Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 16 of 19

#11 Managing your connected place's privileges

Within your connected place, there will be areas of your system that will have the means to perform privileged activities that are not available to a standard user. You need to consider how you are going to manage these privileged accesses securely to reduce the risk of these areas being compromised, as this could lead to an attacker gaining unrestricted access to your system. This level of access may provide an attacker a platform to access sensitive data, such as operational or citizens' data, or be able to disable or degrade a critical aspect of your connected place. Considerations should be taken for the security of the following.

Management devices

You must protect your management devices due to the access they have. If an attacker compromises one of these devices, they could inherit the same level of privileges that the device has access to, which may include accounts and services that manage the connected place. It can be tempting to perform management from the same devices from which email and web browsing are typically conducted, but this should be avoided as it provides the attackers an easy opportunity to inherit privileges that could negatively impact your connected place.

Due to the risks and opportunities for exploitation from these devices (such as spear-phishing), and the massive impact of a compromised privileged account, it is imperative that management functions of a connected place are conducted on devices that are regarded to be at a high-level of trust. You should use a dedicated Privileged Access Workstation, or PAW, in cases where the impact is critically damaging. This provides the opportunity to add additional controls and measures that can be applied to reduce the attack surface.

Management interfaces

You must protect your management interfaces due to the access they have. If an attacker compromises one of these interfaces, they could inherit the same level of privileges that the interface has access to, which may include accounts and services that manage the connected place. If the interface is exposed, attackers may try and brute force the password or use an exploit to gain access.

You should manage these risks based on where your interface is located, what can access it, and who the users are that need access to it. Users requiring access to your management interface need to be authenticated, and where possible, multi-factor authentication (MFA) should be enabled. Only permit authorised devices to access your management interfaces, use PAM and implement principles such as 'just in time' and 'just enough' privileged access.

Privileged accounts

You must carefully manage the accesses privileged accounts have. If an attacker compromises an account with privileged access as mentioned in any of the attack types above, they could misuse the privileges they have access to, such as reading citizen information or making unauthorised changes that could affect a service within your connected place. You need to determine what rights and privileges users need to perform their roles and implement the principal of least privilege. You need a robust joiners, movers, and leavers process for users, so they do not inherit privileges they do not need.

For more information, please refer to the NCSC's guidance on Secure system administration and Protecting system administration with PAM.

Published

Reviewed

Version

1.0