N.1.04 Management control
Control Overview
This control mandates that senior management actively enforces and visibly supports compliance with all information security rules and operational procedures across the entire organization. It requires leadership to explicitly obligate all personnel—including new hires during onboarding—to adhere to security protocols. To drive a top-down culture of accountability, management must ensure that security policies are not just static documents, but are backed by adequate resources (such as time, funding, and tools), verified via regular tracking, and reinforced through mandatory, recurring training and awareness programs.
Applicability Note: This control is fully applicable to the anDREa platform and is enforced throughout all employee lifecycles.
Compliance & Strategic Approach
Our approach leverages the established governance mechanisms of our ISO/IEC 27001-based ISMS to demonstrate continuous, measurable management oversight.
Compliance is legally and operationally embedded from day one. Rather than relying on passive communication, management integrates formal security obligations directly into employment contracts. Adherence is strictly managed through a formalized onboarding track and sustained via mandatory, recurring Information Security & Data Protection training. Executive oversight is structured through the Information Security Management Board (ISMB) and formalized through the regular issuance of the Security Management Report, ensuring resource allocation and compliance are continuously reviewed and signed off at the management level.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | Clause 5 - Leadership | Evidence of management commitment to directing, supporting, and resourcing the ISMS. |
| ISO/IEC 27001 | Clause 5.3 - Organisational roles, responsibilities and authorities | Requires management to ensure all employees and contractors are aware of and comply with established security policies. |
| Legal & HR Framework | Employee Contracts | Legally binds employees to comply with the organization’s information security rules and procedures. |
| Onboarding Process | Onboarding & Offboarding Process | Mandatory review track for new hires covering the ISMS framework, disciplinary policies, incident response, and AI/LLM acceptable use policies. |
| Awareness Program | Training | Tracking data and metrics showing mandatory completion rates for recurring security training. |
| Executive Oversight | Information Security Management Board (ISMB) Meetings | Documented management review, policy sign-offs, and formal resource allocation approvals. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Security compliance is legally binding, verified during onboarding, reinforced via mandatory tracking, and strictly overseen by executive management.