Guidance
Connected Places Cyber Security Principles
Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 18 of 19
Throughout your connected place system's life cycle, its security and technology requirements will evolve. This requires a sustainable engineering approach to continuously develop its underpinning infrastructure for security purposes. There should also be consideration of any evolving interoperability requirements to enable continued development of the connected place's services. This needs to include maintaining your operational security by fixing bugs or dealing with functionality issues as technology evolves. Alongside this, assets need to be reviewed and monitored constantly, which will help to identify end of life/legacy components.
This needs to include:
You need to understand the impact of the components to your connected place, and that you have effective assurance in place that components are still meeting the required security levels needed to protect the system. You can do this by testing your system throughout its life cycle. This can be done through health checks, penetration testing, and continual review of risks and procedures. If you identify that the level of security has dropped below the required levels, appropriate mitigations need to be in place to reduce any risks in the short term. For the long-term support of the connected place system, you should be making arrangements to replace these legacy components as soon as possible.


