Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 20 of 35

6. Manage change effectively

Inevitably, throughout the development process, there will be all kinds of change. From changing requirements, through to product, technology and threat evolution.

Having processes and practices in place that allow agility but ensure coherence and consistency aids cyber resilience. That is, it enables a response to new information about threat, a potential attack or an implementation change that will reduce the harm to the system into which your product is deployed.

Examples of Defensive Measures

  • At the start of product development, identify all classes / types of item that will be subject to configuration management. These should include (but should not be restricted to) anything required to recreate and maintain a specific product version, post release (including the original development and build tools).
  • Configuration management, that tracks changes, implements version control, and enables reproducibility should be applied throughout the lifetime of a product and not just during its initial development. Post release support of specific product versions is not possible otherwise.
  • Configuration items should be version controlled, with full details of any modification (including the author and time / date) recorded. This will allow root cause analysis to be performed when defects are discovered.
  • The product build process should be repeatable and, where possible, automated. Should a defect be discovered in a previous product release, a reproducible build will allow you to revisit the exact build scenario in order to develop a fix. Automation can also reduce the risks of errors and aid efficiency.

Published

Reviewed

Version

1.0