Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.6.06 Outsourced software development

Control Overview

This control mandates that when an organization outsources the development of custom software or platform components to external third parties, it must actively govern, monitor, and validate those development activities. The ultimate accountability for code security remains with the organization. Therefore, it must establish clear security baselines in contracts, continuously verify vendor security posture through audits or certifications, enforce least-privilege access, and subject third-party code to rigorous testing pipelines to prevent supply chain vulnerabilities.


Applicability Status

  • Applicable for anDREa: NO

Justification & Strategic Approach

This control is designed to mitigate information security risks, logic flaws, and supply chain vulnerabilities specifically introduced when code development is delegated to an external, third-party software vendor or offshore team.

anDREa operates an internally managed engineering model. The organization does not outsource its core software development workflows. All platform engineering, system architecture design, and feature iterations for the myDRE platform are executed exclusively by personnel under the direct management, operational control, and employment governance of anDREa.

Because there are no third-party software development vendors writing or contributing code to the core repository:

  • Specialized supplier software lifecycle auditing frameworks are not required.
  • Software supply chain risk is centralized and managed entirely within internal resource boundaries.

Consequently, the specific requirements for third-party outsourced development oversight are classified as Not Applicable. Instead, the security, quality, and integrity of all code written internally by anDREa personnel are governed comprehensively under our IT-focused engineering controls, specifically A.06.01 - Screening, A.06.03 - Information security awareness, education and training, and A.06.07 - Remote working.


Audit Summary

  • Compliance Status: Not Applicable (Exempt via Operational Model)
  • Gaps Identified: None. The justification for non-applicability is operationally accurate and consistent with anDREa’s internal engineering structure. No further remediation or third-party mapping is required.