To help our customers assess our information security, compliance, and Artificial Intelligence governance practices with confidence, we’ve completed the Cloud Security Alliance (CSA) CAIQ – Consensus Assessments Initiative Questionnaire and aligned our management systems with the principles of ISO 27001 and ISO/IEC 42001.
This standardised framework provides transparent, structured responses about how we implement and manage key controls across our systems, operations, and AI-related activities. It enables us to demonstrate our approach to information security, data protection, risk management, governance, and responsible AI practices, while protecting sensitive information contained within our internal policies and documentation.
The CAIQ is widely recognised as a trusted alternative to sharing full internal policy documents and supports due diligence against internationally recognised frameworks. Our controls and processes cover essential areas including access control, data protection, encryption, audit and compliance, AI governance, risk assessment, human oversight, data governance, security monitoring, and continual improvement.
Alignment with ISO 27001 demonstrates our commitment to maintaining an effective Information Security Management System (ISMS), while alignment with ISO/IEC 42001 demonstrates our commitment to responsible AI governance through appropriate oversight, accountability, transparency, and risk management of AI technologies.
We’ve created this document to proactively support your due diligence and vendor risk assessment activities. You can review the information below or download the document for easier review and sharing, please scroll to bottom of article.
| Question ISO27001 | Response ISO27001 | Question ISO42001 | Response ISO42001 |
| Are audit and assurance policies, procedures, and standards established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained audit and assurance policies, procedures, and standards as part of our ISO 27001 certified Information Security Management System (ISMS). These policies cover various aspects of security, including access control, data protection, incident response, and compliance with legal and regulatory requirements. Regular audits and reviews are conducted to ensure ongoing compliance and continual improvement of our security practices. | Are audit and assurance policies, procedures, and standards established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained audit and assurance policies, procedures, and standards as part of its ISO 27001 certified Information Security Management System (ISMS). These policies encompass access control, data protection, incident response, and regulatory compliance requirements. Regular audits and reviews are conducted to ensure ongoing compliance and continual improvement of security practices. |
| Are audit and assurance policies, procedures, and standards reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates its audit and assurance policies, procedures, and standards at least annually in accordance with ISO 27001 requirements. This ensures our practices remain aligned with evolving security threats, technological advancements, and regulatory changes. | Are audit and assurance policies, procedures, and standards reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence maintains audit and assurance policies, procedures, and standards that are reviewed and updated at least annually in accordance with ISO 27001 requirements. This process ensures that practices remain aligned with evolving security threats, technological advancements, and regulatory changes, supporting continuous improvement and compliance with industry frameworks such as ISO 27001 and CAIQ. |
| Are independent audit and assurance assessments conducted according to relevant standards at least annually? | Yes, Built Intelligence conducts independent audit and assurance assessments annually in accordance with relevant standards, including ISO 27001 and Cyber Essentials Plus. These assessments are performed by certified third-party auditors to ensure compliance and to identify areas for improvement in our security and compliance posture. | Are independent audit and assurance assessments conducted according to relevant standards at least annually? | Yes, Built Intelligence conducts independent audit and assurance assessments annually in accordance with relevant standards, including ISO 27001 and Cyber Essentials Plus. These assessments are performed by certified third- party auditors to ensure compliance and to identify areas for improvement in the security and compliance posture of the platform. |
| Are independent audit and assurance assessments performed according to risk-based plans and policies? | Yes, Built Intelligence performs independent audit and assurance assessments according to risk-based plans and policies. These assessments are aligned with our ISO 27001 certified Information Security Management System (ISMS) and include regular internal and external audits to ensure compliance with established security standards and practices. The frequency and scope of these audits are determined based on a risk assessment, ensuring that critical areas are reviewed more frequently and in greater depth. | Are independent audit and assurance assessments performed in response to significant changes or emerging risks and according to risk-based plans and policies? | Yes, Built Intelligence performs independent audit and assurance assessments in accordance with risk- based plans and policies. These assessments are aligned with the ISO 27001 certified Information Security Management System (ISMS) and include regular internal and external audits. The scope and frequency of these audits are determined based on a risk assessment, ensuring that critical areas are reviewed more frequently and in greater depth. |
| Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit? | Yes, FastDraft ensures compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit. Our platform adheres to ISO 27001 standards, and we maintain rigorous alignment with GDPR, Cyber Essentials Plus, and other relevant frameworks. We conduct regular internal and external audits to verify compliance and continuously improve our security and data protection practices. | Is compliance verified with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit? | Yes, Built Intelligence ensures compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit process. The platform adheres to ISO 27001 standards and maintains alignment with GDPR, Cyber Essentials Plus, and other relevant frameworks. Compliance is verified through regular internal and external audits, supporting ongoing verification and continuous improvement of security and data protection practices. This approach addresses key requirements for audit, compliance, and risk management typical of recognized frameworks such as ISO 27001 and CAIQ. |
| Is an audit management process defined and implemented to support audit planning, risk analysis, security control assessments, conclusions, remediation schedules, report generation, and reviews of past reports and supporting evidence? | Yes, Built Intelligence has implemented a comprehensive audit management process as part of our ISO 27001 certified Information Security Management System (ISMS). This process supports audit planning, risk analysis, security control assessments, conclusions, remediation schedules, report generation, and reviews of past reports and supporting evidence. Our process ensures continuous improvement and compliance with industry standards and regulatory requirements. | Are Audit Management processes aligned with global auditing standards, defined and implemented to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, review of past reports and supporting evidence? | Yes, Built Intelligence has implemented comprehensive audit management processes that are aligned with global auditing standards, specifically as part of its ISO 27001 certified Information Security Management System (ISMS). The documented audit management process covers the following areas to support robust compliance and governance: - Audit planning- Risk analysis- Security control assessments- Documenting conclusions and findings- Establishing remediation schedules- Report generation- Review of past reports and supporting evidenceThese processes ensure systematic planning, execution, and continuous improvement, adhering to industry best practices. The ISMS framework supports regulatory and CAIQ- aligned control objectives for audit trail maintenance, evidence management, and control remediation. |
| Is a risk-based corrective action plan to remediate audit findings established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained a risk-based corrective action plan to remediate audit findings. This plan is part of our ISO 27001 certified Information Security Management System (ISMS), ensuring systematic review and management of audit findings. The process includes identifying risks, implementing corrective actions, monitoring effectiveness, and making necessary adjustments to enhance our security posture continuously. | Is a risk-based corrective action plan established, documented, approved, communicated, applied, evaluated, and maintained to remediate audit findings, regularly review, and report remediation status to relevant stakeholders? | Yes, Built Intelligence has established a risk- based corrective action plan as part of its ISO 27001 certified Information Security Management System (ISMS). The documented process incorporates the following controls in alignment with CAIQ and ISO 27001 requirements: - The corrective action plan to remediate audit findings is established, documented, approved, communicated, applied, evaluated, and maintained systematically. - This plan ensures that audit findings are addressed based on risk , with corrective actions implemented, monitored for effectiveness, and adjusted as needed to improve the security posture. - The remediation status of audit findings is regularly reviewed and reported to relevant stakeholders. The process uses both internal and external audits, with findings tracked through a compliance management system. These controls demonstrate ongoing compliance, continuous improvement, and effective risk management in line with best practices for AI governance, security, and risk mitigation. |
| Are application security policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained to guide appropriate planning, delivery, and support of the organization's application security capabilities? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained application security policies and procedures. These guide the appropriate planning, delivery, and support of our organization's application security capabilities. Our policies align with ISO 27001 standards and are integrated into our Information Security Management System (ISMS), ensuring continuous improvement and compliance with relevant security requirements. These policies are regularly reviewed and updated to adapt to new security threats and technological changes, ensuring robust application security across our FastDraft platform hosted on Microsoft Azure. | Are policies and procedures for application security established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established a comprehensive approach to application security policies and procedures. Specifically: - Application security policies and procedures are established, documented, and approved.- These policies are effectively communicated and applied to guide the appropriate planning, delivery, and support of the organization's application security capabilities.- Evaluation and continuous maintenance of these policies are conducted within the framework of the organization's Information Security Management System (ISMS), which is aligned with ISO 27001 standards.- Policies and procedures are regularly reviewed and updated to ensure ongoing compliance and adaptability to emerging security threats and technological advancements.This approach supports compliance with key control objectives required by AI governance frameworks, including CAIQ and ISO 27001, by ensuring that application security is both proactive and responsive. |
| Are application security policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates application security policies and procedures at least annually as part of our ISO 27001 certified Information Security Management System (ISMS). This ensures our practices remain aligned with current security standards and regulatory requirements. | Are the policies and procedures for application security reviewed and updated at least annually or upon significant system changes? | Yes, Built Intelligence has established processes to ensure that application security policies and procedures are reviewed and updated at least annually or upon significant system changes. These practices include: - Formal, documented, and approved application security policies aligned with ISO 27001 standards, maintained as part of the organization's Information Security Management System (ISMS).- Regular reviews and updates of these policies to adapt to emerging security threats and technological changes.- Policies are evaluated and maintained on an ongoing basis and explicitly reviewed and updated at least once per year or when there are significant system changes affecting security posture.These controls support continuous compliance and robust application security within the platform. |
| Are baseline requirements to secure different applications established, documented, and maintained? | Yes, baseline security requirements for different applications within FastDraft are established, documented, and maintained in accordance with our Information Security Management System (ISMS), which aligns with ISO 27001 standards. These requirements are regularly reviewed and updated to ensure they meet current security standards and compliance obligations. Additionally, our platform leverages Microsoft Azure's infrastructure, which provides built-in security controls and compliance certifications, further supporting our security posture. | Are baseline requirements for securing applications established, documented, and maintained? | Yes, Built Intelligence has baseline security requirements for applications within are established, documented, and maintained. These requirements are managed in accordance with the Information Security Management System (ISMS) that aligns with ISO 27001 standards. The documentation further specifies that these baselines are regularly reviewed and updated to ensure they meet current security standards and compliance obligations. Additionally, leverages Microsoft Azure’s infrastructure for its platform, benefiting from built- in security controls and compliance certifications. |
| Are technical and operational metrics defined and implemented according to business objectives, security requirements, and compliance obligations? | Yes, Built Intelligence defines and implements technical and operational metrics according to business objectives, security requirements, and compliance obligations. These metrics are aligned with our ISO 27001 certified Information Security Management System (ISMS) and are designed to ensure continuous monitoring and improvement of our security posture. Metrics include system performance, incident response times, compliance audit results, and user activity logs, all of which are regularly reviewed and reported to ensure alignment with our business objectives and compliance with GDPR and other regulatory requirements. | Are technical and operational metrics defined and implemented in alignment with business objectives, security requirements, and compliance obligations? | Yes, Built Intelligence defines and implements technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations. these metrics are established as part of ’s ISO 27001 certified Information Security Management System (ISMS). Metrics tracked include system performance, incident response times, compliance audit results, and user activity logs. These are regularly reviewed and reported to ensure continuous monitoring, improvement, and adherence to business objectives and regulatory requirements such as GDPR. - Alignment with ISO 27001 ISMS provides a structured approach to defining and maintaining compliance and security metrics.- Regular review and reporting processes support ongoing adherence to compliance and risk management frameworks.- Metrics are selected and implemented specifically to cover technical performance, security, and compliance domains. |
| Is an SDLC process defined and implemented for application design, development, deployment, and operation per organizationally designed security requirements? | Yes, Built Intelligence has a defined and implemented Software Development Life Cycle (SDLC) process for application design, development, deployment, and operation that adheres to organizationally designed security requirements. This process is detailed in our SDLC documentation and is aligned with ISO 27001 controls, ensuring continuous improvement and compliance with our security and quality management standards. | Is a secure software development lifecycle (SDLC) process defined and implemented for application requirements analysis, planning, design, development, testing, deployment, and operation in accordance with security requirements defined by the organization? | Yes, Built Intelligence implements a defined and secure Software Development Life Cycle (SDLC) process for application requirements analysis, planning, design, development, testing, deployment, and operation. Key controls and practices include: - Integration of security checkpoints throughout the SDLC, including requirements gathering, design reviews, code reviews, and testing phases.- Use of static code analysis, peer reviews with a focus on security, and security testing (including vulnerability scanning) prior to deployment.- Alignment of SDLC processes and security controls with ISO 27001 standards, ensuring that organizational security and compliance requirements are incorporated at each phase of the lifecycle.- Continuous monitoring and regular updates to application dependencies based on security advisories (such as OWASP).- Comprehensive vulnerability management practices, including automated dependency scanning, static and dynamic code analysis, regular penetration testing, and peer reviews, all supporting effective risk mitigation and compliance with ISO 27001 and Cyber Essentials Plus.- Operational and technical metrics are established and regularly reviewed to monitor ongoing compliance and performance against security requirements.These measures collectively support robust AI governance, security, and risk mitigation objectives across the software development process. |
| Does the testing strategy outline criteria to accept new information systems, upgrades, and new versions while ensuring application security, compliance adherence, and organizational speed of delivery goals? | Yes, FastDraft employs a comprehensive testing strategy that outlines criteria for accepting new information systems, upgrades, and new versions. This strategy ensures application security and compliance adherence while meeting organizational speed of delivery goals. Our approach includes automated and manual testing phases, security scans, compliance checks, and performance benchmarks, all integrated into our CI/CD pipeline managed on Microsoft Azure DevOps. This process aligns with our ISO 27001 and Cyber Essentials Plus certifications, ensuring that each release is secure, compliant, and delivered efficiently. | Is a testing strategy implemented, including criteria for acceptance of new information systems, upgrades, and new versions, to provide application security assurance, maintain compliance, and meet organizational delivery goals? | Yes, Built Intelligence has employs a comprehensive testing strategy that defines criteria for the acceptance of new information systems, upgrades, and new versions. The key features relevant to AI governance, risk, and compliance include: - Security Assurance:The testing strategy incorporates both automated and manual testing phases, including security scans, compliance checks, and performance benchmarks to ensure application security. - Compliance Adherence:The process is aligned with ISO 27001 and Cyber Essentials Plus certifications, ensuring that compliance objectives are met as part of each release cycle. - Organizational Delivery Goals:The strategy is integrated within the CI/CD pipeline managed on Microsoft Azure DevOps, supporting organizational speed of delivery without compromising security or compliance. - Release Acceptance:Defined acceptance criteria are used to evaluate new systems, upgrades, and versions before deployment. These controls collectively ensure robust governance over changes and releases, supporting both regulatory compliance and overall risk mitigation. |
| Is testing automated when applicable and possible? | Yes, FastDraft employs automated testing where applicable and possible, utilizing Microsoft Azure DevOps for continuous integration and deployment. Automated tests include unit tests, integration tests, and UI tests to ensure code quality and functionality before deployment. This approach aligns with industry best practices to maintain high standards of software reliability and performance. | Is automation applied where applicable and possible? | Yes, Built Intelligence implements automation in its testing processes where applicable and possible. Specifically, utilizes Microsoft Azure DevOps for continuous integration and continuous deployment (CI/CD), incorporating automated tests such as unit tests, integration tests, and UI tests. This automation ensures code quality and functionality before deployment, aligning with industry best practices and supporting robust software reliability and performance. These controls support compliance objectives in line with CAIQ and ISO 27001 requirements for automated testing and secure deployment practices. |
| Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner? | Yes, FastDraft employs secure, standardized, and compliant strategies for deploying application code. We utilize Microsoft Azure DevOps for continuous integration and continuous deployment (CI/CD), ensuring that code is tested and deployed in a controlled and repeatable manner. Our deployment processes are aligned with ISO 27001 standards, incorporating automated security scans and code reviews to maintain code integrity and security. Additionally, we adhere to Microsoft's best practices for Azure, further enhancing our deployment security and compliance. | Are strategies and capabilities established and implemented for secure, standardized, and compliant application deployment? | Yes, Built Intelligence has established and implemented strategies and capabilities to ensure secure, standardized, and compliant application deployment. Key practices include: - Hosting on Microsoft Azure PaaS infrastructure, leveraging Azure’s built- in security, monitoring, resilience, and compliance capabilities.- Established, documented, approved, communicated, and maintained application security policies and procedures aligned with ISO 27001 standards and integrated into a formal Information Security Management System (ISMS).- Regular reviews and updates of security policies and procedures to address emerging threats and changes in technology.- Continuous monitoring and management of vulnerabilities, including the application of secure coding practices, dependency checks, security scans, and penetration testing as part of the application lifecycle.- Assignment, monitoring, and reporting of compliance actions and audit findings to stakeholders, ensuring transparency and accountability in deployment and operations.These measures collectively support secure, standardized, and compliant deployment in alignment with recognized best practices and AI governance requirements. |
| Are application security vulnerabilities remediated following defined processes? | Yes, Built Intelligence follows defined processes for remediating application security vulnerabilities, aligned with our ISO 27001 certified Information Security Management System (ISMS). Our process includes identification through regular security scans and penetration testing, risk assessment, prioritization based on severity, and remediation through secure coding updates or configuration changes. All changes are tested in a staging environment before deployment to production. This systematic approach ensures vulnerabilities are addressed promptly and effectively, minimizing potential risks to our platform and customer data. | Are processes defined and implemented to remediate application security vulnerabilities, automating remediation when possible? | Yes, Built Intelligence has defined and implemented processes to remediate application security vulnerabilities, and automates remediation when possible. Specifically: - follows defined processes for vulnerability remediation, aligned with an ISO 27001 certified Information Security Management System (ISMS).- Processes include identification through regular security scans and penetration testing, risk assessment, prioritization based on severity, and remediation via secure coding updates or configuration changes.- Remediation is automated where possible. The platform leverages Microsoft Azure's integrated security tools (Azure Security Center, Azure Defender) to automatically apply patches and security updates to underlying PaaS services.- Automated dependency checks and security scanning are integrated into CI/CD pipelines to identify and address vulnerabilities before deployment.- Automated alerts are configured for high- severity issues to ensure the security team is notified for immediate action.These practices are aligned with ISO 27001 and Cyber Essentials Plus standards, supporting proactive vulnerability management and continuous security improvement. |
| Is the input against adversarial patterns, failure patterns and unwanted behaviour, validated, filtered, modified, or blocked as necessary, according to organisational policies, applicable laws and regulations? | Yes, Built Intelligence applies layered safeguards to validate and control user inputs to reduce adversarial prompts, failure patterns, and misuse. - Inputs are validated and filtered for prohibited content and policy violations. - Authentication, rate limiting, and monitoring help detect and respond to abuse. - Where third-party foundation models are used, provider safety controls are enabled and monitored. - Controls are reviewed to remain aligned with applicable laws and regulations. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the output against adversarial patterns, failure patterns and unwanted behaviour, validated, filtered, modified, or blocked as necessary, according to organisational policies, applicable laws and regulations? | Yes, Built Intelligence implements controls to review and constrain model outputs to reduce harmful, unsafe, or policy-violating responses. - Output filtering and safety checks are applied where feasible based on the use case. - Logging and monitoring support detection of anomalous or unsafe output patterns. - Where third-party foundation models are used, provider content safety capabilities are leveraged. - Governance processes ensure alignment with applicable laws and regulations. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures and technical measures to secure APIs, including authorization flaws, API key management, regular security testing, defined, implemented and evaluated? | Yes, Built Intelligence has defined and implemented API security controls to address authorization flaws, API key management, and ongoing security testing. - Strong authentication and authorization (least privilege, role-based access control) are enforced. - Secrets and API keys are managed centrally with rotation and access logging. - APIs are protected by network controls, throttling, and monitoring. - Regular vulnerability scanning and penetration testing are performed to validate effectiveness. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are technical measures for any improvements reviewed and updated at least annually or after significant system changes? | Yes, Built Intelligence reviews and updates its technical measures at least annually or following significant system changes. Specifically, the platform maintains policies and procedures for the relocation or transfer of hardware, software, or data/information, which are reviewed and updated annually as part of its ISO 27001 certified Information Security Management System (ISMS). Additionally, annual penetration testing and vulnerability assessments are conducted—extra tests are performed when significant feature or architectural changes occur—to ensure that all technical controls remain current, effective, and aligned with security and compliance best practices. - Annual review of technical and operational procedures (ISO 27001 ISMS compliance)- Routine vulnerability scanning and annual/triggered penetration testing- Immediate updates to controls in response to operational, technological, or threat landscape changes | ||
| Are the security boundaries for agents established? | Yes, Built Intelligence establishes logical security boundaries for AI/agent components to limit access to data and functions. - Components operate under least privilege and are segmented by environment (development, staging, production). - Access to tools, data sources, and external services is explicitly controlled and logged. - Administrative actions require elevated approvals and are reviewed. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are source code management practices, such as version control, code review and static code analysis, implemented and aligning with the SDLC process? | Yes, Built Intelligence has implemented the following source code management practices aligned with its Software Development Life Cycle (SDLC) process: - Version control:All code changes are managed through Git, ensuring traceability and control of source code versions. - Code review:Mandatory peer reviews are required for all code changes, supporting quality assurance and reducing the likelihood of introducing vulnerabilities. - Static code analysis:Static code analysis tools are used as part of the CI/CD process to identify and mitigate potential security issues in the codebase. - Integration with SDLC:These practices are embedded throughout a formal and structured SDLC that covers requirements gathering, design, development, testing (including automated and manual QA), deployment, and post- release monitoring, ensuring alignment with industry best practices and control objectives (such as those found in ISO 27001 and CAIQ frameworks). This evidence demonstrates a strong commitment to software quality, security, and risk mitigation within the development process. | ||
| Are sandboxing techniques implemented to execute AI tools and plugins in isolated environments to prevent unintended interactions with critical systems or data and to limit the possibility of lateral movement? | Yes, Built Intelligence uses isolation controls for executing higher-risk processing tasks to reduce unintended interactions with critical systems or data. - Execution is constrained using environment separation, least-privilege identities, and network controls. - Where tooling/plugins are enabled, permissions are scoped and activity is logged. - Security testing and change control are applied before introducing new integrations. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are security measures implemented to protect cache systems in GenAI systems and services? | Yes, Built Intelligence protects cache and transient storage used by the service through standard security controls. - Cached data is protected by access controls and environment segregation. - Encryption in transit and at rest is used where supported by the underlying platform services. - Retention is minimized (time-to-live/expiry) to reduce unnecessary persistence of sensitive data. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are mechanisms implemented to enable the model to clearly distinguish user-provided input instructions from data and system instructions (e.g., system prompts)? | Yes, Built Intelligence implements prompt and instruction handling patterns designed to separate system instructions from user-provided inputs. - System instructions are maintained server-side and are not editable by end users. - User inputs are clearly delimited and handled as data, with validation and policy checks applied. - Tool/function access is restricted to explicitly permitted actions and is logged. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained business continuity management and operational resilience policies and procedures. These are aligned with ISO 27001 standards and are regularly reviewed and tested to ensure they remain effective and appropriate to the organizational needs and compliance requirements. | Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained business continuity management and operational resilience policies and procedures. These policies are aligned with ISO 27001 standards and are regularly reviewed and tested to ensure they remain effective and appropriate to the organization’s needs and compliance requirements. This approach supports core control objectives for business continuity and aligns with best practices for operational resilience within AI governance and risk management frameworks. |
| Are the policies and procedures reviewed and updated at least annually? | Yes, the policies and procedures are reviewed and updated at least annually to ensure they remain effective and compliant with current regulations and standards. This is in line with our commitment to maintaining high standards of security and compliance, as outlined in our internal documentation and governance frameworks. | Are policies and procedures reviewed and updated at least annually, or when significant changes occur that could impact risk exposure? | Yes, Built Intelligence ensures that policies and procedures—specifically in the domains of cryptography, encryption, and key management—are reviewed and updated at least annually. This review process is managed by the Information Security Team, in accordance with ISMS policies aligned with ISO 27001 standards. The reviews are conducted to address emerging risks, technological changes, and significant changes to the business environment that may impact risk exposure. - Annual review of cryptography, encryption, and key management policies is explicitly confirmed.- Procedures are updated as necessary in response to significant changes and evolving risks.This practice supports compliance with AI governance, risk management, and information security frameworks, meeting control objectives for periodic review and adaptability to changes in risk exposure. |
| Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts? | Yes, the criteria for developing business continuity and operational resiliency strategies and capabilities at Built Intelligence are established based on business disruption and risk impacts. Our Business Continuity Plan (BCP) and operational resiliency strategies are informed by thorough risk assessments and business impact analyses, as outlined in our ISMS documentation. These assessments consider various disruption scenarios and their potential impacts on our operations, ensuring that our strategies are robust and effective in maintaining critical functions and protecting information assets during adverse situations. | Is the impact of business disruptions and risks determined to establish criteria for developing business continuity and operational resilience strategies and capabilities? | Yes, Built Intelligence establishes criteria for developing business continuity and operational resilience strategies and capabilities by determining the impact of business disruptions and risks. Specifically, the platform conducts thorough risk assessments and business impact analyses, as outlined in their Information Security Management System (ISMS) documentation. These assessments consider various disruption scenarios and their potential operational impacts, ensuring that the resulting strategies are robust and effective for maintaining critical functions and protecting information assets during adverse situations. This approach aligns with control objectives found in ISO 27001 and CAIQ for risk- based business continuity planning. |
| Is the risk assessment and impact analysis, reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence ensure that risk assessments and impact analyses are reviewed and updated at least annually, or upon significant changes. Specifically, the organization's risk management framework aligns with ISO 27001 and ISO 9001 standards and includes: - Regular risk assessments covering security, compliance, system availability, and data integrity.- Annual penetration testing, with additional tests commissioned after major feature releases or significant architectural changes.- Continuous operational and enterprise risk management to address emerging risks and evolving business environments.- Systematic integration of risk management processes into governance frameworks, with periodic monitoring and review.Therefore, the controls for scheduled and event- driven (significant change) updates to risk assessment and impact analysis are explicitly addressed. | ||
| Are strategies developed to reduce the impact of, withstand, and recover from business disruptions in accordance with risk appetite? | Yes, FastDraft has developed strategies to reduce the impact of, withstand, and recover from business disruptions in accordance with our risk appetite. These strategies are aligned with our Business Continuity Plan (BCP) and Disaster Recovery (DR) protocols, which are part of our ISO 27001 certified Information Security Management System (ISMS). We conduct regular risk assessments and business impact analyses to ensure that our strategies are effective and compliant with industry standards. Additionally, our hosting on Microsoft Azure provides robust infrastructure resilience, including geo-redundant storage and backup solutions, to support our continuity strategies. | Are strategies established to reduce the impact of business disruptions, and improve resiliency and recovery from business disruptions? | Yes, Built Intelligence has established comprehensive strategies to reduce the impact of business disruptions and enhance operational resiliency and recovery. These include: - Implementation of a Business Continuity Plan (BCP) and Disaster Recovery (DR) protocols as part of an ISO 27001 certified Information Security Management System (ISMS).- Regular risk assessments and business impact analyses to align strategies with risk appetite and ensure effective handling of various disruption scenarios.- Utilization of Microsoft Azure for hosting, leveraging geo- redundant storage and backup solutions to provide robust infrastructure resilience and support continuity strategies.- Establishment of Recovery Time Objectives (RTO) of 8 hours and Recovery Point Objectives (RPO) of 48 hours, with documented procedures regularly tested and reviewed.- Integration of operational resilience strategies and results into business continuity planning, with systematic identification, evaluation, and management of risks through Operational Risk Management (ORM) and Enterprise Risk Management (ERM).These controls are designed and maintained in accordance with industry standards and best practices, helping to ensure business continuity, data integrity, and rapid recovery in the event of disruptions. |
| Are operational resilience strategies and capability results incorporated to establish, document, approve, communicate, apply, evaluate, and maintain a business continuity plan? | Yes, Built Intelligence incorporates operational resilience strategies and capability results to establish, document, approve, communicate, apply, evaluate, and maintain a business continuity plan as outlined in our ISMS DOC ORG09. This plan is regularly updated and tested to ensure it remains effective and compliant with ISO 27001 standards. The plan includes detailed procedures for responding to incidents, ensuring information security continuity, and recovering IT systems at an alternative location within a specified timeframe. | Is a business continuity plan - based on the results of operational resilience strategies and capabilities - established, documented, approved, communicated, applied, evaluated and maintained? | Yes, Built Intelligence have established a business continuity plan that is aligned with operational resilience strategies and capabilities. The documentation confirms the following controls and practices: - The business continuity management and operational resilience policies and procedures areestablished, documented, approved, communicated, applied, evaluated, and maintained. - These policies are reviewed and updated at least annually to ensure they align with ISO 27001 standards and current compliance requirements.- The continuity plan is tested and reviewed regularly, with outcomes documented to ensure appropriateness and effectiveness in line with organizational needs and regulatory standards.- The documented approach includes both business continuity and disaster recovery (BC/DR) for all critical services, with specific Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).These practices meet recognized AI governance and risk management framework objectives for operational resilience, business continuity, and documented control implementation. |
| Is relevant documentation developed, identified, and acquired to support business continuity and operational resilience plans? | Yes, FastDraft has developed, identified, and acquired relevant documentation to support business continuity and operational resilience plans. This includes our Business Continuity Plan (ISMS DOC ORG09), which outlines procedures for IT system recovery at alternative locations, maintaining operations during disruptions, and ensuring information security continuity. Additionally, we utilize Microsoft Azure's robust infrastructure, which includes built-in disaster recovery and high availability features, further supporting our operational resilience. | Is relevant documentation, both internal and from external parties, for supporting the business continuity and operational resilience programs, developed, identified, and acquired? | Yes, Built Intelligence has developed, identified, and acquired relevant documentation to support business continuity and operational resilience programs. This includes the Business Continuity Plan , which outlines procedures for IT system recovery at alternative locations, maintaining operations during disruptions, and ensuring information security continuity. Additionally, the platform leverages Microsoft Azure's infrastructure, which provides built- in disaster recovery and high availability features. These measures ensure operational resilience and support both internal and external documentation requirements. |
| Is business continuity and operational resilience documentation available to authorized stakeholders? | Yes, business continuity and operational resilience documentation is available to authorized stakeholders. Access to such documentation is controlled through role-based access permissions to ensure that only authorized personnel have access to sensitive information. This documentation is classified as restricted and is subject to data protection legislation to ensure confidentiality and integrity. | Is the documentation available to authorized stakeholders and reviewed at least annually or upon significant changes.? | Yes, Built Intelligence maintains comprehensive data flow documentation and data ownership/stewardship records as part of its Information Security Management System (ISMS), which aligns with ISO 27001 standards. The documentation is: - Made available to authorized stakeholders.- Reviewed at defined intervals, at least annually, and after any significant change, to ensure continued accuracy and compliance.This review process is explicitly part of operational controls and is conducted to ensure the ongoing relevance of documentation related to data processing, storage, transmission, and stewardship. These practices meet control requirements for documentation management, review cycles, and stakeholder accessibility, consistent with CAIQ and ISO 27001 compliance expectations. |
| Are the business continuity and operational resilience plans exercised and tested at least annually and when significant changes occur? | Yes, Built Intelligence exercises and tests its business continuity and operational resilience plans annually and when significant changes occur, in alignment with ISO 27001 and our internal ISMS policies. These tests include tabletop exercises, scenario testing, and full recovery simulations to ensure that our response procedures are effective and that staff are familiar with their roles in such events. The results are reviewed to identify any necessary improvements to our plans. | Is a structured approach to evaluate the effectiveness of the business continuity and operational resilience plans, followed at planned intervals or upon significant changes? | Yes, Built Intelligence follows a structured approach to evaluate the effectiveness of its business continuity and operational resilience plans. incorporates operational resilience strategies and capability results to establish, document, approve, communicate, apply, evaluate, and maintain a business continuity plan, as outlined in. This plan is regularly updated and tested to ensure that it remains effective and compliant with ISO 27001 standards. The plan includes detailed procedures for responding to incidents, ensuring information security continuity, and recovering IT systems at an alternative location within a specified timeframe. This demonstrates alignment with control objectives for ongoing plan evaluation in compliance frameworks such as ISO 27001 and CAIQ operational resilience requirements. |
| Do business continuity and resilience procedures establish communication with stakeholders and participants? | Yes, the business continuity and resilience procedures established by Built Intelligence include comprehensive communication strategies with stakeholders and participants. These procedures are detailed in our Business Continuity Plan (ISMS DOC ORG09), which outlines how communication within the organization and with external parties will be handled during a disruptive incident. This includes maintaining effective communication with all relevant stakeholders and ensuring that information released to third parties is managed to be timely and accurate. The plan specifies the use of telephone and email as primary communication methods, with detailed guidelines to ensure clarity and accuracy in all communications. | Are communication channels with all relevant stakeholders established and maintained in the course of business continuity and resilience procedures? | Yes, Built Intelligence maintains defined communication channels for relevant stakeholders as part of business continuity and resilience procedures. - Up-to-date contact lists and escalation paths are maintained for operational, security, and executive stakeholders. - Incident and disruption communications follow documented playbooks, including customer notification where applicable. - Exercises and reviews validate that communication procedures remain effective. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is cloud data periodically backed up? | Yes, cloud data on FastDraft is periodically backed up. We utilize Microsoft Azure's robust backup services, ensuring data is backed up with a default frequency and retention policy that aligns with our RPO (Recovery Point Objective) commitments. Custom backup frequencies and retention periods can be configured based on specific client requirements during the implementation phase. | Are backups periodically performed? | Yes, Built Intelligence implements periodic backups as part of its data resilience and security approach. Specifically: - Backups and archiving are performed according to Azure best practices, with geo- redundant storage (GRS) and point- in- time recovery (PITR) for up to 35 days.- Zone- redundant storage (ZRS) and automatic failover are used to ensure high availability and data integrity.- All backups are AES- 256 encrypted at rest and protected in transit using TLS 1.2/1.3.- Azure Site Recovery (ASR) supports disaster recovery to minimize downtime, maintaining both Recovery Point Objective (RPO) and Recovery Time Objective (RTO) of 8 hours.These controls are consistently applied across both ’s internal operations and subcontractors, supporting compliance with ISO 27001 requirements for backup and data retention. |
