MyNCSC Help Centre
Pages
Page 4 of 22
Asset guidance
This page explains how “assets” are defined in the MyNCSC platform and how to enter them correctly when adding them to your organisation record.
MyNCSC works by using your assets to check for cyber security issues. It accepts three types of asset; domains, URLs and IP addresses.
- A domain is a human-friendly name of a resource on the internet. You can add domains or sub-domains as assets. For example, domain.gov.uk or sub.domain.gov.uk
- A URL is a complete address of a web page on the internet and must begin with a protocol. For example, https://domain.gov.uk/home
- An IP address is a unique identifier for a device on the internet. For example, 192.0.2.1 or 2001:db8:0:1234:0:567:8:1
When you add an asset to your organisation, MyNCSC determines the asset type automatically, so you should ensure that they are in the correct format, so they are correctly categorised. For the MyNCSC services which you can currently add assets to:
- Both the Vulnerability Monitoring Service (VMS) and DNS Check only work with domains. You cannot subscribe URLs or IP addresses.
- Early Warning will accept domains and IP (v4 and v6) addresses. IPs must be static IPs, not dynamic. You cannot subscribe URLs.
You will only be able to add assets to those services which your organisation is eligible to use.
You must only add assets if your organisation has authority to subscribe them to MyNCSC's services. Typically, this will mean that your organisation owns the assets, but other forms of authority may apply such as your organisation being contracted to manage the assets on the owner’s behalf.
Asset types
Domains
A domain comprises a set of labels separated by dots. Each label represents a domain and the order of the labels indicates the hierarchy of the domains, with the highest level on the right.
Using http://ncsc.gov.uk as an example, .uk is a top-level domain, gov is a sub-domain of .uk, and ncsc is a sub-domain of .gov.uk.
All sub-domains are by definition also domains in their own right.
When you add domains to your asset portfolio, we recommend that you include all domains and sub-domains operated by the organisation.
Example of correct format when adding a domain to MyNCSC:
- ncsc.gov.uk
Note: You should add domains without prefixes such as “www”, unless there is a specific need to do so. See the “Subscribing to ACD services” section below for more information.
URLs
A URL is a complete address for a page on the internet. URLs are required to include a scheme followed by a path, where the path is a set of segments separated by the /
Using //home as an example, the scheme is https and the path is http://ncsc.gov.uk/home.
Examples of correct formats when adding a URL to MyNCSC:
- //home
- //section/products-services/active-cyber-defence
Note: If you add a URL to your asset portfolio it must contain a scheme and path. These are mandatory and if you do not include them MyNCSC will not recognise it as a URL.
IP addresses
There are two types of IP addresses:
- IPv4 - these addresses consist of for decimal numbers, each ranging from 0 to 255, separated by . for example, 192.0.2.1
- IPv6 - these addresses consist of eight 16-bit hexadecimal values, separated by colons. For example, 2001:db8:0:1234:0:567:8:1
For both IPv4 and IPv6, in addition to the option to add IPs as single addresses, assets may be specified as IP ranges or CIDR blocks.
Where there are a number of IPs to be added please be aware of the following points:
- It will often be the easiest to add assets in whichever format you already have them listed. An option exists to bulk upload from a CSV file.
- Whether entered manually or in bulk via a CSV file, each single IP address will be held in MyNCSC as a separate asset. For a contiguous set of IPs, this will result in more assets than would be in the case of using an IP range or CIDR block. When viewing assets however, filtering and search options are available.
- MyNCSC will not currently allow you to edit the address(es) of an asset. Should you subsequently need to amend an IP range or CIDR block, it would be necessary to replace the existing asset with a new one.
When you add IPs to your asset portfolio, we recommend that you include all IPs operated by the organisation.
Examples of correct formats when adding an IP address to MyNCSC:
IPv4:
- Single address e.g 192.0.2.0
- IP range. This is a bundle of consecutive IP addresses. e.g 192.0.2.0-192.0.2.255
- CIDR Block. This is a notation for describing blocks of IP addresses and is used in various network configurations. e.g 192.0.2.1/24
IPv6:
- Single address e.g 2001:db8:3333:4444:5555:6666:7777:8888
- IP range. This is a bundle of consecutive IP addresses. e.g 2001:db8::0:1-2001:db8::1:1
- CIDR Block. This is a notation for describing blocks of IP addresses and is used in various network configurations. e.g 2001:db8::/32
Subscribing assets to ACD services
You can subscribe assets to the following services. We generally recommend that you add all IP addresses (if using Early Warning), domains and sub-domains for your organisation into your asset portfolio.
DNS Check
DNS Check only works for domains. You cannot subscribe URLs or IP addresses to DNS Check.
Please note:
We recommend that in most cases you only subscribe domains, as the scan results are usually identical to those performed against URLs. Results may differ where the URL points to a resource which is hosted on a separate platform, and/or is implemented by a different set of technologies.
You should not add prefixes, such as “www”, to your domain(s) unless there is a specific need to do so. For example:
- when only the domain address with the prefix points to a page
- when two addresses - with and without the prefix - point to different pages
If you add a URL to your asset portfolio it must contain a scheme and path. These are mandatory components and if they are missing MyNCSC will not recognise it as a URL.
Early Warning
Both IP addresses and domains can be subscribed to Early Warning. IP addresses must be static, not dynamic. You cannot subscribe URLs to Early Warning.
Asset Discovery
The MyNCSC Asset Discovery feature searches a range of online data sources to identify relevant assets not currently registered by your organisation in MyNCSC. The feature is currently discovers sub-domains, root domains and IP ranges. Asset Discovery is useful in the following ways:
- It helps you identify 'shadow' or 'legacy' IT that is not formally monitored centrally or needs decommissioning. This is relevant to all users of MyNCSC.
- Ensuring all your relevant IT estate is registered and monitored using the MyNCSC services.
Further details can be found when clicking on ‘About Asset Discovery’ on your organisation’s ‘Discovered assets’ tab.