Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.8: Technological Controls

Purpose & Objective

This domain defines the technical countermeasures, cryptographic defenses, and logical boundaries engineered to protect the anDREa B.V. (anDREa) platform and its hosted data assets. Structured in absolute alignment with the ISO/IEC 27001:2023 (Control A.8) taxonomy and NIS 2 cyber hygiene directives, these controls leverage advanced technological solutions to enforce the confidentiality, integrity, and availability of information. By governing system configurations, access management vectors—such as our Workspaces Entitlement Matrix—and rapid threat containment pathways like the Emergency User Isolation "Emergency Brake", this framework ensures resilient defense against unauthorized access, data exfiltration, and modern cyber threats.

Scope & Inapplicability Justifications

The operational scope of these technical protections is detailed within Clause 4: Context of the Organisation of the master ISMS Manual.

The following controls are formally declared not applicable, with documented justifications in the control:

  • A.08.11 (Data Masking): Not applicable. anDREa strictly prohibits the extraction of production data for software testing environments; consequently, data masking routines are not required.
  • A.08.30 (Outsourced Development): Not applicable. anDREa never outsources the engineering of the myDRE core platform or business processes. All external contractors operate under direct, internal supervision and full organizational responsibility.

Availability

This document is classified as Public and is managed under the following access parameters:

  • Required Reading: Mandatory for all anDREa employees and contractors, requiring annual review and technical policy sign-off.
  • General Availability: Accessible to all external interested parties.