Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.6.09 Overview of delivered software

Control Overview

This control mandates that organizations developing and distributing software maintain an accurate, up-to-date registry mapping all customers to the specific application versions and components they are actively running. In the event of a critical security advisory or zero-day exploit, this asset-to-customer mapping allows the organization to instantly identify vulnerable endpoints, measure exposure impact, push targeted emergency patches, and notify affected stakeholders without delay.

note

Applicability Note: This control is fully applicable to the anDREa platform. It ensures that the operational status of all active research environments remains completely transparent to platform administrators.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, benefiting significantly from our unified Software-as-a-Service (SaaS) architecture.

Unlike traditional software vendors who manage fragmented legacy versions across disparate client sites, anDREa operates under a "single version in operation" SaaS model. The entire global production plane of myDRE runs on a uniform, centralized release baseline. This means that version tracking is structurally embedded into our release automation framework:

  • Centralized Environment Telemetry: While all clients run the same core code version, individual tenant parameters, custom configuration matrices, and isolated features are recorded within our *Tenant Configurations index and mapped programmatically via Insights.
  • Release Traceability: Every platform deployment is driven through version-controlled pipelines linked directly to our GitHub repositories, providing an unalterable history of the exact code commit active across the production cloud fabric.
  • Public Transparency & Communication: Approved platform updates, newly deployed features, and upcoming changes are published transparently via the myDRE Feature Release and Roadmap dashboard. If an extraordinary configuration drift or out-of-SLA event occurs, targeted notifications are routed directly to the designated technical owners of the affected tenant environments.

Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.09 - Configuration managementMandates that templates, configurations, and software baselines are explicitly defined, tracked, and maintained.
Release ArchitectureGitHub Release Tags & PipelinesVersion-control markers providing cryptographic traceability for the specific application build deployed to production.
Customer TrackingTenant ConfigurationsThe definitive internal system register mapping active customer organizations to their respective cloud workspace footprints.
Public TelemetrymyDRE Feature Release & RoadmapThe external portal (Roadmap) providing users and auditors with real-time insight into the platform's active release version.
Governance RecordsCTO Security & Management ReportsInternal ISMS executive updates tracking pipeline deployments, software lifecycle milestones, and release compliance metrics.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The single-version deployment model, supported by real-time infrastructure tagging, automated release logging, and automated tenant telemetry, fully satisfies the version-tracking requirements of this control.