Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 22 of 35

Principles: Product design and functionality

6 principles which describe security functionality intended to defend against the most common techniques used by cyber attackers.

It’s essential that products implement the security functionality needed to mitigate the cyber threats they will face in use.

The Product Design and Functionality principles are intended to:

  • Assist product vendors, designers and developers in making security-related decisions as they take a product from concept to installation and use.
  • Help risk owners to gain confidence that a technology solution mitigates the specific threats which they expect it to face.

These principles provide a framework that is not only relevant to cyber security products, but any product which must be resistant to cyber attack, even though its main purpose may not be cyber security related.



These principles detail the areas to be considered when assessing whether the security functionality of a product is sufficient for the level of threat it faces.

Guidance on additional mitigations for elevated threat scenarios can be found in the NCSC Design guidelines for High Assurance products.

Reviewed

Version

1.0