N.6.09 Overview of delivered software
Control Overview
This control mandates that organizations developing and distributing software maintain an accurate, up-to-date registry mapping all customers to the specific application versions and components they are actively running. In the event of a critical security advisory or zero-day exploit, this asset-to-customer mapping allows the organization to instantly identify vulnerable endpoints, measure exposure impact, push targeted emergency patches, and notify affected stakeholders without delay.
Applicability Note: This control is fully applicable to the anDREa platform. It ensures that the operational status of all active research environments remains completely transparent to platform administrators.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, benefiting significantly from our unified Software-as-a-Service (SaaS) architecture.
Unlike traditional software vendors who manage fragmented legacy versions across disparate client sites, anDREa operates under a "single version in operation" SaaS model. The entire global production plane of myDRE runs on a uniform, centralized release baseline. This means that version tracking is structurally embedded into our release automation framework:
- Centralized Environment Telemetry: While all clients run the same core code version, individual tenant parameters, custom configuration matrices, and isolated features are recorded within our *Tenant Configurations index and mapped programmatically via Insights.
- Release Traceability: Every platform deployment is driven through version-controlled pipelines linked directly to our GitHub repositories, providing an unalterable history of the exact code commit active across the production cloud fabric.
- Public Transparency & Communication: Approved platform updates, newly deployed features, and upcoming changes are published transparently via the myDRE Feature Release and Roadmap dashboard. If an extraordinary configuration drift or out-of-SLA event occurs, targeted notifications are routed directly to the designated technical owners of the affected tenant environments.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.09 - Configuration management | Mandates that templates, configurations, and software baselines are explicitly defined, tracked, and maintained. |
| Release Architecture | GitHub Release Tags & Pipelines | Version-control markers providing cryptographic traceability for the specific application build deployed to production. |
| Customer Tracking | Tenant Configurations | The definitive internal system register mapping active customer organizations to their respective cloud workspace footprints. |
| Public Telemetry | myDRE Feature Release & Roadmap | The external portal (Roadmap) providing users and auditors with real-time insight into the platform's active release version. |
| Governance Records | CTO Security & Management Reports | Internal ISMS executive updates tracking pipeline deployments, software lifecycle milestones, and release compliance metrics. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The single-version deployment model, supported by real-time infrastructure tagging, automated release logging, and automated tenant telemetry, fully satisfies the version-tracking requirements of this control.