Communication Facilities & HR Data Lifecycle Alignment Policy
This policy establishes the formal integration of anDREa B.V.’s (anDREa) Information Security Management System (ISMS) within our Human Resources (HR) operational framework. Designed around ISO/IEC 27001:2023 (A.05.10, A.05.11, A.06.06) and NIS 2 guidelines, this document links technical communication governance with the employee lifecycle to enforce a consistent security posture from initial onboarding to structural offboarding.
This framework undergoes mandatory evaluation and re-validation annually or immediately following significant operational changes, including mandatory updates to the corporate Risk Inventory and Evaluation (RI&E).
1. Core Objectives & Scope
To ensure absolute consistency across corporate directories and data storage boundaries, anDREa rejects the duplication of technical controls inside separate policy silos. Instead, this framework explicitly anchors our active *Retention & Destruction Policy and corporate communication controls directly into our HR lifecycle.
This integration enforces four foundational principles:
- The Triad Standard: Protecting the confidentiality, integrity, and availability of all data blocks generated, stored, accessed, or transferred during standard business operations. mydre CIA-AA Classification
- Proportional Safeguards: Ensuring that technical and organizational measures map precisely to the target information's asset classification.
- Lifecycle Continuity: Guaranteeing that identity states, messaging endpoints, and hardware custody arrays align systematically across both HR records and the IT plane.
- Auditability: Providing clear, verifiable proof to data protection regulators and ISO inspectors that employee compliance training match active system configurations.
2. Integrated Employee Lifecycle Phase-Gates
Corporate communication baselines and retention boundaries are systematically enforced at four critical HR touchpoints:
┌─────────────────┐ Continuous Training Loops ┌─────────────────┐
│ 1. ONBOARDING │ ───────────────────────────────────► │ 2. EMPLOYMENT │
└────────┬────────┘ └────────┬────────┘
│ │
▼ ▼
┌─────────────────┐ ┌─────────────────┐
│ 4. RE-AUDITING │ ◄─────────────────────────────────── │ 3. OFFBOARDING │
└─────────────────┘ Account Suspend & Purge └─────────────────┘
A. Onboarding Phase
- Every new hire, contractor, or seconded professional must complete mandatory review and formal signature loops for the Acceptable Use of Hardware & Internet Policy before their core accounts are provisioned.
- Security operations initialize isolated credentials only after the candidate executes their formal employment agreements and yields a validated Certificate of Good Conduct (VOG) or Criminal Background Check and maintained in Identity Checks.
B. Active Employment Phase
- Employees must handle daily corporate messaging, document drafting, and structural code storage inside designated enterprise boundary lines (primarily anDREa’s managed Google Workspace, Microsoft DevOps, and secure myDRE Workspaces).
- Personal information collected during daily performance management or standard team syncs must strictly adhere to the operational schedules outlined within our master post-employment retention tables.
C. Offboarding Phase
- The moment a contract or employment relationship terminates, the exit protocol triggers immediate technical de-provisioning paths designed to stop data leakage.
- Account Suspension Target: Security operations execute the formal Instructions to Suspend a Google Workspace Account, terminating live authentication paths, freezing session states, and establishing temporary mail-forwarding rules to designated company custodians.
- All data assets stored on local endpoint hardware must be transferred back to managed corporate spaces, followed by an immediate remote wipe of the machine under A.7 Physical Controls.
D. Training & Awareness Tracks
- Personnel are subject to continuous security awareness loops to reinforce secure file-sharing habits, phishing indicators, and cryptographic rules.
- Participation matrices are tracked directly within personnel dossiers, matching compliance timelines governed by national labor standards and the Dutch Working Conditions Act (Arbowet).
3. Enforcement & Governance Matrix
- Systemic Monitoring: All communication infrastructure utilization is subject to transparent, proportionate monitoring to ensure alignment with corporate values and data protection guidelines.
- Sanctions Floor: Documented non-compliance with these integrated security controls will immediately trigger disciplinary procedures up to contract cancellation, employment termination, and direct legal referral.
- Policy Authority: The Information Security Management Board (ISMB) retains absolute governance over this document, ensuring its constraints perfectly track updates applied to adjacent internal policies or shifting legal horizons.
Central Operational Repositories (Internal Audit Access Only)
- Master anDREa ISMS Framework Ledger
- Corporate On- & Offboarding Process Guide
- Google Workspace Account Suspension Execution Protocol