N.3.09 Defining access security
Control Overview
This control mandates that the organization defines and enforces logical access rights on a strict per-role or per-function basis, adhering to the principle of least privilege. Access must be limited exclusively to what is necessary for an individual to perform their specific job functions, preventing the systemic risks associated with over-privileged accounts. Furthermore, the control requires that access to sensitive environments is logged, monitored, and regularly reviewed, while any underlying physical infrastructure access risks are managed through continuous verification.
Applicability Note: This control is fully applicable to the anDREa platform and serves as a primary operational guardrail for restricting administrative, developer, and tenant-level workspaces.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, relying on a highly operationalized Role-Based Access Control (RBAC) model.
Rather than managing permissions ad-hoc, anDREa structures all logical authorization around explicitly defined Definition of (Security) Roles and Responsibilities. We maintain a definitive ledger of internal system access permissions within the Asset Overview matrix, which binds each critical information asset to a designated "Asset Responsible." Because anDREa is a cloud-native SaaS/PaaS provider, the physical protection of the primary hosting infrastructure (such as server racks, power supplies, and patch cabinets) is delegated to our cloud infrastructure provider (Microsoft Azure). We actively verify these physical protections through our supplier relationship framework by conducting routine, structured evaluations of the provider's ISO/IEC 27001 certifications and SOC 2 Type II audit reports.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.15 - Access control | Mandates the establishment and operational enforcement of a formal access control policy for systems, networks, and data. |
| ISO/IEC 27001 | A.05.18 - Access rights | Controls the lifecycle of provisioning, modifying, and withdrawing logical access privileges based on organizational roles. |
| ISO/IEC 27001 | A.05.19 - Information security in supplier relationships, A.05.20 - Addressing information security within supplier agreements, A.05.21 - Managing information security in the information and communication technology (ICT) supply chain | The supplier management sub-framework used to govern and verify third-party infrastructure dependencies (Azure physical security). |
| Authorization Matrix | anDREa People - Asset Overview | The central registry detailing personnel access privileges, mapped roles, and the assigned Asset Responsibles. |
| Access Governance | Access Review Policy | Codifies the mandatory cadence and validation steps for pruning stale access rights and verifying least-privilege compliance. |
| Vendor Assurance | Cloud Provider SOC 2 / ISO Dossiers | Saved analysis logs of external hyper-scaler audits verifying that physical data center perimeters match internal expectations. (SOC 2 type II, anDREa Supplier List |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Logical RBAC mappings, least-privilege enforcement, regular access review cadences, and cloud-physical assurance procedures are completely active and verified.