Operational Technology
Pages
Page 32 of 37
Principle 4. Secure firmware controls
Management of firmware updates on all devices should also be implemented.
Management and reconfiguration of the device over-the-air (OTA) can improve the secure posture of a radio network by enabling patching of vulnerabilities and configuration management but without suitable security controls may introduce additional risks.
Ensure that OTA management and reconfiguration commands are cryptographically authenticated.
Ensure that only authorised firmware is accepted by RF devices, for example through the use of cryptographically signed firmware images. Please refer to the NCSC’s guidance on Managing device firmware for more information.
Where possible, use a separate communications channel for critical configuration tasks. If remote configuration is enabled, we recommended you implement secure communications methods (such as IPsec or other standards-based encrypted protocol). For more information, please refer to the NCSC’s Secure communications principles.
Availability of the network should not be impacted by remote configuration or OTA firmware updates. Ensure that processes and technology safeguards prevent these features affecting availability.