Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 10 of 19

#6 Designing your connected place architecture

You need to ensure that your connected place architecture is designed securely. Your designs need to take into consideration the logical separation (or 'zones of trust') of your connected place network and identify critical security boundaries. This should not be limited to the cyber domain but also the cyber-physical (dual redundant sensors and/or actuators), and the physical space (such as diverse power supplies or communication routes). This ensures that if an incident occurs due to component failure or cyber attack, the impact is localised and failover options exist (as specified in the Design principles to make compromise and disruption more difficult).

You need to assess what protections are needed within your connected place. As with Principle 2, you need to understand and make assumptions about the threats your connected place may face, and analyse and deal with those top candidate threats. You then need to use methods such as threat modelling to identify how your connected place may be exploited (using STRIDE, for example). You will need to model your connected place by:

  • Considering the importance of the services available, the operational data it relies on, and the privacy of citizen data that is held within your connected place. You then need to understand what the potential negative impacts may be if these were to be affected.
  • Considering the internal or external events or attacks that may take place.
  • Considering the threats and potential vulnerabilities over the horizon such as quantum computing.
  • Considering each component within your connected place, how it protects itself from attack by making compromise harder, and how compromise is detected to be able to respond quicker.

For further information on threat modelling and determining security protections, here is a relevant blog:

When designing your connected place's architecture, considerations should include:

  • Understanding of the data that your system will ingest and its originating source.
  • Consideration of which elements of your system need to have the highest levels of trust.
  • Consideration of which elements of your system would result in the biggest impact if compromised.
  • Confidence that protections in place are appropriate for the services you are aiming to protect, and will detect or prevent an attacker from achieving their goals.
  • Understanding of how data that services are responsible for are protected when at rest and in transit. You also need to implement protections from the data coming in from less trusted sources (such as the wider network and associated sensors).
  • Ability for all connected place systems to validate, transform or render any external or low-trust data to neutralise potential incoming attacks.
  • Maintaining appropriate trust levels in the tiers of your network most critical to your connected place.
  • Identifying any services or infrastructure (such as management or monitoring) that might bypass your controls.

You also need to implement products, protocols and algorithms to enable authentication, authorisation, and the protection of your data in transit. Where practical, you should look to implement:

  • the latest versions of products to close vulnerabilities before attackers can exploit them
  • products that will give you the right level of confidence of their security ability (and have the latest version of these products)
  • operational technology products and components supported by vulnerability management processes including consistent patching cycles
  • the latest versions of secure protocols, deployed correctly so your data is encrypted to stop attackers being able to view and manipulate it
  • strong cryptographic algorithms that provide you the right level of protection required

The NCSC has published guidance which can help with secure design:

Published

Reviewed

Version

1.0