| Is the confidentiality, integrity, and availability of backup data ensured? | Yes, the confidentiality, integrity, and availability of backup data are ensured through a combination of Microsoft Azure’s built-in security features and our own stringent data management policies, aligned with ISO 27001 and Cyber Essentials Plus standards. Backup data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher. We utilize Azure’s geo-redundant storage (GRS) to ensure high availability and resilience against data loss. Access to backup data is strictly controlled through role-based access controls (RBAC) and multi-factor authentication (MFA), ensuring that only authorized personnel can access sensitive backup information. Regular audits and compliance checks further reinforce the security and integrity of our backup processes. | Is the confidentiality, integrity and availability of the backup, ensured and data restoration from backup verified for resiliency? | Yes, Built Intelligence has the confidentiality, integrity, and availability of backup data within are ensured through the following controls, in line with ISO 27001 and Cyber Essentials Plus standards: - Backup data is encrypted at rest using AES- 256 and in transit using TLS 1.2 or higher.- Backups utilize Microsoft Azure’s geo- redundant storage (GRS) for high availability and resilience against data loss.- Access to backup data is strictly managed through role- based access controls (RBAC) and multi- factor authentication (MFA), ensuring only authorized personnel can access backups.- Regular audits and compliance checks are conducted to maintain ongoing security and integrity.- Appropriate backup restoration is routinely tested leveraging Azure's disaster recovery capabilities, confirming data can be restored accurately and promptly. These procedures are verified through automated and manual recovery drills as part of a formal backup policy aligned to ISO 27001.These practices collectively address CAIQ controls related to data backup, encryption, access management, and resiliency validation. |
| Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters? | Yes, Built Intelligence has established, documented, approved, applied, evaluated, and maintained a disaster response plan to ensure recovery from natural and man-made disasters. This plan is part of our Business Continuity Plan (BCP) and Disaster Recovery (DR) strategies, which are aligned with ISO 27001 standards and tested annually to ensure effectiveness. The plan includes detailed recovery procedures for IT systems at alternative locations, maintains information security controls during adverse situations, and is continually updated based on risk assessments and test results. | Is a disaster response plan to recover from natural and man-made disasters established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence have a comprehensive disaster response plan that addresses recovery from both natural and man- made disasters. The plan exhibits the following control measures in line with ISO 27001 and CAIQ best practices: - Established and Documented:The disaster response plan is formally established, documented, and forms a core part of 's overall Business Continuity Plan (BCP) and Disaster Recovery (DR) strategies. - Approved and Applied:The plan is approved at the organisational level and is actively applied to maintain service resilience. - Evaluated and Maintained:The disaster response plan is evaluated and tested annually, and whenever significant changes to business or infrastructure occur. Updates are made to ensure ongoing relevance and effectiveness. - Communication:The disaster response plan includes provisions for timely and appropriate communication with relevant internal stakeholders and impacted external parties, supporting coordinated response efforts and maintaining transparency during incidents. - Control Objectives Met:The plan includes detailed recovery procedures, ensures continued information security controls during incidents, and maintains ISO 27001 alignment throughout crisis events. This demonstrates adherence to AI governance risk and resiliency controls, supporting compliance with key business continuity and DR requirements. |
| Is the disaster response plan updated at least annually, and when significant changes occur? | Yes, Built Intelligence Ltd’s business continuity plans, including the disaster response plan, are tested and updated on an annual basis. Additionally, the plans are revised when significant changes occur in the business or infrastructure, ensuring they remain current and effective. This process is part of our commitment to maintaining robust business continuity and disaster recovery strategies. | Is the Disaster Response Plan updated at least annually or upon significant changes? | Yes, Built Intelligence has a Disaster Response Plan which is updated at least annually and whenever significant changes occur within the business or infrastructure. This is part of their business continuity and disaster recovery framework, which is aligned with ISO 27001 standards. The procedures are tested and updated regularly to ensure current and effective response capabilities. |
| Is the disaster response plan exercised annually or when significant changes occur? | Yes, Built Intelligence's disaster response plan is exercised annually and when significant changes occur, ensuring continuous improvement and readiness in alignment with ISO 27001 and our internal business continuity policies. This regular testing helps us to identify and address potential gaps in our response strategies and maintain a high level of resilience. | Is a structured approach to evaluate the effectiveness of the disaster response plan followed at planned intervals or upon significant changes, including, if possible, participation of local emergency authorities? | Yes, Built Intelligence follows a structured approach to evaluate and improve the disaster response plan at planned intervals and after significant changes. - Tabletop exercises and recovery tests validate roles, runbooks, and recovery objectives. - Lessons learned are captured and tracked through corrective actions. - Where appropriate, external dependencies and stakeholders are included in testing scenarios. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is business-critical equipment supplemented with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards? | Yes, FastDraft is hosted on Microsoft Azure, which employs redundancy and failover mechanisms across geographically distributed data centers to ensure business-critical equipment is supplemented as per industry standards. Azure's architecture supports high availability and disaster recovery, aligning with industry best practices and compliance requirements. | Are business-critical equipment supplemented with both locally redundant and geographically dispersed equipment located at a reasonable minimum distance in accordance with applicable industry standards? | Yes, Built Intelligence’s service architecture leverages cloud resilience capabilities to support local redundancy and geographic dispersion for business-critical services. - Hosting on Microsoft Azure enables use of redundant components and region-level resiliency options. - Backups and recovery processes support defined recovery objectives. - Resilience controls are reviewed through periodic testing and change management. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are risk management policies and procedures associated with changing organizational assets including applications, systems, infrastructure, configuration, etc., established, documented, approved, communicated, applied, evaluated and maintained (regardless of whether asset management is internal or external)? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained risk management policies and procedures associated with changing organizational assets including applications, systems, infrastructure, and configurations. These procedures are part of our ISO 27001 compliant Information Security Management System (ISMS) and are integrated into our change management processes as outlined in the Operations (ISMS DOC TEC01). This includes handling changes due to incidents, new installations, upgrades, and compliance with new legislation or business requirements. All changes undergo risk assessments and are subject to approval and review processes to ensure security and compliance, whether managed internally or by external providers. | Are policies and procedures for managing the risks associated with applying changes to assets owned, controlled or used by the organization, established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for managing the risks associated with applying changes to organizational assets. These controls are based on an ISO 27001- compliant Information Security Management System (ISMS) and are integrated into the change management process. The procedures cover changes to applications, systems, infrastructure, and configurations, including changes due to incidents, new installations, upgrades, and compliance requirements. All changes undergo risk assessments, are subject to approval and review processes, and are regularly reviewed and updated at least annually to ensure continued effectiveness and compliance. |
| Are the policies and procedures reviewed and updated at least annually? | Yes, FastDraft's policies and procedures are reviewed and updated at least annually to ensure compliance with industry standards and regulatory requirements. This regular review process is part of our commitment to maintaining robust security and compliance standards, as outlined in our internal documentation and supported by our ISO 27001 certification. | Are the policies and procedures reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence ensures that key security policies and procedures—including cryptography, encryption, and key management—are reviewed and updated at least annually. The reviews are conducted by the Information Security Team in accordance with ISMS policies and ISO 27001 standards, and they are updated as necessary to address emerging risks or changes to the business environment. This control promotes ongoing compliance and reduces risks associated with outdated security protocols. |
| Is a defined quality change control, approval and testing process (with established baselines, testing, and release standards) followed? | Yes, FastDraft follows a defined quality change control, approval, and testing process with established baselines, testing, and release standards. Our development and release processes are managed through Microsoft Azure DevOps, which supports continuous integration and delivery pipelines, ensuring that all changes are tested and approved before deployment. We adhere to strict testing protocols including unit testing, integration testing, and user acceptance testing to maintain high-quality standards. Additionally, our processes are aligned with ISO 27001 standards to ensure compliance and security in all changes and releases. | Is a defined quality change control, approval and testing process incorporating baselines, testing and release standards, established, maintained and implemented? | Yes, Built Intelligence has a defined and maintained quality change control, approval, and testing process, which includes: - Change Control:Changes are managed through a formal change control process that is part of the platform’s ISO 27001 compliant Information Security Management System (ISMS). - Approval Process:All changes require formal approval and documentation before deployment, and high- risk changes require additional scrutiny and rollback plans. - Testing Standards:Code changes are subject to peer review, automated vulnerability scanning, and thorough testing in staging environments (using Microsoft Defender for Cloud) before production release. - Baselines and Versioning:System developments and releases use a three- tier versioning methodology (major, minor, patches), with major releases exposed to user acceptance testing (UAT) prior to deployment. - Release Communication:Customers are informed of releases via detailed notes and given access to UAT environments to test and validate major updates in advance. All these controls are implemented under the oversight of ISO 27001 processes, ensuring alignment with industry best practices, and supporting audit, security, and compliance objectives. |
| Are risks associated with changing organizational assets (including applications, systems, infrastructure, configuration, etc.) managed, regardless of whether asset management occurs internally or externally (i.e., outsourced)? | Yes, Built Intelligence manages risks associated with changing organizational assets, including applications, systems, infrastructure, and configurations, whether managed internally or outsourced. Our ISO 27001 certified Information Security Management System (ISMS) includes a structured change management process that encompasses risk assessment, impact analysis, and approval procedures for all changes to our assets. This process ensures that all changes are reviewed for security implications and that appropriate controls are implemented to mitigate risks. Additionally, our subcontractors and supply chain partners are required to adhere to the same stringent security controls and processes, ensuring consistency and security across all managed assets. | Is a change management procedure implemented to manage the risks associated with applying changes to assets owned, controlled or used by the organization? | Yes, Built Intelligence implements a documented change management procedure to manage risks associated with applying changes to assets owned, controlled, or used by the organization. : - Risk management policies and procedures are established, documented, approved, communicated, applied, evaluated, and maintained for organizational assets including applications, systems, infrastructure, and configurations.- These procedures form part of an ISO 27001 compliant Information Security Management System (ISMS) and are integrated into overall change management processes.- All changes undergo risk assessments and are subject to approval and review processes to ensure security and compliance, addressing changes due to incidents, new installations, upgrades, or new compliance or business requirements.- Changes are assessed for security risks using threat modelling, security analysis, peer code reviews, and automated testing prior to approval and deployment.- Procedures and policies are reviewed and updated at least annually.These controls align with CAIQ and ISO 27001 requirements for the management and mitigation of risks associated with asset changes. |
| Is the unauthorized addition, removal, update, and management of organization assets restricted? | Yes, the unauthorized addition, removal, update, and management of organization assets are restricted on the FastDraft platform. We enforce strict role-based access controls (RBAC) that ensure only authorized personnel have the necessary permissions to manage assets. These controls are implemented both at the application level within FastDraft and at the infrastructure level through Microsoft Azure's security management features. Additionally, all actions taken on assets are logged and monitored to ensure compliance and to facilitate audits. | Are procedures implemented and enforced to authorize the addition, removal, update, and management of assets owned, controlled, or used by the organization? | Yes, Built Intelligence enforces stringent procedures to authorize the addition, removal, update, and management of organizational assets. The controls are as follows: - Role- Based Access Controls (RBAC):Strict RBAC mechanisms ensure that only authorized personnel can manage assets on the platform. - Application and Infrastructure Level Controls:These controls are implemented both within the application and at the infrastructure level, utilizing Microsoft Azure's security management features. - Logging and Monitoring:All actions performed on assets are logged and monitored, providing traceability and enabling compliance audits. - Change Management:A structured change management process as part of the ISO 27001 certified Information Security Management System (ISMS) includes risk assessment, impact analysis, and formal approval procedures for any asset changes, regardless of whether management is internal or outsourced. These procedures align with best practices in AI governance and ISO 27001/CAIQ requirements for asset authorization, change management, and access restrictions. |
| Are provisions to limit changes that directly impact CSC-owned environments and require tenants to authorize requests explicitly included within the service level agreements (SLAs) between CSPs and CSCs? | Yes, provisions to limit changes that directly impact CSC-owned environments and require tenants to authorize requests are explicitly included within the service level agreements (SLAs) between cloud service providers (CSPs) and cloud service customers (CSCs). These provisions ensure that any significant changes to the hosted environment, including updates or modifications that could affect the CSC-owned environments, are only conducted with prior approval from the tenant. This is part of our commitment to maintaining the integrity and security of tenant environments and aligns with our ISO 27001 and SOC 2 Type 2 compliance frameworks. | Are provisions included that limit changes directly impacting customer owned environments/tenants to explicitly authorized requests within service level agreements? | Yes, Built Intelligence includes explicit provisions in its service level agreements (SLAs) that limit changes directly impacting customer- owned environments or tenants to only those requests that are explicitly authorized by the tenant. These provisions ensure that any significant modifications, updates, or changes to hosted environments affecting customer- controlled resources are conducted solely with prior tenant approval. This aligns with the platform’s commitments to integrity and security under ISO 27001 and SOC 2 Type 2 compliance frameworks. |
| Are change management baselines established for all relevant authorized changes on organizational assets? | Yes, change management baselines are established for all relevant authorized changes on organizational assets within the FastDraft platform, hosted on Microsoft Azure. Our change management process is aligned with industry best practices and is documented in our internal ISMS policies. This process ensures that all changes are reviewed, tested, approved, and documented before implementation to maintain the integrity and security of the platform. Azure's infrastructure also supports robust change management capabilities, further ensuring the stability and security of our services. | Are change management baselines established for all relevant authorized changes on organization assets? | Yes, Built Intelligence change management baselines are established for all relevant authorized changes on organizational assets within the platform, which is hosted on Microsoft Azure. The documentation specifies that ’s change management process is aligned with industry best practices and documented in internal ISMS policies. This process ensures the following: - All changes are reviewed, tested, approved, and documented before implementation.- The integrity and security of the platform are maintained through these controls.- Azure’s underlying infrastructure further supports robust change management capabilities, contributing to the stability and security of services.These practices support compliance objectives for ISO 27001 and industry- aligned AI governance and risk management frameworks, addressing controls related to asset management, security, and operational integrity. |
| Is the change management baseline reviewed an updated at least annually or upon significant changes? | Yes, Built Intelligence maintains a formal change management process that aligns with ISO 27001 standards. According to the _Security & Compliance: Our CAIQ Document_ , data flow documentation—which is a key component of the change management baseline—is reviewed at defined intervals, at least annually, and after any significant change. This process ensures ongoing compliance, accuracy, and effective risk management within the Information Security Management System (ISMS). - Change management baseline (including data flow documentation) is reviewed at least annually.- Reviews are also triggered by any significant changes to processes, systems, or infrastructure.- This control supports ISO 27001 and CAIQ requirements for regular review and update of security and compliance documentation. | ||
| Are detection measures implemented with proactive notification if changes deviate from established baselines? | Yes, FastDraft employs proactive notification measures for detecting deviations from established baselines. This is facilitated through Azure Monitor and Azure Security Center, which continuously evaluate system performance and security configurations against predefined baselines. Alerts are generated and sent to the system administrators if any deviations are detected, ensuring immediate attention and remediation. This capability is part of our commitment to maintaining a secure and reliable platform, in line with ISO 27001 and Cyber Essentials Plus standards. | Are detection measures with proactive notification implemented in case of changes deviating from the established baseline? | Yes, Built Intelligence implements detection measures with proactive notification for changes that deviate from established baselines. Specifically, Azure Monitor and Azure Security Center are utilized to continuously evaluate system performance and security configurations against predefined baselines. If any deviations are detected, alerts are automatically generated and sent to system administrators, enabling immediate attention and remediation. These controls are aligned with ISO 27001 and Cyber Essentials Plus standards, supporting robust change management and security monitoring as required by AI compliance frameworks. |
| Is a procedure implemented to manage exceptions, including emergencies, in the change and configuration process? | Yes, FastDraft has implemented a procedure to manage exceptions, including emergencies, in the change and configuration process. This procedure is part of our broader IT Service Management framework, which aligns with ISO 27001 standards. The process includes steps for identifying, assessing, and approving exceptions, with specific criteria and controls for emergency changes to ensure they are handled efficiently without compromising security. The procedure is documented and reviewed regularly to ensure its effectiveness and compliance with our security policies. | Is a procedure implemented (aligning with the requirements of GRC-04: Policy Exception Process) for the management of exceptions, including emergencies, in the change and configuration process? | Yes, Built Intelligence has implemented a procedure to manage exceptions, including emergencies, in the change and configuration process. This procedure is part of 's broader IT Service Management framework and is aligned with ISO 27001 standards. It incorporates steps for identifying, assessing, and approving exceptions, with specific controls for handling emergency changes efficiently while maintaining security. Additionally, the procedure is explicitly aligned with the requirements of GRC- 04: Policy Exception Process, including clearly defined roles, responsibilities, and authorities to ensure appropriate management of policy exceptions in accordance with strategic direction and compliance objectives. |
| Is a process to proactively roll back changes to a previously known "good state" defined and implemented in case of errors or security concerns? | Yes, FastDraft has a defined and implemented process to proactively roll back changes to a previously known "good state" in case of errors or security concerns. This process is part of our robust change management and incident response protocols, which are aligned with ISO 27001 standards. We utilize Azure's deployment slots for staging and production environments, allowing us to test changes in a controlled manner before they go live. In the event of an error or security concern, we can quickly revert to the last known good configuration using Azure's point-in-time restore capabilities for databases and rollback features for application deployments. This ensures minimal disruption and maintains the integrity and security of our platform. | Is a process defined and implemented to proactively roll back changes to a previous known good state in case of errors or security concerns? | Yes, Built Intelligence have implemented process to proactively roll back changes to a previously known "good state" in case of errors or security concerns. This is achieved through the following measures aligned with ISO 27001 and CAIQ best practices: - Change management and incident response protocols are established to address errors and security concerns.- utilizes Azure’s deployment slots for both staging and production environments, enabling changes to be tested in a controlled environment prior to deployment.- In the event of a problem, Azure’s point- in- time restore capabilities for databases and rollback features for application deployments are used to revert to the last known good configuration.- This approach ensures minimal disruption of service and maintains the integrity and security of the platform.These controls address risk mitigation, availability, and recovery objectives within AI governance and security compliance frameworks. |
| Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained cryptography, encryption, and key management policies and procedures. These are aligned with industry best practices and standards, including ISO 27001 and Cyber Essentials Plus. Our cryptographic controls are managed through Microsoft Azure services, ensuring robust encryption of data at rest using AES-256 and secure management of cryptographic keys via Azure Key Vault. All policies and procedures are regularly reviewed and updated to address emerging risks and technological changes. | Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are cryptography, encryption, and key management policies and procedures reviewed and updated at least annually? | Yes, the cryptography, encryption, and key management policies and procedures are reviewed and updated at least annually. This is ensured by the Information Security Team in accordance with our ISMS policies, which mandate regular reviews in line with emerging risks and changes to the business environment. | Are cryptography, encryption, and key management policies and procedures reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence has established robust cryptography, encryption, and key management policies and procedures for. These policies and procedures are reviewed and updated at least annually by the Information Security Team. The reviews are conducted in accordance with the organization's Information Security Management System (ISMS) policies, ensuring alignment with ISO 27001 requirements. Additionally, updates are performed in response to emerging risks and significant changes to the business environment, thereby maintaining ongoing effectiveness and compliance. |
| Are cryptography, encryption, and key management roles and responsibilities defined and implemented? | Yes, cryptography, encryption, and key management roles and responsibilities are clearly defined and implemented within our organization. The Information Security Manager oversees compliance with our cryptographic policies, which are in line with ISO 27001 standards. Individual asset owners are responsible for applying cryptographic controls and securing cryptographic keys. Our use of Microsoft Azure also ensures that encryption and key management are handled according to industry best practices, utilizing Azure Key Vault for key management and encryption protocols like AES-256 for data at rest. | Are cryptography, encryption, and key management roles and responsibilities defined and implemented? | Yes, Built Intelligence has cryptography, encryption, and key management roles and responsibilities are clearly defined and implemented within the platform. The Information Security Manager is responsible for overseeing compliance with cryptographic policies, which align with ISO 27001 standards. Individual asset owners are tasked with applying cryptographic controls and securing cryptographic keys. Additionally, encryption and key management leverage Microsoft Azure services, specifically Azure Key Vault, which is managed in accordance with industry best practices. These definitions and implementations support robust AI governance and compliance objectives for risk mitigation and data protection. |
| Are data at-rest and in-transit cryptographically protected using cryptographic libraries certified to approved standards? | Yes, data at-rest and in-transit are cryptographically protected using cryptographic libraries certified to approved standards. FastDraft utilizes Microsoft Azure's built-in encryption mechanisms, which include AES-256 encryption for data at-rest and TLS 1.2 or higher for data in-transit. These cryptographic libraries and protocols are compliant with industry standards and certifications such as ISO 27001 and SOC 2 Type 2, ensuring robust data protection and security compliance. | Is data protection, at-rest, in-transit and where applicable in-use, provided by using cryptographic libraries certified to approved standards? | Yes, Built Intelligence uses industry-standard cryptographic protocols and relies on major cloud platform services that support approved and widely adopted implementations. - Encryption in transit uses modern TLS configurations. - Encryption at rest is provided by managed cloud services. - Where regulatory requirements mandate specific validation (e.g., FIPS), configurations are reviewed and applied as applicable. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are appropriate data protection encryption algorithms used that consider data classification, associated risks, and encryption technology usability? | Yes, Built Intelligence uses appropriate data protection encryption algorithms that consider data classification, associated risks, and encryption technology usability. All data within our Azure environments is encrypted using AES-256 for data at rest, and HTTPS/TLS v1.2 for data in transit, aligning with industry standards and best practices. Our cryptographic practices are managed according to our ISO 27001 certified Information Security Management System, ensuring the confidentiality, integrity, and availability of sensitive and critical information. | Are encryption algorithms utilized following industry standards for protecting data, based on the data classification and associated risks? | Yes, Built Intelligence utilizes encryption algorithms in alignment with industry standards to protect data, considering data classification and associated risks. Specifically: - All data at rest within Azure environments is encrypted using AES- 256, an approved and widely recognized encryption standard.- Data in transit is protected using HTTPS/TLS v1.2 or higher, ensuring secure communications in compliance with current best practices.- The selection and implementation of these cryptographic measures are managed under 's ISO 27001 certified Information Security Management System, supporting the confidentiality, integrity, and availability of sensitive and critical information.These controls align with ISO 27001 and other relevant industry security standards, supporting robust risk- based data protection. |
| Are standard change management procedures established to review, approve, implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources? | Yes, FastDraft has established standard change management procedures to review, approve, implement, and communicate changes related to cryptography, encryption, and key management technologies. These procedures accommodate both internal and external sources, ensuring that all changes are aligned with our security policies and compliance requirements. The process involves multiple stages including proposal, impact assessment, approval by the Information Security Manager, and communication to relevant stakeholders. This structured approach ensures that all cryptographic changes are managed securely and effectively within our Microsoft Azure-hosted environment. | Are standard change management procedures established to review, approve, implement, and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are changes to cryptography-, encryption- and key management-related systems, policies, and procedures, managed and adopted in a manner that fully accounts for downstream effects of proposed changes, including residual risk, cost, and benefits analysis? | Yes, changes to cryptography, encryption, and key management-related systems, policies, and procedures are managed and adopted in a manner that fully accounts for downstream effects, including residual risk, cost, and benefits analysis. This is ensured through our structured Change Control Procedure, which requires that all changes affecting information security, including those related to cryptography and key management, be reflected in our business continuity plans. The procedure involves risk assessment and business impact analysis to determine the information security requirements applicable to adverse situations, ensuring that all changes are comprehensively evaluated before implementation. | Are changes to cryptography-, encryption- and key management-related systems, policies, and procedures, managed and adopted in a manner that fully accounts for downstream effects of proposed changes, including residual risk, cost, and benefits analysis? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is a cryptography, encryption, and key management risk program established and maintained that includes risk assessment, risk treatment, risk context, monitoring, and feedback provisions? | Yes, Built Intelligence has established and maintains a comprehensive cryptography, encryption, and key management risk program as outlined in our ISMS documentation. This program includes risk assessment, risk treatment, understanding the risk context, and provisions for monitoring and feedback. This is managed according to the guidelines set forth in our Cryptography (ISMS DOC TEC04) and is supported by our use of Microsoft Azure's infrastructure, which includes built-in encryption capabilities for data at rest and in transit, and Azure Key Vault for key management. This ensures that cryptographic practices are aligned with industry standards and compliance requirements. | Is a cryptography, encryption, and key management risk program established and maintained that includes risk assessment, risk treatment, risk context, monitoring, and feedback provisions? | Yes, Built Intelligence establishes and maintains a comprehensive cryptography, encryption, and key management risk program. This program addresses the following aspects in alignment with AI governance and ISO 27001 control objectives: - Risk Assessment:The program includes procedures for risk assessment to identify vulnerabilities and threats related to cryptography, encryption, and key management. - Risk Treatment:Controls and mitigation measures are defined and implemented to address identified risks. - Risk Context:The risk management process accounts for the business context, including operational and regulatory requirements. - Monitoring & Feedback:The program provides for ongoing monitoring and feedback to ensure that cryptographic controls remain effective and fit for purpose. - Supporting Documentation:The Cryptography policy and the use of Microsoft Azure's encryption and key management capabilities (e.g., Azure Key Vault) support these requirements. These measures help ensure that cryptographic practices on the platform are robust, continuously reviewed, and updated as required to meet current industry standards and compliance requirements. |
| Are CSPs providing CSCs with the capacity to manage their own data encryption keys? | Yes, Microsoft Azure, the cloud service provider (CSP) for FastDraft, offers customers the capability to manage their own data encryption keys through Azure Key Vault. This service allows customers to control and manage the lifecycle of their encryption keys independently, ensuring enhanced security and compliance with their specific requirements. | Are providers providing customers with the capability to manage their own data encryption keys? | Yes, Built Intelligence’s underlying cloud service provider, Microsoft Azure, offers customers the capability to manage their own data encryption keys via Azure Key Vault. This enables customers to control and manage the lifecycle of their encryption keys independently, aligning with security and compliance requirements relevant to ISO 27001 and industry best practices for encryption and key management. |
| Are encryption and key management systems, policies, and processes audited with a frequency proportional to the system's risk exposure, and after any security event? | Yes, Built Intelligence's encryption and key management systems, policies, and processes are audited with a frequency proportional to the system's risk exposure and after any security event. These audits are part of our ISO 27001 certified Information Security Management System (ISMS), ensuring that all encryption keys and sensitive data handling practices are regularly reviewed and compliant with industry standards. Additionally, any significant changes in our encryption and key management infrastructure or any security events trigger an immediate review and re-assessment of relevant controls. This approach aligns with our commitment to maintaining robust security and data protection standards across all operations. | Are encryption and key management systems, policies, and processes audited with a frequency proportional to the system's risk exposure? | Yes, Built Intelligence's encryption and key management systems, policies, and processes are audited with a frequency proportional to the system's risk exposure and also after any security event. These audits are conducted as part of the ISO 27001 certified Information Security Management System (ISMS), ensuring regular review and compliance with industry standards. The documentation further states that any significant changes to encryption or key management infrastructure, or the occurrence of a security event, trigger immediate review and reassessment of relevant controls. This approach aligns with best practices in risk- based auditing for security and compliance objectives. |
| Are encryption and key management systems, policies, and processes audited (preferably continuously but at least annually)? | Yes, encryption and key management systems, policies, and processes are audited annually as part of our ISO 27001 certification requirements. We use Microsoft Azure Key Vault for managing encryption keys, which is also audited and compliant with multiple standards including ISO 27001. These audits ensure that our encryption practices and key management procedures remain secure and effective. | Are encryption and key management systems, policies, and processes audited preferably continuously but at least annually and after any security event? | Yes, Built Intelligence's encryption and key management systems, policies, and processes are subject to regular audits as part of its ISO 27001 certified Information Security Management System (ISMS). Specifically, these controls are audited with a frequency proportional to the system's risk exposure. Audits are conducted at least annually to meet certification requirements. Additionally, the documentation specifies that significant changes to encryption and key management infrastructure, as well as any security events, trigger immediate reviews and re- assessments of relevant controls. This ensures ongoing compliance with industry standards and proactive risk management. - Annual audits aligned with ISO 27001 requirements- Additional audits after any security event or significant infrastructure change- Continuous review mechanisms as part of the ISMSThis approach helps maintain robust security and effective data protection aligned with AI governance and risk management best practices. |
| Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications? | Yes, Built Intelligence uses industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications. Our cryptographic practices are aligned with Microsoft Azure's platform standards, which include the use of SHA-256 for hashing and AES-256 for encryption at rest. Azure ensures that all cryptographic keys are managed securely through Azure Key Vault, supporting robust key management and compliance with industry standards. | Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications? | Yes, Built Intelligence generates and manages cryptographic keys using industry-accepted mechanisms provided by managed key management services. - Key generation uses strong algorithms and secure random number generation provided by the underlying platform services. - Access to keys is restricted and logged; rotation and revocation processes are defined. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are private keys provisioned for a unique purpose managed, and is cryptography secret? | Yes, private keys provisioned for unique purposes are managed securely, and cryptography is kept confidential. In our Azure-hosted FastDraft platform, cryptographic keys are managed using Azure Key Vault, which ensures that keys are protected and access is strictly controlled through role-based access controls. Azure Key Vault provides secure key management and ensures that private keys are not exposed to unauthorized users. Additionally, all cryptographic operations are logged to ensure traceability and accountability. | Are cryptographic secrets and private keys that are provisioned for a unique purpose properly managed? | Yes, Built Intelligence ensures that cryptographic secrets and private keys provisioned for unique purposes are properly managed as follows: - All cryptographic keys, including private keys for unique purposes, are secured and managed via Azure Key Vault, which provides robust key management features.- Access to these keys is strictly controlled by Azure Key Vault's role- based access controls, preventing unauthorized access.- Cryptography remains confidential, and keys are not exposed to unauthorized users.- All cryptographic operations involving these keys are logged for auditability, supporting traceability and accountability requirements relevant to compliance frameworks such as ISO 27001 and CAIQ. |
| Are cryptographic keys rotated based on a cryptoperiod calculated while considering information disclosure risks and legal and regulatory requirements? | Yes, Built Intelligence manages cryptographic keys based on a defined cryptoperiod that considers information disclosure risks and legal and regulatory requirements. We use Azure Key Vault for key management, which supports automated key rotation and compliance with industry standards and regulations. This ensures that cryptographic keys are rotated in alignment with security best practices and legal obligations. | Are cryptographic keys rotated based on a cryptoperiod calculated while considering information disclosure risks, and legal and regulatory requirements? | Yes, Built Intelligence manages cryptographic keys based on a defined cryptoperiod that takes into account information disclosure risks as well as legal and regulatory requirements. Key management is handled through Azure Key Vault, which enables automated key rotation in compliance with industry standards and regulations. This ensures keys are rotated in accordance with security best practices and legal obligations, supporting control objectives for cryptographic key lifecycle management under CAIQ and ISO 27001 frameworks. |
| Are cryptographic keys revoked and removed before the end of the established cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions? | Yes, Built Intelligence ensures that cryptographic keys are revoked and removed before the end of the established cryptoperiod, in cases where a key is compromised or an entity is no longer part of the organization. This is managed through defined, implemented, and evaluated processes and procedures that comply with legal and regulatory requirements. Our key management practices are aligned with ISO 27001 standards and utilize Azure Key Vault for secure key management, ensuring that keys are handled according to strict security protocols and lifecycle management guidelines. | Are cryptographic keys revoked and removed before the end of the established cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures which include legal and regulatory requirement provisions? | Yes, Built Intelligence ensures that cryptographic keys used within the platform are revoked and removed before the end of the established cryptoperiod in scenarios such as key compromise or when an entity is no longer part of the organization. This is managed through defined, implemented, and evaluated processes and procedures that incorporate legal and regulatory requirements. The key management practices align with ISO 27001 standards and utilize Azure Key Vault for secure key lifecycle management, supporting compliance with industry regulations and best security practices. |
| Are processes, procedures and technical measures to destroy unneeded keys defined, implemented and evaluated to address key destruction outside secure environments, revocation of keys stored in hardware security modules (HSMs), and include applicable legal and regulatory requirement provisions? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for the destruction of unneeded cryptographic keys. These measures address key destruction outside secure environments and revocation of keys stored in hardware security modules (HSMs). Our key management practices are aligned with legal and regulatory requirements, ensuring compliance and secure cryptographic operations. These practices are documented in our ISMS and are reviewed regularly to maintain their effectiveness and compliance. | Are processes, procedures, and technical measures which include provisions for legal and regulatory requirements, defined, implemented and evaluated, to securely destroy cryptographic keys when they are no longer needed? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for the secure destruction of unneeded cryptographic keys. These measures specifically address key destruction both outside secure environments and revocation of keys stored in hardware security modules (HSMs). The key management practices are aligned with legal and regulatory requirements, ensuring compliance and secure cryptographic operations. All practices are documented within the organization’s Information Security Management System (ISMS) and are reviewed regularly to maintain effectiveness and ensure ongoing regulatory compliance. |
