Threat Information
Plan & Build
NCST are highly functional computers which are connected to a network and need to be suitably protected
Electronic attack of physical security systems is the means of carrying out a localised cyber-attack specifically on the security system. This can be to corrupt data, open a portal or disable alarms.
It is important that you understand the risks associated with deploying these technologies, whether they relate to location sensitivities, data protection considerations or privacy concerns
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems.
Operate & Detect
Passport to Good Security - Online Social Behaviour: what your employees do and say online, or how they use digital devices, can make them and your organisation vulnerable to security threats.
Passport to Good Security - Home and Mobile Working: working away from the office can have numerous benefits for employees, but can also present an additional security risks.
This guidance is for users of shared workspaces and provides practical advice tailored to your workspace and activities
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems.
Response & Review
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems
Complete Guidance
A key purpose of connected places, also known as smart cities, also known as is to join up specific vertical sectors across organisational boundaries into a whole-city approach for the creation, delivery and use of city spaces and services
PAS 185:2017 Specification for establishing and implementing a security-minded approach
PAS 185:2023 is a specification for establishing and implementing a placewide, strategic-level, security-minded approach as part of both its development and operation
This guidance provides the questions which an organisation needs to ask of itself and its supply chain, including its professional advisers, in order to gain an understanding of what information it, or others, holds in relation to its built assets
An introductory guide for built asset owners and facilities managers
This guidance document is intended for use by managers leading and teams delivering digitalisation initiatives. It sets out a process to determine high-level information need and any associated security and management requirements
Guidance on how to take a Security-Minded approach to Digital Engineering, Technologies, Projects and Initiatives
This short document illustrates a ‘4 Step Publication Approach’ aimed at helping those preparing documents for electronic publication to a wide community, including publicly accessible websites and document servers
A Security Considerations Assessment (SCA) is a structured process for identifying and managing security risks associated with an activity
This guidance lists the key UK legislation, regulations and codes that decision-makers responsible for connected places should be aware of when collecting, storing, processing, generating or sharing data and information relating to connected place services and built assets
A specification for security-minded building information modelling, digital built environments and smart asset management
A specification for security-minded building information modelling, digital built environments and smart asset management
This guidance is for those procuring construction contracts within government and more widely who may be unfamiliar with the principles and practice behind information management (IM)
Information Management Clause, including requirements for a security-minded information management approach
Information Management Clause, including requirements for a security-minded information management approach
When deploying digitally connected physical security systems in the modern world, is it important to use products that have been independently tested to help withstand cyber threats. This guide sheds light on the different cyber standards available to organisations and products
When deploying digitally connected physical security systems in the modern world, is it important to use products that have been independently tested to help withstand cyber threats. This guide sheds light on the different cyber standards available to organisations and products
Considerations for use of AI in protective security and guidance on defending against AI enabled threats


