Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Solution Architect

previous version on gdrive

A.8.26 Application Security Requirements

Control Objective

Information security requirements shall be identified, specified and approved when developing or acquiring applications.

Policy Statement

anDREa mandates that comprehensive information security requirements are systematically defined, formalized, and approved at the inception of any software initiative—whether developing proprietary capabilities for the myDRE platform or acquiring external third-party applications. This guarantees that security is treated as a fundamental baseline rather than a retrospective adjustment.


1. Unified Security Requirements Gathering

During the initial scoping and planning phases of both software engineering and procurement, technical and compliance teams must identify core security requirements alongside traditional functional attributes. This analysis encompasses:

  • CIA Triad Controls: Core parameters dictating the necessary levels of confidentiality, integrity, and availability for the data lifecycle.
  • Access & Identity Governance: Rules specifying required authentication factors, user provisioning mechanisms, and Role-Based Access Control (RBAC) granularities.
  • Cryptographic Baselines: Encryption mandates covering both transit channels and storage-at-rest tiers.
  • Audit & Monitoring Capabilities: Specific system, administrative, and error logging specifications required to expose anomalous behavior or fulfill compliance baselines.
  • Regulatory Alignment: Verification of full compliance with relevant statutory frameworks, contract rules, and localized privacy regulations (e.g., GDPR, NIS 2).
note

Formalization Mechanism: The collected parameters must be explicitly analyzed, recorded, and formally approved within a dedicated SIA Instructions before implementation or procurement can proceed.


2. Software Development (In-House Engineering)

To operationalize Security-by-Design across proprietary platform developments, generalized SIA requirements are enhanced through a structured engineering lifecycle:

Post-Deployment Continuous Security & Lifecycle Care

Once software is introduced into the production myDRE environment, ongoing operational security is preserved through five interconnected layers:

  1. Logging & Event Monitoring: Continuous integration with central SIEM/log engines to capture systemic anomalies or security events (see A.08.15 - Logging and A.08.16 - Monitoring activities).
  2. Vulnerability Management: Proactive, automated code and dependency scanning to expose hidden flaws (see A.08.08 - Management of technical vulnerabilities).
  3. Security Patch Management: Immediate application of software upgrades and security revisions in strict accordance with the company’s Patch Management SLA.
  4. Incident Response Readiness: Full alignment with formalized technical playbooks to rapidly contain or mitigate application exploits (see A.05.25 - Assessment and decision on information security events).
  5. Independent Security Audits: Deployed features or application revisions are programmatically added to the scope of the next scheduled third-party Penetration Testing cycle.

3. Application Acquisition (Third-Party Procurement)

When anDREa acquires external applications, utilities, or SaaS subscriptions, information security compliance is evaluated through our standardized vendor onboarding framework. The acquisition process must strictly conform to the security controls, review cycles, and legal requirements detailed within the following policies: