Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 34 of 35

5. Be prepared to respond to external events

Plan for failures, vulnerabilities, and supply chain changes.

Not everything that affects the security offered by a product is within the control of developers, users, or the product itself. Having well-rehearsed plans in place to deal with unexpected events that have security implications will help manage such risks.

External events could include vulnerabilities being released publicly without warning, or technical breakthroughs that the product has not been designed to defend against. They can also arise from changes that affect suppliers and services the product depends on.

Hardware components may become hard to source, support for software may end, third-party supplies may suffer a security incident, or manufacturing premises may suffer unexpected damage. All these things have direct implications for the ability of a developer to maintain the security offered by the product.


Published

Reviewed

Version

1.0