| Are processes, procedures, and technical measures to create keys in a pre-activated state (i.e., when they have been generated but not authorized for use) being defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, FastDraft implements processes, procedures, and technical measures to manage the creation of keys in a pre-activated state, ensuring compliance with legal and regulatory requirements. Our key management practices are aligned with ISO 27001 standards, which include the generation, storage, and handling of cryptographic keys. Keys are generated and managed using Microsoft Azure Key Vault, which provides secure key management while adhering to compliance frameworks. These keys are not activated until they pass our stringent internal authorization processes, which include compliance checks and security validations to meet both legal and regulatory standards. | Are processes, procedures, and technical measures to create keys in a pre-activated state (i.e., when they have been generated but not authorized for use) defined, implemented, and evaluated, including provisions for legal and regulatory requirements? | Yes, Built Intelligence defined, implemented, and evaluated processes, procedures, and technical measures for managing the creation of cryptographic keys in a pre- activated state. These measures include: - Keys are generated and managed using Microsoft Azure Key Vault, which ensures secure key management practices.- Keys remain in a pre- activated state (generated but not authorized for use) until they pass internal authorization processes, including compliance checks and security validations.- All procedures are aligned with ISO 27001 standards and are documented within the organization's Information Security Management System (ISMS).- The approach incorporates compliance with applicable legal and regulatory requirements.These practices are reviewed regularly to maintain effectiveness and compliance with current standards and regulations. |
| Are processes, procedures, and technical measures to monitor, review and approve key transitions (e.g., from any state to/from suspension) being defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, FastDraft has defined, implemented, and continuously evaluates processes, procedures, and technical measures to monitor, review, and approve key transitions, including state changes such as suspension. These measures are designed to comply with legal and regulatory requirements. Our platform, hosted on Microsoft Azure, leverages Azure's compliance and security frameworks, which are aligned with global standards including ISO 27001 and Cyber Essentials Plus. Additionally, role-based access controls and logging mechanisms are in place to ensure that transitions are authorized and recorded in compliance with legal provisions. | Are processes, procedures, and technical measures to monitor, review, and approve key transitions (e.g., from any state to/from suspension) defined, implemented, and evaluated including provisions for legal and regulatory requirements? | Yes, Built Intelligence defined, implemented, and continuously evaluates processes, procedures, and technical measures to monitor, review, and approve key transitions, including state changes such as suspension. These measures are designed to comply with legal and regulatory requirements. The platform, hosted on Microsoft Azure, leverages Azure's compliance and security frameworks, which are aligned with global standards such as ISO 27001 and Cyber Essentials Plus. Additionally, applies role- based access controls and logging mechanisms to ensure that all key state transitions are authorized and appropriately recorded, supporting auditability and regulatory compliance. |
| Are processes, procedures, and technical measures to deactivate keys (at the time of their expiration date) being defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, FastDraft has defined, implemented, and regularly evaluates processes, procedures, and technical measures to deactivate keys upon their expiration date. These measures are designed to comply with legal and regulatory requirements. We utilize Microsoft Azure Key Vault for key management, which automates key rotation and expiration based on policies we set. This ensures that expired keys are deactivated and new keys are issued in compliance with our security policies and relevant legal standards. Additionally, our ISO 27001 certification and adherence to Cyber Essentials Plus guidelines reinforce our commitment to robust key management practices. | Are processes, procedures, and technical measures to deactivate keys (at the time of their expiration date) defined, implemented, and evaluated including provisions for legal and regulatory requirements? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures to deactivate cryptographic keys at the time of their expiration. These controls include provisions for legal and regulatory requirements, and are aligned with ISO 27001 standards. The key management process utilizes Azure Key Vault, ensuring that deactivation, revocation, and removal of keys are handled in accordance with strict security protocols and lifecycle management guidelines. Compliance with both internal policies and external regulatory obligations is documented and regularly reviewed to maintain effectiveness. |
| Are processes, procedures, and technical measures to manage archived keys in a secure repository (requiring least privilege access) being defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to manage archived cryptographic keys in a secure repository. This management aligns with legal and regulatory requirements, ensuring least privilege access. Our cryptographic key management practices are part of our ISO 27001 certified Information Security Management System (ISMS), which includes strict access controls, regular audits, and compliance checks to maintain the confidentiality, integrity, and availability of cryptographic keys. | Are processes, procedures, and technical measures to manage archived keys in a secure repository (requiring least privilege access) defined, implemented, and evaluated including provisions for legal and regulatory requirements? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for managing cryptographic keys, including archived keys. The following controls are in place: - Cryptographic keys are managed in secure repositories, specifically utilizing Azure Key Vault for secure key storage and lifecycle management.- Access to cryptographic keys is governed by the principle of least privilege, ensuring that only authorized personnel have access.- Processes and procedures for key management—including revocation, removal, and destruction—are aligned with legal and regulatory requirements, as well as ISO 27001 standards.- Controls and processes are regularly reviewed (evaluated) to maintain compliance and effectiveness.These measures provide organizational assurance of compliance with CAIQ control objectives related to the secure management of archived cryptographic keys, least privilege access, and adherence to regulatory requirements. |
| Are processes, procedures, and technical measures to use compromised keys to encrypt information in specific scenarios (e.g., only in controlled circumstances and thereafter only for data decryption and never for encryption) defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for the use of compromised keys, specifically in scenarios where they are used only in controlled circumstances for data decryption and never for encryption. This approach aligns with legal and regulatory requirements, ensuring compliance while maintaining the security and integrity of data. | Are processes, procedures, and technical measures to use compromised keys to encrypt information in specific scenarios (e.g., only in controlled circumstances and thereafter only for data decryption and never for encryption) defined implemented, and evaluated including provisions for legal and regulatory requirement? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for the use of compromised cryptographic keys. Specifically, in scenarios involving compromised keys, they are used only under controlled circumstances for data decryption, and never for encryption. These measures are reviewed to ensure compliance with legal and regulatory requirements and are supported as part of the organization’s ISO 27001 certified Information Security Management System. This approach maintains both security and compliance objectives and aligns with best practices for cryptographic key management in accordance with CAIQ and ISO guidelines. |
| Are processes, procedures, and technical measures to assess operational continuity risks (versus the risk of losing control of keying material and exposing protected data) being defined, implemented, and evaluated to include legal and regulatory requirement provisions? | Yes, FastDraft has defined, implemented, and continuously evaluates processes, procedures, and technical measures to assess operational continuity risks, including the risk of losing control of keying material and exposing protected data. These measures are aligned with legal and regulatory requirements, and are part of our ISO 27001 certified Information Security Management System (ISMS). This includes regular risk assessments, business impact analyses, and compliance checks to ensure that all aspects of operational continuity are addressed and meet the necessary legal and regulatory standards. | Are processes, procedures, and technical measures to assess operational continuity risks (versus the risk of losing control of keying material and exposing protected data) defined, implemented, and evaluated, including provisions for legal and regulatory requirement provisions? | Yes, Built Intelligence defined and implemented processes, procedures, and technical measures to assess operational risks, including the risk of losing control of keying material and exposure of protected data. The platform applies a structured Operational Risk Management (ORM) and Enterprise Risk Management (ERM) approach, integrated with ISO 27001 and ISO 9001 certified frameworks. These include: - Regular risk assessments focusing on security, compliance, system availability, and data integrity.- Procedures such as threat modelling, vulnerability assessments, penetration testing, and business continuity planning to ensure resilience against operational disruptions.- A Risk Management Framework (RMF) aligns strategic, financial, regulatory, and cybersecurity risks, monitored and reviewed through a dedicated security committee to ensure regulatory compliance.- Key management practices—such as the use of Microsoft Azure Key Vault—are aligned with ISO 27001 standards, ensuring that cryptographic keys are managed securely, including legal and regulatory requirement provisions.These controls demonstrate that assesses both operational continuity risks and risks related to keying material and data protection as part of a comprehensive, standards- based governance process. |
| Are key management system processes, procedures, and technical measures being defined, implemented, and evaluated to track and report all cryptographic materials and status changes that include legal and regulatory requirements provisions? | Yes, FastDraft's key management system processes, procedures, and technical measures are defined, implemented, and evaluated to track and report all cryptographic materials and status changes, including provisions for legal and regulatory requirements. We utilize Azure Key Vault for managing cryptographic keys and secrets, ensuring compliance with industry standards and legal regulations. Our system is aligned with ISO 27001 standards, which include regular audits and reviews to ensure ongoing compliance and effectiveness of the cryptographic controls. | Are key management system processes, procedures, and technical measures defined, implemented, and evaluated to track and report all cryptographic materials and status changes including provisions for legal and regulatory requirements? | Yes, Built Intelligence has established key management system processes, procedures, and technical measures to track and report all cryptographic materials and status changes. The following controls are specified: - Cryptographic keys are managed according to a defined cryptoperiod that considers information disclosure risks and legal and regulatory requirements.- Azure Key Vault is used for key management, supporting automated key rotation, tracking, and compliance with industry standards and regulations.- Processes are in place to revoke and remove cryptographic keys before the end of the established cryptoperiod—specifically in cases of compromise or when an entity is no longer part of the organization.- These practices are aligned with ISO 27001 standards, ensuring compliance with legal and regulatory obligations.- Key management practices, including lifecycle tracking and handling of status changes (e.g., rotation, revocation, destruction), are governed by defined, implemented, and evaluated processes and procedures.Therefore, the documentation confirms that key management processes comprehensively address traceability, reporting, and compliance requirements for cryptographic materials within the platform. |
| Are policies and procedures for the secure disposal of equipment used outside the organization's premises established, documented, approved, communicated, enforced, and maintained? | Yes, policies and procedures for the secure disposal of equipment used outside the organization's premises are established, documented, approved, communicated, enforced, and maintained. These include ensuring that any sensitive data and licensed software have been removed or securely wiped prior to disposal or reuse. The Information Security Manager is responsible for overseeing these processes, and all actions are in compliance with our ISMS policies and relevant legal and regulatory requirements. | Are policies and procedures for the secure disposal of equipment used outside the organization's premises established, documented, approved, communicated, enforced, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, enforced, and maintained policies and procedures for the secure disposal of equipment used outside the organization's premises. These procedures include ensuring that any sensitive data and licensed software have been removed or securely wiped prior to disposal or reuse. The Information Security Manager oversees these processes, and all actions are performed in compliance with the organization’s Information Security Management System (ISMS) policies and relevant legal and regulatory requirements, supporting alignment with ISO 27001 and similar compliance frameworks. |
| Is a data destruction procedure applied that renders information recovery information impossible if equipment is not physically destroyed? | Yes, Built Intelligence applies a data destruction procedure that renders information recovery impossible, even if the equipment is not physically destroyed. This procedure is in accordance with our ISO 27001 certified Information Security Management System (ISMS). We use certified data wiping software that adheres to international standards such as NIST 800-88 to ensure all data is irreversibly destroyed. Additionally, all storage media are encrypted, further securing data against unauthorized recovery attempts. This process is documented and auditable as part of our compliance with ISO 27001 standards. | Is a data destruction procedure applied that renders information recovery information impossible if equipment is not physically destroyed? | Yes, Built Intelligence applies a data destruction procedure that renders information recovery impossible, even in instances where equipment is not physically destroyed. This procedure is aligned with ISO 27001- certified Information Security Management System (ISMS) requirements. Certified data wiping software compliant with international standards such as NIST 800- 88 is used to ensure that all data is irreversibly destroyed. Furthermore, all storage media are encrypted, providing additional assurance that data cannot be accessed or recovered without authorization. This process is fully documented and auditable according to ISO 27001 standards, supporting compliance objectives for secure data disposal under AI governance and information security best practices. |
| Are policies and procedures for the secure disposal of equipment used outside the organization's premises reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures for the secure disposal of equipment used outside the organization's premises annually. This is in accordance with our ISO 27001 certified Information Security Management System (ISMS), which includes controls for asset management and disposal. These policies ensure that all data is securely erased and equipment is disposed of in an environmentally responsible manner. | Are all policies and procedures for the secure disposal of equipment used outside the organization's premises reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence maintains asset management and physical security controls appropriate to a cloud-hosted service, with physical infrastructure controls largely inherited from Microsoft Azure. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location established, documented, approved, communicated, implemented, enforced, maintained? | Yes, policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location are established, documented, approved, communicated, implemented, enforced, and maintained as part of our ISO 27001 certified Information Security Management System (ISMS). These procedures ensure the security and integrity of assets during transfer or relocation, aligning with our commitment to protect information under all circumstances. | Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location established, documented, approved, communicated, implemented, enforced, maintained? | Yes, Built Intelligence has established, documented, approved, communicated, implemented, enforced, and maintained policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. These controls are part of 's ISO 27001 certified Information Security Management System (ISMS), ensuring the security and integrity of assets during transfer or relocation, and aligning with ongoing commitments to protect information under all circumstances. This implementation supports CAIQ and ISO 27001 control objectives related to asset management, change management, and physical/data transfer security. |
| Does a relocation or transfer request require written or cryptographically verifiable authorization? | Yes, a relocation or transfer request within our FastDraft platform requires written or cryptographically verifiable authorization. This is to ensure the security and integrity of user data and compliance with our operational controls and procedures. | Are the written or cryptographically verifiable authorization required for relocation or transfer request? | Yes, Built Intelligence relocation or transfer request requires written or cryptographically verifiable authorization. This requirement ensures the security and integrity of user data in alignment with operational controls and procedures, supporting compliance objectives related to access control, data protection, and risk mitigation frameworks such as ISO 27001 and CAIQ. |
| Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location reviewed and updated at least annually? | Yes, policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location are reviewed and updated at least annually, in compliance with our ISO 27001 certified Information Security Management System (ISMS). This ensures that all changes in operations, threats, or technologies are reflected in our practices to maintain security and compliance. | Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence has policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location are established, documented, approved, communicated, implemented, enforced, and maintained under the ISO 27001 certified Information Security Management System (ISMS). These procedures are reviewed and updated at least annually, or upon significant changes, ensuring ongoing alignment with best practices for AI governance and information security. This supports CAIQ and ISO 27001 requirements for asset management, change management, and ongoing risk mitigation. |
| Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained? | Yes, policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities are established, documented, approved, communicated, enforced, and maintained as outlined in the Physical Security (ISMS DOC PH01) document. This includes controlled access to physical locations, securing offices, rooms, and facilities, and protecting against external and environmental threats. These measures are regularly reviewed and updated to ensure compliance and effectiveness. | Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, applied, evaluated and maintained? | Yes, Built Intelligence ensures that policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities are: - Established and documented in the Physical Security document.- Approved, communicated to relevant personnel, and enforced.- Regularly reviewed, evaluated, and updated to ensure ongoing compliance and effectiveness.These measures include controlled access to physical locations, securing offices, rooms, and facilities, and protecting against external and environmental threats. The review and update of such policies are conducted at least annually, aligning with ISO 27001 requirements and supporting continual improvement and compliance with applicable legal and regulatory standards. |
| Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms) reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures for maintaining safe, secure working environments, including offices and rooms, at least annually. This is in alignment with our health and safety policy and ISO 27001 requirements, ensuring continual improvement and compliance with applicable legal and regulatory standards. | Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms, and facilities) reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence policies and procedures for maintaining safe and secure working environments (including offices, rooms, and facilities) are reviewed and updated at least annually. This review process ensures continual improvement and ongoing compliance with applicable legal and regulatory standards, including alignment with ISO 27001 requirements and the organization’s health and safety policy. The documentation explicitly confirms that these policies are also updated upon significant changes, supporting effective risk management and regulatory compliance objectives. |
| Are policies and procedures for the secure transportation of physical media established, documented, approved, communicated, enforced, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, enforced, evaluated, and maintained policies and procedures for the secure transportation of physical media. These procedures are part of our ISO 27001 certified Information Security Management System (ISMS) and align with our physical security and asset management controls. The policies ensure that all physical media containing sensitive information are handled and transported securely to mitigate risks of unauthorized access, loss, or damage. | Are policies and procedures for the secure transportation of physical media established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence is cloud-first and does not routinely rely on physical media for service delivery. Where physical media handling is required for corporate operations, secure procedures are followed. - Media is encrypted prior to transport where applicable and handled under controlled chain-of-custody. - Approved couriers/secure handling methods are used and records are retained. - Procedures are reviewed at least annually and after significant change. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies and procedures for the secure transportation of physical media reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures for the secure transportation of physical media annually as part of our ISO 27001 compliance. This ensures that all practices remain effective and aligned with current security standards and business requirements. | Are policies and procedures for the secure transportation of physical media reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence is cloud-first and does not routinely rely on physical media for service delivery. Where physical media handling is required for corporate operations, secure procedures are followed. - Media is encrypted prior to transport where applicable and handled under controlled chain-of-custody. - Approved couriers/secure handling methods are used and records are retained. - Procedures are reviewed at least annually and after significant change. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is the classification and documentation of physical and logical assets based on the organizational business risk? | Yes, Built Intelligence classifies and documents physical and logical assets based on organizational business risk. This process is integral to our ISMS and aligns with ISO 27001 standards, ensuring that all assets are evaluated for their confidentiality, integrity, and availability requirements. Asset classification and documentation are regularly reviewed and updated to reflect any changes in business risk or operational requirements. | Are the physical and logical assets (e.g. applications) classified and documented based on the organizational business risk? | Yes, Built Intelligence maintains asset management and physical security controls appropriate to a cloud-hosted service, with physical infrastructure controls largely inherited from Microsoft Azure. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is the assets' classification reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence maintains asset management and physical security controls appropriate to a cloud-hosted service, with physical infrastructure controls largely inherited from Microsoft Azure. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are all relevant physical and logical assets at all CSP sites cataloged and tracked within a secured system? | Yes, all relevant physical and logical assets at all CSP sites are cataloged and tracked within a secured system. FastDraft utilizes Microsoft Azure's infrastructure, which includes comprehensive asset management practices that are compliant with ISO 27001 standards. Azure ensures that all assets are inventoried and managed with strict access controls and monitoring to safeguard against unauthorized access and ensure the integrity of our services. | Are all relevant physical and logical assets located at service provider sites catalogued and tracked within a secured system? | Yes, Built Intelligence has all relevant physical and logical assets at service provider (CSP) sites are catalogued and tracked within a secured system. utilizes Microsoft Azure's infrastructure, which incorporates comprehensive asset management practices aligned with ISO 27001 standards. These practices include: - Inventory and management of all assets using secure systems- Implementation of strict access controls and ongoing monitoring to prevent unauthorized access- Regular reviews and updates to asset classification and documentation to reflect changes in business risk or operational requirementsThese measures ensure the integrity and security of services in accordance with recognized security and compliance frameworks. |
| Are catalogues reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence maintains asset management and physical security controls appropriate to a cloud-hosted service, with physical infrastructure controls largely inherited from Microsoft Azure. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are physical security perimeters implemented to safeguard personnel, data, and information systems? | Yes, Built Intelligence implements physical security perimeters to safeguard personnel, data, and information systems. Our office locations feature controlled access, CCTV monitoring, and burglar alarms. Additionally, the Microsoft Azure data centers where the FastDraft platform is hosted employ robust physical security measures including biometric access controls, 24/7 security personnel, and environmental controls to protect against natural disasters and unauthorized access. These measures are in compliance with ISO 27001 and other relevant standards, ensuring a secure physical environment for both personnel and data. | Are physical security perimeters designed and implemented to safeguard personnel, data, and information systems? | Yes, Built Intelligence ensures physical security perimeters are implemented to safeguard personnel, data, and information systems. Specifically: - Office locations feature controlled access, CCTV monitoring, and burglar alarms to ensure the security of personnel and information.- The Microsoft Azure data centers hosting employ robust physical security measures, including biometric access controls, 24/7 security personnel, and environmental controls to protect against unauthorized access and natural disasters.These measures are stated to be in compliance with ISO 27001 and other relevant standards, supporting the control objectives required by CAIQ and similar frameworks. |
| Is equipment identification used as a method for connection authentication? | Yes, Built Intelligence enforces strong identity and access controls for administrative and internal access to the FastDraft platform, which includes device-level trust policies. Managed endpoints are enrolled in secure device management systems, and equipment identification (such as certificates and endpoint compliance checks) is used to authenticate internal connections. All administrative access to Azure-hosted infrastructure is gated through multi-factor authentication (MFA), conditional access policies, and device identity recognition to support a zero-trust architecture. | Is equipment identification used as a method for connection authentication? | Yes, Built Intelligence enforces equipment identification as part of its connection authentication controls. Specifically: - Strong identity and access controls are implemented for administrative and internal access to the platform, incorporating device- level trust policies.- Managed endpoints are enrolled in secure device management systems.- Equipment identification methods, such as certificates and endpoint compliance checks, are used to authenticate internal connections.- All administrative access to Azure- hosted infrastructure leverages multi- factor authentication (MFA), conditional access policies, and device identity recognition, supporting a zero- trust security architecture.These controls align with security and risk- management requirements in frameworks such as ISO 27001 and CAIQ, ensuring robust authentication of equipment used to access sensitive areas of the platform. |
| Are solely authorized personnel able to access secure areas, with all ingress and egress areas restricted, documented, and monitored by physical access control mechanisms? | Yes, solely authorized personnel are able to access secure areas at Built Intelligence. All ingress and egress areas are restricted, documented, and monitored by physical access control mechanisms such as CCTV, burglar alarms, and locked secure areas. Access to these areas is specifically requested, authorized, and monitored, ensuring that only authorized personnel have access. | Are solely authorized personnel able to access secure areas, with all ingress and egress areas restricted, documented, and monitored by physical access control mechanisms? | Yes, Built Intelligence has authorized personnel are able to access secure areas. All ingress and egress areas are restricted, documented, and monitored through physical access control mechanisms such as CCTV, burglar alarms, and locked secure areas. Access to these areas is specifically requested, authorized, and monitored, ensuring that only authorized personnel have entry. This control meets requirements for physical and environmental security as outlined in frameworks such as ISO 27001 and CAIQ. |
| Are access control records retained periodically, as deemed appropriate by the organization? | Yes, FastDraft retains access control records periodically as deemed appropriate by the organization, in alignment with our ISO 27001 certified Information Security Management System (ISMS). These records are maintained in accordance with defined retention policies and are regularly reviewed to ensure compliance with regulatory and contractual obligations. | Are access control records retained periodically, as deemed appropriate by the organization? | Yes, Built Intelligence retains access control records periodically as deemed appropriate by the organization. This process is aligned with ’s ISO 27001 certified Information Security Management System (ISMS). Access control records are maintained according to defined retention policies and are regularly reviewed to ensure compliance with regulatory and contractual obligations. These practices support control objectives related to auditability, security monitoring, and regulatory compliance. |
| Are external perimeter datacenter surveillance systems and surveillance systems at all ingress and egress points implemented, maintained, and operated? | Yes, the FastDraft platform, hosted in Microsoft Azure data centers, benefits from Azure's comprehensive security measures which include external perimeter datacenter surveillance systems and surveillance at all ingress and egress points. These security measures are maintained and operated continuously to ensure the integrity and security of the infrastructure. Azure's security compliance is validated by certifications such as ISO 27001 and SOC 1/2/3, ensuring best practices in physical security and data protection. | Are datacenter surveillance systems at the external perimeter and at all the ingress and egress points, implemented, maintained, and operated to detect unauthorized ingress and egress attempts? | Yes, Built Intelligence leverages Microsoft Azure data center physical security controls, including perimeter protections and monitoring of ingress/egress points. - Azure maintains physical access controls, surveillance, and security monitoring for its facilities. - Assurance is supported by independent certifications and audit reports provided by the cloud provider. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are datacenter personnel trained to respond to unauthorized access or egress attempts? | Yes, Microsoft Azure data centers, where the FastDraft platform is hosted, have personnel trained to respond to unauthorized access or egress attempts. Azure data centers are staffed with security personnel who are trained in physical security measures and emergency response. They follow strict access control protocols and surveillance to prevent and respond to security incidents effectively. This aligns with compliance standards such as ISO 27001 and SOC 1/2/3, ensuring a high level of security for our hosted services. | Are data center personnel trained to safely manage adverse events, including but not limited to unauthorized ingress and egress attempts? | Yes, Built Intelligence platforms are hosted in Microsoft Azure data centers, where physical security is managed by Microsoft. Data center personnel are trained to respond to security incidents, including unauthorized ingress (entry) and egress (exit) attempts. Security staff are trained in physical security measures and emergency response procedures, and they follow strict access control protocols and continuous surveillance. This approach aligns with ISO 27001 and SOC 1/2/3 compliance standards to ensure robust risk management and control effectiveness for adverse events impacting physical security. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure risk-based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures to ensure risk-based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms. These measures are aligned with ISO 27001 standards and include physical security controls such as secure cable routing, access controls, and environmental protections. Additionally, our hosting on Microsoft Azure ensures further protection through their compliance with global security standards and physical security measures at their data centers. | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure risk-based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures to ensure risk- based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms. These measures are aligned with ISO 27001 standards and include: - Physical security controls such as secure cable routing- Access controls to restrict unauthorized access to infrastructure- Environmental protections to mitigate risks of damage and interferenceAdditionally, the platform leverages Microsoft Azure hosting, which provides further protection through its compliance with global security standards and robust physical security of data centers. |
| Are data center environmental control systems designed to monitor, maintain, and test that on-site temperature and humidity conditions fall within accepted industry standards effectively implemented and maintained? | Yes, FastDraft is hosted on Microsoft Azure, which implements and maintains environmental control systems in its data centers. These systems are designed to monitor, maintain, and test that on-site temperature and humidity conditions fall within accepted industry standards such as ASHRAE guidelines. Azure data centers are equipped with advanced HVAC and cooling systems to manage environmental conditions, ensuring optimal performance and reliability of hosted services. Azure's compliance with global standards, including ISO 27001, further supports the effective implementation and maintenance of these controls. | Are data center environmental control systems designed to implement and maintain, and test for continual effectiveness of temperature and humidity conditions within accepted industry standards? | Yes, Built Intelligence platforms are hosted on Microsoft Azure, which implements and maintains environmental control systems in its data centers. These systems are designed to monitor, maintain, and test that on- site temperature and humidity conditions fall within accepted industry standards, such as those set by ASHRAE. Azure data centers are equipped with advanced HVAC and cooling systems to manage environmental conditions, ensuring optimal performance and reliability of hosted services. Azure’s compliance with global standards, including ISO 27001, further supports the effective implementation and maintenance of these environmental controls for continual effectiveness. |
| Are utility services secured, monitored, maintained, and tested at planned intervals for continual effectiveness? | Yes, utility services within the FastDraft platform, hosted on Microsoft Azure, are secured, monitored, maintained, and tested at planned intervals to ensure continual effectiveness. Azure provides robust security measures, automated monitoring, and maintenance capabilities. Regular testing, including penetration testing and vulnerability assessments, is conducted to ensure the security and resilience of our services. These practices are aligned with our ISO 27001 certification and Azure's compliance standards. | Are utility services secured, monitored, maintained, and tested at planned intervals for continual effectiveness? | Yes, Built Intelligence has utility services within the platform, which is hosted on Microsoft Azure, these are: - Secured using robust security measures inherent to the Azure cloud infrastructure.- Monitored and maintained with automated monitoring tools provided by Azure.- Tested at planned intervals (including penetration testing and vulnerability assessments) to ensure continual effectiveness.- These practices are aligned with ISO 27001 certification and Azure's compliance standards, supporting ongoing resilience and risk mitigation.This demonstrates compliance with control objectives concerning operational resilience, resource security, and continual effectiveness of utility services. |
| Is business-critical equipment segregated from locations subject to a high probability of environmental risk events? | Yes, FastDraft is hosted on Microsoft Azure, which ensures that business-critical equipment is segregated from locations subject to high probability of environmental risk events. Azure data centers are strategically located worldwide with built-in redundancy and disaster recovery capabilities, including geographic distribution to mitigate risks from environmental threats. Azure's infrastructure complies with global standards such as ISO 27001, ensuring high levels of physical and environmental security. | Is business-critical equipment segregated from locations subject to a high probability of environmental risk events? | Yes, Built Intelligence maintains asset management and physical security controls appropriate to a cloud-hosted service, with physical infrastructure controls largely inherited from Microsoft Azure. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies and procedures established, documented, approved, communicated, enforced, evaluated, and maintained for the classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level? | Yes, Built Intelligence has established, documented, approved, communicated, enforced, evaluated, and maintained policies and procedures for the classification, protection, and handling of data throughout its lifecycle. These policies align with applicable laws and regulations, standards, and the assessed risk level. Our Information Security Management System (ISMS), certified under ISO 27001, outlines these procedures, which include data classification, handling, storage, transmission, and destruction protocols. Compliance with these policies is regularly reviewed and audited to ensure continuous improvement and adherence to legal and regulatory requirements. | Are Security and Privacy Policies and Procedures established, documented, approved, communicated, applied, evaluated, and maintained for the classification, protection, preparation, and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level? | Yes, Built Intelligence has established, documented, approved, communicated, enforced, evaluated, and maintained policies and procedures for the classification, protection, and handling of data throughout its lifecycle. These processes are explicitly aligned with applicable laws, regulations, standards, and the assessed risk level. The Information Security Management System (ISMS), certified under ISO 27001, governs these practices and includes procedures for data classification, handling, storage, transmission, and destruction. Compliance with these policies is reviewed and audited regularly to ensure ongoing improvement and adherence to legal and regulatory requirements. |
| Are data security and privacy policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates data security and privacy policies and procedures at least annually in alignment with our ISO 27001 certification requirements. This ensures ongoing compliance with evolving data protection laws and industry best practices, including GDPR and Cyber Essentials Plus standards. | Are Security and Privacy Policies and Procedures reviewed and updated at least annually? | Yes, Built Intelligencehas security and privacy policies and procedures that are reviewed and updated at least annually. These reviews ensure alignment with the latest security best practices and compliance requirements, including guidance from the UK National Cyber Security Centre. The review process forms part of 's ISO 27001 certified Information Security Management System and is intended to keep security and privacy controls robust and effective. |
| Are industry-accepted methods applied for secure data disposal from storage media so information is not recoverable by any forensic means? | Yes, Built Intelligence applies industry-accepted methods for secure data disposal from storage media, ensuring that information is not recoverable by any forensic means. This includes the use of data wiping software that adheres to standards such as NIST 800-88, which specifies methods for media sanitization to ensure that data is irrecoverable. Additionally, physical destruction of storage media is employed when necessary. These practices are part of our ISO 27001 compliant Information Security Management System (ISMS) and align with our data protection and privacy policies. | Are industry-accepted methods applied for securely disposing of data from storage media so that it is not recoverable by any forensic means? | Yes, Built Intelligence applies industry- accepted methods for secure data disposal from storage media to ensure data is not recoverable by any forensic means. Specifically: - Data disposal is conducted using methods aligned with ISO 27001 standards.- Secure erasure is performed with data wiping software adhering to standards such as NIST 800- 88, which prescribes media sanitization practices to guarantee irrecoverability.- When necessary, physical destruction of storage media is also utilized.- For cloud- based data, deletion follows Microsoft Azure’s secure deletion policies.These procedures address CAIQ and ISO 27001 controls concerning secure data lifecycle management and disposal. |
| Is a data inventory created and maintained for sensitive and personal information (at a minimum)? | Yes, Built Intelligence maintains a data inventory for sensitive and personal information as part of our ISO 27001 certified Information Security Management System (ISMS). This inventory includes details such as data type, classification, owner, and storage location, ensuring compliance with data protection laws and regulations. | Are data inventories created and maintained at least for any sensitive, regulated, and personal data? | Yes, Built Intelligence maintains a data inventory for sensitive and personal information as part of its ISO 27001 certified Information Security Management System (ISMS). This inventory includes details such as data type, classification, owner, and storage location, ensuring compliance with data protection laws and regulations. The documentation explicitly confirms this control is in place for sensitive and personal data. |
| Are inventories reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence maintains data protection controls for classification, handling, retention, and access management, aligned to applicable privacy and security requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is data classified according to type and sensitivity levels? | Yes, Built Intelligence classifies data according to type, sensitivity levels, and legal requirements. We use a three-tier classification system: Confidential, Restricted, and Public, to ensure appropriate protection measures are applied based on the sensitivity and value of the information. This classification process is part of our ISO 27001 compliant Information Security Management System (ISMS), ensuring data is handled and protected according to its classification. | Are data classified according to its type and sensitivity level? | Yes, Built Intelligence classifies data according to type, sensitivity levels, and legal requirements. The platform uses a three- tier classification system: Confidential, Restricted, and Public. This classification process is incorporated into ’s ISO 27001- compliant Information Security Management System (ISMS), ensuring data is managed and protected appropriately depending on its classification. These measures support AI governance and risk management by aligning with data security and control objectives as required by standards such as CAIQ and ISO 27001. |
