Guidance
Connected Places Cyber Security Principles
Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 6 of 19
Your connected place cyber security needs to be owned, governed and promoted at the top level of the organisation that is responsible for the risk structure for both service resilience and user privacy. This accountability cannot be outsourced to suppliers. Essential tasks such as short and long-term planning need to be facilitated to support the local area and its citizens.
Over time, the services and functions of the connected place will become embedded within the everyday lives of its citizens. Therefore, you need to ensure that the connected place has the resources and funding available for its upkeep such as operational security, and improving future services in line with technological advances. This also needs to include security considerations behind the development, upgrading, and improvement of the technology to be able to deal with evolving threats and new capabilities. Tasks you need to think about incorporating into your governance process include investing in risk management and trusting your decision makers. As part of this, you should:
You also need to consider what skills and training are required. This needs to be incorporated into your planning for your connected place, which needs to include:
For more information, please refer to the NCSC's guidance on Security Governance, enabling risk management decisions & communication.


