Government Cyber Security Policy: Asset Management Policy for Edge Devices
The asset management policy for government departments and ALBs details controls for how they should acquire, maintain, track, deploy and dispose of edge devices.
1. Policy statement
1.1 All central government departments and their arm’s length bodies (ALBs) shall maintain appropriate asset management controls for how they acquire, maintain, track, deploy and dispose of edge devices. This includes mandatory requirements to:
1.1.1 Ensure all edge device assets within their organisation’s digital estate are identified and inventoried, with the inventory kept up to date.
1.1.2 Ensure edge devices are supported throughout their life cycle, from creation through to eventual decommissioning or disposal, including ensuring end-of-service and end-of-support dates are planned for so that edge devices are not in use without manufacturer support.
1.1.3 Maintain edge devices with an established rebuild process, with a requirement for government organisations to remediate vulnerabilities within the following timescales:
-
- remediate all critical and known exploited vulnerabilities on edge devices within 48 hours of the vulnerability disclosure
- remediate all other vulnerabilities on edge devices within 5 days
- undertake mitigation and/or remediation activity for any vulnerabilities on edge devices where and as directed by the Government Cyber Coordination Centre (GC3), based on GC3 risk assessment
- decommission any currently out-of-support edge devices by the end of December 2026, and afterwards, by no later than the out-of-support date
1.2 Central government departments with Lead Government Department (LGD) responsibility for the wider public sector shall communicate this policy to the bodies and organisations within their remit in accordance with Government Security Policy: Security Functional Accountability.
2. Description
2.1 Edge devices are a subset of assets deployed at the edge of a network to provide network access, route or control traffic, enforce network security, or provide edge computing capability. For the purposes of this policy, an asset is considered an edge device if it performs one or more of these functions and is not expressly identified as out of scope in section 4.
2.2 These devices are attractive targets because they can provide extensive reach into an organisation’s network and may integrate with identity management systems. They can be exploited through both newly-discovered vulnerabilities and older vulnerabilities that remain unremedied.
2.3 This policy sets expectations for how government organisations maintain visibility of, remediate vulnerabilities affecting, and exercise life cycle control over in-scope edge devices within their digital estate. It describes the technical and procedural controls that affected organisations must use to secure those devices and the services and connectivity they enable.
3. Audience
3.1 This policy is intended for:
- chief information security officers (CISOs) and security advisers responsible for the overall security of an organisation
- chief digital and information officers (CDIOs) responsible for the overall digital, data and technology strategy of an organisation
- cyber security professionals responsible for advising technical teams on the secure management of IT assets and infrastructure
- technical delivery teams responsible for managing IT assets and infrastructure
- IT security teams and security operation centre (SOC) teams responsible for integrating edge devices asset management into security information and event management (SIEM) tooling and workflows
- security and cyber teams responsible for addressing identified vulnerabilities and applying remediation guidance
4. Scope and definitions
4.1 This policy applies to central government departments, their ALBs, and other public sector organisations within their remit.
4.2 This policy applies to assets that fall within one of the edge devices categories listed and form part of the organisation’s digital state.
Edge device assets in scope include but are not limited to:
- wireless access points
- routers, switches and firewalls located at the edge of the network
- single appliances that combine any of the above functions
- edge servers used as part of cloud infrastructure
- any other assets deployed at the edge of a network to provide network access, route or control traffic, enforce network security, or provide edge computing capability
Edge device assets out of scope are:
- cameras
- sensors, including temperature and building management sensors
- Internet of Things (IoT) sensors used in operational environments
- smart and end-user devices, including laptops, tablets and phones
- edge software considered as an asset independently of the hardware on which it runs
- terminals and kiosks
- embedded connectivity systems used in manufacturing devices
4.3 This policy applies to vulnerabilities affecting the hardware, software, firmware or operating systems of an in-scope edge device. Where warranted by risk assessment, GC3 may also direct organisations to undertake remediation activity in relation to vulnerabilities affecting other edge devices.
4.4 The following definitions apply to the vulnerability management requirements set out in this policy:
Critical vulnerability
A vulnerability is defined as ‘critical’ if either of the following applies:
- it has a Common Vulnerability Scoring System score of 9 or above
- it is assessed as having a ‘total’ technical impact under the Cybersecurity and Infrastructure Security Agency’s (CISA) Stakeholder-Specific Vulnerability Categorisation (SSVC) system.
‘Total’ technical impact means the vulnerability enables an attacker to gain complete control over the behaviour of the vulnerable software component, or results in the total disclosure of all information managed by the system containing the vulnerability.
In turn, this is where an attacker can install and run arbitrary software on the impacted device, trigger all the actions that the vulnerable component can perform, or access an account with full privileges to the vulnerable component (for example, administrator or root user accounts).
CISA publishes SSVC assessments and related vulnerability enrichment data through its Vulnrichment Programme.
Known exploited vulnerability
A vulnerability is defined as ‘known exploited’ if organisations have any evidence that it is exploited, including but not limited to whether it is in the US CISA’s public Known Exploited Vulnerabilities (KEV) catalogue, which is in turn reflected in the CVE record through the CISA Vulnrichment Programme.
Remediation
Remediation means the permanent removal of a vulnerability through actions including but not limited to:
- applying patches
- installing updates
- replacing vulnerable components
- upgrading software or firmware
- rebuilding affected systems
- decommissioning affected assets
Mitigation
Mitigation means implementing measures that remove the likelihood or impact of exploitation where immediate remediation is not possible. Mitigation does not remove the underlying vulnerability and should be an interim measure pending remediation.
