Technology assurance
Pages
Page 29 of 35
Principles: Through-life
5 principles for maintaining security through all stages of a product's lifecycle.
Against a backdrop of rapid technological advancement and a forever evolving threat environment, continuous management of device security, throughout its lifetime, is vital.
The Through-Life principles are intended to:
- Assist vendors, designers and developers to make decisions about maintaining product security through life
- Help risk owners to gain confidence that a technology solution mitigates the specific threats which they expect it to face through all stages of a product’s lifecycle
About these principles
This guide introduces five principles of through life product security. These principles are intended to draw out considerations for maintaining security through all stages of a product’s lifecycle: from conception, design and development, testing, initial release, in-field updates, decommissioning and disposal.
These principles complement the secure development and product design and functionality principles that also form part of this collection. For each principle in this collection we describe the underlying security issue which needs to be addressed and give a series of example measures which could be used.
There are five bases through life principles:
- 1
Enable people to manage their risks
- 2
Protect the product from unauthorised access or modification
- 3
Monitor services used by a product
- 4
Review and improve the security offered by a product
- 5
Be prepared to respond to external events
The need for through life security
Sources of vulnerability
There are many ways in which a product can become insecure.
Features which are intrinsic to a product or its implementation may become increasingly susceptible to attack over time. Similarly, vulnerabilities overlooked during development may only emerge once a product is in widespread use.
The environment in which a product is developed, built, tested and maintained may be targeted as a means to discover confidential information, or introduce weaknesses through surreptitious modifications.
External events, outside the control of a product developer, also have the potential to impact on the security of a product.
Other parties in the supply chain may be compromised, or components from third parties incorporated into a product may be found to be vulnerable, or become obsolete. Services on which a product depends also need to be considered, as any compromise of these could have a security impact for a product and its users.
Nature of mitigations
Mitigations must address a range of risks, many of which are not solely related to the technical features of a product. So, it’s necessary to consider all potential avenues of compromise.
It is important then, that users of a product are provided with access to sufficient information and capability to help them protect themselves and manage any security risks to their information.