Technology assurance
Pages
Page 8 of 35
Developing a new approach to assurance
The NCSC’s new approach to technology assurance is characterised by its focus on outcomes that demonstrably reduce cyber security risk in systems. These outcomes might include things like, ‘technology is protected against unauthorised access’, or ‘technology cannot silently default to operate insecurely’.
An outcome-based approach enables vendors to demonstrate evidence that they have achieved the desired outcomes in a diverse set of ways. This encourages innovation and expands the breadth of technologies we can assure.
Principles Based Assurance (PBA)
The base set of desirable outcomes are expressed in our Assurance Principles. These are the common set of questions we could ask about any technology. Encouraging a ‘systems first’ attitude, these foundational outcomes give us the name, Principles Based Assurance (PBA).
There will initially be three sets of principles:
-
Product Design and Functionality Principles
Describe the features a product needs to implement.
-
Product Development Principles
Describe how a product should be designed, implemented and tested.
-
Through-life Principles
Describe the security measures that need to happen beyond development.
Assurance in context
Assuring a given technology means interpreting these desirable security outcomes in light of the threats and risks faced by that technology, in its proposed use. For example, Wi-Fi routers in a domestic setting will require less stringent implementation of certain security protocols than those used in an Embassy.
This process uses a ‘risk-based’ approach to generate security requirements from a common technical foundation, managed by the NCSC.
The assurance principles will be published on our website, making them available for others to use as they assess the cyber security of a product for their own particular use case. They can also be used by vendors to demonstrate that they have met the security requirements.
The Principles will also be used by the NCSC, and its industry partners, in the delivery of proportionate and rigorous assurance activities for products and systems used in the UK with critical security requirements.
Deriving new principles
The NCSC will use our unique skills, perspective and insight to continue developing principles, and requirements derived from them, as needed.
The NCSC used this approach to support DCMS in the delivery of the Code of Practice for Consumer IoT Security. The same is true for the ‘High Grade Engineering Standard’.
Principles can be derived under three headings:
- technology-specific principles (e.g. Secure communications principles, security principles for cross-domain solutions),
- domain-specific principles (e.g. Design guidelines for high assurance products)
- application-specific principles (e.g. the Code of Practice for Consumer IoT Security, the forthcoming High Grade Engineering Standard).
These principles, as derivatives of the original set, will be consistent in structure and content; but adjusted to the context and people for which they will be used.
Developing a context
An understanding of context is an essential component of proportionate assurance and effective cyber risk management.
To understand context, we first ask, ‘what business aims are you looking to achieve?’ We next ask, ‘what systems do we need assurance in?’ For each technology, we can then determine, “how can this (technology) contribute to the cyber security of that system?”
This contrasts with the previous approach, which began with the technology, saying, for example, ‘We assure firewalls’. This, clearly does not address the difference in requirements between a firewall in a domestic setting, and one say in a vaccine research lab.
PBA also puts more emphasis on the way in which a technology is built and the competence of the vendor to both develop and maintain their product.
The market for cyber security
At the NCSC, we see cyber security as a crucial property of the UK technology brand. By recognising the ability of vendors to consistently demonstrate good cyber security engineering practices, we help to project the UK as a cyber power, internationally.
For technology developed overseas, the NCSC aims to ‘set the bar’ for the cyber security of products and services we integrate into UK systems.
This more flexible approach also sets the tone for cyber security as an enabler of digital growth, integral to product development, rather than a last minute addition and a blocker to innovation.
