Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.8.3 Information Access Restriction

Control Objective

Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.

Policy Statement

anDREa strictly enforces logical barriers to prevent unauthorized access to its data, source code, and infrastructure assets. Information is not accessible by default; instead, access is denied by default and granted only when explicitly justified by an individual's role, training status, and business requirements.


Access Restriction Mechanism

The practical enforcement of information access restrictions relies on a direct linkage between two primary ISMS security pillars:

  • Risk-Based Classification: Information is first categorized under our data schema, identifying whether the asset carries a Low / Public or High / Confidential impact profile (see A.05.1 and A.05.13: Labelling of Information).
  • Technical Access Enforcement: Once classified, technical restrictions are dynamically applied at the identity layer. These boundaries ensure that High / Confidential systems and data repositories are restricted using modern identity governance, network routing constraints, and explicit authorization protocols (see A.05.15: Access Control).

Key Operational Constraints

  • Least Privilege: Access rights are limited to the minimum permissions necessary for an individual to perform their specific job function.
  • Need-to-Know: Gaining access to a system requires an active, approved business objective, even if an individual's broad role or title might otherwise permit it.
  • Isolation: Internal corporate files, production database segments, and customer research workspaces are technically segmented to prevent lateral movement or unauthorized cross-tenant viewing.