DRAFT — REQUIRES REVIEW BY IASME-ACCREDITED CE+ ASSESSOR AND SIGN-OFF BY BRITIAI CTO BEFORE INCLUSION IN BID.

CE04 — Cyber Essentials Plus Controls Register

Scope: BritiAI UK (parent). UK employee endpoints, BritiAI UK-controlled cloud tenants, UK NHS-facing production environment. Votee (HK) and Beever (Toronto) are out of scope and have no routed access into the in-scope environment. Document owner: BritiAI CTO. Cadence: quarterly review; full re-attestation at CE+ recertification.


1. Register conventions

  • Control ID maps to the IASME Cyber Essentials Montpellier question set families: FW (Firewalls), SC (Secure Configuration), UA (User Access Control), MP (Malware Protection), SU (Security Update Management).
  • Evidence reference points to a file in /04_CEPlus/evidence/. Filenames follow the YYYYMMDD_<control>_<artefact> pattern from CE03.
  • Review cadence is the routine cadence at which the control owner re-verifies the control is still in place. CE+ recertification is annual regardless of routine cadence.

2. Controls register

IDControl descriptionScopeOwnerEvidence referenceReview cadence
FW-1Host-based firewall enabled on every in-scope endpoint (Windows Defender Firewall on Windows; macOS Application Firewall on macOS), enforced and monitored via MDM configuration profile.All UK employee laptops and desktopsIT Leadevidence/YYYYMMDD_FW1_mdm_compliance.csv; YYYYMMDD_FW1_baseline_profile.pdfMonthly MDM compliance review
FW-2AWS production VPC has an explicit inbound services register. Every ingress rule in the production security groups has a documented business justification. No 0.0.0.0/0 ingress except for managed load balancers terminating modern TLS.UK NHS production AWS account (eu-west-2)Head of Platformevidence/YYYYMMDD_FW2_inbound_register.pdf; YYYYMMDD_FW2_sg_export.csvQuarterly
FW-3No inbound services run on user endpoints. No port-forwarding from home routers to BritiAI-managed devices. Confirmed by external scan.All UK employee endpointsIT Leadevidence/YYYYMMDD_FW3_external_scan.pdfAnnual (re-tested at CE+ recert)
SC-1Endpoints provisioned from a hardened MDM baseline: disk encryption on (BitLocker/FileVault), screen-lock ≤15 minutes idle, auto-run/auto-play disabled, guest accounts removed, unused default accounts removed.All UK employee endpointsIT Leadevidence/YYYYMMDD_SC1_baseline_profile.pdf; YYYYMMDD_SC1_mdm_compliance.csvQuarterly
SC-2Cloud tenants in scope (Microsoft 365, AWS, GitHub Organisation, identity provider, DNS registrar, code-signing provider) configured to require MFA for all users and to deny anonymous access to company data. External sharing in M365/Google Workspace restricted to allow-listed domains.All BritiAI UK-controlled cloud tenantsIT Lead + Head of Platformevidence/YYYYMMDD_SC2_tenant_register.csv; YYYYMMDD_SC2_sharing_policy.pdfQuarterly
SC-3No default vendor passwords in use on any device, appliance, or cloud admin account. Re-verified by spot-check during dry-run and at CE+ recert.All in-scope assetsIT Leadevidence/YYYYMMDD_SC3_attestation.pdf (CTO-signed)Annual
UA-1Joiner-mover-leaver process: every user account provisioned via HR-IT joiner; rights changed on role change; account disabled within 1 business day of leaver date.All BritiAI UK staffIT Leadevidence/YYYYMMDD_UA1_jml_log.csvQuarterly
UA-2Admin account register maintained. Every named admin has a paired standard account used for daily work. Admin elevation required for admin actions. Break-glass account exists, is sealed, and has a documented use procedure.All BritiAI UK-controlled cloud tenantsCTOevidence/YYYYMMDD_UA2_admin_register.csv; YYYYMMDD_UA2_breakglass_procedure.pdfQuarterly
UA-3MFA enforced for all users on all in-scope cloud services. Phishing-resistant MFA (FIDO2/passkey) preferred for admin accounts; SMS MFA prohibited for admin accounts. AWS root account uses hardware token MFA. GitHub Organisation enforces 2FA at the Org level.All in-scope identity perimetersIT Lead + Head of Platformevidence/YYYYMMDD_UA3_mfa_status.csv; YYYYMMDD_UA3_github_2fa.png; YYYYMMDD_UA3_aws_iam_report.csvMonthly MFA status export