| Is data flow documentation created to identify what data is processed and where it is stored and transmitted? | Yes, FastDraft maintains comprehensive data flow documentation that identifies what data is processed, where it is stored, and how it is transmitted. This documentation is part of our Information Security Management System (ISMS) and aligns with ISO 27001 standards. It includes details on data handling within the Microsoft Azure infrastructure, ensuring data integrity and security through encrypted storage and secure data transmission protocols. | Are data flow documentation created to identify what data is processed, stored, or transmitted where? | Yes, Built Intelligence has comprehensive data flow documentation which is maintained to identify what data is processed, where it is stored, and how it is transmitted. This documentation forms part of the platform's Information Security Management System (ISMS) and aligns with ISO 27001 standards. The data flow documentation includes details relating to data handling within the Microsoft Azure infrastructure, ensuring that data integrity and security are supported through encrypted storage and secure data transmission protocols. |
| Is data flow documentation reviewed at defined intervals, at least annually, and after any change? | Yes, data flow documentation is reviewed at defined intervals, at least annually, and after any significant change to ensure ongoing compliance and accuracy. This review process is part of our operational controls and is documented in our Information Security Management System (ISMS), aligning with ISO 27001 standards. | Are data flow documentation reviewed at defined intervals, at least annually, and after any change? | Yes, Built Intelligence’s data flow documentation is reviewed at defined intervals, at least annually, and after any significant change. This review process is conducted as part of the operational controls defined within the Information Security Management System (ISMS), ensuring ongoing compliance and accuracy. The described practice aligns with ISO 27001 standards for information security and control maintenance. |
| Is the ownership and stewardship of all relevant personal and sensitive data documented? | Yes, Built Intelligence documents the ownership and stewardship of all relevant personal and sensitive data as part of our ISO 27001 certified Information Security Management System (ISMS). This documentation includes roles and responsibilities for data protection and privacy, ensuring compliance with GDPR and other relevant data protection laws. | Are ownership and stewardship of all relevant personal and sensitive data documented? | Yes, Built Intelligence ownership and stewardship of all relevant personal and sensitive data within the platform are documented. This process is part of ISO 27001 certified Information Security Management System (ISMS). The documentation includes roles and responsibilities for data protection and privacy and ensures compliance with GDPR and other applicable data protection laws. - Ownership and stewardship roles are explicitly documented.- Compliance is aligned with ISO 27001 standards and GDPR requirements.- Regular reviews of this documentation ensure it remains current and accurate. |
| Is data ownership and stewardship documentation reviewed at least annually? | Yes, data ownership and stewardship documentation is reviewed at least annually. This review is part of our compliance with ISO 27001 standards, ensuring that all documentation is current and reflects any changes in data management practices or regulatory requirements. This process is managed by our compliance team and includes updates to reflect any changes in the Microsoft Azure platform that we use for hosting the FastDraft platform. | Are reviews performed at least annually for the documented ownership and stewardship of all relevant personal and sensitive data? | Yes, Built Intelligence performs reviews of documented ownership and stewardship of all relevant personal and sensitive data at least annually. This process is aligned with ISO 27001 standards and is managed through the Information Security Management System (ISMS). The review ensures that all documentation remains current and accurately reflects any changes in data management practices or regulatory requirements, including updates for the Microsoft Azure platform used for hosting. - Annual review of data ownership and stewardship documentation- Compliance with ISO 27001 and GDPR requirements- Ongoing updates to reflect regulatory and platform changes |
| Are systems, products, and business practices based on security principles by design and per industry best practices? | Yes, FastDraft's systems, products, and business practices are based on security principles by design and adhere to industry best practices. We follow a structured Software Development Life Cycle (SDLC) that incorporates security from the initial design through development, testing, and deployment. Our platform is hosted on Microsoft Azure, which aligns with global security standards such as ISO 27001 and SOC 2 Type 2. We implement security controls and practices such as data encryption, regular penetration testing, and compliance with GDPR and other relevant regulations to ensure the security and integrity of our services and customer data. | Are systems, products, and business practices developed based upon a principle of security by design and industry best practices? | Yes, Built Intelligence's systems, products, and business practices are developed according to the principle of security by design and adhere to industry best practices. Specifically: - The development process follows a structured Software Development Life Cycle (SDLC) that incorporates security from initial design through to deployment.- is hosted on Microsoft Azure, aligning with global security standards such as ISO 27001 and SOC 2 Type 2.- Security controls embedded within the platform include data encryption, regular penetration testing, and compliance with regulations such as GDPR.- The platform benefits from a defence- in- depth, multi- tier architecture, with data segmentation, network segmentation, and enforcement of access controls (including principle of least privilege and role- based access control).These measures collectively ensure that security is prioritized throughout the system’s lifecycle and aligned with recognised industry guidance for cloud services and AI governance. |
| Are systems, products, and business practices based on privacy principles by design and according to industry best practices? | Yes, FastDraft is designed and operated based on privacy principles by design and according to industry best practices. Our platform, hosted on Microsoft Azure, adheres to privacy by design principles, ensuring that privacy is integrated into the system development process. We follow industry best practices such as data minimization, encryption, and access controls, aligning with standards like ISO 27001 and GDPR. Our privacy practices are regularly reviewed and updated to comply with evolving regulations and standards. | Are systems, products, and business practices developed based upon a principle of privacy by design and industry best practices? | Yes, Built Intelligence’s systems, products, and business practices are developed according to the principles of privacy by design and industry best practices. Specifically, the following controls and practices are implemented: - Privacy by Design: integrates privacy into its system development process, ensuring privacy considerations are addressed from design through deployment.- Industry Best Practices: Data minimization, encryption, and robust access controls are enforced.- Regulatory Alignment: The platform operates in accordance with ISO 27001 and GDPR requirements, with regular reviews to maintain compliance with relevant privacy laws and standards.- Hosting Standards: is hosted on Microsoft Azure, leveraging Azure's built- in compliance and privacy capabilities.These measures collectively demonstrate alignment with CAIQ, ISO 27001, and AI governance expectations regarding privacy- centric system development and operation. |
| Are systems' privacy settings configured by default and according to all applicable laws and regulations? | Yes, FastDraft's systems' privacy settings are configured by default to comply with all applicable laws and regulations, including GDPR and UK GDPR. Our platform is hosted on Microsoft Azure, which provides built-in compliance and privacy features that we leverage to ensure data protection and privacy by design and by default. | Are systems' privacy settings configured by default, according to all applicable laws and regulations? | Yes, Built Intelligence's systems' privacy settings are configured by default to comply with all applicable laws and regulations, including GDPR and UK GDPR. The platform leverages Microsoft Azure's built- in compliance and privacy features to ensure data protection and privacy by design and by default. This approach aligns with best practices in AI governance by implementing privacy controls that address: - Default privacy settings compliant with legal frameworks such as GDPR and UK GDPR- Integration of privacy features at the systems level using secure infrastructure (Microsoft Azure)- Controls to uphold the principles of privacy by design and by default |
| Is a data protection impact assessment (DPIA) conducted when processing personal data and evaluating the origin, nature, particularity, and severity of risks according to any applicable laws, regulations and industry best practices? | Yes, Built Intelligence conducts a Data Protection Impact Assessment (DPIA) when processing personal data, particularly when introducing new technologies or data processing activities that are likely to result in a high risk to the rights and freedoms of individuals. This assessment considers the origin, nature, particularity, and severity of the risk in accordance with GDPR requirements and industry best practices. Our DPIA process is aligned with our ISO 27001 certified Information Security Management System (ISMS) and includes consultation with stakeholders, risk assessment, mitigation measures, and compliance checks with applicable laws and regulations. | Are Data Protection Impact Assessments (DPIAs) conducted to evaluate the origin, nature, particularity, and severity of the risks upon the processing of personal data, according to any applicable laws, regulations, and industry best practices? | Yes, Built Intelligence assesses privacy and data protection risks for relevant processing activities in line with applicable law (including GDPR where applicable). - Risk assessments consider the nature, scope, context, and purposes of processing. - Where required, a Data Protection Impact Assessment (DPIA) is performed and documented. - Mitigations are tracked through governance and risk management processes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures to ensure the protection of personal and sensitive data during transfer. These measures comply with relevant laws and regulations, including GDPR. Data transfers are secured using encryption protocols such as TLS 1.2 or higher, and all data handling practices are aligned with our ISO 27001 certified Information Security Management System (ISMS). Additionally, data transfer agreements, including Standard Contractual Clauses (SCCs), are used when transferring data outside the EEA to ensure compliance with legal requirements. | Are processes, procedures, and technical measures defined, implemented, and evaluated that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations? | Yes, Built Intelligence has established and maintains robust processes, procedures, and technical measures to ensure the protection of personal or sensitive data during any transfer. These controls include: - Defined and implemented processes and procedures that guide data transfer and processing activities, reviewed regularly for effectiveness.- Compliance with relevant laws and regulations, such as GDPR, is explicitly stated as an operational requirement.- Technical measures such as data encryption protocols (TLS 1.2 or higher) are used to secure data in transit and protect against unauthorized access.- Use of contractual agreements, including Standard Contractual Clauses (SCCs), for data transfers outside the European Economic Area (EEA) to ensure legal compliance and protection levels are maintained.- All practices are aligned with ISO 27001 certified Information Security Management System (ISMS) standards, incorporating regular evaluation and documentation of security controls.This comprehensive approach aligns with best practices for risk mitigation and compliance under AI governance and data protection frameworks such as CAIQ and ISO 27001. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures that enable data subjects to request access to, modify, or delete their personal data in compliance with applicable laws and regulations such as the GDPR. Our Data Protection Policy outlines the steps data subjects can take to exercise their rights, and our systems are designed to facilitate these requests efficiently. Additionally, our ISO 27001 certification ensures that these processes are regularly reviewed and updated to maintain compliance and protect data subject rights. | Are processes, procedures, and technical measures defined and implemented to enable data subjects to request access to, modify, or delete their personal data according to applicable laws and regulations? | Yes, Built Intelligence has established and implemented processes, procedures, and technical measures to enable data subjects to request access to, modify, or delete their personal data, in alignment with applicable laws and regulations such as GDPR. Key points include: - Defined and implemented mechanisms for data subjects to exercise their rights regarding personal data.- Documented Data Protection Policy outlining steps for data access, modification, or deletion requests.- Systems are designed to efficiently facilitate and process these requests.- These controls are regularly reviewed and updated as part of ’s ISO 27001 certified Information Security Management System (ISMS), ensuring ongoing compliance and protection of data subject rights. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to ensure that personal data is processed in compliance with applicable laws and regulations, and strictly for the purposes declared to the data subject. Our adherence to ISO 27001 and GDPR guidelines ensures that all personal data handling aligns with legal requirements and best practices, including data protection impact assessments, regular audits, and strict access controls. | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure that personal data is processed according to applicable laws and regulations and for the purposes declared to the data subject? | Yes, Built Intelligence has established comprehensive processes, procedures, and technical measures to ensure that personal data is processed in compliance with applicable laws and regulations (such as GDPR) and for purposes declared to the data subject. Key controls include: - Defined and regularly evaluated procedures for personal and sensitive data processing, aligned with legal and regulatory requirements.- Personal data handling practices are integrated into an ISO 27001 certified Information Security Management System (ISMS).- Data transfers are protected using encryption protocols (e.g., TLS 1.2 or higher), and appropriate legal instruments such as Standard Contractual Clauses (SCCs) are utilized when transferring data outside the EEA.- Data Protection Impact Assessments (DPIAs) are conducted when introducing new technologies or processing activities likely to result in a high risk to data subjects, ensuring compliance with GDPR and best practices.- Continuous oversight and regular reviews ensure that data is processed only within scope and as declared to data subjects.These measures collectively support compliance with both data protection laws and AI governance best practices by ensuring appropriateness, transparency, and the security of personal data processing activities. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures for the transfer and sub-processing of personal data within the service supply chain, in accordance with applicable laws and regulations such as GDPR. Our ISO 27001 certified Information Security Management System (ISMS) includes controls for data transfer and sub-processing, ensuring compliance with legal and regulatory requirements. We utilize Standard Contractual Clauses (SCCs) for data transfers and conduct regular audits on our sub-processors to ensure they meet our security standards. | Are processes, procedures, and technical measures defined, implemented, and evaluated for transferring and sub-processing personal data within the service supply chain according to applicable laws and regulations? | Yes, Built Intelligence has established and maintains the following controls regarding the transfer and sub- processing of personal data within its service supply chain, in line with applicable laws and regulations: - Defined, implemented, and regularly evaluated processes, procedures, and technical measures for protecting personal and sensitive data during transfers. This includes compliance with GDPR and other relevant laws.- Usage of encryption protocols such as TLS 1.2 or higher to secure data transfers.- All data handling practices are governed by an ISO 27001 certified Information Security Management System (ISMS).- For transfers outside the EEA, Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs) are utilized to ensure legal compliance and data protection.- Third- party suppliers and contractors are subject to formal vetting, contractual controls including data protection obligations, and are required to implement appropriate technical and organisational security measures. Ongoing governance is maintained to manage associated risks in line with ISO/IEC 27001.These measures collectively ensure that the transfer and sub- processing of personal data within the supply chain adhere to relevant compliance and security requirements. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures to ensure that details of any personal or sensitive data accessed by sub-processors are disclosed to the data owner before processing initiation. This is in compliance with GDPR requirements and our ISO 27001 certified Information Security Management System (ISMS). Formal agreements with sub-processors include clauses that mandate the disclosure of such details, ensuring transparency and compliance with data protection laws. | Are processes, procedures, and technical measures defined, implemented, and evaluated to disclose the details of any personal or sensitive data access by sub-processors to the data owner before initiating that processing? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures to ensure that the details of any personal or sensitive data accessed by sub- processors are disclosed to the data owner before processing is initiated. This practice is in compliance with GDPR requirements and is governed by the organization’s ISO 27001 certified Information Security Management System (ISMS). Formal agreements with sub- processors include contractual clauses mandating such disclosures, thereby ensuring transparency for data owners and adherence to applicable data protection laws. |
| Is authorization from data owners obtained, and the associated risk managed, before replicating or using production data in non-production environments? | Yes, Built Intelligence obtains authorization from data owners and manages the associated risks before replicating or using production data in non-production environments. This process is aligned with our ISO 27001 certified Information Security Management System (ISMS), ensuring data protection and compliance with regulatory requirements. | Are authorizations obtained from data owners and associated risks managed before replicating or using production data in non-production environments? | Yes, Built Intelligence controls the use of production data in non-production environments to reduce privacy and security risk. - Use of production data is restricted and requires authorization and risk assessment. - Data minimization, masking/pseudonymization, and access controls are applied where feasible. - Activity is logged and subject to periodic review. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Do data retention, archiving, and deletion practices follow business requirements, applicable laws, and regulations? | Yes, FastDraft's data retention, archiving, and deletion practices are designed to comply with business requirements, applicable laws, and regulations. We align our practices with ISO 27001 standards, ensuring data is handled securely and in compliance with GDPR and other relevant legislation. Data retention periods are defined based on the type of data and its purpose, and we ensure secure deletion of data when it is no longer required or upon request, in accordance with legal obligations and customer agreements. | Are data retention, archiving, and deletion managed per business requirements, applicable laws, and regulations? | Yes, Built Intelligence’s data retention, archiving, and deletion practices are managed in accordance with business requirements, applicable laws, and relevant regulations. The documentation states that these activities are aligned with ISO 27001 standards and ensure compliance with legislation such as GDPR. Key points include: - Retention periods are defined based on the type of data and its intended purpose.- Secure deletion of data is conducted when data is no longer required or upon request, always meeting legal obligations and customer agreements.- Archiving and retention procedures account for backups and data lifecycle management, applying security controls throughout.These controls help ensure secure and compliant data lifecycle management in line with AI governance and CAIQ/ISO 27001 requirements. |
| Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle? | Yes, Built Intelligence has defined and implemented processes, procedures, and technical measures to protect sensitive data throughout its lifecycle. This includes data classification, access controls, encryption in transit and at rest, and secure data disposal practices. Our measures are aligned with ISO 27001 standards and GDPR requirements, ensuring data protection from creation and storage to transmission and deletion. | Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle? | Yes, Built Intelligence implements the following processes, procedures, and technical measures to protect sensitive data throughout its lifecycle: - Defined and regularly evaluated processes and procedures for protecting personal and sensitive data during storage and transfer, aligned with GDPR and ISO 27001 ISMS requirements.- Data transfers are protected using encryption protocols such as TLS 1.2 or higher.- Data transfer agreements, including Standard Contractual Clauses (SCCs), are used for transfers outside the EEA to ensure legal compliance.- Access to the data layer is strictly controlled through the business logic layer, and all data requests utilize stored procedures.- Data segregation and secure storage protocols are enforced via Azure Storage, with backup and disaster recovery plans in place, including defined RTO and RPO targets.- Data retention follows ISO 27001- aligned SLAs: client data is retained for the duration of the contract plus 12 years, with options for extended retention as needed.- A documented data breach response procedure exists, covering detection, assessment, containment, notification, remediation, and compliance with regulatory requirements (e.g., GDPR).- Periodic risk reviews and mandatory data protection/information security training are provided for all staff, including contractors and third- party suppliers.These controls collectively address the protection of sensitive data throughout its creation, storage, transfer, and eventual deletion or retention. The measures are designed to meet both regulatory and industry- standard compliance expectations. |
| Does the CSP have in place, and describe to CSCs, the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations? | Yes, Built Intelligence has established procedures to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities in accordance with applicable laws and regulations. These procedures are part of our ISO 27001 certified Information Security Management System (ISMS) and are aligned with GDPR requirements. The process ensures that all requests are legally validated, documented, and handled in a manner that upholds the privacy and security of the data subject's information. | Are the procedures to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations, implemented and described to the customers by the providers? | Yes, Built Intelligence maintains procedures to handle legally binding requests for disclosure of personal data in accordance with applicable laws and contractual obligations. - Requests are validated for legal authority and scope before any disclosure. - Where permitted, customers are notified and disclosures are limited to what is legally required. - Actions are logged and reviewed for compliance. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up? | Yes, Built Intelligence has defined and implemented processes, procedures, and technical measures to specify and document physical data locations, including locales where data is processed or backed up. Our FastDraft platform is hosted on Microsoft Azure, utilizing data centers located in UK South, UK North, and West Europe to ensure data residency and compliance with local regulations such as GDPR. Data processing and backup locations are clearly documented in our internal ISMS policies and Azure's comprehensive compliance documentation. Additionally, Azure provides geo-redundant storage (GRS) to ensure data durability and high availability, which is part of our business continuity and disaster recovery strategies. | Are processes, procedures, and technical measures defined and implemented to specify and document the physical locations of data, including any locations where data is processed or backed up? | Yes, Built Intelligence documents data hosting and processing locations for the service and aligns these with customer and regulatory requirements. - The service is hosted on Microsoft Azure, and regions are selected/configured based on deployment requirements. - Backup and recovery locations follow the configured hosting region/resiliency settings. - Documentation is maintained and reviewed as part of change control. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to: 1) Document and trace data sources, and 2) Make the data source available according to legal and regulatory requirements | Yes, Built Intelligence maintains processes to document and trace relevant data sources used by the service where required. - Data flows and integrations are documented and updated through change management. - Access to data sources is controlled and logged. - Information can be provided to customers as needed to meet legal and regulatory obligations, subject to security constraints. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures and technical measures to prevent data poisoning in AI models and continuously detect such, defined, implemented and evaluated? | Yes, Built Intelligence implements controls intended to reduce the risk of data poisoning for any data sets used to support AI features (e.g., retrieval corpora or configuration data). - Data ingestion is controlled through validation, access controls, and integrity checks. - Changes to data sources follow change control and are auditable. - Monitoring supports detection of anomalous or unexpected content changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are Privacy Enhancing Technologies (PET) used for training data informed by risk and privacy impact analysis and business use cases? | Yes, Built Intelligence maintains data protection controls for classification, handling, retention, and access management, aligned to applicable privacy and security requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the consistency and conformity of training, fine-tuning or augmentation data regularly validated? | Yes, Built Intelligence maintains data protection controls for classification, handling, retention, and access management, aligned to applicable privacy and security requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is dataset versioning to ensure traceability implemented and are restrictions to prevent unauthorized changes, enforced? | Yes, Built Intelligence maintains data protection controls for classification, handling, retention, and access management, aligned to applicable privacy and security requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is training-data differentiation and relevance to the intended use of the AI Model, ensured? | Yes, Built Intelligence maintains data protection controls for classification, handling, retention, and access management, aligned to applicable privacy and security requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are information governance program policies and procedures sponsored by organizational leadership established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained information governance program policies and procedures, sponsored by organizational leadership. These are integral to our ISO 27001 certified Information Security Management System (ISMS) and are regularly reviewed and updated to ensure they remain effective and compliant with relevant standards and regulations. | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for an information governance program that is sponsored by the leadership of the organization and related to AI systems as well? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are the policies and procedures reviewed and updated at least annually? | Yes, our policies and procedures are reviewed and updated at least annually to ensure they remain effective and compliant with current regulations and standards. This regular review process is part of our commitment to maintaining robust security and compliance standards across our platform and operations. | Are policies and procedures for information governance program and related to AI systems reviewed and updated at least annually? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is there an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks? | Yes, Built Intelligence has an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks. This program is integrated into our ISO 27001 certified Information Security Management System (ISMS), ensuring comprehensive management of all security and privacy risks associated with our cloud operations hosted on Microsoft Azure. The program includes regular risk assessments, mitigation strategies, and continuous monitoring to ensure the effectiveness of the controls in place. | Is a formal, documented, and leadership-sponsored AI risk management (AIRM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of risks, established and maintained? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are all relevant organizational policies and associated procedures reviewed at least annually, or when a substantial organizational change occurs? | Yes, all relevant organizational policies and associated procedures are reviewed at least annually or when a substantial organizational change occurs. This is in line with our commitment to maintaining a robust Information Security Management System (ISMS) and ensuring continuous improvement. The review process is documented and involves key stakeholders to ensure that all aspects of the organization's operations are considered. | Are relevant organizational policies and associated procedures reviewed at least annually or when a substantial change within the organization, occurs? | Yes, Built Intelligence all relevant organizational policies and associated procedures within are reviewed at least annually, or when a substantial organizational change occurs. This process is part of the platform's commitment to maintaining a robust Information Security Management System (ISMS) and supports ongoing compliance with standards such as ISO 27001. The policy and procedure review process is documented and involves key stakeholders to ensure all operational aspects of the organization are considered and addressed. This aligns with best practices for AI governance and risk management by ensuring that controls remain current and effective in response to both organizational and regulatory changes. |
| Is an approved exception process mandated by the governance program established and followed whenever a deviation from an established policy occurs? | Yes, an approved exception process is mandated by the governance program and is followed whenever there is a deviation from an established policy. This process ensures that all exceptions are documented, reviewed, and approved by the appropriate authorities within the organization, maintaining the integrity and compliance of our security and operational standards. | Is an approved exception process mandated by the governance program established and followed whenever a deviation from an established policy occurs? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Has an information security program (including programs of all relevant CCM domains) been developed and implemented? | Yes, Built Intelligence has developed and implemented an information security program that encompasses all relevant Cloud Control Matrix (CCM) domains. This program is aligned with our ISO 27001 certified Information Security Management System (ISMS), ensuring comprehensive coverage of security controls, risk management processes, and compliance requirements. The program includes policies and procedures for access control, incident response, data protection, and continuous improvement, among others, to safeguard our multi-tenant PaaS solution hosted on Microsoft Azure. | Is an Information Security Program that includes programs for all the relevant domains of the AICM developed and implemented? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs defined and documented? | Yes, roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs are defined and documented within our Information Security Management System (ISMS). This documentation includes detailed descriptions of roles such as the Information Security Manager, Information Security Team, and various asset and risk owners, ensuring clear accountability and authority for governance-related activities. This structure supports our commitment to continual improvement and effective governance as part of our ISO 27001 certified processes. | Are roles and responsibilities defined and documented for planning, implementing, operating, assessing, and improving governance programs? | Yes, Built Intelligence roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs are defined and documented within the platform’s Information Security Management System (ISMS). The documentation includes detailed descriptions of roles such as the Information Security Manager, Information Security Team, and various asset and risk owners. This structure ensures clear accountability and authority for governance- related activities. The approach supports continual improvement and effective governance practices, in alignment with ISO 27001 certified processes. |
| Are all relevant standards, regulations, legal/contractual, and statutory requirements applicable to your organization identified and documented? | Yes, all relevant standards, regulations, legal/contractual, and statutory requirements applicable to our organization are identified and documented. We maintain compliance with industry standards and certifications such as ISO 27001 and Cyber Essentials Plus. Our compliance framework is integrated into our Microsoft Azure-hosted platform, ensuring adherence to legal and regulatory requirements across all operational and infrastructure levels. | Are all relevant standards, regulations, legal/contractual, and statutory requirements, applicable to your organization, identified and documented? | Yes, Built Intelligence ensures that all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the organization are identified and documented. The platform adheres to ISO 27001 standards and maintains compliance with GDPR, Cyber Essentials Plus, and other pertinent frameworks. Regular internal and external audits are conducted to verify compliance and continuously improve security and data protection practices. |
| Are all relevant standards,regulations, legal/contractual and statutory requirements reviewed and updated at least annually or when a substantial change occurs within the organization? | Yes, Built Intelligence ensures that all relevant organizational policies and associated procedures, including standards, regulations, legal/contractual, and statutory requirements, are reviewed at least annually or when a substantial organizational change occurs. This process is part of their commitment to maintaining a robust Information Security Management System (ISMS) and is aligned with ISO 27001 best practices. The review process is documented and involves key stakeholders to ensure comprehensive oversight and continuous improvement. | ||
| Is contact established and maintained with related special interest groups and other relevant entities in line with business context? | Yes, Built Intelligence actively establishes and maintains contact with cloud- related special interest groups and other relevant entities. This engagement is designed to ensure that the platform remains up- to- date with the latest industry trends, best practices, and security standards in cloud computing. Such collaboration supports alignment with business context and enhances compliance with relevant regulations and standards, including those related to AI governance, risk management, and security controls. | ||
| Are policies and procedures defined, documented, and enforced for the acceptable use of AI services offered by the organization? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is effectiveness of the acceptable use of AI services policies and procedures evaluated by continuous risk assessments, reviews, and human oversight? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is an AI Impact Assessment process and its criteria to regularly evaluate the ethical, societal, operational, legal, and security impacts of the AI system throughout its lifecycle, established, documented, and communicated to all relevant stakeholders? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are AI systems, models, datasets & algorithms regularly evaluated for bias and fairness to ensure compliance with ethical standards? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is an ethics committee established to review AI applications, ensuring alignment with ethical standards and organizational values? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the degree of explainability required for the AI Services established, documented, and communicated? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the degree of explainability of the AI Services evaluated, documented, and communicated, including possible limitations and exceptions? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures, and technical measures to ensure human oversight and control of the AI system in compliance with regulatory requirements and organizational risk management, established, executed and assessed? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are background verification policies and procedures of all new employees (including but not limited to remote employees, contractors, and third parties) established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained background verification policies and procedures for all new employees, including remote employees, contractors, and third parties. These procedures are part of our ISO 27001 certified Information Security Management System (ISMS) and are regularly reviewed to ensure compliance and effectiveness in mitigating risks associated with hiring. | Are new employee background verification policies and procedures (including but not limited to remote employees, contractors, and third parties) established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained background verification policies and procedures for all new employees, including remote employees, contractors, and third parties. These processes are governed as part of the ISO 27001 certified Information Security Management System (ISMS) and are reviewed regularly to ensure effectiveness in mitigating risks related to hiring. Furthermore, background checks—including identity verification, right- to- work checks, employment history verification, and criminal background checks where legally permitted—are conducted in accordance with relevant local laws, regulations, ethical standards, and data protection requirements (e.g., UK GDPR and EU GDPR). All third- party suppliers and individual contractors undergo similar vetting and control processes, including Baseline Personnel Security Standard (BPSS) checks. - Controls are proportional to data classification, business requirements, and acceptable risk.- Policies and procedures are maintained and periodically reviewed for continued compliance and effectiveness.- All relevant personnel, including contractors and third parties, are subject to these procedures. |
| Are background verification policies and procedures designed according to local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, business requirements, and acceptable risk? | Yes, Built Intelligence ensures that background verification policies and procedures are designed according to local laws, regulations, ethics, and contractual constraints. These policies are proportional to the data classification to be accessed, business requirements, and acceptable risk. Our background checks are conducted in compliance with relevant laws such as UK GDPR and are aligned with our ISO 27001 certified Information Security Management System (ISMS), ensuring that personnel handling sensitive data meet security and integrity standards. | Are background verification policies and procedures designed according to local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, business requirements, and acceptable risk? | Yes, Built Intelligencehas established background verification checks for all employees that are compliant with relevant local laws, regulations, ethical standards, and data protection requirements (e.g., UK GDPR and EU GDPR). These checks are conducted using BBPS and include: - Identity verification- Right- to- work checks- Employment history verification- Criminal background checks where legally permitted adheres to ISO 27001 best practices, ensuring personnel who handle sensitive data meet security and integrity standards. All checks are performed in compliance with local labour laws and contractual obligations, maintaining proportionality to data classification, business needs, and acceptable risk levels. The policy is documented, enforced, and consistently applied to maintain a secure, compliant environment. |
| Are background verification policies and procedures reviewed and updated at least annually? | Yes, our background verification policies and procedures are reviewed and updated at least annually to ensure they remain effective and compliant with current legal and regulatory requirements. This is part of our commitment to maintaining a secure and trustworthy environment, as outlined in our ISO 27001 certified Information Security Management System (ISMS). | Are background verification policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence background verification policies and procedures are reviewed and updated at least annually. This process ensures ongoing effectiveness and compliance with current legal and regulatory requirements. The review and update of these policies form part of ’s commitment to security and trustworthiness, as outlined in its ISO 27001 certified Information Security Management System (ISMS). |
| Are policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets are established, documented, approved, communicated, applied, evaluated, and maintained. These policies are part of our Information Security Management System (ISMS) and are aligned with ISO 27001 standards, ensuring that all organizational assets are used appropriately and securely. Regular reviews and updates to these policies are conducted to adapt to new security threats and changes in the organization. | Are policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for defining allowances and conditions for the acceptable use of organizationally- owned or managed assets. These policies are part of the Information Security Management System (ISMS) and are aligned with ISO 27001 standards. Regular reviews and updates to these policies are conducted to ensure ongoing adaptation to new security threats and organizational changes, supporting AI governance and compliance objectives around asset management and acceptable use. |
| Are the policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets reviewed and updated at least annually? | Yes, the policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets are reviewed and updated at least annually. This is part of our commitment to maintaining a robust information security management system (ISMS), as outlined in our ISMS documentation and supported by our adherence to ISO 27001 standards. The review process is managed by our Information Security Team, ensuring that all updates align with the latest security practices and compliance requirements. | Are the policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets reviewed and updated at least annually? | Yes, Built Intelligence has the policies and procedures for defining allowances and conditions for the acceptable use of organizationally- owned or managed assets on the platform are reviewed and updated at least annually. This is conducted as part of the Information Security Management System (ISMS) and is aligned with ISO 27001 standards. The review process is managed by the Information Security Team to ensure updates adhere to current security practices and compliance requirements. |
| Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures requiring unattended workspaces to conceal confidential data. These policies are part of our ISO 27001 certified Information Security Management System (ISMS) and are regularly reviewed to ensure compliance and effectiveness in protecting confidential information. | Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures requiring unattended workspaces to conceal confidential data. These measures are part of their ISO 27001 certified Information Security Management System (ISMS) and are reviewed regularly to ensure ongoing compliance and effectiveness in protecting confidential information. |
| Are policies and procedures requiring unattended workspaces to conceal confidential data reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures requiring unattended workspaces to conceal confidential data at least annually. This is part of our ISO 27001 certified Information Security Management System (ISMS), ensuring continuous alignment with best practices for data protection and security. | Are policies and procedures requiring unattended workspaces to conceal confidential data reviewed and updated at least annually? | Yes, Built Intelligence established, documented, approved, communicated, enforced, and maintained policies and procedures requiring unattended workspaces to conceal confidential data. These policies and procedures are reviewed and updated at least annually in alignment with their ISO 27001 certified Information Security Management System (ISMS). This annual review ensures that the controls remain effective and compliant with evolving security requirements. |
| Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, and communicated policies and procedures to protect information accessed, processed, or stored at remote sites and locations. These policies are part of our ISO 27001 certified Information Security Management System (ISMS) and are regularly evaluated and maintained to ensure compliance and effectiveness. The procedures include secure remote access protocols, data encryption, and the use of VPNs, all monitored and managed within our Microsoft Azure infrastructure, ensuring robust security controls are consistently applied and reviewed. | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, and communicated policies and procedures to protect information accessed, processed, or stored at remote sites and locations. These controls are implemented as part of the ISO 27001 certified Information Security Management System (ISMS). The procedures include secure remote access protocols, data encryption, and the use of VPNs, all of which are monitored and managed within Microsoft Azure infrastructure. These policies and their associated controls are regularly evaluated and maintained to ensure ongoing compliance and effectiveness for users, aligning with AI governance and security best practices. |
| Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures to protect information accessed, processed, or stored at remote sites and locations at least annually. This is in alignment with our ISO 27001 certification requirements, ensuring that our information security management practices remain robust and effective. | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations reviewed and updated at least annually? | Yes, Built Intelligence’s policies and procedures for protecting information accessed, processed, or stored at remote sites and locations are reviewed and updated at least annually. This practice is part of the platform's ISO 27001 certified Information Security Management System (ISMS), ensuring that changes in operations, threats, or technologies are reflected in procedures to maintain ongoing security and compliance. |
| Are return procedures of organizationally-owned assets by terminated employees established and documented? | Yes, the return procedures of organizationally-owned assets by terminated employees are established and documented. These procedures are part of our operational controls and are enforced through our HR and IT departments to ensure compliance and security of assets. | Are return procedures of organizationally-owned assets by terminated employees established and documented? | Yes, Built Intelligence has established and documented procedures for the return and revocation of organizationally- owned assets upon the termination of employees and individual contractors. Specifically: - Formal termination and offboarding procedures are in place, which ensure that access by suppliers and contractors to systems and data is controlled, monitored, logged, and reviewed, and is removed promptly when no longer required.- These controls are applied consistently to both permanent employees and individual contractors, as part of the platform's ISO 27001- aligned Information Security Management System (ISMS).The documentation verifies that these processes are implemented and audited as part of broader security controls and compliance commitments. |
| Are procedures outlining the roles and responsibilities concerning changes in employment established, documented, and communicated to all personnel? | Yes, procedures outlining the roles and responsibilities concerning changes in employment are established, documented, and communicated to all personnel within the organization. These procedures are part of our internal security and compliance policies, ensuring that all employees are aware of their roles and responsibilities in the event of employment changes. This includes the management of access rights, responsibilities, and the secure handling of information during transitions. | Are procedures outlining the roles and responsibilities concerning changes in employment established, documented, and communicated to all personnel? | Yes, Built Intelligence has established, documented, and communicated procedures outlining roles and responsibilities concerning changes in employment to all personnel. These procedures are incorporated into internal security and compliance policies, ensuring employees are informed of their respective responsibilities during employment transitions. The scope of these procedures includes the management of access rights, assignment of responsibilities, and the secure handling of information throughout employment changes. This aligns with best practices for operational security controls under AI governance and information security compliance frameworks such as ISO 27001 and CAIQ. |
| Are employees required to sign an employment agreement before gaining access to organizational information systems, resources, and assets? | Yes, all employees are required to sign an employment agreement that includes clauses on confidentiality, data protection, and security responsibilities before gaining access to organizational information systems, resources, and assets. This ensures compliance with our security policies and regulatory requirements. | Are employees required to sign an employment agreement before gaining access to organizational information systems, resources, and assets? | Yes, Built Intelligence employees are required to sign an employment agreement that includes clauses on confidentiality, data protection, and security responsibilities before gaining access to organizational information systems, resources, and assets. This process ensures compliance with security policies and regulatory requirements, supporting robust human resource security aligned with ISO 27001 and AI governance best practices for access control and data protection. |
| Are provisions and/or terms for adherence to established information governance and security policies included within employment agreements? | Yes, provisions and terms for adherence to established information governance and security policies are included within employment agreements at Built Intelligence. These provisions mandate compliance with our ISO 27001 certified Information Security Management System (ISMS) and are enforced through regular audits and training, ensuring all employees understand their responsibilities regarding information security and governance. | Are provisions and/or terms for adherence to established information governance and security policies included within employment agreements? | Yes, Built Intelligence has provisions and terms for adherence to established information governance and security policies are included within employment agreements at. These agreements mandate compliance with the organization's ISO 27001 certified Information Security Management System (ISMS). Compliance is further supported through regular audits and training, ensuring all employees are aware of and understand their responsibilities regarding information security and governance. This approach aligns with best practices for AI governance, risk mitigation, and compliance frameworks such as ISO 27001 and CAIQ. |
| Are employee roles and responsibilities relating to information assets and security documented and communicated? | Yes, Built Intelligence has documented and communicated employee roles and responsibilities relating to information assets and security as part of our Information Security Management System (ISMS), which is compliant with ISO 27001 standards. This documentation includes specific roles such as the Information Security Manager, Asset Owners, and Information Security Risk Owner, each with clearly defined responsibilities and authorities regarding the management and protection of information assets. These roles and their responsibilities are communicated internally through training, policy documents, and our internal communication platforms. | Are employee roles and responsibilities relating to information assets and security documented and communicated? | Yes, Built Intelligence have established and documented procedures outlining roles and responsibilities concerning information assets and security. These procedures are communicated to all personnel as part of internal security and compliance policies. The documentation specifically states: - Procedures outlining roles and responsibilities in relation to employment changes—including access rights and secure handling of information—are established, documented, and communicated to all staff.- Employment agreements include clauses on confidentiality, data protection, security responsibilities, and adherence to established information governance and security policies.- Role- based access control (RBAC) is enforced within , with a three- tier hierarchy (system permissions, contract party roles, supplementary roles) to manage user permissions and responsibilities at multiple organizational levels.These measures align with control objectives from ISO 27001 and CAIQ, ensuring that roles and responsibilities for information security and governance are both documented and effectively communicated. |
| Are requirements for non-disclosure/confidentiality agreements reflecting organizational data protection needs and operational details identified, documented, and reviewed at planned intervals? | Yes, Built Intelligence ensures that requirements for non-disclosure and confidentiality agreements reflect organizational data protection needs and operational details. These agreements are identified, documented, and reviewed at planned intervals in alignment with our ISO 27001 certified Information Security Management System (ISMS). This process includes regular updates to address changes in legal, regulatory, and business environments, ensuring continuous protection of sensitive information and compliance with applicable laws and standards. | Are requirements for non-disclosure/confidentiality agreements reflecting organizational data protection needs and operational details identified, documented, and reviewed at planned intervals? | Yes, Built Intelligence ensures that requirements for non- disclosure and confidentiality agreements are established to reflect organizational data protection needs and operational details. These agreements are: - Identified and documented in alignment with the company’s ISO 27001 certified Information Security Management System (ISMS).- Reviewed at planned intervals to address evolving legal, regulatory, and business requirements.- Regularly updated to ensure ongoing protection of sensitive information and compliance with applicable laws and standards.This process supports control objectives related to documentation, periodic review, and the continuous alignment of data protection agreements with organizational and regulatory requirements. |
| Is a security awareness training program for all employees of the organization established, documented, approved, communicated, applied, evaluated and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained a security awareness training program for all employees as part of our ISO 27001 ISMS compliance. This program includes regular training sessions upon induction and annually thereafter, covering the importance of information security, the company's security policies, and employees' roles in maintaining security. The effectiveness of the training is reviewed regularly to ensure it meets our security objectives and compliance requirements. | Is a security awareness training program for all employees of the organization established, documented, approved, communicated, applied, evaluated and maintained? | Yes, Built Intelligence's security awareness training program is established, documented, approved, communicated, applied, evaluated, and maintained for all employees. provides comprehensive data protection and information security training to all staff as part of ISO 27001 compliance. The training program includes the following key elements: - Training is conducted upon hiring and retaken annually.- Content is developed in collaboration with a third- party cybersecurity consultant and delivered through the organization's Learning Management System (LMS).- Training covers security best practices, GDPR, Cyber Essentials Plus, and internal security policies.- This ensures consistent knowledge reinforcement and compliance with information security requirements.This aligns with AI governance and ISO 27001 control objectives for organizational awareness and personnel security. |
| Are regular security awareness training updates provided? | Yes, Built Intelligence provides regular security awareness training updates to all employees as part of our ISO 27001 compliance. Training sessions are conducted annually and whenever significant changes occur in security policies or threats. This ensures that our staff remains informed and vigilant about the latest security practices and threats. | Are regular security awareness training updates provided? | Yes, Built Intelligence has provides regular security awareness training updates to all employees as part of its ISO 27001 compliance program. Training sessions are conducted annually and whenever significant changes occur in security policies or emerging threats. This aligns with security governance and risk management best practices described in frameworks such as ISO 27001 and CAIQ, ensuring that staff remain informed and vigilant regarding the latest security practices and risk mitigations. |
| Are all employees granted access to sensitive organizational and personal data provided with appropriate security awareness training? | Yes, all employees granted access to sensitive organizational and personal data are provided with appropriate security awareness training. This training is mandatory upon hiring and is refreshed annually, aligning with our ISO 27001 compliance requirements. The training covers data protection, secure data handling, recognizing phishing attempts, and other security best practices to ensure that all employees are aware of their responsibilities in protecting sensitive information. | Are employees with access to sensitive organizational and personal data, provided with appropriate security awareness training and regular updates in organizational procedures, processes, and policies, relating to their professional function relative to the organization? | Yes, Built Intelligence employees who are granted access to sensitive organizational and personal data are provided with: - Mandatory security awareness training upon hiring, which is refreshed annually. This training addresses data protection, secure data handling, recognition of phishing attempts, and other security best practices.- Regular updates in procedures, processes, and policies relevant to their professional function, ensuring continued compliance with ISO 27001 and GDPR requirements.- Ongoing notifications about their roles and responsibilities regarding compliance with established policies, procedures, and regulatory obligations.These measures align with recognized frameworks such as ISO 27001 and serve to maintain a strong security culture and up- to- date employee awareness regarding the protection of sensitive data. |
| Are employees notified of their roles and responsibilities to maintain awareness and compliance with established policies, procedures, and applicable legal, statutory, or regulatory compliance obligations? | Yes, all employees at Built Intelligence are notified of their roles and responsibilities to maintain awareness and compliance with established policies, procedures, and applicable legal, statutory, or regulatory compliance obligations. This is ensured through our ISO 27001 certified Information Security Management System (ISMS), which includes mandatory training upon hiring and annual refreshers. Additionally, our internal communication platforms and management oversight ensure continual awareness and adherence to these obligations. | Are employees notified of their roles and responsibilities to maintain awareness and compliance with established policies, procedures, and applicable legal, statutory, or regulatory compliance obligations? | Yes, Built Intelligence ensures that procedures outlining the roles and responsibilities concerning changes in employment are established, documented, and communicated to all personnel. This process is part of the internal security and compliance policies, guaranteeing that employees are aware of their roles and responsibilities during employment transitions, including the management of access rights, responsibilities, and the secure handling of information. Furthermore, all employees granted access to sensitive organizational and personal data are provided with regular updates on procedures, processes, and policies relevant to their professional function. This supports ongoing awareness and compliance with established policies, procedures, and all applicable legal, statutory, and regulatory compliance obligations. These measures align with control objectives in frameworks such as ISO 27001 and the CAIQ, which require active communication and awareness of roles and responsibilities for information security and legal compliance. |
| Are the policies and procedures defining the AI training program for all relevant personnel of the organization established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are regular training updates given to personnel based on their roles? | Yes, Built Intelligence provides regular security awareness training updates to all employees, including those with access to sensitive organizational and personal data. The training is: - Mandatory upon hiring and refreshed annually for all employees.- Updated whenever significant changes occur in security policies or threats.- Tailored to cover data protection, secure data handling, recognizing phishing attempts, and other security best practices, ensuring relevance to employee roles and responsibilities.- Evaluated regularly to ensure alignment with security objectives and compliance requirements.This approach aligns with role- based awareness and the principle of ongoing personnel training as required by AI governance, ISO 27001, and CAIQ control objectives. | ||
| Are the policies and procedures on the acceptable use of AI technologies within the organization established, documented, and communicated to all personnel? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are identity and access management policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? | Yes, identity and access management policies and procedures are established, documented, approved, communicated, implemented, applied, evaluated, and maintained as part of our ISO 27001 certified Information Security Management System (ISMS). These policies cover role-based access control, user account lifecycle management, and regular access reviews, ensuring compliance with security best practices and regulatory requirements. | Are Identity and Access Management policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained for identity and access management? | Yes, Built Intelligence has identity and access management (IAM) policies and procedures are: - Established, documented, and approved as part of the ISO 27001 certified Information Security Management System (ISMS).- Communicated to all employees and relevant parties.- Implemented and consistently applied, covering role- based access control, user account lifecycle management, and enforcement of the principle of least privilege.- Regularly evaluated and maintained, including annual reviews to ensure effectiveness and compliance with current security standards and regulations.These practices ensure robust IAM controls aligned with AI governance and ISO 27001/CAIQ requirements, including provisions for secure role assignment, access revocation, and alignment with regulatory compliance obligations. |
| Are identity and access management policies and procedures reviewed and updated at least annually? | Yes, our identity and access management policies and procedures are reviewed and updated at least annually to ensure they remain effective and compliant with current security standards and regulations. This regular review is part of our commitment to maintaining a robust security posture and is aligned with our ISO 27001 certification requirements. | Are Identity and Access Management Policies and Procedures reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are strong password policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? | Yes, FastDraft has established, documented, approved, communicated, implemented, applied, evaluated, and maintained strong password policies and procedures. These policies align with the UK National Cyber Security Centre guidance, ensuring robust password complexity, regular changes, and prohibiting password reuse. Additionally, two-factor authentication enhances security for user accounts, especially when accessing from non-trusted networks. These practices are part of our ISO 27001 certified Information Security Management System, ensuring continuous evaluation and improvement of our password management procedures. | Are strong password policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? | Yes, Built Intelligence enforces strong password policies and procedures as part of its ISO 27001 certified Information Security Management System (ISMS). The key controls and practices include: - Establishment & Implementation:Password policies are established and implemented, requiring passwords to be at least 16 characters in length and enforcing strong, unique password construction aligned with UK National Cyber Security Centre guidance. - Documentation & Approval:These policies are documented, approved, and form part of the ISO 27001 ISMS governance program. - Communication:Policies and expectations are communicated to all employees, with required training at hiring and annual refreshers. - Application & Maintenance:Password policies are applied across the platform for enterprise clients, including support for multi- factor authentication via SSO with supported identity providers. - Evaluation & Review:Identity and access management (including password policies) are reviewed and updated at least annually as part of ongoing compliance with ISO 27001 and continual improvement practices. These controls collectively demonstrate that strong password policies and procedures are established, documented, approved, communicated, implemented, applied, evaluated, and maintained in alignment with security, regulatory, and ISO 27001 requirements. |
| Are strong password policies and procedures reviewed and updated at least annually? | Yes, our strong password policies and procedures are reviewed and updated at least annually to align with the latest security best practices and compliance requirements, including guidance from the UK National Cyber Security Centre. This review is part of our ISO 27001 certified Information Security Management System, ensuring that our password policies remain robust and effective in protecting user data and access. | Are strong password policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence’s strong password policies and procedures are reviewed and updated at least annually. This review process ensures alignment with current security best practices and compliance requirements, including guidance from the UK National Cyber Security Centre. The periodic review of password policies is conducted as part of 's ISO 27001 certified Information Security Management System (ISMS), ensuring that password controls remain robust and effective in protecting user data and access. |
| Is system identity information and levels of access managed, stored, and reviewed? | Yes, system identity information and levels of access are managed, stored, and reviewed at FastDraft. We utilize Azure Active Directory for identity management and role-based access control (RBAC) to ensure appropriate access levels. Regular reviews and audits of access rights are conducted in line with our ISO 27001 certified Information Security Management System (ISMS) to maintain security and compliance. | Is the inventory of identities managed, stored and regularly reviewed, and is their level of access monitored? | Yes, Built Intelligence manages, stores, and regularly reviews the inventory of system identities and their access levels. Specifically: - System identity information and access levels are managed and stored using Azure Active Directory.- Role- Based Access Control (RBAC) is employed to ensure appropriate and minimum necessary access assignments for each identity.- Regular reviews and audits of access rights are conducted in accordance with 's ISO 27001 certified Information Security Management System (ISMS).- This process includes ongoing monitoring to maintain security and compliance, ensuring that access rights are aligned with the principle of least privilege and that unauthorized access risks are minimized.These practices address control objectives related to identity governance, access control monitoring, and compliance with ISO 27001 requirements. |
| Is the separation of duties principle employed when implementing information system access? | Yes, the separation of duties principle is employed in the implementation of information system access at FastDraft. This is achieved through role-based access controls (RBAC) which ensure that access rights are granted according to the roles assigned to users within the organization. This approach minimizes the risk of unauthorized access and ensures that users only have access to the information and functions necessary for their specific roles. Additionally, our Information Security Team, as part of the ISMS, regularly reviews and updates access controls to maintain compliance and security standards. | Are separation of duties principles employed when implementing information system access? | Yes, Built Intelligence employs the separation of duties principle in the implementation of information system access. This is achieved through the use of role- based access controls (RBAC), which ensure that access rights are granted according to user roles within the organization. The approach minimizes the risk of unauthorized access by restricting users to the information and functions necessary for their specific roles. Regular reviews and updates of access controls are performed by the Information Security Team as part of ’s ISO 27001- aligned Information Security Management System (ISMS) to maintain compliance and security standards. |
| Is the least privilege principle employed when implementing information system access? | Yes, the least privilege principle is employed in the implementation of information system access at Built Intelligence. We utilize Role-Based Access Control (RBAC) to ensure that users are granted access only to the resources necessary for their roles. This approach is consistently applied across all systems and services, including those managed by subcontractors, in alignment with our ISO 27001 and Cyber Essentials Plus certifications. | Are least privilege principles employed when implementing information system access? | Yes, Built Intelligence's least privilege principle is employed when implementing information system access in. This is achieved through the use of Role- Based Access Control (RBAC), ensuring users are granted access only to the resources necessary for their roles. The principle is consistently applied across all systems and services, including those managed by subcontractors. This approach aligns with ISO 27001 and Cyber Essentials Plus certifications, supporting comprehensive access management and risk mitigation in accordance with recognized security frameworks. |
| Is a user access provisioning process defined and implemented which authorizes, records, and communicates data and assets access changes? | Yes, FastDraft has a defined and implemented user access provisioning process that authorizes, records, and communicates data and assets access changes. This process is integrated with Microsoft Azure's infrastructure, utilizing Azure Active Directory for identity management and access control. Changes in access are logged and monitored through Azure's security and compliance centers, ensuring that all modifications are authorized, recorded, and communicated appropriately. This process is in line with our ISO 27001 and Cyber Essentials Plus certifications, which emphasize the importance of secure access control and audit trails. | Is an identity access provisioning process which authorizes, records, and communicates access changes to data and assets, defined and implemented? | Yes, Built Intelligence has defined and implemented user access provisioning process that authorizes, records, and communicates data and asset access changes. This process is integrated with Microsoft Azure's infrastructure, utilizing Azure Active Directory for identity management and access control. All changes in access are logged and monitored through Azure's security and compliance centers, ensuring authorization, record- keeping, and communication of any modifications. These processes are designed in line with ISO 27001 and Cyber Essentials Plus certifications, emphasizing secure access control and audit trail requirements. This approach fulfills CAIQ and ISO 27001 control requirements related to identity and access management. |
| Is a process in place to de-provision or modify the access, in a timely manner, of movers / leavers or system identity changes, to effectively adopt and communicate identity and access management policies? | Yes, FastDraft has a process in place to de-provision or modify access for movers, leavers, or system identity changes in a timely manner. This process is part of our identity and access management policies, which are enforced through role-based access controls and automated workflows within the Microsoft Azure infrastructure. Changes in user status are communicated and implemented promptly to ensure that access rights are always current and secure. This capability is supported by Azure Active Directory, which provides robust tools for managing and securing identities. | Is identity access de-provisioned or modified, in a timely manner? | Yes, Built Intelligence enforces strict onboarding and offboarding procedures to ensure that user accounts are revoked when no longer required. This process is part of a formal user access policy, which applies to both employees and subcontractors. The policy aligns with ISO 27001 requirements and supports the principle of least privilege (PoLP) and role- based access control (RBAC). Regular access reviews further ensure that de- provisioning or modification of access is conducted in a timely and auditable manner to maintain security and compliance. |
| Are reviews and revalidation of user access for least privilege and separation of duties completed with a frequency commensurate with organizational risk tolerance? | Yes, reviews and revalidation of user access for least privilege and separation of duties are completed with a frequency that aligns with our organizational risk tolerance. These reviews are conducted quarterly as part of our ISO 27001 access control procedures. We ensure that access rights are appropriate, enforce the principle of least privilege, and maintain separation of duties across all user roles. This process is supported by our role-based access control (RBAC) system and is audited regularly to ensure compliance and effectiveness. | Are user access for least privilege and separation of duties reviewed and revalidated with a frequency commensurated with organizational risk tolerance and at least annually or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures for the segregation of privileged access roles defined, implemented, and evaluated such that administrative data access, encryption, key management capabilities, and logging capabilities are distinct and separate? | Yes, processes, procedures, and technical measures for the segregation of privileged access roles are defined, implemented, and evaluated within our organization. We ensure that administrative data access, encryption key management, and logging capabilities are distinct and separate. This is managed through role-based access controls (RBAC) and privileged access management (PAM) systems, which enforce the principle of least privilege across our Microsoft Azure-hosted infrastructure. Our approach aligns with ISO 27001 standards and our internal information security policies, ensuring effective segregation of duties and minimizing the risk of unauthorized access or data breaches. | Are processes, procedures, and technical measures for the segregation of privileged access roles, defined, implemented, and evaluated? | Yes, Built Intelligence established and maintains processes, procedures, and technical measures for the segregation of privileged access roles. Specifically: - Defined and implemented separation of administrative data access, encryption key management, and logging capabilities using role- based access control (RBAC) and privileged access management (PAM) systems.- RBAC enforces least privilege and segregation of duties, ensuring that privileges for administrative functions are distinct and appropriately assigned.- These controls are evaluated regularly and align with ISO 27001 standards and internal security policies to minimize risks of unauthorized access or data breaches.This approach demonstrates implementation and ongoing evaluation of access segregation in line with international compliance frameworks and best practices. |
| Is an access process defined and implemented to ensure privileged access roles and rights are granted for a limited period? | Yes, an access process is defined and implemented to ensure that privileged access roles and rights are granted for a limited period. Privileges are allocated on a need-to-use and event-by-event basis, with the request for allocation of a privilege initiated and documented by the user concerned to the Asset Owner or Information Security Manager. This documentation sets out the reasons why the privilege is required and the length of time for which it is required. The Information Security Manager retains a log of all privileges authorized and allocated and checks on a regular basis that they have been deactivated as specified in the original request. | Is an access process defined and implemented to ensure privileged access roles and rights are granted for a time-limited period? | Yes, Built Intelligence defines and implements an access process to ensure that privileged access roles and rights are granted only for a limited period. Specifically, privileges are allocated on a need- to- use and event- by- event basis. The allocation process involves the user requesting permission from the Asset Owner or Information Security Manager, clearly stating the business justification and required duration. All privileged access requests are documented, and the Information Security Manager maintains a log of all authorizations. Regular reviews are conducted to verify that privileged rights are deactivated as specified in the original request. These controls align with ISO 27001 standards and are designed to minimize the risk of unauthorized access or privilege persistence beyond the intended period. |
| Are procedures implemented to prevent the culmination of segregated privileged access? | Yes, FastDraft implements procedures to prevent the culmination of segregated privileged access. We utilize role-based access control (RBAC) within Microsoft Azure to enforce strict segregation of duties. Each role is defined with specific permissions that limit access to necessary resources only. Additionally, Azure Active Directory (AAD) is used for identity management, ensuring that access rights are granted based on the principle of least privilege. These controls are audited regularly to ensure compliance with our ISO 27001 and Cyber Essentials Plus certifications. | Are procedures implemented to prevent the accumulation of segregated privileged access? | Yes, Built Intelligence implements comprehensive procedures to prevent the accumulation of segregated privileged access, aligning with CAIQ and ISO 27001 control requirements. Key controls include: - Role- Based Access Control (RBAC):Privileged access is managed through RBAC, ensuring that administrative data access, encryption key management, and logging capabilities are distinct and not concentrated in a single role. - Separation of Duties: enforces the principle of least privilege and maintains segregation between privileged roles, supported by regular audits and policy enforcement. - Privilege Reviews:Access rights for privileged users are reviewed and revalidated quarterly as part of formal ISO 27001 access control procedures, minimizing the risk of privilege accumulation over time. - Privileged Access Management (PAM):The documentation confirms the use of privileged access management systems to ensure that administrative controls cannot be accumulated by individual users. These measures collectively address the risk of privilege accumulation and demonstrate continuous compliance with recognized AI governance and security standards. |
| Are processes and procedures for customers to participate, where applicable, in granting access for agreed, high risk as (defined by the organizational risk assessment) privileged access roles defined, implemented and evaluated? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes and procedures for customers to participate in granting access for high-risk privileged access roles, as defined by our organizational risk assessment. These procedures are aligned with ISO 27001 standards and include customer involvement where applicable, ensuring that access is granted following strict guidelines and oversight. | Are processes and procedures defined, implemented, and evaluated for customers to participate, where applicable, in granting access for agreed high-risk (as defined by the organizational risk assessment) privileged access roles? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures to ensure the logging infrastructure is "read-only" for all with write access (including privileged access roles) defined, implemented, and evaluated? | Yes, processes, procedures, and technical measures are defined, implemented, and evaluated to ensure that the logging infrastructure is "read-only" for all users, including those with privileged access roles. Our system administrators are prohibited from erasing or deactivating logs of their own activities. Audit log reports are classified as confidential information and must be handled in line with our Information Security Management System (ISMS) requirements. Controls have been implemented to protect against unauthorized changes, alterations, editing, deletion, and overwriting of log information. System logs are securely stored and archived in line with record retention requirements, ensuring compliance with our ISO 27001 and Cyber Essentials Plus certifications. | Are processes, procedures, and technical measures defined, implemented, evaluated to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it, is controlled through a procedure that ensures the segregation of duties and break glass procedures? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures that ensure users are identifiable through unique identification (or can associate individuals with user identification usage) defined, implemented, and evaluated? | Yes, FastDraft implements processes, procedures, and technical measures that ensure users are uniquely identifiable through user identification. This is achieved through the use of Microsoft Azure Active Directory (Azure AD) for identity management, which supports unique user identification and authentication. We regularly evaluate these measures to ensure compliance with security best practices and our ISO 27001 certification requirements. This includes regular audits, reviews, and updates to our identity management protocols to maintain the integrity and security of user identification. | Are processes, procedures, and technical measures, that ensure identities’ activities are identifiable through uniquely associated IDs, defined, implemented, and evaluated? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures to ensure that user identities and their activities are uniquely identifiable. This is achieved through the following controls: - Use of Microsoft Azure Active Directory (Azure AD) for identity management, providing unique user identification and authentication.- Established procedures for uniquely associating users with their identification records and usage activities.- Regular evaluation of identity management protocols, including audits, reviews, and updates, to ensure ongoing compliance with security best practices and ISO 27001 certification requirements.These measures provide clear traceability of user actions and reinforce accountability, aligning with AI governance and ISO 27001 control objectives regarding identity and access management. |
| Are processes, procedures, and technical measures for authenticating access to systems, application, and data assets including multifactor authentication for a least-privileged user and sensitive data access defined, implemented, and evaluated? | Yes, processes, procedures, and technical measures for authenticating access to systems, applications, and data assets are defined, implemented, and evaluated at FastDraft. We utilize Microsoft Azure's infrastructure capabilities to enforce multifactor authentication (MFA) and role-based access control (RBAC) to ensure that access is granted based on the principle of least privilege. Azure Active Directory (Azure AD) is used to manage identities and enforce authentication policies, including MFA, particularly for accessing sensitive data. These measures are regularly reviewed and updated to comply with our security policies and industry best practices, including ISO 27001 and Cyber Essentials Plus standards. | Are processes, procedures, and technical measures defined, implemented, and evaluated for authenticating access to systems, applications, and data assets, including multifactor authentication for at least privileged user and sensitive data access? | Yes, Built Intelligence has established, implemented, and evaluates robust authentication controls for access to systems, applications, and data assets. Key measures include: - Formal user access policy governed by ISO 27001 ISMS, ensuring consistent and secure access management for both employees and subcontractors.- Enforcement of Multi- Factor Authentication (MFA) and Single Sign- On (SSO) for authenticating access, particularly for administrative or privileged roles, as well as sensitive data assets.- Role- Based Access Control (RBAC) to ensure access is granted strictly on the principle of least privilege.- Regular access reviews and onboarding/offboarding procedures to ensure timely revocation or granting of access when required.These controls are regularly reviewed, audited, and are consistent across all users and subcontractors, aligning with ISO 27001 and industry best practices for authentication and access management. |
| Are digital certificates or alternatives that achieve an equivalent security level for system identities adopted? | Yes, FastDraft adopts digital certificates and alternatives that achieve an equivalent security level for system identities. We utilize Microsoft Azure's infrastructure, which includes Azure Key Vault for managing secrets and certificates securely. Additionally, our implementation of Single Sign-On (SSO) and Multi-Factor Authentication (MFA) across all modules and functional areas further enhances the security of system identities. These measures align with industry best practices and compliance standards, ensuring robust security for system identities within our platform. | Are digital certificates or alternatives adopted that achieve an equivalent level of security for system identities? | Yes, Built Intelligence adopts digital certificates that provide an equivalent level of security for system identities. Specifically, the platform utilizes Microsoft Azure's infrastructure, including Azure Key Vault for secure management of secrets and certificates. Additionally, Single Sign- On (SSO) and Multi- Factor Authentication (MFA) are implemented across all modules and functional areas to further strengthen system identity security. These controls align with industry best practices and compliance standards, such as ISO 27001, ensuring robust authentication and identity protection measures within the platform. |
| Are processes, procedures, and technical measures for the secure management of passwords defined, implemented, and evaluated? | Yes, FastDraft has defined, implemented, and regularly evaluates processes, procedures, and technical measures for the secure management of passwords. These measures are aligned with the UK National Cyber Security Centre guidance and include the use of strong, unique passwords, regular password changes, and multi-factor authentication. Additionally, password management is supported by Auth0's IDaaS platform, which provides features such as password strength monitoring and one-time passwords. These practices are part of our ISO 27001 compliant Information Security Management System, ensuring robust security controls and continuous improvement. | Are processes, procedures, and technical measures defined, implemented, and evaluated for the secure management of passwords and other secrets? | Yes, Built Intelligence has established a formal user access policy under its ISO 27001 Information Security Management System (ISMS), covering password and secrets management through enforceable controls such as Multi- Factor Authentication (MFA), Single Sign- On (SSO), and Role- Based Access Control (RBAC). - Password Management Features:Users are enabled to reset passwords securely via their official email addresses. With SSO enabled, password management is typically handled by the customer's authoritative identity provider (e.g., Azure Active Directory). If federated services are used, both native and directory- based password resets are supported. - User Training and Password Strength:The platform provides interactive training on ISO 27001 policies and enforces password best practices by offering LastPass for password generation. LastPass enforces a minimum password length of 16 characters and provides tools to measure password strength. - Regular Review and Access Revocation:Regular access reviews and strict onboarding/offboarding processes are enforced, ensuring prompt revocation of credentials no longer required, aligned with ISO 27001 best practices. These documented features demonstrate that has defined, implemented, and periodically evaluated technical and procedural controls for secure password and secrets management in accordance with AI governance and ISO 27001 objectives. No explicit mention of secrets management outside of user credentials is provided in the available documentation. |
| Are processes, procedures, and technical measures to verify access to data and system functions authorized, defined, implemented, and evaluated? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures to verify and authorize access to data and system functions. Our access control procedures are aligned with ISO 27001 standards and include role-based access controls (RBAC), multi-factor authentication (MFA), and regular access reviews to ensure that access rights are appropriate and up-to-date. These measures are supported by Microsoft Azure's infrastructure, which provides advanced security features such as Azure Active Directory for identity management and Azure Role-Based Access Control. We conduct regular audits and reviews to ensure compliance and effectiveness of these controls. | Are processes, procedures, and technical measures defined, implemented, and evaluated to verify access to data and system functions are authorized? | Yes, Built Intelligence has established processes, procedures, and technical measures to verify that access to data and system functions is authorized. The following controls are in place and aligned with ISO 27001 and CAIQ requirements: - Formal User Access Policy:A comprehensive user access policy is enforced, ensuring secure management of access to systems and data for both employees and subcontractors. - Role- Based Access Control (RBAC):Access rights are assigned based on defined roles and the principle of least privilege. Only necessary access is granted to users relevant to their job responsibilities. - Access Reviews:Regular reviews and revalidation of user access are completed, at least quarterly, to confirm that access privileges remain appropriate. - Onboarding/Offboarding Procedures:Strict onboarding and offboarding policies ensure that only authorized individuals retain access, and privileges are promptly revoked when no longer required. - Multi- Factor Authentication (MFA) & Single Sign- On (SSO):These mechanisms are deployed to further authenticate authorized access to the platform. - Evaluation & Auditing:All access control measures are regularly audited to ensure effectiveness and compliance with internal policies and regulatory requirements. These practices demonstrate a robust framework for ensuring that system access is authorized, controlled, and verifiable, in accordance with AI governance and ISO 27001 best practices. |
