Version: 3.0
Valid until: 2025-04-10
Classification: Low
3.0 | Edward Robinson | Additions/changes as part of the annual review. No changes were made. |
In the interest of all the stakeholders, the top management of anDREa B.V. (hereafter called anDREa) is actively committed to demonstrably maintain and continually improve an information management system in accordance with the requirements of the ISO 27001:2017.
The purpose of this document is to describe the physical and environmental security policy of anDREa and the associated controls, checks and administrations. It is noteworthy that anDREa is a remote-first organisation and therefore has no physical location. Therefore, several annex controls are considered non-applicable.
Annex controls that are considered not-applicable are:
A.11.1.1 Physical security perimeter
A.11.1.2 Physical entry controls
A.11.1.3 Securing offices, rooms and facilities
A.11.1.4 Protecting against external and environmental threats
A.11.1.5 Working in secure areas
A.11.1.6 Delivery and loading areas
A.11.2.1 Equipment siting and protection
A.11.2.2 Supporting utilities
A.11.2.3 Cabling security
The remaining annex controls (A.11.2.4 - A.11.2.9) are considered applicable and detailed below. This policy has a direct relationship with the A.6.2 Mobile devices and teleworking policy. Therefore, the annex controls below will have a brief description and will refer to A.6.2 Mobile devices and teleworking for more detailed information.
This document will be reviewed at least annually and when significant change happens.
The objective of this control is:
To prevent loss, damage, theft or compromise of assets and interruption to the organisation’s operations (A.11.2).
The scope of this document corresponds to Clause 4 Context of the organisation.
This document is:
required reading for:
all employees and contractors of anDREa.
available for all interested parties as appropriate.
“Security shall be applied to off-site assets taking into account the different risks of working outside the organisation’s premises”.
Checks and controls that are described in A.6.2 Mobile devices and teleworking.