Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.04 Management control

Control Overview

This control mandates that senior management actively enforces and visibly supports compliance with all information security rules and operational procedures across the entire organization. It requires leadership to explicitly obligate all personnel—including new hires during onboarding—to adhere to security protocols. To drive a top-down culture of accountability, management must ensure that security policies are not just static documents, but are backed by adequate resources (such as time, funding, and tools), verified via regular tracking, and reinforced through mandatory, recurring training and awareness programs.

note

Applicability Note: This control is fully applicable to the anDREa platform and is enforced throughout all employee lifecycles.

Compliance & Strategic Approach

Our approach leverages the established governance mechanisms of our ISO/IEC 27001-based ISMS to demonstrate continuous, measurable management oversight.

Compliance is legally and operationally embedded from day one. Rather than relying on passive communication, management integrates formal security obligations directly into employment contracts. Adherence is strictly managed through a formalized onboarding track and sustained via mandatory, recurring Information Security & Data Protection training. Executive oversight is structured through the Information Security Management Board (ISMB) and formalized through the regular issuance of the Security Management Report, ensuring resource allocation and compliance are continuously reviewed and signed off at the management level.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001Clause 5 - LeadershipEvidence of management commitment to directing, supporting, and resourcing the ISMS.
ISO/IEC 27001Clause 5.3 - Organisational roles, responsibilities and authoritiesRequires management to ensure all employees and contractors are aware of and comply with established security policies.
Legal & HR FrameworkEmployee ContractsLegally binds employees to comply with the organization’s information security rules and procedures.
Onboarding ProcessOnboarding & Offboarding ProcessMandatory review track for new hires covering the ISMS framework, disciplinary policies, incident response, and AI/LLM acceptable use policies.
Awareness ProgramTrainingTracking data and metrics showing mandatory completion rates for recurring security training.
Executive OversightInformation Security Management Board (ISMB) MeetingsDocumented management review, policy sign-offs, and formal resource allocation approvals.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Security compliance is legally binding, verified during onboarding, reinforced via mandatory tracking, and strictly overseen by executive management.