Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 6 of 19

#3 Understanding cyber security governance and skills

Your connected place cyber security needs to be owned, governed and promoted at the top level of the organisation that is responsible for the risk structure for both service resilience and user privacy. This accountability cannot be outsourced to suppliers. Essential tasks such as short and long-term planning need to be facilitated to support the local area and its citizens.

Over time, the services and functions of the connected place will become embedded within the everyday lives of its citizens. Therefore, you need to ensure that the connected place has the resources and funding available for its upkeep such as operational security, and improving future services in line with technological advances. This also needs to include security considerations behind the development, upgrading, and improvement of the technology to be able to deal with evolving threats and new capabilities. Tasks you need to think about incorporating into your governance process include investing in risk management and trusting your decision makers. As part of this, you should:

  • make your connected place business goals and priorities clear
  • identify assets that your connected place needs to achieve its business goals
  • identify who within their organisation is responsible (and accountable) for the security of your connected systems
  • identify who within their organisation is responsible (and accountable) for the ongoing security of your connected systems throughout the whole system life cycle
  • understand and accept your connected place's inherent risks in delivering its services
  • make sure the decision makers within your connected place have the right security, business and technical knowledge to enable them to make effective and timely risk management decisions

You also need to consider what skills and training are required. This needs to be incorporated into your planning for your connected place, which needs to include:

  • Providing your staff with the right skills and opportunities to learn, so they can manage the security of your connected place effectively. This cannot be a single training opportunity where staff return to their daily roles once it has been completed. This needs to be an ongoing programme that aligns staff development with the evolution of your connected place and its surrounding technology. This will enable your staff to keep up to date with your connected place and be able to manage it more effectively.
  • Building trust and being transparent with your citizens to maximise engagement with your connected place. This needs to include helping them to understand why there is a connected place, the role they have within it, and what data the connected place requires to function, whilst being transparent in providing assurance as to what data is being collected, and how you intend to use, store, and protect any data. This will help in building trust by clearly educating citizens, which will help encourage overall participation in the connected place.

For more information, please refer to the NCSC's guidance on Security Governance, enabling risk management decisions & communication.

Published

Reviewed

Version

1.0