Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 31 of 35

2. Protect the product from unauthorised access

All assets used to design and build the product should be protected from unauthorised modification.

Management of access to products throughout their lifecycle reduces opportunities for malicious interference.

This means that data, software, systems and component parts should be protected from compromise during all stages of development, build, test, use and maintenance. The integrity of tools used to build a product is as important as the integrity of any data that supports development.

Unauthorised or unexpected changes to a product can be detrimental to the security it offers, and it is much easier to gain confidence in products when they function consistently, conforming to known build specifications that only change when new versions are formally approved for release.


Published

Reviewed

Version

1.0