Technology assurance
Pages
Page 30 of 35
1. Enable people to manage their risks
Technical defensive measures designed into a product may have limitations, and their effectiveness may degrade over time. Developers should ensure that advice on these limitations, along with associated mitigations and improvement, is readily available and actively advertised to both risk owners and the people using the product.
The people using the product should have easy access to a range of product support options throughout its lifetime. They should be notified promptly of exploitable vulnerabilities so that they can protect themselves and others, and when a product is updated, they should be advised of the security implications.
When a user passes a product on to another party, they should be confident that their sensitive data is not exposed.
Example defensive measures
- User manuals should be clearly written, and updated as new features are added to a product, highlighting how to improve security. User training should be offered regularly on the security aspects of installation, configuration, maintenance and use, drawing attention to common mistakes to avoid, along with an explanation of security implications.
- Where a product, or a service it depends on, has become vulnerable to compromise, security alerts should be issued immediately to affected users. These should clearly detail mitigating actions they should take. An effective product support service, with contact details accurately maintained, can help users get support in resolving security issues, as well as reporting defects.
- Making the process for updating a product simple and painless maximises the likelihood that users will adopt security enhancements. Whenever a product update includes new features, those features should be configured in the most secure state by default, so that the user is in control of activating any feature that increases the attack surface or otherwise puts them at greater risk.
- End-of-life dates should be clearly published to users, so that they know when security updates will no longer be offered for a product. When a product is known to offer insufficient security, it should be retired.
- Users should be able to clear all their sensitive information and configuration details from a product. This means that the risks to their data are minimised when a product is returned for repair, transferred to a new owner, or disposed of.
