In this weeks update there are the following topics: ISO 27001 *** Does anDREa have access to data? *** Offboarding and Exit Strategy
ISO 27001
On 2021-10-29 anDREa BV will be internally audited by an external party for ISO 27001. Nicely in time for it falls together with our own internal annual review of all our procedures, policies, and other documents.
Does anDREa have access to data?
This question pops up from time to time. From a compliance point of view, the answer to the important question is:
In the event there is a (suspected) incident with or access to the data of a Workspace, it is the obligation of the Controller to be able to take timely any action required to limit further damage and gain control over the situation. anDREa can, on instruction, assist the Controller to gain access (again) to their Workspaces and the data in those Workspace(s).
Offboarding and Exit Strategy
While most users of myDRE Workspaces might at best wonder about this question, for certain functions in your organization and for some grant applications this is a valid question. Suppliers are really pressured to be able to move the data back in control of the Tenant within 5 working days. Think about it moving maybe thousands of VMs and storage accounts, the TBs if not more on data.
anDREa can do this in one hour. anDREa can do this because we do not need to move data, we just hand over the control to your organization. All the Workspaces for a Tenant are deployed in a Microsoft Azure subscription of that Tenant. There is one caveat, anDREa hands it over to the Tenant, the Tenant must make the resources available as the Tenant sees fit.