/secure-communication-principles

Guidance to help you assess the security of voice, video and messaging communication services.

Secure communication principles

Guidance to help you assess the security of voice, video and messaging communication services.

Our blog introduces this guidance.

The guidance is an alpha release that we'd like to share with the community for comment. We welcome any feedback, especially from vendors of communication services, that could help the NCSC improve and finalise the secure communication principles. You can create an issue or e-mail us on scpfeedback@ncsc.gov.uk.

Introduction

Modern technology provides a wealth of options for communicating in the workplace, which now includes voice, email, group messaging, and video.

This guidance contains a set of principles that can help all organisations make sound security decisions when selecting the products and services that provide secure communications. It is aimed at risk owners and security professionals who wish to assess communication technologies for their organisations, to help them achieve the right balance of functionality, security and privacy.

It is of particular relevance for those working in government and the public sector.

The NCSC's secure communication principles

  1. Protect data in transit
  2. Protect network nodes with access to sensitive data
  3. Protect user access to the service
  4. Ensure secure audit of communications is provided
  5. Allow administrators to securely manage users and systems
  6. Use metadata only for its necessary purpose
  7. Assess supply chain for trust and resilience