A.8.21 Security of Networks
Control Objective
Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored.
Policy Statement
anDREa formalizes and continuously monitors the security parameters, operational requirements, and service levels of all network services provisioning the myDRE ecosystem. Network security is not treated as a static configuration, but as a transparent, SLA-backed service framework governed by explicit customer agreements and verified through continuous administrative reporting.
Network Service Level Governance
To ensure consistency, availability, and regulatory alignment, network services are managed through a structured tripartite framework:
- Contractual Commitments: Detailed security mechanisms, technical management rules, and baseline network service levels are explicitly defined within the master Customer Organisation Agreement executed with each tenant.
- Transparent Documentation: Technical details regarding the platform's core connectivity arrays are divided into public-facing tiers within our Knowledge Base:
- myDRE Standard Services: Hardened cloud networking, default routing tables, and native platform isolation metrics (see: myDRE standard services).
- myDRE Optional Services: Advanced edge configurations, including Azure Bastion optimization and custom proxy-based domain allowlisting (see: myDRE optional services).
- anDREa SLA: The master Service Level Agreement defining target network uptime, performance thresholds, and technical support availability windows (see: SLA).
- Continuous Performance Validation: Network performance, availability metrics, and SLA compliance are not evaluated retrospectively. The Chief Technology Officer (CTO) compiles and delivers a comprehensive Management Reports to each tenant organization, summarizing real-time infrastructure usage, bandwidth statistics, and explicit compliance metrics.