N.2.05 Confidentiality agreements
Control Overview
This control mandates that the organization ensures all personnel—including full-time employees, temporary workers, contractors, and external partners—formally sign a Confidentiality or Non-Disclosure Agreement (NDA) prior to being granted access to any sensitive or proprietary information assets. The goal is to establish unequivocal legal certainty and accountability, reducing the risk of data leaks or insider incidents. Furthermore, the control requires that these agreements are managed through a structured system that supports regular reviews, updates, and automated reminders to maintain alignment with evolving organizational and regulatory demands.
Applicability Note: This control is fully applicable to the anDREa platform and represents a non-negotiable security gateway for any internal role or third-party relationship.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, treating confidentiality agreements as a mandatory prerequisite for access control rather than a detached administrative task.
At anDREa, no account provisioning or physical access can occur until a signed confidentiality instrument is executed and verified. For core staff, these parameters are embedded directly into their onboarding legal documentation. For external stakeholders and specialized vendors, dedicated Non-Disclosure Agreements (NDAs) are deployed based on the exact sensitivity of the data they will interact with. This process is maintained through a digital review system that tracks agreement status, triggers periodic compliance reviews, and ensures that agreements are systematically updated alongside our broader risk cycles.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.06.06 - Confidentiality or non-disclosure agreements | Mandates that confidentiality or non-disclosure agreements reflecting the organization's needs for data protection are maintained, reviewed, and traceably signed. |
| Legal Gateway | Onboarding & Offboarding Process | Central secure repository containing all executed, legally binding non-disclosure covenants and employment contract annexes. |
| Lifecycle Governance | Periodic Security Controls | Digital administrative tracking workflow that logs agreement dates, flags expired frameworks, and sends operational alerts for periodic re-signing and legal policy updates. |
| Access Cross-Reference | A.05.15 - Access control | Operational policy rule ensuring that identity provisioning systems (Entra ID/Google) remain locked until HR confirms a signed confidentiality agreement is on file. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Pre-access signature mandates, structured vendor/personnel NDA tracking, and digital agreement review mechanisms are completely active and verifiable.