Secure design principles
Pages
Page 3 of 17
1. Establish the context before designing a system
1.1 Understand what the system is for, what is needed to operate it, and which risks are acceptable
It is essential to have a clear understanding of the purpose of any system. You need to know which data, connections, people, and other systems will be required for it to operate.
You should determine what impacts you are not willing to accept.
Examples might include:
- unauthorised access to view, modify or destroy data, or the system being unavailable to users for a period of time
- a significant fraud being conducted
- the safety protections of an industrial control system being undermined
Explore examples from other organisations where things have gone wrong, and play out what this would mean in your own context. Feed this in to your risk analysis.
To inform your design decisions, you will also need to know which risks are acceptable. Document the risks you are willing to take and ensure that all people involved in designing the system are familiar with them, so they can make well-informed decisions.
1.2 Understand the threat model for your system
Consider employing threat modelling techniques such as attack trees to help you discover the ways in which an attacker could realise their goals. Your design should also consider what level of capability an attacker would need to be successful, and whether your aim is to defend, detect, or recover, along with any useful time bounded goals.
For example, a common level is to be able to defend against publicly known tools and techniques, detect attempted attacks using them, be able to recover within a given time frame from a worst case scenario successful attack such as loss of all data.
Once you understand these items you can map security controls to those attacks to gain confidence that you should be appropriately resilient.
1.3 Understand the role of suppliers in establishing and maintaining system security
The suppliers you choose to build and operate your system play a vital role in helping to keep it secure. It's important that all parties understand their responsibilities.
Contracts with suppliers should make your security requirements clear, but being over-prescriptive can lead to adversarial behaviour. It’s better to build a shared risk proposition with suppliers, so they are invested in doing the right thing, rather than just fulfilling a contractual obligation.
See also
The NCSC's Supply chain security guidance is designed to help you establish an effective regime of control and oversight, for your suppliers.
1.4 Understand the system 'end-to-end'
You should understand the critical information and/or communication flows that your system relies on for operation. Take account of every possible point at which data could be stored, manipulated or rendered.
The following areas are often overlooked:
- 1
Devices used to access data
If data is displayed or processed on a device it should be assumed that the data is present on that device. Any data a user can access could be available to malware on the user’s device.
- 2
Third-party services
Outsourced support suppliers, hosting providers and the management environments of system integrators are often put out of scope when considering the security of a system. Avoid making this mistake, since an attacker with access to one of these environments could attempt to gain access to your system.
- 3
Network-security devices
Web-browsing proxies and other network-monitoring devices typically used in corporate environments may decrypt traffic between your system and its users. These devices may have access to large volumes of sensitive data and could be exploited by attackers.
- 4
Copies of your data
Consider copies of data stored in audit logs and monitoring tools, or copies that have been exported into business intelligence or management information tools.
- 5
Communications over insecure networks
If your system communicates over channels which are not physically secure, your design will need to incorporate technical controls to provide an appropriate level of confidentiality and integrity.
- 6
Appropriate security for every iteration of your system
During the design process, you may create separate iterations of your system for different purposes, such as development, testing and production.
The impact of compromise associated with these environments is likely to vary at different phases of the system life-cycle and should be carefully considered.
This is particularly relevant for complex industrial projects and cyber-physical systems, where a large number of different components are integrated to form a complete system.
1.5 Be clear about how you govern security risks
Good governance implies effective control over your systems and operations security, not blind adherence to pre-determined processes.
Where design decisions require you to balance security, usability and cost, it’s important to talk about any trade-offs in terms of their business impact, rather than relying on technical language.
Consider the cost of not doing something just as much as the cost of doing it. Keep in mind that these costs could include fines under GDPR or NIS legislation, as well as business cost and reputational damage.
Our guidance on governance and risk management may help you decide on suitable governance arrangements for your system.
1.6 Ensure there is no ambiguity about responsibilities
Everyone involved in designing and operating a system should be suitably qualified or experienced, know what their role is, and know what decisions they are empowered to make.
Ensure that the right people are empowered to protect critical systems and accept that this could mean giving relatively junior people the ability to affect business operations. This could extend to deliberately reducing functionality or service levels in response to external events - without reference to senior management.
You should adopt a continual development approach to skills and training. This will ensure that gaps in your capabilities are identified, logged and mitigated. Where appropriate expertise is not available, the associated risk should be escalated and managed as part of your organisation's risk management system.


