Guidance
Secure design principles
Guides for the design of cyber secure systems
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 12 of 17
This principle builds on Making compromise detection easier, from the Cyber security design principles
Design your system so that it's easy to audit. You should be able to answer the question, "What is running, where, and which systems can it access?"
Uncontrolled use of virtualisation can quickly get out of hand, leading to a situation where you have little or no oversight of the systems running on your platform.
Your development workflow should include a process for setting up and documenting new virtualised systems. This is particularly important when deploying production systems which are critical to your organisation.
In a physical environment, keeping track of equipment and "shadow IT" can be difficult. Using virtualisation can compound this problem by enabling quick and easy creation of virtual systems, which may not be secured correctly, or simply forgotten about. This is particularly true in rapid release development cycles where the focus is on the next delivery, rather than cleaning up the last iteration.
Virtualisation can actually make auditing and monitoring easier. Since virtualisation platforms are managed from a central point, it's possible to design the management infrastructure so that it can query virtualised system at each layer of the stack.
Use the flexible nature of virtualisation to insert monitoring capabilities into each layer of the virtualisation platform, reporting back to a central location.


