Skip to main content
Guidance

MyNCSC Help Centre

Page 4 of 22

Asset guidance

This page explains how “assets” are defined in the MyNCSC platform and how to enter them correctly when adding them to your organisation record.

MyNCSC works by using your assets to check for cyber security issues. It accepts three types of asset; domains, URLs and IP addresses.
 

  • A domain is a human-friendly name of a resource on the internet. You can add domains or sub-domains as assets. For example, domain.gov.uk or sub.domain.gov.uk
  • A URL is a complete address of a web page on the internet and must begin with a protocol. For example, https://domain.gov.uk/home
  • An IP address is a unique identifier for a device on the internet. For example, 192.0.2.1 or 2001:db8:0:1234:0:567:8:1

When you add an asset to your organisation, MyNCSC determines the asset type automatically, so you should ensure that they are in the correct format, so they are correctly categorised. For the MyNCSC services which you can currently add assets to:

  • Both the Vulnerability Monitoring Service (VMS) and DNS Check only work with domains. You cannot subscribe URLs or IP addresses.
  • Early Warning will accept domains and IP (v4 and v6) addresses. IPs must be static IPs, not dynamic. You cannot subscribe URLs.

You will only be able to add assets to those services which your organisation is eligible to use.

You must only add assets if your organisation has authority to subscribe them to MyNCSC's services. Typically, this will mean that your organisation owns the assets, but other forms of authority may apply such as your organisation being contracted to manage the assets on the owner’s behalf.


URLs

A URL is a complete address for a page on the internet. URLs are required to include a scheme followed by a path, where the path is a set of segments separated by the /

Using //home as an example, the scheme is https and the path is http://ncsc.gov.uk/home.

  • Examples of correct formats when adding a URL to MyNCSC:

    • //home
    • //section/products-services/active-cyber-defence

    Note: If you add a URL to your asset portfolio it must contain a scheme and path. These are mandatory and if you do not include them MyNCSC will not recognise it as a URL.

IP addresses

There are two types of IP addresses:

  • IPv4 - these addresses consist of for decimal numbers, each ranging from 0 to 255, separated by . for example, 192.0.2.1
  • IPv6 - these addresses consist of eight 16-bit hexadecimal values, separated by colons. For example, 2001:db8:0:1234:0:567:8:1

For both IPv4 and IPv6, in addition to the option to add IPs as single addresses, assets may be specified as IP ranges or CIDR blocks.

Where there are a number of IPs to be added please be aware of the following points:

  • It will often be the easiest to add assets in whichever format you already have them listed. An option exists to bulk upload from a CSV file.
  • Whether entered manually or in bulk via a CSV file, each single IP address will be held in MyNCSC as a separate asset. For a contiguous set of IPs, this will result in more assets than would be in the case of using an IP range or CIDR block. When viewing assets however, filtering and search options are available.
  • MyNCSC will not currently allow you to edit the address(es) of an asset. Should you subsequently need to amend an IP range or CIDR block, it would be necessary to replace the existing asset with a new one.

When you add IPs to your asset portfolio, we recommend that you include all IPs operated by the organisation.

  • Examples of correct formats when adding an IP address to MyNCSC:

    IPv4:

    • Single address e.g 192.0.2.0
    • IP range. This is a bundle of consecutive IP addresses. e.g 192.0.2.0-192.0.2.255
    • CIDR Block. This is a notation for describing blocks of IP addresses and is used in various network configurations. e.g 192.0.2.1/24

    IPv6:

    • Single address e.g 2001:db8:3333:4444:5555:6666:7777:8888
    • IP range. This is a bundle of consecutive IP addresses. e.g 2001:db8::0:1-2001:db8::1:1
    • CIDR Block. This is a notation for describing blocks of IP addresses and is used in various network configurations. e.g 2001:db8::/32

Early Warning

Both IP addresses and domains can be subscribed to Early Warning. IP addresses must be static, not dynamic. You cannot subscribe URLs to Early Warning.


Published

Reviewed

Version

1.0