Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 23 of 35

1. Usability of the product

Making secure operation the natural choice.

Any product which must be resistant to cyber attack should be designed to naturally promote safe and secure use. As far as possible, security functionality should not interfere with day-to-day operation, remaining easily accessible but unobtrusive.

Security functions and interfaces should be intuitive for the people who use them. Support should be available to help ensure the product is configured and used in the way intended.

By making secure operation the preferred choice for users, these design goals will help to ensure that a product remains as secure as possible throughout its life.

Very often, if security doesn’t work for people, it doesn’t work at all. For instance, if a product is clumsy to use, people will find a lower friction way to get their task done. If a product is difficult to configure, then a mistake in its set up could lead to a lack of security functionality further down the line.

These usability challenges can potentially bypass the controls that have been put in place to keep them, and the systems in which they are working, safe.

Examples of defensive measures

  • The product should have a focus on the human-centred design qualities of efficiency, effectiveness, user satisfaction, inclusivity, and accessibility. Education, training, and configuration support should be available to people installing and using the product.
  • Usability testing of the product should be carried out by a representative sample of people, covering potential roles, tasks, constraints, and situational contexts. Product designers should take time to understand who their likely users will be.
  • Product performance should be predictable for users. If performance is not good enough, there will be pressure for people to find alternative ways to get their task done, potentially bypassing security controls.
  • A process for logging usage patterns and reporting pain points should be in place to identify potential sources of vulnerability and enable continuous improvement.
  • The user should be made aware when the product is insecurely configured, and reverting to a secure default state should be easy. The product should provide support, and clear ways to recover, if users have made an error. Any feedback from the product to the user should be clear and meaningful.
  • Measures are put in place, where possible, to prevent or make scenarios that facilitate malicious use or lead to security incidents less likely or dangerous. These could include identifying and controlling for unintended interactions with the product, or moving dangerous actions away from commonly used functions.

Published

Reviewed

Version

1.0