Brightest's Security Management Program.
Last revised: January 4, 2023
At Brightest, we closely integrate physical security, cybersecurity, web application security, risk management, and privacy best practices throughout our business, product development, web architecture, and DevOps processes, allowing us to provide enterprise-ready social impact, sustainability, corporate social responsibility (CSR), and environmental social governance (ESG) software that meets your security controls and requirements, earns your trust, protects critial financial, intellectual property, and employee data, and complies with international data privacy laws.
A central component of that continuous effort is the Brightest Security Management Program (BSMP). Our BSMP is based on the ISO 27001 Information Security Management System standard, which states:
This International Standard can be used by internal and external parties to assess the organization’s ability to meet the organization’s own information security requirements.
Any client considering using cloud software and services for carbon accounting, climate risk management, sustainability reporting, ESG reporting, or supply chain due diligence should take carefully consider what the best sustainability reporting software solution is for their organization, and we strive to be a secure cloud service provider that meets all of an organization's sustainability and IT needs. As a technology partner responsible for hosting and handling client data, Brightest implements appropriate care, controls, and industry best practices to the protect confidentiality of our client's data.
While each of our clients have their own security requirements, the ISO 27001 approach to planning, operating, evaluating performance, and improving allows for continuous evaluation of how our security program is operating, and helps us to learn and enhance the program and our controls over time to take into consideration new threats, new requirements, or to improve the overall performance, governance, and sustainability of our business.
We evaluate recognized international, third-party security standards as a set of well-structured guidelines, but consider each of the controls and whether those controls are appropriate for our particular case, business, and application. We take a similar approach to the overall applicability of these international standards to our environment.
Today, our clients include governments, publicly-traded companies, and organizations operating in highly-regulated industries, thanks to the strength and consistency of our security controls and risk management practices.
Brightest's Security Management Program (BSMP) Overview
Brightest's BSMP takes industry best practices into consideration, including ISO, CSA (Cloud Security Alliance), CAIQ (Consensus Assessments Initiative Questionnaire), OWASP (The Open Web Application Security Project®), and SIG (Standardized Information Gathering) to implement a systematic structure and continuous improvement approach necessary to safeguard company and our clients.
Our BSMP operates around the following principles:
- Clearly outline our security roles and responsibilities: we clearly document who in the organization is responsible for security, our security organizational matrix, and what roles different members of our teams carry out to ensure the ongoing security of our business and platform
- Clearly outline our security objectives and goals: we must maintain clear security goals and hold ourselves to "zero defect" standards
- Always meet our regulatory obligations: we will always comply with local, regional, national, and international data privacy laws and security obligations
- Focused on continuous iteration and improvement: we actively and diligently anticipate, monitor, and evaluate risks in our environment and in our program, and reflect those in our policies, practices, and controls
- Review and train annually: we perform annual risk assessments which incorporate likelihood and impact for all risk categories and are aligned with our risk management model, program, and policies. We also make sure all stakeholders within our BSMP receive the appropriate annual training, including CISA Cyber Essentials. We will periodically perform specific risk assessments around an application, innovation area, environment, risk area, or specific threat, both on an ongoing quarterly basis and in response to a specific risk profile
In order to continuously evaluate risks to our business, environments, and application(s), we perform on-going risk assessments. In many cases, especially in the case of our applications, these are performed as technical risk assessments or code reviews. However, we also evaluate our entire organization and value chain to uncover higher level business risks. Generally, we have adopted the ISO 27005 or ISO 31010 Risk Management methodology and apply that methodology to a particular scope.
Our continuous approach to risk management includes:
- Conducting regular risk assessment activities- this includes executing risk assessments, facilitating risk treatment decisions, identifying the risk scope and potential exposure under that scope, identifying risks, assessing the impact and likelihood, and reviewing, reporting, and preventing or mitigating those risks
- Monitoring and reporting on policies, projects, and controls intended to manage security risks- we continue to monitor and report on all risk-related policies, programs, and projects designed to manage security risks or that fall under our BSMP
- Support the BSMP - through continued risk evaluation as a mechanism to improve the environment and to ensure that the implemented security controls effectively manage identified security risks
- Partnering with AWS - 100% of Brightest's applications and client data are hosted, powered, and protected by the world's #1 cloud hosting provider, Amazon Web Services (AWS), whose ISO 27001 and SOC 2 security and compliance protects Brightest, our clients, and data for organizations like Aon, Adobe, Alcatel-Lucent, Autodesk, BMW, British Gas, Bristol-Myers Squibb, Canon, Capital One, Citrix, Coinbase, Comcast, Disney, Docker, Dow Jones, European Space Agency, ESPN, Expedia, Financial Times, FINRA, General Electric, Guardian News & Media, Harvard Medical School, Hearst Corporation, Hitachi, Johnson & Johnson, Kellogg’s, McDonalds, NASA, NASDAQ, Novartis, Pfizer, Philips, Salesforce, Samsung, SAP, Schneider Electric, Siemens, Slack, Sony, Tata Motors, Unilever, the US Department of State, the USDA Food and Nutrition Service, the UK Ministry of Justice, and more.
Brightest's underlying web infrastructure runs on AWS EC2 servers, Docker, and Kubernetes, the container system underlying Google Cloud. This approach provides us considerable security, flexibility, and scalability across different regions and client needs. To learn more, please see our application security overview>.
For more information on our cloud hosting and database security levels, please see AWS's security resources and policies at https://aws.amazon.com/security/ and https://docs.aws.amazon.com/whitepapers/latest/introduction-aws-security/introduction-aws-security.pdf
Conclusion
At Brightest, we believe we've designed and implemented our BSMP program to be flexible, responsive, and resilient, but also structured in ways that help us continously monitor, evaluate, and address new threats and risks to us and our clients.
Security is an ongoing continuous improvement discipline, we know it matters (that's why you're here), and we're working hard to continue earning and preserving your trust and safety.
Thanks for reading. If you have any questions or comments about our security policies, approach, work, or information, or would like to report a security concern please contact us here.
