N.1.02 Information Security Policy and Management Approval
Control Overview
This control ensures that leadership actively drives cybersecurity by establishing a comprehensive, top-down policy framework. Senior management defines the strategic objectives for protecting the availability, integrity, and confidentiality of data against evolving cyber threats. Rather than generic guidelines, this policy mandates specific, actionable practices across critical domains—including access security, application management, IT management, network infrastructure, and backups. It establishes clear lines of ownership for cybersecurity decisions and requires regular reviews to adapt to organizational shifts or new threat landscapes.
Ultimately, this control eliminates ambiguity, ensures operational preparedness, and fosters a strong culture of security awareness across the entire organization.
Applicability Note: This control is fully applicable to the anDREa platform and its entire operational environment.
Compliance & Strategic Approach
Our approach to satisfying this NIS 2 requirement is built entirely upon our existing, mature Information Security Management System (ISMS). Instead of introducing an isolated policy structure for NIS 2, we have mapped these regulatory demands directly into our ISO/IEC 27001-based framework, enhanced by a topic-specific policy hierarchy.
Ultimate strategic alignment is achieved through an explicitly documented policy framework: a central, overarching information security policy driven by senior leadership, supported by granular, topic-specific policies. These documents are dynamically linked via our Statement of Applicability and an automated ticketing workflow that enforces periodic reviews, management approvals, and mandatory staff acknowledgment cycles.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | Clause 5 - Leadership | Demonstrates active senior management commitment, approval, and definition of strategic security objectives. |
| ISO/IEC 27001 | Clause 5.1 - Leadership and Commitment | Governs the creation, review, and maintenance of security policies and their alignment with organizational goals. |
| Core Strategy Document | anDREa Information Security Strategy | Formally outlines strategic objectives, the boundaries of reasonable preparedness, and documented management commitment. |
| Operational Framework | Statement of Applicability | The central matrix linking high-level NIS 2 requirements to actionable, auditable ISO controls. |
| Topic-Specific Policies | A.05.15 - Access control A.08.26 - Application security requirements A.05.09 - Inventory of information and other associated assets A.08.22 - Segregation of networks A.08.13 - Information backup | Dedicated operational policies providing technical guardrails for daily IT and security practices. |
| Compliance Evidence | Policy Review & Approval Workflow | Audit trail of automated ticketing workflows proving periodic management review, formal approval, and mandatory staff acknowledgment. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The framework, approval matrix, distribution channels, and continuous review cadence are fully documented and operational.