DRAFT — REQUIRES REVIEW BY IASME-ACCREDITED CE+ ASSESSOR AND SIGN-OFF BY BRITIAI CTO BEFORE INCLUSION IN BID.
CE04 — Cyber Essentials Plus Controls Register
Scope: BritiAI UK (parent). UK employee endpoints, BritiAI UK-controlled cloud tenants, UK NHS-facing production environment. Votee (HK) and Beever (Toronto) are out of scope and have no routed access into the in-scope environment. Document owner: BritiAI CTO. Cadence: quarterly review; full re-attestation at CE+ recertification.
1. Register conventions
- Control ID maps to the IASME Cyber Essentials Montpellier question set families: FW (Firewalls), SC (Secure Configuration), UA (User Access Control), MP (Malware Protection), SU (Security Update Management).
- Evidence reference points to a file in
/04_CEPlus/evidence/. Filenames follow theYYYYMMDD_<control>_<artefact>pattern from CE03. - Review cadence is the routine cadence at which the control owner re-verifies the control is still in place. CE+ recertification is annual regardless of routine cadence.
2. Controls register
| ID | Control description | Scope | Owner | Evidence reference | Review cadence |
|---|---|---|---|---|---|
| FW-1 | Host-based firewall enabled on every in-scope endpoint (Windows Defender Firewall on Windows; macOS Application Firewall on macOS), enforced and monitored via MDM configuration profile. | All UK employee laptops and desktops | IT Lead | evidence/YYYYMMDD_FW1_mdm_compliance.csv; YYYYMMDD_FW1_baseline_profile.pdf | Monthly MDM compliance review |
| FW-2 | AWS production VPC has an explicit inbound services register. Every ingress rule in the production security groups has a documented business justification. No 0.0.0.0/0 ingress except for managed load balancers terminating modern TLS. | UK NHS production AWS account (eu-west-2) | Head of Platform | evidence/YYYYMMDD_FW2_inbound_register.pdf; YYYYMMDD_FW2_sg_export.csv | Quarterly |
| FW-3 | No inbound services run on user endpoints. No port-forwarding from home routers to BritiAI-managed devices. Confirmed by external scan. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_FW3_external_scan.pdf | Annual (re-tested at CE+ recert) |
| SC-1 | Endpoints provisioned from a hardened MDM baseline: disk encryption on (BitLocker/FileVault), screen-lock ≤15 minutes idle, auto-run/auto-play disabled, guest accounts removed, unused default accounts removed. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_SC1_baseline_profile.pdf; YYYYMMDD_SC1_mdm_compliance.csv | Quarterly |
| SC-2 | Cloud tenants in scope (Microsoft 365, AWS, GitHub Organisation, identity provider, DNS registrar, code-signing provider) configured to require MFA for all users and to deny anonymous access to company data. External sharing in M365/Google Workspace restricted to allow-listed domains. | All BritiAI UK-controlled cloud tenants | IT Lead + Head of Platform | evidence/YYYYMMDD_SC2_tenant_register.csv; YYYYMMDD_SC2_sharing_policy.pdf | Quarterly |
| SC-3 | No default vendor passwords in use on any device, appliance, or cloud admin account. Re-verified by spot-check during dry-run and at CE+ recert. | All in-scope assets | IT Lead | evidence/YYYYMMDD_SC3_attestation.pdf (CTO-signed) | Annual |
| UA-1 | Joiner-mover-leaver process: every user account provisioned via HR-IT joiner; rights changed on role change; account disabled within 1 business day of leaver date. | All BritiAI UK staff | IT Lead | evidence/YYYYMMDD_UA1_jml_log.csv | Quarterly |
| UA-2 | Admin account register maintained. Every named admin has a paired standard account used for daily work. Admin elevation required for admin actions. Break-glass account exists, is sealed, and has a documented use procedure. | All BritiAI UK-controlled cloud tenants | CTO | evidence/YYYYMMDD_UA2_admin_register.csv; YYYYMMDD_UA2_breakglass_procedure.pdf | Quarterly |
| UA-3 | MFA enforced for all users on all in-scope cloud services. Phishing-resistant MFA (FIDO2/passkey) preferred for admin accounts; SMS MFA prohibited for admin accounts. AWS root account uses hardware token MFA. GitHub Organisation enforces 2FA at the Org level. | All in-scope identity perimeters | IT Lead + Head of Platform | evidence/YYYYMMDD_UA3_mfa_status.csv; YYYYMMDD_UA3_github_2fa.png; YYYYMMDD_UA3_aws_iam_report.csv | Monthly MFA status export |
