Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 21 of 35

7. Build for through-life

Given the increasing interconnectivity of the technology we rely upon day-to-day, and the continuously evolving cyber security threat landscape, it is essential to maintain and support products throughout their lifetime, if they are to remain secure.

Examples of Defensive Measures

  • Product development artefacts, such as design documents, source code and test scripts, should be clear and consistent. This will ensure they are easily understood and maintained in the future.
  • Implement a suitable mechanism by which externally discovered product defects (including vulnerabilities) can be reported easily and responsibly. Security related defects should be acted upon as quickly as possible.
  • Maintain up-to-date knowledge of publicly known security vulnerabilities and, if necessary, augment a product's verification activities to protect against them. Users of at-risk products should be promptly notified and, where possible, a fix deployed as soon as reasonably practicable.
  • Make it easy for a customer to determine which particular version of a product they are using.
  • Publish a product support lifecycle that explicitly states the minimum length of time for which a product will receive security updates and the reasoning behind the stated duration. Customers also need to be provided with suitable notice of when product support will cease, so there is time for them to develop contingency plans, which could include sourcing a suitable alternative, accepting and managing the risk of using an obsolete product.
  • Products should be actively supported, with safe and easy to implement updates. These should be released in a timely manner and advertised to supported customers via a suitable mechanism. The reasons for the update should be clearly communicated.
  • Provide customers with clear guidance on how to securely configure, use and update a product.
  • Employ the concept of ‘Secure by Default,’ so that a product’s default configuration settings are the most secure possible.

Published

Reviewed

Version

1.0