N.5.08 Remote access to critical OT systems
Control Overview
This control mandates that the organization implements a highly secure, centralized gateway—typically a hardened "Jump Host" or bastion server—to strictly regulate and monitor any remote access into critical Operational Technology (OT) networks, such as ICS or SCADA environments. This architecture is designed to reduce the organization's external attack surface by eliminating direct internet connectivity to cyber-physical systems. Any authorized remote session must be routed through this central access point, secured via multi-factor authentication (MFA) and encryption, and subject to continuous monitoring and immutable session logging.
Applicability Status
- Applicable for anDREa: NO
Justification & Strategic Approach
This control targets the specific risks associated with vendors, engineers, or third parties remotely connecting to physical plant machinery, utility grids, or localized industrial networks.
As established across all previous domain declarations, anDREa is a fully remote, cloud-native SaaS/PaaS organization that deploys and maintains the myDRE data platform entirely within the public cloud environment of Microsoft Azure.
Because anDREa's architecture contains zero physical machinery or industrial components:
- The organization does not operate, manage, or provide remote connectivity to any ICS, SCADA, or physical infrastructure control loops.
- There are no local hardware-bound network systems that require the deployment of an OT-specific physical or logical Jump Host perimeter.
Consequently, all requirements under the NIS 2 Operational Technology (OT) remote access domain are formally classified as Not Applicable.
All inbound remote access, administrative sessions, and engineering connections to anDREa’s virtual cloud environments are instead managed under our strict IT zero-trust framework. This is governed explicitly by Controls N.4.02 (Special Access Rights) and N.4.10 (Applying Authentication Methods), utilizing cloud-native Identity Providers, Azure Privileged Identity Management (PIM), Just-In-Time (JIT) conditional access, and mandatory multi-factor authentication (MFA) with number matching.
Audit Summary
- Compliance Status: Not Applicable (Exempt via Architecture)
- Gaps Identified: None. The justification for non-applicability is logically and architecturally complete. No further technical implementation or documentation is required for this control profile.