Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Solution Architect

previous version on gdrive

N.4.08 Managing and securing networks

Control Overview

This control mandates that the organization formally establishes, assigns, and maintains operational governance over its network infrastructure and routing equipment. To prevent security breaches caused by misconfigured or unmonitored networks, the organization must maintain a comprehensive network asset inventory where every device or logical routing component is assigned a clear owner. Furthermore, networks must be secured using robust technical controls—including firewalls, encryption-in-transit protocols, and access restrictions—while network behavior must be continuously monitored to detect and neutralize potential threats.

note

Applicability Note: This control is fully applicable to the anDREa platform and serves as the primary mechanism for isolating multi-tenant research environments and protecting virtual network perimeters.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, translating physical network management concepts into a highly automated, software-defined cloud network paradigm.

Because anDREa provides a cloud-native SaaS/PaaS ecosystem on Microsoft Azure, we do not manage physical switches or routers. Instead, our framework focuses on the lifecycle of logical network perimeters, Software-Defined Networks (SDNs), and virtual appliances. We maintain a centralized Network Asset Inventory alongside a strict Network Baseline configuration pattern. Technical separation is enforced via cloud firewalls, Network Security Groups (NSGs), and strict encryption layers. This infrastructure is further cataloged within our Tenant Configurations matrix, ensuring that any modifications to network routing are explicitly tracked, approved, and assigned to a specific system owner.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.20 - Networks securityMandates that networks and network devices are secured, managed, and controlled to protect information in systems and applications.
Network ArchitectureNetwork Baseline StandardThe definitive technical blueprint defining authorized ingress/egress parameters, port configurations, and protocols.
Inventory GovernanceNetwork Asset InventoryThe official register detailing all virtual network components, gateways, peering arrangements, and assigned owners. (*
Tenant GovernanceTenant ConfigurationsOperational tracking documents capturing custom-scoped network isolation definitions applied to individual myDRE customer workspaces.
Operational ValidationPeriodic Controls Security LogsLogging records showing monitoring histories, connection traffic anomalies, and routine firewall performance metrics. (Periodic Security Controls)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Core software-defined network protections, inventory mapping, baseline configuration controls, and real-time transit logging are fully operationalized.
  • Continuous Improvement (NIS 2 Alignment): To achieve a highly resilient posture for upcoming supervisory reviews, execute the following optimization steps:
  1. Programmatically link the Network Asset Inventory directly to your risk-based configuration hardening standards to prove security-level parity.
  2. Embed explicit, recurring network configuration review cycles as a scheduled line item within your Periodic Controls Security framework to systematically catch configuration drift.