Skip to main content
Guidance

Secure system administration

Design principles for IT and OT systems to help you develop and implement your own system management strategy to protect your most sensitive data.

Page 1 of 6

close up of a chessboard and the white king has been knocked over accepting defeat

System management is a fundamental component of any system. Poor design in this area could have any number of serious side effects - from allowing an employee to make a damaging mistake, to permitting an attacker to gain unrestricted access to your most sensitive data.

Having a strategy in place will help your organisation protect these high value systems. This guidance will help you develop and implement your own secure system administration strategy, based on five design principles.

These principles can be applied to both Information Technology (IT) and Operational Technology (OT) systems. IT systems are those that typically handle data, the way it moves around and is stored. OT systems are typically used to manage physical processes and machinery.

Audience

This guidance has been written to address a wide audience. However, it is expected that system designers, risk owners and people in system administration roles will benefit most. This is because they are responsible for the design, development, deployment and operation of a secure system.

More specifically, this guidance should be beneficial to systems where there is a need for remote management of system components.

Budget holders may also find that this guidance serves to highlight the importance of secure system administration when financial decisions are being made.

Additionally, if you outsource your IT support, this guidance may help you gain an understanding of what to look for when assessing potential solutions and suppliers.

Administrators and Administration

Before considering your current system administration practices, it’s important to clarify the terms administrator and administration.

A system administrator is the person or process responsible for carrying out functions which support the deployment or operation of a system.

This could mean an individual whose job title is 'database administrator.' Alternatively, it could be a system account that is responsible for running a scheduled task periodically. The commonality here, is that they carry out functions that a normal user would not. To do this, they have a higher level of permissions on the system.

System administration refers to the acts carried out by administrators. Again, this has a wide definition and could include:

  • using SSH to access a web server to update a file
  • adding a new user to a domain
  • configuring an alarm on a physical valve in an OT environment

The commonality here, is that all of these functions could be used for malicious purposes and so they need to be appropriately protected.

Maintaining your management systems

Administrators don't have to be members of your staff. It's common for system administration to be carried out by a third party supplier. So, this guidance will apply to anyone who has access to your administration interfaces.

You will also need to consider how you maintain any management system that you put in place. At some point, someone, somewhere will have absolute control over your system. It's important that you have considered this and put an appropriate process in place for this access.


Published

Reviewed

Version

1.1