Baseline and templates
It is important for an enterprise to adopt standards and methodologies in order to follow a standard repeatable process when developing new systems or software. It is important to consider interoperability when designing or considering systems supplied by third parties.
The National Cyber Security Centre (NCSC), a United Kingdom government agency, offers guidance to UK-based enterprises. They have divided each set of principles into five categories, loosely aligned with the stages at which an attack can be mitigated. Here are the five NCSC categories (also available at https://www.ncsc.gov.uk/collection/cyber-security-design-principles):
- Establish the context
Determine all the elements that compose your system, so your defensive measures will have no blind spots.
- Make compromise difficult
An attacker can only target the parts of a system they can reach. Make your system as difficult to penetrate as possible.
- Make disruption...