The following sections provide recommendations and guidance for each phase of the security lifecycle of a smart streets project. Some recommendations are relevant to all smart streets use cases, while others have limited applicability. This is indicated at the start of each recommendation. Authorities may choose not to implement all recommendations, however, some recommendations may have dependencies on others, so consider this when deciding which recommendations to implement.
Security Lifecycle Phases and Recommendations:
| 1. Vision 2. Define Needs |
SECURITY PREREQUISITES | A1 – Ensure Your Cyber Security Management System is Fit for a Connected Place |
| A2 – Establish the Rationale for Securing Your Connected Place | ||
| A3 – Define Security Roles and Responsibilities for Your Connected Place | ||
| A4 – Establish a Security Assurance Framework | ||
| A5 – Dictate Security-Informed Project Management | ||
| A6 – Improve Staff Security Awareness and Training | ||
| 3. Market Testing 4. Strategy and Plan |
SECURITY CONCEPT | B1 – Consider Security as Early as Possible |
| B2 – Ensure All Projects Have Security Accountability and Responsibility Defined | ||
| B3 – Understand the State of Cyber Security of Existing Systems and Consider the Security Implications of the Project | ||
| B4 – Create a Project Security Assurance Plan | ||
| 5. Specification | SECURITY DEFINITION | C1 – Identify Where Regulatory Requirements Potentially Impact Security Considerations |
| C2 – Create a Zone and Conduit Model | ||
| C3 – Conduct an Initial High-Level Threat and Risk Assessment (TRA) | ||
| C4 – Develop Security Requirements Based on a High-Level TRA | ||
| 6. Procurement 7. RFI and Tender 8. Tender Evaluation 9. Award |
SECURE PROCUREMENT | D1 – Identify Relevant Security Standards and Guidance to Reference |
| D2 – Use a Procurement Framework That Considers Cyber Security | ||
| 10. Implement | SECURE DELIVERY | E1 – Continue Managing Security Risk |
| E2 – Track Security Requirements | ||
| E3 – Carry Out Appropriate Security Testing | ||
| E4 – Securely Commission | ||
| E5 – Document the Security Case | ||
| 11. Operate 12. Evaluate |
SECURE OPERATIONS | F1 – Conduct Periodic Security Testing and Manage New Vulnerabilities |
| F2 – Manage Security Patching of Smart Streets Assets | ||
| F3 – Monitor Systems for Unusual Behaviour | ||
| F4 – Prepare for an Incident | ||
| F5 – Audit Suppliers’ Ongoing Security Programme | ||
| 13. Decommission | SECURE DECOMMISSIONING | G1 – Securely Dispose of Hardware and Data |
Case Studies:
Additional: