Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.6: People Controls

Purpose & Objective

This domain defines the mandatory lifecycle controls, vetting protocols, and behavioral standards used to govern human resources across anDREa B.V. (anDREa). Structured in absolute alignment with the ISO/IEC 27001:2023 (Control A.6) taxonomy and NIS 2 personnel security requirements, these controls mitigate the risk of human error, insider threats, and unauthorized data exposure. By enforcing rigorous background vetting via the Employee Data Sharing Policy, mandatory security awareness training, and structured remediation paths like the Workplace Behavior & Disciplinary Action Policy, this framework ensures that all personnel are technically equipped and contractually bound to uphold the platform's strict security baselines from onboarding through post-employment.

Scope

The operational scope of these human-centric controls is fully detailed within Clause 4: Context of the Organisation of the master ISMS Manual.

Availability

This document is classified as Public and is managed under the following access parameters:

  • Required Reading: Mandatory for all anDREa employees and contractors, requiring annual review and technical policy sign-off.
  • General Availability: Accessible to all external interested parties.