Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.3.09 Defining access security

Control Overview

This control mandates that the organization defines and enforces logical access rights on a strict per-role or per-function basis, adhering to the principle of least privilege. Access must be limited exclusively to what is necessary for an individual to perform their specific job functions, preventing the systemic risks associated with over-privileged accounts. Furthermore, the control requires that access to sensitive environments is logged, monitored, and regularly reviewed, while any underlying physical infrastructure access risks are managed through continuous verification.

note

Applicability Note: This control is fully applicable to the anDREa platform and serves as a primary operational guardrail for restricting administrative, developer, and tenant-level workspaces.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, relying on a highly operationalized Role-Based Access Control (RBAC) model.

Rather than managing permissions ad-hoc, anDREa structures all logical authorization around explicitly defined Definition of (Security) Roles and Responsibilities. We maintain a definitive ledger of internal system access permissions within the Asset Overview matrix, which binds each critical information asset to a designated "Asset Responsible." Because anDREa is a cloud-native SaaS/PaaS provider, the physical protection of the primary hosting infrastructure (such as server racks, power supplies, and patch cabinets) is delegated to our cloud infrastructure provider (Microsoft Azure). We actively verify these physical protections through our supplier relationship framework by conducting routine, structured evaluations of the provider's ISO/IEC 27001 certifications and SOC 2 Type II audit reports.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.15 - Access controlMandates the establishment and operational enforcement of a formal access control policy for systems, networks, and data.
ISO/IEC 27001A.05.18 - Access rightsControls the lifecycle of provisioning, modifying, and withdrawing logical access privileges based on organizational roles.
ISO/IEC 27001A.05.19 - Information security in supplier relationships, A.05.20 - Addressing information security within supplier agreements, A.05.21 - Managing information security in the information and communication technology (ICT) supply chainThe supplier management sub-framework used to govern and verify third-party infrastructure dependencies (Azure physical security).
Authorization MatrixanDREa People - Asset OverviewThe central registry detailing personnel access privileges, mapped roles, and the assigned Asset Responsibles.
Access GovernanceAccess Review PolicyCodifies the mandatory cadence and validation steps for pruning stale access rights and verifying least-privilege compliance.
Vendor AssuranceCloud Provider SOC 2 / ISO DossiersSaved analysis logs of external hyper-scaler audits verifying that physical data center perimeters match internal expectations. (SOC 2 type II, anDREa Supplier List

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Logical RBAC mappings, least-privilege enforcement, regular access review cadences, and cloud-physical assurance procedures are completely active and verified.