Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 14 of 35

Principles: Product development

7 principles which underpin the development of secure products.

Good security engineering means building technologies that remain usable and resilient throughout their lifetime, even in the face of cyber attack.

These principles describe the overarching security outcomes that the NCSC would look for when assessing product development processes and practices.

Determining the degree to which a product developer meets these principles gives us a measure of how competent they are at building secure technologies. To aid this, accompanying each principle is a non-exhaustive list of the type of defensive measures which a product developer can provide evidence of, in order to demonstrate their competence.

Demonstrating competence

As a competent product developer, you should be able to demonstrate that you have processes and practices in place to incorporate security and usability into your whole development process and resultant products.

You should also be able to demonstrate you have secured your development infrastructure against unauthorised access, data transfer and data modification (from both internal and external sources), to maintain the confidentiality and integrity of your product development artefacts, including requirements and design documentation, source code and test plans.

Minimising the likelihood and impact of compromise

The security of a finished product can be compromised when a vulnerability - which may have been introduced during development - is exploited.

Product development itself can also be disrupted by a security compromise. For example, by a ransomware infection enabled by a phishing attack on one of the development team.

These compromises can result from either malicious activity or through a simple mistake.

Ensuring that a product vendor’s engineering processes and practices minimise both the potential likelihood and possible impact of a security compromise plays an essential part in gaining assurance in both their overall competence and trust in the products that they produce.

Technology Assurance Principles - Developing a secure product

Developing and building products which are resilient to cyber attack can be broken down into seven areas of concern. These are:

Reviewed

Version

1.0