| Are policies and procedures defined for "need to know" access to knowledge, information and data within the organization and in the context of the AI system to be applied when regulating access to resources? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are role for access when allowing model output modification of AI-generated output established to ensure changes are made only by authorized identities? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are agents' access to the tools and plugins necessary for the activity or use case at hand, restricted to ensure adherence to the principles of need-to-know and least privilege? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for communications between application services (e.g., APIs)? | Yes, FastDraft has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for communications between application services, including APIs. These are governed by our comprehensive Information Security Management System (ISMS), which aligns with ISO 27001 standards. Our API documentation, which is available upon request, details the security measures and protocols in place to ensure secure and effective communication between services. This includes authentication, authorization, encryption, and secure data transmission standards. Additionally, our use of Microsoft Azure infrastructure provides built-in security controls and compliance frameworks to further safeguard these communications. | Are interoperability and portability policies and procedures established, documented, approved, communicated, evaluated, and maintained, including requirements for: a. Communications between application interfaces b. Information processing interoperability c. Application development portability d. Information/Data exchange, usage, portability, integrity, and persistence? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures that address interoperability and portability requirements in alignment with ISO 27001 standards. Specifically, the following controls are in place: - Communications between application interfaces:Policies and procedures governing secure and interoperable communications are covered as part of the platform's Information Security Management System (ISMS), which is reviewed and maintained regularly. - Information processing interoperability:The platform is built on Microsoft Azure PaaS, supporting flexibility and interoperability across different environments. Procedures are established to ensure effective information processing interoperability. - Application development portability:Documented policies are in place to address application portability, ensuring that development practices promote scalability and environmental flexibility. - Information/Data exchange, usage, portability, integrity, and persistence:Procedures address secure data exchange, usage, portability, integrity checks, and data persistence. These are regularly reviewed, aligned with ISO 27001, and ensure compliance with data protection laws. All such policies and procedures are formally reviewed and updated at least annually to address emerging security requirements and technological changes. |
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information processing interoperability? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for information processing interoperability. These are aligned with ISO 27001 standards and are part of our Information Security Management System (ISMS). Interoperability procedures ensure that our systems, including FastDraft, effectively interact with other systems, both internally and with third-party services, maintaining security and functionality. These procedures are regularly reviewed and updated to adapt to new technological and business requirements. | Are interoperability and portability policies and procedures reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are CSCs able to programmatically retrieve their data via an application interface(s) to enable interoperability and portability? | Yes, FastDraft supports interoperability and portability by allowing CSCs to programmatically retrieve their data via application interfaces. Our platform provides robust API access that enables seamless integration with other systems, ensuring that data can be efficiently exchanged and utilized across different platforms. This capability is supported by our use of Microsoft Azure PaaS services, which ensure secure and scalable interactions with external applications. | Are application interface(s) to AICs provided so that they programmatically retrieve their data to enable interoperability and portability? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are cryptographically secure and standardized network protocols implemented for the management, import, and export of data? | Yes, FastDraft implements cryptographically secure and standardized network protocols for the management, import, and export of data. We use TLS 1.2 or higher for all data in transit and AES-256 encryption for data at rest, ensuring compliance with industry standards and best practices. These protocols are part of our ISO 27001 certified Information Security Management System, ensuring secure and standardized handling of data across our platform. | Are cryptographically secure and standardized network protocols implemented for the management, import, and export of data, according to industry standards? | Yes, Built Intelligence implements cryptographically secure and standardized network protocols for the management, import, and export of data. Specifically: - All data in transit is secured using TLS 1.2 or higher.- Data at rest is encrypted using AES- 256 encryption.- These protocols comply with industry standards and best practices and are enforced as part of 's ISO 27001 certified Information Security Management System.This ensures that the platform aligns with recognized control objectives for secure data transmission and storage within AI governance and risk management frameworks. |
| Do agreements include provisions specifying CSC data access upon contract termination, and have the following? a. Data format b. Duration data will be stored c. Scope of the data retained and made available to the CSCs d. Data deletion policy | Yes, Built Intelligence includes comprehensive data exit and retention provisions in all customer contracts for the FastDraft platform. Upon contract termination, customers (CSC) can request a copy of their data in commonly used formats such as SQL backups, CSV exports, or structured JSON files (a). Data is retained as per the agreed rentention policies in the contract (b). The scope of accessible data includes all user-generated content, file uploads, and transaction records associated with the customer’s project(s) (c). After the retention window, data is securely deleted following our documented data deletion policy, which complies with ISO 27001 and GDPR requirements (d). | Are agreements including provisions specifying AICs access to data upon contract termination, including: a. Data format b. Length of time the data will be stored c. Scope of the data retained and made available to the AICs d. Data deletion policy? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Has the organization established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for infrastructure and virtualization security? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are these policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence ’s cryptography, encryption, and key management policies and procedures are reviewed and updated at least annually. The Information Security Team ensures these reviews occur in accordance with the ISMS policies, which also require additional reviews in response to emerging risks or business environment changes. This annual and change- driven review process is in alignment with ISO 27001 standards for continuous improvement and risk mitigation. | ||
| Are availability, quality and the adequate capacity of resources, being planned and monitored in order to deliver the required system performance as determined by the business? | Yes, Built Intelligence employs the following controls to ensure availability, quality, and adequate capacity of resources for system performance: - is built and hosted on an industry- recognised, robust coding platform, supporting effective operation with standard broadband connections and modern web browsers. No additional software installations are required, streamlining resource requirements for users.- The platform supports contract data quality through standardized formatting, use of dropdowns, check- boxes, radio buttons, mandatory/optional field configuration, and character limits for free- text fields. These features ensure consistent data entry and support business requirements for system quality.- Business continuity and operational resiliency strategies are based on risk assessments and business impact analyses. Regular review and testing of the Business Continuity Plan (BCP) and Disaster Recovery (DR) protocols, in accordance with ISO 27001, further bolster system availability and resource planning.- The organization maintains ISO 27001 and ISO 9001 certifications, providing formal frameworks for ongoing risk assessment, resource management, and continual improvement across operations.Capacity and quality controls are planned, implemented, and monitored as part of documented governance and management processes to ensure system performance aligns with business requirements. | ||
| Are communications between environments being monitored, encrypted, and restricted to only authenticated and authorized connections, as justified by the business? | Yes, Built Intelligence implements the following controls regarding communications between environments, in alignment with AI governance and CAIQ/ISO 27001 security objectives: - Encryption:Communications between environments are encrypted. The platform operates exclusively over HTTPS using the latest TLS protocols to ensure privacy and data integrity for all data in transit between clients and Azure services. - Authentication and Authorization:Administrative and internal access to the platform utilizes strong identity and access controls, including multi- factor authentication (MFA), conditional access policies, and device identity recognition. Device- level trust policies and certificates are required to authenticate internal connections, supporting a zero- trust architecture. - Monitoring and Restriction:Access to environments is monitored and restricted to solely authorized personnel. Physical and logical access controls are in place, and access control records are retained and reviewed regularly in accordance with the organization's ISO 27001 certified ISMS. These controls ensure that communications are encrypted, actively monitored, and accessible only to authenticated and authorized connections, as justified by business and compliance requirements. | ||
| Are these configurations reviewed at least annually and supported by a documented justification of all allowed services, protocols, ports, and compensating controls? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are the host and guest OS, hypervisor, or infrastructure control plane, being hardened according to their respective best practices and supported by technical controls as part of a security baseline? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are production and non-production environments kept separate? | Yes, Built Intelligence's production and non- production environments are fully separated. The controls in place include: - Development, test, and production environments are logically and securely isolated to prevent unauthorized access or cross- contamination of data and services.- Only anonymized or synthetic data is used in development and test environments to protect customer confidentiality and comply with GDPR and ISO 27001 requirements.- Role- based access controls and permissions are enforced according to the principle of least privilege, restricting access to authorized personnel only.Additionally, AI- powered components such as SupportBot are deployed in non- production environments with network restrictions and private endpoints, and no cross- environment data transfer occurs.These measures directly map to standard requirements in security frameworks like ISO 27001 and are consistent with CAIQ controls for environment segregation and data protection. | ||
| Are applications and infrastructures designed, developed, deployed and configured such that tenant access is appropriately segmented, segregated, monitored, and restricted from other tenants? | Yes, Built Intelligence maintains cryptography, encryption, and key management controls to protect data in transit and at rest. - TLS is used for data in transit, and platform services provide encryption at rest. - Key management is centralized with restricted access, logging, and rotation practices. - Cryptographic and key management changes follow formal change control with risk assessment. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are secure and encrypted communication channels used when migrating servers, services, applications or data to hosted environments? | Yes, Built Intelligence utilizes secure and encrypted communication channels—including only up- to- date and approved protocols—when migrating servers, services, applications, or data to cloud environments. Specifically, the platform employs TLS 1.2 or higher for all data in transit and AES- 256 encryption for data at rest. These practices align with industry best practices and regulatory requirements for data protection, supporting compliance with ISO 27001 and CAIQ control objectives regarding secure data migration and transmission. | ||
| Are such channels including only up-to-date and approved protocols? | Yes, Built Intelligence all data transfers, including channels for personal or sensitive data, are protected through the implementation of up- to- date and approved protocols. Specifically, data transfers are secured using encryption protocols such as TLS 1.2 or higher. These measures are regularly evaluated and are aligned with the ISO 27001 certified Information Security Management System (ISMS) to ensure compliance with relevant laws and regulations, including GDPR. - Encryption protocols used: TLS 1.2 or higher- Processes are regularly evaluated for effectiveness- Alignment with ISO 27001 controls and GDPR | ||
| Are high-risk environments identified and documented? | Yes, Built Intelligence supports the identification and documentation of high- risk environments as part of its operational and enterprise risk management processes. Specifically: - utilizes a structured approach to Operational Risk Management (ORM) and Enterprise Risk Management (ERM), including regular risk assessments that cover security, compliance, system availability, and data integrity.- High- risk environments and activities are identified through threat modelling, vulnerability assessments, penetration testing, and business continuity planning.- The risk management framework integrates identification and review of risks, with escalation procedures via the security committee to ensure proper documentation and alignment with business objectives and regulatory requirements.Therefore, risk environments—including high- risk categories—are systematically identified and documented through formal processes aligned with ISO 27001 and ISO 9001 frameworks. | ||
| Are processes, procedures, and defense-in-depth techniques for the protection, detection, and timely response to network-based attacks, defined, implemented and evaluated? | Yes, Built Intelligence's defense- in- depth security measures aligned with ISO 27001 and CAIQ control objectives for protection, detection, and response to network- based attacks. Specifically: - Protection: infrastructure utilizes Azure- native firewalls, DDoS protection, Virtual Network (VNet) isolation, and endpoint protection to prevent unauthorized access. All data is encrypted at rest (AES- 256) and in transit (TLS 1.2/1.3). Strict access controls, Role- Based Access Control (RBAC), and Privileged Access Management (PAM) are enforced to follow the principle of least privilege. - Detection:Continuous threat monitoring is in place using Microsoft Security Center and Defender, providing real- time detection of suspicious activities. Automated vulnerability scanning is conducted across the platform. - Response:There is continuous threat monitoring that supports real- time response to suspicious security events. Data Loss Prevention (DLP) policies and automated security audits help ensure timely mitigation of risks. - Governance:’s security model is reviewed through regular security assessments, annual penetration testing, and maintains compliance with ISO 27001 and Cyber Essentials Plus certifications. These controls demonstrate that processes, procedures, and defense- in- depth techniques for network security are defined, implemented, and regularly evaluated. | ||
| Are logging and monitoring policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, logging and monitoring policies and procedures are established, documented, approved, communicated, applied, evaluated, and maintained as per our ISMS documentation. These procedures are integral to our operations and compliance with security standards, including ISO 27001. We utilize Azure's native capabilities such as Azure Monitor and Azure Security Center to ensure comprehensive logging and real-time monitoring. These tools help us maintain and manage the security and performance of our infrastructure effectively. | Are logging and monitoring policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence employs comprehensive logging and monitoring controls as part of its security framework. The platform implements: - Continuous threat monitoring using Microsoft Security Center and Defender to ensure real- time detection and response to suspicious activities.- User activity logging and automated security audits to track and analyze events, supporting the principle of least privilege and risk mitigation.- Annual penetration testing and regular security assessments to evaluate and adjust monitoring controls.- Policies and procedures aligned with ISO 27001 standards, which are established, documented, approved, communicated, applied, evaluated, and maintained as part of 's Information Security Management System (ISMS).These controls collectively address the requirements for establishing, documenting, approving, communicating, applying, evaluating, and maintaining logging and monitoring policies and procedures for effective security and compliance management. |
| Are policies and procedures reviewed and updated at least annually? | Yes, our policies and procedures are reviewed and updated at least annually to ensure they remain effective and compliant with current regulations and standards. This is part of our commitment to maintaining robust security and compliance frameworks, as outlined in our internal documentation and supported by our ISO 27001 certification. | Are policies and procedures reviewed, approved and updated at least annually, or upon significant changes? | Yes, Built Intelligence ensures that key policies and procedures—including those related to cryptography, encryption, and key management—are reviewed and updated at least annually or upon significant changes. This process is managed by the Information Security Team in accordance with Information Security Management System (ISMS) policies and aligns with ISO 27001 standards. The established review cadence ensures the policies remain current relative to emerging risks and business changes. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure audit log security and retention? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to ensure the security and retention of audit logs. These measures are aligned with ISO 27001 standards and include secure storage, restricted access, regular reviews, and real-time monitoring to detect and respond to anomalies. Logs are retained according to defined schedules that comply with legal and regulatory requirements, ensuring both the integrity and availability of audit data. | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure audit log security and retention? | Yes, Built Intelligence implements robust controls aligned with ISO 27001 standards to ensure audit log security and retention. Specifically: - Processes, procedures, and technical measures for audit log security and retention are defined, implemented, and regularly evaluated.- Measures include secure storage, restricted access, regular reviews, and real- time monitoring to detect and respond to anomalies.- Audit logs are retained according to pre- defined schedules that comply with legal and regulatory requirements, supporting both integrity and availability of audit data.These practices provide assurance of audit trail security and support compliance with AI governance, CAIQ, and ISO 27001 control objectives. |
| Are security-related events identified and monitored within applications and the underlying infrastructure? | Yes, security-related events are identified and monitored within the FastDraft application and the underlying Microsoft Azure infrastructure. We utilize Azure Security Center and Azure Monitor to continuously track and manage security events, including unauthorized access attempts, system changes, and potential security threats. This proactive monitoring aligns with our ISO 27001 certified Information Security Management System (ISMS) and helps ensure the integrity and security of both the application and infrastructure layers. | Are security-related events within applications, the underlying infrastructure, and the supply chain being identified and monitored, and are other events being logged based on risk evaluation? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is a system defined and implemented to generate alerts to responsible stakeholders based on security events and their corresponding metrics? | Yes, Built Intelligence has implemented a system to generate alerts to responsible stakeholders based on security events and their corresponding metrics. This system is integrated within our Microsoft Azure hosting environment and utilizes Azure Security Center and Azure Monitor. These tools provide comprehensive monitoring, threat detection, and alerting capabilities. Alerts are configured to notify designated security personnel and stakeholders via email and SMS based on predefined security events and metrics thresholds. This ensures timely and effective response to potential security incidents, aligning with our ISO 27001 and Cyber Essentials Plus standards. | Is a system to generate alerts, defined and implemented, to responsible stakeholders based on security-related events and corresponding metrics? | Yes, Built Intelligence has implemented a defined system to generate alerts to responsible stakeholders based on security- related events and their corresponding metrics. This system is integrated within the Microsoft Azure hosting environment and utilizes Azure Security Center and Azure Monitor. These tools provide comprehensive monitoring, threat detection, and alerting capabilities. Alerts are configured to notify designated security personnel and stakeholders via email and SMS based on predefined security events and metrics thresholds. This approach supports timely and effective responses to potential security incidents and is aligned with ISO 27001 and Cyber Essentials Plus compliance requirements. |
| Is access to audit logs restricted to authorized personnel, and are records maintained to provide unique access accountability? | Yes, access to audit logs in the FastDraft platform is restricted to authorized personnel only, and records are maintained to ensure unique access accountability. We use role-based access controls (RBAC) to enforce strict access permissions, and all access to audit logs is logged and monitored to provide an auditable trail of who accessed what information and when. This aligns with our ISO 27001 and Cyber Essentials Plus certifications, ensuring compliance with industry best practices for data security and access control. | Is access to audit logs restricted and are the records of access logs maintained? | Yes, Built Intelligence restricts access to audit logs to authorized personnel only. The platform employs role- based access controls (RBAC) to enforce strict permissions, ensuring that only users with appropriate authorization can view or interact with audit logs. Additionally, all access to these audit logs is logged and monitored, providing a full auditable trail that uniquely identifies who accessed which information and when. These controls align with ISO 27001 and Cyber Essentials Plus requirements, supporting unique access accountability and compliance with industry best practices for data security and auditability. |
| Are security audit logs monitored to detect activity outside of typical or expected patterns? | Yes, security audit logs within FastDraft are monitored to detect activities that deviate from typical or expected patterns. We utilize Microsoft Azure's monitoring tools, including Azure Monitor and Azure Security Center, to continuously analyze log data for anomalies and suspicious activities. These tools help us ensure that any unusual patterns are quickly identified and investigated by our security team, aligning with our ISO 27001 and Cyber Essentials Plus standards for proactive threat detection and response. | Are security audit logs monitored to detect activity outside of typical or expected patterns? | Yes, Built Intelligence has security audit logs that are monitored to detect activities that deviate from typical or expected patterns. The platform utilizes Microsoft Azure's monitoring tools, including Azure Monitor and Azure Security Center, to continuously analyze log data for anomalies and suspicious activities. These controls ensure that unusual patterns are promptly identified and investigated by the security team. This monitoring process aligns with ISO 27001 and Cyber Essentials Plus standards for proactive threat detection and response. |
| Is a process established and followed to review and take appropriate and timely actions on detected anomalies? | Yes, Built Intelligence has established and follows a process to review and take appropriate and timely actions on detected anomalies. This process is part of our ISO 27001 certified Information Security Management System (ISMS), which includes monitoring, detection, and response procedures for anomalies and events that could impact security. Anomalies are logged, analyzed, and escalated according to predefined severity levels, ensuring rapid and effective response to potential security incidents. | Is a process, on reviewing and taking appropriate and timely actions on detected anomalies, defined, established and followed? | Yes, Built Intelligence has implemented defined processes for monitoring, reviewing, and responding to security anomalies. Specifically: - Security events are logged across infrastructure, application, and database layers, covering authentication attempts, API access, privileged actions, and data modifications.- Logs are monitored in real time with Azure Defender tools, and automated alerts are triggered for detected anomalies.- Security log reviews occur periodically as part of established risk management and compliance processes aligned with ISO 27001 and Cyber Essentials Plus.- There is a commitment to taking corrective or preventative action regarding deficiencies detected in third- party services, underlining a process of continued review and remediation.These processes support the control objective of ensuring timely detection and handling of anomalous activities within the platform. |
| Is a reliable time source being used across all relevant information processing systems? | Yes, FastDraft utilizes Microsoft Azure's infrastructure, which includes synchronization with reliable time sources for all information processing systems. This ensures that all operations and transactions within the FastDraft platform are timestamped accurately, maintaining consistency and reliability across the service. | Is a reliable time source being used across all relevant information processing systems? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are logging requirements for information meta/data system events established, documented, and implemented? | Yes, FastDraft has established, documented, and implemented logging requirements for information metadata and system events. We utilize Microsoft Azure's infrastructure capabilities, including Azure Monitor and Azure Log Analytics, to ensure comprehensive logging across all system and user activities. These logs include user access events, system changes, and data transactions, which are retained according to our data retention policies outlined in our security and compliance documentation. | Are information metadata system events that should be logged, established, documented, and implemented? | Yes, Built Intelligence maintains a structured approach to logging system events through its webhook service. The platform can broadcast a near real- time stream of events to a specified URL, allowing third- party software or integration hubs to monitor, customize, and trigger actions based on these logged events. This capability supports the documentation, establishment, and implementation of event logging and monitoring, which is key for auditability and compliance with control requirements such as those specified in CAIQ and ISO 27001. Key controls include: - Establishment of system event logging through real- time event broadcasts (webhooks).- Ability to filter and monitor specific high- risk or critical events for incident response or compliance verification.- Documentation of event activity via streamed data accessible to authorized systems, enhancing traceability. |
| Is the scope reviewed and updated at least annually, or whenever there is a change in the threat environment? | Yes, the scope of the Information Security Management System (ISMS) is reviewed and updated at least annually or whenever there is a change in the threat environment, as per the requirements outlined in our ISMS documentation. This ensures that our security measures remain effective and aligned with current risks. | Is the scope reviewed and updated at least annually, or whenever there is a change in the threat environment? | Yes, Built Intelligence's scope of the Information Security Management System (ISMS) is reviewed and updated at least annually, or whenever there is a change in the threat environment. This practice is in line with established security and compliance frameworks such as ISO 27001, ensuring that security measures remain effective and appropriately aligned with current risks. This control demonstrates proactive governance and risk management in maintaining the relevancy and adequacy of the ISMS in response to evolving threats. |
| Are audit records generated, and do they contain relevant security information? | Yes, audit records are generated and contain relevant security information. These records include user activity, authentication events, system changes, and access to sensitive data. We use Azure Monitor and Microsoft Defender for Cloud to ensure comprehensive logging and monitoring, supporting security, compliance, and operational visibility. | Are audit records generated, and do they contain relevant security information? | Yes, Built Intelligence's audit records are generated within the platform and include relevant security information. Specifically, these records cover user activity, authentication events, system changes, and access to sensitive data. Comprehensive logging and monitoring are implemented through Azure Monitor and Microsoft Defender for Cloud, ensuring support for security, compliance, and operational visibility. These practices align with control requirements commonly found in frameworks like ISO 27001 and CAIQ, helping to ensure traceability and accountability for security- related activities. |
| Does the information system protect audit records from unauthorized access, modification, and deletion? | Yes, the FastDraft platform protects audit records from unauthorized access, modification, and deletion. We utilize Microsoft Azure's security controls, including role-based access control (RBAC), encryption, and logging mechanisms, to ensure that audit records are securely managed. Access to audit records is strictly limited to authorized personnel, and all interactions with these records are logged and monitored to prevent and detect any unauthorized activities. | Is the audit records protected from unauthorized access, modification, and deletion? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are monitoring and internal reporting capabilities established to report on cryptographic operations, encryption, and key management policies, processes, procedures, and controls? | Yes, Built Intelligence has established monitoring and internal reporting capabilities to report on cryptographic operations, encryption, and key management policies, processes, procedures, and controls. These capabilities are integrated into our ISO 27001 certified Information Security Management System (ISMS) and are supported by Microsoft Azure's comprehensive security and compliance features. We utilize Azure Key Vault for key management and encryption, ensuring that cryptographic keys are protected and managed securely. Regular audits and reports are conducted to ensure compliance with our internal policies and industry standards. | Are monitoring and internal reporting capabilities established to report on cryptographic operations, encryption, and key management policies, processes, procedures, and controls? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are key lifecycle management events logged and monitored to enable auditing and reporting on cryptographic keys' usage? | Yes, key lifecycle management events are logged and monitored to enable auditing and reporting on cryptographic keys' usage. We use Microsoft Azure Key Vault for managing cryptographic keys, which automatically logs all key lifecycle events such as creation, deletion, and access. These logs are integrated with Azure Monitor and Azure Security Center, providing comprehensive monitoring and alerting capabilities to ensure the security and compliance of key management operations. | Are key lifecycle management events logged and monitored to enable auditing and reporting on cryptographic keys' usage? | Yes, Built Intelligence utilizes Microsoft Azure Key Vault for the secure management and storage of encryption keys. Access to cryptographic keys is tightly controlled, logged, and audited. Key usage follows defined policies, and rotation is enforced in accordance with ISO 27001 controls. These practices support audit and reporting requirements associated with cryptographic key lifecycle management and enable organizations to meet compliance objectives regarding logging and monitoring of key usage. |
| Is physical access logged and monitored using an auditable access control system? | Yes, physical access is logged and monitored using an auditable access control system. Our facilities, including data centers hosted by Microsoft Azure, implement strict physical security measures. Access logs are maintained and regularly audited in compliance with our ISO 27001 certification requirements, ensuring that all access is appropriately authorized and recorded. | Is physical access logged and monitored using an auditable access control system? | Yes, Built Intelligence physical access to secure areas is restricted to solely authorized personnel. All ingress and egress areas are documented and monitored by physical access control mechanisms, including CCTV, burglar alarms, and locked secure areas. These access control systems ensure that access events are auditable and that only authorized personnel are granted entry. The documentation explicitly confirms that these measures support logging and monitoring for compliance and audit purposes. |
| Are processes and technical measures for reporting monitoring system anomalies and failures defined, implemented, and evaluated? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes and technical measures for reporting monitoring system anomalies and failures. These measures are integrated into our Microsoft Azure-hosted FastDraft platform and are aligned with ISO 27001 standards. We utilize Azure Monitor and Azure Security Center to detect, analyze, and respond to anomalies and failures. Alerts are configured to notify our IT and security teams of potential issues, and incident response procedures are in place to address and mitigate any identified problems. Regular reviews and updates of these processes ensure they remain effective and compliant with our security and operational policies. | Are processes and technical measures for reporting monitoring system anomalies and failures defined, implemented, and evaluated? | Yes, Built Intelligence's measures for reporting and monitoring system anomalies and failures are defined, implemented, and evaluated as follows: - Monitoring Tools: uses the Solarwinds Pingdom Real User Monitoring (RUM) toolset for detailed insights on platform performance. These tools monitor real user interactions and generate statistical reports to identify problems and improve reliability and performance. - Management Reporting:RUM reports are analysed as part of management reporting to spot issues with web applications and platform performance. Synthetic monitoring is also conducted to further detect and address anomalies. - Incident Management:In the event of a data breach or security incident (which can be triggered by system anomalies or failures), there is a defined process aligned with the ISO 27001- certified ISMS. This includes detection, logging, escalation, assessment, containment, and remediation. - Alerting:The system is supported by Microsoft Azure Security Center and Microsoft Defender, which provide alerts for suspicious activities, supporting the identification and response to system anomalies. These controls demonstrate a structured approach to the detection, reporting, and management of monitoring system anomalies and failures, in alignment with ISO 27001 and good practice for AI governance risk management. |
| Are accountable parties immediately notified about anomalies and failures? | Yes, accountable parties are immediately notified about anomalies and failures. Our FastDraft platform, hosted on Microsoft Azure, utilizes Azure Monitor and Azure Alerts to detect and notify relevant personnel of any system anomalies or failures. These tools provide real-time monitoring and alerting capabilities, ensuring that system owners and administrators are promptly informed for quick resolution. This aligns with our operational controls and procedures to maintain system integrity and availability. | Are accountable parties immediately notified about anomalies and failures? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are all input events (content and metadata) logged and monitored to enable auditing and reporting on the usage of AI models? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are all output events (content and metadata) logged and monitored to enable auditing and reporting on the usage of AI models? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure the security of the Training Pipeline? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies, procedures and technical measures to address new security threats and best practices regularly review and update? | Yes, Built Intelligence has established, documented, and maintains application security policies and procedures that specifically address new security threats and industry best practices. These policies are aligned with ISO 27001 standards and form part of the organization's Information Security Management System (ISMS). The documentation explicitly confirms that these policies and procedures: - Are established, documented, approved, communicated, and applied across the organization.- Are evaluated and maintained regularly to guide appropriate planning, delivery, and support of application security capabilities.- Are reviewed and updated at least annually to adapt to new security threats and technological changes, ensuring ongoing compliance and robust security posture.This approach provides strong controls for continuous improvement and alignment with evolving cybersecurity threats, supporting compliance with regulatory standards and governance requirements. | ||
| Are processes, procedures, and technical measures defined, implemented, and evaluated for the periodic scanning of model artifacts for vulnerabilities and attacks at each step of the service lifecycle and at each handover point? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies, procedures and technical measures to address model artifact scanning regularly reviewed and updated? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes and procedures defined, implemented, enforced, and evaluated for documenting, approving, communicating, evaluating, and maintaining model documentation? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the model documentation regularly reviewed and updated? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are baseline requirements for Model documentation established and implemented? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures, and technical measures defined, implemented, and evaluated for the validation of the model documentation aligned with the current model? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes and technical measures defined, implemented, and evaluated to regularly assess adversarial threats specific to each AI model? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures, and technical measures defined, implemented, and evaluated for Model Hardening to mitigate relevant adversarial attacks as identified in the Threat Analysis and Adversarial Threat Analysis? | Yes, Built Intelligence monitors and assesses the threat landscape relevant to its cloud and AI services and uses the outputs to inform risk treatment. - Threat intelligence sources and vulnerability disclosures are reviewed routinely. - Risk assessments and threat modelling are performed for material changes. - Findings drive control improvements and remediation priorities. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are checksums regularly calculated and compared using cryptographic hashes of model checkpoints to detect unauthorized modifications? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are these measures applied at least annually based on the level of risk, or after any change of hands? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are models signed cryptographically and are signatures verified to ensure model provenance and ownership any time the model changes hands or is loaded from storage? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes, procedures, and technical measures defined, implemented, and evaluated for continuous monitoring of model performance metrics over time to identify sudden shifts or unexpected changes in predictions that could degrade model performance? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are risk-based evaluation of the model and model serving infrastructure for model failure performed? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are measures defined and implemented to mitigate model and model serving infrastructure failures, and are they regularly evaluated throughout the AI system's lifecycle? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are processes established to evaluate the risk associated with open models? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are risk factors periodically reviewed, and is a process implemented to monitor and mitigate any determined vulnerabilities? | Yes, Built Intelligence risk factors are periodically reviewed and a structured process is implemented to monitor and mitigate vulnerabilities. Specifically: - Risk Review:, the provider of , conducts regular assessments of risk factors associated with all organizations in the supply chain as part of an ISO 27001 certified Information Security Management System (ISMS). This includes ongoing monitoring and periodic review of supplier risks. - Vulnerability Management:The platform follows a formal vulnerability management process aligned with ISO 27001 and Cyber Essentials Plus standards. When publicly disclosed vulnerabilities arise, such as major industry incidents, processes are in place for rapid assessment and mitigation. benefits from being hosted on Microsoft Azure’s PaaS infrastructure, where OS, firmware, and hypervisor patching are managed by Microsoft. Additional continuous monitoring of Microsoft Security Advisories is in place. - Operational Risk Management:The organization utilizes a structured approach to Operational Risk Management (ORM) and Enterprise Risk Management (ERM), conducting regular risk assessments, threat modeling, vulnerability assessments, penetration testing, and business continuity planning. These practices align with the requirements of compliance frameworks such as ISO 27001 and meet control objectives for risk mitigation and continuous monitoring. | ||
| Are secure model formats and processes for AI model serialization adopted where applicable? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies and procedures for security incident management, e-discovery, and cloud forensics established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, policies and procedures for security incident management, e-discovery, and cloud forensics are established, documented, approved, communicated, applied, evaluated, and maintained as part of our ISO 27001 certified Information Security Management System (ISMS). These procedures are regularly reviewed and updated to ensure they remain effective and compliant with current standards and regulations. | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for Security Incident Management, E-Discovery, and Forensics? | Yes, Built Intelligence has established comprehensive controls and policies regarding security incident management, e- discovery, and cloud forensics. Specifically, policies and procedures for security incident management, e- discovery, and cloud forensics are established, documented, approved, communicated, applied, evaluated, and maintained.- These practices form part of ’s ISO 27001- certified Information Security Management System (ISMS).- The procedures are subject to regular review and updates to ensure ongoing effectiveness and compliance with current standards and regulations.This aligns with ISO 27001 and CAIQ objectives for policy lifecycle management and demonstrates a structured and auditable approach to incident and forensic management controls. |
