Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 12 of 15
How to gain and maintain assurance

How to gain and maintain assurance for your risk treatments
Assurance is a means of providing confidence that security controls are working in the way you expect to ensure the security of the system. Assurance should be continually sought from the controls (whether these are procedural, personnel, physical or technical) you apply to treat cyber security risks. Gaining this confidence in your risk treatments - through the effective use of assurance activities - is therefore essential for managing cyber risks.
It is useful to note that many assurance activities are only able to provide a snapshot of the performance of a security control or measures at a particular period in time. Gaining and maintaining confidence in your risk treatments should be a continuous activity throughout the life cycle of the system or service, responding to changes in threats, vulnerabilities, technologies and business use.
The assurance model presented here is intended to describe the different activities needed to gain and maintain assurance in your cyber security risk treatments. These activities need to be considered and applied in the context of what your organisation does, what it cares about, and the cyber security risks it faces. Where risk treatments are being applied using technology products or services, then this model can be used in conjunction with our technology assurance guidance and our blog here to help you think about, plan for and apply assurance activities to provide decision makers with the confidence they need that a system (or service) is 'secure enough'.
An assurance model
The following model identifies four broadly-scoped assurance mechanisms which, if used appropriately, can provide the confidence required by the business that your risk treatments are both appropriate and effective. These mechanisms are:
- intrinsic assurance
- extrinsic assurance
- implementation assurance
- operational assurance
A key aspect of this model is that each mechanism is interlinked, and all of them will be needed to provide your business with the confidence required. This is illustrated in the following diagram which shows how all four assurance mechanisms contribute to the overall assurance of a system or service, and provides some example assurance activities. Note these are for illustrative purposes only and do not present a complete list of activities that an organisation could use to provide them with the confidence and assurance they need in the technology systems and services they use.
This is any activity which provides confidence in the process applied by the supplier during the development of the product, service or system. Examples of intrinsic assurance include:
- establishing your supplier’s reputation for delivering, and where appropriate, maintaining the integrity of its products (for example, using secure design and development practices, quickly rectifying security vulnerabilities by regularly releasing patches)
- application of principles based assurance outcomes in a product or service
- the practices a supplier or vendor uses to design and develop its product or service
- the way a supplier or vendor manages vulnerabilities in its product or service
This is any activity independent of the development environment which provides a level of trust in the product or service. For example, ensuring the product or service goes through a recognised, independent evaluation scheme which is appropriate to its function and anticipated use.
Note that:
- extrinsic assurance alone provides little or no security without the other mechanisms
Examples include:
determining if your supplier and its supply chain have any form of appropriate independent certification (such as Cyber Essentials or Cyber Essentials Plus, or an appropriately scoped ISO 9001 and/or 27001 certification)
a formal evaluation of a product or service such as FIPS-140, Common Criteria, etc. Note: such evaluation is becoming increasingly niche, and will not be appropriate for the vast majority of commercial products or services (this is not a problem, as the other mechanisms in the model can compensate for any lack of extrinsic assurance).
This is any activity which provides confidence that the product, system or service has been correctly implemented. Examples of such assurance activities might include:
- subjecting the product, system or service to a review by appropriately qualified personnel to ensure that the design and implementation delivers the risk management benefits required by the business
- security testing the system (again by appropriately qualified personnel) to determine if any vulnerabilities were introduced as a result of the deployment
- avoiding well known security anti-patterns
This is any activity necessary to maintain the product, system or service’s security functionality once it has entered operational use. This includes provision for enterprise activities that will monitor changes in vulnerability and threat.
Examples of operational assurance activities might include:
- monitoring for the emergence of any new vulnerabilities concerning the product, system or service
- applying patches to address known security vulnerabilities where they are available
- training relevant personnel in how to monitor for and safely apply security patches
- testing whether security patches or updates have been applied and whether these have addressed the vulnerability
- ensuring any vulnerable devices that cannot be patched are effectively defended in depth by the system security architecture and compensating measures as necessary
Using this model
The model should be used with care, especially as it is primarily designed for use with enterprise IT systems where the business owner has full control of the system and its cyber security. How you use the model will depend on your context and system. For example, with operational technology (OT) systems there are fewer options for all 4 types of assurance mechanisms especially around extrinsic assurance, and you may need different strategies for gaining confidence in your risk treatments.
When using cloud services, you need to understand what confidence can be gained from the service provider. The assurance mechanisms need to be used in a complementary manner, and some (such as extrinsic assurance) may not be available. In addition, the operational assurance mechanisms will require ongoing activities (such as security monitoring and software updates and patching), with regular supporting implementation and extrinsic assurance through IT health checks and active vulnerability testing.
Assurance example 1: using a certified product
The use of a certified product such as a FIPS 140-3 encryption device (through which you have extrinsic assurance) from a long established vendor in the market place (providing intrinsic assurance) may still pose risks. These risks will occur if the device is not configured properly within a sensible security tested security architecture (providing implementation assurance). And, despite its formal assessment, the product will likely require software updates through its lifecycle, due to ongoing active vulnerability testing of the product (providing further extrinsic assurance). These software updates will need to be installed quickly and (of course) the device will need to be monitored for security alerts (providing operational assurance).
Failure of any one of these assurance mechanisms will mean that the device - despite having undergone a FIPS 140-3 certification - will not be providing the security that the business requires and expects it to provide, and indeed will provide a false level of confidence.
Assurance example 2: using a cloud service
Whilst public cloud services (IaaS, PaaS, SaaS or FaaS) may go through a formal independent certification (providing extrinsic assurance), intrinsic assurance can also be gained by the way in which the cloud provider meets the NCSC Cloud Security Principles, and some of the bigger cloud providers (such as Microsoft, Google and Amazon have done so publicly). Other smaller providers can be assessed against SaaS Security Principles.
Beyond certification, some extrinsic assurance is trickier as cloud providers generally do not allow you to externally security test their services, but this doesn't mean that you shouldn't security test your use of the services, and whether through this you can confirm you are meeting your obligations under any shared responsibility model. Through this, you can gain implementation assurance by ensuring your use of cloud services is implemented correctly and that effective security monitoring is in place for your use of the cloud to provide operational assurance.
It is important to note that if you fail to correctly implement the cloud services you are responsible for configuring, to monitor your usage of those services, and to react to any security alerts, you will not provide the confidence required despite the cloud service provider meeting the NCSC Cloud Security Principles or any other known to be good guidance or cloud security standard.


