Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.5.11 Overview of OT systems and additional information

Control Overview

This control mandates that the organization establishes, maintains, and continuously updates a centralized, granular ledger of all Operational Technology (OT) systems. This master registry must document extensive metadata for each asset, including hardware specifications, software/firmware versions, specific configuration baselines, active security settings, manufacturer/supplier details, and maintenance history. Additionally, an explicit manager or owner must be assigned to each system to ensure continuous oversight, vulnerability tracking, and rapid incident response coordination.


Applicability Status

  • Applicable for anDREa: NO

Justification & Strategic Approach

This control is designed to address lifecycle tracking and vulnerability monitoring for physical cyber-physical components, such as managing supply chain details for specific hardware revisions of industrial switches, or tracking proprietary firmware bugs across distributed programmable logic controllers (PLCs).

As a fully remote, cloud-native SaaS/PaaS organization, anDREa manages and delivers its research data platform (myDRE) entirely within the virtualized environments of Microsoft Azure.

Because anDREa's architecture and corporate workflows are entirely software-defined:

  • The organization does not operate, lease, or connect to any industrial machinery, factory floor equipment, or cyber-physical infrastructure.
  • There are no hardware components, firmware builds, or mechanical maintenance schedules to log or review.
  • Vendor relationship management for physical engineering equipment or industrial component suppliers is entirely outside the scope of our business model.

Consequently, all requirements under the NIS 2 Operational Technology (OT) asset overview domain are formally classified as Not Applicable.

All asset logging, configuration baselines, and ownership assignments for anDREa’s active infrastructure are instead handled comprehensively within our IT-focused governance models. This is executed using our Asset Overview ledger, Tenant Configurations matrices, and automated configuration baselines governed under Controls N.3.09 (Defining Access Security) and N.4.08 (Managing and Securing Networks).


Audit Summary

  • Compliance Status: Not Applicable (Exempt via Architecture)
  • Gaps Identified: None. The justification for the non-applicability of this control is logically sound and completely aligned with anDREa's remote, cloud-native operational profile. No further mitigation or tracking actions are required.