# Security at NiCE | Cognigy

NiCE | Cognigy provides enterprise-grade AI automation and conversational platforms that enable organizations to deliver secure, compliant, and human-centric customer experiences. Headquartered in Düsseldorf, Germany, the company operates under a unified governance framework certified to international standards including ISO 27001, ISO 27701, ISO 42001, SOC 2 Type II, TISAX and BSI C5. NiCE | Cognigy’s platform combines advanced automation, AI orchestration, and natural language understanding (NLU) with a strong focus on data protection, reliability, and regulatory compliance.

## Controls

### Infrastructure security

| Control | Status |
| --- | --- |
| Unique account authentication enforced<br>The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys. |  |
| Unique network system authentication enforced<br>The company requires authentication to the "production network" to use unique usernames and passwords or authorized Secure Socket Shell (SSH) keys. |  |
| Remote access MFA enforced<br>The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method. |  |
| Remote access encrypted enforced<br>The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |  |
| Intrusion detection system utilized<br>The company uses an intrusion detection system to provide continuous monitoring of the company's network and early detection of potential security breaches. |  |
| Infrastructure performance monitored<br>An infrastructure monitoring tool is utilized to monitor systems, infrastructure, and performance and generates alerts when specific predefined thresholds are met. |  |
| Network firewalls reviewed<br>The company reviews its firewall rulesets at least annually. Required changes are tracked to completion. |  |
| Network firewalls utilized<br>The company uses firewalls and configures them to prevent unauthorized access. |  |
| Access revoked upon termination<br>The company completes termination checklists to ensure that access is revoked for terminated employees within SLAs. |  |

### Organizational security

| Control | Status |
| --- | --- |
| Asset disposal procedures utilized<br>The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed. |  |
| Production inventory maintained<br>The company maintains a formal inventory of production system assets. |  |
| Portable media encrypted<br>The company encrypts portable and removable media devices when used. |  |
| Anti-malware technology utilized<br>The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems. |  |
| Confidentiality Agreement acknowledged by contractors<br>The company requires contractors to sign a confidentiality agreement at the time of engagement. |  |
| Confidentiality Agreement acknowledged by employees<br>The company requires employees to sign a confidentiality agreement during onboarding. |  |
| Performance evaluations conducted<br>The company managers are required to complete performance evaluations for direct reports at least annually. |  |
| MDM system utilized<br>The company has a mobile device management (MDM) system in place to centrally manage mobile devices supporting the service. |  |
| Security awareness training implemented<br>The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter. |  |
| Employee background checks performed<br>The company performs background checks on new employees. |  |

### Product security

| Control | Status |
| --- | --- |
| Data encryption utilized<br>The company's datastores housing sensitive customer data are encrypted at rest. |  |
| Control self-assessments conducted<br>The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA. |  |
| Data transmission encrypted<br>The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks. |  |
| Vulnerability and system monitoring procedures established<br>The company's formal policies outline the requirements for the following functions related to IT / Engineering:<br>- vulnerability management;<br>  <br>- system monitoring. |  |

### Internal security procedures

| Control | Status |
| --- | --- |
| Cybersecurity insurance maintained<br>The company maintains cybersecurity insurance to mitigate the financial impact of business disruptions. |  |
| Configuration management system established<br>The company has a configuration management procedure in place to ensure that system configurations are deployed consistently throughout the environment. |  |
| SOC 2 - System Description<br>Complete a description of your system for Section III of the audit report |  |
| Whistleblower policy established<br>The company has established a formalized whistleblower policy, and an anonymous communication channel is in place for users to report potential issues or fraud concerns. |  |
| Board charter documented<br>The company's board of directors has a documented charter that outlines its oversight responsibilities for internal control. |  |
| Board expertise developed<br>The company's board members have sufficient expertise to oversee management's ability to design, implement and operate information security controls. The board engages third-party information security experts and consultants as needed. |  |
| Board meetings conducted<br>The company's board of directors meets at least annually and maintains formal meeting minutes. The board includes directors that are independent of the company. |  |
| System changes externally communicated<br>The company notifies customers of critical system changes that may affect their processing. |  |
| Organization structure documented<br>The company maintains an organizational chart that describes the organizational structure and reporting lines. |  |
| Roles and responsibilities specified<br>Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy. |  |