| UA-4 | No staff of out-of-scope entities (Votee, Beever) hold admin rights or standard user rights in in-scope BritiAI UK tenants. Confirmed by quarterly cross-entity sweep. | All BritiAI UK-controlled tenants | CTO | evidence/YYYYMMDD_UA4_cross_entity_sweep.pdf | Quarterly |
| UA-5 | Legacy authentication protocols (IMAP, POP, basic auth, SMTP AUTH) disabled at the tenant level in Microsoft 365 / Google Workspace. | UK email and collaboration tenants | IT Lead | evidence/YYYYMMDD_UA5_legacy_auth_off.png | Annual |
| MP-1 | Managed endpoint protection (Microsoft Defender for Endpoint on Windows; standardised managed EDR/AV on macOS) installed, running, definitions ≤24 hours, tamper protection enabled, on every in-scope endpoint. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_MP1_edr_compliance.csv; YYYYMMDD_MP1_tamper_protection.png | Monthly |
| MP-2 | Email gateway anti-malware enabled at the M365/Google Workspace tenant level. Confirmed by live EICAR delivery test during dry-run and CE+ assessment. | UK email tenant | IT Lead | evidence/YYYYMMDD_MP2_email_gateway.png; YYYYMMDD_MP2_eicar_test.pdf | Annual (re-tested at CE+ recert) |
| MP-3 | Browser-level web malware blocking (SmartScreen / Safe Browsing) enforced via MDM. Confirmed by live malicious-download test during dry-run and CE+ assessment. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_MP3_browser_policy.pdf; YYYYMMDD_MP3_eicar_download_test.pdf | Annual |
| MP-4 | Mobile devices in scope rely on the platform application store as the application allow-list. Sideloading and developer mode disabled by MDM policy. Devices enrolled in MDM with screen lock and disk encryption enforced. | UK staff mobiles used for work email/Slack | IT Lead | evidence/YYYYMMDD_MP4_mobile_policy.pdf | Quarterly |
| SU-1 | OS auto-update enabled on every in-scope endpoint. High and critical vendor patches applied within 14 days of release, evidenced by MDM patch-compliance report. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_SU1_patch_compliance.csv | Monthly |
| SU-2 | No out-of-support operating systems on any in-scope endpoint. No Windows 10 without ESU; no macOS older than the vendor-supported window. Re-verified before each CE+ assessment. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_SU2_os_inventory.csv | Quarterly |
| SU-3 | Developer runtimes (Node.js, Python, JDK, container base images) tracked and kept on supported versions. Out-of-support runtimes removed or upgraded within 30 days of EOL. | Engineering endpoints and production build pipeline | Head of Platform | evidence/YYYYMMDD_SU3_runtime_inventory.csv | Quarterly |
| SU-4 | Browser and browser-extension inventory maintained per endpoint. Out-of-support extensions removed. Browser auto-update enabled. | All UK employee endpoints | IT Lead | evidence/YYYYMMDD_SU4_browser_inventory.csv | Quarterly |
| SU-5 | AWS-managed service patching is the responsibility of AWS under the shared responsibility model; BritiAI-managed AMIs and container images are rebuilt on a documented cadence and on CVE-trigger for high/critical findings. | UK NHS production AWS account | Head of Platform | evidence/YYYYMMDD_SU5_image_rebuild_log.csv | Monthly |
3. Out-of-scope declaration
The following are explicitly out of scope for this controls register and for the CE+ assessment:
- Votee Ltd (Hong Kong) corporate IT estate and cloud tenants.
- Beever (Toronto) corporate IT estate and cloud tenants.
- Personal devices of BritiAI UK staff. BYOD is not permitted for NHS-data-touching work.
- Any infrastructure outside the BritiAI UK production AWS account that is not used to deliver or support the NHS-facing services.
The out-of-scope estates have no routed access into the in-scope environment. This is enforced by separate identity tenants, separate cloud accounts, and the UK-only deployment topology declared elsewhere in the bid.
4. Register review and change control
- Quarterly review chaired by the CTO; output is a short minute filed in
/04_CEPlus/evidence/. - Any change to a control (e.g. swapping EDR vendor) requires CTO approval and a register update within 5 working days.
- The register is re-attested in full at every CE+ recertification.
End of CE04.
