Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 13 of 25

Principle B4 System security

iStock.com/Hasan As Ari

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.




System design

A secure by design approach should be taken to ensure that effective cyber security practices are incorporated into system design. You should design the systems and networks operating or supporting the operation of essential functions to make compromise difficult, avoid disruption and reduce the impact of compromise. Where the design also makes compromise easy to detect, this will help achieve effective monitoring. 

Stronger security architectures usually include:

  • the most critical services and systems segregated into a higher security zone. This corresponds with the concept of zones and conduits described in the IEC 62443 reference model.

  • at boundaries with higher security zones where it’s necessary to import and trust data from a lower security zone, where possible.

  • in a DMZ convert the data into the simplest appropriate alternate protocol, to create a “break” that makes protocol-based attacks more difficult.

  • perform validation of both message format and content.

  • where messaging received from outside the organisation is used to control the essential function (e.g. customer or supplier system messages or critical telemetry), prefer a simple messaging format that can be validated and authenticated, or consider additional monitoring.

  • reducing the attack surface by limiting software, network data flows, system access, etc. to only those essential and necessary.

  • secured platform by default, with a system design that enables application of system updates without interrupting business, wherever possible.

  • a separate management layer, preferably using dedicated equipment and a separate network.

Configuration

Well-configured networks and information systems reduce unauthorised access to technologies and simplify security management across hardware, firmware, software and configuration data. This should include:

  • A baseline build (also known as a “gold build”) is recommended to apply a well-understood, consistent and secured platform across the organisation, and can also apply system hardening techniques to minimise the attack surface. Gold build images should be appropriately protected from interference and be available for use in the event of system recovery.

  • Configuration management policies or software should be used to ensure that only permitted software is installed and authorised devices, e.g. mobile devices and removable media, are permitted to connect. An asset management inventory could be used to manage authorised devices.

  • In addition to the gold build and permitted software installed, maintain a record of the current “known good” configuration (including, for example, patch levels, OT ladder logic) and the resources, such as patch and configuration files, required to create this environment. It should be possible to revert or rebuild to this known good baseline.

  • Systems, software or devices that are not actively supported by the developers should be identified, with appropriate additional security measures in place until they can be retired and removed.

  • Users should not be able to change settings affecting the security of the service.

  • Network devices should be configured to limit access to the minimum required for business operation. It may also be possible to apply standardised network device builds.

Some organisations responsible for essential functions may use automated decision making technologies, for example safety systems or machine learning in smart transport technologies. Where such automated decision making has the ability to affect an essential function, it must be possible to understand the data, process and thresholds used to make automated decisions so that it can be reproduced, audited and malicious changes detected.

  • For decisions based on pre-determined, unchanging behaviour this would entail knowing the exact hardware, firmware, software, and configuration of individual systems (this may be achieved with detailed configuration and asset management) and monitoring for any unplanned changes.

  • Where systems use some element of machine learning and the decision making process changes over time. The model used should be auditable, so that malicious changes can be detected. This should identify cases where changes have been made directly, or where malicious or misleading data has been used for learning.

System management

Routine system management should support and maintain security. Technical documentation of the networks and information systems should be up to date. 

Access to the essential function’s facilities and systems should be managed and monitored to restrict to authorised personnel, in line with guidance in B2 Identity and Access Control. 

As described in B2 Identity and Access Control Privileged User Management, technical means for access should separate essential functions from other activities, for example using dedicated separate systems or sandboxed email and Internet access. 

Further protection from physical interference can be afforded through tamper protection, such as port locks and tamper evident tape. Such physical tamper protections should be regularly checked.

Vulnerability management

Flaws, features and user errors that impact the security of the essential function may be known to the organisation, or not yet discovered. System design, configuration and system management can reduce the likelihood of a vulnerability being accessed or exploited. New vulnerabilities need to be managed to maintain network and system security. 

Effective risk management should ensure that appropriate measures are taken to maintain awareness of and address known vulnerabilities. The organisation endeavours to detect when changes to internally managed settings and configurations introduce vulnerabilities. 

The latest mitigated vulnerabilities are often published by vendors, some providing automatic update functionality. Other vulnerabilities can be discovered through threat intelligence sources. 

You should prevent the exploitation of known vulnerabilities in networks and information systems supporting essential functions. Many of the most effective methods are well-known, including: 

  • removing vulnerabilities by maintaining systems to the latest patch level and only applying authentic, vendor-sourced and validated updates.

  • removing access to vulnerabilities by segregation, or ensuring the vulnerable system only receives trusted data.

  • verification of imported data and software. Where possible this should be automatic.

  • regular vulnerability and security assessments, e.g. penetration tests and vulnerability scans. NCSC guidance on penetration testing provides further detail. Operators should carefully consider their approach to the testing of live Operational Technology, as system operation or availability could be affected. Assurance could be gained without this additional risk by testing against non-operational environments or by testing individual components in a laboratory environment.

  • software that the essential function relies upon should be in active support, so vulnerabilities will be patched. You should provide additional protection where obsolete platforms cannot be easily replaced.

B4.a Secure by Design

You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems. 

Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).

Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.

Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).

You employ appropriate expertise to design network and information systems supporting your essential function(s).

You design strong boundary defences where your network and information systems interface with other organisations or the world at large.

You design simple data flows between your network and information systems and any external interface to enable effective monitoring.

You design to make network and information system recovery simple.

All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.

 

You employ appropriate expertise to design network and information systems supporting your essential function(s).

Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).

The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.

The network and information systems supporting your essential function(s) are designed to be easy to recover.

Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).

If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).

B4.b Secure Configuration

You securely configure network and information systems that support the operation of your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).

Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).

Configuration details are not recorded or lack enough information to be able to rebuild the system or device.

The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.

Generic, shared, default name and built-in accounts have not been removed or disabled.

Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).

You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).

Secure platform and device builds are used across the estate.

Consistent, secure and minimal system and device configurations are applied across the same types of environment.

Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.

You verify software before installation is permitted.

Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.

Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).

You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).

All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.

You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.

You regularly review and validate that your network and information systems have the expected, secure settings and configuration.

Only permitted software can be installed.

If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.

Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.

B4.c Secure Management

You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed. 

You do not have good or current technical documentation of your network and information systems.

Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.

Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.

You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.

Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.

You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.

You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.

B4.d Vulnerability Management 

You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.

You do not mitigate externally exposed vulnerabilities promptly.

You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).

You have not suitably mitigated systems or software that is no longer supported.

You are not pursuing replacement for unsupported systems or software.

You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.

Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly. 

Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.

You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.

You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).

You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.

Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly. 

You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.

You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).


Published

Reviewed

Version

4.0