### Data and privacy

| Control | Status |
| --- | --- |
| Customer data deleted upon leaving<br>The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service. |  |

### Responsible AI

| Control | Status |
| --- | --- |
| AI system impact assessment<br>The AI system impact assessment shall determine the potential consequences an AI system’s deployment, intended use and foreseeable misuse has on individuals or groups of individuals, or both, and societies. The AI system impact assessment shall take into account the specific technical and societal context where the AI system is deployed and applicable jurisdictions. The result of the AI system impact assessment shall be documented. Where appropriate, the result of the system impact assessment can be made available to relevant interested parties as defined by the organization. The organization shall consider the results of the AI system impact assessment in the risk assessment (see 6.1.2). |  |
| Determining the scope of the AI management system<br>The organization shall determine the boundaries and applicability of the AI management system to establish its scope. When determining this scope, the organization shall consider:<br>— the external and internal issues referred to in 4.1;<br>— the requirements referred to in 4.2.<br>The scope shall be available as documented information. The scope of the AI management system shall determine the organization’s activities with respect to this document’s requirements on the AI management system, leadership, planning, support, operation, performance, evaluation, improvement, controls and objectives. |  |
| AI objectives and planning<br>The organization shall establish AI objectives at relevant functions and levels. The AI objectives shall:<br>a) be consistent with the AI policy (see 5.2);<br>b) be measurable (if practicable);<br>c) take into account applicable requirements;<br>d) be monitored;<br>e) be communicated;<br>f) be updated as appropriate;<br>g) be available as documented information.<br>When planning how to achieve its AI objectives, the organization shall determine:<br>— what will be done;<br>— what resources will be required;<br>— who will be responsible;<br>— when it will be completed;<br>— how the results will be evaluated.<br>NOTE A non-exclusive list of AI objectives relating to risk management is provided in Annex C. Control objectives and controls for identifying objectives for responsible development and use of AI systems and measures to achieve them are provided in A.6.1 and A.9.3 in Table A.1. Implementation guidance for these controls is provided in B.6.1 and B.9.3. |  |
| Monitoring, measurement, analysis<br>The organization shall determine:<br>— what needs to be monitored and measured;<br>— the methods for monitoring, measurement, analysis and evaluation, as applicable, to ensure valid results;<br>— when the monitoring and measuring shall be performed;<br>— when the results from monitoring and measurement shall be analysed and evaluated.<br>Documented information shall be available as evidence of the results. The organization shall evaluate the performance and the effectiveness of the AI management system. |  |
| General<br>When planning for the AI management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to:<br>— give assurance that the AI management system can achieve its intended result(s);<br>— prevent or reduce undesired effects;<br>— achieve continual improvement.<br>The organization shall establish and maintain AI risk criteria that support:<br>— distinguishing acceptable from non-acceptable risks;<br>— performing AI risk assessments;<br>— conducting AI risk treatment;<br>— assessing AI risk impacts. |  |
| Continual improvement<br>The organization shall continually improve the suitability, adequacy and effectiveness of the AI management system. |  |
| Nonconformity and corrective action<br>When a nonconformity occurs, the organization shall:<br>a) react to the nonconformity and as applicable:<br>1. take action to control and correct it;<br>   <br>2. deal with the consequences;<br>   <br>b) evaluate the need for action to eliminate the cause(s) of the nonconformity, so that it does not recur or occur elsewhere, by:<br>1. reviewing the nonconformity;<br>   <br>2. determining the causes of the nonconformity;<br>   <br>3. determining if similar nonconformities exist or can potentially occur;<br>   <br>c) implement any action needed;<br>d) review the effectiveness of any corrective action taken;<br>e) make changes to the AI management system, if necessary.<br>Corrective actions shall be appropriate to the effects of the nonconformities encountered.<br>Documented information shall be available as evidence of:<br>— the nature of the nonconformities and any subsequent actions taken;<br>— the results of any corrective action. |  |
| Objectives for responsible development of AI system<br>The organization should identify and document objectives to guide the responsible development of AI systems, and take those objectives into account and integrate measures to achieve them in the development life cycle. |  |
| Processes for responsible design and development of AI systems<br>The organization should define and document the specific processes for the responsible design and development of the AI system. |  |
| External reporting<br>The organization should provide capabilities for interested parties to report adverse impacts of the system. |  |
