Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 19 of 35

5. Review and test frequently

You should have a rigorous verification regime in place, which uses multiple approaches, such as testing and peer review. This helps you find defects and ensures that security works in practice. It will also tell you whether the product is achieving its end goals. The verification process should not get in the way of delivery and should be automated where possible.

Examples of Defensive Measures

  • A comprehensive verification regime should be in place that will be used to both locate defects and determine whether each of the product requirements has been met. This should involve both Static Verification (e.g. personal and peer review, static code analysis and formal verification) and Dynamic Verification (all forms of testing).
  • Verification should be made as easy as possible through the creation of consistent, well-structured and understandable product development artefacts. This should include design documents, models and source code. Adherence to simple and unambiguous procedures should help the process to run smoothly.
  • The location, independence, coverage, frequency and repeatability of verification activities should be optimised. Automation can greatly support this and also aid efficiency.
  • Verification should be a continuous process that is performed during both product development and post release (to ensure a product remains secure throughout its life). The specifics of its constituent activities, as well as their coverage, should be frequently reviewed and, if appropriate, updated. For example, the contents of test suites, or what is looked for during peer review should be kept current and regularly exercised (test runs, reviews performed, etc.) so that they protect against the latest threats.
  • When defects are discovered, they should be promptly addressed. Root causes should be analysed to determine if they are endemic and ensure that similar mistakes are avoided in the future.

Published

Reviewed

Version

1.0