Skip to main content
Guidance

Device security principles for manufacturers

Principles to guide manufacturers in the design of secure, enterprise-connected devices.

Page 7 of 12

6. Permit only trusted software

If users can run untrusted software on a device, an organisation is likely to be exposed to malware threats such as ransomware. Depending on the device, both the manufacturer and the organisation need to have the capability to determine which software they trust. This software also includes the operating system and any software to support peripherals such as device drivers.

Mechanisms for determining and defining which software is trusted will often rely on cryptographic methods and by determining an allowed list of apps that users can install within a device management platform. Organisations may require different user roles to establish who is trusted to install and run software at different levels of trust.




Published

Reviewed

Version

2.1