Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 15 of 35

1. Design for user need

Appreciating how your product will be used and maintained throughout its life, is a crucial aspect of ensuring that security will endure in practice.

You must frequently and consistently capture and record requirements (including security requirements) for all of your product’s intended operational uses, and the different people that will be involved in installing, using, and maintaining it. This will help to ensure that your resultant product’s functionality meets the user’s needs whilst also being both usable and secure.

Examples of Defensive Measures

  • A process for discovering requirements on a continuous basis should be in place. Requirements should be validated and documented in a consistent and auditable way. This helps to ensure that the goals of the product are visible, remain current, and that changes are easily identified and tracked.
  • Requirements should be sought from a sufficiently representative group of stakeholders. Without this understanding, products are unlikely to meet the intended users' needs and this can have a direct security impact (for example, if usability is not adequately considered a device may be difficult to configure, leading to a prospective customer purchasing a less secure but easier to use product instead).
  • Requirements need to be usable for the developers that implement them. That is, they should be understandable and easy to access, their purpose and reasoning should be clearly articulated. They should be readily and easily absorbed into the product’s existing development and implementation processes from the outset.
  • Security requirements should be derived from an understanding of the potential threats to a product.
  • All requirements should be used to inform and evolve the product’s verification regime.

Published

Reviewed

Version

1.0