Guidance
Connected Places Cyber Security Principles
Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 14 of 19
Your connected place monitoring system needs to be independent from the operational connected place systems. This ensures that if the system operating the connected place is compromised, the attacker will have no visibility of whether the breach has been detected, and cannot remove their tracks from the logs.
Your monitoring design should give you visibility of all aspects of your connected place system, including endpoints and network edge devices. You should look to understand and create a baseline view of the normal operations of your connected place, which will enable the detection of abnormalities, and help you be better placed to identify true and false events. As threats and technology evolve, so must your monitoring and event selection, which will enable wider visibility of your system. You can use threat hunting exercises and tools to support this, such as the MITRE Attack Framework. Taking these steps will assist your ability in being able to monitor the areas of your connected place that rely on key data inputs and outputs.
Before designing your monitoring system, it is important to understand the context of your connected place operations first. This will enable you to develop and capture requirements that need to be considered and developed into the design of the system. Within your monitoring design, you should include the visibility of:
Depending on your connected place, this could include data from traffic lights, streetlights, CCTV systems, parking sensors, pollution sensors, noise sensors, and other IoT devices that are part of your connected place infrastructure where these components produce security events or logs.
For more information, please refer to the NCSC's blog on What exactly should we be logging?


