Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.02 Information Security Policy and Management Approval

Control Overview

This control ensures that leadership actively drives cybersecurity by establishing a comprehensive, top-down policy framework. Senior management defines the strategic objectives for protecting the availability, integrity, and confidentiality of data against evolving cyber threats. Rather than generic guidelines, this policy mandates specific, actionable practices across critical domains—including access security, application management, IT management, network infrastructure, and backups. It establishes clear lines of ownership for cybersecurity decisions and requires regular reviews to adapt to organizational shifts or new threat landscapes.

Ultimately, this control eliminates ambiguity, ensures operational preparedness, and fosters a strong culture of security awareness across the entire organization.

note

Applicability Note: This control is fully applicable to the anDREa platform and its entire operational environment.

Compliance & Strategic Approach

Our approach to satisfying this NIS 2 requirement is built entirely upon our existing, mature Information Security Management System (ISMS). Instead of introducing an isolated policy structure for NIS 2, we have mapped these regulatory demands directly into our ISO/IEC 27001-based framework, enhanced by a topic-specific policy hierarchy.

Ultimate strategic alignment is achieved through an explicitly documented policy framework: a central, overarching information security policy driven by senior leadership, supported by granular, topic-specific policies. These documents are dynamically linked via our Statement of Applicability and an automated ticketing workflow that enforces periodic reviews, management approvals, and mandatory staff acknowledgment cycles.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001Clause 5 - LeadershipDemonstrates active senior management commitment, approval, and definition of strategic security objectives.
ISO/IEC 27001Clause 5.1 - Leadership and CommitmentGoverns the creation, review, and maintenance of security policies and their alignment with organizational goals.
Core Strategy DocumentanDREa Information Security StrategyFormally outlines strategic objectives, the boundaries of reasonable preparedness, and documented management commitment.
Operational FrameworkStatement of ApplicabilityThe central matrix linking high-level NIS 2 requirements to actionable, auditable ISO controls.
Topic-Specific PoliciesA.05.15 - Access control
A.08.26 - Application security requirements
A.05.09 - Inventory of information and other associated assets
A.08.22 - Segregation of networks
A.08.13 - Information backup
Dedicated operational policies providing technical guardrails for daily IT and security practices.
Compliance EvidencePolicy Review & Approval WorkflowAudit trail of automated ticketing workflows proving periodic management review, formal approval, and mandatory staff acknowledgment.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The framework, approval matrix, distribution channels, and continuous review cadence are fully documented and operational.