Guidance
Connected Places Cyber Security Principles
Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 12 of 19
Connected places rely on the collection and processing of huge amounts of data. Taking a data-driven approach to governing and operating a connected place can bring significant benefits in terms of efficiency and improvements to the quality of life of citizens.
However, the storage and transportation of data are not without risk; where there is potentially sensitive bulk data there will be threat of attack or accident. Your connected place system design should not cache unnecessary data. These data stores are likely to be less well protected than the primary data store, but can potentially yield high-value or sensitive information to an attacker. Care should be taken to protect data at rest and in transit, with a primary focus on resilience of services and the privacy of the citizen.
You should make sure that you understand:
You should also understand your responsibilities in the event of a data breach, and have procedures in place to handle such an event. This needs to include managing your data in high trust zones by moving it as far away as possible from the untrusted edge quickly. The Information Commissioners Office (ICO) and the NCSC have issued guidance on data protection that:


