Skip to main content

Design guidelines for high assurance products

Approaches to the design, development and assessment of products capable of resisting elevated threats.
Image of padlock in circle for high assurance products

This guidance recommends approaches to the design, development, and security assessment of products (and systems) capable of resisting elevated threats. It contains a set of principles that can be used to set high level security objectives, which in turn can be used to guide design decisions and development processes.

It's written for organisations that are at risk from these elevated threats, or those seeking to develop products and systems capable of resisting these threats, specifically:

  • buyers of these products (or independent assessors), to help them gain confidence that a product is capable of resisting elevated threats
  • developers of product and systems that are intended to protect against elevated threats

This guidance complements the NCSC's existing technology principles (such as those for cloud security, cross domain products, and secure communications), and may be used in conjunction with these to assess the extent to which products offer protection against both commodity and elevated threats.

Note: The ability to gather and validate evidence against these principles is fundamental to their use. The generation and validation of evidence can be achieved in a number of ways that give differing levels of confidence, such as:

  • self-assertion by product developers
  • validation of presented evidence by a procuring organisation for their own use
  • the commissioning of independent validation by a 3rd party organisation.

CAPS High Grade assessment

For certain threat models and technologies the NCSC undertakes independent assessment of products (primarily cryptographic products) that require an NCSC ‘High Grade’ Certificate. This assessment is performed under the CAPS assurance scheme, which is underpinned by detailed requirements and specifications derived from these principles. Compliance against these is tested in the most rigorous way.

The CAPS requirements and specifications are not available online, so developers looking to develop High Grade products must contact the NCSC for more information.

These high assurance principles can help risk owners to make informed decisions in cases where NCSC CAPS assessment is not appropriate. For example, deployment scenarios that limit the ability of products to meet CAPS requirements, or technology that is not designed to deliver the full range of security functionality required by CAPS.


Published

Reviewed

Version

1.0