Guidance
Secure design principles
Guides for the design of cyber secure systems
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 13 of 17
This principle builds on Reducing the impact of compromise, from the Cyber security design principles
Virtualisation provides functionality which can help you recover from compromise quickly.
For example, your virtualisation platform can consist of multiple nodes to make a cluster, virtualised systems can then be replicated to multiple nodes, providing a quick recovery option should a node in your infrastructure become unavailable.
Having a backup of your system in a known good state could also be beneficial when recovering from a compromise. This can be achieved using snapshots or separate reference platforms. Ensure that these backups represent the latest iteration of your system and are continually patched.
Design systems which can gracefully degrade functionality, delivering a minimal set of services, in the event of an incident which prevents you from maintaining full functionality.
In a situation where the full feature set of a system can’t be delivered, perhaps due to cyber attack or even natural disaster,use the flexibility of virtualisation to respond quickly to any degradation in service.
For example, virtualisation can provide a means to quickly spin up systems in a good known state or perhaps networking can be quickly reconfigured to direct users to a failover system.


