Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.8.9 Configuration Management

Control Objective

Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed.

Policy Statement

anDREa establishes and enforces standardized security configuration baselines across all hardware, software, network elements, and cloud services. Configuration drift is prevented via automated monitoring, strict access restrictions on administrative consoles, and mandatory annual reviews, ensuring full alignment with ISO/IEC 27001 and NIS 2 standards.


Core Security Configuration Repositories

Rather than managing configurations ad-hoc, anDREa maintains documented baselines across four primary operational pillars:

  • Endpoint Hardware & Local Software: Baseline rules including full-disk encryption, automated patch timelines, and local antimalware parameters are detailed in A.06.07 - Remote working.
  • Corporate Cloud Ecosystem: Structural settings, access groups, and core security configurations for office operations are managed within Google Workspace Security.
  • Platform Architecture and Fabric: Network routing rules, firewall tables, and isolation parameters for research networks are documented in A.08.20 - Networks security.
  • Software Development Infrastructure: Branch protection rules, continuous integration (CI) guardrails, and access group constraints are maintained within A.08.25 - Secure development life cycle.

Authorization & Monitoring of Changes

  • Privileged Access Enforcement: Altering established security configurations requires explicit authorization and the activation of elevated privileges using Just-In-Time role management (see A.08.02 - Privileged access rights).
  • Continuous Monitoring: Configuration changes are systematically logged, audited, and monitored through automated threat defense platforms (e.g., Azure Monitor and Google Security Center).
  • Lifecycle Review: All master configuration baselines are formally reviewed at least annually to ensure they address current threat landscapes.

NIS 2 Compliance & Platform Architecture

To satisfy strict regional infrastructure availability and supply chain standards, anDREa operates under a structured cloud service delivery model:

SaaS Uniformity (Single Version Policy)

anDREa provides myDRE as a continuous Software-as-a-Service (SaaS) platform. there are no customized or distinct code versions maintained for separate clients.

  • All active tenants natively utilize the single, most current, and fully patched "Production" build of the myDRE platform.
  • The current active release state is tracked, versioned, and audit-logged transparently via our master GitHub Repositories (see: Roadmap).

Tenant-Specific Parameters

While the underlying application code remains uniform across the entire user base, customer-specific operational variables are dynamically loaded and managed within the secure Tenant Configurations. This repository isolates and tracks:

  • Active operational and service-level agreements.
  • Virtual network peering configurations and localized routing tables.
  • Custom external license server connections.
  • Tenant-level enabling or disabling of optional platform features.

Shared Responsibility Model: User-Managed Software

In accordance with our cloud security model, anDREa does not track, manage, configure, or version software layers running inside customer-provisioned Virtual Machines (VMs), nor does it maintain custom VM templates generated by research teams.

  • The tenant organization retains full administrative ownership and responsibility for the configuration lifecycle, operating system patching, and software vulnerability remediation within their specific VM images.
  • Users maintain these layers independently utilizing the native, self-service capabilities of the myDRE platform.