Technology assurance
Pages
Page 34 of 35
5. Be prepared to respond to external events
Not everything that affects the security offered by a product is within the control of developers, users, or the product itself. Having well-rehearsed plans in place to deal with unexpected events that have security implications will help manage such risks.
External events could include vulnerabilities being released publicly without warning, or technical breakthroughs that the product has not been designed to defend against. They can also arise from changes that affect suppliers and services the product depends on.
Hardware components may become hard to source, support for software may end, third-party supplies may suffer a security incident, or manufacturing premises may suffer unexpected damage. All these things have direct implications for the ability of a developer to maintain the security offered by the product.
Example defensive measures
- Maintain a register of all components supplied by a third party, including those that are free or open source, and routinely check for vulnerabilities that affect them. Vulnerability news feeds and threat intelligence services can help you maintain awareness of trends in cyber security and develop plans to address any relevant risks
- An obsolescence management plan, based on the known, supported life of components, should keep an up-to-date record of options that can be pursued to replace them. You should take care to ensure that you are acquiring replacements from reputable sources.
- Third party suppliers should only be allowed to retain the information they need, and have access to your systems that is necessary for them to fulfil their role. Accurate records of third-party information holdings can help you assess the impact if they are compromised.
- Business continuity plans should be updated regularly, and you should ensure you follow the measures defined in them. For example, creating secure offsite and offline back-ups will help with disaster recovery, but only if they are updated frequently and the restoration process is tested regularly.
- You should be ready to respond to vulnerabilities in tool chains by assessing the potential impact and take mitigating actions, including installation of updates or patches. It is sensible to plan for tool chain elements becoming obsolete, which may result in loss of functionality or, if cloud-based, complete unexpected withdrawal.