UA-4No staff of out-of-scope entities (Votee, Beever) hold admin rights or standard user rights in in-scope BritiAI UK tenants. Confirmed by quarterly cross-entity sweep.All BritiAI UK-controlled tenantsCTOevidence/YYYYMMDD_UA4_cross_entity_sweep.pdfQuarterly
UA-5Legacy authentication protocols (IMAP, POP, basic auth, SMTP AUTH) disabled at the tenant level in Microsoft 365 / Google Workspace.UK email and collaboration tenantsIT Leadevidence/YYYYMMDD_UA5_legacy_auth_off.pngAnnual
MP-1Managed endpoint protection (Microsoft Defender for Endpoint on Windows; standardised managed EDR/AV on macOS) installed, running, definitions ≤24 hours, tamper protection enabled, on every in-scope endpoint.All UK employee endpointsIT Leadevidence/YYYYMMDD_MP1_edr_compliance.csv; YYYYMMDD_MP1_tamper_protection.pngMonthly
MP-2Email gateway anti-malware enabled at the M365/Google Workspace tenant level. Confirmed by live EICAR delivery test during dry-run and CE+ assessment.UK email tenantIT Leadevidence/YYYYMMDD_MP2_email_gateway.png; YYYYMMDD_MP2_eicar_test.pdfAnnual (re-tested at CE+ recert)
MP-3Browser-level web malware blocking (SmartScreen / Safe Browsing) enforced via MDM. Confirmed by live malicious-download test during dry-run and CE+ assessment.All UK employee endpointsIT Leadevidence/YYYYMMDD_MP3_browser_policy.pdf; YYYYMMDD_MP3_eicar_download_test.pdfAnnual
MP-4Mobile devices in scope rely on the platform application store as the application allow-list. Sideloading and developer mode disabled by MDM policy. Devices enrolled in MDM with screen lock and disk encryption enforced.UK staff mobiles used for work email/SlackIT Leadevidence/YYYYMMDD_MP4_mobile_policy.pdfQuarterly
SU-1OS auto-update enabled on every in-scope endpoint. High and critical vendor patches applied within 14 days of release, evidenced by MDM patch-compliance report.All UK employee endpointsIT Leadevidence/YYYYMMDD_SU1_patch_compliance.csvMonthly
SU-2No out-of-support operating systems on any in-scope endpoint. No Windows 10 without ESU; no macOS older than the vendor-supported window. Re-verified before each CE+ assessment.All UK employee endpointsIT Leadevidence/YYYYMMDD_SU2_os_inventory.csvQuarterly
SU-3Developer runtimes (Node.js, Python, JDK, container base images) tracked and kept on supported versions. Out-of-support runtimes removed or upgraded within 30 days of EOL.Engineering endpoints and production build pipelineHead of Platformevidence/YYYYMMDD_SU3_runtime_inventory.csvQuarterly
SU-4Browser and browser-extension inventory maintained per endpoint. Out-of-support extensions removed. Browser auto-update enabled.All UK employee endpointsIT Leadevidence/YYYYMMDD_SU4_browser_inventory.csvQuarterly
SU-5AWS-managed service patching is the responsibility of AWS under the shared responsibility model; BritiAI-managed AMIs and container images are rebuilt on a documented cadence and on CVE-trigger for high/critical findings.UK NHS production AWS accountHead of Platformevidence/YYYYMMDD_SU5_image_rebuild_log.csvMonthly

3. Out-of-scope declaration

The following are explicitly out of scope for this controls register and for the CE+ assessment:

  • Votee Ltd (Hong Kong) corporate IT estate and cloud tenants.
  • Beever (Toronto) corporate IT estate and cloud tenants.
  • Personal devices of BritiAI UK staff. BYOD is not permitted for NHS-data-touching work.
  • Any infrastructure outside the BritiAI UK production AWS account that is not used to deliver or support the NHS-facing services.

The out-of-scope estates have no routed access into the in-scope environment. This is enforced by separate identity tenants, separate cloud accounts, and the UK-only deployment topology declared elsewhere in the bid.


4. Register review and change control

  • Quarterly review chaired by the CTO; output is a short minute filed in /04_CEPlus/evidence/.
  • Any change to a control (e.g. swapping EDR vendor) requires CTO approval and a register update within 5 working days.
  • The register is re-attested in full at every CE+ recertification.

End of CE04.