanced transport encryption standards (e.g., TLS 1.3), as detailed in A.08.24 - Use of cryptography. This ensures that any data moving between cloud environments, developer endpoints, or client management tools is encrypted by default.

2.2 Account and Environment Isolation

To minimize the blast radius of a credential compromise and enforce clean boundaries, anDREa strictly segregates its operational communication ecosystems:

  • Corporate Business Operations: Handled exclusively through an isolated Google Workspace (formerly Google Suite) tenant.
  • Platform & Core Infrastructure Operations: Handled through an independent, segregated Microsoft Office 365 tenant.

2.3 Electronic Messaging Controls

The corporate Google Workspace environment implements all foundational and advanced security measures recommended by Google’s Security Advisor. This email security posture includes:

  • Sender Policy Framework (SPF): Restricting which mail servers are authorized to send email on behalf of anDREa's domains.
  • DomainKeys Identified Mail (DKIM): Cryptographically signing email headers to verify sender authenticity and prevent email tampering.
  • Malware and Phishing Protection: Actively enforcing automated, cloud-based heuristic filters to block malicious attachments, suspect URLs, and inbound social engineering threats.

See DNS & Domain Checks
See Google Security Advisor

For the Microsoft Office 365 environment, native Microsoft enterprise security controls and threat protection modules are enabled to safeguard platform-level messaging and administrative updates.


3. Contractual and Client Boundaries

3.1 Shared Responsibility Model

anDREa operates under a clear shared-responsibility model regarding data ingress and egress:

  • Platform Security: anDREa is responsible for securing the pipeline mechanics, backing architecture, and orchestration APIs of the myDRE ecosystem.
  • Tenant Data Transfer: Institutional clients and tenant administrators are independently accountable for defining and executing their own transfer policies, data loss prevention (DLP) procedures, and access controls when importing or exporting data portfolios into individual workspaces.

3.2 Supplier and Client Agreements

The technical and administrative criteria for secure information transfer are hardcoded directly into all standard Customer Agreements and anDREa Supplier List, making secure transit a binding contractual requirement.

3.3 Human Factors

All data transfers conducted outside corporate network boundaries follow the strict device-hardening and secure connectivity rules defined in A.06.07 - Remote working.


4. Overarching Governance Standards

In all transfer scenarios, information handling must comply with the foundational constraints outlined in the Communication Facilities Policy.