Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
Assured Consultancy - Security Architecture Offering
ACSC Security Architecture Companies apply NCSC advice and guidance. They are able to design systems which achieve a Customer’s security goals using technical methods. Companies must design systems with appropriate security controls considering the Customer's threat model, business needs and constraints. They must provide guidance on the technical security controls available to prevent, detect and recover from security incidents and to mitigate risk. The Companies must:
- Remain up to date in capabilities, behaviours, tactics, techniques and procedures of modern threats applicable to their Customers and technology types.
- Be able to use threat intelligence in conjunction with modern threat modelling techniques to assist in determining the appropriate cyber security defences and architectural designs for a particular context.
- Remain up to date on modern and developing technologies that Customers could use to achieve operational and security outcomes.
Expected Activities
Companies assured under the ACSC Security Architecture Offering are likely to undertake the following (not exhaustive list of) activities:
- building and / or designing architectures that manage identified risks, using proportionate controls;
- identifying and articulating risks in the architectural, high level, and detailed design of systems and services;
- advising on how to reduce the likelihood and impact of vulnerabilities – whether in existing systems or those under development. This includes guidance on secure development, build, deployment, operation, and ongoing management;
- providing guidance on how to adopt and securely implement common architectural blueprints or patterns;
- providing guidance on selecting technologies which provide adequate mitigation of potential vulnerabilities identified in a system architecture;
- communicating security advice and guidance in ways appropriate for a wide variety of stakeholders, from senior board members through to security and technology implementation teams.