Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 27 of 35

5. Protect against compromise from connected technology

Ensuring connectivity can be achieved without compromising security.

Handling connectivity to external devices, or networks, is a critical security function for most systems. This can range from the pairing of a Bluetooth headset with a mobile phone, to the dynamic interconnections of a large scale enterprise architecture across a global network.

While these connections are essential, they have the potential to create additional areas of focus for an adversary. If an attacker can gain control over a connected device, and if they can use such a device to send malicious data through your system, the have the potential to compromise security functionality.

Control over how connections are authorised and managed, what data is allowed to pass through them, and the way your product protects against exploitation, can help manage this risk.

Attacks may also come from supposedly trusted connections if another device on your network has been compromised, or there is an insider threat. So, measures to protect against compromise from connected technology should be considered even when you are only connecting inside your local network. 

Example defensive measures

  • You should only establish connections with devices, systems or networks you can trust. Use standardised cryptographic methods for device authentication and management of connection sessions, wherever possible. This means that you can be confident that whoever you are communicating with is who they claim to be.
  • Ensure you have a method for revoking access granted to connected devices. If an attacker is able to control a compromised device, you want to be able to stop them from establishing a trusted connection with your product.
  • You should control the processing or forwarding of data. This means checking that data reaching your product has an expected format and that you are able to discard anything that does not match expectations. When forwarding data to other devices, you should apply technical controls to establish trust and protect against malign content.
  • Products should be designed so that an attacker cannot easily exploit any vulnerability even if they can establish an initial presence. As described in Principle 2, restoring and rebooting from a trusted, known state at power-up make establishing persistent presence hard, and strong physical separation between sensitive and non-sensitive data area can make accessing sensitive data harder.

Published

Reviewed

Version

1.0