Technology assurance
Pages
Page 22 of 35
Principles: Product design and functionality
It’s essential that products implement the security functionality needed to mitigate the cyber threats they will face in use.
The Product Design and Functionality principles are intended to:
- Assist product vendors, designers and developers in making security-related decisions as they take a product from concept to installation and use.
- Help risk owners to gain confidence that a technology solution mitigates the specific threats which they expect it to face.
These principles provide a framework that is not only relevant to cyber security products, but any product which must be resistant to cyber attack, even though its main purpose may not be cyber security related.
Cyber attacks
The Product Design and Functionality principles describe security functionality which is intended to defend against the most common techniques used by cyber attackers. They include measures to:
- Protect sensitive data in transit, and at rest on the product
- Maintain the secure operation of the product
- Enable malicious activity to be detected and acted upon
These fundamental principles apply across the assurance spectrum, from defending against the most basic commodity-level threats to countering the elevated threat from extremely capable, and motivated, threat actors.
Implementing the principles
How the principles are met in practice, and the strength of any protective measures, is expected to vary according to the anticipated level of threat. The amount of confidence needed will also vary according to risk appetite.
The principles provide a framework against which the design and functionality of the product can be analysed. For each principle in this collection we describe the underlying security issue which needs to be addressed and give a series of example measures which could be used.
There are 6 principles
- 1
Usability of the product
- 2
Restrict access to authorised users
- 3
Protect sensitive data when in transit
- 4
Protect against unauthorised access and modification
- 5
Protect against compromise from connected technology
- 6
Security events should be logged and monitored
These principles detail the areas to be considered when assessing whether the security functionality of a product is sufficient for the level of threat it faces.
Guidance on additional mitigations for elevated threat scenarios can be found in the NCSC Design guidelines for High Assurance products.