N.1.11 Transferring information internally and externally
Control Overview
This control mandates that the organization defines, communicates, and enforces strict guidelines for the secure transmission of confidential information, both internally among staff and externally with third parties (such as clients, vendors, and partners). To eliminate data leakage, interception, or unauthorized alteration during transit, the organization must clearly delineate which communication channels, software platforms, and physical media are approved for use. These rules must account for diverse transmission formats—including electronic communications, physical storage media, and verbal exchanges—while ensuring that staff are fully trained to use these mechanisms safely.
Applicability Note: This control is fully applicable to the anDREa platform and covers all internal corporate operations, platform management data, and customer data transfers.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement is seamlessly built into our ISO/IEC 27001-based ISMS, linking transmission protocols directly with cryptographic standards and clear environment separation.
Rather than relying on ad-hoc tools, anDREa restricts data transit to a centralized list of approved, secured communication channels. To mitigate systemic risk, we strictly maintain an operational boundary between our internal business operations environment (managed securely via Google Workspace) and our core platform delivery environment (managed via Microsoft Office 365). Technical enforcement mechanisms—including mandatory transport-layer encryption, SPF/DKIM authentication, and automated anti-malware/anti-phishing filters—are natively embedded into these channels to ensure that security controls do not depend on manual user configuration alone.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| A.05.14 - Information transfer | Dictates the implementation of transfer policies, procedures, and controls for all types of communication facilities. | |
| ISO/IEC 27001 | A.08.24 - Use of cryptography | Enforces strict encryption-in-transit parameters across all internal and external communication nodes. |
| ISO/IEC 27001 | A.06.07 - Remote working | Governs off-site data transmission rules, including mandatory secure network/VPN infrastructure requirements. |
| Communication Governance | Communication Facilities Policy | The authoritative text defining approved corporate channels, explicit tools allowed for data share, and baseline communication standards. |
| Lifecycle Standards | Retention & Destruction Policy | Defines operational parameters for data lifecycle handling post-transfer to prevent data accumulation on transmission nodes. |
| Technical Architecture | Business vs. Platform Environment Isolation | Architectural boundary configuration proving the logical separation between corporate back-office traffic (Google Workspace) and production environment operations (Microsoft Azure). |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Approved transmission channels are explicitly defined, strictly separated across architectural boundaries, enforced via strong cryptography, and fully documented.