Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.8.34 Protection of Information Systems During Audit Testing

Control Objective

Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.

Policy Statement

anDREa requires that all penetration tests, security code audits, and technical compliance assessments involving active operational environments are rigidly planned, tightly scoped, and formally authorized before execution. Operational system audits must be conducted under controlled conditions to eliminate the risk of unexpected service downtime, performance degradation, or data compromise.


1. Audit Evaluation and Decision Metrics

The Director retains ultimate accountability for system security and availability during assurance activities. The decision to initiate a technical audit is made in direct consultation with the Business Manager and designated lead developers, evaluated against:

  • The sensitivity and classification of the target infrastructure in alignment with active corporate risk profiles.
  • Historic incident trends or structural anomalies that warrant deeper technical forensic inspection.
  • Specific contractual compliance mandates or verification requests submitted by tenant organizations.

2. Lifecycles and Operational Guardrails for Technical Audits

To ensure that assurance tasks do not compromise system performance, all testing schedules must adhere to a strict chronological governance framework:

A. Pre-Audit Control Measures

Before granting any external auditor or security firm operational access, the Director must verify that:

  1. CIA-A Safeguards: Clear technical mechanisms are established to protect the mydre CIA-AA Classification of the target environment during active execution.
  2. Scope Definition: Boundary limits, target IP addresses, application endpoints, and explicit exclusion zones are definitively agreed upon and recorded.
  3. Formalized Test Plan: A comprehensive, step-by-step test plan is drafted, vetted, and approved by anDREa engineering leadership.

B. During-Audit Monitoring

  • Real-Time Threshold Supervision: System infrastructure is heavily monitored by internal operations teams.
  • Incident Escalation: If the mydre CIA-AA Classification of any operational asset is inadvertently degraded or compromised (e.g., an automated fuzzing tool causes an unexpected denial-of-service state), the activity must be stopped immediately and handled as a high-priority event under A.05.25 - Assessment and decision on information security events.

C. Post-Audit Closure Actions

Following the conclusion of the technical audit, the Director records and addresses the outcomes through a standardized administrative wrap-up:

  • Impact Logging: Formal registration of whether any systemic stability or CIA-A thresholds were breached during active testing, including suggestions to optimize protection protocols for future audit iterations.
  • Executive Reflection: The Director synthesizes technical findings into a strategic Management Summary if one was not natively provided by the auditing vendor.
  • Triage & Remediation: Findings are formally reviewed by stakeholders during the bi-monthly IInformation Security Management Board (ISMB) Meetings. Discovered flaws are re-assessed based on real-world severity, and immediate Product Backlog Items (PBIs) are generated within Azure DevOps to schedule remediation (see A.08.08 - Management of technical vulnerabilities).
  • Transparency Distribution: The resulting Management Summary is published within the Management Reports, either as a standalone artifact or integrated directly into the distributed monthly CTO Report.