Guidance
Technology assurance
The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.
Pages
Page 26 of 35
4. Maintain the integrity of a product and any sensitive data held on it
Ensuring the product is resilient to attempts to change its behaviour.
Adversaries may want to gain access to sensitive data, either to compromise the user or to aid development of future attacks. They may look to modify software, firmware or hardware to alter the operation of the product, or to enable a persistent presence.
Product designers should ensure that there is appropriate identification of, and protection for all sensitive data in the product - both user data and device-sensitive data. They should also ensure that mechanisms exist to protect against physical modification, and to give confidence in the integrity of the product and the components it relies upon.
Example defensive measures
- Sensitive user data and device-specific data, should be clearly identified during design and, where possible, be separated from non-sensitive data, for example, in separate memory, or separate locations within file systems. This enables data protection mechanisms to be well targeted.
- If sensitive data needs to be persistent, apply appropriate confidentiality and integrity mechanisms. Where sensitive data is updated, update mechanisms should provide authentication. This gives the user and the product developer confidence that their personal and proprietary information is well protected.
- It is important to minimise the amount of data that is potentially accessible to an adversary. For user data, information should not be retained when it is no longer required. For device-specific data, the developer should limit the amount of information available to someone scanning or probing the device.
- Verify the integrity of software and hardware components during start-up and operation, and through product updates. Where the device relies on external components (e.g. unique cables or peripherals), these should also be verified prior to use. This provides confidence that the device remains in a trusted state throughout its lifetime.
- Where they are available, use the built-in security features of components within a product. Many security-focussed components provide protections for memory contents, or mechanisms to aid with separation of sensitive and non-sensitive data.
- Incorporate methods to detect and respond to attempts at physical compromise of the product. These methods could be procedural, but can also include passive or active anti-tamper technologies. A layered approach, comprising a few such approaches, provides defence-in-depth.
