Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

Definition of (Security) Roles and Responsibilities

This document defines the formal security roles and operational responsibilities within the anDREa ecosystem. It serves as a regulatory supportive document for ISO 27001 (A.05.03- Segregation of Duties , A.06.08 - Information Security Roles and Responsibilities) and NIS 2 (Governance & Risk Management).

This framework undergoes mandatory review at least annually, or immediately following any significant operational or organizational adjustments.


1. Operational Context & Segregation of Duties

anDREa operates as a lean, agile organization. Consequently, complete segregation of duties is balanced against organizational size. anDREa explicitly acknowledges the risks associated with overlapping roles (such as insider threat and human error) and actively integrates mitigating technical controls, peer reviews, and automated logging into its workflows to manage these risks.

The internal corporate governance structure and core executive matrices are formally maintained in anDREa's Roles and Responsibilities Matrix.


2. Key Security & Support Roles

Research Support (Tenant-Mandated)

Research Support personnel are employed directly by a Tenant and are authorized to act strictly under that specific Tenant's governance and instructions. They bridge the gap between end-users and the core platform framework.

  • SLA & Support Management: Actively assist end-users to meet anDREa SLA baselines; maintain and curate documentation on support.mydre.org.
  • Tracking & Documentation: Systematically log, track, and document the lifecycle progress of all user requests and operational assistance tickets.
  • Escalation Management: Route platform issues that cannot be resolved locally to the Service Provider, in strict accordance with the Tenant Agreement.
  • Security Incident Triage: Immediately escalate any suspected cyberattacks, anomalous risks, or potential data breaches directly to anDREa security channels.
  • Continuous Improvement: Conduct platform demonstrations and gather structured user feedback to drive platform optimizations.

Internal Auditor

The Internal Auditor provides independent assurance regarding the design, implementation, and operating effectiveness of anDREa's security controls.

  • Audit Planning & Execution: Formulate the annual audit schedule and participate directly in strategic audit planning.
  • Compliance Validation: Assess and verify the organization’s ongoing compliance with the security measures approved in the Statement of Applicability (SoA).
  • Reporting: Prepare and distribute objective Audit Reports to management detailing findings, non-conformities, and observations.
  • Framework Optimization: Define and refine audit criteria to enhance quality, develop specialized technical expertise, and drive continuous improvement of anDREa’s integrated management systems.