Technology assurance
Pages
Page 24 of 35
2. Only authorised users should have access to data and functionality
A key principle in security is that users should only have access to data and functionality that is necessary to support their legitimate aims. ‘Access’ can mean both physical access to a device, and remote access to services and functions provided by the product.
Products that may be subject to cyber attack need to be managed and configured. Access to the management and configuration functions of a device should be regarded as a privileged role, restricted to authorised users and implemented securely. Access should then be logged and monitored accordingly (see Principle 5).
An attacker who can gain access to the management of a product can affect its security and functionality, and compromise sensitive data. If regular users also have access to low level functionality beyond that needed for their role, there is unnecessary potential for them to gain access to more sensitive functions.
Example defensive measures
- The product should support role-based authentication and access control. Access to data and functionality is defined by the role. All users should be issued with unique, but usable, authentication credentials before their first access to the system.
- All requests for access should be authenticated before being granted, so that users are only given access to the data and functionality to which their role entitles them. Authentication mechanisms might range from simple usernames / passwords to large certificate-based trust architectures, depending on the complexity and security requirements of the system.
- Only authorised and authenticated administrators should have access to the management interface - it should be unavailable to all others. Management can be remote or local, and if either mode is not required, it should be disabled.
- Privileged functions should afford access to the minimum amount of sensitive user data necessary. The purpose of management and configuration is to support the operation of the device, not give access to all data.
- Authentication credentials should be generated and managed securely. Management could involve technical considerations, such as not storing passwords in plain text, or procedural, such as controlling distribution of physical access tokens and applying time limits to credential validity. Default credentials, such as those used during manufacturing must be removed before the product is operational.
- You should consider how to protect sensitive user data from other users, either from attempts to bypass or undermine security functions, or through inadvertent implementation errors (see Principle 4).
