A.5.15 Access Control
1. Core Architectural Access Principles
anDREa enforces strict physical and logical access controls over all corporate information repositories, technical cloud fabrics, and platform assets. Our access governance framework satisfies ISO/IEC 27001 Annex A.5.15 and is built upon two core principles:
- Principle of Least Privilege (PoLP): Personnel are granted only the minimum access rights absolutely required to fulfill their specific operational role. Rights are restricted to the narrowest possible scope and provisioned for the shortest duration necessary.
- Role-Based Access Control (RBAC): Access permissions are bundled into standardized, predefined roles tied to specific organizational functions rather than assigned to individual users.
2. Asset and Access Registration
Access controls are managed and auditable through centralized directories:
- Asset & Owner Mapping: A comprehensive directory of all corporate infrastructure components, software suites, and physical hardware is maintained in the Asset Overview.
- Asset Responsibility: Every asset entry has a designated Asset Responsible who holds operational accountability for the access approval loops, baseline hardening, and ongoing maintenance of that item.
- Permission Schema Indexing: The explicit permission levels, administrative roles, and access tiers available for each tool are documented within the anDREa People HR matrix.
- Customer Workspace Audits: For end-user environments within the myDRE platform, anDREa develops and operates native Access Review Policy. These automated, periodic verification checkpoints allow tenant administrators to review active user lists and confirm that only authorized researchers retain access to myDRE Workspaces.
3. Operational Authorization Workflows
3.1 Access to Internal anDREa Assets
- Issuance: Access to internal systems is granted exclusively by the assigned Asset Responsible, who verifies that the request aligns with the Least-Privilege principle and matches the user's role.
- Google Workspace Access Engineering: Primary authentication occurs via unique corporate
@andrea-cloud.comaccounts provisioned by designated Google Admins (who are indexed within the HR system). - Group-Based Permissions: Permissions are managed via Google Groups. Adding an employee to a specialized group (e.g., the Security Group) automatically provisions the corresponding baseline access rights (view, create, or edit) for files in that domain.
- External Sharing Control: Document owners retain the authority to invite external, non-anDREa accounts to specific items on an exceptional, need-to-know basis.
3.2 Access for Customer Platform Support
To maintain a secure multi-tenant cloud architecture, anDREa operates under a clear Shared Responsibility Model for platform support:
┌──────────────────────────────────────────────────────────────────┐
│ anDREa Support Team │
└─────────────────────────────────┬────────────────────────────────┘
│ Provisions Guest Identities
▼
┌──────────────────────────────────────────────────────────────────┐
│ Research Support Team (RST) Members │
├──────────────────────────────────────────────────────────────────┤
│ • Must sign the formal RST Agreement │
│ • Must complete mandatory training & pass the ST Quiz │
│ • Manages user account submissions & local workspace creation │
└─────────────────────────────────┬────────────────────────────────┘
│ Bypasses anDREa Intervention
▼
┌──────────────────────────────────────────────────────────────────┐
│ End-User Workspaces & Research │
└──────────────────────────────────────────────────────────────────┘
- Guest Provisioning: The internal anDREa support team provisions guest user identities within Microsoft Entra ID exclusively for authorized members of a customer's Research Support Team (RST) .
- RST Qualification Gate: Before Entra ID or ticketing system access is enabled, anDREa requires all RST members to complete a mandatory training curriculum, pass the Training including the Support Team Agreement.
- Tenant Autonomy Boundary: anDREa does not participate in the daily creation of workspaces, user account invitations, or day-to-day access requests within individual client workspaces. This operational layer is managed independently by the qualified customer RST.
4. Technical Identity Assurance and Authentication Baselines
To safeguard administrative interfaces, anDREa enforces cryptographic authentication parameters across all internal personnel:
-
Identity Verification: All personnel must authenticate using a unique username paired with a strong password.
-
Mandatory Multi-Factor Authentication (MFA): Access to all enterprise environments requires continuous MFA validation.
-
Session Validity: Active sessions expire and require full re-authentication at least every 24 hours.
-
MFA Context: Authentication requests utilize secure push notifications with number matching, application verification, and geographic telemetry to prevent prompt-fatigue exploits.
-
Advanced Authentication (Highly Recommended): Personnel are encouraged to implement Passwordless Authentication or utilize physical FIDO2 hardware keys (e.g., YubiKey, Feitian) to protect administrative accounts.
Privileged Identity Management (PIM)
- Just-In-Time Elevation: Personnel executing administrative tasks within Microsoft Entra ID are prohibited from holding standing privileges. They must request temporary elevation through Azure Privileged Identity Management (PIM) (see Azure PIM Review).
- Oversight Loops: Active PIM activations are reviewed by management on a monthly basis. Any identified deviations, baseline anomalies, or unauthorized elevations are escalated to the bi-monthly Information Security Management Board (ISMB) Meetings for triage.
5. Governance Registries and Audit Evidence
To demonstrate access control enforcement to external ISO/IEC 27001 and NIS 2 auditors, the following records serve as evidence:
- anDREa People HR (Asset Overview & Role Maps): The central registry for tracking asset ownership, assigned operators, and system permission levels (Authorized Personnel Only).
- Support Team Agreement & ST Training Quiz Responses: Verifiable datastores logging successful compliance onboarding for external client RST members (Authorized Support Personnel Only).
- Azure PIM Activation Logs & ISMB Minutes: Technical event trails and management logs documenting the monthly review of privileged cloud elevations (Authorized Personnel Only).