Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 11 of 19

#7 Designing your connected place to reduce exposure

You need to ensure your connected place interfaces are only exposed where necessary, to reduce the attack surface. This needs to include:

  • implementing firewall rules which deny everything except for agreed critical network services where appropriate (especially where services communicate with each other)
  • removing default configurations for sensors and other information gathering systems (such as default passwords)
  • switching off unused or unnecessary services and closing ports
  • isolating management interfaces, and constraining who can connect to the system (and from where)
  • integrating products that are well supported and have the right security characteristics you require within your connected place to give you confidence
  • ensuring all code is securely developed (whether this is in house or from your suppliers); all software builds and pipelines need to be secured (regardless of who runs them), you can use our Defending software build pipelines from malicious attack guidance to support this
  • where you are building and developing code yourselves, you need to design your code to restrict functionality to only allow those necessary for the service to operate
  • using software products that are well supported including up-to-date and regularly patched software; do they have the right level of security that gives you confidence when used in your connected place?
  • ensuring how and if the software protects your data in transit, protects your user accounts, and whether it provides logging and auditing
  • ensuring all software does not run using administrator rights, and adopts 'least privilege' access control rights
  • only allowing users limited data views of the system (and its data) by adopting access controls for 'least privilege' and on a 'need to know' basis by focusing on that user's job role
  • controlling data behind demilitarized zones (DMZs) to stop an attacker from interacting with higher trust zones if it was compromised (where cross-border interactivity is unavoidable within your connected place architecture, strong authentication mechanisms need to be in place to control access to these areas that are exposed)

Published

Reviewed

Version

1.0