Skip to main content
Guidance

Secure system administration

Design principles for IT and OT systems to help you develop and implement your own system management strategy to protect your most sensitive data.

Page 2 of 6

Gain trust in your management devices

The devices you use to access your system administration interfaces must be trustworthy.

Management devices

These are the devices that you use to perform system administration. They come in all shapes and sizes: laptops, desktops, phones and tablets.

We care about the security of management devices because they are used to access our administration interfaces. If an attacker compromises one of these devices, they could inherit the same level of access. This could lead to your service being disrupted or your data being stolen.

You may use a physical device and jump box to administer your system. In the context of this guidance, both of these are considered management devices. For more information on jump boxes please see 2 - Protect your administration interfaces.

Privileged Access Workstations (PAWs)

Dedicated management devices are often referred to as privileged access workstations (PAWs). It is quite common to use these when administering higher tier services. See 3 - Risk manage administration using tiers for more information.

If you are allowing a device to connect to your administration interfaces, you should to be able to trust it. This makes it less likely that an attacker will be able to use the device to access your systems, instead of a legitimate system administrator. See 2 - Protect your administration interfaces.

If your administration access could be considered high risk for your organisation, with significant impact if it is compromised, you should review the NCSC PAW principles and follow the guidance there.






Reviewed

Version

1.1