| Are policies and procedures reviewed and updated annually? | Yes, our policies and procedures are reviewed and updated annually to ensure compliance with current regulations and industry best practices. This includes updates to our security and compliance policies, operational controls, and procedures, all of which are documented and approved at the executive level. | Are policies and procedures for Security Incident Management, E-Discovery, and Forensics reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies and procedures for timely management of security incidents established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, and communicated policies and procedures for the timely management of security incidents. These are maintained and evaluated as part of our ISO 27001 certified Information Security Management System (ISMS). Our incident management procedures ensure that all security incidents are assessed, contained, and remediated effectively. Regular reviews and updates to these procedures are conducted to ensure they remain effective and aligned with emerging security threats and compliance requirements. | Are Service Management Policies and Procedures established, documented, approved, communicated, applied, evaluated, and maintained for the timely management of security incidents? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained security and service management policies and procedures as part of its Information Security Management System (ISMS). These policies align with ISO 27001 standards and are designed to ensure robust security incident management, including the continuous improvement of incident response capabilities. Policies and procedures are integrated into the organization’s ISMS and reviewed regularly to adapt to new threats and changes in technology.- Internal and external audits are conducted to assess compliance with these policies, and findings are documented, tracked, remediated, and reported to relevant stakeholders.- Security features such as continuous threat monitoring, automated security audits, and logging of user activities are supported by systematic operational controls for managing security incidents. |
| Are policies and procedures for timely management of security incidents reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates policies and procedures for the timely management of security incidents at least annually. This is in accordance with our ISO 27001 certified Information Security Management System (ISMS) requirements, ensuring continuous improvement and alignment with emerging risks and changes in the business environment. | Are Service Management Policies and Procedures reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is a security incident response plan that includes relevant internal departments, impacted CSCs, and other business-critical relationships (such as supply-chain) established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained a security incident response plan that includes relevant internal departments, impacted CSCs, and other business-critical relationships such as supply-chain. This plan is part of our ISO 27001 certified Information Security Management System (ISMS) and aligns with our incident management document (ISMS DOC ORG08). The plan ensures coordinated response efforts across all necessary parties and is regularly reviewed and tested to ensure its effectiveness and compliance with current security standards and business requirements. | Is a security incident response plans which includes but is not limited to a communication strategy for notifying relevant internal departments, impacted AICs, and other business critical relationships (such as supply-chain) that may be impacted, established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is the security incident response plan tested and updated for effectiveness, as necessary, at planned intervals or upon significant organizational or environmental changes? | Yes, Built Intelligence regularly tests and updates our security incident response plan to ensure its effectiveness. This is done at planned intervals and upon significant organizational or environmental changes, in alignment with ISO 27001 and Cyber Essentials Plus standards. These updates are based on the outcomes of cyber-attack simulations, risk assessments, and actual incidents to continuously improve our response capabilities. | Is a structured approach followed, to evaluate the effectiveness of incident response plans at planned intervals or upon significant changes? | Yes, Built Intelligence regularly tests and updates its security incident response plan to ensure its effectiveness. This process is conducted at planned intervals and also upon significant organizational or environmental changes. The approach aligns with ISO 27001 and Cyber Essentials Plus standards, and updates are informed by outcomes from cyber- attack simulations, risk assessments, and actual security incidents. This structured methodology demonstrates adherence to recognized best practices for control effectiveness and continuous improvement in incident response capability. |
| Are information security incident metrics established and monitored? | Yes, Built Intelligence has established and monitors information security incident metrics as part of our ISO 27001 certified Information Security Management System (ISMS). Metrics include the number, type, severity, and resolution times of incidents, which are tracked through our incident management tool, ZenDesk. These metrics are reviewed monthly by the Information Security Manager and reported to the Information Security Team to ensure continuous improvement in our security posture and incident response capabilities. | Are information security incident metrics established, monitored and reported? | Yes, Built Intelligence has established information security incident metrics, which are monitored and reported as part of its ISO 27001 certified Information Security Management System (ISMS). The following controls are detailed: - Metrics tracked include the number, type, severity, and resolution times of security incidents.- All incidents are managed through the ZenDesk incident management tool.- Metrics are reviewed monthly by the Information Security Manager and are reported to the Information Security Team.- This process ensures continuous improvement in security posture and incident response capabilities, aligned with ISO 27001 requirements. |
| Are processes, procedures, and technical measures supporting business processes to triage security-related events defined, implemented, and evaluated? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to triage security-related events. These are aligned with our ISO 27001 certified Information Security Management System (ISMS) and include incident identification, assessment, response, and recovery procedures. We utilize Microsoft Azure's security tools like Azure Security Center and Azure Monitor to detect and manage security events effectively. Regular reviews and updates to these processes ensure they remain effective and compliant with current security standards. | Are security-related event triage processes, procedures and technical measures supporting business processes, defined, implemented and evaluated? Alternative formulation: Are processes procedures and technical measures supporting business processes to triage security-related events, defined, implemented and evaluated? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to support business processes in triaging security- related events. These controls are aligned with the ISO 27001 certified Information Security Management System (ISMS) and include the following: - Documented incident identification, assessment, response, and recovery procedures.- Use of Microsoft Azure's security tools—such as Azure Security Center and Azure Monitor—for detecting and managing security events.- Regular review and updates of triage processes to ensure ongoing effectiveness and compliance with current security standards.These measures are designed to ensure prompt and effective response to security incidents and support continuous improvement in the organization's overall security posture. |
| Are processes, procedures, and technical measures for security breach notifications defined and implemented? | Yes, Built Intelligence has defined and implemented processes, procedures, and technical measures for security breach notifications as part of our ISO 27001 certified Information Security Management System (ISMS). These include immediate detection and reporting mechanisms, assessment and containment procedures, and timely notification to affected parties and regulatory authorities in compliance with GDPR and other relevant laws. | Are processes, procedures and technical measures for security breach notifications defined and implemented? | Yes, Built Intelligence has defined and implemented processes, procedures, and technical measures for security breach notifications. These controls are integrated with the ISO 27001 certified Information Security Management System (ISMS). Key elements include: - Immediate detection and reporting mechanisms that leverage tools such as Azure Security Center and Defender monitoring.- Assessment and containment procedures to evaluate incident impact, affected data, and root cause, with rapid implementation of containment actions.- Notification protocols that comply with regulatory requirements, including GDPR guidelines for personal data breaches. This ensures timely notification of affected individuals and regulatory authorities within the required timeframes.- Remediation and recovery actions, which involve updating security controls, restoring affected systems, and conducting post- incident reviews to strengthen defences.This structured approach ensures effective identification, escalation, communication, and continuous improvement of incident response capabilities, aligning with relevant security and compliance objectives. |
| Are security breaches and assumed security breaches reported (including any relevant supply chain breaches) as per applicable SLAs, laws, and regulations? | Yes, Built Intelligence reports all security breaches and assumed security breaches, including any relevant supply chain breaches, in accordance with applicable Service Level Agreements (SLAs), laws, and regulations. Our incident response plan, aligned with ISO 27001 and GDPR requirements, ensures timely notification to affected parties and regulatory bodies. This process includes immediate investigation, containment, eradication, and recovery actions, with documentation and review to prevent future occurrences. | Are material security breaches and assumed security breaches, including any relevant supply chain breaches, reported as per applicable SLAs, laws and regulations? | Yes, Built Intelligence reports all material security breaches and assumed security breaches, including those involving the supply chain, in accordance with applicable Service Level Agreements (SLAs), laws, and regulations. The incident response plan is aligned with ISO 27001 and GDPR requirements and includes the following controls: - Immediate detection, reporting, and escalation of suspected breaches.- Assessment and containment of security incidents.- Timely notification to affected parties and regulatory authorities, including supply chain incidents as required.- Documentation and review processes to identify root causes and prevent recurrence.This approach ensures compliance with legal and regulatory obligations and supports effective risk management across the service and supply chain. |
| Are points of contact maintained for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities? | Yes, Built Intelligence maintains points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities as required under ISO 27001 and Cyber Essentials Plus certifications. This ensures compliance with legal and regulatory requirements and facilitates prompt communication in the event of security incidents or legal inquiries. | Are points of contact maintained for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are the points of contacts reviewed and updated at least annually? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are incident categories and severity levels defined for AI systems, and response procedures determined for each, including automated response where applicable? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies and procedures implementing the shared security responsibility model (SSRM) within the organization established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, policies and procedures implementing the shared security responsibility model (SSRM) within the organization are established, documented, approved, communicated, applied, evaluated, and maintained. These are integral to our ISMS and align with Azure's infrastructure capabilities, ensuring both application-level and infrastructure-level security controls are robustly managed. Regular reviews and audits, as per ISO 27001 and Cyber Essentials Plus certifications, ensure continuous improvement and compliance with these policies. | Are policies and procedures for supply chain risk management established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence established, documented, approved, communicated, applied, evaluated, and maintained risk management policies and procedures associated with organizational assets, including those involving third- party suppliers and contractors. These procedures align with ISO 27001 requirements and are integrated into the company's Information Security Management System (ISMS) and change management processes (as per Operations ). The approach to third- party and supply chain risk management includes: - Careful supplier selection and formal vetting.- Contractual controls to ensure compliance and accountability.- Technical safeguards (e.g., encryption, access management).- Ongoing governance, monitoring, and review of suppliers.- Regular risk assessment, approval, and review related to any changes involving third- party assets or services.This comprehensive approach maintains a strong standard of security, resilience, and compliance across the supply chain, as referenced by ISO/IEC 27001, Cyber Essentials Plus, and UK Government expectations. Documentation also affirms that these policies and procedures are reviewed and updated at least annually. |
| Are the policies and procedures that apply the SSRM reviewed and updated annually? | Yes, the policies and procedures that apply to the Security and Risk Management (SSRM) are reviewed and updated annually. This is in line with our commitment to maintaining a robust Information Security Management System (ISMS), as outlined in our internal documentation and leadership directives. The review process ensures that our policies remain effective and compliant with relevant standards and regulations, including ISO 27001 and Cyber Essentials Plus. | Are the policies and procedures reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence ensures that policies and procedures—specifically for cryptography, encryption, and key management—are reviewed and updated at least annually. The Information Security Team oversees this process in accordance with the organization’s ISMS policies, ensuring that documentation is kept current in response to emerging risks and changes to the business environment. This practice aligns with ISO 27001 and CAIQ requirements for regular policy review and risk mitigation. |
| Is the SSRM applied, documented, implemented, and managed throughout the supply chain for the cloud service offering? | Yes, the Supplier Security and Risk Management (SSRM) is applied, documented, implemented, and managed throughout the supply chain for our cloud service offering. FastDraft, hosted on Microsoft Azure, adheres to stringent security and compliance frameworks, including ISO 27001 and Cyber Essentials Plus. Azure's infrastructure provides robust security measures such as network segmentation, access controls, and continuous monitoring, which extend to all our suppliers and partners involved in the service delivery. Our operational controls and procedures ensure that all suppliers comply with our security policies and standards, which are regularly reviewed and updated to address emerging threats and vulnerabilities. | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for applying the Shared Security Responsibility Model (SSRM) within the organization? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies and procedures for applying the Shared Security Responsibility Model (SSRM) within the organization reviewed and updated at least annually, or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Is the CSC given SSRM guidance detailing information about SSRM applicability throughout the supply chain? | Yes, Built Intelligence provides customers with a clear overview of the Shared Security Responsibility Model (SSRM) as it applies to the FastDraft platform. This documentation explains the division of security responsibilities between the customer, Built Intelligence, and Microsoft Azure. Customers are informed of their responsibilities around data access, user management, and project permissions, while Built Intelligence is responsible for infrastructure security, encryption, application-level controls, and vendor management. Additionally, Azure’s role in physical security and infrastructure compliance is outlined, providing transparency across the supply chain. | Is the SSRM applied, documented, implemented and managed throughout the supply chain? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is the shared ownership and applicability of all CSA CCM controls delineated according to the SSRM for the cloud service offering? | Yes, the shared ownership and applicability of all Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) controls are delineated according to the Shared Security Responsibility Model (SSRM) for our cloud service offering. FastDraft, hosted on Microsoft Azure, clearly defines the responsibilities between us and our clients. Azure's infrastructure provides robust security measures compliant with CSA CCM, while FastDraft ensures application-level controls are in place and documented as per SSRM guidelines. | Are customers provided with SSRM guidance detailing its applicability throughout the supply chain? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is SSRM documentation for all cloud services the organization uses reviewed and validated? | Yes, SSRM documentation for all cloud services used by the organization is reviewed and validated to ensure compliance with our security and regulatory standards. This includes a thorough assessment of the security measures and controls provided by our cloud service providers, such as Microsoft Azure. We maintain up-to-date certification records, including ISO 27001 and Cyber Essentials Plus, to support our compliance and security posture. | Is the shared ownership and applicability of all CSA AICM controls delineated according to the SSRM? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are the portions of the SSRM the organization is responsible for implemented, operated, audited, or assessed? | Yes, the portions of the Security and Risk Management (SSRM) that the organization is responsible for are implemented, operated, audited, and assessed. This includes adherence to our security policies, regular audits conducted by our internal teams and third-party auditors, and continuous assessments to ensure compliance with standards such as ISO 27001 and Cyber Essentials Plus. Our Information Security Team, led by the CTO and including roles such as the Information Security Manager, oversees these activities to maintain and improve our security posture. | Are the SSRM documentation reviewed and validated? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is an inventory of all supply chain relationships developed and maintained? | Yes, Built Intelligence maintains a detailed inventory of all third-party suppliers and service providers involved in delivering the FastDraft platform. This includes vendors providing cloud infrastructure (Microsoft Azure), identity and access management, email delivery (e.g., Mailgun), support services (e.g., Zendesk), and monitoring tools (e.g., Pingdom). Each vendor is assessed for compliance, security, and data protection alignment, and this inventory is reviewed regularly as part of our ISO 27001-certified supplier management process. | Are the portions of the SSRM the organization is responsible for implemented, operated, audited, or assessed? | Yes, Built Intelligence the Shared Security Responsibility Model (SSRM) is implemented and maintained in accordance with ISMS (Information Security Management System) policies. These controls are regularly reviewed, audited, and assessed to ensure ongoing compliance and effectiveness. This aligns with ISO 27001 requirements and CAIQ control objectives regarding the effective operation and regular assessment of organization- specific security responsibilities within a shared cloud environment. |
| Are risk factors associated with all organizations within the supply chain periodically reviewed by CSPs? | Yes, Built Intelligence periodically reviews risk factors associated with all organizations within the supply chain as part of our ISO 27001 certified Information Security Management System (ISMS). This includes regular assessments of suppliers and third-party service providers to ensure compliance with our security requirements and to mitigate potential risks in our supply chain. | Is an inventory of all supply chain relationships maintained and developed? | Yes, Built Intelligence maintains an inventory of all supply chain relationships, including subcontractors and supply chain partners. This is indicated in the following controls: - All suppliers and individual contractors are subject to formal onboarding, risk assessment, contractual, and security controls aligned with ISO/IEC 27001 and Cyber Essentials Plus standards.- Supplier and subcontractor relationships are managed through careful supplier selection, formal vetting, and a maintained supplier register.- Documentation highlights ongoing governance of third- party relationships, with a focus on identifying, assessing, and managing risks associated with external parties.This practice directly supports CAIQ controls related to maintaining a comprehensive inventory of supply chain relationships and aligns with ISO 27001 supply chain management requirements. |
| Do service agreements between CSPs and CSCs (tenants) incorporate at least the following mutually agreed upon provisions and/or terms? • Scope, characteristics, and location of business relationship and services offered • Information security requirements (including SSRM) • Change management process • Logging and monitoring capability • Incident management and communication procedures • Right to audit and third-party assessment • Service termination • Interoperability and portability requirements • Data privacy | Yes, the service agreements between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs) for FastDraft incorporate the following mutually agreed upon provisions and terms: - **Scope, Characteristics, and Location**: The agreements clearly define the scope of services, characteristics of the service offerings, and the geographical location of data storage and processing, leveraging Microsoft Azure's global infrastructure. - **Information Security Requirements**: These include specific security measures and controls that align with industry standards and certifications such as ISO 27001 and Cyber Essentials Plus, ensuring a robust security posture. - **Change Management Process**: The agreements outline the procedures for managing changes in the service or operational environment, ensuring that changes are controlled and do not adversely affect security. - **Logging and Monitoring Capability**: Leveraging Azure's native capabilities such as Azure Monitor and Azure Security Center, the agreements ensure comprehensive logging and real-time monitoring of the environment. - **Incident Management and Communication Procedures**: Detailed incident response plans and communication strategies are included to ensure timely and effective management of security incidents. - **Right to Audit and Third-Party Assessment**: The agreements provide CSCs with the right to conduct audits and to request third-party security assessments to verify compliance with the agreed security requirements. - **Service Termination**: Provisions for service termination are included, detailing the processes for data return, destruction, or transition to another service provider, ensuring data integrity and continuity. - **Interoperability and Portability Requirements**: These provisions ensure that data and services can be moved seamlessly between different platforms or providers, leveraging Azure's built-in support for data export and interoperability standards. - **Data Privacy**: The agreements comply with relevant data protection regulations such as GDPR, ensuring that data privacy is maintained throughout the data lifecycle. These provisions are designed to ensure a secure, reliable, and compliant operational environment for all tenants of the FastDraft platform hosted on Microsoft Azure. | Are risk factors associated with the supply chain relationships periodically reviewed? | Yes, Built Intelligence periodically reviews risk factors associated with all supply chain organizations as part of its ISO 27001 certified Information Security Management System (ISMS). This includes regular assessments of suppliers and third- party service providers to ensure ongoing compliance with security requirements and to mitigate potential supply chain risks. The reviews form part of a structured, audit- ready supplier management process. |
| Are supply chain agreements between CSPs and CSCs reviewed at least annually? | Yes, supply chain agreements between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs) are reviewed at least annually to ensure compliance with current regulations and standards, and to address any changes in operational requirements or security postures. This regular review process is part of our commitment to maintaining robust security and compliance standards across all our service offerings in Microsoft Azure. | Are service agreements required to include at least the following mutually agreed upon provisions and/or terms? • Scope, characteristics and location of business relationship and services offered • Information security requirements (including SSRM) • Change management process • Logging and monitoring capability • Incident management and communication procedures • Right to audit and third party assessment • Service termination • Interoperability and portability requirements • Data privacy | Yes, Built Intelligence service agreements between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs) are required to include the following mutually agreed upon provisions and terms: - Scope, Characteristics, and Location:Agreements clearly define the scope of services, characteristics of the service offerings, and the geographical location of data storage and processing, utilizing Microsoft Azure’s infrastructure. - Information Security Requirements (including SSRM):Specific security measures and controls are included, aligned with ISO 27001 and Cyber Essentials Plus certifications. - Change Management Process:Procedures for managing changes in the service or operations are detailed in the agreements. - Logging and Monitoring Capability:Agreements specify requirements for activity logging and system monitoring to detect and respond to security events. - Incident Management and Communication Procedures:Incident management processes and communication protocols are outlined within the agreements. - Right to Audit and Third- Party Assessment:Both parties’ rights to audit and engage independent third- party assessments are addressed. - Service Termination:Terms and conditions governing service termination and post- termination procedures are included. - Interoperability and Portability Requirements:Provisions regarding data portability and interoperability between cloud services are covered. - Data Privacy:Data privacy requirements and data protection obligations are addressed in accordance with relevant legal and regulatory standards. These controls are implemented to support contractual compliance, regulatory alignment, and risk mitigation as required by AI governance and ISO 27001 best practices. |
| Is there a process for conducting internal assessments at least annually to confirm the conformance and effectiveness of standards, policies, procedures, and SLA activities? | Yes, Built Intelligence conducts internal assessments annually to confirm the conformance and effectiveness of our standards, policies, procedures, and SLA activities. These assessments are part of our ISO 27001 certified Information Security Management System (ISMS) and include reviews of our operational controls, security practices, and compliance with relevant regulations. The assessments are performed by our internal audit team and are supplemented by external audits from certified bodies to ensure thoroughness and objectivity. | Are supply chain agreements reviewed at least annually or upon significant changes? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are policies that require all supply chain CSPs to comply with information security, confidentiality, access control, privacy, audit, personnel policy, and service level requirements and standards implemented? | Yes, Built Intelligence has implemented policies that require all supply chain Cloud Service Providers (CSPs) to comply with information security, confidentiality, access control, privacy, audit, personnel policy, and service level requirements and standards. These policies are part of our ISO 27001 certified Information Security Management System (ISMS) and are enforced through contractual agreements and regular audits of our CSPs. Compliance with these policies ensures that our supply chain aligns with our security and privacy standards, protecting both our data and that of our customers. | Is there a process for conducting internal assessments at least annually to confirm the conformance and effectiveness of standards, policies, procedures, and SLA activities? | Yes, Built Intelligence has established a regular process for reviewing and updating policies and procedures at least annually. This includes: - Annual review and update of policies and procedures to maintain compliance with industry standards and regulatory requirements.- Integration of these reviews as part of ’s ISO 27001- certified Information Security Management System (ISMS), supporting the ongoing conformance and effectiveness of internal controls and procedures.- Annual testing and review of Business Continuity and Disaster Recovery (BCP/DR) procedures, with outcomes used to refine and improve processes.These practices collectively support continuous internal assessment and maintenance of established standards, policies, procedures, and service level activities. |
| Are supply chain partner IT governance policies and procedures reviewed periodically? | Yes, Built Intelligence periodically reviews the IT governance policies and procedures of our supply chain partners to ensure compliance with our security standards and contractual obligations. This review process is part of our broader vendor management and risk assessment practices, aligned with ISO 27001 requirements. | Are policies implemented requiring all service providers throughout the supply chain to comply with information security, confidentiality, access control, privacy, audit, personnel policy and service level requirements and standards? | Yes, Built Intelligence enforces the following controls related to supply chain management and service provider compliance: - All subcontractors and supply chain partners working with the platform are required to adhere to ISO 27001 security controls and Cyber Essentials Plus standards.- Contractual agreements are established with suppliers, which include security, confidentiality, data protection, and access control requirements, as well as personnel policy provisions.- Access to production environments and customer data is restricted, logged, monitored, and reviewed regularly. Contractors are only granted access necessary for their role and for the minimum period required.- Periodic reviews of supplier security posture and performance are conducted as part of ’s ISO 27001 certified Information Security Management System (ISMS).- Service agreements between providers and customers explicitly address information security, change management, audit rights, service termination, interoperability, data privacy, and other key areas.These policies collectively support comprehensive control objectives for confidentiality, access control, privacy, and ongoing supplier security, in alignment with CAIQ and ISO 27001 best practices. |
| Is a process to conduct periodic security assessments for all supply chain organizations defined and implemented? | Yes, Built Intelligence has defined and implemented a process to conduct periodic security assessments for all supply chain organizations. This process is part of our ISO 27001 certified Information Security Management System (ISMS) and includes regular reviews and audits of our suppliers to ensure compliance with our security requirements and standards. These assessments help manage and mitigate risks associated with third-party services and products integral to our operations and service delivery. | Are the IT governance policies and procedures for organization's supply chain partners periodically reviewed? | Yes, Built Intelligenceensures that IT governance policies and procedures for its supply chain partners are periodically reviewed. maintains a detailed inventory of all third- party suppliers and service providers. Each vendor is assessed for compliance, security, and data protection alignment. Regular reviews of risk factors associated with organizations in the supply chain are performed as part of the ISO 27001- certified Information Security Management System (ISMS). This process ensures ongoing alignment with IT governance, risk management, and control objectives in accordance with established security frameworks. |
| Is a process for conducting periodic security assessments for all organizations within the supply chain defined and implemented? | Yes, Built Intelligence has defined and implemented a process for conducting periodic security assessments for all organizations within its supply chain. This process is managed as part of the ISO 27001- certified Information Security Management System (ISMS) and includes regular reviews and risk assessments of suppliers and third- party service providers to ensure compliance with security requirements and to mitigate potential risks throughout the supply chain. | ||
| Are processes defined, implemented, enforced, and evaluated for establishing a Bill of Material for the entire AI service supply chain, including the model, orchestrated services, and AI applications? | Yes, Built Intelligence addresses this requirement through documented policies, technical controls, and periodic review aligned to ISO 27001. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained to identify, report, and prioritize the remediation of vulnerabilities to protect systems against vulnerability exploitation? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures to identify, report, and prioritize the remediation of vulnerabilities to protect systems against vulnerability exploitation. These procedures are part of our ISO 27001 certified Information Security Management System (ISMS) and are aligned with Cyber Essentials Plus requirements. Regular security scans, penetration testing, and vulnerability assessments are conducted to ensure continuous identification and mitigation of risks. Remediation activities are prioritized based on the severity and impact of the vulnerabilities identified. All relevant personnel are trained on these procedures to ensure effective implementation and compliance. | Are policies and procedures that identify, report, and prioritize the remediation of vulnerabilities and threats in order to protect systems against vulnerability exploitation, established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence policies and procedures for vulnerability and threat management are fully established, documented, approved, communicated, applied, evaluated, and maintained. These controls are integrated into 's ISO 27001 certified Information Security Management System (ISMS) and are also aligned with Cyber Essentials Plus requirements. Specifically, the documentation confirms the following: - Policies and procedures areestablished and documented to identify, report, and prioritize the remediation of vulnerabilities. - Procedures areapproved and communicated to relevant personnel, ensuring operational awareness and implementation. - Controls areapplied and evaluated through regular security scans, penetration tests, and vulnerability assessments. - Remediation of vulnerabilities isprioritized based on severity and impact , supporting risk- based decision making. - All procedures aremaintained as part of the certified ISMS , ensuring ongoing compliance and effectiveness. These measures are regularly reviewed and include comprehensive staff training to ensure compliance and effective application. The program directly supports ISO 27001 and CAIQ control objectives for vulnerability and threat management. |
| Are threat and vulnerability management policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence's threat and vulnerability management policies and procedures are reviewed and updated at least annually to ensure they remain effective and aligned with current security best practices and compliance requirements. This process is part of our ISO 27001 certified Information Security Management System (ISMS), which mandates regular reviews and updates to all security policies and procedures. | Are threats and vulnerabilities policies and procedures reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence vulnerability management and related security procedures are reviewed and updated at least annually. Specifically, regular vulnerability scanning and annual penetration testing are conducted, with findings reviewed, risk- assessed, and remediated in alignment with an ISO 27001- aligned vulnerability management process. This demonstrates adherence to a scheduled review cycle and ensures that procedures are updated as necessary to address any significant changes or emerging threats. Business Continuity and Disaster Recovery (BCP/DR) procedures are also tested annually and updated based on test outcomes, supporting continuous improvement in security posture and resilience. |
| Are policies and procedures to protect against malware on managed assets established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures to protect against malware on managed assets. These measures are part of our ISO 27001 certified Information Security Management System (ISMS) and include the use of anti-malware software, application whitelisting, and regular updates and patches to our systems, hosted on Microsoft Azure. Our policies also mandate regular security training for employees to recognize and manage malware threats. These procedures are regularly reviewed and updated to adapt to new threats. | Are policies and procedures to protect against malware and malicious instructions, established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence policies and procedures to protect against malware and malicious instructions are established, documented, approved, communicated, applied, evaluated, and maintained. employs a zero- trust, defence- in- depth security model that includes multi- layered malware controls, automated patch management, continuous vulnerability scanning, and endpoint protection. All controls are part of an ISO 27001 and Cyber Essentials Plus certified Information Security Management System (ISMS), ensuring compliance with internationally recognized security standards. Regular security scans, penetration testing, and vulnerability assessments are conducted to maintain an effective malware and threat prevention posture. All relevant personnel are trained on these procedures to support effective implementation and ongoing compliance. |
| Are asset management and malware protection policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates asset management and malware protection policies and procedures at least annually. This is in alignment with our ISO 27001 certification requirements, which mandate regular reviews of security policies and operational controls to ensure they remain effective and compliant with evolving security standards and threats. These updates are documented and approved by senior management, ensuring our practices are current and robust. | Are malware and malicious instructions protection policies and procedures, reviewed and updated at least annually or upon significant changes? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to enable scheduled and emergency responses to vulnerability identifications (based on the identified risk)? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to enable both scheduled and emergency responses to identified vulnerabilities, in alignment with our ISO 27001 certified Information Security Management System (ISMS). Our approach includes regular security scans, penetration testing, and dependency checks at the application level, alongside Azure's infrastructure-level protections. Critical vulnerabilities trigger our incident response process, ensuring rapid mitigation. These measures are regularly reviewed and updated based on emerging threats and vulnerabilities, maintaining compliance with industry standards and best practices. | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable scheduled and emergency responses to vulnerability identifications based on the identified risk? | Yes, Built Intelligence implements processes and procedures to manage vulnerability identification and response, in alignment with ISO 27001 controls and industry best practices. Specifically: - Risks—including software, firmware, and operating system vulnerabilities—are systematically identified and managed using a structured Operational Risk Management and Enterprise Risk Management approach.- Regular risk assessments are conducted, which include vulnerability assessments and penetration testing.- A defined incident and data breach response procedure is in place, covering detection, assessment, containment, and escalation of security incidents.- Detection and alerts are supported by Azure Security Center and Defender monitoring for threats and vulnerabilities.- Responses (both scheduled and emergency) are managed as part of the ISO 27001- aligned Information Security Management System (ISMS) to ensure timely and effective mitigation.These measures collectively ensure that processes, procedures, and technical controls are not only defined and implemented, but also regularly evaluated to address vulnerabilities based on assessed risk levels. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to update detection tools, threat signatures, and compromise indicators weekly (or more frequent) basis? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to update detection tools, threat signatures, and compromise indicators on a weekly basis. This is in alignment with our ISO 27001 certified Information Security Management System (ISMS) and leverages Microsoft Azure's infrastructure, including Azure Defender and Azure Security Center, which provide automated security updates and threat intelligence. These tools ensure that our security measures are up-to-date and effective against emerging threats, maintaining the security and integrity of the FastDraft platform. | Are processes, procedures, and technical measures defined, implemented, and evaluated to update detection tools, threat signatures, and indicators of compromise weekly or more frequently? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to identify updates for applications that use third-party or open-source libraries (according to the organization's vulnerability management policy)? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical measures to identify updates for applications that use third-party or open-source libraries, in accordance with our vulnerability management policy outlined in our ISO 27001 ISMS documentation. This includes regular security scans, dependency checks, and the application of patches to address identified vulnerabilities, ensuring that all components of our FastDraft platform hosted on Microsoft Azure remain secure and up-to-date. | Are processes, procedures, and technical measures defined, implemented, and evaluated to identify updates for applications that use third party or open source libraries according to the organization's vulnerability management policy? | Yes, Built Intelligence continuously evaluates processes, procedures, and technical measures to identify updates for applications that use third- party or open- source libraries, in accordance with its vulnerability management policy. These practices are outlined within the organization’s ISO 27001 Information Security Management System (ISMS) documentation. Controls include regular security scans, dependency checks, and the application of patches to address identified vulnerabilities, ensuring the platform remains secure and up- to- date. This approach aligns with CAIQ and ISO 27001 requirements for vulnerability management and control over third- party components. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated for periodic, independent, third-party penetration testing? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures for periodic, independent, third-party penetration testing. Our penetration tests are conducted annually by a CREST-approved provider, ensuring compliance with industry standards and our ISO 27001 certification. These tests help identify and mitigate vulnerabilities, enhancing the security posture of the FastDraft platform hosted on Microsoft Azure. | Are processes, procedures, and technical measures defined, implemented, and evaluated for the periodic performance of penetration testing by independent third parties? | Yes, Built Intelligence has established the following in alignment with AI governance, security, and risk management best practices (including CAIQ and ISO 27001 requirements): - Processes, procedures, and technical measures aredefined, implemented, and regularly evaluated for the periodic performance of penetration testing by independent third parties. - Penetration tests are conductedannually and performed by a CREST- approved provider , ensuring independent assessment. - This approach supports compliance with industry standards and ISO 27001 certification, with findings used to identify and mitigate vulnerabilities, thereby enhancing the overall security posture of the platform.These controls directly support CAIQ control objectives related to vulnerability and penetration testing, periodic independent assessment, and continuous improvement of security measures for cloud- based AI platforms. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated for vulnerability detection on organizationally managed assets at least monthly? | Yes, FastDraft implements processes, procedures, and technical measures for vulnerability detection on organizationally managed assets at least monthly. These measures include regular security scans, dependency checks, and penetration testing as part of our security strategy hosted on Microsoft Azure. Azure's infrastructure provides continuous security monitoring and threat management that align with our internal policies and the ISO 27001 and Cyber Essentials Plus standards we adhere to. | Are processes, procedures, and technical measures defined, implemented, and evaluated based on identified risks to support scheduled and emergency responses to vulnerability identification? | Yes, Built Intelligence has defined, implemented, and evaluated processes, procedures, and technical measures to address vulnerability identification and response aligned with ISO 27001 requirements. The approach includes the following controls: - Regular risk assessments and vulnerability management as part of their Operational Risk Management (ORM) and Enterprise Risk Management (ERM) frameworks.- Threat modelling, vulnerability assessments, and penetration testing to proactively identify and mitigate vulnerabilities.- The integration of Azure Security Center and Defender monitoring for real- time detection and response to security incidents, ensuring both scheduled and emergency responses.- Formal incident response and escalation procedures are in place for effective containment and reporting of identified vulnerabilities.These measures demonstrate an ongoing, risk- based approach to both scheduled (e.g., regular assessments, penetration tests) and emergency (e.g., immediate incident containment and escalation) responses for managing vulnerabilities, in accordance with industry best practices and compliance objectives (such as CAIQ and ISO 27001). |