5. Risks addressed
5.1 The risk to edge devices is systemic, severe and cross-government. These types of assets are routinely targeted by sophisticated threat actors. While a necessary part of modern enterprise IT, edge devices create significant risk because of their role connecting internal networks to the internet and due to regular insecure configurations.
5.2 The rapidly increasing capability of frontier artificial intelligence (AI) further heightens this risk. Among other impacts, the technology almost certainly enables adversaries to identify and exploit vulnerabilities at greater speed and scale than ever before, including in edge devices.
5.3 Exploitation of edge devices could have a significant impact on government, requiring central management and monitoring.
The primary impact is against data compromise risks. Exploitation of edge devices can provide hostile actors with persistent access to government networks, enabling compromise of systems, services and information across multiple organisations. This could in turn contribute to:
- reduced government operational effectiveness
- loss or degradation of critical services
- reduced public confidence in government’s ability to deliver secure and reliable digital services
- compromise, loss or unauthorised disclosure of sensitive information
5.4 A reasonable worst-case scenario (RWCS) is that unpatched edge devices are exploited at scale across multiple organisations by a hostile actor, providing persistent access to government networks and enabling compromise across multiple organisations.
6. Policy requirements
6.1 This policy contains both mandatory and advisory elements, using the same language as Functional Standard GovS 007: Security:
- ‘shall’ means a requirement: a mandatory element
- ‘should’ means a recommendation: an advisory element
6.2 All central government departments and their ALBs shall:
- ensure all edge device assets within their organisation’s digital estate are identified and inventoried, with the inventory kept up-to-date. This process must ensure dependencies on supporting infrastructure are recognised and recorded and that edge device assets are prioritised according to their importance to the operation of the essential function(s)
- ensure edge devices are supported throughout their life cycle, from creation through to eventual decommissioning or disposal – including ensuring end-of-service and end-of-support dates are planned for to ensure edge devices are not in use without manufacturer support
- maintain edge devices with an established rebuild process, with a requirement for government organisations to remediate vulnerabilities within the following timescales:
- remediate all critical and known exploited vulnerabilities on edge devices within 48 hours of the vulnerability disclosure
- remediate all other vulnerabilities on edge devices within 5 days
- undertake mitigation and/or remediation activity for any vulnerabilities on edge devices where and as directed by the GC3, based on GC3 risk assessment
- decommission any currently out-of-support edge devices by the end of December 2026, and afterwards, by no later than the out-of-support date
6.3 All central government departments and their ALBs should:
- regularly monitor edge devices, to detect unusual or anomalous activity such as configuration changes, including unauthorised access, modification, or changes to protective measures before or during patching, using logs and monitoring data
- collect and retain key security logs from edge devices for at least 180 days to support detection and investigation
- have the capability to undertake forensic triage and collect detailed forensic data from edge devices following suspected compromise
- maintain an organisational view of cyber risk for edge devices and their impact on services
- share observations and provide relevant information requested by the Government Cyber Unit (GCU) to enable holistic monitoring of threat, vulnerability, and risk across government
- integrate asset management for edge devices into incident response plans, including how to investigate, contain and recover from any compromise
- manage edge devices through secure access methods rather than exposing interfaces directly to the internet
7. Implementation and compliance
7.1 Central government departments are responsible for ensuring their ALBs and other public sector organisations in their remit are compliant with the requirements of this policy.
7.2 Organisations shall comply with the mandatory requirements of this policy. Where an organisation is not compliant, the accounting officer shall provide the GCU with a remediation plan in line with the organisation’s risk tolerance. This should set out:
- the requirement or requirements with which the organisation is not compliant with
- the reason compliance has not been achieved
- the actions that will be taken to achieve compliance
- the date by which compliance will be achieved
7.3 Compliance with this policy may be subject to additional assurance activity conducted by or on behalf of the GCU. Organisations shall provide information reasonably requested to support monitoring of compliance and management of cyber risk across government.
7.4 Organisations should have a plan in place to work towards future compliance with this policy in a way that meets their business objectives and priorities and to ensure continuous improvement over time.
8. Supporting material and standards
8.1 This policy is supported by and relates to:
- Functional Standard GovS 007: Security which sets expectations for what security activities organisations must carry out and why to protect government assets
- The Government Cyber Security Standard, which sets out how this should be done in relation to cyber security, specifying the particular procedures organisations must follow and the performance criteria to be met
- other applicable cross-government policies published in the Government Cyber Security Policy Handbook
- relevant security directives from the Government CISO, GCU, or government ministers
- guidance for organisations from the National Cyber Security Centre (NCSC) on digital forensics and protective monitoring specifications for producers of network devices and appliances and vulnerability management
- guidance for organisations from Members of the Five Eyes Intelligence Partnership on:
- prioritising security updates based on risk (CISA, BOD 26-04)
- mitigating risk from end-of-support edge devices (CISA, BOD 26-02)
- threat actors exploit multiple vulnerabilities in Ivanti connect secure and policy secure gateways (CISA, AA24-060B)
- implementation guidance for mitigating the risk from internet-exposed management (CISA, BOD 23-02)
- the critical importance of edge device security (CISA)
- best practices for event logging and threat detection (ASD)
9. Cyber Assessment Framework (CAF) outcomes
9.1 The controls described in this policy will help government organisations demonstrate that they have met the required security outcomes in the NCSC Cyber Assessment Framework (CAF), including but not limited to:
- A2.a Risk management process
- A3.a Asset management
- B4.b Secure configuration
9.2 The mandatory elements of this policy are aligned with or exceed the Basic Government CAF profile. Any elements that exceed the profile requirements do so because they are essential to achieving the policy’s core aims.
Further guidance for government organisations on meeting the required security outcomes of the CAF is provided in the Government Cyber Security Policy Handbook.