Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 19 of 19

#14 Managing incidents and planning your response and recovery

Inevitably security incidents will occur and in the context of connected places, this could result in degradation or loss of critical public services. It is therefore essential that thought is given to your incident management policies and procedures, and that you plan for recovery in the event of an incident effecting critical functions or services. Following on from Principle 10, you need to have a wide variety of methods for detecting incidents. This could include:

  • technical alerts from your monitoring architecture (such as connection attempts into your sensor zones)
  • encouraging staff to report suspicious activity (such as phishing emails or social engineering attempts)
  • third parties such as partners, suppliers, private companies or the public performing incident investigations and threat research

To effectively manage incidents to your connected place, you need to be well prepared; you may experience a security incident sometime in the future. To do this, you need an incident management plan that will oversee the incident, communicate with necessary parties, engage support (such as the NCSC incident management service), report discoveries of the incident to the necessary parties, and notify them throughout an incident. Effective incident management will pull the whole response together, including dealing with any communications, media handling, escalations, and any reporting issues.

You should follow the NCSC's Incident Management guidance to help develop your connected place incident management and response plans. This includes:

Published

Reviewed

Version

1.0