| Is vulnerability remediation prioritized using a risk-based model from an industry-recognized framework? | Yes, Built Intelligence prioritizes vulnerability remediation using a risk-based model aligned with industry-recognized frameworks such as OWASP and ISO 27001. Our approach includes regular vulnerability assessments, prioritization based on risk severity, and timely remediation to ensure the security and integrity of the FastDraft platform. | Are risk-based models utilized to prioritize vulnerability remediation using an industry-recognized framework effectively? | Yes, Built Intelligenceemploys a risk- based approach to prioritize vulnerability remediation as part of its ISO 27001 certified Information Security Management System (ISMS). The control objectives are addressed as follows: - Policies and Procedures:Established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for identifying, reporting, and prioritizing vulnerability remediation. - Risk- Based Prioritization:Remediation activities are prioritized based on the severity and impact of identified vulnerabilities, constituting a risk- based model for remediation. - Industry Framework Alignment:The ISMS is certified under ISO 27001 and procedures are further aligned with Cyber Essentials Plus requirements, ensuring the use of industry- recognized best practices. - Regular Assessments:Security scans, penetration testing, and vulnerability assessments are conducted regularly to ensure ongoing risk identification and mitigation. - Personnel Training:Relevant staff receive training to ensure procedures are effectively implemented and complied with. These practices demonstrate effective alignment with CAIQ and ISO 27001 expectations regarding risk- based vulnerability management and remediation prioritization. |
| Is a process defined and implemented to track and report vulnerability identification and remediation activities that include stakeholder notification? | Yes, Built Intelligence has a defined and implemented process to track and report vulnerability identification and remediation activities, which includes stakeholder notification. This process is part of our ISO 27001 certified Information Security Management System (ISMS). Vulnerabilities are logged, assessed, and prioritized for remediation in our system. Stakeholders are notified through established communication channels as per our incident response and stakeholder communication procedures. | Are processes defined and implemented for tracking and reporting vulnerability identification and remediation activities that include stakeholder notification? | Yes, Built Intelligence has defined and implemented processes for tracking and reporting vulnerability identification and remediation activities, which include stakeholder notification. Specifically: - The process is part of ’s ISO 27001 certified Information Security Management System (ISMS).- Vulnerabilities are logged, assessed, and prioritized for remediation within their system.- Stakeholders are notified through established communication channels, as governed by incident response and stakeholder communication procedures.This aligns with CAIQ and ISO 27001 control objectives for vulnerability management, stakeholder communication, and incident response. |
| Are metrics for vulnerability identification and remediation established, monitored, and reported at defined intervals? | Yes, metrics for vulnerability identification and remediation are established, monitored, and reported at defined intervals as part of our ISO 27001 certified Information Security Management System (ISMS). We utilize Microsoft Azure's security tools to continuously monitor our infrastructure and applications for vulnerabilities. Remediation efforts are tracked and managed through our incident response process, ensuring timely updates and patches. Reports on these activities are reviewed monthly by our security team and quarterly by senior management to ensure ongoing compliance and improvement. | Are metrics established, monitored, and reported for vulnerability identification and remediation at defined intervals? | Yes, Built Intelligence has established comprehensive controls for vulnerability identification and remediation, structured as follows: - Policies and Procedures:Established, documented, approved, communicated, applied, evaluated, and maintained as part of the ISO 27001 certified Information Security Management System (ISMS). - Monitoring and Reporting:Regular security scans, penetration testing, and vulnerability assessments are performed to ensure ongoing identification and remediation of vulnerabilities. - Remediation and Metrics:Vulnerabilities are prioritized for remediation based on severity and impact, and relevant personnel are trained on procedures to ensure effective implementation. Findings from assessments (e.g., penetration testing) are addressed through structured remediation plans. - Defined Intervals:The policies and procedures, including threat and vulnerability management, are reviewed and updated at least annually. These practices collectively demonstrate that metrics for vulnerability identification and remediation are established, systematically monitored, and reported at defined intervals in alignment with ISO 27001, Cyber Essentials Plus, and AI governance best practices. |
| Are processes, procedures, and technical measures to apply guardrails to the AI system defined and implemented? | Yes, Built Intelligence maintains threat and vulnerability management processes to identify, assess, and mitigate security risks. - Regular vulnerability scanning and penetration testing are performed, with remediation tracked to closure. - Threat intelligence and risk assessments inform prioritization and control updates. - Processes are reviewed periodically and after significant changes. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are guardrails continuously evaluated for changes in regulatory requirements and risk scenarios? | Yes, Built Intelligence addresses the evaluation and updating of security controls and risk management as follows: - ensures systematic identification, evaluation, and management of risks through a structured approach aligned with ISO 27001 certification.- There is a Risk Management Framework (RMF) in place to integrate strategic, regulatory, and cybersecurity risks into governance processes, with regular risk assessments and monitoring.- The change management process requires risk assessments, including threat modelling and impact analysis, and is overseen and approved by relevant information security authorities.- Standard change management procedures for cryptography, encryption, and key management accommodate both internal and external sources and require impact assessment and compliance with security policies.- Changes to security systems, including potential guardrails, are reviewed for downstream effects such as residual risk and compliance requirements. The business continuity plan and information security requirements are updated based on these assessments. | ||
| Are threat analysis processes and procedures defined, implemented, and evaluated to identify, assess, and review the threat landscape for Cloud and AI systems? | Yes, Built Intelligence monitors and assesses the threat landscape relevant to its cloud and AI services and uses the outputs to inform risk treatment. - Threat intelligence sources and vulnerability disclosures are reviewed routinely. - Risk assessments and threat modelling are performed for material changes. - Findings drive control improvements and remediation priorities. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. | ||
| Are threat models built according to industry best practices to inform the risk mitigation strategy? | Yes, Built Intelligence employs threat modelling as part of its operational risk management processes. The platform's security features include regular risk assessments covering security, compliance, system availability, and data integrity, with specific mention of "threat modelling" as a core activity. These practices are aligned with ISO 27001 certification, ensuring that threat models are developed in accordance with established industry standards for information security management. The outputs of this process inform the broader risk mitigation strategy, which also includes vulnerability assessments, penetration testing, and business continuity planning to ensure comprehensive risk management and resilience. | ||
| Is a risk-based method for the prioritization and mitigation of threats, used, leveraging an industry-recognized framework to guide threat decision-making and protection measures? | Yes, Built Intelligence employs a risk- based approach for the prioritization and mitigation of threats, leveraging industry- recognized frameworks to guide decision- making and protection measures. Specifically: - structured Operational Risk Management (ORM) and Enterprise Risk Management (ERM) processes.- ISO 27001 and ISO 9001 certifications frame risk assessment, mitigation, and continuous improvement activities.- Regular risk assessments cover security, compliance, system availability, and data integrity, including threat modelling, vulnerability assessments, penetration testing, and business continuity planning.- An overarching Risk Management Framework (RMF) integrates strategic, financial, regulatory, and cybersecurity risks into governance and oversight processes.- Risks are monitored, reviewed, and escalated regularly through security committees to ensure alignment with business objectives and regulatory requirements.This approach demonstrates compliance with recognized industry standards (ISO 27001) and reflects alignment with CAIQ controls for risk- based threat management and mitigation processes. | ||
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for all endpoints? | Yes, policies and procedures are established, documented, approved, communicated, applied, evaluated, and maintained for all endpoints as per our ISMS documentation. These include user endpoint devices such as laptops, mobile phones, and tablets, which are covered under our User Endpoint Devices policy (ISMS DOC TEC05). This policy outlines the responsibilities, required controls, and guidelines for the protection and management of endpoint devices. Regular audits, access controls, encryption, and training are part of these procedures to ensure compliance and security. | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for all endpoints? | Yes, Built Intelligence maintains endpoint security controls as part of its corporate security program. - Managed endpoints are subject to baseline configuration, patching, and access control requirements. - Endpoint inventory, monitoring, and policy enforcement support secure handling of organization-managed data. - Controls are reviewed periodically within the ISMS. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are universal endpoint management policies and procedures reviewed and updated at least annually? | Yes, our universal endpoint management policies and procedures are reviewed and updated at least annually. This is in accordance with our internal Information Security Management System (ISMS) guidelines, which mandate regular reviews to adapt to emerging risks and changes in the business environment. The Information Security Manager is responsible for ensuring compliance with this policy and for overseeing the annual review process. | Are the policies and procedures reviewed and updated at least annually or upon significant system changes? | Yes, Built Intelligence's policies and procedures are reviewed and updated at least annually or upon significant system changes. Specifically, this practice applies to: - Policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. These are reviewed and updated at least annually as part of 's ISO 27001 certified Information Security Management System (ISMS), ensuring adaptation to operational changes, emerging threats, or new technologies.- Policies and procedures for maintaining a safe and secure working environment are also established, documented, and regularly reviewed to ensure continued compliance and effectiveness.This approach aligns with AI governance and risk management best practices and supports CAIQ and ISO 27001 control requirements for regular policy review and responsiveness to change. |
| Is there a defined, documented, applicable and evaluated list containing approved services, applications, and the sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data? | Yes, FastDraft maintains a defined, documented, applicable, and evaluated list of approved services, applications, and sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data. This list is part of our Information Security Management System (ISMS) and is regularly reviewed and updated to ensure compliance with our security policies and standards, including ISO 27001. Access to these services and applications is controlled through role-based access controls and authentication mechanisms, including Azure Active Directory and multi-factor authentication to ensure secure access to organization-managed data. | Is there a defined, documented, applicable and evaluated list containing approved services, applications, and the sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data? | Yes, Built Intelligence maintains endpoint security controls as part of its corporate security program. - Managed endpoints are subject to baseline configuration, patching, and access control requirements. - Endpoint inventory, monitoring, and policy enforcement support secure handling of organization-managed data. - Controls are reviewed periodically within the ISMS. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Is a process defined and implemented to validate endpoint device compatibility with operating systems and applications? | Yes, FastDraft has a defined and implemented process to validate endpoint device compatibility with operating systems and applications. This process is part of our ISMS documentation under User Endpoint Devices (ISMS DOC TEC05), which ensures that all user endpoint devices are automatically updated with the most recent operating system and application security-related patches, fixes, and updates. Regular and ad hoc audits of all mobile devices are conducted to ensure that they are configured in compliance with this procedure. | Is a process defined and implemented to validate endpoint device compatibility with operating systems and applications? | Yes, Built Intelligence has a defined and implemented process to validate endpoint device compatibility with operating systems and applications. This process is documented within the Information Security Management System (ISMS) under User Endpoint Devices. The controls include: - Automatic updates ensuring all user endpoint devices have the latest operating system and application security- related patches, fixes, and updates.- Regular and ad hoc audits of all mobile devices to confirm compliance with these procedures.This approach aligns with ISO 27001 requirements for system and application compatibility, maintaining risk- managed, secure endpoints throughout the organization. |
| Is an inventory of all endpoints used and maintained to store and access company data? | Yes, FastDraft maintains an inventory of all endpoints used to store and access company data. This inventory is part of our comprehensive security and compliance framework, managed through Microsoft Azure's infrastructure. Azure provides robust tools for monitoring and managing endpoints, ensuring that all access points are secured and compliant with industry standards, including ISO 27001 and Cyber Essentials Plus. | Is an inventory of all endpoints used to store and process company data maintained? | Yes, Built Intelligence maintains endpoint security controls as part of its corporate security program. - Managed endpoints are subject to baseline configuration, patching, and access control requirements. - Endpoint inventory, monitoring, and policy enforcement support secure handling of organization-managed data. - Controls are reviewed periodically within the ISMS. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented and evaluated, to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data? | Yes, Built Intelligence has defined, implemented, and regularly evaluates processes, procedures, and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data. These measures are aligned with ISO 27001 standards and include endpoint security solutions, access controls, encryption, and regular security assessments to ensure compliance and data protection across all organizational data handling activities. | Are processes, procedures, and technical measures defined, implemented and evaluated, to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data? | Yes, Built Intelligence established and maintains processes, procedures, and technical measures to enforce policies and controls for all endpoints that access, store, transmit, or process organizational data. Specifically: - Defined and implemented policies and controls align with ISO 27001 standards.- Technical measures include endpoint security solutions, access controls, encryption, and regular security assessments.- These controls are regularly evaluated to ensure ongoing compliance and data protection across all organizational data handling activities.These practices support core AI governance and risk management objectives by ensuring robust endpoint security and compliance with industry standards. |
| Are all relevant interactive-use endpoints configured to require an automatic lock screen? | Yes, all relevant interactive-use endpoints in the FastDraft platform are configured to require an automatic lock screen. This security measure is part of our comprehensive approach to safeguarding user data and ensuring the integrity of our multi-tenant PaaS solution hosted on Microsoft Azure. This feature is in alignment with our security policies and helps in maintaining compliance with industry standards and certifications such as ISO 27001. | Are all relevant interactive-use endpoints configured to require an automatic lock screen? | Yes, Built Intelligence enforces device security baselines for interactive endpoints, including automatic screen locking where applicable. - Endpoint configuration standards require automatic lock after a period of inactivity. - Compliance is monitored through endpoint management controls. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are changes to endpoint operating systems, patch levels, and/or applications managed through the organizational change management process? | Yes, changes to endpoint operating systems, patch levels, and/or applications are managed through the organizational change management process at FastDraft. We adhere to structured change management protocols to ensure that all modifications are reviewed, tested, and approved before implementation. This process is designed to minimize disruptions and maintain the integrity and security of our multi-tenant PaaS solution hosted on Microsoft Azure. | Are changes to endpoint operating systems, patch levels, and/or applications managed through the organizational change management process? | Yes, Built Intelligence changes to organizational assets—including applications, systems, infrastructure, and configurations—are managed through a structured change management process. This process is part of ’s ISO 27001 certified Information Security Management System (ISMS). The change management process encompasses risk assessment, impact analysis, and approval procedures for all changes, regardless of whether asset management is internal or outsourced. This ensures that changes to endpoint operating systems, patch levels, and applications are reviewed for security implications, controlled, and documented in line with industry compliance frameworks such as CAIQ and ISO 27001. - Risk assessment and impact analysis are performed for all changes affecting organizational assets, including endpoints.- Approval procedures ensure only authorized changes proceed.- The process covers both internally managed and outsourced assets, maintaining consistent security controls.- Controls are extended to subcontractors and supply chain partners to meet equivalent security standards. |
| Is information protected from unauthorized disclosure on managed endpoints with storage encryption? | Yes, information on managed endpoints is protected from unauthorized disclosure with storage encryption. FastDraft leverages Microsoft Azure’s infrastructure, which includes built-in encryption mechanisms for data at rest, ensuring that all stored data is encrypted using industry-standard protocols such as AES-256. This applies to all endpoints managed within the Azure environment, aligning with our ISO 27001 and Cyber Essentials Plus certifications. | Is information protected from unauthorized disclosure on managed endpoints with storage encryption? | Yes, Built Intelligence employs robust encryption controls to protect information from unauthorized disclosure on managed endpoints: - All data collected through the web application is encrypted at rest using industry- standard encryption protocols.- Microsoft Azure’s built- in encryption mechanisms are leveraged, including Transparent Data Encryption (TDE) for SQL databases and server- side encryption with AES- 256 for Azure Blob Storage.- Disk- level encryption is enabled by default for Azure managed disks, providing an additional layer of protection for stored data.These measures align with best practices for information security and support compliance objectives under frameworks such as ISO 27001 and CAIQ, specifically for endpoint and storage- level protection. |
| Are anti-malware detection and prevention technology services configured on managed endpoints? | Yes, FastDraft employs anti-malware detection and prevention technology services on all managed endpoints. This includes real-time scanning, automated updates, and advanced threat protection capabilities provided through Microsoft Defender for Endpoint, integrated within our Microsoft Azure infrastructure. This ensures robust security against malware, viruses, and other malicious threats, maintaining the integrity and security of our platform and user data. | Are anti-malware detection and prevention technology services configured on managed endpoints? | Yes, Built Intelligence uses endpoint protection/anti-malware controls on managed endpoints. - Anti-malware and threat protection is enabled and kept up to date. - Alerts are monitored and investigated through incident management procedures. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are software firewalls configured on managed endpoints? | Yes, All company-managed endpoints used to access and administer the FastDraft platform are configured with host-based firewalls. Built Intelligence uses centralized endpoint protection and configuration management to enforce firewall rules, detect anomalies, and ensure devices are compliant with internal security baselines. These configurations prevent unauthorized inbound traffic and support network segmentation policies when accessing Azure-hosted administrative consoles or sensitive data environments. | Are software firewalls properly configured on managed endpoints? | Yes, Built Intelligence requires host-based firewall controls on managed endpoints where applicable. - Firewall policies are configured as part of endpoint security baselines. - Exceptions are controlled and reviewed. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are managed endpoints configured with data loss prevention (DLP) technologies and rules per a risk assessment? | Yes, Built Intelligence configures managed endpoints with Data Loss Prevention (DLP) technologies and rules based on a comprehensive risk assessment. This is in alignment with our ISO 27001 certified Information Security Management System (ISMS), which includes policies and controls for data protection and loss prevention. DLP configurations are tailored to protect sensitive information against unauthorized access and data breaches, ensuring compliance with GDPR and other regulatory requirements. | Are managed endpoints configured with data loss prevention (DLP) technologies and rules in accordance with a risk assessment? | Yes, Built Intelligence applies controls to reduce the risk of data loss from endpoints handling organization-managed data. - Access controls, encryption, and policy-based restrictions are applied based on risk. - Additional DLP controls may be implemented where warranted by risk assessment and legal requirements. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are remote geolocation capabilities enabled for all managed mobile endpoints? | Yes, Built Intelligence uses mobile device management (MDM) tools to manage and monitor mobile endpoints used by staff to access FastDraft or company resources. These tools support remote geolocation, remote lock, and remote wipe capabilities to protect data in case of device loss or theft. All mobile devices with access to FastDraft administrative or support tools must be enrolled in MDM and meet our minimum security requirements, including encryption and PIN protection. | Are remote geolocation capabilities enabled for all managed mobile endpoints, according to all applicable laws and regulations? | Yes, Built Intelligence can enable remote management capabilities for managed mobile endpoints where permitted by law and organizational policy. - Mobile device management controls are configured in line with legal and regulatory constraints. - Usage is limited to legitimate security and operational purposes and is subject to governance oversight. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical measures defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices? | Yes, processes, procedures, and technical measures are defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices. Our policy, as outlined in the User Endpoint Devices (ISMS DOC TEC05), mandates that all user endpoint devices are equipped with capabilities for remote disablement and wiping. This is enforced through the deployment of management software that allows our Information Security Team to remotely access and manage endpoint devices, ensuring the ability to delete company data remotely in case of device loss, theft, or when an employee leaves the company. This capability is regularly tested and audited to ensure compliance and effectiveness. | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices? | Yes, Built Intelligence maintains processes to support remote removal of company data from managed endpoints where applicable. - Remote wipe/retire capabilities are used for lost, stolen, or decommissioned devices. - Actions are authorized, logged, and reviewed. These controls are managed through our ISO 27001-certified Information Security Management System (ISMS), including risk assessment, change control, and periodic review. |
| Are processes, procedures, and technical and/or contractual measures defined, implemented, and evaluated to maintain proper security of third-party endpoints with access to organizational assets? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and technical and/or contractual measures to maintain the security of third-party endpoints accessing organizational assets. These measures are aligned with our ISO 27001 certified Information Security Management System (ISMS) and include: - Rigorous third-party risk assessments and due diligence before granting access. - Use of Data Processing Agreements (DPAs) that include security requirements and Standard Contractual Clauses (SCCs) for compliance with GDPR and other relevant regulations. - Implementation of role-based access controls (RBAC) to ensure that third-party access is restricted to what is necessary for their role. - Regular audits and reviews of third-party access and activities to ensure compliance with our security policies and standards. - Mandatory security training for third parties accessing our systems, covering best practices and compliance requirements. These measures ensure that third-party endpoints are secured and that their access to organizational assets does not compromise our security posture. | Are processes, procedures, and technical and/or contractual measures defined, implemented, and evaluated to maintain proper security of third-party endpoints with access to organizational assets? | Yes, Built Intelligence has established the following measures to maintain the security of third- party endpoints with access to organizational assets: - Defined Processes and Procedures:All third- party suppliers, including those providing infrastructure such as Microsoft Azure, undergo due diligence before onboarding and are subject to periodic review thereafter. This process evaluates the supplier’s security posture, certifications, and data processing arrangements. - Technical and Contractual Measures: ensures that Data Processing Agreements (DPAs) are established when personal data is processed by third parties and requires the implementation of appropriate technical and organizational security measures. These practices are aligned with ISO 27001 standards. - Ongoing Review:Supplier risk, criticality, and continued suitability are periodically reviewed to maintain an appropriate security posture. The documentation explicitly confirms that these controls are in place and regularly evaluated to mitigate risks associated with third- party endpoints accessing organizational assets. |
| Is the remediation status of audit findings reviewed and reported to relevant stakeholders? | Yes, the remediation status of audit findings is reviewed and reported to relevant stakeholders. FastDraft, hosted on Microsoft Azure, adheres to strict compliance and audit processes. We conduct regular internal and external audits, and findings are documented and tracked through our compliance management system. Remediation actions are assigned and monitored for completion. Status updates and final reports are communicated to relevant stakeholders, including management and, if applicable, external clients, ensuring transparency and accountability in our compliance and security posture. | ||
| Is the deployment and integration of application code automated where possible? | Yes, the deployment and integration of application code in FastDraft are automated where possible. We utilize Microsoft Azure DevOps for continuous integration and continuous deployment (CI/CD) pipelines, ensuring that code changes are automatically built, tested, and deployed to production environments efficiently and reliably. This automation helps in maintaining high standards of code quality and security compliance. | ||
| Is the remediation of application security vulnerabilities automated when possible? | Yes, the remediation of application security vulnerabilities in FastDraft is automated when possible. We leverage Microsoft Azure's integrated security tools, such as Azure Security Center and Azure Defender, to automatically apply security patches and updates to the underlying PaaS services. Additionally, our development processes include automated dependency checks and security scanning within our CI/CD pipelines to identify and address vulnerabilities before deployment. For high-severity issues, automated alerts are configured to notify our security team for immediate action. This approach aligns with our ISO 27001 and Cyber Essentials Plus standards, ensuring a proactive stance on vulnerability management. | ||
| Is business continuity and operational resilience documentation reviewed periodically? | Yes, the business continuity and operational resilience documentation is reviewed periodically in alignment with our ISO 27001 certification requirements and internal policies. These documents are updated as necessary to reflect changes in business processes, technology, and compliance obligations, ensuring that our response strategies remain effective and relevant. | ||
| Can backups be restored appropriately for resiliency? | Yes, FastDraft ensures appropriate backup restoration for resiliency. We utilize Azure's robust backup and disaster recovery capabilities, which include geo-redundant storage to ensure data is replicated in multiple locations. Our backup procedures are tested regularly to confirm that data can be restored accurately and promptly in the event of an incident. This aligns with our ISO 27001 certified processes, ensuring data integrity and availability. | ||
| Are local emergency authorities included, if possible, in the exercise? | Built Intelligence includes business continuity and disaster recovery (BC/DR) testing as part of its annual operational risk assessment for the FastDraft platform, which is hosted in Microsoft Azure. While direct inclusion of local emergency authorities is not typically required due to the nature of our cloud-based SaaS delivery, our incident response and escalation procedures align with regional Azure data center protocols, which do involve local authorities when necessary. In regions where FastDraft is deployed, we ensure that our response plans align with Azure’s local compliance and continuity frameworks, which include cooperation with emergency services during major regional disruptions. | ||
| 'Is the procedure aligned with the requirements of the GRC-04: Policy Exception Process?' | Yes, the procedure outlined in the Leadership (ISMS DOC C5) - Restricted document is aligned with the requirements of the GRC-04: Policy Exception Process. The document clearly defines roles, responsibilities, and authorities, ensuring that exceptions to policies are managed appropriately and in accordance with the strategic direction of the organization. This includes the assignment of specific roles such as the Information Security Manager and the Information Security Team, who have the authority to approve significant expenditures and high-level policies related to information security, which are essential components of managing policy exceptions effectively. | ||
| Are physical security perimeters established between administrative and business areas, data storage, and processing facilities? | Yes, Built Intelligence has established physical security perimeters between administrative and business areas, data storage, and processing facilities. Our physical security measures include controlled access points, CCTV surveillance, and secure areas designated for sensitive data handling and processing. These controls are in place at both our office locations and the Microsoft Azure data centers where the FastDraft platform is hosted, ensuring compliance with ISO 27001 and Cyber Essentials Plus standards. | ||
| Does the CSP give special attention to the notification procedure to interested CSCs, unless otherwise prohibited, such as a prohibition under criminal law to preserve confidentiality of a law enforcement investigation? | Yes, Built Intelligence ensures that the notification procedure to interested CSCs is given special attention, unless prohibited by law, such as in cases where confidentiality of a law enforcement investigation must be preserved. This is in compliance with our ISO 27001 certified Information Security Management System, which includes procedures for handling such legal constraints while ensuring transparency and communication with relevant stakeholders. | ||
| Is contact established and maintained with cloud-related special interest groups and other relevant entities? | Yes, Built Intelligence actively establishes and maintains contact with cloud-related special interest groups and other relevant entities to stay updated on the latest trends, best practices, and security standards in cloud computing. This engagement helps us ensure that our FastDraft platform, hosted on Microsoft Azure, aligns with industry-leading practices and complies with relevant regulations. | ||
| Are all employees granted access to sensitive organizational and personal data provided with regular updates in procedures, processes, and policies relating to their professional function? | Yes, all employees at Built Intelligence with access to sensitive organizational and personal data are provided with regular updates in procedures, processes, and policies relating to their professional functions. This is part of our commitment to ISO 27001 and GDPR compliance, ensuring that all staff are aware of and adhere to the latest security practices and data protection requirements. Training is conducted upon hiring and annually thereafter, with additional updates provided as necessary when changes occur. | ||
| Is the ability to disable the "read-only" configuration of logging infrastructure controlled through a procedure that ensures the segregation of duties and break glass procedures? | Yes, the ability to disable the "read-only" configuration of logging infrastructure is controlled through a procedure that ensures the segregation of duties and break glass procedures. This is managed through role-based access controls and audit policies within Microsoft Azure, ensuring that only authorized personnel with specific roles can make such changes. Additionally, any changes to the logging configuration are logged and monitored to ensure compliance with our security policies and procedures. | ||
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for application development portability? | Yes, FastDraft has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for application development portability. These are outlined in our Information Security Management System (ISMS) and adhere to ISO 27001 standards. Our development practices ensure that FastDraft's application is built on Microsoft Azure PaaS, supporting scalability and flexibility across different environments, which is critical for maintaining portability. These procedures are regularly reviewed and updated to align with evolving security standards and technological advancements. | ||
| Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information/data exchange, usage, portability, integrity, and persistence? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained policies and procedures for information and data exchange, usage, portability, integrity, and persistence. These are aligned with ISO 27001 standards and are part of our Information Security Management System (ISMS), ensuring compliance with data protection laws and regulations. Our procedures include secure data transfer protocols, data integrity checks, and measures for maintaining data persistence, all regularly reviewed and updated to address emerging security threats and technological changes. | ||
| Are interoperability and portability policies and procedures reviewed and updated at least annually? | Yes, interoperability and portability policies and procedures are reviewed and updated at least annually to ensure they align with current technological standards and business requirements. This regular review is part of our commitment to maintaining ISO 27001 standards and ensuring our systems and services remain efficient, secure, and compliant with industry best practices. | ||
| Are infrastructure and virtualization security policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes, Built Intelligence has established, documented, approved, communicated, applied, evaluated, and maintained infrastructure and virtualization security policies and procedures. These are outlined in our ISMS documents, specifically ISMS DOC TEC01, which covers operations including change management, capacity management, and protection against malware. Our policies are regularly reviewed and updated to align with emerging risks and changes in the business environment, ensuring compliance with ISO 27001 standards. | ||
| Are infrastructure and virtualization security policies and procedures reviewed and updated at least annually? | Yes, Built Intelligence reviews and updates infrastructure and virtualization security policies and procedures at least annually, in alignment with our ISO 27001 certification requirements. This ensures that our policies remain effective and compliant with current security standards and best practices. | ||
| Is resource availability, quality, and capacity planned and monitored in a way that delivers required system performance, as determined by the business? | Yes, resource availability, quality, and capacity are planned and monitored to ensure required system performance as determined by the business. This is managed through Microsoft Azure's capabilities such as autoscaling, load balancing, and performance monitoring tools, ensuring that FastDraft meets the performance standards set by our business requirements. Azure's infrastructure provides detailed insights and analytics that help us maintain optimal performance and resource allocation. | ||
| Are communications between environments monitored? | Yes, communications between environments in FastDraft are monitored. We utilize Azure's native capabilities such as Azure Monitor and Azure Security Center to oversee and manage the traffic and activities between our environments. This ensures that any unusual or unauthorized activities are detected and addressed promptly, maintaining the integrity and security of our data and services. | ||
| Are communications between environments encrypted? | Yes, communications between environments in FastDraft are encrypted. We utilize Microsoft Azure's built-in security controls, including TLS/SSL protocols, to ensure that all data in transit is securely encrypted. This aligns with industry best practices and compliance standards such as ISO 27001, which we are certified under. | ||
| Are communications between environments restricted to only authenticated and authorized connections, as justified by the business? | Yes, communications between environments in the FastDraft platform are restricted to only authenticated and authorized connections. This is enforced through role-based access controls and secure communication protocols implemented within the Microsoft Azure infrastructure. Azure's built-in security controls, including network security groups and application gateways, ensure that only legitimate and authorized traffic is allowed between different segments of our environment, aligning with business justifications and compliance requirements. | ||
| Are network configurations reviewed at least annually? | Yes, network configurations for FastDraft are reviewed at least annually. This review is part of our ISO 27001 compliant Information Security Management System (ISMS) processes, which include regular audits and assessments of our network infrastructure hosted on Microsoft Azure. These reviews ensure that configurations are optimized for security, performance, and compliance with current industry standards and best practices. | ||
| Are network configurations supported by the documented justification of all allowed services, protocols, ports, and compensating controls? | Yes, all network configurations in FastDraft are supported by documented justifications for all allowed services, protocols, ports, and compensating controls. These configurations are aligned with our ISO 27001 certified Information Security Management System (ISMS) and are regularly reviewed to ensure they meet security best practices and compliance requirements. Changes to network configurations are managed through our change control process, ensuring that any modifications are justified, documented, and approved by relevant authorities. | ||
| Is every host and guest OS, hypervisor, or infrastructure control plane hardened (according to their respective best practices) and supported by technical controls as part of a security baseline? | Yes, FastDraft is hosted on Microsoft Azure, where the host and guest OS, hypervisors, and infrastructure control planes are hardened according to their respective best practices. Azure follows a rigorous security baseline that includes regular updates, patch management, and compliance with international security standards such as ISO 27001, SOC 1/2/3, and PCI DSS. Technical controls implemented include network segmentation, access controls, threat detection, and response mechanisms, ensuring a robust security posture for the hosted services. | ||
| Are production and non-production environments separated? | Yes, FastDraft ensures that production and non-production environments are separated. This separation is maintained within the Microsoft Azure infrastructure, which provides distinct and secure environments for different stages of application deployment, including development, testing, and production. This approach aligns with best practices for security and operational efficiency, ensuring that testing and development activities do not impact the production environment. | ||
| Are applications and infrastructures designed, developed, deployed, and configured such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented, segregated, monitored, and restricted from other tenants? | Yes, FastDraft's multi-tenant PaaS solution hosted on Microsoft Azure ensures that user access and intra-tenant access are appropriately segmented, segregated, monitored, and restricted from other tenants. We utilize Azure's built-in security controls and services such as Azure Active Directory for identity management and access control, and Azure Virtual Networks to isolate network traffic between tenants. Additionally, role-based access controls (RBAC) are implemented to ensure that users can only access resources necessary for their role. Monitoring and logging are handled by Azure Monitor and Azure Security Center, providing visibility and proactive security alerts. This architecture aligns with our ISO 27001 certification requirements regarding information security management. | ||
| Are secure and encrypted communication channels including only up-to-date and approved protocols used when migrating servers, services, applications, or data to cloud environments? | Yes, FastDraft utilizes secure and encrypted communication channels, including only up-to-date and approved protocols, when migrating servers, services, applications, or data to cloud environments. We employ TLS 1.2 or higher for all data in transit and AES-256 encryption for data at rest, strictly adhering to Microsoft Azure's security standards. This ensures compliance with industry best practices and regulatory requirements for data protection. | ||
| Are high-risk environments identified and documented? | Yes, high-risk environments within the FastDraft platform are identified and documented as part of our ISO 27001 compliant Information Security Management System (ISMS). This includes detailed risk assessments and mitigation strategies for environments handling sensitive data, ensuring robust security controls and compliance with regulatory requirements. | ||
| Are processes, procedures, and defense-in-depth techniques defined, implemented, and evaluated for protection, detection, and timely response to network-based attacks? | Yes, Built Intelligence has defined, implemented, and continuously evaluates processes, procedures, and defense-in-depth techniques for the protection, detection, and timely response to network-based attacks. Our security strategy is aligned with ISO 27001 standards and leverages Microsoft Azure's robust security features, including Azure Firewall, Network Security Groups (NSGs), and Azure Sentinel for comprehensive monitoring and threat detection. We conduct regular security assessments, penetration testing, and real-time monitoring to ensure rapid response to any network-based threats, maintaining the integrity and availability of the FastDraft platform. |
Comments
0 comments
Please sign in to leave a comment.