Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 30 of 35

1. Enable people to manage their risks

Equip users with the tools and information needed to mitigate any residual risk.

Technical defensive measures designed into a product may have limitations, and their effectiveness may degrade over time. Developers should ensure that advice on these limitations, along with associated mitigations and improvement, is readily available and actively advertised to both risk owners and the people using the product.

The people using the product should have easy access to a range of product support options throughout its lifetime. They should be notified promptly of exploitable vulnerabilities so that they can protect themselves and others, and when a product is updated, they should be advised of the security implications.

When a user passes a product on to another party, they should be confident that their sensitive data is not exposed.


Published

Reviewed

Version

1.0