N.5.06 Segmentation of OT networks
Control Overview
This control mandates that the organization establishes, implements, and documents strict architectural rules for segregating Operational Technology (OT) networks from standard corporate IT networks and the public internet. By creating isolated network zones and enforcing micro-segmentation, organizations prevent cyber threats (such as malware or unauthorized lateral movement) from migrating across IT boundaries into critical safety and production environments, thereby enhancing overall cyber resilience.
Applicability Status
- Applicable for anDREa: NO
Justification & Strategic Approach
This control addresses the containment of network traffic within physical industrial zones, such as isolating SCADA control loops from corporate workstations or partitioning automated manufacturing floors using industrial firewalls and DMZs.
As a fully remote, cloud-native SaaS/PaaS organization, anDREa’s platform (myDRE) exists exclusively in a software-defined public cloud environment (Microsoft Azure).
Because anDREa has no physical offices, factories, or physical IT-to-OT infrastructure interfaces:
- The organization does not deploy, manage, or route traffic for any physical industrial machinery, factory floors, or OT control networks.
- There are no hardware-bound OT segments or localized cyber-physical connection paths to partition.
Consequently, all requirements under the NIS 2 Operational Technology (OT) network segmentation domain are Not Applicable.
All network isolation, multi-tenant containment, and data-plane security requirements for anDREa are handled strictly within our IT cloud architecture. This is governed explicitly by Control N.4.09 (Network Segmentation) and verified independently through routine third-party penetration testing under A.08.22 - Segregation of networks.
Audit Summary
- Compliance Status: Not Applicable (Exempt via Architecture)
- Gaps Identified: None. The justification for non-applicability perfectly reflects anDREa's pure-cloud software model. No further configuration or documentation is required.