Brian Sims
Editor

Cyber agencies combine to deliver new guidelines for secure edge devices

CYBER SECURITY chiefs in the UK and their international allies have issued a new set of guidelines designed to assist manufacturers of edge devices in making their products that much more secure and easier to investigate if a compromise should occur.

Published by Government Communication Headquarters’ National Cyber Security Centre in tandem with cyber security agencies in Australia, Canada, New Zealand and the US, the new guidance highlights an increasing number of sophisticated malicious actors targeting vulnerabilities in edge devices.

Edge devices are Internet-connected devices that sit at the ‘edge’ of a network, acting as entry points for data between local networks and the wider Internet. Examples include routers, smart appliances, Internet of Things devices, sensors and surveillance cameras, which can be particularly vulnerable to hackers as they often handle important data and connect directly to external networks.

The new guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default such that network defenders can more easily detect malicious activity and investigate following an intrusion event.

They also set out the minimum standards for forensic visibility in order to help network defenders in securing organisational networks, both proactively and in response to a compromise episode.

Relentless wave 

NCSC technical director Ollie Whitehouse explained: “In the face of a relentless wave of intrusions involving network devices globally, our new guidance sets out what we collectively see as the standard required to meet the contemporary threat.”

Whitehouse continued: “In doing so, we are giving manufacturers and their customers the tools to ensure products not only defend against cyber attacks, but also realise the investigative capabilities required post-intrusion.”

In conclusion, Whitehouse noted: “Alongside our international partners, we’re focused on nurturing a tech culture that bakes security and accountability into every device, while in parallel enabling manufacturers and their customers to detect and investigate sophisticated intrusions.”

The new guidance is part of a co-ordinated series of complementary publications on edge device security.

*Access the new Guidance on Digital Forensics and Protective Monitoring Specifications for Producers of Network Devices and Appliances online

Company Info

WBM

Dorset House
64 High Street
EAST GRINSTEAD
RH19 3DE
UNITED KINGDOM

01342 33 3711

Login / Sign up