Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.5.01 Register of all OT assets

Control Overview

This control mandates that the organization establishes, maintains, and continuously updates a comprehensive inventory of Operational Technology (OT) assets. This register must include critical configuration baselines, hardware models, embedded software/firmware versions, current patch levels, and network interconnection paths. Furthermore, a specific manager or owner must be assigned to each asset to ensure accountability, safe operations, and prompt vulnerability lifecycle management.


Applicability Status

  • Applicable for anDREa: NO

Justification & Strategic Approach

Operational Technology (OT) refers to programmable systems or devices that interact directly with the physical environment, or manage and monitor physical processes—such as Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) systems, programmable logic controllers (PLCs), smart building sensors, and physical factory automation equipment.

anDREa is a purely software-driven, cloud-native SaaS/PaaS organization delivering virtualized data and analytics workspaces (myDRE) hosted entirely within Microsoft Azure public cloud infrastructure.

Consequently, anDREa:

  • Does not own, manage, operate, or interface with any industrial networks or physical manufacturing facilities.
  • Does not control any building automation, smart utility grids, or hardware-level industrial machinery.
  • Operates under a fully remote corporate model with zero office locations, eliminating any exposure to physical site OT footprints.

Because anDREa’s environment is composed strictly of logical, software-defined cloud assets and standard user endpoints, all requirements under the NIS 2 Operational Technology (OT) domain are formally classified as Not Applicable. Asset management, configuration baselines, and ownership mappings are instead governed strictly through our IT-focused inventories under Controls N.4.01 (User Devices) and N.4.08(Network Security).


Audit Summary

  • Compliance Status: Not Applicable (Exempt via Architecture)
  • Gaps Identified: None. The justification for the non-applicability of OT controls is architecturally sound and compliant with the scope of anDREa's virtual cloud-delivery model. No further remediation actions are required.